BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//program.foss-backstage.de//fossback23//speaker//LABXMM
BEGIN:VTIMEZONE
TZID:Europe/Berlin
BEGIN:STANDARD
DTSTART:20220313T000000
TZNAME:CET
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20220327T030000
RDATE:20230326T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20221030T030000
RDATE:20231029T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Securing OSS across the whole supply chain and beyond - Nick Vidal
DTSTART;TZID=Europe/Berlin:20230313T160500
DTEND;TZID=Europe/Berlin:20230313T163500
DTSTAMP:20260815T043512Z
UID:pretalx-fossback23-ZMCST7@program.foss-backstage.de
DESCRIPTION:As we celebrate the triumph of open source software on its 25t
 h anniversary\, at the same time we have to acknowledge the great responsi
 bility that its pervasiveness entails. Open source has become a vital comp
 onent of a working society and there's a pressing need to secure it across
  the whole supply chain and beyond. In this session\, we'll take the oppor
 tunity to look at three major advancements in open source security\, from 
 SBOMs and Sigstore to Confidential Computing.\n\nOpen source plays a vital
  role in modern society given its pervasiveness in the Cloud\, mobile devi
 ces\, IoT\, and critical infrastructure. Securing it at every step in the 
 supply chain and beyond is of ultimate importance.\n\nAs we prepare for th
 e "next Log4Shell"\, there are some technologies that are emerging on the 
 horizon\, among which SBOMs\, Sigstore\, and Confidential Computing. In th
 is session\, we'll explore these technologies in detail.\n\nWhile SBOMs (S
 oftware Bill Of Materials) allow developers to track the dependencies of t
 heir software and ensure that they are using secure and reliable packages\
 , Sigstore allows developers to verify the authenticity and integrity of o
 pen source packages\, ensuring that the code has not been tampered with or
  compromised\, \n\nConfidential Computing\, on the other hand\, protects c
 ode and data in use by performing computation in a hardware-based\, attest
 ed Trusted Execution Environment\, ensuring that sensitive code and data c
 annot be accessed or tampered by unauthorized parties\, even if an attacke
 r were to gain access to the computing infrastructure.\n\nSBOMs\, Sigstore
 \, and Confidential Computing provide a powerful combination to address se
 curity concerns and ensure the integrity and safety of open source softwar
 e and data. They focus on “security first\,” rather than perpetuating 
 existing approaches which have typically attempted to bolt on security mea
 sures after development\, or which rely on multiple semi-connected process
 es through the development process to provide marginal improvements to the
  overall security of an application and its deployment.\n\nAs we celebrate
  the 25th anniversary of open source\, these three technologies emerging r
 epresent a step forward on securing OSS across the whole supply chain and 
 beyond. We foresee them playing a key role on minimizing the risk of vulne
 rabilities and protecting software and data against potential attacks\, pr
 oviding greater assurances for society as a whole.
LOCATION:Stage 2
URL:https://program.foss-backstage.de/fossback23/talk/ZMCST7/
END:VEVENT
END:VCALENDAR
