USENIX Enigma 2023 - Understanding Trust & Security Processes in the Open Source Software Ecosystem

  Рет қаралды 135

USENIX Enigma Conference

USENIX Enigma Conference

Күн бұрын

Understanding Trust and Security Processes in the Open Source Software Ecosystem
Dominik Wermke, CISPA Helmholtz Center for Information Security
Open source software has an important role in our everyday-lives: as foundation, glue, or tooling, open source constitutes many important links in the software supply chain. But the openness of this ecosystem brings unique (security) challenges, including code submissions from unknown entities, limited developer-hours & tooling to review commits or dependencies, and the necessity to vet included open source components. Through the results from interview studies with contributors of open source projects, companies that use open source components, maintainers that distribute their packages on open source packages repos, as well as developers that create reproducible software, we examined the security and trust processes and considerations in the open source supply chain, especially those that are not directly visible on a data level and can only be understood through engagement with the open source community.
During this talk, I will introduce the different aspects and challenges of security and trust in the open source ecosystem to a wider audience, highlight interviews as a collaborative, less harmful approach for open source research that positively engages with the community and creates excitement for academic research, and share practical advice on how to improve security in the software supply chain by enabling stakeholders such as maintainers and contributors.
View the full Enigma 2023 program at www.usenix.org...

Пікірлер
USENIX Enigma 2023 - The Slippery Slope of Cybersecurity Analogies
16:11
USENIX Enigma Conference
Рет қаралды 276
Lazy days…
00:24
Anwar Jibawi
Рет қаралды 8 МЛН
How Many Balloons To Make A Store Fly?
00:22
MrBeast
Рет қаралды 172 МЛН
Farmer narrowly escapes tiger attack
00:20
CTV News
Рет қаралды 13 МЛН
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 34 МЛН
USENIX Enigma 2023 - Protecting Whistleblower Information
20:24
USENIX Enigma Conference
Рет қаралды 60
Recursion 'Super Power' (in Python) - Computerphile
12:18
Computerphile
Рет қаралды 491 М.
USENIX Enigma 2023 - Adventures in Authentication and Authorization
20:52
USENIX Enigma Conference
Рет қаралды 1 М.
So einfach ist Docker
16:14
c't 3003
Рет қаралды 166 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
USENIX Enigma 2023 - Invited Talk: Metric Perversity and Bad Decision-Making
19:05
USENIX Enigma 2023 - Meaningful Hardware Privacy for a Smart and Augmented Future
22:35
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 48 М.
Lazy days…
00:24
Anwar Jibawi
Рет қаралды 8 МЛН