Keynote: The XZ-Utils Backdoor: A Case Study in Software Supply Chain Security and Social Engineering

No ratings

Presented at SecTor 2024 by

How did social engineering, binary artifacts and sock puppet accounts lead to the (almost) biggest open-source backdoor, ever?This keynote will deconstruct the XZ-Utils backdoor, into its technical and social engineering components. We will also explore security and engineering best practices to thwart future attacks and the societal change that needs to take place in order to ensure future open-source supply chain compromises are less likely.Open to All Pass Holders.