
DOP 277: Making Security Tooling Easy for Developers
Source: YouTube · DevOps Paradox · published Aug 21, 2024 · 44:49
Luke Hines discusses Sigstore, a project making cryptographic software signing accessible to improve supply chain security without hindering productivity 3:05-3:15.
Key Takeaways:
• Sigstore replaces cumbersome GPG with user-friendly provenance verification 3:05-3:30.
• Donated to Linux Foundation and OpenSSF for neutrality, following Let's Encrypt model 10:30-10:50.
• Community SREs maintain the infrastructure, sponsored by their employers 17:45-18:10.
• Sigstore provides machine-level trust but can't prevent all human trust-based attacks 26:19-26:58.
Security tools must be intuitive to achieve better software integrity.
Sources:
- 3:05-3:30 Sigstore's goal to replace GPG
- 10:30-10:50 Donation to Linux Foundation
- 17:45-18:10 Community SREs and sponsorship
- 26:19-26:58 Limitations of machine-level trust
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
if you make security tool in easy and accessible to adopt developers will adopt it so developers do want to do the right thing but they don't want it to be a protracted long difficult cumbersome experience because they want to write code they want to get hacking they want to build things this is devops paradox episode number 277 making security tooling easy for developers welcome to devops paradox this is a podcast about random stuff in which we Darren and Victor pretend we know what we're talking about most of the time we mask our Ignorance by putting the word devops everywhere we can and mix it with random buzzword like kubernetes serverless cicd team productivity islands of happiness and other fancy Expressions that make us sound like we know what we're doing occasionally we invite gues…