Myrror Security’s Yoad Fekete Addresses OSS Supply Chain Attacks
The rising rate of open source software (OSS) supply chain attacks poses a significant threat to enterprises’ software development life cycle (SDLC). Yoad Fekete, CEO and co-founder of Myrror Security, discusses these attacks’ impact on businesses and the broader implications for the software industry. The Myrror Security platform seamlessly unites the two essential pillars required to effectively address these threats – the detection of malicious packages and CI/CD attacks and the prioritization of known vulnerabilities.
Transcript
This is Textron tv. Hey everyone, welcome back here to Techstrong tv. I'm happy to have, I think this is his first time on Textron with us Joad fete.
If I mispronounce I messed it up, I apologize. But Joad, welcome. How Are you?
Thank you for having me. I'm perfect. How are you?
Excellent. It's great to have you on. Uh, for those who are wondering, Joad is the CEO and Co-founder of Mira Security.
And, and before we even go there, let me just tell you that Mira is spelled M-Y-R-R-O-R, so not Miro like a looking glass. It's Mira, M-Y-R-R-O-R. Maybe we'll find out what, what's behind that name.
But, uh, Joad, let's, let's first start with you, give people a little bit of your own story. Sure, sure. So, um, my background is technical, um, fortunately and unfortunately, but, um, I've been in the tech industry for about, uh, 12 years.
Not the usual suspect for Israeli founders. I served in the artillery forces. And then, So you are in 8,200?
I was in 8,200 as a citizen, which is, uh, I just, you know, I was, after the army, I started, you know, working, I'm a musician in my past. Okay. I started working in music for a couple of years, and then I rolled in a, we don't have time from that story to the tech industry.
Um, started from, you know, um, old space of, uh, on-prem data centers, uh, virtualization, you know, the old stuff. And then slowly migrated to cloud. And then I always wanted to do the 8,200 stuff, you know, because it's, I was curious about that.
And then I figure out you can, you can do it as a citizen, so don't tell anybody, but you can do it. So I served there, uh, in one of the units for, uh, three years, so worth it. Uh, so lucky to have, I'm privileged to have done that and slowly migrated as I mentioned, to, to DevOps DevSecOps.
And, uh, yeah, in my last role, I, uh, was at Microsoft. Uh, I, I led a group of DevOps engineers at the cloud application security group. So fortunate, all in all to, to, you know, to have my, uh, experience.
Absolutely. That's a great story. security.
So Joha, tell us, tell us a little bit about mi Like, let's start with the name, The name. So, uh, the name was Blind Spot at first. What happened?
What happened is that we were, um, too slow to register the trademark, and we've been at Black Hat in August, and, you know, I got an email from a company, uh, saying that, you know, I, we, they registered, they saw us at, it turns out that we had, uh, some exposure, black hat, and they told us, listen, we guys, we, uh, we have a product called Blind Spot. And then we said, okay, we either gonna fight it or we're gonna change the name, right? So then we said, okay, we don't wanna be actually blind spot.
We wanna kind of, uh, do a mirror, like you've mentioned, it's a mirror. But, so our technology, we built a, a tech, a unique technology that can actually reverse a binary and compare it to the source code. And then you kind of have your binary in a mirror to the source code.
And then we took the approach of, again, don't get involved too much in trademark problems. And, um, mirror with a y like a lift with, with a a y, right? So that Uhhuh sense of people have traveling in you.
So then it's kind of a reflection of your source code and your binary in one word. I love it. I love it to reflect your code integrity, right?
Mirror. That's, that's a great story on that. Um, so how, how did you come to by and by the way, I had a similar experience.
You know, I wasn't doing this forever. I, I've done venture backed startups most of my life, and we also, we had a product back in the early two thousands. It was in IPS intrusion prevention.
I'm trying to think. I think we called the border guard. And, and all of a sudden one day we got a letter that some company somewhere in Washington or something named Border Guard had been around.
No one ever heard of them, but nevertheless, they were there and we could afford it, but it was just easy. We When was that? When, when, when was that by the way?
2004. Got it. 2005, something like that.
So not, you know, uh, not too early, but, uh, today there's, you ca there's no new space left for new names anymore. It's like songs, right? No.
Every song time does sound the same, so, yeah. Yeah. And it's great.
And then you get sued that it was based on that. I mean, look, it was a different world back then. org, that's all there was, right?
org unless you know it, it was a different world. You're right. So let, let's talk about, I, I assume you're a co-founder, so there's another co-founder, but you guys, whatever the name of the company was, felt compelled to develop something that was gonna help with code integrity with, with, you know, security of code.
It's kind of in a DevOps setting, pre pre-deployment kind of stuff. Yeah. Right?
Yeah. Um, so it was, uh, you know, 2021 and you can go with, uh, presentation and get money, and that's, uh, no, I'm kidding. The reason we, the reason we started the company is because, um, Microsoft was one of the companies that's been hit by the SolarWinds attack.
Yes. And my team was part of the incident response team. And, you know, post the attack, we were looking for a solution to do couple of things, one of them to be able to detect attacks originating from your open source, or if somebody attacking your own CICD pipelines.
And the second thing was, we spend about 50% of her time on vulnerabilities with no context. Um, and I hate my manager for that until this day, but it's not to blame. So those two main problems, those were something that we really wanted to solve, and we spoke with a lot of, uh, security, um, professionals, uh, practitioners and executives, and we understood that it's a real problem putting aside the solar weeds poster, right?
That's, that's one thing. But we understood it. It's a real concern, and that's why we started the company.
That's great. You know, I I, it, it kind of boggles my mind that we're seeing companies that have come up as a result of like the SolarWinds breach, right? So I remember sitting right here in this studio, it was already Covid time, and I, I guess it was around January of 2021, wasn't it, that SolarWinds first kind of became public.
Yeah. And, um, you know, and, and, and here, here's a company, you know, built up, built up as a result of that. That's a, that's a great story.
So, you know, when we look at the solar wind attack, and that kind of does kind of start, you know, it's kind of the BCE versus, uh, after, right? B-B-C-A-D. So when we look at supply chain attacks, software, supply chain attacks, unfortunately a lot of those attacks are based on open source vulnerabilities.
Now, I, I've been a big open source supporter for a very long time, and I was always of the opinion that the open source code would be more secure because there's more eyes on it. You know that argument, right? It's an old argument.
Yeah. The fact of the matter is, it's not necessarily true. I don't think today we realize, I think that open source software is no le no more secure than commercial or close source software, right?
Software is software. It has vulnerabilities. Um, I think people are just more aware of open source software now and that there's so much open source software in, in the code of these applications that it becomes like the low hanging fruit.
I'm wondering, like what, what's your, what's your opinion on that? Um, I think you basically covered everything because you're right, um, my opinion was as well, you know, there's, it's open source, so you can have more eyes on that. And I think the statement, it's true when we're looking at the code itself.
So we do have some protests where, and some script kitties that, you know, try to upload malicious packages or try to inject, uh, you know, malicious source code in the actual code base. But those kind of attacks are easy to detect because you immediately see them in the history of your GIT repository. Mm-Hmm.
And I think the me the mechanism of on the source control management today are good enough. You have two peers review, you can't really push code. So sometimes you have some kind of an Easter egg, uh, that people try to push, but it's hard.
So that's why we kind of saw the shift and evolvement of attacks and it's shifted. It's still on open source, but it's on the process. So it's on the CICD process, it's on, uh, um, on the actual package repository, on the developer, maybe attack the developer and upload a malicious package.
So that way you are attacked and you don't see, you don't see it in the code base, but the attack might be on the final package. So that what happened to SolarWinds, that's what happened to ua parser coa, js, rt, RCJS, jump cloud in another scenario, right? So quiet, quiet attacks that is, are very, very hard to detect, either originating from your open source or your own CICD pipelines, You know, a lot of those attacks you mentioned.
So phishing is part of it too, right? You need to get access to the, to the code in order to be able to do that. And, and that's how a lot, and, and by the way, a lot of the ones you mentioned are, are nation state, sort of perpetrators, not just, uh, You know, which is crazy, right?
I mean, a 600 com like people company being attacked by a nation state, Korean force with, you know, you, you wouldn't imagine that could happen, right? No. But you know, so, so in the case of JumpCloud, for instance, right?
My friend's, the CEO, there, they, and they, I, I advise them on disclosure for that right? To PR for it. And, you know, they were pretty transparent about it.
That whole attack was around reaching a handful of Jump Cloud's customers. Yeah. JumpCloud was the mean to the end, the means to the end.
Yeah. They went, there was a few customers that they specifically were targeting. And I think that's what people need to realize with the software supply chain attacks is this is not code red worms or something like that.
You know what I mean? These are very, as you say, quiet targeted attacks with a definitive goal of who they want to get into, who, what, you know, what information they want to do, what damage do they want do. They're very targeted, very specific, and, and, you know, they just use these, I mean, and that's why though, case of SolarWinds a perfect example, right?
What is it? I dunno, 480 of the Fortune 500 use SolarWinds. And then, you know, because of Microsoft, how many other companies were exposed to this?
How many were actually attacked as a result? A handful. Because it, it, it it's targeted like that.
And I think people, you know, it's another thing to realize, but, you know, you guys started mirror security as a result of this and, and Yep. You have a new defense strategy now for this Yeah. Against this kind of thing.
Let, let's hear about that. Ya. So I think, um, a lot of people are familiar with the kind of, uh, salsa and attestation that's been around for the past Sure.
Uh, couple of years, right? And the, basically what it says, listen, we need to implement, um, some kind of framework on our open source to be able to trust it and make sure we kind of put gates and trust mechanism along the way of the open source package stages. And we sign each step and then we know, okay, the final package is proven to be, uh, uh, compiled from the source it's meant to be.
The problem is that, is we can't really require open source vendors to do that security for us, especially when it takes time and money. So we as a company, as Microsoft, as other organization, we have money for security, we have time for security, or we have people for security, open source suppliers, they don't, they do it voluntarily. So I think us as consumers, we have the responsibility to verify that the problem.
How do you do that? It's like, uh, am I kind of, uh, how I like to, uh, put it is, think about it when you have to, uh, kind of, uh, shake hands with a hundred of people. So you can either count on them to wash their hands at home, or you can put a, um, a soap and water, uh, next to you before they wash your hand.
So our approach is to verify on the, on the consumer, and you say, how would you do that? Like, independently. So we build a technology that can actually take a compiled product, a build software decompose that run models, and those models, uh, know actually how to compare it back to t trace it back to the source code, and then if there's something in the end result that isn't found in the source code, we have a problem.
And that's the strategy. That's our main strategy. So how, how does this play with SBOs?
Good question. So the whole, the whole SBO thing, right? It's, uh, it's a shenanigan because you don't really know, um, you can, you can export SBO m from a repository, um, you can export it from binary, you can export it from runtime.
Where do you get the asbo? What, what kind of information do you want to SBO to actually contain? Because you might spend a lot of time on SBO m So as we see it, the SBO should be as concrete as possible.
So first of all, be focused on actually what you have. That's one thing. See if it's exploitable, see if it's dangerous, if you need to do anything with this.
So when you, uh, produce or digest sbo, and we have a lot of, you know, um, products in that space, you need to be really concrete about that. So the way I see it, when we export asbo today, we enrich it with the information on the packages themself a after our verification. So is, has it been tempered?
Does it contain malicious code on the source code? Is it exploitable, is it reachable? And then we, you can provide that information to your, uh, customers and kind of make a statement of why you do or don't do something with that in terms of fixing or not fixing that.
Love it. You what? We're almost out of time.
Last question or last topic more than a question I'd like you to address is for people out here who say, you know what, this sounds good. I'd, I'd like to check it out. I'd like to try it.
What, what's kind of the on-ramp for mirror security? How do people engage with mirror? So you can just, you know, uh, on the website you can send us a message.
You don't even need a demo. I mean, I don't want, I don't like wasting people's time. We open, we onboard like independently, so we can, uh, send you an invite link.
The onboarding is really five minutes. We integrate with most systems out there today. And you can try out the product and, you know, compare, use and don't compare.
Do whatever you want. We give you use cases, we give you guidance on how to use the product and you can see, uh, and test how we protect you from vulnerabilities and attacks all at once. And that's it.
security. security. Yes.
Yes. Alright. Right.
Joad, thank you so much for coming on and, and giving us a little education here today. Keep up the work and come back and keep us posted. Thank you so much.
I appreciate, uh, the time and the opportunity. Our pleasure. Joad.
Let's see if I say it right. Joad? Yeah, You go.
There you go. Yeah. CCEO Co-Founder Mirror Security.
Here on, on, uh, text Drug tv. We're gonna take a break. We'll be back with another guest in just a bit.