Back To Schedule
Wednesday, August 21 • 3:10pm - 3:40pm
Binary Policy with IMA and AppArmor - Eric Chiang, Google

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Google operates one of the largest fleet of developer machines, supporting a wide range of user workflows and expectations. While techniques such as social voting of binaries for whitelisting on other OSes have been successful, Corp Security has taken novel approaches on Linux workstations for providence based policy. Over the past year Eric’s worked to build features into AppArmor for targeting IMA signatures, enabling restrictions of executables that don’t originate from Google’s centralized package repositories. This talk will dive into the technical aspects of Google’s binary signing and operational challenges rolling out restrictive policies at scale.

avatar for Eric Chiang

Eric Chiang

Security Engineer, Google
Eric is a security engineer on the Platform Security team at Google where he focuses on securing Google’s Linux workstation fleet. Previously he worked at CoreOS on identity management and co-lead the Kubernetes Auth special interest group. Eric is a Bay Area native, SFSU alumni... Read More →

Wednesday August 21, 2019 3:10pm - 3:40pm PDT
Sapphire D