Software Signing for Kubernetes Supply Chain & Everybody Else

Software Signing for Kubernetes Supply Chain & Everybody Else

In this episode of the Virtual Coffee with Ashish edition, we spoke with Luke Hinds (Luke's Twitter) the open source Sigstore project and how it is helping with software signing and protecting the software supply chain

Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv

Host Twitter: Ashish Rajan (@hashishrajan)

Guest Twitter: Luke Hinds (Luke's Twitter)

Podcast Twitter - @CloudSecPod @CloudSecureNews

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- Cloud Security News

- Cloud Security Academy

Spotify TimeStamp for Interview Questions

(00:00) Ashish's Intro to the Episode

(01:39) https://snyk.io/csp

(05:21) What is the software supply chain and why is it important?

(08:20) Common supply chain attacks in Kubernetes

(09:53) Codecov attack

(11:14 )Kubernetes and API

(14:10) Vulnerability scanning tools

(16:38) Explaining the importance of supply chain security

(19:19) What is a signing service

(19:56 )The SLSA framework

(20:42) Importance of signing service

(23:35) What is Sigstore?

(27:57) What is Lets Encrypt

(31:48) The aim of sigstore

(34:39) What is Co-Sign

(36:40) Co-Signing and non-repudiation

(46:29) Where to start

Jaksot(345)

Cloud Security Careers: Threat Analyst Skills

Cloud Security Careers: Threat Analyst Skills

In this episode of the Virtual Coffee with Ashish edition, we spoke with Abisola Dayspring Johnson aka Day (@CyberwoxAcademy) is a Threat Analyst at Optiv (@Optiv) and the Founder of Cyberwox Academy ...

24 Syys 202141min

Vulnerabilities in AWS, GCP and Azure - Cloud Security News

Vulnerabilities in AWS, GCP and Azure - Cloud Security News

Cloud Security News this week - 22 September 2021 AWS, Google Cloud and Azure have all been busy last few weeks fixing and patching Vulnerabilities. In addition to Azure's OMIGOD flaws which we cove...

22 Syys 20212min

Cloud Security Careers: From University to Security Engineer at Atlassian

Cloud Security Careers: From University to Security Engineer at Atlassian

In this episode of the Virtual Coffee with Ashish edition, we spoke with Kaif Ahsan (@KaifAhsan1) is a Security Engineer at Atlassian (@Atlassian). Episode ShowNotes, Links and Transcript on Cloud Sec...

19 Syys 202146min

Cloud Security Careers: Getting an Entry Level GRC Role

Cloud Security Careers: Getting an Entry Level GRC Role

In this episode of the Virtual Coffee with Ashish edition, we spoke with Gerald Auger (@Linkedin- Gerald Auger) is a CyberSecurity PhD holder, Content Creator at Simply Cyber(@SimplyCyber) and a Cyber...

15 Syys 202145min

fwd:cloudsec conference this week, Vulnerabilities discovered in AWS  - Cloud Security News

fwd:cloudsec conference this week, Vulnerabilities discovered in AWS - Cloud Security News

Cloud Security News this week - 15 September 2021 Oracle Chief Technology Officer and co-founder Larry Ellison told their investors this week that Oracle Cloud is superior to AWS when it comes to s...

15 Syys 20213min

Cloud Security Careers: From Executive Assistant to Head of Security

Cloud Security Careers: From Executive Assistant to Head of Security

In this episode of the Virtual Coffee with Ashish edition, we spoke with Lisa Hall (@Lisa_H_), the Head of Security, PagerDuty(@PagerDuty). Episode ShowNotes, Links and Transcript on Cloud Security Po...

12 Syys 202144min

IBM Launches Servers for Hybrid Cloud, Microsoft and Verizon bring 5G Edge Cloud Computing - Cloud Security News

IBM Launches Servers for Hybrid Cloud, Microsoft and Verizon bring 5G Edge Cloud Computing - Cloud Security News

Cloud Security News this week - 8 September 2021 Verizon, a multinational telecommunications giant and Microsoft have teamed up to bring on-prem, private 5G edge cloud computing to business. Their o...

8 Syys 20212min

Cloud Security Careers: Skills Required for an Associate Cloud Security Engineer

Cloud Security Careers: Skills Required for an Associate Cloud Security Engineer

In this episode of the Virtual Coffee with Ashish edition, we spoke with Zinet Kemal (Linkedin - Zinet-Kemal) is an Associate Cloud Security Engineer at Best Buy (@BestBuy) Episode ShowNotes, Links an...

5 Syys 202146min