
François Proulx -- Actionable Software Supply Chain Security
Om avsnittet
Software supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole. François is a senior product security engineer for Boost Security, where he leads the supply chain research team. With over 10 years of experience in building AppSec programs for large corporations such as Intel and small startups, he's been in the heat of the action as the DevSecOps movement took shape. François is one of the founders of NorthSec and was a challenge designer for the NorthSec CTF.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
François is a senior product security engineer for Boost Security, where he leads the supply chain research team.
→ Learn more about Security Journey
Connect with François Proulx:
→ François Proulx on LinkedIn
→ deps.dev
Mentioned in this episode:
→ deps.dev
→ Sigstore
→ OpenSSF Scorecard
→ SLSA
→ Attack Trees (Schneier)
→ Let's Encrypt
→ OpenSSF
→ Terraform
→ OpenID Connect
→ Brook S.E. Schoenfield
→ Jonathan Marcil
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet François Proulx: Actionable Software Supply Chain Security
02:18 I do, definitely. Okay. I was going to trademark it, but
12:20 I think about the complexity of the modern software supply chain
18:57 Okay. So, what are some of the lessons
25:36 Continuing on the ATT&CK tree perspective, I'm going to kind of
27:51 Okay. Thanks. Yeah, that was helpful to kind of, as I'm
33:20 Could we or should we create the same thing for the
39:46 François, we're coming to the end of our conversation, and I
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.