Rust Adoption Bolsters Cloud-Native Application Security – William Morgan, Buoyant
Buoyant CEO William Morgan dives into how increased adoption of the Rust programming language is enabling cloud-native applications to be built more securely.
Transcript
This is Techstrong tv. Hey guys, thanks for the thrill. We are here with William Morgan, c e o of Boyn, and we're talking about how Rust is slowly but surely transforming our happy little cloud native ecosystem.
William, welcome the show. Thanks, Mike. It's great to be here.
We have seen the rise of Rust, and we've seen the folks who create Lennox are starting to embrace it and other folks are starting to take it on as well, but it seems like it's a slow process. So from your perspective, where are we with this transition? How long might it take and why should everybody maybe get on board a little faster?
Yeah, yeah. So, you know, uh, the project that I work on, uh, Linkerd, which is a, a service mesh kind of firmly embedded in the cloud native space, um, was one of the earliest projects to adopt Russ. And that was about, you know, 2018.
So was that five years ago? Um, and at that time, you know, it was kind of like the scary decision as over the past couple years. It, you know, the, the rust ecosystem has evolved and you see a lot more kind of cloud native projects adopting it as, as their kind of programming language of choice.
And I think the reason why it's such a good fit for the cloud, uh, native world comes down to trust, right? That's, I think that's kind of the fundamental reason why, you know, uh, why a, why the cloud is strange in a lot of ways and scary compared to pre-cloud environments. And also why ru uh, why Rust is so useful.
Cause, you know, in the olden days, of course, we used to have, when I was a baby, uh, we had data centers that, that we owned and all of our code right, was running on these machines with, and we owned the wires and we, you know, machines weren't racks and we had the keys to the locks, you know, and of course, in the cloud, like you own none of that, right? So it's someone else's machine, someone else's network hardware could be your competitors, you don't know. So like suddenly there's this big shift in trust, right?
Like now you have to trust a lot of things, uh, that you didn't have, uh, have to trust before you had that trust in the hardware level, right? Have the software level. Um, and so what Rust does is it gives you some new and kind of very fundamental, um, uh, abilities to trust the code that you're writing.
And it does it in a really interesting way, and it's kind of like profoundly wired through the entire language. Um, but it means that you can now write code that you can run in these cloud environments. You can have a level of trust in that code that you've never had before.
You know, not in the whole wide world of, of c and and and c plus plus code, at least. Are we drawing a line in the sand and saying we're gonna write new software in a modern line language, or do we need to go back in and kind of rewrite some of this stuff that's already out there that people are using and, um, maybe, you know, modernize it, make it into a cloud native thing that's more secure? Yeah, that's a great question.
You know, so our, you know, kind of my, my, my statement, my evocative statement, uh, is that rust is the future of, of cloud native. You know, I think if, if you are writing new code today, and that code has to be, you know, and, and, and you know, the application that you're writing has to be a systems level program, right? So it's not, you know, it's, the world is a little different, uh, and the constraints are different.
If you're writing an application that you know, processes, you know, a request from a user and talks to the database, and like there you've got kind of higher level languages where you can, uh, you know, take a, a performance hit if you want to in exchange for, you know, attaining that same level of trust for Rust. You know, for your, if you've, if what you were writing is something like, you know, the linker d has this component called the micro proxy, which has to be an incredibly fast proxy, you know, as, as fast as it's possible, as fast as a machine can go. If you're writing something like that right, systems code and you're writing new code today, then yeah, I think absolutely Rust is, is has got to be what you're writing it.
I don't think you can write that in C or c plus plus in the modern world and, and really, you know, take statements around security seriously now for the preexisting code, you know, it's a momentous task to just go and rewrite everything that's out there in the world, probably impossible. Um, but there are some really interesting initiatives. There's a, uh, an organization called I S R G, the Internet Security Research Group, which is most famous for Let's Encrypt, which is kinda a, a free tls, uh, you know, service.
So, you know, that was part of the move to get everyone on the internet to adopt TLS and, and to uplevel the security of the internet. One of their initiatives is also going and rewriting some of the important components of, um, of the internet that are currently written in languages like c or c plus plus in Rust. So they're going on their finding, you know, what are the biggest surface areas, you know, across the entire internet of how we, uh, handle application traffic and can we rewrite those things in rust?
So yes, that is, that's a thing that can be done. It's expensive, it has to be targeted, you know, but it is, uh, you know, it's just as critical as kind of the forward facing, you know, let's, let's write everything important in the future in Rust. Are there enough, Russ, programmers to accomplish this mission?
I mean, how hard is it to learn Rust? Yeah, well, uh, no, probably not, not yet. Um, you know, I guess Rust has the advantage that it's a cool language.
Like it is, you know, as a programmer going into it, it is challenging in a way that forces you to really think about, um, this notion of ownership. And when you allocate memory, who owns it, and what's the life cycle there. And that's kind of, you know, uh, for many programming languages that's not, uh, an existing concept.
So you coming to, to Rust, even if you're an expert programmer, you come into RU for the first time, the learning curve can be quite steep. But once you master this new kind of mental model that you have to adopt, then you know, it's, it's powerful. It's expressive, it's elegant, you know, it's got all these nice, it's got an ecosystem of, of things that you can rely on.
So it's, it's very nice. Uh, it's a very nice way to develop code once you master that, uh, that learning curve. We of course, hear a lot about DevSecOps and securing software supply chains.
Are we kind of doing cartwheels because we don't have something like rust? So maybe, you know, if we add up all the cost and effort that's involved in securing stuff that's written in another language, maybe it becomes more cost effective to move to Rust a little faster. Yeah, I mean, I think that is, that is the trade off and the, you know, the, the, the story of security certainly is like, you know, if you find any security expert worth their salt, they're gonna say the number one, you know, security vulnerability in any system is the human being, right?
The human who is involved is the one who's gonna make mistakes. Whether you're asking them to, you know, to pick a password for the, you know, 500th time and they're just gonna reuse the same password all the way to the programmer, the human programmer who's like writing that code, you know? And, and that, you know, I think I saw a study from Microsoft that, you know, looked at all of the CVEs and security vulnerabilities that have been reported in, you know, in, in, in the giant like CVE database.
And some astonishing portion of them are due to programmers making mistakes around things like memory management that, you know, don't cause a, don't cause a the program to do the wrong thing, but they leave a security vulnerability in there. You know, if you input something in the wrong way or it's too long, or you, you know, something like that, then you can gain access to the parts of the program that you're not supposed to have access to. So it really comes down to, I think, you know, DevSecOps as well as y you know, all of security is like, how do we make it so that we can build software and develop things and like progress and like do all the things, you know, uh, that, that we wanna do in a way that takes into account the fact that, you know, the, the, the humans who are both producing and consuming the system are fundamentally like insecure creatures that do crazy things.
Well, the uninitiated, can you explain what makes Rust more secure? Because there does seem to your point about when you look at all those CVEs, they involve some issue involving memory. Yeah, yeah, that's right.
That's right. So the, the, the weird thing about computers is that memory is used both for data and for code that gets executed. So what happens is if you have a little spot in memory that the program is allocated, and you write in there stuff like, um, uh, you know, um, uh, you write in their data normally.
So like, let's say we're taking an input string from, from you, you've like typed your name, okay, we store that in memory somewhere. But if we're not very careful with the way that memory is managed, then if you put in your name and then you add a bunch of, you know, uh, uh, bike codes at the end of that, there's a potential for those co for that code to actually be executed then by the program, right? So that's like a, a huge security vulnerability cuz if you find that out, you now can control what that program is doing.
And this program is not running on your computer, typically it's running on the server, right? It's running in some environment. So that's the kind of exploit that is caused by poor mana memory management.
You know, there's many other examples and that this is kind of like a basic one, but if you don't validate input and if you're not careful about what gets stored in the memory, then you can make it so that anyone on the internet can end up running code on your server, you know, even your, even if it's in a VM or containerized or whatever. And that leads to a, a huge security vulnerability. So what Russ does, right?
And, and I should contrast this with, that's kind of the state of the art for, for languages like c and c plus plus, which I keep kind of picking on, cuz those are the canonical ones where it's very easy to make these mistakes, right? You write your code, you, you're taking input from the user, you're storing it in memory, you're moving on, you test it, you know, you type in your name, okay, everything's fine, you know, and the program works, right? And it's only till later that you find out, oh, this code that's out there in the wild for 20 years suddenly has this problem where if you type your name and you put some extra special care, cause at the end you can own the, you know, you can own the server.
So what Russ does is obviously it's checking for stuff like that. There's also checking for ownership of this memory saying who created that? And at every point, if you have memory in there, there's an explicit owner, and that gets passed from function to function if you unwind the entire program and it avoids, and that way you avoid a whole class of vulnerabilities where you have this, you know, memory that you did, that you forgot, that you literally forgot about, or, um, you know, that gets and ends up somewhere where you don't want it to go.
This is a, a very high level, you know, explanation, but that's, that's the basic, uh, model, is that Rust has this very strict model of memory management that precludes a whole set of, uh, um, vulnerabilities that could turn into CVEs and, and, and exploits. You cannot walk down the street these days without somebody leaping out to tell you about their great new AI thing. And we've seen all these co-pilots.
Do you think that AI will make it easier to learn a new language as we go forward because something will be typing ahead of me so I don't make as many mistakes or I can reduce the cognitive load of learning? Yeah, that's, you know, that's a really good question. I thought you were gonna ask, well, can AI just write the code and then we don't have any vulnerabilities?
Then it's like, well, okay, I don't, I don't know, I don't think we're there. I would not feel confident in that statement. Yeah, I don't think we're, you know, we even at, at, at Buoyant, you know, in the, in the rust code that we write in linker D is, is very, it's like advanced rust, right?
This proxy has very high performance. It has to handle very, uh, complex transformation. We've got, uh, transformations of data and memory.
We've got HTP two, you know, requests coming in, which has this very rich, uh, you know, set of features you can enable. And then we have to proxy them and we have to handle this stuff. So it's very advanced, Russ, but you can take, we've done experiments with chat G P T and G P T, uh, uh, four, but you can take snippets of Rusty, you can say, Hey, can you explain what this thing is doing?
And it is shockingly good at saying yes. Like, here's what this thing does, and like, there's an issue over here, or you can ask it to like write unit tests for you. So I w I've been blown away by how helpful AI can be in learning.
Russ specifically, you have to take everything with a big grain of salt, right? It's like, uh, you know, at its core, I wouldn't say it's understanding this stuff so much. It's like doing an incredibly good job of, of pattern matching.
Um, so you have to evaluate what it's saying and, and be a little skeptical, but yeah, it's shockingly useful. Do you think we'll get to a point soon where the buyers of software, the organizations that consume it, are just gonna say, we're not buying anything that's not written in rust here because, you know, these other languages are too problematic from a security perspective? Yeah, I think it's a possibility, but you know, the reality is there's many ways of developing trust in a, in a system.
Uh, you know, we had, um, you, you can write it in language like Rust, you could write it in, you know, uh, in a language like c or c plus plus, which does have those memory vulnerabilities, but it could just be exposed to so much testing or it could be around, you know, for so long that people develop confidence in it. Like open SSL is kind of a, well, I don't know if that's a great example, but you know, that's a big piece of software that people have vetted for a very long time and we're still finding issues in it, you know, but by virtue of it being so important and having so much embedding placed on it, we do develop confidence over time. So would I mandate rust?
You know, probably not, but I think what you would mandate is, you know, uh, the level of trust at which you need, you know, the level of trust you need before you absorb the software into your, um, into your environment. And whether that's, you know, a function of, uh, you know, what language's written in, whether it's a function of things like, uh, SBOs or software, you know, bills of material or some other metric of, of trust. Um, you know, we had this mission statement early on in Voyant, which we've revised since, which I really like.
Um, but you know, and NCA has kind of stuck with me, which is, you know, our job is to make it so you can trust the software that you rely on. There's all the software that we have to live with every day, whether we want to or not, right? Software that we didn't choose to live with.
It's software that controls the traffic lights or software that, you know, gives us our credit scores or that monitors our, you know, the processes, our medical records, how do we develop trust in that software? And I think that's kind of the fundamental, uh, question for a lot of software engineering. You know, both, all the way from, you know, kind of me as a consumer or as a, as a person living in the modern world all the way to, well, how do enterprises, you know, make a risk decision about absorbing new software into their ecosystem?
All right, so what's that one thing that you know now that you kind of wish you knew earlier about Rust when you first started down this journey that other folks could probably, uh, use to shorten what, uh, some of us occasionally refer to as the idiot attacks? Right. Well, I think there's a couple things that we've definitely learned along the way.
Um, you know, one of them, which, which I is, has been encouraging to see, we kind of knew early on, you know, 2018 when we first started adopting Rust in, in linker de we knew that the ecosystem was a little, uh, underpowered, right? You know, it was still relatively new. The set of libraries in Rust for handling, you know, web traffic, h htp, traffic, G R P C traffic was still pretty new.
Um, and so that, but I don't think we realized quite how, how young it was at that point. Now, five years later, okay, you know, we've got a nice mature ecosystem. And I'd say actually some of the, the, the cutting, if you look at the cutting edge of, of network programming today across the entire universe, it's all happening in rust.
That is where the absolute state of the art stuff for network programming, ay, highly, you know, performant, asynchronous network programming is all happening in Rust. And it's really exciting to watch. I think another thing that we, that we learned is that, um, rust is powerful and, and exciting, and it's like, it's great as a, you know, as a language that pe people who get very attached to it, but ultimately it's just a tool, right?
And like there are parts of Linker D that are not written in rusts are written in Go, because the constraints are different, right? And the requirements are different, and Go is secure, right? It's not as fast, not nearly as fast as rust, but it's also secure via a different set of mechanisms.
And being very clear about, you know, what parts of my system require rust, which will have very different ergonomics from what parts of my system require other languages, um, is, is, is all part and parcel of building a, um, a product. All right, William, as always, thanks for being on the show and sharing your insights. It's great to be here, Mike.
Thanks for having me. And folks, as you heard it here, you can continue using the same programming language you always used, but realize that you know, there's gonna be a phone call coming from somebody from security. So maybe you might wanna shortcut that whole process.
All right guys, thanks for watching the show. We'll see you all next time.