Open Source Software in the Face of Cybersecurity Challenges – Cédric Gégout, Canonical
Cédric Gégout, vice president of product management for Canonical, dives into how enterprise IT organizations should assess open source software projects in light of recent cybersecurity concerns.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Cedric Gaje, who's vice president of Product Management for Canonical, and we're talking about open source in the enterprise, which is a hot issue these days because everybody's talking about open source software security and where it fits in the supply chain and what we need to do about all that.
Cedric, welcome to the show. Welcome, and thank you, Michael. Thank you for hosting me for this, uh, this meeting.
What is the current status of things, because there's a lot of concern, obviously. I guess my first question always goes to, especially among enterprise customers, how many of these folks would be using something that wasn't curated in the first place, and doesn't that kind of mitigate a lot of the risks that we're seeing versus how many folks out there are just kind of downloading raw bits where they ever find them, which seems to me maybe, you know, a little dangerous. Hmm.
Yeah, I, I think, look, let, let's step back a bit on why people are doing open source and why it's important in the enterprise domain, right? I think, um, since the emergence of the cloud, et cetera, I mean, all the major, uh, cloud providers are, are heavily, are relying on open source software and open source really serve as a catalyst for growth, providing different avenues for promotion and commercialization of the open source effort, right? So it create obviously a large incentive for starting new open source project.
And many projects that emerge accordingly, were actually the most successful ones, right? Speaking about OpenStack, Kubernetes, Terraform, and many others, right? And this dynamic is still in action, and don't expect this to end, I think open.
We are just at the beginning of the open source era, and I think every open source will be everywhere and everywhere. Everything will be open source. Right now.
I think there are a lot of, I think, concern about if open source is actually evolving now it's DeVol and it's actually reaching a big crisis. Uh, we'll discuss about that. But I think, you know, there were a lot of challenges for open source, and you mentioned, for instance, security.
Uh, we, we, we, we can discuss about also the, uh, competition, uh, how our open source and competition, uh, can, uh, work together. Um, I think fundamentally all those people, you know, need to work together, cloud providers, vendors, open source platform providers, such as us, and it cannot be done, you know, without friction because we have different objective and business objective. So how everybody can work together, you know, it's just a matter of learning how to work together.
I can say that for us in canonical, we were always for two decades working the same way, trying to amplify the open source, trying to build enterprise software on top of open source, but respecting all the communities and to be sure that all customers, you know, can really enjoy open source in an open manner. And that's key, right? Because at the end of the day, we can discuss about it as well, but being locked into a specific technology, even though it's coming from open source communities, it's actually a, a bad thing, right?
You, what you really want is, as an enterprise is to be able to use open source in a open manner to be able to switch one another technology, one of the vendor, if you believe that the, you will have more value working with another vendor, how this can work, you know, it's a difficult thing to where we, we are so we are trying to solve, right? So none of these issues appeared overnight. We've been kind of dealing with this for the last decade, and they probably won't be solved overnight either.
But from your perspective, what could the ecosystem be doing better? I mean, there was a meeting recently in Washington where everybody got together and kind of talked about the progress they're making, but out of that and what you're seeing from where you sit, what could we be doing? Well, uh, look, look, I, I will not advise other companies.
They have their own business, their own maybe, uh, uh, way to approach the, the, the business, right? I mean, in, again, in canonical thinking about what we, uh, I believe is important is that first open source really nurtures the competition. And it, because it's a powerful innovation force, and by by nature it can create competitions, you can, uh, and we are contributing to some open source, uh, software that are used by our competitors.
And that's great. That's great because we have feedback from other enterprise saying, okay, you know what? We're working with one of your competitor using this technology and then using it very, very nicely.
And maybe you need to learn from that. And, and I think this is, this is this position that everybody needs to have, right? I mean, I'm not, I don't want to give advice for others, but just by experience, after two decades, uh, KO was one of the pioneer in term of, uh, uh, Linux distribution with Ubuntu.
Right. And why are Ubuntu communities so vibrant today? And is Ubuntu is more the most used, uh, Linux distribution in, uh, uh, in the world?
Well, it's because, you know, we, we are welcoming any improvement, any contributions to, uh, to Ubuntu. And, uh, our job is to make sure that enterprise can use Ubuntu safely and with, uh, with trust. Do organizations need to look harder at the size of the community before they jump into open source software?
Because what we saw saw with something like Log four J Shell was there was only a handful of maintainers, and they couldn't handle the patch requests and what was needed immediately. And so that became a pressing issue and, um, arguably led to all the conversations we've had in the last year. But, um, is that a bigger factor in the decision as to what you should and should not be using?
That's a very good point actually, because it, I think it's echoing also the, what I was trying to say is that in the sense that when you are using an open source, be careful that it's open source as a vibrant community behind it. Uh, because if you have only one actor trying to, you say, okay, I develop an open source, and then for example, I'm developing an, an enterprise edition, then fundamentally you have only one actor, right? And it's a very complex ecosystem.
You know, we used to say that one open source project usually have a dependency with more than 60 or sometimes 70 other open source project. It means that if you want to fix by yourself something, you have to manage all these complexity of dependencies. And if there are CVS can be, you know, uh, uh, vulnerability can be with low severity at one time and one month after can be high severity.
So it's evolving so fast, it's, it is moving so fast that we, we, you need to have actors which are taking care of all this complexity and trying to be to, to, to develop enterprise edition or at least software, which is stable enough for the enterprise to use, right? And this is exactly what the open source platform providers, such as canonical and others, right, red, that et cetera, are trying to do, right? So our job is to, um, be sure that this kind of event that you mentioned before, will, will, will, will be mitigated first, and, you know, for the future should not happen, right?
But I think there are a lot, you know, if you look, uh, uh, about the evolution of the progress that the open source community did starting for Log four G event for instance, it's huge, right? I think now at least the communities became more mature. They know how to handle those kind of vulnerabilities.
They know how to contribute together to collaborate in order to fix issues in a, in a, in a better, uh, uh, uh, pace. So I'm very, very confident to be honest about the, the evolution of the open source. Now, yes, again, there are discussion about what, what should be the right model.
You know, on our side, we, we, we have the right, we, we, we built for more than two decades a fruitful business model, uh, that is, uh, and, and we believe this is the right one. What's your sense of how sophisticated are the bad guys right now? Are they targeting vulnerabilities and open source software?
Do they have the tools to scan for that? Or is this much more of a, an ounce of prevention in the hopes that we don't have to deal with a pound of cure later? But I mean, how serious is the threat?
Well, more and more, you know, those black guys, s uh, rogue developer, uh, are becoming, I will say, smarter, smarter and not because, not because it's just open source, right? I mean, they can, it's, it's, it's, this can happen also with proprietary software. It's just that now they have more, more and more powerful tool.
And especially with AI and generative ai, they have more and more tools to understand the complexity of the, of the, of the, of the software, and to be able to exploit small vulnerabilities and then to increase, uh, the, a risk by, by, uh, uh, making is exploit more and more sophisticated, right? Our job actually as a open source platform provider is, and building a distribution such as, uh, uh, all two, is actually to put all the DevSecOps controls to be sure that we are taking care of all the dependencies I've mentioned, also, to be sure that we are scanning everything and, and, and take and, and, and, and evolving at the pace that is required for the business. So, you know, before it was, uh, um, I will say two or three years ago, you know, we had sometime critical cvs coming every, uh, uh, every month, right?
Some something like, I don't remember exactly the numbers, but it was something that was, that was, uh, acceptable. Now we have zero day attack things where we have to, to, uh, to be able to, uh, to, um, to cover and to mitigate very quickly. We have hundreds of cvs criti, critical cvs on one software in one month.
So in order to, uh, to, to, to solve those issues, what we're building is a infrastructure, again, based on ai, based on, uh, on collaboration with other open source, uh, uh, uh, communities and open source vendors who are trying to build a network, an army that will be, uh, that is stronger than the the whole army, right? And, and, and it's a, it's a race, uh, obviously, and something that will be, probably will never end. But, uh, actually, I, I, I can state today that open source software can be perceived as even more secure than, uh, as you mentioned, software, which are managed by only one actor.
As we go forward, um, there's a lot of debate about liability now and arguments where rules from the European Union talking about even individual maintainers may be held liable. Um, is that the right way to go, or do we need to hold the liability somewhere else? I mean, is it in the hands of the organization distributing it?
Is the hands of the user? What's your sense of where are we on that conversation? There was, you know, especially with L L M, right?
Large model, uh, large models for ai, uh, I think it, it makes sense that the regulation are trying to, in a way to regulate what is happening and to protect them, the, the, the countries against, uh, software which are becoming sometimes, you know, uh, a weapon, right? But the way, the reaction today is a bit, uh, um, uh, extreme in a way, right? The, it seems that the, we, we are trying to, to, to, to, to, uh, activate some protection without really thinking on the impact of them.
Again, open source is working well, and it's a secure software I, we just discussed, and it's very, it's a very powerful innovation force because we have this collaboration across the globe. If we're trying to protect something by limiting the usage of open source or trying to limit also the innovation of others, right? The reuse of soft open source software elsewhere, actually, we are damaging this, this, this innovation force.
And at the, ultimately, it'll, it'll be even worse. I think we, when all the regulator really needs to understand the dynamic of open source and really try needs to learn how to make this open source maybe more trustable, I mean, maybe more secure or something like that, but doing so again, they need to, uh, to make it probably more open, uh, and more, um, uh, and, and try to reinforce a good collaboration. So, so I think from now I was very sur uh, I will say surprised to, to see some, uh, actions that was taken by some regulators, um, which are against, uh, that, that ultimately will be against what they expect to do, right?
So, so I think it's also, or I mean, our mandate, right? As a professional of the open source to also communicate with them to exchange and to help them to build the right framework around it, right? Um, and I'm sure they can, right?
For instance, a very good example, very good example of regulators that was very aligned with open source approach and was very, uh, uh, uh, was not limiting the use of the opensource G D P R, right? Or C C P A, right? Or, or all those regulators, the regulation, uh, we can think as discussed also about P C I or sox, et cetera, right?
All those frameworks where actually very powerful and are very powerful because they were built in a specific way, in a humble way, I will say, without trying to limit the usage of open source, but more to dictate or, or, or to guide how to use the software, uh, better, right? And I think this, this is, this is what the regulators, uh, should continue to do instead of trying to control, uh, how, uh, open source vendors should work together. What's your best advice then to the average enterprise, many of whom are getting criticized for using and benefiting from open source software without contributing back to the community enough?
And I mean, should they set up a, an office of open source consumption? Should they be funding projects, contributing developers? What's your sense of what is the obligation or commitment they should have?
So it's, it's, as I said, right? It's, it's really about how we can work together, and then obviously it comes with some frictions because sometimes objective are not, right? So, so this, this is life, right?
So we are, people are just learning and trying to, to, to adjust, I think, again, in the same manner as what I said, right? I, it, it'll be diff it'll be, I don't think, I think it'll be a bad move to try to regulate this or this dynamic. If some actors are using open source, our buildings opera, uh, software with it and, and, and, and they're making money with this, fine.
I mean, what, I mean, I'm, I'm not, we are not trying to, uh, judge them and say, okay, you are doing a bad thing or a good thing. At the end of the day, the market is the ones that will judge if it's a good approach or not, right? And we see that some actors, uh, actually are uh, uh, moving away from some this, this kind of, uh, behavior, right?
And trying to go to the source of where the open source is built, right? For on, on our side, you know, we are, as I said, we are working with Open two community. We are trying to amplify, uh, the usage of this open source, right?
Trying to help fixing by fixing and creating orchestration and, uh, combining different open source software. We're trying to make this open source enterprise version for the, for the, for the enterprises, right? But we're not trying to, uh, denature the software or trying to steal software from models, right?
And, and I think for us, we were, as I said, we find a fruitful business model and, and a collaborative model thanks to that. And I believe that ultimately the market will decide and we'll, we, we'll take the, the most, uh, fruitful and, uh, beneficial, uh, model because they need it. All right, folks.
Well, you heard it here. Basically when it comes to open source, it takes a global village and we are all interconnected and we're all working together one way or another. Cedric, thanks for being on the show.
Thank you, Michael. It was a pleasure. You, And back to you guys in the studio.