Jan. 29, 2024, 2:10 a.m. | Taylor R Schorlemmer, Kelechi G Kalu, Luke Chigges, Kyung Myung Ko, Eman Abdul-Muhd Abu Isghair, Saurabh Baghi, Santiago Torres-Arias, James C Davis

cs.CR updates on arXiv.org arxiv.org

Many software applications incorporate open-source third-party packages
distributed by third-party package registries. Guaranteeing authorship along
this supply chain is a challenge. Package maintainers can guarantee package
authorship through software signing. However, it is unclear how common this
practice is, and whether the resulting signatures are created properly. Prior
work has provided raw data on signing practices, but measured single platforms,
did not consider time, and did not provide insight on factors that may
influence signing. We lack a comprehensive, multi-platform …

applications arxiv can challenge distributed guarantee maintainers package packages party practice public quality signatures signing software software applications supply supply chain third third-party

Enterprise Threat Intel Analyst

@ Resource Management Concepts, Inc. | Quantico, Virginia, United States

IT Security Engineer III

@ Mitsubishi Heavy Industries | Houston, TX, US, 77046

Cyber Intelligence Vice President, Threat Intelligence

@ JPMorgan Chase & Co. | Singapore, Singapore

Assistant Manager, Digital Forensics

@ Interpath Advisory | Manchester, England, United Kingdom

Tier 3 - Forensic Analyst, SME

@ Resource Management Concepts, Inc. | Quantico, Virginia, United States

Incident Response, SME

@ Resource Management Concepts, Inc. | Quantico, Virginia, United States