Challenges in DevSecOps with Jeff Williams and Katie Norton at Black Hat 2024
Jeff Williams, co-founder and CTO at Contrast Security, and Katie Norton, research manager at IDC, discussed the challenges in DevSecOps, focusing on the need for better integration of security into the development process. They highlighted Contrast Security’s new Application Detection and Response (ADR) tool, which enhances runtime visibility and helps teams detect and stop attacks in production environments. The conversation emphasized breaking down silos between development, security, and operations to improve collaboration and efficiency.
Transcript
This is Techstrong tv. Hey everyone. Welcome back to our Techstrong tv, live Coverage of Black Hat 2024.
Um, you know, a day and a half in we, we've got our first AppSec, genuine AppSec, uh, interview where we can talk AppSec, which for those of you who are security people, you may find that a little weird. This is Black Hat. It's the AppSec Hacking Conference.
It's not, you know, everything under the Sun security, but for whatever reason, that's the state of black hat. We'll, we'll, you know, we could talk more about it, but we're thrilled to have back with us. This gentleman right here, his name's Jeff Williams.
Jeff is the C-C-E-O-C-T-O-C-T-O-C-T-O. I've made that mistake before with you at Contrast Security, and it's always a pleasure to have Amad. But we've got more joining us from IDC Katie Norton.
You got it with The green hair. She's an Eagles fan. We won't hold it against her.
Um, joining us, Katie, welcome. I know this the first time. Pleasure.
Yeah. Text from tv. Yeah.
It's great to have you on here. Yeah. Um, so Jeff, I'm gonna let you start the off and everything, but before we get to that, a little bit about you and what you do at IDC maybe and our, you're new to our audience, introduce yourself.
Yeah. I'm, uh, a research manager at IDC and I, uh, cover the dev sec ops software, supply chain security tools world. So all everything developer and SDLC and how security is integrated into that.
Love it. Jeff. Contrast security needs no introduction to our audience.
As I was telling you, we love having Larry Marcone in everything we do. I think I invited him to every event we do, um, but maybe there are some people who aren't familiar with contrast. So, before we get to the topic of discussion today Yep.
Maybe a quick contrast background. Yeah, sure. So, you know, we started contrast because we saw so many big enterprises struggling with application and API security.
They, you know, spent a lot of money on scanners and web app firewalls and, you know, big teams to deal with the false positives and all that. It was just, and it ultimately, those organizations were not producing a lot of value. What they, what they did generate was a huge backlog of vulnerabilities.
1 million vulnerabilities in their application security backlog. That's not success. That's not working.
So we started, we have a different approach. We instrument the application a little bit like an A PM tool, but for security. And we watch the code as it runs and we'll tell you if there's vulnerabilities or library problems, and in production, we'll stop attacks.
Excellent, excellent. And that's what the game is about. You know, I had, you know, Brian Fox from Sony Type was here this morning.
We were talking about the difference between vulnerabilities and malicious, you know, vulnerable and malicious. Oh, yeah. Yeah.
I disagree with him about that. We've had some argument I wish I would've known it would had you. We could've done counterpoint.
Well, we're gonna be doing some videos on that with him, and I'm gonna invite you to one. Excellent. That'll be fun.
Yeah. Wait for the fireworks. All right.
Um, but let, let's get back to the instant at hand here. So we're at Black Hat, it's an AppSec show, contrast security AppSec company, and you mentioned APIs, right? And I did, you know, it's funny, API security kind of burst on the scene maybe four or five years ago.
Yeah. It's gone a little quiet. I think some of the employee API guys, well, Most people are realizing that it's really just application security applied to a different kind of application.
And it, it's all the same stuff. So, uh, yeah. We treat it like one thing, same tools, same technology, all is one.
You don't wanna have a bunch of separate tools doing essentially the same thing That an C agreement. No. Yeah.
Well, actually, what I was gonna say is I think that there's been really a shift in API It very much started on, um, that the protection, it really on the runtime side of things. And we've recognized, and this kind of goes to what we're gonna keep talking about here, is this, you can't understand the code apart from the, the, the runtime. And that we're more and more needing to be able to bring these two things together.
And so for me, API security has really been trying to understand it. And the, the shift has been understanding it in the development process more than even just what's happening in the runtime and bringing those two things together. So it was almost an artificial distinction, let's say between like BC and ad, you know?
Mm-Hmm. Yeah. Before deployment, after deployment.
And, you know, I, and I, I like what you said, Jeff. I think it is, it's AppSec just in different, uh, different, uh, you know, yeah. Not venue.
Uh, you know, a different path, if you will. Um, anyway, though, let, let's turn. You guys made a big announcement yesterday.
Yeah. We did. Functionality.
Let's, I'm turning it over to you, Jeff. Tell 'em, share. So, uh, we noticed that there's a big problem in production environments.
Like Katie was talking about that for AppSec and a p iec, people really don't have visibility into what's going on in production in their apps. Absent APIs from a security perspective, they don't see attacks. They don't, you know, all they get is maybe a little bit of, of telemetry from their waf, which is a mono False positive say anymore.
Well, everybody has them, but come off and nobody uses the telemetry 'cause it's, it's, the WAF doesn't know anything about what is protected. The APIs go the API traffic, which is the majority of internet traffic today, right. Goes under the radar there.
Yeah, That's right. So, uh, we announced something. We're calling application detection and response a DR.
And if you think about how other parts of cybersecurity work with, uh, like EDR, endpoint detection response and, uh, cloud detection response and so on. There's, there's a bunch of drs but there's this big gap at the application layer. And so we're filling that gap.
We've got a great offering that allows you to, uh, instrument your applications. They watch for attacks in production. And when we see one, we can share the telemetry about it, the full context of it, which we were talking about a little bit, and prevent that, uh, exploit from harming your applications and APIs.
So we're really excited about it. We think it's a, a big gap in the cybersecurity landscape, and it fits right into the way that, uh, security works in operations XDR platforms, taking all the data from A-D-R-C-D-R-A-D-R, so on, and building that, that picture that the SOC analysts use. I love it.
Katie. Yeah. What do you think?
Yeah, I, I, it's, uh, almo it goes to like, almost that, that artificial gap you were just talking about or line between, you know, before and after, um, deployment, this is like a, almost an even bigger chasm I think, that we're crossing and bringing together of like what's happening in the SOC and what's happening with developers. And it's this like huge lever that needs to be pulled in the larger prioritization problem to the one point, you know, whatever million in vulnerabilities, you know, we've seen that you can't understand. You can't prioritize what you need to do just with code context.
And so we've added runtime and we've seen things like code reachability, uh, exploitability, all sorts of things, business context to be able to try to better narrow down this list of things that need to be addressed, particularly from the development perspective. And now, like this is such a huge gap. It's like an even higher order of like, okay, your application is under attack and the security analyst doesn't have the application context to be able to even pass it back to the developer what to fix.
They might be able to say, pull lever, close this off, shut this down to like temporarily stop this. But ultimately there's something that our part, the resolution and, uh, of what needs to be fixed. And that's got to go when it's related to the application back to development.
And so the shared knowledge, this, this leg inlets chasm that has to close between what's happening in the sock and what's happening in development. And that's where I see this A DR really bringing these two areas to work together a little more collaboratively. You know, DevOps is all about breaking down silos.
That's right. And we generally think of it as a development ops silos that get broken here. Right.
Or that we hopefully break down those silos, those walls with the advent of DevSecOps. We're breaking down that silo too. Kenny and I were talking about that on the way over here.
I just wanna make one observation. So, you know, DevOps was pretty good at breaking down the, the S deployment on Between dev and ops. Uh, but DevSecOps didn't do that for security.
It didn't break down the silos between security and dev and ops. Uh, really. But I think why?
Well, I think it's just the security tools and, and teams have their own way of working, you know, and, and I think actually the tools, tools Security team look kind of weird. Clearly I got an, But like, the way that those tools work and teams work, they, they create silos. They naturally create silos because they create this huge backlog that nobody wants to touch.
And so they're like, well, let's have a group over there that manages that giant pile of stuff. Nobody wants to Fix many security pull, especially in the soc. Like the app's not my problem.
When you bring up the app to them, you know, and the engagements I've had that it's like, they, it's almost No, that's right. That's exactly like heal up. We have to empower them to deal with application.
And API incidents that happen in production log for Shells, one example that's like a library example, but there's plenty of examples of custom code getting exploited. And, you know, we can't communicate with the operations team in the same language. We can't use words like vulnerability and remediation and backlog and quality and testing and all that.
They need a runbook that talks about events and incidents that correlates with their events that are already in their SIM or their XDR. So that's the, that's the big thing that a DR is, is creating, is that, that translation of AppSec into operations. You know, it kind of reminds me of when, when CISOs first became a thing, right?
What was the CISO's job? Well, it wasn't just to manage the security team or architect security architecture. The CISO was there as a translator to talk, to take vulnerability and, and, you know, intrusion talk speak and turn it into business talk.
Yeah. That his fellow, assuming you think CISO's are really on that C level, uh, that his fellow CISOs or their, her, her fellow CISOs can understand. And that was a, it was a, that took a moment right.
To, to, to do that translation. You're talking about yet another boundary layer where we translate. Um, so I, you know, I've been in DevSecOps since before we called it DevSecOps.
The first time I did that show at RSA, my annual DevSecOps actually called it Rugged DevOps. Oh, right. Yeah.
It wasn't DevSecOps yet. We had Wicked, we just launched that rugged dev. Yeah.
Did James op those guys? Yeah. Rugged.
I think one of the lessons learned, and, and probably the hard way, was that developers will never be security Pros. That's right. They're just, you know, it doesn't make 'em bad people.
They're just, they're not security pros. And to your point, security pros are never gonna be developers. And as I've gotten older, and I've gotten old, I've learned, you take people through who and what they are and don't try to fit that square peg into the round hold.
The key is to it, it's like being at the UN and everybody puts on their little translator. Yeah, that's a great one. Thingies, right?
Yeah. You gotta be able to, they've gotta talk a common language. Yeah.
And You gotta make the tools work. And, and I think that's what you, what's such important part. And I think why what Contrast is doing is really interesting is because to be able to like, uh, to create, you have to create a product that you understand how to speak both languages.
And also to be able to provide the, the data in the way that like, that persona is, is going to understand it. And it, it's super important to not, this is an area that bleeds again between just, you know, really that, that SEC ops part, uh, you know, the, we've, we've shift left and devs sec, we've brought those together a little bit. It's that second ops part that needed to come closer together and learn how to communicate with each other to kind of complete the full, the full loop.
There's one other huge part of that conversation that's, that's really breaking down the, the ability for those teams to work together. And it's the accuracy of the data. And it just in AppSec the data from WAFs and from static scanners and dynamic scanners, it's, and, and SCA tools is super noisy.
And so if you try to just hand that to developers, they'll throw their hands up and say, what, I can't fix all this. Like, I just, I, it. And 90% of the time it's a false positive.
They just like, this is just a waste of my time. So by watching applications run in production and APIs run in production, we can get really good, we call it security observability, or we build a picture of how those applications actually work. And then we can say what's real in production.
So when, when we take that and show it to developers, they'll know what's real and can focus on fixing it. And I use the analogy, you know, uh, movie cars and Doc Hudson when he is teaching, uh, lightning McQueen not to drive off the track, and he says, you gotta turn right to go left. Yeah.
That's what we're doing here. We gotta get some data from production, and then we gotta use that data production to inform the decisions that developers have to make. So we're turning right to, to achieve the goals of Shift left, which frankly, you know, haven't really produced any, any change right.
In the market. So Let me make sure I got this right there. This is a tool for security people to help the ops folks.
It's important to, to recognize that security can't be in the critical path of software development and production operations can't. It's just that that pipeline has to move much faster than that. You know, it's gotta be minutes right.
Seconds. So We've gotta enable the developers to do it on their own. And to do that, we've gotta get accurate information from operations stop attacks at operations to give development cover, and then give them contextual findings so that they can make the right fix on stuff that matters right away.
That's how we get these three teams working together, because now the goals are shared. So I think this was another fundamental mistake we made in DevSecOps early on, is that we had security people create security tools for developers. Yeah.
And then, then we said, geez, I wonder why that didn't work. But you know, I call that s******g left, right? Yeah.
We Could censor that Outs. No, no. We're live.
You He said it, not me. Yeah. Uh, but, but that's the truth.
I mean, that didn't work. And, and there was a lot of venture capital dollars that went down the journey with companies that made security tools. 1 million vulnerability backlog.
Yeah. That's p****d off. Developers who get decent to and say, I'm done, I'm Done.
And the amount of time that developers, uh, you know, and, and research I've done that developers are spending on security related tasks. But yet when you, uh, you know, in some of my survey work, it time and time again, developer security knowledge comes up as like the one of the top problems. And, and I think as we see, I mean year over year, over year, that surfaces and that hasn't changed.
And I think it goes back to your point of like, I don't think it's like, yes, training is important, just like we should all have phishing training and all of that kind of stuff. But we have to have the tools that enable the work, like in the context and the flow of how development's being done, and make it easy so that developers don't have to be, I think the expectation of developers to be a security expert is really where they, we went off rail where it went or wet shifted. Right.
And we're not going back. You know, and that, that it's, you need to get that, that right information at the right time in the right context and make it easy for them to make the fix to make this whole, you know, flow work. Right.
Agreed. Agreed. Jeff, you said something I want to dig in a little more on, if it's okay, working with ops to stop, what's the attack right now?
Stop the bleeding right now while we get it over to Dev to kind of make that permanent fix. Right? How are we stopping the bleeding?
So the way that contrast a DR works is by instrumenting the application. So we put security sensors in that watch the application or API run, and we can see an attack when it happens. And unlike a waf, which tries to block it at the perimeter, and without context, it's gonna make a lot of mistakes.
It's gonna break applications and miss attacks and stuff. Instead, we see that how the application handles that data. So for a SQL injection attack, for example, we'll see that attack, go through the application, get into the SQL query, and modify the meaning of the query.
That's when we intervene and we, we, because we know it's an attack, we know that it's, no one should ever modify the meaning of your queries. Right? So if we see it, we know it's an attack.
So that's when we intervene, we throw an exception, which keeps the application from sending that query to the database. Database stays safe, application keeps running perfectly, and you get all the telemetry. So now you can feed that upstream to your XDR, whatever.
You can piece all the, uh, events, uh, together from, you know, maybe the attackers attacking different parts of your system. And you're like, Hey, that IP address is really bad. We gotta watch that.
But that's how we keep everything safe while also informing everybody. I love it. Any pushback on that piece of it?
On like, 'cause I, I know people get a little freaky sometimes about automated defense like that. Yeah. So it's, it's more accepted now than it was when I was, that's still, you know, starting still secure and trying to sell stuff.
Yeah. We're, we're following the, you know, star DR model, the XDR model here. And, you know, ops teams are very comfortable installing EDR and endpoints and CDR on their cloud and SDR on their servers and application.
DR is exactly the same model. It's, you add contrast to your application layer, it monitors for attacks and it stops them and keeps you safe. And, and I'm seeing in my research as well, and in the conversations that I have with end user organizations, as well as in the survey research I do, where the, um, the, it's the, the overwhelmed problem.
Like there has to, I think the cover part of all this is so important because when you think about stuff like Log for J and like you all had a great story there and how you helped organizations with that. Like these fixes in many cases, especially like an open source, say if it's an open source problem, and like that's not, most of the time is not like an easy, like, I'm gonna push a button and like, and just vulnerability thought. Right?
Right. Exactly. Right.
And, and, and then so developers need time to evaluate like, what is the level of investment and time that is gonna be on my part to be able to actually, you know, correct what the vulnerability is. And you can't do that, what you continue No, not With the fire is Raging. You can't, you can't take your application down.
So there has to be this intermediate, uh, between providing protection while also meeting, you know, the, the consumer demand for, um, you know, a flawlessly running application. Uh, I agreed. No, that's why I, that's why I kind of zeroed in on that because that, you know, it is a little bit of a finger in the d kind of thing.
It's not a permanent patch or something, but it takes the pressure. It's like a Steve, a valve release. It takes the pressure off.
Now the developer doesn't have a gun to his head. I I got no fires this. Right.
It's not a fire jack. That's an excellent point. Excellent.
Now, does this cost more money? Is it part of it? If I'm a, if I'm a contrast customer, is it part of my suite?
How, how is this packaged? Yes, this came out yesterday, but what the No, we have, We have two main product areas that we focus on a ST, which focuses on, on giving great telemetry to developers and helping them fix vulnerabilities and helping them get their open source straightened out. Yeah.
Uh, again, it's all runtime. So we, we monitor how the libraries are used. We don't overwhelm you.
That's one product. You buy it per application. Yep.
License it. And then we have a DR on the production side. So, uh, you can buy it, you can, This is a, it's actually a product then It's actually a one plus one equals three because they use the same underpinning.
But if you use it in dev, that's a ST If you use in production, you got a DR. And really, when you put it together, that's when the magic really happens. And you can get a real DevSecOps program.
Really. I love it. Excellent.
I, I, I, you got me, you had me at hello on this. I think it's a time, you know, sometimes you look at stuff and you say, what took so long to come on with this That, you know, my colleague, my colleague and I, I think when we were talking to you about this early on, we're just, we kind of both. I have a, a colleague that covers more XDR, right?
From the security perspective, I'm the, I'm the dev person, right. And we were both kind of looked at each other like, why doesn't this exist? You know, like the No.
And then you said, he said, why didn't I think of this? That's why I'm so working right Now. We see it and, you know, as an analyst, it's an, an emerging space.
But I'm, I'm having a lot of conversations from a variety of different perspectives in the market around this sort of gap around being able to bring, you know, that again, that, that dev second ops, the what's happening in production with, with, and, and that runtime concept, plus the attack and code, and being able to understand that all holistically to just, you know, better and more effectively be able to resolve vulnerabilities and, and have a more secure, and I should Say this is an evolution of our existing platform. And we've been supporting a lot of these use cases with contrast for a number of years. So we've got hundreds of thousands of servers that we protect in production already.
And we've been doing this for quite a long time. So this is proven technology. I know we're launching today and we've added a bunch of things to, to really support the, the operations environment.
But the technology's proven. We've been on, you know, really critical applications as some of the biggest companies in the world for a long time. Absolutely.
People out here, Jeff saying, you know, that sounds pretty guy. I'd like to take it for a ride. I want to dig in.
What, what should they do? Yeah, I mean, reach out to us. The website's a good place to start.
com. And, uh, we've got some really good materials there. If you wanna read about it, you can reach out to our team.
Uh, and if you just have questions about anything about it, please reach out to me on LinkedIn. I'm, uh, easy to find on LinkedIn. Uh, Very easy to find on LinkedIn.
Yeah. Yeah. Well, Jeff's not a hard, Jeff's a hard guy to miss in person if you've never met Jeff in person.
I mean, I'm a big guy, but I, I always feel small when I'm with Jeff. Um, but sounds like a great tool. Congratulations to you and the whole contrast team on this.
I I, it's gonna be interesting to see Katie. Yeah. I, I Point of view, point of view, it's a, a space that I've, uh, really the last probably three, four months start been starting to track.
And I have a lot of, uh, hope for, uh, and, and feeling that we're gonna see these sort of capabilities, uh, you know, evolve in, in, throughout the market in different places. I think the recognition of like the, this is a big missing piece of information that could really help those workflows be more effective and efficient. Um, so I do wanna give a shout out to our launch partner Splunk.
Uh, we're demoing our integrations with Splunk down in the Oh, really? Yeah. And it's nice because I think that's how people are gonna consume this information through the tools they're already using.
So we've got, uh, ways to integrate with, uh, the, the tools people are already using in operations to manage their work. Very cool. One part of Cisco.
Um, so I mean, it sounds great. Every, everything sounds great about it. Let's talk about Black Hat a little bit.
I know today's the first day that the Exhibit Hall album, but people have been here. Jeff, you, you know, from Black Hat. What do you, what's your impressions?
I mean, it seemed super crowded. We had a lot of booth traffic this morning. Granted, we were giving away some Lego Star Wars stuff.
Uh, so there was raffles and so, so there was a lot of people cracking. But adult trick or treaters, I gonna say it's also the a DR message is a lot of people wanna learn about that. Um, in, in Black Hat, you know, big picture, I've seen a lot of people talking about, you know, the, the open source problems.
Uh, a lot of, there's a lot of chatter about CrowdStrike and, uh, yeah, our dependence on monoculture and things like that. So, I mean, it's, it's, uh, for sec I've had people in all day, and you, you get the, you, you're, you're in security. We're all in security long enough.
You, you have people moaning and growing. It is nothing new, nothing new. It's all just more the same.
We don't change the equation. And I, I keep telling people, I think you used the term earlier too, evolutionary, right? So much of what we do in security today is evolutionary built on what came before, right?
There's no magic bullets. This sounds like a great, right. Like, you look at it and say, geez, why didn't I think of this?
Of course. But it's not, none of it is, it all needs, as you said, it's the one plus one equals three aspect of these things that make it truly valuable. I wanna get Katie's opinion on this, but I'll, I'll tell you what I think is really the big change in the cybersecurity world is just the level of transparency that's being demanded in the market.
So it's just, I dunno, two days ago or something, CISA issued, it's, uh, secure by demand and on addition to it secured by design, things secured by demand. And I just, I think that the system is putting a lot of pressure on the, the software market to be transparent about cybersecurity in a way that's never happened before. Absolutely.
And so, things like SBOs and, you know, we, and mandatory disclosures from OMB and so on, like, those are little baby steps, but if you look at where they're pointed, it's where organizations are gonna have to be transparent about what they're doing to secure the, the systems and software that we all trust everything that's important in our lives too. And that to me, is something I've been pushing for, for decades, and I'm really glad to see it finally coming to fruition. And, you know, hopefully Contrast can be a little part of that where companies can get, get ahold of their applications and APIs and be transparent about what they're doing to secure those.
Well, look at CrowdStrike. I mean, it's not even, that's not even a secure, it's not a really a security issue, but even the level of transparency, like how, uh, you know, quickly they've been asked to explain, I mean, it's not, it was what July 19th we're not even a month from when that all happened. The Lawsuits are filed.
Right. Right. And the Right, the lawsuits are filed.
The, like, the final like rundown of it was just came out the other day, I think officially. And like, I mean, that's a pretty quick turnaround that's expected of a company to be able to explain exactly what happened and what's Gonna do, and prop their CEO e for being here. Yeah.
Talking about it. Right. And that, I know George, I know George A.
Long time. I found Stone, I remember when we Foundstone was bought by McAfee. I was Yeah.
Still secure. We had a product called Van Foundstone was kind of our big, well, it was Foundstone in EI with back then where the, yeah. Everyone thought Dle Qualis was crazy because he was starting stuff not on prep.
Right, right. He was talking about stuff they didn't even call it cloud that. So I know George Kurtz a long time, and I, you know, worked with him through McAfee.
He's not, George is a great guy. He's a standup guy. He's, and what happened to them?
I tell you, it can happen to anyone, anyone. So I Definitely, anybody messing with the colonel, You know, now if you listen to Microsoft, Microsoft says, well, I told you not to let anyone mess with the Colonel EU and EU forced us to it. It happened.
I, I get all that. But you're right. There is, I again, we had this discussion, a couple of the interviews today.
I'm not a big fan of, you know, I'm from the government and I'm here to help. Right. I, I would rather we police ourselves.
I would rather, we didn't have government intervention. However, the CSA that we have today, certainly for the last two, three years, if not even, uh, when, when Chris, I forgot Chris's last name. He got, who was it?
csa, and he got Oh, you A loft. Oh, you mean, uh, uh, Dan Ge? No.
Well, no, Dan Gear's old. He's my eight. Uh, no, no.
The guy Trump fired him. I forget his name. Uh, I'll, I'll, it'll come to me.
I had him on here one. Anyway, the last four or five years, csar has really been sort of a beacon of good government industry cooperation, doing some common sense things that, because by doing it, it speeds up the adoption cycle of these kinds of technologies. I think what they're trying to do, and they're just trying to do it.
It's, they got a long path ahead of 'em. But what they're trying to do is the least intrusive thing that government could do in the cybersecurity market. Forcing transparency is pretty much fair.
Like companies, if they just disclose what they're currently doing, that's all we're asking. And that, I think that's a fair ask. I get much more concerned when they start talking about software liability, uh, because that's gonna create a whole regime of insurance and lawyers.
Lawyers, I mean, lawsuits and negligence. Unfortunately, I think that's what you're gonna see in this cut start trike thick, right? The lawyers are involved.
The guy from Delta wants blood. Um, in my mind, ula right? I don't think you got it.
That's a case. But in any event, I I do applaud them. The other thing I worry about, quite frankly, and I'm not looking to get into politics here, but ceases and agency, a government agency, these guidelines and, and edicts they're putting out, do not have congressional approval.
That's right. So, you know, according to the latest Supreme Court rulings, these agencies Yeah. Have overstepped their bounds and Right.
And so is it gonna be enforceable? Is it gonna mean anything, is when the next administration comes in? And again, I'm not getting into politics, but if they, if they change things, does this roll back?
We can't have a a a a CSA CHACHA one step forward, two steps back. I think though, the, like, like even just on the SBO front, like it, it's gotten to the point now, like, like SBO saying, the word sbo M isn't something like that. Somebody goes, what?
Like, when maybe when you say a DR, we're still getting the, like, what are you talking about? Conversation. But when you say SBO m now, like most people know what you're talking about.
Both, both organizations and, and in, in, in the industry. And I, I, I'm hopeful at least that like we've come far enough as, uh, you know, as an industry and acknowledging that like this, even if SBO m and some of the stuff that we've put in place with like CISA and the, like, it doesn't end up being the way that it is, and then that it's regulated, that the, the underlying concepts of software transparency and, and the need for it will still like, continue to move forward regardless of politics. It's a fair point.
There's massive, uh, energy trying to stifle transparency because, you know, it's really not in a lot of company's best interest right now. Right. Uh, I think it actually, in long term it would market, but it's not better for an individual company who has to disclose stuff.
Um, look, I Give you here is, do you remember the fights we used to have over responsible Disclosure? Oh, sure. Right.
Everybody, you know, now we look at it and say, of course you do the, you don't just release a, uh, a bug until you've given coordinated notice. Right. Coordinate, let's call it that.
But there was a time where that wasn't that so such a clear understanding. There were people who argued, you know, No, keep it, keep it quiet so the developer or the the attackers can't get ahold of it. Right.
And, you know, and so the all will exist there for 12 years until one day I think transparency is unstoppable. I think it's like a thread. You start pulling it and you realize once you get the S bomb, you're like, wait a minute, this is just a list of ingredients.
I don't know what the actual thing is. And I use this analogy of like, uh, you could give me the same ingredients as my mom to make an apple pie and mine's gonna come out garbage. Hers will be beautiful, But I'm living, what Matters is what you do with the ingredients.
Right? And so, like, then you ask this, start asking those questions like, well, what did you do with the ingredients? And, you know, what's your threat model?
What are the defenses in place? And like, so people are starting to pull that threat and vendors are getting pressure. We get asked for our SBOs all the time, really.
And yes. So we, we deliver SBOs with everything. I I was just gonna say you, I, I don't see anything wrong with that.
No, we're happy to, to disclose that because we're really careful about it. But there are a lot of companies that they have a lot of backlog. Okay.
And then if you have a backlog, you can't, it's hard to be transparent when you've, your house is, But this, that's a great, a great saying. I'm gonna steal that. Um, it's hard to be transparent when your house is dirty.
That's right. But it's the truth too. It's so dead on.
I mean, a lot of these companies, you know, it's the old saying, if you didn't have anything to hide, you wouldn't worry about that illegal search and seizure. Um, but a lot of companies do have something to hide. Mm-Hmm.
Oh, I, I, I just, uh, I've just done a recent survey that is to be published by, or questions around, like, I, I asked explicitly like, are you releasing applications into production with known vulnerabilities? And like, what's the top reason for doing so? And the percentage that replied that they're not like, we never do this very low.
And then most of the, and they're lying was lying 2% that supposed, you know, you know, whatever it was we're lying. But like the top, it's all business. The top response was, you know, there's a business demand for this feature.
The business need trumps, and that's got a sh that's gotta a shift. And I think transparency's all a big part of this. He could try to mark up those vulnerabilities with Kev and say, well, it's not exploitable and happen, but it's really hard that like Kevs are, are a good idea, but difficult to implement.
Mm-Hmm. You know, I'm gonna tell you, I remember I did a podcast 2008, 2009, that area, that timeframe. I had the CEO of Mongo.
Oh yeah. And the CEO of Couchbase, I think Couchbase had just merged, was Couch and something else. Anyway, NoSQL databases are all the rage.
And I asked both of them, I said, Hey, a lot of people say no, SQL stands for no security. 'cause I was younger than, um, I said, what, what's the deal with security and your database products? And I'll never forget this.
They had, they actually had the nerve to say, look, we'll, we'll put in better security when our customers demand better security. It's, you know, it's not a crazy point because that's, that's really what the CISA security by demand is trying to encourage is the market has to ask for it. Right?
And, and one customer in a market can't ask for, but when the government says, this is what you're going to do, it carries it, it accelerates what would take the market five years. They're trying to standardize how to ask that question. Because right now people don't ask.
'cause it's complicated to ask the question in a, in a fair way. But it will put some burden on, on vendors to be, to produce the information. But if it's all one standard, you know, Hey, hey, here's like my 10 questions I want to know.
Like, Well, and that's why yes, it'll put burden on, on vendors, but if you could standardize it, everybody's the better for it. And, and look, I, you know, from your mouth to God's ears, I hope it works. Anyway, enjoy the rest of black hat.
Right? We've got another full day of this, of this. You doing anything exciting tonight, guys?
It's always good parties of Black Hat. I've got some parties, but I'm also meeting with my whole team that's here and, uh, pull the team together. 'cause that's, uh, it's hard in the Covid era to get your whole team Together.
That's No, I know. You gotta take advantage of those moments. Yep.
What about you? The, the, the wonderful, extravagant, crazy life of the analyst. What do you got going on?
A nap. A nap. 10 hours of meetings Probably to write some research Reports today.
I do. I do. I, the, the, the backlog is long, so We're Waiting to join us for dinner.
Yeah. I appreciate It. We were, we were supposed to be going to Rod Stewart.
He was playing tonight at Caesars. And I just got an email before you guys came up. He has strep throat.
Oh no. And the show's canceled. Oh no, Ed and the, you said the spear?
No, it said Caesars. Oh, okay. All the sphere the dead are playing their last Kel home.
So had I known that I would've stayed till Friday instead of going home tomorrow. Yeah. On Bridge Breakdown.
And my dad, my dad, dad, I Was, I called my wife. I was like, why don't you jumping on a plate? I like cancel and we'll stack.
She was like, no, you gotta come out. But anyway, uh, enjoys it. Enjoy.
I have a lot of friends who've gone to the show. It's amazing. I've heard, I I I myself am am not the dad.
My dad that is joining me is the, I can't Tell you. I can't wait to see. Every time you say your dad loves this, I'm thinking send him first, Shut him out, whatever it is.
Like, you know what? I, I've been following. You're trying to be daughter of the year here.
Come on. You're Doing good. And your dad's gonna love this show because I heard they're playing.
Yeah. I'm looking forward to it. They're Really jamming out and, and that whole experience in there is, I've heard of Amazing.
John have three fingers now. I know. Oh, wow.
He crossed a finger in a car. Yeah, He did. But he's still amazing.
I, I, I have friends who've been out multiple times and seen multiple shows of it. Every show is different. Uh, cool.
Enjoy. I'll report back. Yeah, please do.
This is their last weekend. If you don't catch 'em this weekend, that's it. The residency's over.
Well, thank you for doing this, Katie. Thanks Alex for us. Thanks for having me, both of you.
This was a pleasure. I'm Supposed to thank you. This is Fun.
Absolutely, Jeff. It's always fun with you, man. Thank congratulations on the lunch of a DR.
It's an important thing. Katie, a pleasure meeting. Always.
Yes. Keep in touch with us. Well, you're welcome to come on anytime.
We always Talk. Great. I appreciate it.
Love being here. All right. This is Alex Shemel for Text Drug TVs.
Thank you. Stay, take care.