The Shifting Privacy Left Podcast

S2E14: Addressing Privacy with Static Analysis Techniques Like ‘Taint-Tracking’ & ‘Data Flow Analysis’ with Suchakra Sharma (Privado.ai)


Listen Later

This week, we welcome Suchakra Sharma, Chief Scientist at Privado.ai, where he builds code analysis tools for data privacy & security. Previously, he earned his PhD in Computer Engineering from Polytechnique Montreal, where he worked on eBPF Technology and hardware-assisted tracing techniques for OS Analysis. In this conversation, we delve into Suchakra’s background in shifting left for security and how he applies traditional, tested static analysis techniques — such as 'taint tracking' and 'data flow analysis' — for use on large code bases at scale to help fix privacy leaks right at the source.

---------
Thank you to our sponsor, Privado, the developer friendly privacy platform.
---------

Suchakra aligns himself with the philosophical aspects of privacy and wishes to work on anything that helps in limiting the erosion of privacy in modern society, since privacy is fundamental to all of us. These kinds of needs have always been here, and as societies have advanced, this is a time when we require more guarantees of privacy. After all, it is humans that are behind systems and it is humans that are going to be affected by the machines that we build. Check out this fascinating discussion on how to shift privacy left in your organization.

Topics Covered:

  • Why Suchakra was interested in privacy after focusing on static code analysis for security
  • What 'shift left' means and lessons learned from the 'shift security left' movement that can be applied to 'shift privacy left' efforts
  • Sociological perspectives on how humans developed a need for keeping things 'private' from others
  • How to provide engineering-focused guarantees around privacy today & what the role should be of engineers within this 'shift privacy left' paradigm
  • Suchakra's USENIX Enigma talk & discussion of 'taint tracking' & 'data flow analysis' techniques
  • Which companies should build in-house tooling for static analysis, and which should be outsourcing to experienced vendors like Privado
  • How to address 'privacy bugs' in code; why it's important to have an 'auditor's mindset;' &, why we'll see 'Privacy Bug Bounty Programs' soon
  • Suchakra's advice to engineering managers to move the needle on privacy in their orgs

Resources Mentioned:

  • Join Privado's Slack Community
  • Review Privado's Open Source Code Scanning Tools

Guest Info:

  • Connect with Suchakra on LinkedIn

Send us a text



Privado.ai
Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans.

Shifting Privacy Left Media
Where privacy engineers gather, share, & learn

Buzzsprout - Launch your podcast


Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.

Copyright © 2022 - 2024 Principled LLC. All rights reserved.

...more
View all episodesView all episodes
Download on the App Store

The Shifting Privacy Left PodcastBy Debra J. Farber (Shifting Privacy Left)

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

17 ratings


More shows like The Shifting Privacy Left Podcast

View all
The Lawfare Podcast by The Lawfare Institute

The Lawfare Podcast

6,278 Listeners

The Digiday Podcast by Digiday

The Digiday Podcast

103 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,010 Listeners

DataFramed by DataCamp

DataFramed

269 Listeners

AHLA's Speaking of Health Law by American Health Law Association

AHLA's Speaking of Health Law

28 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

142 Listeners

Practical AI by Practical AI LLC

Practical AI

193 Listeners

Our Curious Amalgam by American Bar Association

Our Curious Amalgam

42 Listeners

Serious Privacy by Dr. K Royal, Paul Breitbarth & Ralph O'Brien

Serious Privacy

24 Listeners

POLITICO Tech by POLITICO

POLITICO Tech

391 Listeners

Privacy Please by Cameron Ivey

Privacy Please

28 Listeners

Surveillance Report by Techlore & The New Oil

Surveillance Report

89 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

The Privacy Corner by Robert Bateman

The Privacy Corner

1 Listeners

The AI Fundamentalists by Dr. Andrew Clark & Sid Mangalik

The AI Fundamentalists

9 Listeners