Speaker
Abstract
Should we trust the code we run in production? Not if a motivated attacker can compromise our system’s complex supply chains. While hardened runtimes and detection can mitigate some zero day attacks, malicious internal threat actors and software implants are much harder to detect. Supply chain security looks to address some of these concerns, but with so many signing options available to us, what do we really care about? Our source code, open source dependencies, CI/CD, built containers, vendor software — or the hardware and operating systems we run on? Securing the whole supply chain is a non-trivial task, and requires consideration at all of these levels.In this talk we:
- Undertake a risk-based threat model of supply chain attacks against our systems
- Compare the open source supply chain security controls available to us
- Examine trusted execution environments and their security properties
- Propose an open source solution for end to end supply chain security
QCon San Francisco 2022 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.
Part of the track
Operating Microservices: Patterns for Success Hosted by Wes Reisz Technical Principal @Thoughtworks, 16-Time QCon Chair, & Creator of The InfoQ PodcastFrom the same track
Tuesday 25 October
10:35 Seacliff D Session Unconference: Microservices Shane Hastie Global Delivery Lead for SoftEd and Lead Editor for Culture & Methods at InfoQ.com What is an unconference? At QCon SF, we’ll have unconferences in most of our tracks. 11:50 Ballroom A Session Microservices Dark Energy, Dark Matter and the Microservices Patterns?! Chris Richardson Creator of microservices.io, Java Champion, & Core Microservices Thoughtleader Dark matter and dark energy are mysterious concepts from astrophysics that are used to explain observations of distant stars and galaxies. 13:40 Ballroom A Session Microservices Orchestration vs Choreography, A Guide To Composing Your Monolith Ian Thomas Software Engineer @Meta, QCon London 2024 PC Chair, Previously Technology Leader @Genesis Global Microservices promise rapid evolution, operational independence, and technological freedom but come with imperceptible drag factors. Left unchecked, this drag leads to distributed balls of mud – hard to operate, evolve and maintain. 14:55 Seacliff ABC Session Microservices [Recording] Overcomplicated Architecture: Scaling Bottleneck Cassandra Shum Technologist | Architect | Ex-Thoughtworks As a digital scale-up continues to gain momentum and grow rapidly, one of the key determining factors of success is how quickly they can evolve their product. The business desires to push features to production as fast as possible and prove value to its customers. 16:10 Pacific DEKJ Session Untrusted Execution: Attacking the Cloud Native Supply Chain Francesco Beltramini Security Engineering Manager @controlplaneio Should we trust the code we run in production? Not if a motivated attacker can compromise our system’s complex supply chains. While hardened runtimes and detection can mitigate some zero day attacks, malicious internal threat actors and software implants are much harder to detect. 17:25 Ballroom A Session Panel: Building Performant Microservice Architectures Chris Richardson, Ian Thomas, Todd Montgomery Microservices improve cognitive load, velocity, isolation, and scalability. They also introduce complexity, increased reliance on the network, observability challenges, and, often, request latency.