The MonkCast podcast

The BOM Explosion & Why PQC Stopped Being 10 Years Away with David Pollak & Allan Friedman

24/9/2026
0:00
58:01
Retroceder 15 segundos
Avanzar 15 segundos

In this episode, David Pollak, founder and CEO of Spice Labs, and Allan Friedman, Senior Technical Advisor at the Institute for Security and Technology, discuss the importance of software supply chain security, bills of materials, and the emerging field of post-quantum cryptography with Kate Holterhoff. Friedman, "the godfather of SBOMs," gives a state of play for 2026: where the tooling has matured, where it still falls short, and why the Cyber Resilience Act is about to make this everybody's problem. From there the conversation moves to CBOMs and post-quantum cryptography. Pollak argues PQC stopped being a 2035 problem in June, when the White House, the US military and French standards bodies all pulled their deadlines forward by five years. Also covered: whether developers should have to think about security at all, what the IPv6 transition taught us, and the 360,000 Maven packages carrying vulnerable code nobody disclosed.

 

This RedMonk conversation is sponsored by Spice Labs.

Show notes: https://redmonk.com/videos/david-pollak-allan-friedman/

Chapters

00:04 Introduction to the Guests and Topics

06:29 The State of SBOMs in 2026

13:46 Understanding Cryptographic Bills of Materials

22:12 The Intersection of Security and Development

31:25 The CBOM Approach and Its Importance

33:23 Post-Quantum Cryptography: A Future Concern?

38:55 Navigating Regulations and Compliance

43:57 Finding vs. Fixing Vulnerabilities in Open Source

49:58 AI's Role in Security and Vulnerability Management

53:31 Lessons from IPv6 and Cryptography Libraries

Otros episodios de "The MonkCast"