Aeva Black, Microsoft | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. Thanks for joining us on our coverage of the Linux Foundation open.
Source Summit here in Austin, Texas, right the JW Marriott hotel. We'll be streaming live through the day. We have a bunch of different speakers lined up to talk to us.
I should mention from the outset before we introduce our first get guest is today is What do they call it if it's not zero day, but it's it's co-located events co-located events day where so the main open source Summit actually starts tomorrow today. There are a number of co-located events though that have kicked off the open source security Foundation. I know is one finops is another one.
There's two or three others that I don't Recall right. Now do you I don't know there's others as well. So a lot of people in Hall it's a little quiet where we are here, which is pretty cool.
But there's a lot of people in the various rooms listening to some amazing content with that said though. Let me introduce you to our first guest here this week. Their name is Aeva Black.
And we had a look conversation off off camera. I should just clue you in, you know, sometimes I still mess up today pronouns and and so Avis Province to help me. So if I mess up she'll correct us and hopefully they'll correct.
I think excuse me. There we go. First what and we're doing the best we can with it anyway.
Ava that was a lot of preamble Tell people a little bit about yourself. Well today I work at Microsoft in the office of the CTO. I've been doing open source contributions and Community leadership for about 23 years now.
So I also sit on a couple different boards. I got elected to the board of the open source initiative last year and the open ssf tack which is part of why I'm here today at the open ssf day earlier this year. For people who aren't familiar with tech.
I'm sorry technical advisory committee. So we're sort of we're not the governing board. Right but the open ssf technical advisory committee guides supports the technical projects in the open ssf.
So it's not the board of directors governing board that are making sort of if we want to call a business decisions. It's really the technical advisory. Where would you know what it's at a much more technical level of what they say the two go the two go hand in hand.
The board makes the business decisions around finance and events and marketing and attack makes the technical decisions around what projects become part of the open ssf how projects are governed what the structure sort of the templates for projects should become absolutely and I want to delve more into the open ssf and especially from a technical point of view some of the things that they're involved in some of the other things that you're involved in around that but before we do that, I want dinner come back to this side and talk about your keynoting tomorrow. I am and not to let you know the cat out of the bag, but I wanted to have you talk a little bit about it. And before Ava does though.
I want to remind you all that in addition to the live in person. Aspect of this event. It is virtual.
So if you're watching us on Textron TV or Facebook or LinkedIn or devops like I'm Security Boulevard, whatever wherever you're watching this there's still time for you to register and tune into Avis keynote tomorrow as well as the whole week where it is a whole roster of some great great sessions. You can check out so check that out at Linux Foundation open source, Summit, but Ava Go ahead without giving too much away. I'm really excited to give the opening keynote tomorrow on community codes of conduct inclusivity how to build sustainable diverse communities really and it's it's a bit of a short one just about five or six minutes kick off the morning with that content.
Part of the backstory is that we're in Texas and Texas has been passing some rather. Let's see some some laws or some things that are not in accordance with our values around diversity. So I'm going to talk about that and what we can all do to make our community is more inclusive than a longer discussion I have on Thursday on Code of Conduct not as a tool of punishment, but as a tool of restoration and support for communities on Thursday afternoon.
Thank you someone who lives in Florida. Who am I to say anything? I mean quite frankly.
We've got our own issues, but I know you want to get into it. But you know, but let's talk a little bit about the code of condom so that in my mind here this two aspects number one is look. com Security Boulevard container Journal text drug TV digital cxl.
So one in several brands. And we we are challenged around diversity right finding speakers. You know what we do a lot of webinars.
We do a lot of video panels. And if you couldn't tell I'm a I'm a white male, right? So when I host something we already got one white guy on the table here.
I need to we are constantly looking for diversity and quite frankly. It's a challenge right? Especially as we go deeper technically.
It's like there's an inverse law there right where my my pool becomes smaller and and so we're always Looking right always trying to find yeah, you know people who will represent a more diverse Community when we do these kinds of video events. But I don't think we're alone right? It's not just Tech strong.
It's not just my company. Yeah, everyone's working on this and everyone should be working on this not it's not a pipeline problem. There's no shortage of women and non-binary people who want to work in Tech.
We have to make our communities welcoming for them to stay. I think you hit a nail on the head there and let me just mention it's not just ninebinary or even women it's people of color. Absolutely.
Yeah, you know, we we do something down home in Florida. There's a school that open near us called Boca code where they teach people to be full stack developers. And we we sponsor a scholarship called engineering the change.
We're actually doing a whole team not TV video series on it this but we've been doing it for two years. and we look for people who you know underrepresented communities, right and Even there it's hard. I mean quite frankly getting people to apply and you know, it's a 12-week intense class.
A lot of people don't want to put or don't have the privilege right to to dedicate 12 weeks the financial investment of that as well as the time. Yeah from the family or child care. Whatever it might be your first hand don't have that.
No, it's hard. It's a hard push. So, you know, so that's one aspect right?
It's just finding the right people, but then there's the second piece of it and I think you touched on it, which is how do you keep how do you nourish them? How do you nurture? How do you build a community?
Yeah of practice in open source. That's what we're here to talk about is open source. Yep.
How do you build that in a way that such a diverse Community feels continually welcome and when there are crises when there are incidents toes get stepped on accidents happen my experience working in consent incident response for about seven years now 95% of the time it's an accident. But you still have to work at it people still have to recognize the harm. They did cause make amends learn do better and that's how we make Community safer.
We also do need to identify the few percent of people that are just being being malicious and it's it's a real challenge the few people that are trying to do harm. I don't want to focus on them because they are really really small minor really is. Yeah.
I think the problem. Is when that small minority runs into public policy like all those people elected officials. Unfortunately, I don't know what I don't it goes right?
I don't know but I mean for those out there who you know, maybe deal with this issue with without giving that Minority more than there. Do you just ignore them? Do you somehow try to cut them out like you exercise a tumor?
That's an analogy. The one I like to talk about is called the analogy of a broken stare. Right?
We can't just ignore when there's someone in a community who's actively harming any minority in that group what happens when we do ignore that is the folks who are in the community for a long time. No. Oh, yeah, just just don't work with that person.
We know that they just I don't know always try and get. Always trying to do X or they're always kind of bad just ignore them. The new people come in, especially from underrepresented backgrounds and don't know that yet and get caught a trip on the broken stair.
And so for that reason we need groups like a code of conduct committee. I was on in kubernetes for a while. You identify these these situations reach out to that person offer to work with them to address this not just automatically, you know, excise the tumor.
But offer to support them, assuming good intention from the beginning and if they then demonstrate a lack of good intention then and only then push them out. pranks on it So I want to talk a little bit about open source, though. And yeah, you know, look I I've been involved in open source software on the security side 20 a long time 25 years something like yeah.
Yeah 99 for me is and I got him. Yeah, you know would snorting nothing. Anyway.
Yeah, but the nice thing about the open source Community is I've always thought there was a much more welcomeing. Yeah big tent kind of community as opposed to, you know, maybe some others So I mean with all due respect, I think it's almost easier to do these codes of conduct. Kind of enforcement or you know enforcement seems like you have a stick but you know pretty much that right stewardship great work.
In the Linux Foundation, it's much harder when we go to like in security at the RSA show or black cat or DEF CON. No, it's not impossible in those. No, it's not.
I have a lot of friends who are not binary we can look at some of the intersect conferences have done a really good job and some that have tripped multiple times. There's a recent incident with one of these sides. That's all over Twitter not gonna Point attention to it more than that, but we can see examples of good and bad that is and kind of what it's surprised me with the one you're talking about.
Look I was at the very first besides, Las Vegas. Long time ago you beat me there. Oh, yeah.
I was there the first time when they did it cool. I was at the first beside San Francisco. I love that event.
I was a Wrangler one year for besides Vegas to it. Anyway, not sponsor Wrangler, but the whole b-sides movement much like Linux Foundation was a very inclusive movement. Yes from the get-go Jack Jack Daniels and team did a great job.
It bummed me out a little bit to see that that happen in a besides. Yeah, bum made a lot too. I've had a lot of trust with the b-sides community and I know they're sort of syndicated or French you don't want right and you don't want to make blanket, you know kinds of things but as a whole I've always had good experiences in besides me too.
And but this this sort of touches on something else right inclusivity feeds into security. Okay, talk to me if if someone doesn't feel safe to be themselves. In a community to put on my sort of deeper infosec hat right part of as I understand going for clearance is making sure there's no compromise things like that.
So if people need to feel safe emotionally to contribute lest someone be able to push them out or apply leverage or scare them in some way and so from that from that angle specifically inclusivity is a security issue coming another one. It's a sustainability issue you're talking about wanting to have diverse communities, but to do that we have to have people who contribute to open source pick up the you know, The acts the bucket of water chocolate cherry water that analogy and then stay around for a long time. And then teach the Next Generation.
Yeah, that's about sustainability, especially in our security projects and open source. We have to encourage that yeah, I mean, yeah, I wasn't that long ago we were reading about you know harassment and so forth that worse than harassment attacks at some infrastructure. So I don't want to give a false impression.
We've made progress right here and look back. Yeah, just yes, it's there's more to be done one other quick point on the diversity thing and then I want to get a little technical. Look you are who you are and you've been doing this a long time.
I am who I am. I've been doing this a long time. It's very different when you're 22 years old coming out of school.
And you're dealing with life and in its entirety and you are either non-binary or you know, there's something else your person of color whatever you're coming into this industry, right? And I mean people could look at you and say they're a role model. I could thank you very much.
So honored the people, you know, I mean, but but that's the truth, right? But they look. At you and say well there they've been around a long time.
They they may not know the bumps and bruises along the way to get to where you are today, right and they may not understand. Well. Hopefully it's easier for that right because they've been Trailblazers who kind of did that but what talk to people coming into our communities now whether it be in for a sec or open source or just technology in general What advice do you give?
to to non-binary other underrepresented communities here you just Damn the Torpedoes Full Speed Ahead. Will you know what? What's the right advice?
I don't know that there is any one right answer or certainly not a one size fits all answer, but to anyone non-binary transgender non-conforming other minority is coming into infosec or open source. It's a finder people. Stick together and find supportive communities work in them help grow them help pass on that knowledge and make safety for others and communities that become more welcoming.
Will Thrive those that are not welcoming will not Thrive and that's part of the nature of Open Source. I love it. All right, we probably took a lot of time more than we want but we still have more time.
Let's talk a bit now. So you're doing another session. I thought you said it was tomorrow afternoon.
Yes tomorrow afternoon. I'm giving a talk on get bomb, which is a terrible name people should never let me name open source projects you name this my name this one I'm one of the two co-founders it is we've repurposed part of gets it's a Version Control System. But under the hood, it's actually a blockchain believe it or not.
Okay. It's a miracle tree. And so we repurpose part of that to handle software supply chain Security in a particular way that others aren't doing yet.
This is complementary to s-bomb software bill of materials, right? It's complementary to software signing projects like Sig store. It's complementary to build Integrity sort of build observation like in Toto.
It solves a different problem and that is How do I know what's in this package? What's in this tin? I like the analogy of a can of soup and say oh, it's Campbell's chicken noodle soup.
You kind of know what it is. And if you want to buy it, right if you have allergies, you can look at the back and say well does it contain these allergens? But that's not enough information to for a recall.
If you buy soup and there happens to be a recall the store could actually call you up and say hey that can of soup does it have this, you know, 10 digit number stamped on the bottom of it because they know how to trace back from the factory or the farm that it came from when there's a salmonella outbreak or something all the way through the supply chain to the store to who bought it. I want to enable that kind of artifact resolution across a supply chain in open source. At zero cost to developers and projects.
I wanted to be automatic in our build tools. For every small project out there that doesn't have a budget to buy run big infrastructure. So that everyone who's consuming open source software has more ability to trust what's in it.
This doesn't solve security problems, but it helps people discover later on after it's been built and downloaded and being run in production if there's a known vulnerability somewhere deep in the dependency chain. make log4j to two things. Yeah.
So first of what you had a very interesting conversation with my friend chancy Wang at RSA last a couple weeks ago around s bombs specifically, but around this whole idea now signing no kind of really delve into the ingredients if you will, yeah and and see chancy smart smart woman. She brought up a interesting point, which is this isn't soup this software. And if I start giving you the recipe for my software, what's to stop you?
From spending up your own version of it. And if it's open source. Well, that's fine.
You're related to do that. But if it's not open source will will proprietary software folks be willing to play when they realize that they're giving out their recipes. So that's a totally great point and one we have taken into consideration to get bomb project doesn't give out the recipe.
It's just giving out the the fingerprint the little barcode of things not the details of how they made it or put it together. And for commercial software because it's a it's a Merkle tree. There's a tree structure.
A vendor who's combining open source and proprietary software can choose to selectively truncate the tree. Distribute the rest of the tree with a stub there that you can then reattach under NDA if a customer asks garlic, I love it now. next question on this area that I want to explore is what's the is the goal here to be potentially to get like you mentioned artifacts get like maybe Jay frog artifactory to include it with.
All of their artifacts in there in their repo or maybe in the Nexus not necess next is not right for miter or minor even too sure. Yeah. Is is that kind of where this head?
This is where it could go. Yeah in the get bomb project. It's open source.
I'm not focusing on any of the commercialization of this but I can see ways where companies like those or Snick who just run the project sure could totally commercialize on this or build capabilities into their scanning tools. So that's possible that it would and I think enabling that isn't our primary goal, but it certainly a secondary and we're taking it into account. I also just want to be clear that get bomb is not part of open ossf or Linux at this point correct at this point in time, but that's also a normal part of the process of the open ssf projects usually spin up in kind of a neutral non-affiliated space.
And then when they have a community around them, they reach a certain maturity level then they might apply to join a foundation like the open ssf and go through a review process. And so if I speak from my my role on the open ssf technical advisory committee right now, I'm actually helping to Define that process for project intake. In a way that supports everybody.
Will there be sort of a defined thing sort of like you haven't cncf with sandbox? Yeah incubation all the way through the graduation. We are working on that right now.
We have a proposal getting ready to share from the tact to the governing board pretty soon that that defines all that. It's it's analogous to the cncf but not exactly the same because we are different Foundation services. All right last thing for people who are more want more information around get bomb.
dev? That's easy and I assumed some probably on get up to this. That's up on GitHub with a GitHub org.
I think I think it's git Dash bomb on GitHub and just get bomb git bom dot Dev or tune into my talk Tuesday afternoon. You can do that. Even if you're not here in Austin again, as I said in the beginning of your missed it it is available as a virtual event.
Well anyway, but this was probably the longest 15 minute and you you've ever done. But I wouldn't thank you. Well, we get a lot to come.
Yeah, we had a lot to cover. I want to thank you. Thank you for all you do not not just for being on our show, but for all you doing for communities around open source and elsewhere as well as the security work.
Thanks so much for having me Allen. My pleasure. Thank you.
Aeva Black here on textrung TV. We're live in Austin. We'll be back soon with some other interesting folks to speak with.