The Application Security Podcast

François Proulx -- Actionable Software Supply Chain Security

• Chris Romeo and Robert Hurlbut • Season 10 • Episode 13

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 42:04

Software supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole. François is a senior product security engineer for Boost Security, where he leads the supply chain research team. With over 10 years of experience in building AppSec programs for large corporations such as Intel and small startups, he's been in the heat of the action as the DevSecOps movement took shape. François is one of the founders of NorthSec and was a challenge designer for the NorthSec CTF.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
François is a senior product security engineer for Boost Security, where he leads the supply chain research team.
→ Learn more about Security Journey

Connect with François Proulx:
→ François Proulx on LinkedIn
→ deps.dev

Mentioned in this episode:
→ deps.dev
→ Sigstore
→ OpenSSF Scorecard
→ SLSA
→ Attack Trees (Schneier)
→ Let's Encrypt
→ OpenSSF
→ Terraform
→ OpenID Connect
→ Brook S.E. Schoenfield
→ Jonathan Marcil

Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook

Chapters:
00:00 Meet François Proulx: Actionable Software Supply Chain Security
02:18 I do, definitely. Okay. I was going to trademark it, but
12:20 I think about the complexity of the modern software supply chain
18:57 Okay. So, what are some of the lessons
25:36 Continuing on the ATT&CK tree perspective, I'm going to kind of
27:51 Okay. Thanks. Yeah, that was helpful to kind of, as I'm
33:20 Could we or should we create the same thing for the
39:46 François, we're coming to the end of our conversation, and I

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo