Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security episode artwork

EPISODE · Jan 30, 2024 · 41 MIN

Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security

from The Application Security Podcast · host Chris Romeo

Kyle Kelly joins Chris to explore the wild west of software supply chain security. Kyle, author of the CramHacks newsletter, sheds light on the complicated and often misunderstood world of software supply chain security. He brings unique insights into the challenges, issues, and potential solutions in this constantly growing field. From his experiences in sectors like cybersecurity and security research, he adapts a critical perspective on the state of the software supply chain, suggesting it is in a 'dumpster fire' state. We'll dissect that incendiary claim and discuss the influence of open-source policies, the role of GRC, and the importance of build reproducibility. From starters to experts, anyone with even a mild interest in software security and its future will find this conversation enlightening.Connect with Kyle Kelly:→ CramHacks→ Solve for Happy by Mo GawdatMentioned in this episode:→ CramHacks→ Solve for Happy by Mo Gawdat→ Semgrep→ Log4j→ OWASP Dependency-Track→ OpenSSF→ OpenSSF Scorecard→ GitHub Dependabot→ ReversingLabs→ Roblox→ Black HatFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Kyle Kelly: The Dumpster Fire of Software Supply Chain Security04:23 Very cool. Very cool. So let's, let's, uh, engage on this08:27 Yeah, I mean, so when you think about SolarWinds then, and09:39 Yeah, I think at the end of the day, many of11:43 Okay. And so let's come back around to the, to the19:13 I think the reality is nobody actually does. Because it's not23:09 I think that's a good way to get fired as well24:30 Mean, that's a great, it's a great practice. If you have30:11 Yeah. And that, that just, I mean, it gets to the31:39 Yeah. And then you've got like the scorecard, right34:13 Good luck with that. I think you will get zero total37:11 Yeah, I mean, there's, there's some truth to that in the40:14 Alright. How about a key takeaway or a call to action

Episode metadata supplied by the publisher feed · Published Jan 30, 2024

Embed this episode

Kyle Kelly joins Chris to explore the wild west of software supply chain security. Kyle, author of the CramHacks newsletter, sheds light on the complicated and often misunderstood world of software supply chain security. He brings unique insights into the challenges, issues, and potential solutions in this constantly growing field. From his experiences in sectors like cybersecurity and security research, he adapts a critical perspective on the state of the software supply chain, suggesting it...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security

0:00 41:17

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 41 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 30, 2024.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!