SE Radio 630: Luis Rodríguez on the SSH Backdoor Attack

SE Radio 630: Luis Rodríguez on the SSH Backdoor Attack

Luis Rodríguez, CTO of Xygeni.io, joins host Robert Blumen for a discussion of the recently thwarted attempt to insert a backdoor in the SSH (Secure Shell) daemon. OpenSSH is a popular implementation of the protocol used in major Linux distributions for authentication over a network. Luis describes how a backdoor in a supporting library was recently discovered and removed before the package was published to stable releases of the Linux distros. The conversation explores the mechanism of the attack through modifying a function table in the runtime; how the attack was inserted during the build; how the attack was carefully staged in a series of modifications to the lz compression library; the nature of "Jia Tan," the entity who committed the changes to the open source project; social engineering that the entity used to gain the trust of the open source community; what forensics indicates about the location of the entity; hypotheses about whether criminal or state actors backed the entity; how the attack was detected; implications for other open source projects; why traditional methods for detecting exploits would not have helped find this; and lessons learned by the community.

Brought to you by IEEE Computer Society and IEEE Software magazine.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(740)

SE Radio 735: Vivek Yadav on Regression Testing Microservices

SE Radio 735: Vivek Yadav on Regression Testing Microservices

Vivek Yadav, an engineering manager at the payment company Stripe, speaks with host Adi Narayan about building regression testing for microservices. Drawing on his work estimating network costs for ca...

26 Aug 59min

SE Radio 734: Sathiesh Veera on Engineering Data-Protection Guardrails with LLMs

SE Radio 734: Sathiesh Veera on Engineering Data-Protection Guardrails with LLMs

Sathiesh Veera, a GenAI Solutions Architect at At&T, speaks with host Brijesh Ammanath about the data-protection guardrails required when using LLMs. The core issue is that LLMs sit outside the cloud ...

19 Aug 42min

SE Radio 733: Max Corbridge on Securing AI Agents

SE Radio 733: Max Corbridge on Securing AI Agents

Max Corbridge, an ethical hacker and red teamer who is co-founder and CEO of Secure Agentics, speaks with SE Radio host Amey Ambade about how AI agents get attacked and what engineers can actually do ...

13 Aug 1h

SE Radio 732: Jason Gorman on The Effective Use of AI For Software Development

SE Radio 732: Jason Gorman on The Effective Use of AI For Software Development

Jason Gorman, a software development expert and founder of Codemanship, joins host Giovanni Asproni to explore how best to use AI in software development. They start by considering how established tec...

5 Aug 57min

SE Radio 731: Sonali Varde on AI and the Engineering Manager Role

SE Radio 731: Sonali Varde on AI and the Engineering Manager Role

Sonali Varde, Senior Software Engineering Manager at LinkedIn, joins host Kanchan Shringi to discuss how AI is changing the role of the engineering manager. They explore how AI is showing up in day-to...

29 Juli 50min

SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

Birgitta Boeckeler, a Distinguished Engineer and consultant focused on AI-assisted software delivery at Thoughtworks, joins host Priyanka Raghavan for a deep dive into harnesses for AI agents. The epi...

22 Juli 54min

SE Radio 729: Garth Mollett on AI Supply Chain Security

SE Radio 729: Garth Mollett on AI Supply Chain Security

Garth Mollet, Senior Principal Product Security Engineer and Technical Advisor for Product Security at Red Hat, joins host Robert Blumen for a discussion of AI supply chain security. They start with t...

15 Juli 48min

SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents

SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents

Clare Liguori, a Senior Principal Engineer who works on developer tooling and agentic AI at Amazon Web Services, speaks with host Sri Panyam about the Amazon Strands Agents SDK. This episode explores ...

8 Juli 1h 8min

Populärt inom Utbildning

historiepodden-se
det-skaver
rss-bara-en-till-om-beroende-medberoende
nu-blir-det-historia
harrisons-dramatiska-historia
not-fanny-anymore
rss-viktmedicinpodden
johannes-hansen-podcast
roda-vita-rosen
allt-du-velat-veta
rikatillsammans-om-privatekonomi-rikedom-i-livet
i-vantan-pa-katastrofen
rss-ar-det-rimligt
rss-max-tant-med-max-villman
rss-basta-livet
sa-in-i-sjalen
rss-foraldramotet-bring-lagercrantz
sektledare
rss-traningsklubben
rss-autismandan