Black Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOM @HackersOnBoard
Black Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOM  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 3 hours ago
Despite its simplicity, the "software bill of materials" (SBOM) has been met with apathy and hostility, especially in policy circles. Why has this common industrial concept been so unpopular when translated into the information security context, and how can it potentially revolutionize our industry? This talk will shed light onto the policy context of this discussion, and lay out a vision of how members of the security community can win over the naysayers to foster greater transparency.

The US Department of Commerce recently announced a new 'multistakeholder initiative' on software bill of materials. The goal is for software and IoT vendors to share details on the underlying components, libraries, and dependencies with enterprise customers. This transparency can catalyze a more efficient market for security by allowing vendors to signal quality and giving enterprise customers key knowledge—you can't defend what you don't know about.

This transparency creates a new paradigm of shared security responsibilities, where an enterprise customer can have greater insight into what is running on their network. This, in turn, complicates existing relationships between vendor and customer. With this transparency, how can vendors offer assurances that a discovered vulnerability doesn't affect a particular product? How can vendors safeguard trade secrets with an incomplete SBOM, along the lines of "natural and artificial flavorings" on an ingredient list? And lastly, how will this inform the emerging debate over end-of-life in the IoT space, particularly for medical devices and automobiles that have a physical life space beyond their software support model? None of these hurdles are insurmountable, but solutions will require finding common ground. A world where SBOMs are more common can be a more secure world, but we'll need to tackle the newly raised policy issues as well.
Black Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOMBlack Hat USA 2018 - Remotely Attacking System FirmwareBlack Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus EmulatorDEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the WebDEF CON 27 - The Dark Tangent - Closing CeremoniesOver-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla CarsBlack Hat USA 2018 - Outsmarting the Smart CityBlack Hat USA 2018 - Meltdown Basics, Details, ConsequencesBlack Hat USA 2018 - An Attacker Looks at Docker Approaching Multi Container ApplicationsBlack Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social EngineeringDEF CON 27 - albinowax - HTTP Desync Attacks Smashing into the Cell Next DoorDEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant Drive
HackersOnBoard |

Black Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOM

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER