Loading…
Attending this event?
October 22-23, 2024 | Atlanta, Georgia USA
View More Details & Registration

The Sched app allows you to build your schedule but is separate from your event registration. You must be registered for SOSS Fusion 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Saving Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
Tuesday October 22, 2024 4:10pm - 4:40pm EDT
Most of us trust Git’s security features—signed commits and tags, strict access controls, and robust verification processes—to protect our codebases, even if the Git host is compromised. We rely on practices like ensuring merge commits are signed by trusted authorities, requiring feature branch commits to come from a single user, and having multiple users with appropriate authority levels verify each merge.

But what if I told you that a malicious attacker could still introduce harmful code into a repository, manipulate signed tags, and roll back patches—all without breaking a single signature or triggering any alarms?

In this talk, we will demonstrate how easily an attacker can execute these malicious actions, bypassing all the supposed security measures. You’ll witness firsthand how undetectable these changes can be, highlighting a critical and often overlooked vulnerability in Git.

We will also introduce gittuf, an up-and-coming tool from the OpenSSF project that can mitigate these risks with a decentralized key management permission-based verification system.
Speakers
avatar for Neil Naveen

Neil Naveen

Highschool, Highschool
Neil Naveen is an 9th grader in the US who is passionate about jiu-jitsu, solving Leetcode problems, a book author, and an active contributor to supply chain security projects. https://leetcode.com/neilnaveen/ https://github.com/neilnaveen/
Tuesday October 22, 2024 4:10pm - 4:40pm EDT
Salon 1

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link