Loading…
May 2-4, 2018 - Copenhagen, Denmark
Click Here For Information & Registration
View analytic
Wednesday, May 2 • 14:45 - 15:20
TUF / Notary Project Intro – David Lawrence, Docker, & Justin Cappos, NYU, TUF (Any Skill Level)

Sign up or log in to save this to your schedule and see who's attending!

Feedback form is now closed.
Software distribution and packaging systems are rapidly becoming the weak link in the software lifecycle. This talk provides an accessible overview of two CNCF projects (Notary and TUF), that provide a secure (compromise resilient) mechanism for distributing software.

Notary, which implements the TUF specification, signs and transparently validates metadata to enable the system to recover from the compromise of servers, theft of keys, insider attacks, etc.  Notary / TUF are surprisingly easy to use and are deployed not only across major cloud companies, but a diverse set of adopters, including automobiles.  

WARNING: Attending this talk may cause (justifiable) fear in the software update mechanism on your devices!

Speakers
avatar for Justin Cappos

Justin Cappos

Professor, NYU
Justin Cappos is a professor in the Computer Science and Engineering department at New York University. His research includes the TUF project (which is hosted by the Linux Foundation / CNCF), which provides a compromise-resilient mechanism for the secure distribution of software... Read More →
DL

David Lawrence

Senior Security Engineer, Docker
Lay security developer that has learned a lot of mistakes the hard way. David started off building authentication systems, moved on to encrypted cloud storage for a few years, and is now working on the Security Team at Docker, presently focused on securing software distribution


Wednesday May 2, 2018 14:45 - 15:20
B4-M2+4