Caleb Brown, Google | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. We're back here live in Austin continuing our coverage of Linux Foundation open source Summit and and forgive me if we're a little security heavy this week, but it's actually it's it's good for my soul to see security taking Center Stage here first and front and center.
Our next guest is Caleb Brown Caleb joins us from Sydney. Yes, I come from Sydney on behalf of Google and the open source security team. Absolutely Kayla first of all welcome and thanks for joining us.
My pleasure. Second of all. We were talking off camera.
I know several friends in the Google security world, but not in the open source security team. So tell me what's the charter for the Google open source security team. That's a great question and what I should be able to answer the top of my head.
I've only been with the team like a six to nine months. So I'm still like I feel green but The charter is to like improve the security of Open Source and to make it safe and secure for people to consume. And so we work very closely with the open ssf and and a lot of our work is through them and through the projects that they run.
Well Google is one of the biggest corporate benefactors. Of open ssf but they're not alone. No that IBM Microsoft to name some of the big ones and I there's a lot more ideas 30 or 50.
Oh, it's growing really rapidly and growing every day. I was gonna say that. And and I mean look, you don't have to be a rocket scientist to figure out why Google is invested in this Google.
probably one of the biggest Open source I consumers as well as open source creators in the world. So if we're going to Tackle open source security head on you'd want Google involved in it AVID for obvious reasons totally agree. Yep.
Yeah, so Look six to nine months is a lifetime in Tech right his internet time. You're like 21 years in on this but you know, we were talking a little off off camera. Your background is is more in in devops and so like so I've worked on a variety of projects but my interest in terms of places that I I've enjoyed kind of having an impact and being able to work has been in thinking through like, how can we make what we how can we make the process of development like not just easier for developers but easier to like repeatable and safe and to be able to like be confident that we're gonna be able to ship products that are going to work for our customers.
Absolutely. Yeah. And you know, and again we were talking off camera this whole notion of calling something software supply chain security.
you know, if you're from a devops background, you know how much it borrows from lean and lean it and lean engine how much lean it borrow some lean manufacturing so that whole notion of supply chain and supply chain security to me is like lifted out of the lean lexicon and and so You know, so it's a very devops. Centric view of how we build software and how we should secure it for sure. Yeah that being said It's been a tough couple years.
Okay, we've had some very very high profile incidents and you know not to say didn't happen before and it won't happen again, but certainly the last few years have been the tough, you know, and it's shined a real Spotlight on this. Yeah. I think that's a huge part of driving.
The growth of the open SS. Oh no space is is the pretty prior incident. Yeah the focus from the White House those sorts of things.
Yeah. You know what? I've been in security 20 something almost 25 years.
I will tell you there's nothing better for security than a good old breach or incident, right because that gets people religion, right and and but it's amazing memories are short lived in and they go back to their old ways is what it is anyway. Let's talk about you know, what? What is Google?
And I'm asking, you know on behalf of you know in your position here. What do you guys seeing from the open ssf that gives you like makes you optimistic that says hey we're doing something on the right track here. I I am a few things that I'm kind of been really impressed to see particularly yesterday in the open ssf day was And also my involvement through the open ssf is the like growing adoption of things like Sig store for artifact signing and at a station and osv being more broadly adopted.
So those sorts of initiatives give me some hope that always yeah, I don't know. So I was IV is I'm going to get the name wrong. It's it's basically you open source, it could be but it's it's kind of a cve.
I can't remember and I'm like my team in Sydney is the one working on it. I wouldn't actually gonna go anyway, it's it's kind of a a contributor an open approach to things like cve. Oh, so again TV is kind of centralized and why don't this and if somehow looks at the CV and goes that's wrong or we need to update that it's very hard.
Actually look I was I don't mean to give you a tripped up question, right? Do we've had guests explained it to us and it really from what I know about it. And if I'm wrong you could blame me don't blame Caleb from what I know about it is cve is rather rigid and that they tell you if something is a critical or medium or light kind of vulnerability.
with osv there are other factors that get put into the mix that allow an organization each organization on there for their world to rate a given vulnerability or a given condition. As oh this is red, you know red yellow or whatever you want to scale it the the other big problem. It's trying to solve is it's really hard to kind of take that and then process it in a way where you can do it at scale.
So osv is like a specific schema around how this vulnerability information is defined so that you can build tooling around it. Yes, and you can automate the process of linking up your internal dependencies to the report so and super valuable putting the cherry on it gives organizations a chance to customize this with their own. Environments in their own risk factors and everything else which is important, right?
That was always one of the things with cve just because you're categorizing it is critical. Look. It's yeah for us.
It's not because for whatever reason right, we've got it walled off. It's it's whatever. I think that is important.
I'd like to so you had much into involvement with some of the other ossf partners. I'll get to that you mean the other companies. Yeah, we've I've been some small collaboration some with IBM on one of the projects that I'm involved in the which has been really interesting and a little bit with sonotype as well.
I've come like bumped into them on another project that I work on as well. I haven't had a lot of opportunities to be engaged and it's like very early days but it's one of the things I'm actually also it's really exciting about this space is that there's this place where people are communicating right from different companies to try and come up with things together rather than somebody saying here's a thing we built please use it and yeah and never go look, open source security and software supply chain security is so important right now that It's too important to let it become balkanized right to let it to become. You know every company has their own flavor of this.
because you never gonna really address the totality of of it if if it's broken into 20 different flavors languages, that's right and variations this this is something that screamed out for a industry-wide response and it just so I'm in that open ssf was I mean sometimes things happen for a reason right? I was talking to the guy the person before you supply chain security company based on Tel Aviv. They were founded I think in December of 2019.
The next month solarwinds not was that snake by the way? No. No, they're older than okay.
They're oh legit. I think it was the name of oh, okay. Yeah sneaks a little older.
But but anyway, you know talk about better to be lucky than smart. Sometimes you're gonna start a software supply chain company a month or two before the solar winds incident is in a bad time to do it. No, it's very fortunate.
Yeah, but unfortunate for people who well love it, right and you know, I'm not minimizing any of the suffering or aggravation it's close, but you know, certainly It seems to me is just someone setting I'm not as involved as you are that excuse me. having an organization like this to tackle the problem that we're seeing right now. If this was five years ago, what would we be doing?
Right? You know, we'd be yeah people were trouble. So I like like even the collaboration amongst the the package repositories.
It's been amazing to see where you have people from may even and ruby gems and Pipi and mpm all these different parts of the world like an open source being together in a room and talking about what's going on and how can they improve their their security? That's a great thing to see and I think it's going to have absolutely I think it will. And you know when 90% of the software were using has open source in it.
It's a it's a it's the time has come for this right. This is oh, yeah, this was best time even so I'm really happy to be you know involved in that you mentioned several projects are involved in why don't you tell us a little show things. I I'm involved into kind of the still growing and establishing projects.
The first is about scoring and discovering critical projects. So one of open ssf's kind of biggest thing is to make spend money and and make the most critical projects secure or more secure and I guess a big question in that is like what are the critical projects? So there is a working group that is involved in trying to like answer that question and there are various approaches.
So open ssf spent money like collaborated with Harvard to produce the Harvard census report, which is academic researchers looking at Data from some organizations about how their dependencies fit together and how what are the critical dependencies based on that? And then there in the working group as well they're talking about how can we engage experts in communities to be able to get their thoughts on what is or isn't critical the project I'm specifically involved in is about doing that programmatically and automatically by basically querying sources of data on the internet collecting a bunch of signals about all the projects that are out there and then trying to like computer School basically that we can use to discover what is critical and what's not critical Adventure. It's great stuff.
So yeah big part of this is about automating it and making it so we can keep repeating it. It's hard to query experts over and over again. It's hard to conduct research in a way that's regular and repeatable but computers are really good.
Doing automatic things. So yeah, that's what we're trying to do. There's Something's Gonna work.
That should work. Right? Yeah.
So yeah that that's at the stage where like I'm trying to kind of get it get up and get it automated but we're all so interested in how organizations can use this project for understanding their own dependencies and what things that they use that are critical as well so that yeah, they can see the like where they're I guess gaps and exposure is to and hopefully invest back into open source in those areas where where they can and where they need to so I love it. That's that project. Yeah, and I also work on another one.
It's got a really boring name. It's just called package analysis and what it does is the way I've been explaining it because it's kind of tricky is it's basically like a viral virus scanning for open source packages on package repositories. When you say it's looking for virus, so it's not it's not actually looking for viruses.
It's what it's trying to do is collect behavioral data and the way it works is it watches for an update for on the package of repository? So someone posts a new package to npm it'll detect that and download it and then it does currently only does dynamic analysis, but it'll run dynamical analysis on the mpm package in a sandbox and it sees what are the DNS requests. Is it making what are the sockets that's opening?
And what are the files that's touching. Is it exactly executing commands and from that in like then stores that information and then the idea is that researchers could use that as a way to find malicious packages, which is what I've basically been doing with it for the moment. But you can also then use that over time to start to get a picture of how package might change in terms of Its Behavior.
So if somebody compromises an account for a repository maintainer our package maintainer We can see that thing was just doing normal stuff. And now suddenly it's hitting some random domain on the internet. Maybe that's a problem could be.
Yeah, and so hopefully like in the next steps. It's about kind of integrating in a way where developers can better use that data that we're generating so that we can be meaningful like that data is Meaningful and useful to somebody other than people who are using that the database as a security researching tool. So yeah, so that's where we're heading with that and it's kind of Both interesting to see what it can detect.
It's very early stages. So we haven't got a whole lot of kind of smarts built into it, but even steel where detecting things which yeah is great, but it's also kind of like a sign of how much with how far we've got to go and improving things. So that's a fine beginning as they see in Las Vegas.
That's right. Other thing is it's really important. I feel it's important to be doing this as well because supply chain Integrity is going to solve a lot of problems where you can be confident that That binary that package you've got is what like is from somebody, but if you don't if that person is untrustworthy and build something insecure or malicious, and then delivers it to you.
They can have the perfect supply chain software supply chain Integrity all the signing and signatures can be correct. The attestation might be correct, but if that thing is itself malicious, then that's a place for package analysis sit there and be able to detect where that still happening. So love it.
Sounds great, man. Hey Caleb. We're overtime guys pull it, but it's not principal.
Thank you for coming all the way here from Sydney. Thank you for your involvement in the open ssf and for the projects you're on and when she nothing but success with this man. Thanks Ellen.
We're all falling for you. Yeah. No your success is all of our success.
So thank you very much. Caleb Brown Google open source security and member of the open ssf here at we're on techstruck TV. We're live in Austin for the Linux Foundation open source summit.
We're gonna take a break. We'll be right back.