Derick Townsend, Legit Security | Open Source Summit NA 2022
Transcript
This is Textron TV. All right everyone. We're back here continuing our coverage from the open source.
Security Summit in Austin. Our next guest is Derek Townsend Town Townsend, like you like Pete Townsend Derek's with legit security to Legit to Quit. We've we've actually covered legit Security on Tech short TV before but they are an exhibitor here and we didn't really talk about it up.
We're on the second floor here at the JW Marriott. I believe it's the third note. It's on the fourth floor fourth floor is the sponsors exhibit area.
It's a large exhibit area legit is one of the exhibitors there, but on top of that they're also a member of the open ssf. I always open source security foundation ossf and we're gonna talk about that. We're gonna talk about supply chain some other stuff.
But anyway, Derek welcome. Thanks for Finding us. It's great to be here.
Thank you. And I'd like to get out of the way though. And I I didn't mention it to you when we when we first started which is look not everyone out here knows legit security.
I would you know I said, oh we've covered him before but not everyone watched that either. So why don't we start there man? Let's let's give them a little legit background and a little bit of your background.
Sure. So just background on the company. So legit security is headquartered in Tel Aviv, but almost all of our sales and marketing activity right now is in North America.
So we're selling to larger Enterprises and it's a software supply chain security solution. I think the the interesting thing is it's a really popular space right now. So there's a lot of vendors talking about software supply chain security.
So when you even say that now you kind of have to Define what that means to you. Well, I don't and we're going to Define that in a minute, but not only that. I mean when was legit founded, you know, yes, it was back in 2019.
So it was just prior to solar winds right sometimes just as though I've learned this lesson in business. Sometimes it's better to be lucky than smart and man. What a good time to get into software supply chain security right that the whole world's blown up since then, let's talk a little bit about you though.
What's your background? Oh, I've been doing software startups for quite some time bounce around a different areas developer tools Cloud Management Solutions identity management, which got me into cyber and now here Same here. I've been chasing that.
Well, so text Strong's not Venture back. So it's my this was my blog and it became this but yeah, I know how that goes too. So, let's talk a little software supply chain security.
As we said, it's it's certainly a Hot Topic even here, right? This is our second day here, you know, I'm gonna say filming but that's an old word recording and speaking with folks broadcasting streaming. And you know, that's been topic one.
Yeah software supply chain security and it was interesting. I had a conversation earlier today with the one of our guests. And it's like so this is a word that's coming to Vogue.
Let's say in the last two years right maybe since solarwinds. But really what we talk about. When we say software supply chain security.
Goes back a lot longer than two years. Right, we've always been worried. I mean, look I You know.
I remember selling Security in the federal government space years and years ago 15 years ago and they were worried about back doors and about what was embedded in the software they were They were installing back then. We just don't supply chain security, right? What's legit's take on this?
Well, I think a lot has transpired with devops that has made software supply chain security a more urgent problem and a much broader attack surface. I think rewind the clock years ago. There was always a risk of Insider attack.
There was always a risk of some open source libraries potentially causing a vulnerability, but now when you look at devops and what's happened across the sdlc All the different tools all the different developers and collaborators that get involved all those moving Parts have gotten much more complicated and although Cloud security and other aspects of code scanning Technologies are getting more mature looking at the sdlc and all of its complexity and all of its moving parts has not caught up and solarwinds was the wake-up call and it wasn't the only one no several after that and now that's why you're seeing this rush into the space. yeah, so I I don't disagree but I I would add to it in this way when we look at what devops is about right and There's no official definition and all that but certainly was a big dose of agile. Yeah, and some a pinch of lean it right added into that and and you know how we do Deb and Ops and in the whole software development life cycle pipelines all of these things, you know, it introduced especially from the lean Heritage from lean manufacturing and Deming and all that stuff, right it introduced this.
analog of of people building software the way we build stuff and assembly lines. Yes, you know on a pipeline and and it goes along the pipeline getting finished until it's delivered until it's deployed. And and so I think the very name software supply chain security comes from supply chain security.
Yeah, right that we see there. So I I think that's the Heritage for it of where that analogy comes in for something that as we both said we has been done before necessarily, but we've never had software. Be developed in the factory sort of mode.
Yes, that devops is introduced. I think factories are good word because Factory also connotes automation. Yep, and the automation is there.
Yeah at all of these multiple steps and it's also got this sense of kind of lean manufacturing and just in time assembly that takes place from multiple different sources and dependencies and that's part of the complexity problem. And then you add on top of that. You've got different Developers.
Different teams contractors other folks coming in and out. It's a very Dynamic environment and that is representative of modern kind of physical Supply chains today too. Absolutely.
So let me ask another question that I've spent the last two days talking probably to a dozen people already about software supply chain security s bombs and so forth. my fear Is everything a person I spoke to gave me a different story? Yeah, or not a different story but a different take On this issue and and that's okay.
You know that there's no one right way one wrong way. The world doesn't go necessarily go black white right this gray, but my take is are we gonna extend it and embrace it for every single vendor out here? Yeah until you Unix fire it right where you have all these different flavors, but they're not really compatible, you know cybers interesting and and you look at the evolution of different categories of Cyber Solutions.
It takes a little bit of time for to gel and for the boundaries to kind of could be right where we are in categorize and I think this is early days. There is no formal category defined by someone like a Gartner or a forest or yet for what software supply chain security is But I think what you're seeing is that when you look at the attacks, they come from a lot of different vectors and there's a lot of lateral movement. And so someone can claim a kind of a more narrow scope solution to software supply chain security.
It's not exactly wrong. It could be one attack Vector. But when we think about it, we we think that what the market needs is something more holistic that looks across everything from when the developers submits the code it goes through the build server you go through the artifact repo and it gets just ready to go into production that to us is the scope of the software supply chain.
So it's the pipeline it's the systems and infrastructure in that pipeline. It's the developers and the collaborators that are interacting in it. And it's also the code that's passing through it.
But where we draw the line internally is that we're not a code scanning tool. We're not sassed. We're not SCA.
Those are well defined categories lots of vendors in it mature Tech. We're not trying to recreate that wheel, but there are some other pieces of code security like secret scanning and scanning infrastructures that code that still have space and we think are still part of that integral solution. But our take is don't try to replace them.
But there's value in finding where they are positioned across a software supply chain. So sometimes you know your sa tool got turned off or sometimes you don't have SAS scanning on a product line you should and just getting visibility into that is really important and the other thing that we're finding this is at the intersection of Dev and security devsecops. Development teams might know some of this kind of back of the envelope or back of their hand.
They know where these tools are the security folks don't necessarily and so it starts in our mind getting visibility into that whole pipeline that whole sdlc first including knowing where the other security controls are and now you can start taking action. Now you can start doing important things to tighten up your security posture. Love it.
I want to talk a little ossf participation. So legits of corporate member of the ossf along with some of the you know, the biggest names IBM Microsoft Google. Yeah big big Tech.
What do you guys like? What's your and I don't mean you personally butcher. What do you see is the role of legit Security in this kind of organization.
Yeah. I mean, this is something that really comes from our Founders that were part of the IDF and have seen these things in the real world and they want to you know, truly kind of help out the broader Community not just our customers. And that's in a couple different ways.
One is the research that we have. So we actually have an actual security research team within legit. We're actively looking for vulnerabilities and Publishing them doing responsible disclosure.
We had one two months ago. We have another one coming out later this month. So part of it is finding those vulnerabilities and sharing them before they get out of control.
But the other one that's probably going to be even more impactful is the open source tools that worried and contribute. So I mentioned earlier, you know, our platform. Does this automated Discovery across this whole pipeline so you get to see what's out there.
We're going to carve off small pieces of that capability for example looking at your GitHub instances is it properly configured has a developer taken a private repo and made it public which they shouldn't do. That sort of security posture management for a GitHub repo is something that we're now actively working at to provide to the open source Community as a tool that folks can use on their own to improve their own software supply chain security for that piece. Now if they find that useful, they might find legit security and they might find out that we do not just that but all the other repos all the other build servers all the other artifact repos and everything else so it could be an entry point to that.
But in the meantime, it definitely helps the community at Large. Love it. Absolutely.
yesterday was I forgot what they call it, but like affiliate day or whatever and they open ssf had their kind of event would not to say that. You know, it's very embedded into everything going on this week. But I'm wondering if you were involved in that at all what your impressions are from what you've seen so far.
I wasn't involved in the event but I think the open source Community as a whole has a really important role in just the topic of software supply chain security and you know part of it is SCA tools and just the vulnerabilities that can be introduced through open source libraries consumed in software That and of itself is a huge deal. You talked to some people and they'll tell you commercial software today is composed anywhere from you know up to 80% or even more of Open Source libraries. That's not going to change.
So continuing to focus on that and and bring more attention to that space is really important. And then I think it takes you in other important areas about all the other dependencies associated with building software today. S-bombs are part of that which is picking up momentum you think so.
Yeah, and you know, and there's a there's other things. It's not just open source libraries. There's other dependencies across the board.
So the more people talk about it the more people start to take put their attention to how this is being managed and it's not a mystery anymore and people are looking at ways to secure I think is better for everyone. I I don't disagree with you at all. Hey, you know what?
We didn't tell people if they want to get information on Legit security. L e g i t. com.
Okay, come check out a demo. Yeah, and go to the website. There's a book of demo button, you know.
We found that like a lot of these vendors, they'll talk about software supply chain security. When you see the product work, then the light bulbs really go off and and that's not unlike us so go check out a demo actually. Hey man, thank you so much.
Enjoy the rest of the week here it open source Summit check out legit security. There are a member of open ssf. We're live here in Austin.
We'll be back in a moment with another guest.