38 karma · joined July 7, 2022
Upon conclusion of #DEFCON 31, the source code will be made available for anyone who wants to modify and upgrade their very own copy of flight history.
All proceeds will go towards supporting our mission to build an inclusive community & promote knowledge.
As attackers increase their sophistication, our defensive technologies for software signing must grow more sophisticated as well. This post focused primarily on the Android ecosystem in light of recent events, but the lessons learned apply to all systems for distributing software securely, including the internal software supply chain of any organization.
To protect yourself, it’s best to use tools with these principles built-in. For instance, Sigstore has transparency as a fundamental component, and uses TUF to manage its own root of trust, ensuring that if the worst were to happen, the project can safely recover.
The availability of Chainguard Enforce on AWS Marketplace makes it easier for existing AWS customers, software developers, enterprises and small and mid-sized businesses (SMB) to discover, purchase and deploy Chainguard Enforce in their existing AWS account.