Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Type: Digital Trust clear filter
Friday, October 9
 

11:05 CEST

Proofs of Personhood: Managing Identity in the Age of AI - Hart Montgomery, The Linux Foundation; Drummond Reed, First Person Cooperative; Glenn Gore, Affinidi
Friday October 9, 2026 11:05 - 11:45 CEST
“On the internet, nobody knows you’re a dog,” the famous New Yorker comic goes, and that aphorism couldn’t ring truer today. In a world of AI agents, how can we be sure that we (or our agents) are interacting with other trusted, reputable systems and agents rather than impersonators or scammers? As open source maintainers, how can we be sure that new contributors are responsible, trustworthy individuals rather than adversarial state actors, helping to thwart compromises like the XZUtils attack? More generally, how do we deal with digital identity in the age of AI?

Our proposal is to use cryptographic proofs of personhood. These can be built from a decentralized, privacy-preserving reputation system, which we can build with tools and standards we have developed in several projects in LFDT. The session will cover some background on how proofs of personhood work, including privacy guarantees from cryptography (at a beginner level). Then, we will explain some applications in agentic AI and open source software maintenance. Finally, we will give an end-to-end demo of how our systems work in practice which will include audience participation in a “verifiable trust graph”.
Speakers
avatar for Drummond Reed

Drummond Reed

Director, First Person Cooperative
30+ years working on Internet identity, security, privacy & trust
Co-Editor, W3C Decentralized Identifiers (DID) Specification
Steering Member, Trust Over IP (ToIP) Foundation
Co-Author, Self-Sovereign Identity (Manning, 2021)
avatar for Hart Montgomery

Hart Montgomery

CTO, LFDT, Linux Foundation
Hart Montgomery serves as the CTO of LFDT and the ED of the PQCA. Hart previously worked in blockchain and cryptography research at Fujitsu Research where he helped lead Fujitsu’s contributions to Hyperledger. Prior to Fujitsu, Hart received a Ph.D. in cryptography at Stanford under... Read More →
avatar for Glenn Gore

Glenn Gore

CEO, Affinidi
30+ year Veteran of building Internet-scale infrastructure (OzEmail, UUNet, AWS, Affinidi). CEO of Affinidi, board member to tech startups. Glenn is still a hands-on developer, building next-generation security and privacy services that are open by design and open-source in devel... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club H (Floor 1)
  Digital Trust
  • Audience Experience Level Any

11:55 CEST

Building Trust in the AI Era: Agent-to-Agent Communication With DIDs and VCs - Alexander Shcherbakov, DSR Corporation
Friday October 9, 2026 11:55 - 12:35 CEST
As AI moves from isolated chatbots to autonomous agent ecosystems, the "identity problem" becomes a critical security bottleneck. How does an agent verify the legitimacy of a requestor before executing a sensitive task? Traditional API keys are insufficient for dynamic, decentralized agent interactions.
This session explores a cutting-edge extension to the Linux Foundation A2A protocol that leverages Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to establish high-assurance trust and bridges the gap between Decentralized Identity standards and AI, creating a secure backbone for the next generation of agent interoperability.
We will dive into the technical design of integrating OpenID for Verifiable Presentations (OID4VP) into agent communication flows. Attendees will learn how this proposed extension moves beyond static credentials to enable granular, verifiable Authentication (AuthN) and Authorization (AuthZ) for autonomous tasks. Beyond the protocol basics, we will analyze different patterns for VC presentation—comparing interactive vs. automated flows—and evaluate diverse wallet options, ranging from cloud-based agent wallets to secure edge implementations.
Speakers
avatar for Alexander Shcherbakov

Alexander Shcherbakov

Head of Digital Trust Labs, DSR Corporation
Ph.D. in Mathematics. Master of Applied Mathematics and Computer Science.
Extensive experience in Blockchain, DLT, Self-sovereign Identity (SSI).
Significant contribution to open source. Maintainer and contributor of popular LF open-source projects (Hyperledger/OWF/Indy/Hiero).
Extensive experience speaking at international conferences: LF Open Source Summit North America 2026, LFDT Member Summit 2026, Hyperledger Global Forum 2020, Hyperledger Bootcamp 2019, Internet Identity Workshop 2021... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Club H (Floor 1)
  Digital Trust

14:00 CEST

Why We Fixed It Upstream: A Telco Perspective - Kashif Khan, Ericsson & Jan Melen, Ericsson Software Technology
Friday October 9, 2026 14:00 - 14:40 CEST
Working in telco infrastructure means regulatory compliance isn't optional. When a CVE drops, we can't wait a quarter. We can't backport locally. We have to fix it upstream, and we have to do it fast. This constraint forced us to ask harder questions about how we collaborate with open source projects.

At Ericsson we maintain bare metal Kubernetes using Metal3, Cluster API, and Ironic. Over the past few years, we've learned that regulatory pressure actually makes us better engineers. It forced us to build real relationships with upstream maintainers, contribute more thoughtfully, and think long term instead of short term.

This talk explores what changed in how we work with upstream projects when we couldn't carry local patches. We'll talk about the specific practices that work when your infrastructure depends on fast, reliable upstream collaboration. You'll hear about what changed in how we communicate with maintainers, how we structure our releases, and what we learned about contributing upstream that applies whether you're bound by regulation or not.
Speakers
avatar for Kashif Khan

Kashif Khan

Maintainer | Co-Chair CNCF TAG Infrastructure | Principal Open Source Architect, Ericsson
Kashif Khan is a co-chair of CNCF TAG Infrastructure and maintainer of the CNCF project Metal3.io for 6 years. He works as an open source Architect for Ericsson Software Technology, Finland. He holds a PhD in Computer Science. Kashif is a research and open source enthusiast and his... Read More →
avatar for Jan Melen

Jan Melen

General Manager, Ericsson Software Technology
Jan Melén is an expert in networking, open-source software, and cloud technologies, with a career spanning over two decades. He is a staunch advocate for Free and Open-Source Software (FOSS) adoption within Ericsson and the broader community he engages with.

Since 2019, Jan has led a team dedicated to CNCF open-source projects, contributing to Ericsson's K8s distribution, and fostering an "upstream-first" culture. He oversees Ericsson’s open-source contributions and collaboration with CNCF... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club H (Floor 1)
  Digital Trust

14:50 CEST

Panel: Found It. Filed It. Forgotten? The Open Source Fix Problem in AI Era - Rao Lakkakula, Microsoft; Amanda Casari, Google; Stormy Peters, AWS
Friday October 9, 2026 14:50 - 15:30 CEST
We have become highly effective at finding vulnerabilities, accelerated by AI-driven analysis. We can scan at scale, assign scores, and generate reports with unprecedented speed. The breakdown happens after discovery.

For many maintainers, security reports arrive as noise: limited context, unclear expectations, and little support to carry fixes through to completion. Backlogs grow, trust declines, and critical issues remain unresolved.

This panel brings together security and open source leaders from Microsoft, Google and AWS to confront an uncomfortable reality: discovery is the easy part. Remediation, especially in shared infrastructure maintained by a small number of overextended contributors, is where the system fails.

We will explore what actually helps maintainers move from report to resolution. What makes a report actionable? How do we reduce noise and avoid drive-by reporting? How do we support fixes through triage, patching, and downstream adoption without taking over projects?

If you are a struggling maintainer or an industry consumer who wants to support OSS you depend on without overloading it, this session is for you. The focus is simple: fixes that land.
Speakers
avatar for Rao Lakkakula

Rao Lakkakula

Partner Director, Microsoft
Rao Lakkakula is Director of Open Source Ecosystems at Microsoft. He brings over 25 years of experience in security and software development, with prior leadership roles at JPMorgan Chase, The Climate Corporation, Amazon, and several startups. Rao serves on the Linux Foundation Research... Read More →
avatar for Amanda Casari

Amanda Casari

Staff Developer Relations Engineer, Google
amanda casari is a researcher and engineer in the Open Source Programs Office at Google, where she is co-leading research and engineering to better understand risk and resilience in open source ecosystems. She was named an External Faculty member of the Vermont Complex Systems Center... Read More →
avatar for Stormy Peters

Stormy Peters

Head of Strategy & Marketing, AWS
Stormy Peters is Head of Open Source Strategy & Marketing at AWS.
Friday October 9, 2026 14:50 - 15:30 CEST
Club H (Floor 1)
  Digital Trust

15:40 CEST

When the LLMs Come Knocking: Surviving AI-Powered Vulnerability Reports - Vincent Demeester, Red Hat
Friday October 9, 2026 15:40 - 16:20 CEST
In early 2026 our vulnerability inbox suddenly exploded. Tekton, the Kubernetes-native CI/CD framework we maintain, received more security reports in four months than in all the previous years combined: detailed, with working reproducers and CVSS scores. Many were genuinely valid. They were also, overwhelmingly, AI-generated.

LLM-powered research has changed the game. Tools now audit codebases systematically and surface real bugs humans missed for years: a path traversal reading arbitrary files from the controller pod, an SSRF exfiltrating cloud credentials, a JSON injection enabling RCE. These aren't hallucinations, and they arrive faster than a small team can patch, disclose, and backport.

But the flood carries noise too: variants of fixed CVEs, reports that misunderstand the threat model, duplicates. The challenge has shifted from "find vulnerabilities" to "triage an AI-accelerated firehose without your disclosure process collapsing."

This is an honest, in-progress survival guide from maintainers living through it: how triage holds up under pressure, how we separate signal from noise, what we got right, and what we got wrong.
Speakers
avatar for Vincent Demeester

Vincent Demeester

Senior Principal Software Engineer, Red Hat
I'm a french developer 🐻, Gopher 🐹, sysadmin 🐺, factotum 🦁, free-software fan 👼 and unicode lover 🐸. I'm working at Red Hat 🎩 as a senior principal software engineer, previously at Docker 🐳 and Zenika 🐯. I am a maintainer of the docker project (moby/moby... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club H (Floor 1)
  Digital Trust

16:30 CEST

State of the OSS Union: Assessing Your Stack’s Autonomy Under EU Law - Emiel Brok, SUSE / DOSBA
Friday October 9, 2026 16:30 - 17:10 CEST
Open source is the bedrock of European digital sovereignty, but a wave of aggressive new EU legislation is transforming how organizations must build, source, and secure their digital environments. Navigating this shift requires unpacking complex regulatory mandates and understanding their operational impact on modern enterprise and cloud software architecture.

This fast-paced session strips away the legal jargon to deliver a real-time status update on Europe’s changing digital roadmap. We will analyze the mandatory software bill-of-materials (SBOM) rules of the Cyber Resilience Act (CRA) and the open standards driving the Interoperable Europe Act. Crucially, we dive into the European Commission's freshly unveiled Cloud and AI Development Act (CADA) to unpack its cloud sovereignty tiers and its "open-source first" procurement principles.

Moving from compliance theory to practical execution, attendees will gain a concrete framework to audit their own production IT stacks. We will walk through the web-based SUSE Cloud Sovereignty Self-Assessment tool to measure true autonomy using weighted SEAL (Sovereignty Effective Assurance Level) metrics.
Speakers
avatar for Emiel Brok

Emiel Brok

Global Sovereignty Ambassador, SUSE / DOSBA
Open Source & Sovereignty Ambassador at SUSE.
Co-founder DOSBA (Dutch Open Source Business Alliance)
Social Media activities through #FridayKetchup and #GeekOnTour.
Mission in life: Make the world a better place by evangelizing open source.
Friday October 9, 2026 16:30 - 17:10 CEST
Club H (Floor 1)
  Digital Trust
  • Audience Experience Level Any
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.