What’s on the Horizon for Cybersecurity and Open Source in 2023 | DevOps Connect: DevSecOps 2023
Katy Craig, adjunct faculty at National University, Jennifer Czaplewski, Sr. director of cyber security solutions at Target, Kadi Grigg, developer advocate at Sonatype, and Mark Miller, founder and executive director, The Sourced Podcast Network, discuss open source and cybersecurity in 2023. The panel covers a wide range of topics, from AppSec, to generative AI, to the intersection of technology with everyday life.
Transcript
This year, I want to take a review of what has happened in the past year as far as cybersecurity and open source news. So we've got two journalists and a practitioner here that are going to give you kind of their insights on what they have looked at in the last year, what has interested them, and, and they followed up on. And then what they're gonna be looking for this year, what kind of things they're working on.
I am the, um, the founder and CEO of the Sourced Network Productions, which has four podcasts. And so for the, one of the podcasts is called 5 0 5. It's 5 0 5.
And every day at 5:05 PM we do a roundup of the cybersecurity news. And so the panelists today are gonna be talking 5 0 5 will let them introduce themselves, but this is where they're getting their information from. It's the research they've done for their sessions.
So, Katie, let's start with you real quick. Just a quick hello and who you are. Uh, my name is Katie Craig, and I'm currently serving as an adjunct professor at National University.
I'm also an independent consultant. I've been practicing cybersecurity for, oh, a couple of decades now. Mm-hmm.
And I'm really happy to be here with you this Morning. Good. Thank you.
KD with the d I know, I feel like I should have, uh, put Jen in between us, so it wasn't so confusing. But yeah. My name's Katie Grig, um, and I'm a developer advocate at Sonotype.
And, um, I've been in tech for about 10 years now. And I am Jennifer Leski. I'm a senior director at Target, and I lead application security and endpoint security.
Um, I don't know, maybe a decade and a half or so in the cybersecurity space. I'm just always really happy to be here connecting with all of you, like we get to do over Here. That's great.
Uh, go ahead and keep the mic cuz I'm gonna ask you first. Okay. All right.
So, when you were scouring the news this year, when you were actually doing as a practitioner, what stood out to you? Well, I think that the concept of security is now mainstream news, which I don't feel like that's been the case. Um, even a few years ago.
Like, things that are happening for my everyday world are now things that I see on the news. And so what I'm thinking about as I read the news is how is this going to affect the people that I support? So if I'm reading application security at Target, how do I support the developers at Target mm-hmm.
And make sure that they're set up to do successful things. So for me, over the past year we're, we were here last year in the middle of 2022, still talking about Log four J. We hadn't really started talking that much about generative AI at that point.
And so it's really thinking about how are we going to make sure that we continue to protect the companies that we support. Great. Does that resonate with anybody?
Yes. Good. Good.
I think similar to Jen, um, while I don't have a team, you know, that I'm supporting and trying to help scale, I, I think it's interesting where tech meets every day, right? Because like she said, it is often, you know, mainstream in the news now. So I have my family who, my mom barely knows how to dial her like phone number, right?
But she's calling me asking like, what is Log for J? Like, is my computer hacked? So I think it's interesting where it's meeting everyday life and then there's things that affect, like, you know, FDA is no longer gonna be accepting certain devices based on cybersecurity guidelines October 1st.
So it's those types of stories I find interesting. It's interesting because the mainstream news tends to blow things up that people, normal people can't do anything about. Right.
What are we doing talking about Log for J on the main headlines? That's, that's an interesting concept, right? Well, for me it's been how can I take what's happening in the tech, um, ecosystem and bring that to the classroom and convey to the students who may have these, uh, traditional, you know, mindsets or thoughts about what developers do, what software developers do, and where cybersecurity belongs.
You'd be surprised how many people come with, you know, these preconceived notions. And for me it's been finding ways to incorporate generative AI in the classroom. You know, let them know about the weaknesses and the constraints of the tools, et cetera.
Good. The, the AI thing came on so fast because of chat gtp, I'm gonna back up a second because one of the things that was concerning me throughout the year was the proliferation of consumer apps breaking down. And the big one for me was Last pass.
What the hell happened with Last Pass? Um, it's like if you're using a password manager and the manager itself can't even maintain safety, where's our confidence in what's going on in that industry? That was a big one for me.
When you guys are scouring the news for your stories each day, where are you looking? Katie? I'll, I'll start with you.
Where do you, where do you look for, for your news? You'll be surprised to hear that I get my news ideas from everything from podcasts to what comes up in my LinkedIn feed to the Drudge Report. Oh, I mean, I scour the spectrum because if Drudge is reporting on something cyber number one, it's usually very timely.
It's usually kind of breaking and it's something that's gonna appeal to like we're talking about mainstream, um, you know, society. It's not necessarily very deeply technical. Great, Thanks.
Okay. I think mine would be similar. Um, there's also, you know, like bleeping Computer Security Boulevard Bleeping computer is great.
I love it. Um, but, you know, I also try to look, and this is gonna sound crazy, but you know, apple News, you can pick one of those headers, so it's like open source or cybersecurity. And for me, I always get interested what actually pops up there and what the level of depth is in those articles and what it's actually highlighting to people.
Because you know, like I said, I'm interested at where it intersects with daily life and I'm trying to see where someone in my family might take this wrong or where you might need to do some education, you know, as to like, okay, it says this, but it means this. So it doesn't mean you need to like put a whole protection zone around your home. Okay.
So do I need to be pen testing my Right. Exactly. So I, for me, that's kind of it.
The interesting thing that we do at 5 0 5, and you might consider doing this yourself when you see something in the general news, don't take it at face value. No, actually go to the piece that they're talking about. I never, if I find something that interests me, I will dive in.
Where did they get that information and new backup and backtrack to where the original source came from. And I think that's important as you're trying to get and wrap your head around daily. What's happening is to go to the original source, The same thing.
You can't always, hopefully it or not, you can't take what you see on Twitter at face value. No. So you have to go digging and figure out what's going on.
So that's where I get a lot of really timely, like what's going on immediately stuff. But I'll tell you, if I'm trying to explain to my family what it is that I do or why I think something is interesting, I don't think a month goes by that like a 60 Minutes isn't doing something about cybersecurity these days, which is so fascinating to me. When I started in this field a decade and a half ago, it wasn't on 60 minutes and it certainly wasn't on a monthly basis, but I love nothing more than sending, um, sort of well done news segments to my family to explain a little bit more about, But you have to take that at face value as well because 60 Minutes just dared an episode about chat G P T that was immediately proven wrong on Twitter.
Yeah, It, it's interesting because chat GTP has literally taken over the media itself. I mean, you, you can't get away from my feet. I'm, I'm just deleting get get rid of this stuff.
But you can't, because what's happening is we're in a transition period right now and it's the hype cycle, there's no doubt about it, but it's still climbing after even this amount of time. I, I think it's fascinating. John Willis and I actually did a, uh, an AI versus human against three of the Chad engines.
So John is, uh, an Edwards Deming expert. And so we asked questions about Edward stemming and we looked at the three chat engine responses, perplexity, Jasper, and chat GTP to see how accurate they were. I mean, I'm thinking about starting another podcast called Expert versus AI because that's how a lot of stuff was wrong, let's put it that way.
It's interesting. Alright. I, I think the chat g p t stuff is interesting to me.
Um, and you know, Katie does a really great job of covering a lot of this stuff. Mm-hmm. But I always find it interesting kind of where that also interacts with ethics, right?
Because you're like, where, where is the line on some of this stuff? So I reported, um, last year actually on a mental health company called Coco mm-hmm. Who was using, um, basically an experiment with at-risk youth who were looking from health in mental health and they ran an experiment and didn't tell the people who were using the chat.
So you're like, is that ethical? I think you crossed a line there. So there's some of that stuff now where there's really no rules on it.
And I think we do need to kind of not only understand the technology better, what it can and cannot do, but also be putting some safeguards around it because I think the whole cocoa thing shouldn't have happened. What do you think about the open letter from Musk and the other leaders about, Hey, let's put a halt on nothing beyond G P T four for the next six months. What do you think of that?
Nothing's grandstanding standing Too late. Jeanie's out of the bottle. Yeah.
Yeah, Yeah. Um, what I'd like to do now is move to the future. Uh, Jen I'll start with you if I would, um, when you're looking at the next six months to a year, where are you seeing the trends go?
Well, I'm here as a practitioner. Yeah. And so for me, whenever I'm here at RSA or looking at Twitter or learning about things, um, as the world is changing so quickly, the other thing that's changing so quickly that comes to mind is sort of remote work and how fast everything's developing in that space.
And so for me it's how do we scale? I'm a, a security practitioner, I love security, um, but it's not really feasible to put genie's back in bottles. And so how do we do things securely and thoughtfully, but also, um, keep up with everything that's happening.
So like thematically, that's what comes to my mind. Like, gosh, how are we gonna do all of this at scale all the time while we're securing it? You know, vulnerabilities are exploding and we're talking about all the different things that are happening in applications.
And so just how we scale and keep up is what I'm really interested in and where I spend a lot of my time thinking without any, you know, magic answers. So scaling how hands please. Who's concerned about scale?
And if you haven't raised your hand, start thinking about it. Go ahead, Katie. Um, I think for me, I'm interested in a lot of the psychology, I think be between why these hacking groups are doing what they're doing, because there really are a variety of reasons.
You know, most recently North Korea has kind of been all over the news and they have a very unique, um, motivation because they are state backed, which is kind of an anomaly in this situation. And it's often, uh, economically driven because their economy is in dire straits. So that's one.
Um, you know, I'd like to, If, if I can interrupt, you did do a segment on that last week, right? I Did. Yeah, I did.
So I, I think trying to understand different hacking groups, but I'm also really interested in our critical infrastructure because that is something we have seen, you know, um, a couple hiccups. You know, we can name the colonial pipeline attack. Um, but then there's also things to worry about, like our power grid, you know, we have 70 year old infrastructure coupled with, you know, not the best cybersecurity practices, and we need to think about these things because if the power grid goes out, what are we gonna do?
So some of those things, who's Worried about their power, But you can apply it to water, right? Like water, railroads, those types of things. So it's A lot airlines.
Yeah. Yeah. For me, going back to the generative ai, I, I'm gonna keep an eye on it because like you said, mark, it's moving, I mean so rapidly.
But what I kind of worry about is how are we going to know what is real or not? You know, in the coming year, if the Pope is wearing a yaga puffer jacket and look and fly, you know, I mean, we see it with our own eyes. It's becoming so believable and so real.
I wonder about my mother, I wonder about some of my elderly relatives. Like, it would, you know, it's totally understandable for them to believe what they're seeing. So, so how do you feel about the Metaverse?
So to me the Metaverse is something separate. It's different. It's about having an avatar.
It could be something that helps close some of the hybrid work, things that we lost, you know? Mm-hmm. That's what I think about the Metaverse.
I don't think it's ready Player one quite yet. All right. Thank you guys.
Thank you very much For coming. Thank you.





