WeHackPurple Podcast

Chat with Tanya Janca

2023/02/09

AI Generated Summary

This podcast interview from WeHackPurple features Anant Shrivastava discussing supply chain security, DevSecOps, Android security, and his open source projects.

Guest Background

Key Topics Discussed

Supply Chain Security:

Definition:

Real-World Examples:

Package Sources and Dependencies:

The Package Problem:

Container Complexity:

Trust and Zero Trust:

Dependency Hell:

Software Composition Analysis (SCA):

Asset Inventory:

Asset Inventory Story (2010-2012):

Dev vs Ops:

Traditional Waterfall Model:

Operations Aspect:

Dev vs Ops Disagreements:

Startup vs Corporate:

Android Security:

Key Mental Shift:

Hostile Environment:

Infosec Community Problem:

Mobile Device Security Model:

Complexity:

Middleware Frameworks:

Advice:

Open Source Projects:

Tamer Platform:

Code Vigilant:

Hacking Archives of India:

Cultural Aspect:

Key Insights:

Actionable Takeaways:

  1. Don’t store data you don’t want to protect
  2. Supply chain includes everything - every software, every environment
  3. Package sources are varied - accountability is on you
  4. Reduce dependencies where you don’t actually need to depend
  5. Asset inventory is crucial - you can’t protect what you don’t know
  6. DevSecOps: Term that should never have existed but exists
  7. Mobile apps: No trusted end, hostile environment, validate everything
  8. If you don’t keep the data, you don’t have to worry about it
  9. Don’t idolize people - everyone is doing their own journey
  10. It’s okay to say you don’t know - what’s not okay is still saying you don’t know after 6 months

Contact Information: