Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

You Can Sign It, But Can You Trust It? - Securing the Compilation Process

OpenSSF via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the critical security challenges in software compilation processes and learn about innovative solutions for establishing trust in build environments. Discover why existing CNCF projects like in-toto and Sigstore, while securing upper supply chain layers, fall short of verifying the integrity of underlying OS stacks, leaving vulnerabilities exposed as demonstrated by attacks like SolarWinds. Examine the complexities of modern software stacks with their deep layers and interdependencies that make comprehensive component verification nearly impossible. Understand a groundbreaking approach that rethinks trust establishment in software builds through build environment verifiability, utilizing SGX enclaves to enclose the entire compilation process within a non-interactive secure environment and leveraging in-toto attestation to ensure verifiable builds. Gain insights into how this security enhancement can strengthen the CNCF ecosystem and protect against sophisticated supply chain attacks targeting the compilation process itself.

Syllabus

You Can Sign It, But Can You Trust It? Securing the Compilation Process - Yaxuan (Alice) Wen, NYU

Taught by

OpenSSF

Reviews

Start your review of You Can Sign It, But Can You Trust It? - Securing the Compilation Process

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.