Amir Montazery, Open Source Technology Improvement Fund | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. Wow.
What a morning. I don't even I lost count, but we did a lot of great interviews great conversations this morning a lot of it as we've been doing all week has been around security. I think we're gonna continue talking a little bit about security with our next guest here.
Let me introduce you and if I mess up his name, he'll correct me Amir Montazery. It right. I'm your Montessori.
Yes Montez area. Okay. Yeah.
I've got that New York accent. But anyway, I'm here man. Welcome.
Welcome TV. Thank you. So happy to be here.
Yep. So, you know, I guess we'll start with the obvious question of what brings you here. Yeah.
Absolutely. So I co-founded ostif the open source technology Improvement fund which was designed to solve the classic problem in open source of how do we make open source more secure. How do we do it in a way that doesn't disrupt open source project maintainers and the great work that they do and how do we do it in a way that's impactful.
And so we started exploring this problem. And so what when did you sort of been over seven years ago now wow, so it was about seven years ago. Some of the inspiration came from the CII the core infrastructure initiative.
That was also attempting to solve this problem as well. And it's a very big and complex problem. So it needs all the all the help it can get ahead.
Yes. And so so since then we have honed in on a method for helping projects and the organizations that support those projects with auditing and improving security holistically and we Champion that audit process from start to finish. So a project can come to us and say we want this project audited and we get it done and what are you auditing it for for security for stability viability correct mostly for security and sustainability.
So a lot of research suggests that a lot of those deep-seated problems. Vulnerabilities and bugs aren't on the surface level when you look at the code. They are deep into the code.
So deeper auditing more logic review. So you're really doing code audit correct? Not not auditing how many maintainers there are exactly the liquid scorecard does and our last guys, this is really looking at the code and seeing how How safe is the code how secure exactly?
Yes, and so part of this process that we've developed in the method that we've developed is. Finding the best suited teams out there folks from all around the world audit teams from all around the world finding the best suited ones the most specialized ones that can do this kind of work. I love this resulted in it's been very successful.
Thankfully we've found over 40 critical or high vulnerability risk vulnerabilities. These are those deep-seated problems at when exploited in the wild can cause headlines cause those kind of things you read about log for Shell or lead all that good stuff. So we're going out in proactively finding these problems and fixing them, of course because a great part of our method is not only finding these problems but our Auditors work with the maintainers to fix them as well.
Love it. I have a few questions on that, but before we jump into that I want to give our people at home. So it's oh open source technology Improvement fund.
Yes already go on the web. org. That's what we were wanting.
Okay. Now I hear the word finding I'm thinking well, maybe there's fundraising involved here. Yes, so the fundraising typically comes from the organizations and foundations that are stewards of these open source projects or kind of the the supporters are maintainers of it.
So they they pay you to Due to perform this service, correct? Yes, and another a really nice thing about our method too. Is that instead of just working with one or two audit teams?
We're able to actually go to a large number of them and effectively have them bid against each other as well. So we're able to do it for almost a third of the costs that kind of more traditional audits in this space cost. It's great.
And I being that kind of that champion to manage this process. It makes the quality bar much higher as well if these reviews got it. So let me go back to what we were talking about before I I wanted to just give people a sense right away.
Yeah, I want to check this, you know, people are there listening? They'll go check the site out, but you know We find a deep-seated vulnerability defect whatever you want to call it. Come up with a way to fix it.
So let's take sort of struts and struts too is an example. Okay. So now we fixed it and we need to update to the new version and all the repositories out there where people download this this open source code from And not only do we need to update all those repositories but we've got to somehow notify all of the people who have Incorporated that.
Code into their projects into their applications they're using it. To hey, we got a problem. You need to update this right?
It's one thing when we're talking about an OS. Right and you can kind of you know hit people like that or a phone app that you can do, but how do you do it? So that's a great question.
That's a really great question. I would say the what we do to help with that is we really focus on transparency. So once all of the work is done fix this have been made remedy.
They've been tested we know that the fixes are are in fact fixed. We put all of that into an audit report that is then published publicly to the for free for anyone to review and we're also Publishing those out onto the Open ssf Security reviews repo which is a collection of these types of this type of work to really get the word out there. And I think the one of the biggest value adds that that provides is being able to show the open source community at large what was done how we fixed it so that they can take that back to their teams and and learn from them service case studies and really just raise the bar as a whole of open source security.
I love it. So it sounds to me then look the mission of your group is to undertake this audit uncover if there's any kind of, you know, vulnerability defects that we got to fix fix it publish the fix publish the background on it and then we need the community. It sounds like to get involved from that point on and the users of the Consumers of this stuff, right?
You know the old saying you could lead the horse to water exactly right, but they need to go update and and do their thing. Have you thought about maybe adding that aspect to The the charter of your organization. Um I'm I don't think we have no we've been so hyper focused on.
Well, it's a big job. Yeah. Yeah, and there's a lot of big jobs involved.
Unfortunately in this whole thing indeed. Yes, but part of I think why we've been so successful is Focusing on solving the problem the way this is what you someone else has to do that exactly but a couple a couple great things that are happening are as there's more awareness in the space. There's more funding being put into security auditing and more attention being drawn to it.
I'm hoping that that will basically improve the landscape as a whole and we can take lessons from what else is going on out in the space and incorporate that into our processes to but I think by focusing our Focus really I think has led to our success and that you know, we'd had lots of folks early on say hey, why don't you do this? Why don't you do that? Why don't you try this?
Why don't you try that and while you know, well gladly take any feedback and advice. I think just being really hyper focused on facilitating executing on these audits improving the software pots or the security posture rather. Of this projects we've been able to be pretty successful.
actually I wanted to Pivot a little bit and ask you. I mean look you started this seven years ago. There wasn't an open ssf that over the last I I guess it's been about two years now year and a half.
We open this SF. You know from the Linux Foundation how has the the Advent of the open ssf kind of? Helped hurt boosted.
You know, what effect is it at? Mm-hmm on your organization? Yeah, that's a great question.
I would say overall it's helped because as you know, open source is largely relatively decentralized and having a strong Consortium of organizations foundations individuals who are focused on solving this problem kind of giving them a platform or a forum to to talk about this stuff has been really helpful and I think another way open ssf has helped is by going out and actually doing some of the fundraising getting more money into security and in more awareness, you know from both generally and in government as well with the with the executive order responses and those and those efforts. I mean, it's certainly broad a big spotlight. yeah to the whole area and You know, we're a lot stronger together than we are individually.
So, you know, I think that obvious yes, um, but you know, there's a there's a little bit of a chicken and an egg question here, which is you know, if not for the solar winds and some of these really high profile Supply software supply chain issues with open ssf in the whole open source software. You know Market got the attention that it has unfortunately because of these things, right? I mean you obviously believe this was a problem seven years ago, right and you went out and did this.
So, this is not a new problem since whenever solo was once December of or January goes December, I believe so, yeah of 2021 or something right or 20 or one of them. I don't even remember but 20 so this has been an ongoing problem. So certainly right, you know, sometimes sometimes things just come together right?
It's like fate and it just boom it blows up, you know in many ways. You're the you're one of the benefactors because you were here, you know kind of shouting in the wilderness, right? Yes about this issue before it was you know with the cool kids.
Yes. Um, where do you see it going in the future? Yeah.
So I do think it's it's human nature to to react right to be reactive and I think largely what has been driving the the progress made in the space has been reactive and one thing that we're trying to do with our with our Audits and with the With getting the word out about the work that we're doing is to try and shift to be more proactive because we can you know, wait for the problems to happen or we can proactively go out there and fix the problems. And so I hope I think and I hope that the focus shifts more towards proactive security as opposed to reactive security and because the benefits of proactive security are You don't see it as much, you know, when you prevent a problem from happening in the future that never happened. It's hard to attribute that to the that probe that action you.
Okay, but when something happens like you scrape your knee or something you you have something very real that happens. You can react to it, you know much stronger. So in general I'd like to shift to focus more towards proactive security which definitely seems to be where the open ssf and organizations that are part of open ssf seem to be going and it's something that I would love to really help take the organization take open ssf to the Forefront of that and really be one of the Premier organizations in the world that is actually going out and proactively fixing problems.
Yeah. Look I I think with the open ssf behind you was that you have Expectation of being able to do that, right? There's no in fact, you should do that, but you know what?
It's great and it's Look on a personal level. I'm great grateful to hear about people like you doing this. Before you know as I said before the cold kids got involved because we needed this.
This isn't a problem since solo wins. Yeah, and and I think the beauty is asleep. Now that it's more action as being called for we have been doing this for seven years now.
So we had a lot of lessons learned. Yeah, a lot of bloody idiot taxes paid. Yes, exactly.
And and we both Point we've gotten to a pretty good level where we are confident that we can do this. But as always, you know, open source in general is largely underfunded and us as an organization, you know, we need funding as well, you know to continue doing this to scale that's money. Yeah, exactly.
So to scale up even and to do more work that I know we're capable of doing so hopefully again as more fun and goes into the space as a whole more funding goes into open ssf and other foundations doing this work and US supporting those goals I'm hoping more funding will come our way as well. I hope so too. Hey, man, thank you so much.
My pleasure. Good. Keep up the great work and we're gonna take a break here for lunch in Austin.
I think we'll be back in about an hour. Okay, stay tuned where we are live here at open source Summit. Thank you everyone.
Thank you Ellen. Thank you, man. That was great easy.
Yeah, that's all right.