Reflections on Trust in the Software Supply Chain

No ratings

Presented at BlackHat USA 2023 by

This talk delves into the current state of software supply chain security and the challenges organizations face in ensuring the security and trustworthiness of their software. The current efforts to secure the software supply chain, including Supply-chain Levels for Software Artifacts (SLSA), Software Bill of Materials (SBOM), code signing, and the security of the build tool chain, will be critically evaluated. While many of these efforts are key to securing the software supply chain - a demonstration will highlight how some of the current efforts may just be security theater. The talk concludes with a discussion of binary-source validation as a promising solution to enhancing the security of the software supply chain.