Resilient Cyber

S3E24: Chinmayi Sharma - Tragedy of the Digital Commons


Listen Later

- First off, tell us a bit about your background, you were a developer prior to focusing on Law. Why the change and do you feel that technical background helps you in your legal and academic career?

- Before we dive into the specifics of the paper and topics, what led you to focus on this issue for research and publication?

- You penned an article about how modern digital infrastructure is built on a "house of cards". Can you elaborate on that?

- Your paper is broken down into several sections, so let's step through those and dissect each area a bit.

- You touch on the unique aspects of OSS from proprietary code and discuss the benefits and also the risks. Can you discuss some of those?

- You claim that OSS should be designated critical infrastructure and arguably under areas such as the IT Sector. First off, why do you think it should be, and why do you think it already hasn't been?

- In part II of your paper you went into topics around the origins of OSS security issues and barriers to resolution. What are some of the major issues and barriers to resolving them?

- You touch on economic theory such as the least-cost avoider. What exactly is that, and why do you think software vendors in this case are best-suited to fix some of the core OSS security issues?

- In part III of the paper you discuss some of the current interventions and efforts. Can you touch on what some of those major efforts are?

- You discuss emerging things such as the Open Source Software Security Act as well as the OMB Memo requiring vendors to self-attest to NIST's SSDF and even provide SBOM's. What are your thoughts on these emerging requirements?

- How do you think we balance the need to keep the spirit of OSS, in terms of being open to everyone, cultivate a society of citizen developers and a thriving FOSS ecosystem while also pushing for more rigor and governance? 

Do we risk constraining the ecosystem and limiting the Federal government (and industry's) access to small innovative software projects and initiatives? 

...more
View all episodesView all episodes
Download on the App Store

Resilient CyberBy Chris Hughes

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

15 ratings


More shows like Resilient Cyber

View all
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

627 Listeners

The Cloudcast by Massive Studios

The Cloudcast

152 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,003 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

203 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,875 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

167 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

CISO Tradecraft® by CISO Tradecraft®

CISO Tradecraft®

48 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,306 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

No Priors: Artificial Intelligence | Technology | Startups by Conviction

No Priors: Artificial Intelligence | Technology | Startups

122 Listeners

AI Security Podcast by Kaizenteq Team

AI Security Podcast

4 Listeners

Threat Vector by Palo Alto Networks by Palo Alto Networks and N2K Networks

Threat Vector by Palo Alto Networks

34 Listeners