InfoQ Homepage Security Content on InfoQ
-
Will Agentic AI Bring Fantasia’s Sorcerer's Apprentice to Life?: A Conversation with Tracy Bannon
In this podcast, Michael Stiefel spoke to Tracy Bannon about the role of artificial intelligence in software and the attendant risks in the areas of security, software development, and society at large. While it might be reasonable to assume a certain amount of trust within a software ecosystem, the risks escalate when the boundary between two software ecosystems is crossed.
-
WebAssembly on the JVM: Feature Evolution, Performance, and the Transition to Endive
Andrea Peruffo discusses the evolution of WebAssembly beyond the browser and its growing role on the server-side JVM. He covers performance advancements in Wasm runtimes, moving from interpreters to efficient JIT compilation, and explores real-world production use cases ranging from edge computing platforms to modular plugin architectures.
-
Spite-Driven Engineering: a New Blueprint for Cloud Security in the AI Native Era
In this episode, Alex Zenla (CTO/co-founder, Edera) challenges the "laissez-faire" attitude toward modern infrastructure. She promotes "spite-driven development", building software to solve genuine technical pain points rather than passively accepting flawed abstractions, as a philosophy of improving the world of software.
-
How eBPF Empowers Developers to Observe inside the Linux Kernel in a Safe and Unintrusive Way
Daniel Finneran explores how eBPF has evolved far beyond its roots in packet filtering into a robust, safe way to extend the Linux kernel. He explains how the eBPF "verifier", the security guardrail, enables implementation of deep observability and networking without the risks of traditional kernel modules or the slow upstreaming process.
-
How SBOMs and Engineering Discipline Can Help You Avoid Trivy’s Compromise
Viktor Peterson, part of the CISA task force working on SBOM blueprints and co-founder of sbomify, explores the shifting landscape of software supply chain security as the EU's Cyber Resilience Act (CRA) comes into force, a "GDPR moment" for the industry.
-
Investing in Open Source: The Open Source Pledge and Why it Matters
In this podcast, Shane Hastie, Lead Editor for Culture & Methods, spoke to Chad Whitacre about the Open Source Pledge, an initiative to encourage companies to financially support open-source maintainers to ensure the sustainability and security of the software they depend on. The goal is to address the social contract within open source, where companies benefit from freely available software.
-
Spies, Lies, and Cybercrime: Insider Perspectives from a Former FBI Agent
In this podcast Shane Hastie, Lead Editor for Culture & Methods spoke to Former FBI Operative Eric O’Neill about the growing threat of cyberattacks, cyber espionage and cybercrime, and how organizations and individuals can "think like a spy hunter" to better protect themselves.
-
The Ongoing Challenges of DevSecOps Transformation and Improving Developer Experience
In this podcast Shane Hastie, Lead Editor for Culture & Methods, spoke to Adam Kentosh about the ongoing challenges organisations face in their DevOps, DevSecOps and digital transformation journeys.
-
Crisis Management, Black Swans and Resilience
In this podcast Shane Hastie, Lead Editor for Culture & Methods spoke to Sharon Robson about crisis management and business resilience, particularly in the context of technology and software supply chains.
-
Data Privacy, Retention and Security Challenges and Opportunities
In this podcast Shane Hastie, Lead Editor for Culture & Methods spoke to Shiva Nathan about data security, privacy, retention and enabling a security mindset in development.