Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

You Can Sign It, But Can You Trust It? - Securing the Compilation Process

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the critical security challenges in software compilation processes and discover innovative solutions for establishing trust in build environments through this 18-minute conference talk. Learn about the vulnerabilities in modern software stacks where compilers operate on complex, interdependent layers that make it difficult to verify every component's integrity during builds. Understand how existing CNCF projects like in-toto and Sigstore secure upper supply chain layers but leave gaps in verifying the complete underlying OS stack integrity. Examine real-world attack scenarios like SolarWinds (2020) that demonstrate the urgent need for stronger compilation process security. Discover a proposed solution that rethinks trust establishment in software builds through build environment verifiability, utilizing SGX enclaves to enclose the entire compilation process within a non-interactive secure environment and leveraging in-toto attestation to ensure verifiable builds. Gain insights into how this approach can enhance security within the CNCF ecosystem and address the fundamental challenges of securing deeply layered and interdependent software stacks.

Syllabus

You Can Sign It, But Can You Trust It? Securing the Compilation Process - Yaxuan(Alice) Wen

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of You Can Sign It, But Can You Trust It? - Securing the Compilation Process

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.