EPISODE · Jun 22, 2023 · 42 MIN
François Proulx -- Actionable Software Supply Chain Security
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Software supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole. François is a senior product security engineer for Boost Security, where he leads the supply chain research team. With over 10 years of experience in building AppSec programs for large corporations such as Intel and small startups, he's been in the heat of the action as the DevSecOps movement took shape. François is one of the founders of NorthSec and was a challenge designer for the NorthSec CTF.The Application Security Podcast is brought to you by Security Journey.About Security JourneyFrançois is a senior product security engineer for Boost Security, where he leads the supply chain research team.→ Learn more about Security JourneyConnect with François Proulx:→ François Proulx on LinkedIn→ deps.devMentioned in this episode:→ deps.dev→ Sigstore→ OpenSSF Scorecard→ SLSA→ Attack Trees (Schneier)→ Let's Encrypt→ OpenSSF→ Terraform→ OpenID Connect→ Brook S.E. Schoenfield→ Jonathan MarcilFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet François Proulx: Actionable Software Supply Chain Security02:18 I do, definitely. Okay. I was going to trademark it, but12:20 I think about the complexity of the modern software supply chain18:57 Okay. So, what are some of the lessons25:36 Continuing on the ATT&CK tree perspective, I'm going to kind of27:51 Okay. Thanks. Yeah, that was helpful to kind of, as I'm33:20 Could we or should we create the same thing for the39:46 François, we're coming to the end of our conversation, and I
Embed this episode
What this episode covers
Software supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole. François is a senior product security engineer for Boost Security, where he leads the supply chain research team. With over 10 years of experience in building AppSec programs for large corporations such as Intel and small startups, he's been in the heat of the action as the DevSecOps movement took sh...
Ready to play
François Proulx -- Actionable Software Supply Chain Security
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.