WeHackPurple Podcast

Chat with Tanya Janca

2023/02/09

AI Generated Summary

AI Generated Content Disclaimer

Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.

This podcast interview from WeHackPurple features Anant Shrivastava discussing supply chain security, DevSecOps, Android security, and his open source projects.

Guest Background

Key Topics Discussed

Supply Chain Security:

Definition:

Real-World Examples:

Package Sources and Dependencies:

The Package Problem:

Container Complexity:

Trust and Zero Trust:

Dependency Hell:

Software Composition Analysis (SCA):

Asset Inventory:

Asset Inventory Story (2010-2012):

Dev vs Ops:

Traditional Waterfall Model:

Operations Aspect:

Dev vs Ops Disagreements:

Startup vs Corporate:

Android Security:

Key Mental Shift:

Hostile Environment:

Infosec Community Problem:

Mobile Device Security Model:

Complexity:

Middleware Frameworks:

Advice:

Open Source Projects:

Tamer Platform:

Code Vigilant:

Hacking Archives of India:

Cultural Aspect:

Key Insights:

Actionable Takeaways:

  1. Don’t store data you don’t want to protect
  2. Supply chain includes everything - every software, every environment
  3. Package sources are varied - accountability is on you
  4. Reduce dependencies where you don’t actually need to depend
  5. Asset inventory is crucial - you can’t protect what you don’t know
  6. DevSecOps: Term that should never have existed but exists
  7. Mobile apps: No trusted end, hostile environment, validate everything
  8. If you don’t keep the data, you don’t have to worry about it
  9. Don’t idolize people - everyone is doing their own journey
  10. It’s okay to say you don’t know - what’s not okay is still saying you don’t know after 6 months

Contact Information: