CyberWire Daily

Proxy wars and open doors.

Jan 29, 2026
Tom Pace, CEO of NetRise and former DOE cyber analyst, explains why knowing who maintains open-source code matters. He discusses open-source provenance risks and how visibility into maintainers can close doors for nation-states. Short takes cover supply chain flaws, targeted phishing via Signal, and covert operations against influence networks.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Provenance Matters As Much As Hardware

  • Knowing the provenance of open-source components is now as critical as traditional supply-chain concerns.
  • Tom Pace warns that unknown risks in OSS can hide in plain sight and affect national security.
ANECDOTE

Real Examples Highlight OSS Risk

  • Tom Pace cites XZutils as a near-miss example where open-source issues were caught late.
  • He also noted a Russia-based sole maintainer that raised provenance concerns flagged to the National Cyber Director.
INSIGHT

Frameworks Need Data, Not Assumptions

  • Compliance frameworks without real data produce poor security outcomes.
  • Tom Pace cautions against building policy on assumptions instead of measured analysis.
Get the Snipd Podcast app to discover more snips from this episode
Get the app