François Proulx -- Actionable Software Supply Chain Security episode artwork

EPISODE · Jun 22, 2023 · 42 MIN

François Proulx -- Actionable Software Supply Chain Security

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Software supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole. François is a senior product security engineer for Boost Security, where he leads the supply chain research team. With over 10 years of experience in building AppSec programs for large corporations such as Intel and small startups, he's been in the heat of the action as the DevSecOps movement took shape. François is one of the founders of NorthSec and was a challenge designer for the NorthSec CTF.The Application Security Podcast is brought to you by Security Journey.About Security JourneyFrançois is a senior product security engineer for Boost Security, where he leads the supply chain research team.→ Learn more about Security JourneyConnect with François Proulx:→ François Proulx on LinkedIn→ deps.devMentioned in this episode:→ deps.dev→ Sigstore→ OpenSSF Scorecard→ SLSA→ Attack Trees (Schneier)→ Let's Encrypt→ OpenSSF→ Terraform→ OpenID Connect→ Brook S.E. Schoenfield→ Jonathan MarcilFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet François Proulx: Actionable Software Supply Chain Security02:18 I do, definitely. Okay. I was going to trademark it, but12:20 I think about the complexity of the modern software supply chain18:57 Okay. So, what are some of the lessons25:36 Continuing on the ATT&CK tree perspective, I'm going to kind of27:51 Okay. Thanks. Yeah, that was helpful to kind of, as I'm33:20 Could we or should we create the same thing for the39:46 François, we're coming to the end of our conversation, and I

Episode metadata supplied by the publisher feed · Published Jun 22, 2023

Embed this episode

Software supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole. François is a senior product security engineer for Boost Security, where he leads the supply chain research team. With over 10 years of experience in building AppSec programs for large corporations such as Intel and small startups, he's been in the heat of the action as the DevSecOps movement took sh...

Distinct summary based on available episode metadata or transcript content.

Ready to play

François Proulx -- Actionable Software Supply Chain Security

0:00 42:04

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 42 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 22, 2023.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!