4.8 • 1K Ratings
🗓️ 31 August 2022
⏱️ 25 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | We need a shared vision of what basic software supply chain transparency looks like. |
0:10.0 | Hi and welcome to Cyber Reasons Mal life besides I'm Ren Lett Winston Churchill, who led Britain in World War II is credited with saying never let a good crisis go to waste. |
0:37.2 | I'm pretty sure he wasn't talking about cyber security, but you know great insights into human behavior have a tendency to be relevant across a wide range of different domains. |
0:50.0 | Software Bill of Materials, or SBAN, for short, is an idea that has been floating around for quite a few years. |
0:58.0 | It is inspired by or derived from an established practice in the field of manufacturing, one which was old |
1:06.4 | news even back in the early 2000s when I was an electronics engineer. In hardware, a bill of materials |
1:14.8 | is a list of all the different components and items, |
1:18.5 | from capacitors and resistors to silicon chips |
1:22.1 | included in a product. |
1:24.0 | Our software bill of materials is a very similar idea |
1:28.0 | just for the software side of a system. |
1:31.0 | It is a list or a nested inventory of all open source and third party software components |
1:38.5 | present in a code base. |
1:40.8 | It lists all the versions of these software components, their patch status, and even their licenses. |
1:48.0 | This way, when a new version of a software component is released or a new vulnerability is discovered in some |
1:55.2 | library, developers can easily identify which of their code bases are |
2:00.4 | affected. I think all of us can intuitively grasp how useful such a list could be. |
2:08.0 | A typical electronic board has hundreds, if not thousands of components. But when a vendor announced a recall of a leaky |
2:16.1 | capacitor or a new version of some chip, all I had to do was a simple search in my Excel files to see which of my projects used that |
2:26.4 | capacitor or cheap. Similarly, a big software project can include a large number of |
2:32.4 | third-party libraries, and to make matters worse, each |
2:36.1 | of these libraries can depend upon its own variety of other libraries, and so on and so on and so on and S-bomb can really make life easier |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from Malicious Life, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of Malicious Life and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.