Supply chain security

Open Source Is Dead. Long Live Open Source. — Saoud Rizwan, Cline

Open Source Is Dead. Long Live Open Source. — Saoud Rizwan, Cline

Saoud Rizwan, founder of Cline, discusses how AI has eroded trust in open-source communities, leading projects like Zig and curl to restrict AI-generated contributions and exposing severe supply chain risks, as seen with the litellm compromise. He argues that while community open source is struggling, the economic imperative of "open weights" models is rising. Citing the high costs of closed LLMs and the success of models like GLM at Coinbase, Rizwan draws parallels to the Open Compute project, predicting a commoditization of AI inference. He urges American labs to release open-weights models to maintain technological leadership against foreign competitors and prevent lock-in.

The Great Loops Debate — Dex Horthy, Geoff Huntley, Ian Livingstone, Greg Pstrucha, @insecure-agents

The Great Loops Debate — Dex Horthy, Geoff Huntley, Ian Livingstone, Greg Pstrucha, @insecure-agents

An Oxford-style debate exploring the gap between the hype and practical reality of "loops" in AI/ML development. Experts discuss their history, optimal anatomy, future role in software factories, and challenges like security, economic viability, and the imperative for strong engineering discipline.

The new post-quantum cryptography executive order. Plus: What is Q-Day, really?

The new post-quantum cryptography executive order. Plus: What is Q-Day, really?

This episode delves into Q-Day, the anticipated future when quantum computers can break public key cryptography, and the U.S. Executive Order accelerating the transition to post-quantum cryptography. Experts discuss why Q-Day is a gradual process rather than a sudden event, the critical importance of "crypto-agility" as a long-term strategy, and the necessity for organizations to begin immediate discovery and planning to secure data against "collect now, decrypt later" threats. The discussion also touches upon the broader, transformative benefits of quantum computing beyond just security.

Cloud, Containers & Security • Adrian Mouat, Kief Morris & Sam Newman • GOTO 2025

Cloud, Containers & Security • Adrian Mouat, Kief Morris & Sam Newman • GOTO 2025

In this panel discussion, experts Adrian Mouat, Kief Morris, and Sam Newman delve into the current landscape of cloud technology, container security, and infrastructure automation. They cover key topics such as supply chain security with Sigstore and SBOMs, the practical impact of AI on deterministic systems, the ongoing debate about cloud repatriation, and advanced Infrastructure as Code practices like TDD and managing configuration drift.

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

A detailed breakdown of the updated OWASP Top 10 vulnerabilities for Large Language Models (LLMs), explaining threats like prompt injection, data poisoning, and supply chain risks, along with practical defense strategies.

State of the Art of Container Security • Adrian Mouat & Charles Humble • GOTO 2026

State of the Art of Container Security • Adrian Mouat & Charles Humble • GOTO 2026

Adrian Mouat from Chainguard discusses the evolution of container security, highlighting the flaws of traditional Linux distributions for modern container workflows. He explains how Chainguard's approach of building minimal, 'distroless' images from source using Wolfi addresses the noise from vulnerability scanners, and delves into the importance of SBOMs, attestations, and a 'defense in depth' strategy, contextualized by recent major security incidents like the XZ Utils backdoor and Shai-hulud attacks.