Jamie Thomas, IBM Systems | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. We're back here live at the Linux Foundation open source Summit here in Austin, Texas.
And as we mentioned earlier today is is a day of I don't know if you want to call it daughter sister foundations or satellite conferences the main event really starts tomorrow, but there's several important foundations who are holding conferences today one of which and kind of the one probably nearest to me is the open source security foundation ossf and we are really happy to be joined by Janie Thomas, who is the governing chair or the chair of the good board. That's exactly got it Jenny Welcome to our show. Thanks for joining us.
So look when you're not busy running or got being chair of the board for ossf you have a day job as well. If you want to share with our audience. Feel free.
Well, first of all Ellen thanks for having me. I'm really pleased to be here to talk about open ssf but I am a general manager at IBM responsible for systems development and delivery as well as IBM's Enterprise security program and Enterprise security, of course is how I got involved in this particular topic absolutely and that look that is a world and job unto itself and we could probably do a few hours on that, but we're going to focus on on ossf today. So, you know for most of our audiences familiar we've covered we've had the pleasure speaking with Brian from ossf a few times.
It was a nice idea. I think when it was first conceived about yes, we need to do something about security about the security of Open Source tools specifically and then kind of all hell broke loose, you know, sometimes sometimes things just work like that right history runs in currents. So we started the open in the ossf and then we had this space of supply chain.
Yes security issues and the whole that's bomb thing with the white house and then like kind of the the cherry on top was locked for Jay. Yes. I was around when January or December last year.
And that's really I guess accelerate as it accelerated. Maybe you had big plans to begin with talk to us a little bit about kind of the whole OSS how this whole ossf how it all came together. And what's happened.
Well, I think was very fortuitous at the industry did come together last year with the Linux Foundation to create a new governing body around open source security called the open ssf because as you say not long after that we had this industry compelling event like for Jay and realize the industry had already had we'd already had solar winds the year before which also ruined our holiday in December good we had to say we had a number of these big supply chain of text. But the difference I would say in love for Jay is just the predominance of the asset in code. It had been out there for over 20 years.
It was a very utilized very popular a piece of code. And so it affected a lot of software. So one of the things that you realize when this kind of thing happens, it's not just about your fidelity.
Are being able to identify and get it patched but for all those Downstream consuming organizations how fast do they roll out these patches because we're talking about a huge amount of effective software. So I I think that there's nothing like a true test of your governing body. And this was actually a real test run of what we needed to do in open ssf and of course it garnered a lot of tension from the US government and and other entities that we can we can talk more about sure.
Okay. So let's talk a little bit about The charter or the mission of the open ss7, it's something I brought up to you off camera, which is okay log4j. Let's make that the poster child for a second.
So log for J is basically this open source component. If you will write that many many many many applications have incorporated into their package if you wanted to their source code and it's not look I'm not blaming the log for J developers or anything. There was a defect I don't even want to you know, it became a vulnerability but there's a defect a lot of software has defects that we haven't even found yet.
But nevertheless this one kind of went public and then we saw exploits with it and in the wild and you such as the world of security we both live it. What is the choice is that what ossf is about to prevent or deep not prevent but deal with future log4j kind of events. Well, I think first and foremost open ssf is focused on a proactive posture, right?
So how do we prevent these kinds of events? And so to do that? We think there's a number of things we have to do first and foremost is education.
Of course in terms of basic security education for developers. Another key tenant is how do you put automation on steroids? So the Automation and best practices that are reflected in that automation that open source projects can consume.
How do you get that out to the most critical projects and then provide some support for the long tail projects if you will sure it's also about working frankly with other industry consortia as well as the government particularly. We've been working with the US government in in the open ssf to Define. What are some actions that are really going to make a difference and I think critical to all of this is getting collaboration across the different insights from the governing body, which includes a lot of Technology firms as well as commercial firms.
Like there's a lot of financial firms actually involved in the governing body. What are the key elements that we really need to address first. So getting those priorities set and then having an execution agenda and really getting something done in the short term I think is really going to be important for for this group.
Well, look a lot of people look at what you guys have done and you've gotten stuff done right? There's been a tremendous Groundswell of support and granted live for Jade didn't hurt you in that regard, which is there others but there's been a tremendous Groundswell, right? There's been a You know, I think that 30 million dollars raised right between some of the biggest names in Tech taking in here.
There's been the White House and and cisa involvement. So it certainly for a relatively new Foundation. It has really guarded a lot of I don't want to say market share but a lot of publicity a lot of attention.
Yeah. Now of course the question is, okay. How does this translate to rubber meets the road?
How do we prevent the next log for? I don't know if we can prevent the next log 4J but how do we minimize that he minimize the impact exactly because I would say if you look at what happened with love for Jay the level of preparedness was not there. So, how do you get it remediated fast enough.
How do you identify it? How do you help the open source projects be more effective. In this case.
It was a of course tied to the Apache Foundation, but not only that how do the commercial entities then take advantage of that patch and expeditiously to benefit the clients. So I I think there's a real opportunity here in the world of cybersecurity. You often learn that no one pays attention to a lot of things unless there's a huge compelling event.
And that's what this was. So while it was not desired it was helpful in that in that vein. So coming out of all of the meetings that we've had the collaboration that we've had across the industry is going to be imperative that we execute and that the things that we have identified as top priorities that we make measurable progress on those projects this year and I think that's the importance of this open ssf day here today in Austin, which is allowing us with a key set of stakeholders to start to share perspectives of the projects that are underway and how others can engage in those projects and how once again working together we can actually make a difference.
I think this on this ongoing level of Engagement making sure that we have the right stakeholders engaged is going to be important to make progress. Smoothly and as you know when the world of Open Source the the nice thing about open ssf is we do have the ability to hire critical roles that can focus on this full-time because the nature of Open Source typically is that it's a it's a volunteer army, right and there's thousands and thousands of volunteers out there. But then how do we help with these resources enable those volunteers to be more effective and frankly that's been one of I think the key ingredients for the Linux foundations.
Formula for success is you know herding it's a bit like hurting cats turning the open source Community. It's it's that so you know, that's the Thousand hundreds of thousands millions, but you need a few full-timers. Who are this is their day job, right?
Is there this is what they do. Jenny I want to talk a little bit the people who are watching this now at home. Or maybe you know recorded later on they weren't here.
They didn't get what was happening especially today, which is kind of you know, the ossf stay give them if you don't mind a little bit of maybe a synopsis of what they're missing. Well, we just got started of course, so we have a little bit more to go today, of course in terms of the actual kickoff of open ssf day, but I think what I see is real commitment particularly from the presenters I've seen so far a commitment that they've all personally made and outside of their day jobs frankly to make a difference in security for open source software and that's really the key here. Are we turning the corner on a new level of commitment around security?
There's always been a commitment in open source around Innovation around feature function. I mean, that's what's loved it. You know, that's what's Driven open source and allowed it to be so successful and for others Other corporations like IBM we've taken enormous Advantage out of that, right?
We've all gotten a huge advantage in productivity out of that. But now it's really about turning the focus a little bit more getting that focus on security so that we can use open source and continue to have that productivity but with confidence as we go forward and I really been been impressed with all the speakers today and their personal commitment to this topic and and that's really impressive and I think we'll see that for the rest of the day as well. I'm gonna come back to it that to you in one second.
I want to touch on something else though, and that and that is this look I've been insecurity for 25 Going on 30 years. Well security 25 it 30 plus years and I you know. If I had a nickel for every survey, I read that said security is one of the top three priorities of it or the CIO or an organization.
I'd be a rich rich person right now. But I'd like I always said their arms were too short to reach their pockets oftentimes. Yeah, and it wasn't until something bad happened like a log 4J or you know some incident.
Yeah code red. I could go through a whole history of these things that people trying to get religion, right? Excuse me.
Sometimes it takes that for them to get religion. I don't I don't know why. I hope I always hope that it changes that people finally do start taking it seriously.
I think for the ossf though the important thing to remember especially in our audience. This is a fact we give them all the time today's applications. There's 75% 80% open source components that it kind of stitched together with maybe 20 25% of you know, sort of original code if you will.
And so if someone's not watching the store on those open source components whether they're artifacts or scripts or whatever. It's only a matter of time. It's not if it's when right and so that's why I think this is such a vital.
A such a vital function this Foundation it something needed to happen. Yeah, and is the perfect I think place for it? And we are step off the soapbox.
You mentioned a couple of the speakers anything stand out to you or that you can kind of clue our audience into well. I think other than the commitment of there's a keen focus on making it easy for the developers, right? How do we make it easy for the maintainers or these open source projects?
How do we make it easy for the contributors? Because without doing that it will not have the consumption by developers at large rain, and I know this even inside a corporation we have the same challenge really it's all about codifying the best practices in an automation framework and you know, whatever that is for your organization that's going to be critical and that's why it's so critical for these open source projects. Um, you know, I I think that with the right approach we will make a difference but it also as you said requires stakeholders involved to continue to educate their organizations about why is it important because all of us actually have the ability to increase the number of contributors we have on these projects to contribute our expertise and that's going to be very important.
I think that we as the governing body and other organizations really create a sustaining promise around open source, so it's not just what the open ssf is doing itself, but how we enable that to be successful in the long run because we're all getting the advantage from open source and like IBM we of course IBM plus our company Red Hat it has a little bit to do with open source, but those kinds of Efforts and keeping that Keen Focus are going to be very very important as we go forward. There's no doubt about it be also is back to what we said before is. Look, there's a new log for Jay kind of horizon Event Horizon out there every day.
Yeah, there is so you're not going to prevent them. You've got to put in your response. You've got to have your protocols in place.
And this is the kind of stuff for absolutely I will tell you that, you know, I have a window into cyber operations, which is my job every day at IBM and we're getting over 100 billion events a day. So that gives you kind of the context for what you got to deal with in the landscape and product security of course is one of those triggers if it's not if you've got malware if you've got issues they're going to be one of your events, right? So it's a little bit of a reflection on our responsibility to enable effective cyber operations for organizations.
And then we have a huge responsibility but we have a huge opportunity here and I I think I want to make Heroes out of Developers for really worrying about security. That's kind of one of the goals. com in 2013-2014 and I did it because as a security person I thought it was the best thing that happened in security if we can get developers security aware security conscious.
Would have to have the battle half the battle and you know for a long time it was it was an uphill battle. Let me say that but this whole notion of what we call deaf SEC Ops and making security for developers. It's really gone mainstream.
Right? And I think part of that is realizing is developers Securities. Everyone's responsibilities, very overuse thing developers are not security people, but I've never met a developer in my life who says yeah.
I'd like to develop insecure software, right? I want to use I want to use an old version of an open source, you know component that has some known vulnerability. None of them want to we all have pride in our work.
It's just we need to make it easier for them. To do and I think that's something OSS can OSS African really help with anyway. I know you're busy as Hector.
I want to thank you for coming down and hanging out with us a little bit to you Brian the whole ossf team. Keep up the great work. Well, we're expecting big things no pressure, but we're expecting big things from you guys really make make the difference.
Thank you Ellen. I'm really pleased to be here today and immerse myself in this topic and get to know many of the players that are here today and actually the opportunity to chat. No problem.
Just before we leave real quickly the ossf website. org. Open open.
org is I got a Little Help From My off camera team over there. So go check it out. If I you know, if you're not here in person, I believe it is virtual as well.
We'd love to see as part of it and support the open ssf. We're gonna take a break here in Austin. We'll be back in a bit.