Amir Montazery, OSTIF | KubeCon + CloudNativeCon Europe 2023
Amir is co-author of the CNCF and OSTIF Impact Report, focused on vital security auditing across the foundation’s project base. He outlines details of the report, talks about OSTIF’s work with the Linux Foundation and other projects, discusses funding and the need to secure the open source commons that the DevOps community increasingly rely on.
Transcript
This is texturing TV. Hey everyone. We're back here.
Trying to wrap up day one of our kubecon coverage. org. He's gonna tell you all about it.
We've had a mirror on was it in Detroit. It was Austin. Oh, sorry Summit last year.
Yeah, that's right in the hallway in the hallway. That's right. I remember now.
Yeah. Hey, you're welcome back. Anyway, thank you have money back.
Thank you. So let before we jump in one ostif is and what's going on? Why don't we do a little bit of your background?
Sure. Absolutely. My name is Amir Montazery.
I'm from Chicago born and raised there. I originally got my schooling in business and finance before going into it auditing and what was really cool about that was I got to work as an internal auditor overseeing the US payments channel, so I got to really see what the most. Did security requirements measurements and mitigation strategies out there look like and then when we started ostiff open source technology Improvement fund to specifically focus on helping open source projects with their security needs and security auditing.
We I was able to incorporate a lot of that knowledge and best practices from internal audit practices and kind of marry that with with the complexities of the open source space and especially when it comes to security and here we are eight years later really happy to say that just in the last month. We actually grew the team finally. We had our first staff hire and immediately after had one more.
So I'm really happy birthday. That's great. Yeah, we're growing and it's gonna help definitely allow us to do more for the open source community.
So we're here what kind of new with those different cubecon any announcements or any kind of goings on? Yeah. Absolutely.
Yeah, a lot of a lot has happened last Almost year now, I think it was June. It was in Austin. We have been very busy.
We have a lot of new work done with the cncf as one of their main partners for doing these security audits. We make it really easy. So yeah, really, we just get a project and walk the whole take them through the whole process and Complete it with an audit report.
So one really nice thing. We did was a impact report for cncf where we aggregated all of the results from the last year to really show in aggregate the work that we're doing. So I was really proud of that as well as our first annual report practice that I saw as the best practice with a lot of other similar organizations, you know, and we're so focused on transparency has really a tenant of our organization.
We thought you know, a annual report would be a great way to aggregate all of our work to showcase our work and provide, you know evidence of our effects I get it. So yeah, so I'm really happy to be here in Amsterdam meeting with a lot of the project contributors and maintainers that we've been working with and just you know taking it all in it's it's a lot it's a great conference crazy conference. And yeah.
Oh, the website is oats ostif dot org. That's right. It is a bit of a mouthful but it's very succinct.
And and when you kind of say it a bunch of times, but that's open source technology Improvement fund. Yeah, so I just want people to be able to know that right? Absolutely.
org. Yes. what do you think is, you know as we sit here now and we can see this thing really kind of coming back to life because it was it's been a cut rough couple years with covid and everything indeed.
Where do you see going now from here? I'm here. What's great to have people back back in person?
I would say one of our most successful audits was. Pre-covid where the audit team we had picked for a project and the project the core maintainers. We're just a short train ride away from each other.
So we were able to facilitate a in-person all hands on that kind of meat where because we're so focused on collaboration they were able to do it, you know very directly and we that was actually one of our most successful security audit. So it's great to see the in person the in-person interaction back building that rapport with folks. I love it.
You know, it's great to be you know and Amsterdam, you know in Europe. Yeah. I had the chance to explore amsterdament not quite yet still getting over the jet lag but I've been here a few days.
Yeah. Yeah. So we we've been out to the flower garden nice museum, very nice and Frank and the Jewish quarter there.
And then sampled, you know. Sampled some of the Wares they sell right here. It's all good.
It's all good. Yeah good, man. Hey.
I'm here. If I don't have no more the questions, but if people want to get involved or want, maybe you know, I should have asked this. Let's say they've got an open source project.
That's not cncf you could still do it. Absolutely. Yeah, we're always open to helping open source projects out organizations who maintain or Foster these open source projects, we're certainly open to working with them.
So anybody out there with an open source project, you know things can benefit. Yeah. org you check it out.
Absolutely. Yeah. Yeah, check out the website.
We have all of our work on there and we are relatively easy to contact so and just to conclude you mentioned kind of where where the where really the the puck is moving towards to use that idiom. It's changing, you know security is indeed a moving Target and we are doing our absolute best to Adapt with that and increase our really our service offering to projects doing things like supply chain reviews and fuzzing Audits and really incorporating all of that into the into the engagement. So it's a comprehensive engagement kind of hitting all the different aspects of where the where the space is moving towards.
So we're really excited excited to be back here. Thank you again. And how's your man?
Yeah. I look forward to the rest of you in Chicago. It's coming.
I'll see here next right finally coming in our hometown right here November. We're November in Chicago. It's gonna be windy.
Yes. Thanks again everyone. All right.
org check them out. We're gonna take a break. We've got our next guest waiting in the wings.
So give us a minute. We'll be back.





