ravirockks,

Latest piece of guidance from the NSA and friends on securing the software supply chain has dropped.

This edition is on OSS and SBOMs.
https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3613105/nsa-and-esf-partners-release-recommended-practices-for-managing-open-source-sof/

kkarhan,

@ravirockks I'd be #sus amidst #NSA recommendations, as they've pushed so much #bs and #Govware in the past that they can't be considered a "reliable authority" in that regard...

#PRISM #Speck #DUAL_EC_DRBG

ravirockks,

@kkarhan Let's assume the NSA and friends are Satan incarnate.

What do you make of the actual recommendations in the guidance?

kkarhan,

@ravirockks I've had not read them yet but I'd say that one should always archive dependencies and aim to only have reproducible builds.

Something that I work on OS/1337.

Now granted @os1337 is NOT built with security in mind at all, but that's due to it's specific goals.

But archiving releases and mirroring repos is an important way to keep things secure.

And in high-security envoirments and should be mandatory to the point that only and no are legal.

ravirockks,

@kkarhan Could you clarify why said archiving and mirroring and having reproducible builds is important?

Asking as I don't come from a technical background.

kkarhan,

@ravirockks Because code releases for are pointless if one can't verify the released code is actually what is being released as .

Something was rightfully criticized for back in it's days.

In , noone trusts anyone and thus being able to let everyone see and reproduce code as well as it is vital to security.

Same with on how to build something from source: It's vital to be able to do so for longterm-maintainability.

kkarhan,

@ravirockks Side note: You threaten me and a lot of followers with a good time...

https://infosec.exchange/@ravirockks/111565412133956679

kkarhan,

@ravirockks Needless to say that only with can enshure the is related to the released.

And being able to audit oneself or choose any auditor of choice to do so is also critical to the whole aspect of it.

You don't want people to be able to "pull rank" but instead you want critical code to be looked at with as many eyes as possible.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • normalnudes
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • mdbf
  • InstantRegret
  • JUstTest
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • Leos
  • anitta
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • megavids
  • provamag3
  • tester
  • lostlight
  • All magazines