SBOMs and Software Supply Chain Security – Scott Robertson, ActiveState
ActiveState has launched a new active state repository to help software supply chain security, which uses SBOMs and builds software based upon case-specific dependencies.
Transcript
This is Textron TV. Hey everyone, welcome back to techstrung TV. I've got a company that we haven't covered before on texture on TV or at least not know really long time active State and we're gonna hear all about and I want to introduce you first to their CTO Scott Robertson.
Hey, Scott, welcome to Tech strong TV Allen. Nice to meet you and thanks for having me. It's our pleasure to have you on here.
So Scott, we're gonna jump into active state in just a minute. You guys didn't have some really big news yesterday. But before we do, let's give people a little background on the Scott Robertson story.
Oh sure. I yeah. Well, I'm CTO of active State.
I've been in software development for over 20 years. Now. I'm actually doing the math last night.
It's getting close to 30. It's kind of getting along. Yeah that goes yeah always a big open source Enthusiast that was even from my very first job.
That was the person advocating bringing that in and out was gonna change. The world in the way that we we develop software. I went down in two or three different startups.
And now I'm working on over here at the state on open source supply chain problems. Which look is a top? Three on everyone's list.
It seems these days right the the software supply chain issue and it's in its primarily open source. so You're right there think back 25 years 30 years. And if I told you 99% of every company in the world is going to run open source software.
You would just yeah, you're crazy. Absolutely. That was that was the thing that was always arguments how to get it.
I'm like this is gonna change everything we're gonna change it development and I was a crazy guy shouting at it from the hilltops, but absolutely it was a crazy notion back then you know, I just crazy but but you know how it's changed. I mean specifically the software development I had this conversation again the other day with some folks is we've truly entered the age of the software Factory where software isn't something like bespoke. Kind of design one off for each app that we create from scratch and have to kind of reinvent the wheel.
You know today software is assembled much like cards. Are there third-party suppliers most of it open source, right that we we grab these components from various repos or containers and you know, what have you and Put it all together into whether we're using microservices or classic cicd or what have you, you know, we grab all of these pieces together. We kind of stitch and glue it together with some custom code maybe right for what we don't get from components, but that represents a small minority of the actual code.
In in most of these apps, you know, it's it's very different model. Oh, yeah. I've heard by some accounts the the code that you're shipping these days only 1% of it is that proprietary IP that you're actually creating and everything else that's coming from from contributors that you know that we're all setting on the backs of giants here.
In order to you build up, you know with the Advent of things like get and Repose like this and and public repositories. You know from java and JavaScript and everything else that you see out there. We've built up this massive Library where I mean really?
If it works good and it ain't broke. Don't fix it. Why wouldn't you want to reuse it?
Oh, absolutely, of course until you get like You know some of the things we've been dealing with in software supply chain. Oh, yeah, right. Oh, yeah, I mean That's that's been the case.
Right? We've we've been we've shifted the corner now. We're like it makes sense to use everybody's collected contribute contributions to get going and it's it's funny.
You mention it. We you know digging back in the days like active State really got its business, you know back in the day when it was hard to find open source, like literally the only way to do that was to go out to use that groups and he was everybody else happening and you get a link to some, you know website. You don't clean library or something.
So yeah, you bring it in you wouldn't even think twice about using it and now it's kind of the state where it's become so convenient ubiquitous to go out and use open source and and bring it in your applications. You don't even thinking about it anymore. And then that's actually the source of the problem these days people aren't thinking about where the stuff that's coming from.
And that is what attackers are using because we say open source, but reality is we're actually bringing down open source components and open source Miners and you might think that the source code that you're using Is vulnerability free but the binary doesn't necessarily always match exactly what the code you're trying to bring it and that then they're different versions. Yeah, right, depending where what repo you pull it from and you know, especially with microservices where you're not even necessarily pulling code. You're pulling apis.
Right that are talking in some code or something in that lift somewhere else all together. And yeah, it's it's a it's a crazy mixed up world except for Lola but you know, what, do you what are you going to do here? This is the world we live in so you mentioned active State and sort of it's early mission, you know.
I'm sure a lot of our audience has heard. Of active state of chunk of the may even be familiar, but there's a chunk who aren't I know? Why don't if you don't mind Scott give us a little bit of the active State story.
Sure. I kind of touched on it a little bit but we'll give you from the step up. So accurate was one of the early pioneers and helping Enterprises adopt open source in their technology stacks and our claim to fame was we helped port a lot of the dynamic stripping languages to the infrastructure and Hardware the Enterprises were using at the time.
So whereas most of the Enthusiast we're working on Linux in Enterprises. They were using big Iron machines or Microsoft Windows and things like that. So we help bring Pearl and Python and and tickle to these other hardware infrastructures and and we ended up with a business model similar to what you saw with like Linux vendors out there red hat and things like that.
But but I've always liked to say is where every where they went vertical they collected open source, and they got it to work on Linux machines. We went horizontal and we would get we get collection of Open Source based on Programming languages that we're using and we would get that the work across the entire ecosystem for that language and we'd have it built on many different hardware architectures and we do porting if necessary and things like that. And so that was our early days with just making it easy to use open source in in these Enterprise settings and and we built up our great subscription-based model of always delivering the software.
And in over time the what you notice is the concerns. What from what is this open source scary stuff that is coming into my Enterprise to other types of concerns. Like am I managing my license is correctly and now more often than not it was managing license correctly and the other big concern was how do I even build this stuff in the first place still is our actually our biggest one.
It's we are the place when you're stuck independency hell you come to ACT the state we help get you out of it. We help we help keep you all the right configurations if you're running multiple operating systems, but you need to keep everybody in sync but Where Rasheed the world going now is a concerns about the consequences of using open source inside of these Enterprise settings. So being able to figure out where what is the Providence of this component?
Did it come from the legitimate author or as is it coming from has it been replaced in transit from the point where I'm getting it from a public repository all the way down into our system and those that's where we're going these days. It's where the bigger concerns are. Our Enterprise customers are are having and I think the world in general you're seeing all these concerns now about the supply chain and it's it's kind of fun for us.
We've been doing this for so long, but now there's actually words to explain what we're doing. So right now we can actually say the supply chain is under attack and you know, the open source you're getting any assuming this is having problems and that's where energy is to make continue making open source easy to use at in Enterprises and make it safe. So, you know make it so easier you even have to worry about all the other problems, you know, we'll take care of the safety issues and and the build complexity and things like that.
You know, and that's certainly what's needed. I'm almost surprised Scott with all of the PR not good PR that we've seen with open source, and so forth supply chain security. That we haven't seen more people who say you know, what I've seen enough.
I'm not gonna do it this way anymore. Right, I think people realize that trains left the station. This is the way we're doing it.
We just have to do it better. We have to have solutions that take kind of the risk out of it and and the you know and give us that confidence just do it. But that is We're not gonna go back.
We're not turn here. That's one thing. I've learned in also 30 years of Technology right time only goes forward it.
You know, you impossible just about to roll back time. It only goes in that One Direction. So yesterday you guys announced some big news around this.
and I wanted to have you kind of share a little bit with our audience if it's okay. Absolutely. So yeah, so well, I guess what we talked about our mission is to make open source easy and safe to use and actually how we do that and this is something we've been doing for a bit is we have created a secured build service for building compiling delivering deploying open source components from the internet to your very simple structure.
And yesterday we're excited to announce at least of our artifact repository, which is a combined to our secure build service. So now you can come to us and especially your python user. You can automatically plug it a plug-in the protocol and grab components that come directly from our services.
So all the components so imagine having a pit prepository for feeding the python defendant seeds to your microservices, but knowing that the components are coming through a secured supply chain. So what I like to say is don't bother setting up your own supply chain come back to State we have one set up for you. And we can Plumb all of those packages directly into your your building infrastructure and doing that allows you to go back and audit each of those individual components exactly how it was built find out how it was sourced how it was provisioned and be able to completely monitor the the s-bombs that you're consuming from us as you're delivering to your pipeline.
Love a great idea. What what gives me the confidence that you're doing a better job than I am. Is whatever you probably even hearing about s bombs or I kind of All the Rage which is yeah.
I know they say well, yeah, even at our so we do the devset cops day at RSA every year. Yeah this year this year. It's Monday back to Monday at the Moscone Center last year was Tuesday, but last year we had Allen Freedman and a bunch and some other folks from the government as well as I think a doctor from Intel we had a whole espomb.
Panel going crazy was the highlight of the day. So yes, it's a big news. Yeah, so everybody's talking about s bombs and and I I would find it funny because not a lot of people understand what you're supposed to do with them or how you doing in the first place.
But what we notice is everybody will you know, the business is usually build their open source software, they deploy it on the machines and then when they need an s-bomb, they make these tools to go back and scan and try to retroactively figure out what the S5 is supposed to be. We kind of looked at it like that isn't the right way to be secure to be managed. So we flip the script on the head.
What we do first is based on your software. Dependency you're required. It's we have technology that can calculate and figure out what the F-bomb should be.
There should be so based on your dependencies these exact specific binaries must exist. It must be built and we have a system that takes that s bomb and constructs the that software from open source everything we deliver to our customers and stuff that comes to our system is built ourselves. It's built in hermetically sealed environment so that the outside world can't come back in and contribute it and manipulate it and then we end up actually producing the complete as well.
And so then when we deliver our technology Or those those components to our customers based on that technology what we can do this different from everybody else is these are the exact binaries that must be in here with these exact checksums. If you have anything else different on your machine, you have a problem or that needs to be upgraded but we do it the other part of it is we don't just stop in one ecosystem. So if we are doing something like python our system is modeled the software dependencies all the way down to the native sea libraries for every operating system that you have and so we can say okay you might have an environment where you've got Matt.
Windows and Linux. This is exactly the Manifest of materials that must be there. And so now we plug that on top of our artifact system.
I love it. So that is really flipping on its head. So instead of like building out your system and then saying okay, let me make a list of what I got here.
You know for my S5, you are creating an s bomb is almost a recipe and then, you know baking your your software based upon the s bomb recipe, which is really really cool Let me ask another question. Often, you know, and it's been our experience lock for J and things like this, right? What happens is today?
I don't know of any vulnerability in this particular component. And so you you grab that component and you put it in your hermetically sealed. Kind of, you know ingredients.
for my application tomorrow we discover a bug vulnerability whatever you want to call it weakness in one of those components that's in your hermetically sealed. Recipe but I didn't know it when I put it in but I know it now and I may I maybe I deployed something with it already or I didn't yet. How do I how do I recognize that update?
What's been deployed update the next time I'm gonna use it. How does this is that part of this? Yeah, so that That's actually what the active State platform does today.
So we figure out the the S bombs that should be there and you know, we've been what we have done is we're constantly cataloging the internet for all open source that has ever released. We bring it in into an immutable database which is we call our catalog of this is the source that's available for us. We then generate the S bombs ahead of time.
And from there. We we convert the S bombs the actual binarys that you need to have and and to deploy that but we practice all in a nice self-serve UI so things that we can do is we can tell you the vulnerability if you're gonna get today if you install these components even today if you run out there and tip install something maybe even install something or do any of these kind of package management things chances are you're already gonna get a component with vulnerability we can tell you install time what what vulnerability and you're gonna have and whether they're acceptable or not give me that data available. But because we're so driven off of the s bomb we're constantly then monitoring various data.
is for known vulnerabilities new package releases and because we have that complete picture we can tell you okay this component that was vulnerable free at the time now has a critical vulnerability and if you're managing your projects using our self-serve platform from that we need that complete visibility of here's all of the projects you have but we take it a step further we go down to not only these are the components. She should be using we actually tell you where those can those S bombs have been deployed down to the individual machine. So you've got this machine with these dependency problems and it's vulnerable right here.
It just needs to get a couple of updates to go over and we also put this grip around sometimes we'll tell our customers because we have a we have a technology called Spectacular build. We know the sbon you're supposed to have If we see an update we see a vulnerability in an update package released. We actually can rebuild all of your complete your software for you ahead of time and let you know if it's gonna work or not.
We can tell you don't even bother trying to get vulnerability because even though it's been fixed in this current dependency. You have somewhere deep down in your dependency stack. It doesn't like the new the new update don't even try to deploy it and I actually think that's the number one reason vulnerability stay around is because you know, you spend so much time getting your application built and all these dependents and play.
I don't have time to fix them. Right and if it's gonna break the app, I take my chances. Yeah, that's unfortunately.
That's the truth. Right that's been a true truth and security for a long time if it ain't broke. I don't want to fix it unless I really really have to and so we're trying to put that script around being well we can monitor what you have we can figure out if it's all going to work and be vulnerability free and Using our platform notifications and DUI, you can find out these are the components.
Oh I can get an update and it's safe to take it update. Not only from security standpoint from from the fact that I'm not going to take production down when I bring that update down because that's just equally as bad I passed security thing. But you know, I I killed my entire production stack is the other side of that.
Yeah. This is the lesser than two evils here now right Scott you sold me how to how do people out here get it where what do we do here? What do we have to do?
com you can sign up for a free account. We offer our services or anybody's using open source can use this for personal projects or if you're an open source Community. We make all of the functionality we get Enterprises for free with our to To open source communities, but anybody can go get started and it's just simple as signing up on our platform.
You can link your GitHub repository. You can which you get up account to us. We can scan your repositories tell you what the tendency they have in it.
And then we produce this thing called a runtime which is based off of that s Palm that we're producing and and then it's then you have we have various deployment mechanisms that you can plug this into your various software Stacks. So you can profit in your ci/cd systems. com get an account start playing with some of the language ecosystems that we served and and you can get in touch got forms and everything else like that to talk about what we get what we're doing and how we can help.
I love it. And just one more time for the audience this new service. What's it called?
We call it the at the state artifacts repository and that's that's sitting on top of the accostate platform today, which is so the I can stay platform is our security build service for for sourcing compiling building monitoring open source components that you need and now the repository lets you use those components that we're building through some of your favorite package manager protocols specifically the one where we're launching right now is the pipei protocol. Got it. Hey, Scott.
Thanks for jumping on and and sharing with us. Appreciate it. Keep up the great work man.
Come back and keep us posted on what's happening at active State. Absolutely Island. Thank you for having me.
My pleasure Scott Robertson CTO active State here on text on TV. We're gonna take a break. We'll be right back with our next guest.