Open Source Security Foundation – David A. Wheeler, Linux Foundation
Open source software (OSS) is everywhere, but unfortunately that means it’s under attack. The good news is that there are many efforts to improve the security of OSS, including its supply chain. David A. Wheeler will discuss some of the ways that the industry is working to improve security, focusing especially on efforts by the Linux Foundation’s Open Source Security Foundation.
Transcript
This is texturing TV. Hey everyone, welcome to techstrug TV for another interview. You know, for those of you who me who watch Tech strong regularly, you know, we've I guess it was last month.
Actually. It was almost two months ago now month and a half. We were down in Austin, Texas for the Linux Foundation open source Summit and we had a chance to talk to A wide variety of some amazing people one of the people we met there and spoke with is David wheeler and I asked I invited David I said, hey, let's continue the conversation.
David is a more than a bit of an expert on the whole open source. Software supply chain, so same and open source software supply chain security at spawns and everything that we've been talking about recently. He's very well.
He'll tell you about his position with Linux Foundation Etc David, welcome back to Tech strong TV great to have you. Thank you so very much. pleasure so David I I didn't want to embarrass you but I didn't you know, right I'm gonna let you tell your road story.
Give our audience a little background about David wheeler. Okay? Well, let's see always hard to answer, you know figure out what what is most relevant but I guess I should start by my title.
Um, I'm the director of Open Source supply chain security and besides filling in some Bingo cards what that really means is that I'm I am a subject matter expert I try to I cannot possibly rewrite all the open source all for out there. I certainly can't change everyone's processes. But what I can do is go out and work with various projects and Foundations to help them improve the security both during development and out when it's an operations because unfortunately the software out there is under attack and we're not gonna be able to convince attackers to stop talking.
So we need to deal with Situation as it actually is the good news is that there's a lot that can be done. A lot of developers really aren't told how to develop secure software and so a good part of my job is doing things like pointing people information to to help them deal with the world as it actually is Yeah, let's see a little bit about me more generally, you know, I have various degrees and such. I've been developer for a very long time and variety of programming languages and I basically just try to show up and ask, how can I help?
Absolutely. Let's be clear. I think we discussed the last time you and I spoke when we talk about open source.
Open source software supply chain security that is not to imply that open source to somehow implicitly less secure than you know closed Source or commercial software software supply chain security is an issue regardless of of Open Source or not. That's absolutely right attackers. Don't care what the licenses they just want to get whatever ill gotten game.
They're interested in absolutely. So I I want to make that clear however, that being said the Linux Foundation the open source or security Foundation beyond that the White House and the federal government and many other organizations and entities out there have really shined the light recently on open source software supply chain security. Because open sources almost a victim of its own success when you have 90% right of organizations running open source and numbers.
I've got synopsis did a study they found 98% of the codeine. He is 98% And by the way, that's the ones they could verify I think that number's low right? Well how much lower can you can only be two percent right?
That's right. But no serious. I mean, you know, this reminds me back in the in the 90s when they said well Max are inherently more secure because you don't see any viruses for Mac.
Well when you only had two percent of the market, right it didn't do attack it but not that Windows was so secure. But you know, the fact is open source is so successful today that it's put a big bullseye on its back in some regard. I mentioned the open source software Foundation ossf.
Yes, open SS. Oh, yes. Yeah open ssf part of Linux foundation and there they really are.
Hey, they're putting a lot of money and resources. behind this cause but as part of that they're really Gathering. momentum and and followers across the world To to address this right, right?
Yep, so that David absolutely happy to so um, yeah, I think first of all you're absolutely right, you know to attackers are attacking open source offers simply because it's it's all over there are potential advantages to open source from a security advantage point. I mean the big potential advantage of Open Source is that anyone can review it? So that anyone can look for problems look for vulnerabilities look for malicious code.
But like many things potentials are not you but anyone who's had children will know the potentials are not always realized. Yeah, so I agree. So the more the time yeah in the world wasted potential and the thing I my kids are awesome.
By the way, this is not meant to be an attack on children. My point though is that potential is not always realize and unfortunately, we're really pushing against a broader deficit that's been going on for decades in the software development World, which is in general. We are teaching our software developers how to write more secure software.
So unfortunately both open source and proprietary software developers typically often don't know how to develop security software the people who review the open source, you know, if they don't know to look for either that mean they can help in other ways, but not necessarily anything involving security because they don't know either. So one, I'm sure we'll go talk about the very specific actions that better being taken but one of the first things that the open ssf did and you can blame me. I led some of the efforts on this is developing courses on how to develop more secure software.
And by the way, the course that the openness is SEF developed called the security fundamentals. It's not specific to use opens open source at all. Right more secure software is a general issue.
It's not really specific at all. But obviously if your developers don't know how to write secure software, they're not going to do it. So we need to make sure that that information gets out really to all developers, but that's really includes the developers of the open source software the reviewers and so on so, you know, if nothing else if you're listening to remember nothing else if they remember hey if I'm a developer I should and I've never taken a course on how develop security software.
org. There's a training tap. You can go click and take it if you manage software developers get them to take a course.
It doesn't take that long. And that's the sort of thing that can give you just endless dividends. Absolutely, you know, David I had a guest on text strong the other day my friend Tyler Joel.
Tyler is a He manages a Dell it's delves VC firm. And I forget the name of it now something like Dell financial investments or but it tells VCR. Okay, and you know, he he just did a study and in his mind.
He thinks we've reached what he calls peak devops in that, you know, we we've been in this agile. world for 20 plus years now and that We are not seeing productivity gains from developers because developers have too much on their plate. Right, and that when we say developers need to learn to develop more secure software developers have to have more responsibility around you developing secure software and Security in general.
We're not doing them any favors because it's already damn near impossible to be a good developer at scale. Right, there are individuals who are but when we look at it as an industry. Yeah, I'm gonna push back a little bit on that if you want to thank you the interviewer.
I actually I agree with the premise that oftentimes developers are asked to do too much. I mean that's you know, I mean, this is the challenge for anybody who's asked to create things is you know, if that you don't have to ask about software, you know, your customers your clients whoever it is who wants but whatever product you're producing they always want more than you can possibly give especially in time a lot of it. Okay, so I don't think that's particularly unique to software at all.
That's it as far as you know, knowing how to develop secure software and actually executing it. First of all as far as knowledge goes, I'm sorry. We should expect not the developers are like, you know World leading experts on a topic, but they need to know the basics.
If you don't know how to use any programming language. You're not going to be writing much software. Okay.
Yeah, if you're if you're expecting to write software to exist in the real world where attackers exist, then you need to know the basics about how to counter attackers now, I'm not taught when we're not talking about. Hey spend the next five years in a class in classes. the fundamental S course we estimated takes about 16 hours to take Okay, it's a computer-based training, you know, take a couple hours a day.
You can wrap that up and knock that out relatively quickly you can there are various courses that go more in depth. But even then we're not talking, you know change your career. We're talking relatively small amounts of time that produce lifelong dividends.
Now it's absolutely true that just learning isn't enough. There's other things that folks need to do and I'm glad you mentioned devops and a lot of folks. Will you say devsecops or SEC devops because you need more Just knowing stuff.
People are still going to make mistakes, even if they know things. but there's things you can do after that the most obvious one is You need to get tools into your CI pipelines that look for vulnerabilities. Will they sometimes miss things?
Yes. Will it sometimes report things that really are false positives. Yes.
That's why you need education. So, you know how to use your tools. Okay, just like a compiler doesn't teach people how to write software.
Okay, you know the tools don't meet you how to write secure software, but they can help find problems that if you know something you can quickly On it and there's other things you can do. I think we I can't remember if we talked about having to go in more depth. But like if you're developing an open source project, there's the open ssf best practices badge, which is basically a list of things that are good things to do and you can say Hey, you know, do you do these things?
You can monitor for the dependent for the vulnerabilities and the code you depend on and make sure you're prepared to do updates because you're going to depend on a lot of other software. That's normal today. It's crazy to try to rewrite the world from scratch.
So it's a lot of the software that you're you're loss offer is soft for you didn't write but soft for you to depend on you need to have tools to warn you when you know a vulnerabilities found. I need your prepared to rapidly update and that means use package managers. Don't try to do this stuff by hand that's ridiculous.
You know manual management of dependency is a parable idea at the scale people working at now. Another is automated tests automate automate automate because when you that vulnerabilities reported, it's not if it's win. You don't know where you know, what's gonna happen?
You all you should need to do is tell your package manager. Oh. Update the package.
I'm depending on it depends on whether or not a library application but these are details. I don't want to get in right now and run your tests. Oh everything works still great ship.
Okay, you're ready to go. But if you're not ready to go then you know, people say oh my gosh. Yeah, there's a vulnerability wanted events these how do I deal with this?
You know, it's gonna take me months. Well, you're already screwed up you you designed your whole process to fail because you know that's going to happen. So you need to be repaired for the things that certainly will happen.
The things you can do to but I mean it's these kinds of things of thinking ahead and being prepared looking at your dependencies before you bring them in being prepared one of vulnerabilities found in them. These are not Rockets. Let me play let me play Devil's advocated we do please do that's the fun part.
So I don't disagree with anything. You said packet management package management. You know getting alerted when there's an update to a component you using or even a whole application or dependency or what have you?
Yeah, but I think when you talk to the average developer, they say look. I developed this six months ago. I'm working on three different other projects.
This ain't on me. This isn't on me. Right this should be the SRE guy or the the devops engineer or someone because all we're doing is updating a library here, right?
And that's right. It is one as the answer is it's someone's job. Okay, okay fair enough.
So when you take developer you're talking about the whole department not the individual necessary. Yeah, I'm telling me anybody who put this and somehow change his software and they can have lots of titles. I don't I actually prefer the word developer because the word programmer often implies some very narrow specific skills, whereas the word developer is anyone who helps develop software and then includes any kind of Maintenance.
Okay. There's a phrase. There's a free time I've liked to use and I want to try it on you as well.
There's only one. Programming the world. It's called hello world.
Everything else is maintenance. Okay. Absolutely.
I I although people usually smile when I say I think it really has a point, you know software typically isn't done in the sense same sense as I built a screw and here's the screw and I don't want it to change. Most software is living it changes over time. And so we need to you that is the way of software and so we need to expect that.
I agree with you 100% Hey, you know we only these these interviews are only 15 or so minutes. I I want to use our remaining time to help our audience you searching some of the training over on open ssf. Can you give me give us some specifics, you know, are these classes expensive are they long?
How how can people get it under their belt? Absolutely. I'm sure I've got we've got people out here who say I would do it if it's not crazy, but what's love?
Okay. Well, I'll tell you what, I mean there's I'm the number one thing is learn. Okay, I'm less focused on what that said.
The open ssf has specifically developed a course for developers people who develop maintain software. org look in the top you'll see a little training Tab and then the very first thing you'll see is secure software development fundamentals courses click on that. Okay, and what you'll find is there's several ways.
You can get the easy way to do it is there's just developing security software. It's called lfd 121. It's completely free.
It costs you exactly Euro dollars. It's computer, you know, it's run completely computer to do whatever Pace you want. Are your own pay so crazy.
Yeah, so please and what's great is that not only is the course itself free, but the certificate you can get from that is free and then you can show people. Hey, I actually Conversionless material right. So let me be clear.
I'm not here. We're not here trying to sell you something or no. This isn't actually don't money for the world should people know because you know, David everyone has an angle right everyone but this is truly something go do this.
It's free itself face. You don't have to do it at a set time do it on your time, but you'll be you'll be better for it right. Now.
Some people have this same with horse materials actually also available on edx. A lot of people like Alex and if you like Eric's great, we make it available in edx. If you want to take it does have a certificate that one does cost money.
So if you want to do it through edx and people sometimes do that's great care for their choice, but that your choice if you do it through the elf trains the same material and that causes nothing but really as I said, our goal is we want to make sure that people learn the information. In fact, we're even if you're like a an accredited educational institution come talk to us. We're trying to get that actually available within the learning.
Android systems of like universities and colleges because we're trying to get the knowledge out to the people who need it. And we fully that's a subject David of are our schools preparing our developers our cybersecurity Professionals for what with what they need to succeed in the market. I have a quick answer for you.
It's the word. No, I agree with you but it's something we've got to keep working at actually jobs open then there's too many people out there. Right just not skilled in the way we need them.
Right and that's not to say that there are there are some awesome people within the College University. I I teach it one so there's some great folks but this is an area where the educate the formal educational system is lagging the needs of society. And so we need to this is a this is something that we need to keep working at.
Absolutely, David. I need to jump off. For our next guest.
I want to thank you as always, you know, you have an open invitation anytime you want to come on we're here. All right. Thank you.
Thank you so very much seeing you David Taylor Linux Foundation open source software security supply chain. We'll be back.