> Markdown version of [/videos/784-overcome-your-trust-issues-in-a-world-of-fake-data-data-provenance-ftw?t=242](https://www.wearedevelopers.com/videos/784-overcome-your-trust-issues-in-a-world-of-fake-data-data-provenance-ftw?t=242). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Overcome your trust issues! In a world of fake data, Data Provenance FTW Traditional firewalls are useless against AI deepfakes and fake data. Adopt a 'verify then trust' architecture using cryptographic data provenance to permanently secure your software supply chain. - **Speakers:** Jon Geater - **Event:** World Congress 2023 - **Published:** October 23, 2023 - **Duration:** 26:41 - **URL:** https://www.wearedevelopers.com/videos/784-overcome-your-trust-issues-in-a-world-of-fake-data-data-provenance-ftw ## Summary The modern software landscape has fundamentally shifted from code-centric vulnerabilities, like the widespread Log4j and ImageMagick incidents, to broader data-driven risks. The current cyber supply chain relies heavily on traditional "trust but verify" paradigms, utilizing firewalls and network perimeters. However, as APIs and disparate data sources dominate business operations, this approach fails to scale against threats such as generative AI-driven deepfakes, sophisticated invoice fraud, and stolen signing keys. These breaches demonstrate that merely hiring more manual reviewers or clinging to legacy IT security models is inadequate to defend a highly connected, deeply integrated application architecture. To overcome these scalable threats, the industry must adopt a "verify then trust" model centered on data provenance and authenticity. This framework relies on three fundamental pillars: strong identification of the source to avoid corruption, immutability to prevent data from being altered or retracted during discovery processes, and non-equivocation to eliminate split histories where different parties receive conflicting information. Spearheaded by standards like the IETF Supply Chain Integrity, Transparency, and Trust (SCITT), this architectural shift ensures that every piece of data—from AI models to Software Bills of Materials (SBOMs)—carries a decentralized, verifiable receipt. Implementing data provenance transforms abstract security concepts into actionable engineering practices through simple API calls and distributed ledgers. By attaching cryptographic attestations to operations via Merkle trees, developers can create transparent, offline-verifiable records for software releases, data storage, and external integrations. This empowers organizations to definitively track code dependencies, detect compromised inputs, and maintain resilient data structures. Embedding provenance at the core of data exchanges reclaims control from opaque supply chains, ultimately ensuring applications run on unalterable operations and verified truths. **Keywords:** data provenance, cyber supply chain, log4j vulnerability, generative AI risks, verify then trust model, data authenticity, immutable data management, IETF SCITT standard, cryptographic attestation, merkle tree receipts, software bill of materials, SBOM, non-equivocation, offline verification, distributed ledgers, API integration security ## Chapters 1. **Vulnerabilities within the cyber software supply chain** (00:03) — Why relying on open-source software packages like Log4J exposes enterprises to long-tail security patching risks. 1. **Transitioning from code risks to data-driven business threats** (04:02) — As modern enterprise stacks mature, unverified external data inputs pose systemic risks previously isolated to faulty code frameworks. 1. **The inability to scale human data verification efforts** (07:09) — Scalable forms of fraud like AI-generated invoices bypass traditional human-led moderation processes and demand automated verification pipelines. 1. **Devastating impacts of stolen infrastructure signing keys** (11:39) — Compromised authentication keys bypass system configurations and render standard perimeter security architectures completely ineffective. 1. **Establishing an authentic model of data provenance** (13:59) — Verifiable supply chain integrity standards supported by major national technology institutions improve upon outdated zero trust boundaries. 1. **Core principles for verifiable supply chain transparency** (16:28) — Protocols dictating source identification, record immutability, and safeguards against equivocated histories establish robust foundations for unalterable data trust. 1. **Decentralizing trust through immutable digital ledger receipts** (18:57) — API-driven attestations and offline cryptographic receipts guarantee clear lineage tracking without relying on vulnerable centralized certificate authorities. 1. **Real-world operational use cases for data provenance architectures** (21:21) — Immutable system tracking principles expose and resolve operational defects across physical manufacturing pipelines, IoT integrations, AI logic, and SBOMs. 1. **Live demonstration of API based public data attestation** (22:56) — A live API integration validates real-time test claims by publishing JSON string payloads directly onto a decentralized ledger. 1. **Building verifiable application logic using transparent data models** (25:03) — Non-repudiation standards and immutable timestamps maintain honest program states by preventing retroactive manipulation of recorded historical events. ## Related Moments - [Securing digital supply chains using isolated build environments](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) (from "An alternative approach to digital sovereignty: Confidential Computing") - [Securing code provenance with digital identity signatures](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) (from "One Pipeline, Three Regulator - SBOM Compliance for the Developer") - [Solving data integrity and digital ownership with distributed ledgers](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) (from "Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation") - [Audience questions on model security and continuous fuzzing](https://www.wearedevelopers.com/videos/347-mlops-and-ai-driven-development) (from "MLOps and AI Driven Development") - [Embedding data security and applied ethics into developer education](https://www.wearedevelopers.com/videos/1107-the-future-of-developer-experience-with-genai-driving-engineering-excellence) (from "The Future of Developer Experience with GenAI: Driving Engineering Excellence") - [Assessing data provenance and offline software coding challenges](https://www.wearedevelopers.com/videos/1759-ai-killed-devops-what-now-lee-faus) (from "AI Killed DevOps... What Now? - Lee Faus") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [The Rise of Disinformation on the Web](https://www.wearedevelopers.com/magazine/539-the-rise-of-disinformation-on-the-web) ## Related Jobs - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Lead Software Engineer - Data Engineering](https://www.wearedevelopers.com/jobs/ext/2000968-lead-software-engineer-data-engineering) at **Dynatrace** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub**