Skip to content
Artwork for Firewalls Don't Stop Dragons Podcast
Firewalls Don't Stop Dragons Podcast · August 31 · 1 hr 15 min

Supply Chain Attacks

Software apps today are a hodgepodge of libraries, software development kits, and third party code, all stitched together like Frankenstein’s monster. Furthermore, software developers use common tools to create and deploy this software. The bad guys have figured out that by compromising one of these third party components or the tools used to create the products, they can instantly infect hundreds or thousands of products that all share the same underlying resources. This is a supply chain attack. Today we’ll discuss these single points of failure, how to identify them ahead of time and try to prevent these sorts of attacks with Cassie Crossley, CEO and co-founder of VulNow. Interview Notes Cassie Crossley: https://www.linkedin.com/in/cassiecrossley/ VulNow company website: https://vul.now/ VulNow’s Pre-CVE database: https://precve.vulnow.com/ CyBeats company website: https://www.cybeats.com/ Software Supply Chain Security (book): https://www.oreilly.com/library/view/software-supply-chain/9781098133696/ Proton blog on supply chain security: https://proton.me/business/blog/supply-chain-attack Malus AI re-write tool: https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/ xkcd on Dependency: https://xkcd.com/2347/ Updated dependency diagram: https://www.grc.com/SN/1078.jpg Further Info Phase 2 has begun!! : https://fdsd.me/phase2 Countdown to FDSD500!! https://fdsd500.com Get your FDSD500 merch!! https://fdsd.me/merch My book: https://fdsd.me/book My newsletter: https://fdsd.me/newsletter Support the mission: https://fdsd.me/support Give the gift of privacy and security: https://fdsd.me/coupons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Table of Contents 0:00:14: Intro 0:00:35: Phase 2 reminder 0:01:52: Interview setup 0:06:05: What is VulNow? 0:08:34: What software is vulnerable to supply chain attacks? 0:13:16: Have you heard of AI clean room coding? 0:15:34: How do SW supply chain attacks work? 0:21:21: How do we identify the weak points? 0:34:24: What are SBOM’s and how do they work? 0:43:45: What is needed beyond SBOMs? 0:50:32: Can tools reveal the contents of SW? 0:56:13: How do we encourage SBOM creation? 1:01:35: As consumers, how do we know who to trust? 1:06:09: What’s next for you? 1:08:46: Wrap-up 1:13:23: Patron podcast preview 1:14:19: Looking ahead

0:00 · Intro-1:15:04

transcript

No transcript — this publisher did not publish one.

show notes

Software apps today are a hodgepodge of libraries, software development kits, and third party code, all stitched together like Frankenstein’s monster. Furthermore, software developers use common tools to create and deploy this software. The bad guys have figured out that by compromising one of these third party components or the tools used to create the products, they can instantly infect hundreds or thousands of products that all share the same underlying resources. This is a supply chain attack. Today we’ll discuss these single points of failure, how to identify them ahead of time and try to prevent these sorts of attacks with Cassie Crossley, CEO and co-founder of VulNow.

Interview Notes

Further Info

Table of Contents

  • 0:00:14: Intro
  • 0:00:35: Phase 2 reminder
  • 0:01:52: Interview setup
  • 0:06:05: What is VulNow?
  • 0:08:34: What software is vulnerable to supply chain attacks?
  • 0:13:16: Have you heard of AI clean room coding?
  • 0:15:34: How do SW supply chain attacks work?
  • 0:21:21: How do we identify the weak points?
  • 0:34:24: What are SBOM’s and how do they work?
  • 0:43:45: What is needed beyond SBOMs?
  • 0:50:32: Can tools reveal the contents of SW?
  • 0:56:13: How do we encourage SBOM creation?
  • 1:01:35: As consumers, how do we know who to trust?
  • 1:06:09: What’s next for you?
  • 1:08:46: Wrap-up
  • 1:13:23: Patron podcast preview
  • 1:14:19: Looking ahead
links16

chapters

17 chapters

more episodes

All episodes