
SE Radio 606: Charlie Jones on Third-Party Software Supply Chain Risks
Software Engineering Radio - the podcast for professional software developers
00:00
Securing Software in the Supply Chain: Lessons Learned and Best Practices
The chapter presents a case study on a supply chain attack at software publisher 3CX due to unauthorized software, emphasizing the need for rigorous testing and security measures. It explores the risks of cascading attackers compromising widespread software, discusses the NIST secure software development framework, and advocates for a shift from vulnerability detection to identifying malicious components. The challenges of patching, including the log4j incident, are examined, highlighting the need for comprehensive security protocols beyond celebrity vulnerabilities.
Transcript
Play full episode