TIL @ConEdison doesn't validate that someone has authorization to request to stop service at an address. Someone was able to request that power be cut off to my house, have it back dated to April and not even have the right account number.
Supply Chain Security Person
New York
Joined December 2008
- I know everyone wants to work on the cool thing or save/make a ton of money by throwing AI at a problem but it's extraordinarily dangerous. How many folks are verifying that the provenance and that the code/training data isn't malicious or vulnerable?Model storage under attack (techcrunch.com/2024/05/31/hug…). Models are uninspectable, so the only solution to prevent tampering is to sign them. OpenSSF has a model signing SIG as part of the AI/ML WG. Both biweekly meetings are in the OpenSSF calendar. Also, github.com/sigstore/model…
- Software Supply Chain Security with Michael Lieberman Michael Lieberman is the Co-Founder and CTO of Kusari and has an extensive background in software security. Michael joins the show today to talk about challenges and strategies in software supply chain security.
- I’m out in Tokyo for talks at @openssf day and @linuxfoundation open source summit Japan. For folks who want to chat cybersecurity and GUAC hit me up.



