Build from source with Matt Moore from Chainguard | Zero-Shot Learning
In 2020, the SolarWinds attack exposed the vulnerability of supply chains worldwide, a problem this episode’s guest, Matt Moore, had already been working to solve for years. In 2021, he co-founded Chainguard to protect supply chains from future breaches. His conversation with 1Password CTO Nancy Wang and Google Gemini’s Dev Tagare covers why the open source trust model is structurally broken and how AI agents have complicated supply chain security, with a live demo demonstrating how standard tools overlook many vulnerabilities.
In this episode:
AI is shrinking the window for patching, as AI-powered attacks accelerate and demand for pre-alpha code grows
Hacks usually target the delivery pipeline rather than the source code
Net-new, AI agent-written code creates more burden for teams to maintain and secure
Most breaches exploit long-lived credentials
Audited least privilege flips the security model from restricting identities to guarding sensitive resources
Zero-Shot Learning is a builder-to-builder podcast about how AI systems are designed, deployed, and secured. Subscribe for more.
Go deeper:
Episode companion blog: https://www.1password.com/blog/
1Password Developer newsletter: https://1password.com/developer-newsletter
LinkedIn: https://www.linkedin.com/in/mattmoor/
Connect with 1Password
1Password.com
1Password Developer newsletter: https://1password.com/developer-newsletter
Build securely with 1Password Developer: https://developer.1password.com/