EPISODE · Jan 30, 2024 · 41 MIN
Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security
from The Application Security Podcast · host Chris Romeo
Kyle Kelly joins Chris to explore the wild west of software supply chain security. Kyle, author of the CramHacks newsletter, sheds light on the complicated and often misunderstood world of software supply chain security. He brings unique insights into the challenges, issues, and potential solutions in this constantly growing field. From his experiences in sectors like cybersecurity and security research, he adapts a critical perspective on the state of the software supply chain, suggesting it is in a 'dumpster fire' state. We'll dissect that incendiary claim and discuss the influence of open-source policies, the role of GRC, and the importance of build reproducibility. From starters to experts, anyone with even a mild interest in software security and its future will find this conversation enlightening.Connect with Kyle Kelly:→ CramHacks→ Solve for Happy by Mo GawdatMentioned in this episode:→ CramHacks→ Solve for Happy by Mo Gawdat→ Semgrep→ Log4j→ OWASP Dependency-Track→ OpenSSF→ OpenSSF Scorecard→ GitHub Dependabot→ ReversingLabs→ Roblox→ Black HatFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Kyle Kelly: The Dumpster Fire of Software Supply Chain Security04:23 Very cool. Very cool. So let's, let's, uh, engage on this08:27 Yeah, I mean, so when you think about SolarWinds then, and09:39 Yeah, I think at the end of the day, many of11:43 Okay. And so let's come back around to the, to the19:13 I think the reality is nobody actually does. Because it's not23:09 I think that's a good way to get fired as well24:30 Mean, that's a great, it's a great practice. If you have30:11 Yeah. And that, that just, I mean, it gets to the31:39 Yeah. And then you've got like the scorecard, right34:13 Good luck with that. I think you will get zero total37:11 Yeah, I mean, there's, there's some truth to that in the40:14 Alright. How about a key takeaway or a call to action
Embed this episode
What this episode covers
Kyle Kelly joins Chris to explore the wild west of software supply chain security. Kyle, author of the CramHacks newsletter, sheds light on the complicated and often misunderstood world of software supply chain security. He brings unique insights into the challenges, issues, and potential solutions in this constantly growing field. From his experiences in sectors like cybersecurity and security research, he adapts a critical perspective on the state of the software supply chain, suggesting it...
Ready to play
Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.