Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I don't think people are quite grasping the issue with software supply chain attacks.

I don't think people are quite grasping the issue with software supply chain attacks.

Scheduled Pinned Locked Moved Uncategorized
6 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • xssfox@cloudisland.nzX This user is from outside of this forum
    xssfox@cloudisland.nzX This user is from outside of this forum
    xssfox@cloudisland.nz
    wrote last edited by
    #1

    I don't think people are quite grasping the issue with software supply chain attacks. It's not just a case of compromised built software, it's also the build time. One popular package being compromised means every other package that depends on it is also now potential compromised or soon to be. And the targets can often move across other repos in the same org or account

    Basically a slow moving worm today is rapidly accelerating to collapse. Kessler syndrome of software packages.

    xssfox@cloudisland.nzX itgrrl@infosec.exchangeI 2 Replies Last reply
    1
    0
    • xssfox@cloudisland.nzX xssfox@cloudisland.nz

      I don't think people are quite grasping the issue with software supply chain attacks. It's not just a case of compromised built software, it's also the build time. One popular package being compromised means every other package that depends on it is also now potential compromised or soon to be. And the targets can often move across other repos in the same org or account

      Basically a slow moving worm today is rapidly accelerating to collapse. Kessler syndrome of software packages.

      xssfox@cloudisland.nzX This user is from outside of this forum
      xssfox@cloudisland.nzX This user is from outside of this forum
      xssfox@cloudisland.nz
      wrote last edited by
      #2

      Even if you ci/cd is version pinned/locked to not get owned, did any of your developers pull down the new version while trying to fix an unrelated dependency issue?

      What about third party software that vendors in packages?

      xssfox@cloudisland.nzX 1 Reply Last reply
      0
      • xssfox@cloudisland.nzX xssfox@cloudisland.nz

        Even if you ci/cd is version pinned/locked to not get owned, did any of your developers pull down the new version while trying to fix an unrelated dependency issue?

        What about third party software that vendors in packages?

        xssfox@cloudisland.nzX This user is from outside of this forum
        xssfox@cloudisland.nzX This user is from outside of this forum
        xssfox@cloudisland.nz
        wrote last edited by
        #3

        (btw, most vulnerability scanning software isn't magic, it requires lock files, dpkg files or other data to work out what's installed. If you are using cut down builds, distroless and what not, most of these tools will not work and you cannot truly rely on them)

        1 Reply Last reply
        0
        • xssfox@cloudisland.nzX xssfox@cloudisland.nz

          I don't think people are quite grasping the issue with software supply chain attacks. It's not just a case of compromised built software, it's also the build time. One popular package being compromised means every other package that depends on it is also now potential compromised or soon to be. And the targets can often move across other repos in the same org or account

          Basically a slow moving worm today is rapidly accelerating to collapse. Kessler syndrome of software packages.

          itgrrl@infosec.exchangeI This user is from outside of this forum
          itgrrl@infosec.exchangeI This user is from outside of this forum
          itgrrl@infosec.exchange
          wrote last edited by
          #4

          @xssfox 💯

          but also… 👇 ✨😜✨

          1 Reply Last reply
          0
          • xssfox@cloudisland.nzX This user is from outside of this forum
            xssfox@cloudisland.nzX This user is from outside of this forum
            xssfox@cloudisland.nz
            wrote last edited by
            #5

            @krishean

            pros: vendor responsibility
            cons: vendor responsibility

            1 Reply Last reply
            0
            • itgrrl@infosec.exchangeI This user is from outside of this forum
              itgrrl@infosec.exchangeI This user is from outside of this forum
              itgrrl@infosec.exchange
              wrote last edited by
              #6

              @krishean @xssfox

              1 Reply Last reply
              0
              • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups