David A. Wheeler, Linux Foundation | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone, we're back. I hope you can hear me.
My microphone's a little a little messed up here, but In fixing it, they mangled it. But anyway, we're live in Austin at the Linux Foundation open source, security Summit. I am joined by David a Wheeler not to be confused with any of the other many David wheelers out there, but David welcome.
Thanks for joining us. Thank you very much. So Well, I'm not getting introduce.
I'm gonna let you introduce yourself. I've given them your name, but tell tell our audience who who's David a Wheeler. Okay.
Well what many ways to answer that one, but I guess what you're probably looking for family show. Okay, so I work for the Linux foundation and my title tells me that I'm the director of Open Source supply chain security and what the heck does that mean quickly? It's I'm a subject matter expert I go around to the various foundations within the Linux foundation and really in some guys with with other foundations and projects as well.
Trying to help improve the security of Open Source software, which we all depend on all around the world got it and I should say I mean soup did not saying we're from it's in the developers head getting into a Version Control built turning into a package just all the way top operations. Absolutely. So look as I was kidding around before we went live we've had Shortage of open source security of the nine open source here supply chain security discussions in the last two days.
It is the top of the line here and quite frankly. We were in RSA conference two weeks ago doing similar interviews are broadcast alley and and so for supply chain security was top top of Mind there as well sensibly. So yeah, I put on the Mark Miller and I put on the devsecops event every year at RSA at Moscone and and Not surprisingly open source.
Supply did not open so supply chain security was top there. Just random on my way before sending back down here to the men's room. I ran an allen Friedman.
Yes. He's the yes bar man missed respond Mrs. Bob.
And so all good it certainly a very relevant topic. So I got asking honest question. How long have you had this title?
I only joined the Linux foundation in 2020 April 2020. So you've been super supply chain security that well, that's been my title since I enjoyed in 2020. What's it after solarwinds?
No, that's before solar runs. In fact, I wrote an essay about solar winds as a Linux Foundation employ. That was pretty creation then well, you know what?
I don't I really some people are surprised and where's the supply chain coming from? But you know, all you have to do is look at some of the numbers there are several studies that look at just open source, and they're finding anywhere from 70 to 90% of the components within an application are actually open source. It's not including any proprietary software.
They're reusing. So I I've been around software industry for a while. There was a time when software was pretty much you developed the entire application from scratch all that's right and the big concern then was how do we enable reuse?
How can we make it so that we don't have to write once right at wheel write something once and reuse it and the good news is we have solved that problem but like Ed news is the bad news is if the bad news is fundamentally is that the causes of today's problems are often yesterday's delusion yesterday solution. And so that's very much. So what we're seeing is we have now mostly solve the ReUse problem, but now we have to deal with the because software is mostly other software.
We now need to deal with that other software as a potential source of defects in general including security problems. com right back in 2014. One of the reasons was because I thought it was a great thing for security, but I will say that supply chain security software supply chain security.
We wouldn't have that had it not been for devops. Because I think we've always had and I'll explain to you what I mean. So you don't think okay fine.
I think we've always had to worry about what is the Security posture of any components or scripts or artifacts or whatever we're using in our software. but one of the unique or one of the great contributions to Software and and the way we do technology today, the devops is made has been the introduction of sort of lean it. Lean manufacturing Concepts into building software and its result.
It's not the only thing but it's resulted. One of the things that is contributed towards resulting in this idea of a software Factory, right? We didn't think of software factories before even though oh, yes, we did my University Maryland had such programs.
I think in the 80s. Yeah. Yeah.
So any that concept's been around for a while, but that wasn't commercial now like when we talked about People developing software was very much a custom right developers. They they you know, they started with them. I'll never forget like one of the first companies I started we going to meet with Time Warner and they wanted a it was a customer service after their cable customers or something like that and and they said well They asked my partner.
Well what IDE do you use one ID you use what so all the people this one used Borland. This one used the semantic one and my my partner who is a stone cold code. I said why use VII he just he developed in Beyond so everybody in those days.
I mean that's That's our software was done now today. We really do for the first time on a commercially scalable scale. Have this concept of software factories where software moves along a pipeline.
Right? Right. I mean the whole idea of a CI pipe on isn't really new.
It's just finally it's it's become widely a diet that I would argue that that's not the problem that's part of a solution the supply chain problem. I would argue funneling comes down to you've got all these reused components that enables you to not have to rebuild everything from scratch, but now you're dependent on all those tears and tears and you know, all those those the software that it depends on and the software that depends on and so on but things like see I pipelines can help us address. But again, let's go back to the factory piece.
Yes, what made that assembly line work is the Model T every gear shift on the Model T was the same bowl with the same threads, so I could I could sit here and just screw balls on stick shifts all day, right and and that's how an assembly line in Factory worked. It wasn't. You know, whether it was third party products that were putting in cars or building appliances or whatever you build on your pipeline.
It's I believe right? You can't have too much customization. If you're gonna do that at scale you had to have that you had to agree on some things.
We just have to make sure you agree on the right things. So for example, I think vast numbers you mentioned idea nowadays most we don't care what idea, you know knowing why care that Ireland's not here, you know, basically focusing on first figure out what matters that's always like easier thing to see after the fact it's much harder to figure it out when you're in the midst of the problem. And then okay, this is the part we need to agree on and coming back to the Sea pipelines, you know after I make a proposed change making it go through stages and doing automated tests running various kinds of scanners to look for various kinds of potential problems.
So that by the time you bring it in you have very high confidence that result is going to be is going to be better than what you had before. Yeah, but you know So there was an argument. I forgot what presidential election it was already, but you know cards made in America.
Cars assembled in America. Yes, which is different right parts made in Mexico, right? Wherever sure.
Today, I think our software is like that then yes, it may be assembled by any software. You know who I've done there is during that but the parts I made all over the place. It's frankly in many ways even more than the rest of the physical world because at least in the physical world, there's a cost of physical movement right?
Whereas the bits are essentially free to copy around exactly. So yes, though the world of software development is internationalized. It has been for a while.
It's just that some policy makers haven't noticed, you know, but now we but the other thing that's given rights who's the repost and I don't mean we both carts, right? Yes. I mean the repositories of these software like GitHub and get lab and those kinds of facilities.
Yes. Well, GitHub certainly begin in general okay version of natural system. Yes of yes.
We are. We we are storing reusable code. And in some cases like you look at the doc or right repos and you look at an artifactory or the net necess on some Sunset.
We are storing reusable components. That you could be sitting whether you're sitting here with me or you create right you could pull it down. and assemble, right and that is that's powered.
That's look that's been a an igniter for all kinds of software development. It's also been a security and you know, it's been a bit of a security issue because now we're pulling down what version are you pulling down? Right?
And are you updating because there's a vulnerability found in that version. Are you keeping things up to date? So, I mean I think we both agree on that.
Here's my take I always thought. That the choke point if we can use that word would be at those reposts because that's where people are getting these reusable components. Why wouldn't a repo Have a toll gate or a nest bomb Checker or something.
Whatever you want to call it, right that says. Oh wait David you you pulling down the old version of this. Yeah, you need the new version to be fair that people are actually working on those sorts of things.
The open ssf has something called package and Analysis. Yeah. I actually just spoke to oh about it great great.
So, you know, there are some efforts to do that and I think in many cases it's not so much the repo as the package manager, you know, making it easy to say. Hey, wait a minute. That's a vulnerable version, you know, please update there is any and by the way the openness and stuff has a number of working groups.
And the newest one is specifically for the folks who manage repository. I think that's that's where we got a big yeah and the package repositories and the package managers and I mean, they're just starting but already I have I think there's there's great promise. The challenge that they have is scale though in particular.
Of people, you know, why don't you just take detect all malicious software? Good luck. Wow, you know there are there are tools we can use to detect them in some cases.
It cannot be helpful. Yes, that better not be your only mechanism that exists now and frankly the big one the biggest problems now because most software is actually the soft you bring in one of the biggest problems now is old out of date. Software that I know you vulnerable that needs to be updated if you're ready out there by the way.
Oh, yeah, and and the good news is that there are tools to help you identify tools to help you update but people have to basically to automate it if you're only like a lot of automations there, but you know thing I a lesson I learned in security too over the last 25 years. People talk automation. They get scared when it comes time to automate because they're afraid they're gonna break something else would by doing it automatically.
This is where the CI pipelines come in. Yeah, they fundamentally, you know, I tell people you know, there's some really excellent academic research software testing and that sort of thing but you know what you can make this much simpler how you need automated tests. How many tests you need you need to have tests to be confident that what you release is going to be okay to use if you're automated tests are good enough then if you're on the main test can't do that then they're not a problem.
You got a problem. Once you're automated tests are good enough. Now, you can do things like fearlessly upgrade to a newer package because I ran my tests everything works, but I didn't see of that software on other thing same thing.
You're you as those get updated you immediately notice does it work or not? And and so and so this this combination basically see I've Science including on a made tests various tools to analyze the software looking for vulnerabilities looking for issues. It's it's very simple.
It's not complex, but it's powerful. Yeah, it is no doubt about it. I had something and I went to Freight out of my mind.
It's terrible getting old but you know that back to the this whole concept of that with software supply chain. Look Mark Miller. Was it sonotype right when when starts to was it Equifax, right?
Mm-hmm came out. What was an interesting thing is him and Derek week. So was that sound a type of the time do they did a Survey and some research like six to eight months after Equifax.
Yeah. So we already everyone who would top of the news for charts, right? People are still downloading and using the old version right of struts to in their packages instead of the new version, right?
And there's been a lot of discussion about how do you deal with that? You don't want to break somebody's system and yet this is a real problem for a lot of folks. So there are very discussions about how to deal with this anywhere from maybe slowing down those those bad downloads, you know, so to give a hint Without Really breaking from with system, but there's very ideas.
But you know, it's it's a really issue right now. I think the goal is to just try to make it easy and easier and easier to do the right thing. We want to try to make the default the right thing and then if we truly for the true stragglers Need to find other approaches but let's make it really easy to use a little character a little stick is what I'm hearing in some sense.
You can call making it easy a carrot but I think fundamentally generally people do what is the easy thing to do? So we met the right thing is that's right. We make the right thing the easy thing we don't have to worry so much about the sticks.
Yep. All right, so David this all we've set the table. We used our whole 15 minutes, but we've said the table, let me go now to the next part.
You're the first person we've had on from around open source security that actually is a Linux Foundation employee. Oh, so I got to ask you the question. Beyond Giving the open ssf a home, right you were doing this before there was hoping that sets up.
Yes. What is the role of the Linux foundation in your mind? Okay in making open source security open source software more secure.
Well, actually, let me step back further because there's the question of what is the purpose of this Foundation? Yeah, absolutely period right and and then because I will take because of that. I think the security question follows.
Yeah the fundamental goal of the Linux foundation and really any good open source software Foundation is to enable collaboration. There's all sorts of legal wickets that you can get in trouble with there's there are many things you that a project often needs Beyond just hey, I need a repo with Version Control and so a lot of organizations have decided that it's a lot easier to get things done to get collaboration done if they can create a project within a foundation. There are some Associations that you know create Foundation specifically for a particular project.
I mean the python software Foundation, you know, it's focused on python absolutely and there's many other foundations. The lens Foundation is basically a foundation that creates foundations. So we create foundations to quickly get going and why do we create foundations and more specifically why I create projects the answer is to solve a problem.
So now so that's the general now the more specific what about security same kind of thing don't we need to make things more secure and specifically open source software more secure. Oh, how do we do that collab we want to do collaboration to because it's too hard for anyone organization to do it themselves. Oh that makes sense Foundation to do because as soon as you say we want to enable collaboration to solve a problem.
That's what the link Foundation is for and really I would say any foundation. I mean, I work the foundation I like them, but you know it really, you know, I work for the links Foundation but really that should be the job of any foundation is trying to help enable collaboration in terms of Open Source software foundation. And in this particular issue though in the Linux foundations, one of the largest maybe the largest open source software foundation and just kind of made sense for the many many many people that have to deal with security.
Is this is truly an industry-wide issue? So it made sense to put this in the Linux Foundation to work on industry-wide Solutions. I love it.
I love it. Hey, man, we're overtime. Okay.
Can I make a couple of quick points go? All right. So I just you know before we head off, I would love to encourage anybody who sees this thing talk to them talk to them.
Okay? Hello them. Okay.
So if you develop open source software, I would love for you to take advantage of some of the stuff that we've already developed within the Linux foundation and especially the open ssf. So there's a free course on how to develop secure software. If you haven't taken of course take that course, we have all sorts of guidance on best practices and how to develop software more securely, you know best practices badge.
There's a scorecards if I project is something called Salsa to help identify some key requirements for the supply chain and build and so we've got some good stuff take a look. I think you Users will be grateful. Absolutely anything else?
I'm sure there is but we're out of time. All right. Hey, look you're invited back anytime you want.
Thank you. David a Wheeler Linux Foundation open source. software supply chain security Director, I got a little light of order, but I think I got all the words.
Here in Austin. We'll be back in a minute with our next guest. Thanks.