colek42c Profile Banner
Cole Kennedy Profile
Cole Kennedy

@colek42c

Followers
544
Following
1K
Media
201
Statuses
2K

Founder - TestifySec - Secure Systems from Source to Production

Huntsville, AL
Joined November 2015
Don't wanna be here? Send us removal request.
@colek42c
Cole Kennedy
1 year
AI makes Helm tolerable
1
0
5
@outshiftbycisco
Outshift by Cisco
2 years
In the latest episode of Cloud Unfiltered, @colek42c breaks down the concepts of supply chain security and discussed the importance of attestation with @mchenetz. Listen on Substack: https://t.co/J62BciNLS7 or watch here: https://t.co/aEUfP4maTn
0
2
7
@colek42c
Cole Kennedy
2 years
Can you guess what we are working on?
0
0
6
@colek42c
Cole Kennedy
2 years
If you are in Chicago for #KubeConNA I highly recommend @Wookiefoot playing at Reggies tonight at 9:30.
0
0
3
@lorenc_dan
Dan Lorenc
2 years
Bingo! Signatures are empty attestations, or even Implicit Attestations where the subject and predicate are defined out of band by the context of how the signature was generated. Explicit is better than implicit in security!
@realjohnkjell
John Kjell 🦉🛡️
2 years
@witness_dev Signatures are really just an empty attestation. ❤️ this framing.
2
6
27
@colek42c
Cole Kennedy
2 years
Has anyone used, or maybe written about using in-toto for tracking provenance of AI models? cc @trishankkarthik @justincormack, @torresariass , @ffkiv , @adityasaky
2
0
6
@colek42c
Cole Kennedy
2 years
For anyone looking for a last minute Halloween Costume... We hear that supply chain security experts get paid well... This kit could get you started. 😎 💻 Stay safe out there in the digital world. #halloween #cybersecurity #softwaresupplychain
0
1
4
@colek42c
Cole Kennedy
2 years
2 offers out and signed!
0
0
11
@realjohnkjell
John Kjell 🦉🛡️
2 years
We’re hiring @testifysec! 🛡️🎉 Have you ever wanted to work on open source full time? Do you want to make the world’s 🌎 software more secure? 🔐 This could be for you:
0
6
14
@realjohnkjell
John Kjell 🦉🛡️
2 years
We're having our first Witness and Archivista community call today at 11:00 am EDT! 🎉Come learn about attestations for your supply chain. ⛓️Meeting info here:
Tweet card summary image
github.com
Witness and Archivista community information. Contribute to testifysec/community development by creating an account on GitHub.
0
1
7
@colek42c
Cole Kennedy
2 years
Are you heading to #devopsdaysdc? I will be there Thursday, Sept 14. Who want's to meet up and nerd out over the importance of software supply chain security. #testifysec #software #supplychain
0
0
2
@colek42c
Cole Kennedy
2 years
My personal version of hell is using JIRA over a VDI hosted across the ocean.
1
0
5
@colek42c
Cole Kennedy
2 years
As supporters and maintainers of in-toto, we are extremely excited to support their graduation proposal. The in-toto framework is the security backbone of our products at TestifySec, and we couldn’t be more proud to support the project for graduation.
0
0
7
@colek42c
Cole Kennedy
2 years
Happy Labor Day! I hope you too are ghosting work today like I am. #laborday
0
0
1
@clintgibler
Clint Gibler
2 years
📦 SBOMit An SBOM format independent method for attesting components with additional verification information Uses in-toto attestations and layouts https://t.co/73cbh6Vn6I
sbomit.dev
Software Bill of Materials on in-toto
0
1
14
@clintgibler
Clint Gibler
2 years
📚 tl;dr sec 196 How secrets leak in CI/CD @KarimPwnz WrongSecrets lab @owasp AI threat modeling @DanielMiessler in-toto: API of DevSecOps @adityasaky, @colek42c Rein in your SIEM @ExpelSecurity Simple parenting hacks @rez0__ #cybersecurity https://t.co/ggg5F5MkqW
Tweet card summary image
tldrsec.com
Some subtle ways secrets leak and how to mitigate, AI threat modeling for policymakers, in-toto and TACOS
2
13
25
@colek42c
Cole Kennedy
2 years
Who would be interested in a co-located conference dedicated to TUF and in-toto?
0
3
8
@colek42c
Cole Kennedy
2 years
At TestfiySec we want to encourage our team to lean into innovation and not doing something just because everyone else is. But find creative ways to deliver better results for our partners and the Saas community as a whole. Thoughts? #cybersecurity #testifysec #saas
0
0
3