セキュリティアーキテクト・エンジニアであるken5(@ken5scal)が1人で、時にはゲストを招き、セキュリティネタをまったりと話すテック系Podcastです。通勤通学や作業のお供にお楽しみください。 ハッシュタグ:#secure旅団, おたより・アンケート:https://forms.gle/4hJNHn6ZfW5CAza9A

Secure Liaison
Claim This Podcastby Secure旅団
Podcast Overview
セキュリティアーキテクト・エンジニアであるken5(@ken5scal)が1人で、時にはゲストを招き、セキュリティネタをまったりと話すテック系Podcastです。通勤通学や作業のお供にお楽しみください。 ハッシュタグ:#secure旅団, おたより・アンケート:https://forms.gle/4hJNHn6ZfW5CAza9A
Language
🇯🇵
Publishing Since
7/29/2020
1 verified contact email on file for Secure Liaison
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

June 20, 2024
SBOMについてワイワイ話す会
<p>(収録日: 2024/06/06)</p> <p># 感想はSNSでハッシュタグ「#secure旅団 #secureLiaison」や<a href="https://docs.google.com/forms/d/e/1FAIpQLSew7UrL0o5yKXaE7Umd42SWIGAMH-skMx3D4dVth__YBjKubg/viewform">Google Form</a>にいただけると嬉しいです。</p> <p># 内容</p> <ul> <li>@EurekaBerryさん登場</li> <li>ひとくちPKI</li> <li>2020年近くのSBOMの概要 - 国家安全保障</li> <li>サプライチェーンとは何を指すのか</li> <li>2010年近くのSBOMの概要 - Component管理、透明性管理</li> <li>本邦におけるSBOMは?</li> <li>各機関におけるSBOM</li> <li>Metiの「ソフトウェア管理に向けたSBOMの導入に関する手引」</li> <li>厚生労働省</li> <li>(米)FDA</li> <li>attestation可能な方法での配布パイプライン</li> <li>2020年におけるニーズの高まりからよりその課題は高まった</li> <li>SLSA, CICD</li> <li>OSSとSBOM</li> <li>PowershellのSBOM</li> <li>まとめ</li> </ul> <p><br></p> <p># 参照</p> <ul> <li>https://whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/</li> <li><a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/">https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/</a></li> <li>https://csrc.nist.gov/glossary/term/sbom</li> <li>https://www.meti.go.jp/press/2024/04/20240426001/20240426001.html</li> <li>EU’s Cyber Resilience Act</li> </ul> <p><br></p> <p>#積ん読</p> <ul> <li>なし</li> </ul> <p># 参加者: @EurekaBerry、@Wireworkes、@ken5scal</p>

April 18, 2024
XZ UtilsのSWサプライチェーンとOSSエコシステムの話
<p>(収録日: 2024/04/14)</p> <p># 感想はSNSでハッシュタグ「#secure旅団 #secureLiaison」や<a href="https://docs.google.com/forms/d/e/1FAIpQLSew7UrL0o5yKXaE7Umd42SWIGAMH-skMx3D4dVth__YBjKubg/viewform" target="_blank" rel="noopener noreferer">Google Form</a>にいただけると嬉しいです。</p> <p># 内容</p> <ul> <li>XZ Utilsに脆弱性が埋め込まれた話</li> </ul> <ul> <li>OSSエコシステムの課題と、それに対する立法的アプローチ、技術的アプローチ等の話</li> </ul> <p><br></p> <p># 参照</p> <p>## 経緯</p> <ul> <li><a href="https://research.swtch.com/xz-timeline" rel="noopener noreferrer">https://research.swtch.com/xz-timeline</a></li> <li><a href="https://www.mail-archive.com/xz-devel@tukaani.org/msg00567.html" rel="noopener noreferrer">https://www.mail-archive.com/xz-devel@tukaani.org/msg00567.html</a> </li> <li>https://techcrunch.com/2024/04/02/open-source-foundations-unite-on-common-standards-for-eus-cybersecurity-resilience-act/</li> </ul> <p><br></p> <p>## CVEそのもの</p> <ul> <li>SIOS: <a href="https://security.sios.jp/vulnerability/xz-security-vulnerability-20240330/">https://security.sios.jp/vulnerability/xz-security-vulnerability-20240330/</a></li> <li>Sysdig: <a href="https://sysdig.com/blog/cve-2024-3094-detecting-the-sshd-backdoor-in-xz-utils/?utm_campaign=Oktopost-2024+Blogs+and+Articles&utm_content=Oktopost-twitter&utm_medium=twitter&utm_source=organic-social&utm_term=Blog%2CThreat+Research%2CVulnerability">https://sysdig.com/blog/cve-2024-3094-detecting-the-sshd-backdoor-in-xz-utils/?utm_campaign=Oktopost-2024+Blogs+and+Articles&utm_content=Oktopost-twitter&utm_medium=twitter&utm_source=organic-social&utm_term=Blog%2CThreat+Research%2CVulnerability</a></li> <li>Ossf: <a href="https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/">https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/</a></li> <li>CISA: <a href="https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094">https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094</a></li> </ul> <p><br></p> <p>## 関連PR</p> <ul> <li>https://github.com/libarchive/libarchive/pull/1609</li> <li>https://gist.github.com/smx-smx/a6112d54777845d389bd7126d6e9f504</li> <li>https://web.archive.org/web/20240329180818/https://github.com/tukaani-project/xz/pull/86</li> </ul> <p>#積ん読</p> <ul> <li>なし</li> </ul> <p># 参加者: 中谷さん、ken5scal</p>

November 12, 2023
CVSSv4.0とかOkta(続)などの話
<p>(収録日: 2023/11/05)</p> <p># 感想はtwitterでハッシュタグ「#secure旅団 #secureLiaison」やGoogle Formにいただけると嬉しいです。</p> <p># 内容</p> <ul> <li>CVSSv4と、今までの脆弱性評価の思い出</li> </ul> <ul> <li>Oktaのインシデントの話(10/30以降に更新された話)。主に公私分離、体制、サービスアカウント</li> </ul> <p># 参照</p> <ul> <li><a href="https://www.first.org/cvss/v4-0/">https://www.first.org/cvss/v4-0/</a></li> <li><a href="https://www.sec.gov/Archives/edgar/data/1739942/000173994223000079/swi-20230623.htm">https://www.sec.gov/Archives/edgar/data/1739942/000173994223000079/swi-20230623.htm</a></li> <li>https://sec.okta.com/harfiles</li> </ul> <p>#積ん読</p> <ul> <li>なし</li> </ul> <p># 参加者: 松本さん(@ym405nm)、名無しさん、ken5scal</p> <p># ジングル: @hajipion</p>
60 total episodes available
Deep-dive analytics for Secure Liaison
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Secure Liaison?
- How often does this podcast release new episodes?
This podcast updates weekly.
- Where can I listen to this podcast?
This podcast is available on 2 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
No, this podcast does not typically feature guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.
