Open Source, Supply Chain Attacks and AI: The Risks and Challenges Ahead – Loreli Cadapan, ActiveState
First, everyone uses open source, that is not going to change. The AST toolset is simply not built to address supply chain attacks, so leaving your pre-build process to chance is a disaster waiting to happen. Second, hackers KNOW that tracking open source components and providing provenance/attestations is difficult. It makes typosquatting and other common vectors even more appealing to target. And third, AI will undoubtedly improve the creation of simple apps, but it will also enable smarter hacks.
Transcript
This is Text Strong tv. Hey everyone, welcome back to Textron tv. I am so happy to have our next guest on.
Her name is Lo Lei Kapen. I, I know Lo Lei a while. Well, she's young, so I don't know her that long, but, Oh, I'm not that Lo I go back a bit and, and LOI is now with a company called Active State, where I have a, a lot of my, uh, some good friends working there, so it's always nice to hear what's going on in the world of active state.
Loi, welcome to techstrong tv. How are you? Oh, good, good.
How are you? I'm great, and it's great to have you on here. Um, I didn't mean to embarrass you about how long we know each other, but why don't you give people a little sense of, of kinda your history?
Yeah, absolutely. Um, while I started off as a developer, I'm a developer at heart, uh, to be honest with you. Um, and so, you know, throughout my career, probably spent half of my time in development, um, before getting into product.
Um, and, you know, throughout the, my career have really kind of gravitated into development practices, best practices and, and software development lifecycle, um, and eventually DevOps DevSecOps. Um, and in my re recent couple, um, lives of my career, I was at JF Rog spent, um, some time there. Sure.
Um, and, you know, saw the, the company go from, you know, an early startup all the way to going public. So a great, great and exciting journey there. Um, and then now I'm at Active State, um, in the same space really.
Um, and, you know, helping organizations secure their software supply chain. Um, and so at Active State, I'm leading the product team, um, and we're super excited, especially around where the space is starting to realize the importance of security, especially around the AppSec, um, domain. And so, and this is a exactly where we are.
So this, that's my short and sweet. No, no, it's, it's all good. And of course we, I, I knew you back in the J Rog days and did great job there, but now you are chief Product Officer at Active State and, uh, you know, not everyone in our audience may be familiar with Active State.
Laura. I, so why don't we, why don't we kind of give them a little bit of an active state primer so they understand. Yeah, absolutely.
So Active State has been around for quite some time actually. Um, but the last, uh, several years we've, uh, focused on open source. So we really help really organizations manage their open source dependencies.
Um, as you already know, open source, um, is a great way to be able to accelerate your development, um, speed up, um, going to market, um, and developers love it. Um, um, but using open source can provide, um, some challenges, especially on the security side and can keep sec, you know, AppSec and security leaders up at night. Um, and this is what we're doing.
We're helping, um, development or, and organizations really be able to tackle that problem, um, and providing them a secure software supply chain focusing on op, their open source use. Um, and what we essentially do is we, um, compile and build your open source dependencies from source. So what that, um, and we're using best practices, um, all outlined by, you know, the secure software development, uh, framework by the nisc.
Um, as well as, you know, the, the recent, um, SALSA framework that, um, has been emerging in the last couple years, um, really using reproducible environments, hermetic builds hermetic environments for your builds. Um, and what that allows us to do is to be able to provide you SBOs and attest stations for your open source dependencies. Um, which is, can be challenging.
Um, there are a lot of tools out there that allows you to provide or to, to, uh, produce, um, um, US bombs or attestations, but when it comes to open source, unless you're vening your open source, unless you're building your open source, it's really ch uh, um, a very much of a challenge to, to, uh, produce those for your consumers. So that's where we're at. Um, that's what Active State provides.
Um, we support, um, different operating systems from Linux to Windows to Mac, um, and really helping developers get through their dependency hell, um, from an open source perspective. Absolutely. Very cool.
And you know, this, this brings into this whole software supply chains and SBOs and everything else, but you guys are using a term three sc Yes. Correct. Ex if you don't mind, you know, share with the audience what, what's three SC exactly.
Um, so it stands for Secure Software Supply Chain. Um, and so it's Threes and a C. Exactly, yes.
And, and look, this is, as you know, Laura, like we do the, uh, DevSecOps days at RSA conference every year, or we have for the last eight eight. We didn't even call it DevSecOps in the beginning, but, um, but it's DevSecOps and certainly for the last two years it's been all about software supply chain security. I actually, active State was a sponsor at this year's RSA DevSecOps event with us.
Yes. And, and they were there. So you saw for yourself it was a decent turnout of people.
Very, very interested in this. Um, you know, I, I don't disagree. It's probably the most important security initiative right now.
It's getting attention from the White House and from the federal government and, and in Europe and and everywhere else. Um, and you know, and one could say, well, it's obvious why, I mean, it's a security issue and, you know, security issues are top of mind, but what are the, the, the factors that are really driving that in your mind? Yeah.
Um, well, you know, there's, there's a few things like I, I could, uh, mention, you know, the enterprise software makeup, um, you know, within your average enterprise software, about at least 70% at least of the source of your software are made up of open source. So a good chunk of your software is really composed of open source dependencies. Um, and you're, as a developer, you're not necessarily, you're not writing those open source, you're relying on the community to contribute on those open source dependencies, um, which is super helpful.
Um, you know, and, and so I think that's part of it is that you don't necessarily have full control of what you put into your software, and hence now you have to put in guards, um, in order to make sure that you're preventing as much as you can, um, from attacks from, you know, cybersecurity attacks and threats, um, from vulnerabilities and so forth. And really understanding where they're coming from. You know, that's where the attestation and Providence attestation is coming in, is understanding that the source that you think you're relying on is actually what you're using, right.
So, um, ensuring that that is something that you can trust, um, especially for the consumers of your software that you're building, um, and providing that trust between your, your customers and, and the vendors. So, sure. Yeah.
I, I think, you know, part of it is really part of that and, um, there are many solutions out there, um, and, you know, some, some solutions will tackle certain aspects of security, right? So you can't just, you know, uh, focus on one, but you have to really understand from the entire software development life cycle, what are the things, the threats that could go along that life cycle and how are you going to prevent it? Absolutely.
I, I think there's a couple of things here. Those dependencies, a lot of times you don't even have visibility, right? Because you have dependencies of dependencies.
Exactly. Right. That, that's how complicated these things are right there.
There's generations. So you may have good line of sight into this particular component, but what you may not realize is that component actually has dependencies on other libraries, on other artifacts, on other, you know, components and and so on and so on. And you could wind up going down a chain like that, down a rat's nest.
Exactly. And it's hard to have that line of sight visibility. The other thing is, you don't Almost all the way down, Right?
It, it does, you know, and so on and so on. And so, like, uh, you know, like the commercial, the old commercial, the other thing is, look, when I, I've been involved in tech obviously a long time and open source for a long time, you know, there was always this fight, open source software is more secure cause more eyes are on it because it's community supported. So it gets tested more, it gets looked at more, it gets, it's, it's inherently safer over the last couple years, 6, 7, 8 years, there's been a little bit of a pushback saying, well, not necessarily because the amount of eyeballs that actually look at the source code or actually doing these tests are, you know, security testing especially, uh, isn't as big as you think it is, right?
Because 98% of the people in the open source community are just, they use the software, they don't contribute, they don't test, they don't, you know, do these things. And, and we've had some high profile open source vulnerabilities struts too with Equifax, for instance. Right, exactly.
That have made people realize, Hey man, you gotta be, gotta be testing your open source. It's not open source. So here's where I've wound up.
Now, open source is not inherently more secure than non-open source, but it's not inherently less secure than non open source, right? Yes. All software needs to be tested.
All software could potentially be, uh, you know, have, have vulnerabilities. Um, yeah. And so I, I think when we look at software supply chain security, we need to remember that we gotta test everything.
Exactly. And, you know, you got companies who, so software composition analysis, right? SCA is, is a thing.
And then you have static and dynamic and there's all these acronyms for all the different tests we use more. Like frankly, part of the problem is how many tests can I run? Yes.
How many tools should I put? Yeah. I mean, you know, cuz otherwise I'll never release anything, but I'll test the heck out of it, right?
Yeah. So where, where do you draw the line there? Like what's too much?
Oh, well, you know, it, it really depends on, on your organization and how complex it is and you know, the scale of your, your, um, your team and so forth. Um, and I have to tell you like, you know, definitely the, the whole transitive dependencies is really does introduce even a lot more challenges in securing your supply chain cuz you don't necessarily have the observability of all of the dependencies that you have, right? You definitely might have visibility on your direct dependencies as what you're saying.
Like, you know, to your point, do you have the visibility all the way down, all the way down to your native libraries, all the way down to your C libraries, right? Yep. Some of the challenges that the s e A tools are, are, are running into is they rely on the manifest files, right?
Yeah. And, and hence you don't necessarily have all of the components that make up that package, for example, right? Um, and you know, this is where, um, other solutions, like active state is looking at it in a different way.
Okay, well, let's build it, right? And, and on top of that, it provides additional security, um, um, benefits which is preventing, um, threats or attacks in the build, in the build, uh, stage of your, of your packages. So, um, it, you know, in some ways, you know, but S C A also does provide some other benefits, right?
So, you know, it's not just the vulnerabilities, but it's also, okay, well was there a middleman attack? You know, solar Winds is similar to that, right? Yes.
Solar Winds is, is there, and, and I think also part of the reason why the government's starting to really, um, hammer down on this is because they're realizing now they're sensitive data is actually being compromised, right? Um, and, and, um, and I think also the software pro producers really have to internalize that and be responsible, uh, for the, you know, the security of the software that they're providing for their cons, cons, customers and consumers. I, I agree.
If you wouldn't mind highlight the difference, if you will, for our audience between like a manifest versus the, the S bomb, right? That's the other thing we hear all over the place. That's bomb sbo the difference between a manifest and an sbo.
Yeah. So, you know, SBOs can be based on a manifest, right? Mm-hmm.
Um, so that can give you some level of visibility of your, uh, dependencies. Um, so the manifest is really just, uh, specifying well, what are some your dependencies, um, you know, of this particular package or project and so forth. Now SBO can be produced in other ways, right?
SBO m can be produced in a way that you're really tracking what are you putting in as you're building this package, right? Um, what are the different dependencies? What are the native libraries, right?
And so your SBO can have, uh, a much deeper level. It really depends on the tool that you're using, right? Um, you know, there are definitely a lot of tools out there that helps you do that.
But then I think the challenge here is on the open source dependencies that you have, what is the s mom for that? Right? Because especially when you don't necessarily have visibility in how it was built.
Right. Excellent. Good stuff.
Laura, I, I don't know if we mentioned for people who want to get more information on all this, have more information about the active state offering. com? io?
Active state? Do Com's ac Yeah, exactly. com.
Um, you can try it out. We have a, uh, free offering. Um, so developers are welcome and anyone, uh, AppSec are welcome to, to try it out and see if it works for their solution, for their problems.
Um, and um, we'd love to get the feedback, uh, from the community as well. We're in fact, um, you know, partnering, uh, with the Python community, um, and especially working with the open source maintainers. So more to come on that side as well.
So, Well, you'll have to come on here and tell us then you just got an invite. Ah, happy to do so. All Right, Lorelai, it's so great seeing you.
Good work over. There're doing a great job too. Hello now.
Thank you. We'll see you soon. Say hello.
We're gonna take a break here on Text Junk tv. We'll be right back in a moment with our next guest.