Building on Bedrock: A Security Philosophy from Bootloader to Runtime

QCon London 2026

Session Kernel

Building on Bedrock: A Security Philosophy from Bootloader to Runtime

Tuesday Mar 17 / 11:45AM GMT, Mountbatten (6th Fl.) at The QEII Centre, London

Abstract

In Minecraft, every world is built from blocks. At the very bottom lies bedrock: an unbreakable foundation that everything else rests on. Above it sit layers of stone, dirt, sand, and other materials. The surface looks quite beautiful, but the resources essential for survival are buried deep below, and players must descend to reach them. Of course, they’re warned: “don’t dig straight down”: remove the block under your feet and you might plunge into lava.

Our technological infrastructure works the same way. We often focus on the surface: APIs, clusters, and users. But just above the bedrock of our systems are the crucial yet less visible layers: hardware drivers, kernels, bootloaders. Developers know that digging too far down can be difficult and risky because of the complexity involved. Yet, as in Minecraft, you can descend safely with the right approach, working your way towards a once untouchable foundation to solve the biggest challenges you face such as security, performance, or velocity.

This talk traces through the way we think about layers of software today and how simplifying those layers can lead to improvement in outcomes in both functionality and security. It also will explain a strategy for working on layers that a developer doesn't traditionally work on.

This isn't about software being a silver bullet or any single technology solving our problems. It’s a mindset to restore holistic system security, not accepting the status quo just because it’s always been that way. Stripping back layers of complexity and building what we really need, all at the bottom layer of the stack.

Security done right isn't a gate that slows people down, it’s an enabler. But getting there requires us to stop accepting that some layers are just "too hard" to fix and start building the bedrock our systems deserve. You can't solve security at just one layer. You have to do it all, from bedrock up.

Topics

Kernel Rust architecture platforms
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2026 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 17 March

10:35 Mountbatten (6th Fl.) Session security Why Governance Matters: The Key to Reducing Risk Without Slowing Down Sarah Wells Independent Consultant and Author 11:45 Mountbatten (6th Fl.) Session Kernel Building on Bedrock: A Security Philosophy from Bootloader to Runtime Alex Zenla Founder & CTO @Edera 13:35 Mountbatten (6th Fl.) Session SBOMs From Chaos to Clarity: Modern SBOM Practices That Actually Work Viktor Petersson Founder of sbomify, Co-founder & CEO of Screenly, Host of Nerding Out with Viktor 14:45 Rutherford (4th Fl.) Unconference Unconference: Software Security & Risk Management 15:55 Windsor (5th Fl.) Session security Exploding GPUs Andrew Martin Founder and CEO @ControlPlane, CISO OpenUK, CNCF Security Advisory Group 17:05 Windsor (5th Fl.) Session security Adopting Memory-Safety and Fine-Grained Compartmentalisation With CHERI David Chisnall Director of System Architecture @SCI Semiconductor, OS, Compiler, and Computer-Architecture Expert, Maintainer of the CHERIoT Platform