Below the Surface (Audio) - The Supply Chain Security Podcast

The Hidden Risks of Open Source Components - BTS #49


Listen Later

In this episode, Paul Asadorian and Josh Bressers delve into the complexities of open source supply chain security, discussing the prevalence of open source components in modern software, the challenges posed by legacy systems, and the critical importance of vulnerability management. They explore the regulatory landscape surrounding software liability and the need for better tools and practices to ensure secure product development. The conversation highlights the necessity of understanding dependencies and the implications of consumer security in a market driven by features rather than security. In this conversation, Josh Bressers and Paul discuss the importance of Software Bill of Materials (SBOMs) in enhancing supply chain security and vulnerability management. They explore the role of metadata in programming languages like Go and Rust, the challenges of accurately identifying vulnerabilities through CVEs, and the need for better automation in vulnerability detection. The discussion also touches on the potential of AI in identifying vulnerabilities, the introduction of tools like SIFT and GRIPE for generating SBOMs and scanning for vulnerabilities, and the future implications of these technologies in software security.

...more
View all episodesView all episodes
Download on the App Store

Below the Surface (Audio) - The Supply Chain Security PodcastBy Eclypsium

  • 5
  • 5
  • 5
  • 5
  • 5

5

2 ratings


More shows like Below the Surface (Audio) - The Supply Chain Security Podcast

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

228,524 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,004 Listeners

Security Weekly Podcast Network (Audio) by Security Weekly Productions

Security Weekly Podcast Network (Audio)

209 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

265 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

637 Listeners

Destination Linux by TuxDigital Network

Destination Linux

89 Listeners

Smashing Security by Graham Cluley

Smashing Security

322 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,020 Listeners

Three Buddy Problem by Security Conversations

Three Buddy Problem

61 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

586 Listeners

Untitled Linux Show (Audio) by TWiT

Untitled Linux Show (Audio)

1 Listeners