Emelie Markianos

Every piece of software an organization runs — from the framework in production to the small utility library buried four dependencies deep — has a public shadow: commit histories, mailing list threads, forum posts, expired domains, and the personal footprints of the people who maintain it. None of this is secret. All of it is searchable. And almost none of it shows up in a vendor questionnaire or an SBOM.


This talk uses open-source intelligence (OSINT) as a lens for a question security teams rarely ask directly: what does the internet already know about the software we depend on — and about the people who build it?

Using the 2024 xz-utils backdoor as the central case study, we walk through how publicly available signals — commit timestamps, account histories, and infrastructure metadata could let independent researchers to reconstruct a multi-year supply chain compromise using nothing but open sources. The aim
of the talk is to broaden the understanding of how companies and infrastructure footprints can be used by malicious actors and what a subdomain map, a dependency graph, or a maintainer’s public activity can reveal about risk.

The goal is not to turn the audience into investigators. It’s to leave developers, security leads, and decision-
makers with an understanding for the dual aspects of transparency, for building resilience, but also used by malicious actors and and a few concrete questions to start asking about their own OpSec.


Why this talk, why now
Supply chain trust is the recurring theme of the last few years of software security — and almost every
high-profile incident, from log4j to xz-utils, was preceded by public signals that were visible before the
compromise was understood as a compromise. OSINT is usually framed as either a pure red-team skill or a
journalist/investigator’s toolkit. This talk repositions it as a everyday risk-assessment discipline for anyone
who ships or depends on software.

Focus on Supply Chain Security
Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)