Aaron Davis — LavaMoat — solving JavaScript software supply chain episode artwork

EPISODE · Sep 15, 2020 · 40 MIN

Aaron Davis — LavaMoat — solving JavaScript software supply chain

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Aaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet. He introduces us to LavaMoat, an approach to solving javascript software supply chain security for node and the browser. The LavaMoat runtime prevents modifying JavaScript's primordials, limits access to the platform API, and prevents packages from corrupting other packages. We hope you enjoy this conversation with... Aaron Davis.Connect with Aaron “kumavis” Davis:→ Aaron “kumavis” Davis on GitHub→ LavaMoatMentioned in this episode:→ LavaMoat→ MetaMask→ npm event-stream incident→ Snyk→ Node.jsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Aaron “kumavis” Davis02:10 Aaron’s security origin story03:29 Security lessons from building MetaMask05:20 Why tackle the JavaScript supply chain?09:06 The problem reaches beyond JavaScript10:40 Malicious updates and compromised maintainers12:47 The hidden scale of transitive dependencies14:52 Open source economics and critical packages18:42 Is LavaMoat a firewall for JavaScript?20:22 Could browsers make LavaMoat obsolete?22:35 Runtime performance costs25:11 Threat modeling LavaMoat itself28:36 Static analysis and policy generation30:07 Understanding LavaMoat policy files33:01 Using LavaMoat in complex applications37:36 How to get involved

Episode metadata supplied by the publisher feed · Published Sep 15, 2020

Embed this episode

Aaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet. He introduces us to LavaMoat, an approach to solving javascript software supply chain security for node and the browser. The LavaMoat runtime prevents modifying JavaScript's primordials, limits access to the platform API, and prevents packages from corrupting other packages. We hope you enjoy this conversation with... Aaron Davis. Connect with Aaron “kumavis” Davis: → Aaron “kumavis” Davis on...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Aaron Davis — LavaMoat — solving JavaScript software supply chain

0:00 40:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 40 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 15, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!