October 11, 2021
Los Angeles, California + Virtual
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon North America 2021 - Los Angeles, CA + Virtual and add this Co-Located event to your registration to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Standard Time (PST), UTC -7. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change.

IMPORTANT NOTE: Timing of sessions and room locations are subject to change through Monday, September 13 due to schedule changes that will be made as speakers finalize whether speaking in person or virtually.
Back To Schedule
Monday, October 11 • 11:20am - 11:50am
Whose Sign Is It Anyway? - Marina Moore, NYU & Matthew Riley, Google

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Code signing is the security foundation of the software supply chains we rely on every day. But if you let yourself think about it for too long -- like we have -- it starts to seem weird that we’re so sure a random download won’t steal our credentials or ransom our data just because someone, somewhere happened to choose a very special point on an elliptic curve.

In this talk, we will explore what a digital signature really means -- and what it doesn’t. We’ll look at the implications of policy choices around key handling, what gets signed, and when we call a signature "valid". And we’ll dive so deeply into the very idea of identity that you may begin to question the nature of your reality.


Marina Moore

PhD Candidate, New York University
Marina Moore is a PhD candidate at NYU Tandon’s Secure Systems Lab focusing on secure software updates and software supply chain security. She is a maintainer of TUF, a CNCF graduated project, as well as Uptane, the automotive variant of TUF. She contributed to the updated TAG Security... Read More →
avatar for Matthew Riley

Matthew Riley

Software Engineer, Google
Matt works on Kubernetes security at Google. His previous work has involved various combinations of container infrastructure, platform security, code integrity, and applied cryptography.

Monday October 11, 2021 11:20am - 11:50am PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015