Josh Bressers, Anchore | Open Source Summit NA 2022
Alan is joined by Josh Bressers, VP of security at Anchore, to discuss the company’s two main open source projects, Syft and Grype, as well as how it shifted its focus from vulnerabilities to broader supply chain issues. Alan and Josh also dive into the current tech landscape and how it’s been affected by vulnerabilities like Log4j.
Transcript
This is Textron TV. Everyone we're back here live on opening day of the Linux Foundation open source Summit is as I mentioned earlier calling this opening day. But really the opening day was yesterday.
I your Linux foundations have this concept of zero day, which is a bedtime to use it is, you know for the the day before the opening we did a lot of the affiliate conferences. They didn't use the term zero day this time. They got another reason.
They had another I think was called affiliate day or something. But anyway, but one of the big ones was the open source security foundation and we had a bunch of people from there yesterday some today. I'm happy to be joined Now by Josh, press who's also a security person.
I imagine that's right. Very involved with ossf and Josh. Welcome to Tech strong TV.
Awesome. Thank you so much. Yeah.
My name is Josh. I'm the vice president of security at a company called Angkor. We do supply chain things are two open source projects many people have heard of our called sifting gripe.
We can talk about those a little later. But then I'm also a member of the technical advisory council at the open ssf and I've been involved in open source security for more than 20 years at this point. It's been I mean way back in the early days and I have a couple of podcasts I do I do the hacker History Podcast, which is a ton of fun.
I'm always looking for guests. So if anyone watching is interacted, let me know. How did they reach out to you for that for the hacker history.
So there's a little conference in Johnson I live in I live in Wisconsin and okay a hackercon called ciphercon really and I don't know I've known the organizers for many many years and one day the the organizer the guy in charge of Mac getzman. His name is he comes to me and says hey, I want you to bring your open source security podcast, which is another podcast I have into cybercommon. I said, I don't want to do that because I don't I like to be able to do whatever I want.
No one's in charge of me, right? I have no sponsors. It's almost self-funded and I say he said well, I want you to do something with me then right?
And so I said, okay, let me think about it and I come back to him maybe a month later and I said I want to do a podcast where I just sit down with people and they tell me their story right about whatever it is. They want to talk about and kind of how that's where they are. It's super fun.
com and I'm like what that was you late? Yeah, perfect. Yeah.
Yeah, and so I've been doing it for about a year now with them and yeah as we get guests we we put them on what a look thing that he had. I love you. Energy to yidish word.
I think called Berkshire which means it it's just bound to happen. Like they go. Yeah, so this that is for shared indeed.
It's interesting. So we've got hacker history. Then we've got the open source security podcast.
That's right and your title with anchor vice president of security. I do it. We're a small startup company.
So I do all kinds of stuff with I remember the year. So in your old I remember the day anchor launched. com or continue Journal.
Yeah, I'm trying to remember who the CEO was that I interviewed. It was it. I had to be in the last six seven years.
No, I mean it's been right around five years. You probably talked to Syed as the yeah CEO. Yep, and anchor has gone through kind of a couple of changes just related to the industry because you figured back in the early days.
It was all about vulnerabilities. Yeah, and now today through just kind of the process of evolution. It's the broader supply chain story not just focused on vulnerabilities and so it's been a ton of fun getting to kind of go through a lot of these changes and experience it and make a difference as well.
Which I love you talk about being, you know, open source security for 20 years. Yeah. Yeah what you're talking about this evolution is so true, right so I started security company in 2001 2003 Maybe 2004 we come out with a vulnerability assessment tool called van.
You know. I was the she's cute a chief strategy officer Biz Dev Corp that I did everything as many of us do it startups, right the marketing product sales, but I used to go out to our Enterprise customers and talk to them about and they used to call our van our vulnerability assessment tool the bad news generator, right? Because it just made bad news.
That's true. It was But I remember back then what a struggle. And this wasn't this was scanning for vulnerabilities and deployed software right and deployed infrastructure and services and things like right?
Yeah. Yeah. just to get them to do it once a year or to move from once a year to a quarterly scan was like it was like, you know sweating bullets.
We didn't even think about hey, maybe someone should scan this software before we deploy it put it out there into the world right that whole AppSec thing sort of burst on the scene made me a little later. Yeah, then we started scanning that but it was you want to know that I mean, all right yet pen testing at vulnerability scanning had app scanning, but it was still kind of that same looking for known vulnerabilities, or maybe we were fuzzing and and doing things like that. the whole concept of viewing it as a supply chain issue and applying you know manufacturing kind of outlooks, whether it's lean or Demi kind of stuff to this idea of hey, we've got a manufacturing process for software and we have a supply chain for software and we need to secure or apply security controls a point along the supply chain.
I mean you said it Josh you said it just rolled off your tongue like it was You know, well, I mean it's a relatively new but it's relatively new concept or think of it or not. So I spent a decade at Red Hat. I started there in 2004 and I spent 12 years at the company.
Okay and my job when I started there was functionally supply chain security. We didn't call it but I was just no one it because we didn't think of it exactly exactly and the the attitude was that red hat was the vendor and everything behind Red Hat was Red Hats problem to take care of and everything and then the customer was paying redhead to make all those problems go away. And in many ways they did and I think Red Hat brought a lot of legitimacy to open source, I didn't exist.
Right? And so they spent literally decades building trust in Good Will for open source, and then we saw companies like Google come along and you have GitHub and Microsoft mean heck Microsoft. When I started at Red Hat Microsoft was the enemy like there was I remember I would go Empire.
I would pick fights with them on purpose at conferences. Just because could and it was It was ridiculous. It wasn't ridiculous.
I was there. I believe it. Well, I was ridiculous.
Okay, but but now but they had in common. They were awful allergies. Let's let's let's face it I won't argue with you.
Okay, but we had all of this work that happened and I think now what's happened is the world realized the power of Open Source. They realized all of the advantages they get how fast they can move by incorporating this these projects that are already done. And so now they've in many instances they've just said well, we don't need a company to vent this for us now, we're just gonna go right to the source and we're going to use it but the problem is and in fact, this was talked about in the keynote earlier today is they're vetting costs money, right?
If you just take the raw open source, and you try to consume it. This is where you start running into issues. And this is why we're seeing all these supply chain topics now because you can't just like take open source, you can't do an npm install and forget about it forever.
That's not that doesn't work. A lot but now we're seeing all these tools that are able to look at what's happening and understand like what are you shipping? What is in your stuff?
What matters to you? What is important? Because I think one of the other things I love is something like log4j comes along and log for J is, you know, the world's ending.
Holy cow. It's Christmas time everyone like haha. You're working over the holiday.
Right and we all suffered through it and we all made it through and then the obsession became okay, we have to look for log for Jay but in many instances there's other things in your infrastructure. There's other things in your products that matter but what are those and we don't always have insight into that. And so this is what makes me so excited with all the work.
I see at open ssf and the Linux foundation in general and all the products going on. I mean, there's gonna be a room full of vendors upstairs that are all working on this problem together. And so now it's about starting to figure out what do we have like in the case where you were working with a vendor like red hat Red Hat new what they had because they hired a bunch of people like me and it was just through suffering and we figured we Literally, you literally had text files because humans were looking through.
Oh I get packages and then obviously doesn't scale right and so now it's all about how can we use tooling and obviously open source to understand our open source, and it's really exciting it. That's what I'm saying. It's like it's a Brave New World out there absolutely two things that you mentioned.
I want to dig in on so let's take log4che for yeah. Yeah to me. There's a classic supplier and a supply chain issue where it was so good what it was intended to do that.
It was the only game in Canada if you wanted to do this you use Lockport check, right? And and so the same way when we found out all of our Mass came from China and when China can send us Mass we had no masks with covid. That's right, right.
I don't know how like this arguments to be made on either side of that. Yeah, how do you broaden your supply or supply chain for critical care? If you want to call it a critical component if it's in every if it's so widely used in all this software to me.
That's a critical component. Yeah. Yeah, right.
So how do you make sure we're not all dependent on the same critical deployment component because look defects are gonna happen. Absolutely. Yeah.
No one does that on purpose? It happens. That's right.
And so when they happen in the future number one, we want to correct them as quickly as we can. But how do we stop it from affecting 90% of whatever the number is of what's out there that's That's number one. My second question is that's great for the log4js and those rock stars over achieved Monopoly status or whatever you want to call it.
But what about as I was talking with Justin Hutchings, right a little early he calls it the Nebraska project right two guys in, Nebraska. See a problem. They they come up with a solution.
They open source it. Some University uses it here. Someone's son who works a Microsoft gets it they decide you and before you know, it it has a nice little cottage following right?
It's becomes a cottage industry. It's not log4j. That's right.
It's way down here, but how do we maintain the Integrity of that too? So This is a marvelous question. And this is something I've been doing a bunch of research on so I worked at elastic prior to coming to Anchor and so elastic has elastic search which is for no processing huge volumes of data and I become obsessed with data.
Yeah anyone who knows me knows like at some point in the conversation. I'm going to show me your data anytime they talk about anything. And so one of the things I'm doing is I've taken all of the npm data and I've been looking at it to understand like what what does the ecosystem look like?
I want to see it right? It's not enough to just talk about and let's a lot of this is guesses from smart. People are not always wrong, but If you look at the npm request right here, yes, yes, but if you look at the npm ecosystem and you look at just say the top thousand packages half of those have only one maintainer and when I say top thousand I mean by downloads right like okay go to packages.
Oh half of them have one maintainer, right which when you when you learn that it's a terrifying number and so there's a lot of talk about we have to understand our open source, and we should be careful and it's risky to use one maintainer projects and all of this and I think what the data is showing me is that you can say a one maintainer project is risky, but a one maintain a project is reality, right you can risky or not. It's what we have. It's just right.
That's just right. That's right. And so this is where I think our challenge now is partially understanding what we have and this is where we need the tooling and the data and we need people to actually look at what's going on instead of making Up and then we have to say Okay.
This is the world. We live in how do we work within the confines of this world? 6 million have one maintainer.
6 million maintainers to work. That's a lot of volunteers. That's right.
But you know, so again we do I discuss this a bit with Justin. He called the one bus problems if that maintain it gets hit by a bus or project die, right? You know what?
Probably the sad truth is? Yeah. Because I agree with I agree with you.
The amount of Open Source projects that rise to commercial viability. We were talking security for the snorts the necesses the end maps to these kinds of the amount of those projects that rise to that level versus. 9.
Million Mass here. Yep. He's probably not even one percent.
01. 8% or whatever it is, you're not gonna you know, you can't go to the local Home Depot and find some people hanging around. And say you want to be maintainer today.
That's open the truck. That's right, right. We're here in Texas, but you know this.
And I think for us to think that part of the ossf or in fact the Linux foundations. Charter is to to somehow change that I think that's just shoveling sanding against the tide. I mean sort of I I think it's a very large problem, but I also think we need someone to care right think of lying people care.
But to say I'm going to get to maintainers or three maintainers for every project. You're kidding yourself. No idea.
I don't want to make something here. Yep. Yep.
Exactly exactly that and I think that those are the spaces that we're gonna have to investigate for the future. I think that's trying to brute force it by just saying but again, this is I think that that kind of crap smart people made up categoria single every project should have two maintainers. Like should they sounds great.
Show me sign me up show me how that matters and I think you can make the argument if we look at like the Linux kernels easy, right Linux kernel has literally hundreds and thousands of developers. You can take a look at how successful it is. It's successful because they have all these developers but is it we don't know we think so.
It's coming to a desktop near you this year. It's the year. It's always here.
I've been using don't don't laugh. I've been using Linux on my desktop since probably what 1999 or take and yeah, it's always been every year but seriously Again lyrics is the point. Oh, oh one.
Open source projects, right? It's a one of a kind. It's a unique unicorn.
That's right. For us to say look our best practices every open source project should have three maintainers and at least 12 core contributors and you know, we're striving for a community and and that and no knock on the Lennox Foundation they do an amazing job, but that's part of what they do with the sandbox and they graduated and the all of the different, you know levels of incubated all the different levels here, right? Those are some of the metrics that matter but not every would you say one point nine million projects and that's just npm.
That's one ecosystem. Right? So I think we need to be more practical.
Yeah, absolutely and say hey if you're a one maintainer Project, you know this town ain't big enough for both of us. This is what this is. These are some best practices.
You should follow that can ensure the continuity and security of your project sure and list them out. Maybe I mean, I'm just I'm just one person giving you my opinion, right? No.
No, I agree. I think that's better than trying to change the universe. Absolutely.
I I think it's trying to work within the constraints of what we have. But now on the other side of this log for Jay wasn't a one person. No, it wasn't that was the guy that was that's right.
And so even even when you have a foundation backing a project it's still happen crazy things happen. Absolutely. Well because I think the lesson is as I said before, There's always defects in software.
Yeah. Oh, yeah, you never going away. You can't it's the nature of that piece.
We've seen it over and over again and it happens in open source. It happens in non-open sorts it it's software that that's what it's yeah. I want to return a little bit.
I know we're rambling on here. We're probably way over but let's talk about the two anchor projects. You mentioned early on.
Yeah, definitely, you know, they're paying you they gave you the shirt. That's right. That's gonna give us some do so.
So what did they do sifting? Right? All right there they're open source projects sift is an SBOM scanner.
The idea is you point sift at a container a directory kind of whatever you have and it will try to figure out what's happening inside of your project. So, for example, I put in a container, it'll show me like my npm modules and so it'll show me the RPMs installed in the container. It'll show me other things that might find and it out puts an ESP bomb and this is you know Cyclone DX or spdx so that you standards and then Once you have your s-bomb, what do you do with it?
Right that's part of the question is obviously there's always this talk. That's what oh, you need an S fun everybody needs to necessary. It's like it feels like that, you know the fish at the end of Finding Nemo where they get in there.
Yeah. Yeah. Now what they got, right they're stuck in the bags.
So this is where kind of gripe comes in gripe is a vulnerability scanner where you can take an SBOM and you feed the SBOM into gripe and then gripe will look at all the contents from here. It's not even a vulnerability scanner. It's almost well.
It is a vulnerability but it's not actually scanning your your software it can but scanning a sponsors better because here's the thing when you scan software, you have to look into your inspections, right? You know, it's reachable and right there and all but now if you have an SBOM you can usually you know, we'll call it scan the ass bomb very very quickly the idea being that when you generate an F-bomb the contents of your container don't change right but once you vulnerabilities do because there's always new vulnerability everyday I could scan something right now and in 10 minutes, there could be a new find And also for that moment, that's right. So that's right.
Started still secure the company with Vamp in seven six. We came out with a product called safe access which was one of the first what became known as NAC network access control. And and there we had to we were working with the federal government.
There. We when you logged on we had to make a split second decision whether you are compliant. Can't do a scan.
No, no definitely just didn't it didn't it didn't work. So what we were doing is we were looking if you were Windows box, you know when you wasn't dot IO config or whatever it was. I don't know.
I haven't run Windows in years. Was it Ayo config? That sounds like something they would have but no there was a Linux equivalent because Linux was really easy to scan because there you had all your packages.
Right? Right, so you didn't really scared just like you don't really scan the ass Farm you read the ass farm and baseball what's on the edge Farm? You know, what what has a patch what version you know, what needs to be done.
It was the same thing. We could oh, it was an eye out. I'm really old.
I'm sorry. I don't config might have been like ibmos too or something, but it was it was your registry file. Okay and windows that the registry, right?
And and so you can look in the registry and it would tell you everything every version number theoretically everything and you can make you know in a half a second where you are. We use your antivirus up to date whatever and that's how we did that versus a full-blown scan which oftentimes we would do after we let you on sure as a secondary thing right just belt and suspenders. Yeah, it's the same thing here with us.
Yeah, exactly. But here's my question to you. You know, they say the average life span of a container is mere seconds or whatever.
How do you use these products and still be successful when these containers are coming and going like that? So this is where when you use something like kubernetes they have this concept called an admission controller. So what happens is you can't do this with sifting right by themselves.
There's some people who've built some other projects around them with an obviously there's a lot of Enterprise like what the Anchor Enterprise product doesn't work well and there's others but you scan your container you get your ass bomb you store your ass bomb you conduct whatever will say due diligence on that container SBOM you need to do as part of your policy and then it basically has like a go or no go from the policy engine and so in the kubernetes admission controller, it can phone home and say hey, I'm about to run this container. Am I good and it'll just be like, yep, we're fine with that one or it can say no not that one like don't let it run and it's very very fast and it works very well. Yeah, it is very cool.
Where can people get more information on that. com Is pulling it out if you Josh anything else you want to share with our audience. What do you think so far of the event?
I'm loving it. It's I haven't been anywhere in a long time. I hear you.
It's been a wild couple of years and it is I'm ecstatic. I've got my a couple of talks coming up and I I am the sort of person that thrives with an audience versus staring at my computer screen for 11 hour. So I'm ecstatic to have people in seats I get to interact with and it's going to be a treat I think and actually there's a ton of great people at the show.
It's been a lot of fun. I got in yesterday and I'm loving it. It's a blast so far cool, man.
Hey for those watching this live at home, you know, the event is there's a virtual that's right twin to it and and you can check Josh out live. If you go over the Linux Foundation open source, Summit and and sign up. I think it's free the virtual.
I do not know the answer to that me either, but I'm hoping Anyway, I'll be on YouTube at some point in the near future. I hope so. Well, this will be too awesome.
Actually this on YouTube now there might be people watching it on YouTube right this second, but it'll be on as late. Well as well later. Anyway, hey Josh.
Thanks for stopping by thank you. It was a great conversation. Absolutely.
We're gonna take a quick break. We'll be back here live at the Linux Foundation open source Summit in just a moment.