Securing the Software Supply Chain: How in-toto and TUF Work Together to Combat Supply Chain Attacks

QCon New York 2023

Session Software Supply Chain Security

Securing the Software Supply Chain: How in-toto and TUF Work Together to Combat Supply Chain Attacks

Tuesday Jun 13 / 05:25PM EDT, Dumbo / Navy Yard

Abstract

Software supply chain attacks have seen a 742% increase in the last three years. in-toto is a battle-tested and broadly deployed CNCF incubated project that counters these threats. The framework connects security efforts such as SLSA, Sigstore, and SBOMs, where signed and verifiable in-toto attestations are used to express claims about software supply chain steps and artifacts. However, trusting attestations and their policies is predicated on bootstrapping their verification keys and securely distributing them to end users.

Enter TUF! The Update Framework (TUF) is a widely adopted CNCF graduated project used to secure software repositories. TUF protects against a range of subtle attacks on software distribution, and is designed to be secure even when some components of the system are compromised. TUF can be used to unambiguously associate artifacts with their in-toto metadata, thereby bootstrapping trust for attestations. Thus, combining in-toto and TUF provides a secure way to verify end-to-end software supply chain integrity. This talk covers the fundamentals of both in-toto and TUF, discusses how to combine them with a real world case study where Datadog has been using two technologies together for years, and presents new open source tooling that simplifies deploying the two systems together.

Topics

Software Supply Chain Security secure software updates End-to-end software supply chain security
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon New York 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 13 June

10:35 Dumbo / Navy Yard Session WebAssembly Wasm: What is Universal Compute Good For? Sean Isom Senior Engineer @Adobe 11:50 Dumbo / Navy Yard Session Security Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software Billy Lynch, Zack Newman 13:40 Dumbo / Navy Yard Session WebAssembly Build Features Faster With WebAssembly Components Bailey Hayes Director @Cosmonic 14:55 Dumbo / Navy Yard Session jvm Virtual Threads for Lightweight Concurrency and Other JVM Enhancements Ron Pressler Technical Lead OpenJDK's Project Loom @Oracle 16:10 Dumbo / Navy Yard Session Software Supply Chain Security Achieving SLSA Certification with a “Bring-Your-Own-Builder” Framework Asra Ali Software Engineer @Google 17:25 Dumbo / Navy Yard Session Software Supply Chain Security Securing the Software Supply Chain: How in-toto and TUF Work Together to Combat Supply Chain Attacks Marina Moore PhD Candidate @NYU & Tech Lead for CNCF's TAG Security