Andrew Aitken, Wipro Lmtd | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. We just took a quick little break here for lunch.
But we're back in Austin at the Linux foundation's open security Summit. I'm really happy to joined by our next guest. His name is Andrew Aitken and Andrew works from Repro whipro Wipro and and he is sort of well, he is the we Pro rap to The Linux foundation in all in various aspects and sub foundations of the LF as well as open source in general, but we're gonna dive into that in a little bit here Andrew.
Welcome new texturung TV. Thanks for joining us. Thank you for inviting me happy to be here.
I'm glad to have you so Andrew. I I mean I did my best right but you can do better explain to the audience. You know, what what you do is as part of where Pro and I think most of our audience knows who we're always but probably wouldn't hurt to give them a little background on that too.
Sure. For those of you who may not be familiar with Wipro. We Are One the large Global Systems integrators somewhere around 240,000 employees across the planet today.
We are a fairly traditional systems integrator. We provide resources Solutions Technology Innovation to our to our clients again across the globe and across all industry sectors my role. I am the head of open source for whippo I am Office of CTO my team and I and really we are the face of open source for for Wipro and for the this community the analyst Community clients and and so on.
And I'm here representing Wipro for at this at the open source Summit and as the board Observer for open ssf. Sure. So let's talk about we're pro a little bit.
Look you don't get 240,000 odd people without being deeply embedded into You know a good chunk of the global 2000 Global 2000 and Beyond. Yeah and You know with that kind of coverage with that kind of footprint when we talk about being the head of Open Source or what we're prose, you know, open source strategies and and tools and everything are there's a big there's a big chunk of business right when when you think about how much software and so forth is based or anything is open source or contains open source. Today, you know, this is this is important.
It's very important depending upon which of the analysts or reports that that you subscribe to over 90% of production software in the world. Today is either completely based on open source, or has a portion of Open Source on it. Yeah.
So it's it's very critical software. Absolutely. So yeah, this isn't some dusty Corner in the office of the CTO where people are mulling few sorts licenses or something like that.
This is really Dynamic kind of stuff. Secondly, you mentioned you were an observer on the ossf board, but I thought you are on another board or two as well. I am I'm on a few the other one.
The main one that I am the board member of is Finas the fintech open source Foundation one of the very first vertically oriented industry foundations out there most foundations or projects or communities are horizontal based on a technology. This is more vertically or industry oriented. So that's not the finops people who know about Cloud costs.
In fact, right? No, this is fin us with an S. Oh fintecho problems.
Yeah, so it was founded I think about six years ago now by eight of the world's largest banks, and now there they have dozens and dozens of members and organizations like Wipro and and non-bank vendors and it really was set up to provide an environment where Financial Services organizations can open source their own software and kind of a safe and compliant environment with a group of peers who understand what it means to to develop software in such a highly regulated environment. Got it. Excellent.
And I figured me if I didn't catch it. Was there a meaning of them here. I know they have their own event.
They have the open source strategy Summit in London in three weeks. I think that's kind of rare version of this event. They are also under the Linux Foundation umbrella.
They're a sub Foundation as is open ssf and the other Foundation. Oh, yeah. That's the umbrella right?
It's the the legal kind of Format that I think LF favors. Yeah, I always try. I always call them for some reason daughter foundations.
And that's today's world if that's still after it's called some foundations sub Foundation sound good. Yeah, um, you know, it's funny. I I thought I knew about a lot of the foundations but I wasn't I'm not as familiar with Finance.
It's it's one to take a look at they're becoming a real industry driver more and more Global banks are joining them along with the number of the large Tech vendors, so they're really and they're getting involved with some other interesting standards bodies. So they're beginning to promote open source as a standard within Financial Services. Excellent.
Excellent. org? Okay.
Check it out. Yeah. All right.
Let's go to open ssf. They had a big day here yesterday. Yep.
We've interviewed a number of people from the open ssf over the last two days. What what's been you are a board Observer there on behalfa we probably what what's your take our CTO? Subah tatavarte is our board representative, but on the day-to-day basis, I'm the board Observer and drive a lot of the programs.
So and today's obviously continuing more and more open ssf related activities. I just spoke on a panel about an hour ago. My takeaways.
I'm glad to see more and more people are taking paying attention to the to this effort recently. I in my peers were in Washington DC for a number of meetings with agency different agencies who are again also really beginning to pay attention to this issue. Obviously driven by Biden's executive orders of a year over year ago.
But my takeaway is it's interesting to see the overall industry momentum and the collaboration between public and private sector on some of these software supply chain security initiatives. Absolutely. So let me play Devil's Advocate.
Hmm, so I've been in I've been in security for 25 years. I've been in technology from 30 plus years. You know and in security, we always had open source tools that we use to secure.
also far the open ssf's Charter is to secure open source software. Which is great right when 90% of software contains open source. Yep.
It's important. It's important thing. what I'm worried about with the whole supply chain, that's bombs and all of these things is will we focus so much on open source that maybe Something else sneaks through that's not open source, that that's likely to happen right sneaks through.
I don't know. Well, I definitely by definition it kind of snakes through right matter whether it's open source or proprietary. Um, but will it do that because there's too much attention on open source.
I don't know that that's the case. I don't know if that can be the case. The fact is there's not enough attention today.
We've heard there's a whole bunch of initiatives for example around SBOM everywhere SBOM anywhere, right? We did our own survey of our customers and about 65 responses. I think and of those You know a dozen were actually asking for s-bombs.
Far fewer were getting s bombs and then even the s-bombs they they received they couldn't really do much with them. So the fact that we're there's a lot of talk around s-bombs and Biden's executive orders doesn't mean that there's actually a lot going on at the end user consumer. Point it's it's we have a long long way to go.
Yeah. I I don't I don't doubt it. Right especially when you're doing 90% of the so far as open sorts.
Look if you covered 90% that's pretty damn good. Yes. I I think also part of it is we spent so long.
kind of fight and when I say we I mean at the Enterprise level right for so long a lot of Enterprises sort of fought Open source software. I was like, oh no. Who you gonna call for support, right you're gonna get training I get it and and then there was this there was this also this especially as I was coming up, right?
It was this like two-faced argument, which is well open source software is secure by more secure by Design. Because there's more eyeballs. Yeah.
And you know, how could something be insecure when everyone's but the fact of the matter is who the heck looks at the source code, you know, very few people are actually unfortunately. We're testing these open source. Tools components whatever that you just so you use Andrew used it good right for me.
I'll use it too. And and so we you know, it really became. You know, it was a fallacy about the open Ice.
Or do you know how many sets of eyes the not necessary fallacy? It's it was actually the impact. It was maybe not what that truism says, right because People and I've been in open source for 22 years.
That's probably one of the very first people to be wearing a suit in open source. Mm-hmm, and I fought many many of those early early battles. And I think the issue is that developers open source developers people who are creating all this new Innovative technology, right?
They don't they don't grow up thinking about secure by Design right or secure from the ground up. They just wanted to get good code out there or code and make it good over time and make it Innovative and make it useful to themselves and to others right? They weren't worrying about the security issues.
And today that's one of the the challenges for the open ssf and it's members is working with the projects and helping them understand why it's important to implement secure coding best practices and providing them the resources to do so because open ssf represents big brother, right? If you look at who the members are that's just the reality or the perception that many open source projects have is okay, we should be improving our our the way we develop software, but we don't want you to tell us how Right. And so you have to find this balance as the open ssf has to find this balance.
In working with the projects and communities and saying we're we're here to help and we truly are and we're not going to try and change the way you develop software. Totally. We're going to try and help you improve it.
Good great. now The other thing that I spent a lot of today talking to a bunch of folks from openness I said, I've broken a bunch of other people as well on various. Sub foundations or some groups within Linux Foundation.
It it's amazing and maybe it's just because when your Hammer everything looks like it now, but it's amazing to me. How much? Oxygen open SSI is attracting right now.
Absolutely I mean and I mean, I think it speaks to just how important it is. That's what the security guy and he says yeah, I've heard this story before top three priority top three priority. Yeah, and here we are still with issues.
That we have an address. So open ssf is still primarily vendor driven. There are some end user consumer organizations like JPMorgan and City and a few others, right that's going to change, you know over time.
I expect more end users to join but it's a vendor driven organization who understands the issue because we're the ones that that actually use the open source to build our products and then bring those products to market sell them to our consumers. I mean our customers right so we know at kind of a core level that this is a huge issue. That doesn't necessarily mean that the end user consumer one, even if they recognize it as an issue has the ability to actually do anything about it.
One of the things I shared during my talk is how many titles that I have seen in our customers just the title has gone from devops. to SecOps and when you ask those people, so what does that mean now that you have those additional three letters in your title, and they're like not really much of anything. Right.
com. Okay, but we're also Security Boulevard and I've been bringing the deaf SEC Ops event RSA for seven years. Yeah.
And I've said this publicly before to me. There was always second devops. It was always part of it, but by putting those three letters in there.
We clearly sent a message to the security community that hey you're part of this too. Not necessarily that shift left and and right excuse everyone's responsibility wasn't already something we should be doing but it it gave the security folks who for a long time were a Wandering tribe in the desert, right? Yeah.
They weren't really part of it. They were kind of in Risk in some places and other places. They are ID, they were clearly other right not them other and so it made them them right?
That was a good thing. Excuse me. I do want to point out that adding those three letters has it necessarily translated.
Yeah do additional training additional headcount additional budget it is you are now deaf secops figure it out without any additional resources. So I tell you what and I spend a good chunk of my time talking to vendors and offered devsec Absolution and to end users who employ them. Here's the funny thing.
No, it hasn't necessarily added to budget. And in fact, most of secops solutions still come out of the security budget not out of the developer budget or devops if you want to call it that budget. And that that's the fact right?
That's so that I understand is true. But what we are seeing is it more traditional devops tools are now beginning to include security components to it. So that's a very positive development.
I think it's gonna it is now bringing additional capabilities to the tools that many devops people have been using for years and a lot of that I'll tell you is through Partnerships like the sneak for instance. There's a great job. Yeah.
Absolutely Partners in another company shift left is a bunch of the dev set up vendors who recognize that look in order to make tools for developers. You got to kind of embed this stuff in the tools. They're using yep.
With a platforms they're on or whatever you want to call it. And is everyone today is a platform but it's interesting and bodes. Well, right.
Yeah that that's my only good I think about as well. Absolutely. Yeah.
Hey, we're overtime, but I want to talk about we Pro a little bit. We're pro. I mean obviously CTO on the board of open sslm you are kind of the liaison to Lennox Foundation open source, beyond the obvious.
Why why is this so important to we're pro it it boils down to trust Right, we we talk about. Being a trusted partner to our our clients. How can you how can you do that?
If you're not paying attention to their security whether your customers are or not? Right. So that's one of that is at the end of the day the core reason that we're investing in this now there are all sorts of other benefits, but it's making sure that our trust our customers.
Have real trust in US understand that we from a software security best perspective. We have their best interests. And there's all sorts again.
There's benefits in upskilling our Resources by participating here and through contributing through the training programs. It helps with our branding and our differentiation our ability to recruit good good developers. They're all other all these are a lot of benefits.
These are core benefits, but the end of the day is trust excellent, man. Hey, I want to thank you for coming on today. I don't want to thank you for all the work you're doing in the community.
Well, thank you and I appreciate the time. Alrighty. Andrew Aitken from Wipro here board Observer an open ssf board member of sinus another Linux foundation and would you say about three weeks is a big fenox Conference Center Finance.
Yeah in London. Yeah, excellent. All right, we're gonna take a break.
We've got a full line up this afternoon of folks here. So stand by we'll be right back.