The Changelog: Software Development, Open Source

Securing GitHub (Interview)

Jun 19, 2024
Jacob DePriest, VP and Deputy Chief Security Officer at GitHub, shares insights on securing GitHub and open-source software. He discusses the vital role of Artifact Attestations and the challenges of social engineering in developer security. The conversation covers GitHub's advanced security features, like mandatory two-factor authentication and code scanning, revealing how they bolster the safety of software dependencies. DePriest also highlights the synergy between AI tools and security measures, emphasizing collaborative efforts to navigate security complexities.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Start With The Developer

  • Start with the developer when thinking about open source security.
  • Empower developers and secure their workflow.
ADVICE

Securing Profiles

  • Secure developer profiles on GitHub beyond just preventing takeovers.
  • Consider social engineering aspects and nefarious actions, not just security breaches.
INSIGHT

Insider Threats

  • Social engineering attacks are difficult to detect because it's hard to distinguish between nefarious actions and mistakes.
  • The software ecosystem needs an "insider threat program" like corporations have.
Get the Snipd Podcast app to discover more snips from this episode
Get the app