The supply chain is complicated – which is why it is vulnerable to exploitation

Bruse Schneier has an interesting article out today, describing how a Russian company that produces code that is included in thousands of smartphone apps, both iOS and Android, masquerades as an US company.

Russian Software Company Pretending to Be American – Schneier on Security

There is no suggestion of wrong doing, but it leads into the questions of transparency – how can you do your cyber security due diligence if you do not get the whole picture – and data sovereignty – if you think the data is held in the US when it is really in Russia and subject to Russian laws.

Clive Catton MSc (Cyber Security) – by-line and other articles

Further Reading