
Radio and PodcastLive Radio & Podcasts
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security
Guest: Dan Lorenc , Founder / CEO, Chainguard Topics: We just saw a security tool (Trivy) get used to pop an AI infrastructure tool (LiteLLM) to eventually pop end users. Have we reached the point where our security tool...
About This Episode
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security is an episode from Cloud Security Podcast by Google by Anton Chuvakin. Guest: Dan Lorenc , Founder / CEO, Chainguard Topics: We just saw a security tool (Trivy) get use...
This episode belongs to Cloud Security Podcast by Google.
Use the player on this page to stream the episode online.
Published Apr 6, 2026, 27:23 long, audio available.
Questions About This Episode
What is EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security about?
Guest: Dan Lorenc , Founder / CEO, Chainguard Topics: We just saw a security tool (Trivy) get used to pop an AI infrastructure tool (LiteLLM) to eventually pop end users. Have we reached the point where our security tooling is actually our largest unmanaged attack surface? Why now? Software supply chain security had the perennial vibe of "not top concern" for most organizations, right? TeamPCP pushed malicious code to existing GitHub tags. We've been screaming about pinning versions to SHAs for years, but clearly, nobody is listening. Is it time to admit that 'convenience' is the primary enemy of supply chain security? The Axios incident showed a victim compromised in under two minutes. In a world of auto-updating dependencies, is the concept of a human-in-the-loop for software updates officially dead, or do we need to look very hard at version pinning and such? With XZ Utils case, we saw a long-game social engineering attack. Beyond just 'watching npm closely,' what are the realistic architectural safeguards for an org that knows they can't audit every line of an update? We've spent the last three years talking about SBOMs (Software Bill of Materials) like they were a pill for supply chain health. But if the scanner producing the SBOM is the one that's compromised, isn't the SBOM just a signed receipt for your own house being on fire? What is the one practical thing they can do to ensure their CI/CD isn't a credential-exfiltration-as-a-service platform? Resources: Video version North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security EP116 SBOMs: A Step Towards a More Secure Software Supply Chain EP226 AI Supply Chain Security: Old Lessons, New Poisons, and Agentic Dreams EP24 Linking Up The Pieces: Software Supply Chain Security at Google and Beyond Matt Levine blog
Where can I listen to EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security?
You can listen to EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security online on Radio and Podcast. Open the player on this page to stream the available audio.
Which podcast is EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security from?
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security is an episode from Cloud Security Podcast by Google by Anton Chuvakin.
How long is this episode?
This episode is 27:23 long.
When was this episode published?
This episode was published on Apr 6, 2026.
Can I save EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security for later?
Yes. Use the heart button on the episode page to add it to your favorite episodes list.
Are there related episodes from Cloud Security Podcast by Google?
Yes. This page shows related episodes from Cloud Security Podcast by Google when more episodes are available from the podcast feed.
Quick Answers About This Episode
Where can I listen to EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security?
You can listen to EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security on this page when the episode audio is available from the podcast feed.
Which podcast is this episode from?
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security is from Cloud Security Podcast by Google by Anton Chuvakin.
What are the episode details?
Published Apr 6, 2026 and 27:23 long