Linux has gained an impressive collection of security features over the last two decades. The Kernel Self Protection Project (KSPP), compiler-assisted hardening, seccomp, mandatory access control systems, and more recent memory-safety initiatives have made life harder for attackers.
Yet in the embedded world, products are often built on kernels several years old, security features are selectively enabled, and applications frequently run with privileges that would be considered excessive on a desktop or cloud system.
During my work with embedded companies, I regularly encounter a striking contrast: upstream Linux is becoming increasingly secure by default, while many deployed devices continue to rely on only a small subset of the protections available to them.
This talk explores that gap.
Using examples from embedded Linux systems, Yocto Project-based products, and upstream kernel development, we will examine how Linux performs against key security principles such as least privilege, attack-surface reduction, isolation, exploit mitigation, and memory safety. We will look at the progress achieved through KSPP and related initiatives, discuss why some security mechanisms are widely deployed while others remain rare in embedded products, and evaluate how close Linux is to being secure by default in practice.
The goal is not to review every security feature in the kernel, but to answer a practical question relevant to both kernel developers and product builders: Have we reached the point where a modern embedded Linux device is secure by default, or are the hardest problems now outside the kernel itself?
Marta Rybczynska