
The BOM Explosion & Why PQC Stopped Being 10 Years Away with David Pollak & Allan Friedman
In this episode, David Pollak, founder and CEO of Spice Labs, and Allan Friedman, Senior Technical Advisor at the Institute for Security and Technology, discuss the importance of software supply chain security, bills of materials, and the emerging field of post-quantum cryptography with Kate Holterhoff. Friedman, "the godfather of SBOMs," gives a state of play for 2026: where the tooling has matured, where it still falls short, and why the Cyber Resilience Act is about to make this everybody's problem. From there the conversation moves to CBOMs and post-quantum cryptography. Pollak argues PQC stopped being a 2035 problem in June, when the White House, the US military and French standards bodies all pulled their deadlines forward by five years. Also covered: whether developers should have to think about security at all, what the IPv6 transition taught us, and the 360,000 Maven packages carrying vulnerable code nobody disclosed.
This RedMonk conversation is sponsored by Spice Labs.
Show notes: https://redmonk.com/videos/david-pollak-allan-friedman/
Chapters
00:04 Introduction to the Guests and Topics
06:29 The State of SBOMs in 2026
13:46 Understanding Cryptographic Bills of Materials
22:12 The Intersection of Security and Development
31:25 The CBOM Approach and Its Importance
33:23 Post-Quantum Cryptography: A Future Concern?
38:55 Navigating Regulations and Compliance
43:57 Finding vs. Fixing Vulnerabilities in Open Source
49:58 AI's Role in Security and Vulnerability Management
53:31 Lessons from IPv6 and Cryptography Libraries
Otros episodios de "The MonkCast"



No te pierdas ningún episodio de “The MonkCast”. Síguelo en la aplicación gratuita de GetPodcast.








