
Aaron Davis — LavaMoat — solving JavaScript software supply chain
Om avsnittet
Aaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet. He introduces us to LavaMoat, an approach to solving javascript software supply chain security for node and the browser. The LavaMoat runtime prevents modifying JavaScript's primordials, limits access to the platform API, and prevents packages from corrupting other packages. We hope you enjoy this conversation with... Aaron Davis.
Connect with Aaron “kumavis” Davis:
→ Aaron “kumavis” Davis on GitHub
→ LavaMoat
Mentioned in this episode:
→ LavaMoat
→ MetaMask
→ npm event-stream incident
→ Snyk
→ Node.js
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Aaron “kumavis” Davis
02:10 Aaron’s security origin story
03:29 Security lessons from building MetaMask
05:20 Why tackle the JavaScript supply chain?
09:06 The problem reaches beyond JavaScript
10:40 Malicious updates and compromised maintainers
12:47 The hidden scale of transitive dependencies
14:52 Open source economics and critical packages
18:42 Is LavaMoat a firewall for JavaScript?
20:22 Could browsers make LavaMoat obsolete?
22:35 Runtime performance costs
25:11 Threat modeling LavaMoat itself
28:36 Static analysis and policy generation
30:07 Understanding LavaMoat policy files
33:01 Using LavaMoat in complex applications
37:36 How to get involved
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.