It may take decade to shore up software supply chain security, says infosec CEO
- Reference: 1714757415
- News link: https://www.theregister.co.uk/2024/05/03/it_might_take_a_decade/
- Source link:
"The numbers are going to go from 80 to 90 percent to maybe 95, 98, 99 percent of your code in an enterprise environment would be written from basically untrusted, unvetted sources," Badhwar, referring to the proliferation of open-source software packages, told us. "The software supply chain is going to be the next frontier of cybersecurity and cybersecurity attacks."
Getting around those sorts of problems is going to require good documentation, Badhwar told us, which he said includes reliable software bills of material and better vetting of open-source libraries. You can watch the full video below.
[1]
[2]Youtube Video
[3]
Badhwar, whose company sells SSC management automation products, naturally believes automation is the solution for better software supply chain management, but even still he told us good software isn't the sole solution.
"Malicious code does not pop up as a CVE or of known vulnerability in your vulnerability database," Badhwar added. So, what's an enterprise to do? "You need to go back and retool your entire organization looking at the top risks around open source," Badhwar advises.
[4]
But lest you think that's all we have to do to better protect ourselves from software supply chain exploits, we're nowhere near a stable SSC yet.
"In baseball analogy, we're probably in the first or second innings of this, and we still have a long way to go," Badhwar told us. It could be as long as a decade for us to get this whole mess under control.
You can watch our full interview above. ®
Get our [5]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjVefLen6HtsE7YV8LZkHQAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://youtu.be/RepgvXhXG4k
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjVefLen6HtsE7YV8LZkHQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjVefLen6HtsE7YV8LZkHQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://whitepapers.theregister.com/
Re: Always releveant article
We need a lot of discussions about cybersecurity prevention but just talking about "solutions" is only a discussion ... so many discussions everywhere sound wonderful but then we discover problems when we implement our "solutions" ... it's a bit like talking about how we can get to the top of Mount Everest; do we need to ride a bike, ski up there, drive a Tesla, or maybe even walk?
I'm not complaining, this is just the software environment that we've all lived with for years now - We have to describe a problem, wait for a solution, install an upgrade and then see a few new problems so we buy a new computer but starting seeing a few problems again that may have evolved from the original infections. We all want easy access on the Internet but thinking about how nice it is for us normally means that we often don't realize that easy access has become the wide problem. For years now I've been thinking that we need an icon for our security discussions - a pair of wire cutters - LOL El Reg , this is me laughing about the icons every time, this icon choice is so much better!
A decade to get it fixed? I admire the optimism but I don't think I can share in it.
Always releveant article
https://medium.com/@antweiss/learned-helplessness-in-software-engineering-648527b32e27