Keynote: Securing Open Source - David A. Wheeler, Director, Open Source Supply Chain Security

preview_player
Показать описание

Keynote: Securing Open Source - David A. Wheeler, Director, Open Source Supply Chain Security, The Linux Foundation

The subversion of SolarWinds’ Orion build system, dependency confusion attacks, and event-stream's subversion make it clear that attackers can successfully attack systems by attacking their supply chains, and attackers have not stopped attacking vulnerabilities in software developed & deployed. This talk will briefly discuss the software supply chain environment, some countermeasures, and some ongoing activities to reduce risks from software vulnerabilities and the software supply chain. The good news is that there are ways to counter such attacks, but they will require changes in how we do software development, selection, and deployment.
Рекомендации по теме