Justin Hutchings, GitHub | Open Source Summit NA 2022
Justin Hutchings, the director of product management at GitHub, joins Alan Shimel at Open Source Summit to give information about GitHub, the Open Source Security Foundation and open source projects, tools and security. Alan and Justin discuss adoption of security standards and what’s required to move forward in this sector. They also discuss a lack of diversity in certain software offerings and tools, and why it’s important to have more choices. As additional open source projects are created and become popular, Justin explains why there is a point in which these projects outgrow their individual creators and more governance is needed through a larger foundation.
Transcript
This is Textron TV. Hey, everyone. Welcome back.
We're here. This is the wheel here yesterday. This is officially day one of the Linux Foundation open.
Source Summit yesterday it was more of a satellite conference day and we had like our friends from the open ssf here and the fin Ops Foundation as well as the open Telemetry group. But today it's it's you know, mainstream Linux foundation and the obligatory, I guess lioness talk about keynote was this morning which I caught a piece of it's a little too crowded the room for me to stay there much longer, but I'm really happy that we have our first guests from this morning with us. And if you've watched extra on TV, you've seen Justin before Justin Hutchings is with GitHub.
And he is well, he's got a lot going on here too. He's gonna tell us about it. Hey, Justin Welcome to our coverage of Open Source Summit.
Hey, Alan good to see in first and finally thank Yes. Actually this is the first time Justin. I see each other from the from here below.
It's a it's a funny world. You know, it's something lioness did say they asked well, you know, what effect is covid had on Linux kernel development everything. He said, well, I'm happy to report.
You know, there's a Linux kernel was not infected by covid. yeah, and so that's the good news. The other good news is we are here in person.
Absolutely. So tell us what what are you doing here? Well, you know, I'm here representing GitHub and all the things we're doing around security, you know, we had the open ssf day yesterday which was a great sort of set of intro sessions for folks that haven't been involved in open source security for a while, you know, there are a ton of cross company initiatives that are going on right now, whether it's around software Bill materials and trying to figure out how to you know, make it so that software is inspectable by default things around better vulnerability disclosure and improving interoperability and then all the you know, the the larger programs around like the alpha omega project that you know, the open stuff is running for both depth security research on the most important projects and breath research across, you know, as many open source projects as we can.
These are all things that you know, Really exciting and important for folks that use GitHub and you know folks that consume open source in other ways. I I think it's exciting for anyone who knew you so for a period right because we're all though we may not even realize it many of the applications. We are all using actually.
Have open source in them open source components the kind of stuff that ossf is is trying to help with and then it's really behind this whole bill of materials and software supply chain issues, you know, just for those who don't know out there, right the the open ssf has really gotten a boost. Well, they've got about 30 million dollars in money through which gives you a good boost as well, but it's got no boost by some, you know, big companies getting behind this initiative. One of which is Microsoft, which is obviously the parent company of GitHub.
Absolutely. It's not until I'm hearing you talk here that I'm realizing how There's a GitHub initiative or is it a larger Microsoft initiative as well? I mean, it's both, you know, we look at a lot of the things going on in software security and they're bigger than any one company absolutely tackle, you know, you look at some of the efforts going on on software Integrity.
For example. Nobody can build that as a commercial product because if you want every open source project to adopt security standards that are going to improve safety for everyone. It can't be a commercial project.
And so Foundations like the open ssf are the only place these kinds of conversations can really happen. Yep, because it's neutral territory. Everyone is doing this for Community benefit.
Absolutely. So it's GitHub. It's the larger Microsoft but you know, look, let's not stop there Google we actually had and I'm gonna blank on her name the chair of the open.
That's of Jamie Jamie. Yeah for my yeah. Yes, we had her here interviewing her.
Yes saying that was great. So there are large companies and you know real muscle behind this, but I want you to pull up something else and I'd love your opinion on again because I know you've been you've been around the block sure, you know when I first got into security about 25 years ago, There was a strong. Lineage a strong tradition of open source security tools right I grew up.
Came into this when things like nmap and snort and nessus and and clammy V. And you know, there were a lot of Open Source tools that we used for security. and there still are yeah the ones I mentioned may have you know changed and evolved over the years but really I want to make sure people understand this.
The charter or the mission of the open SS of the ossf the open source security Foundation is not necessarily to use open source software to secure. Everyone's software but it's to make sure the open source software. We're all using is secured.
Yeah, absolutely. Absolutely. And you know, that's not cement.
No pun intended. That's not the semantics right? It's it's sem that's why it's not semantics.
It's an important distinction. It's true. It's true.
I mean, you know, even where some of the security analysis tools out there maybe proprietary, you know companies like GitHub are you know, making them available to security researchers to go and do the kind of assurance that folks need you mentioned that open sources use in all kinds of commercial software, you know, the latest data we've seen is 90% of software contains open source, and you know, when you think about that it means you know the random they call it the you know, Nebraska where what have you random projects supported by some guy in Nebraska that you know, nobody knows is important in so many of these pieces of software and so you know, the The job that we have is first raising awareness of how important open source is making the tooling available and really providing support and services to help make sure that open source can be secured because it's a huge ecosystem, you know, every one of the tools that we deal with is language specific, you know, there's a lot of domain knowledge that's necessary to provide true security assurance and we've got more diversity than ever in how people are developing software in terms of languages and Tool chains. So it's a huge problem space. So we do have more diverse City in terms of languages until chains.
But we lack diversity in some things and I think the Nebraska issue you're bringing up, you know, the Nebraska projects fine until everyone starts using it like log4j right or something like that. And now all of a sudden we don't have so much diversity. We have like a single Supply.
Yep, supplier supply chain. And so you get a defect in that and it affects everything. Yep.
Just you know, as far as the I can see and I think that's something I don't know if and you would know better than me is the ossf. Oh, yes. Yes.
I always worry. I put too many yeses. It's all good.
Yeah is the OSS have doing anything about that where? You know, I'm of the opinion. It's not a good idea to only have one one lock for Jay for instance.
Right and granted the market is if it's that good it'll dominate. Yeah, but I mean there's a project that we've got in one of our working groups, which is a critical software project which is identifying the pieces of software that everybody is using and trying to make sure that they have a sustainable funding model maintainership model and and support because it turns out a lot of these things even when they're part of Foundations. They're not very small.
Yeah exactly, you know, we talk sometimes and core contributors and that's it. Yeah, we talked sometimes you kind of grimly about like a bus number right, you know, if somebody stepped out into traffic and got hit by a bus. Would anyone be there to keep that in critical piece of Open Source around and the sad answer is too many projects.
It's a number of longer. Absolutely. Yeah.
Just want to clarify when you say I would group. Are you talking about GitHub? Are you talking about ossf both?
Yeah, we're all really concerned about these problems because you know, when we have a project that becomes unmaintained that a lot of people are using the security researchers don't have anyone to contact to get patches. Yeah, you know and so things start to fall apart where you could potentially have someone trying to do coordinated disclosure waiting 90 days hearing nothing and then having to just disclose a zero day on people because there's no patch available. And that is a worse case out good everybody.
That's the nightmare. I mean, you know and truthfully that's one of the It's actually one of the advantages of a project being accepted into Linux Foundation, right? Yeah, you know, we've spoken many times on the show.
We have sandbox and incubation and eventually you got graduated projects, but you know, what moves a project through the various stages. Is that yeah. Stability to eliminate the one as you mentioned the bus problem, right?
How many maintainers are there? How many? Core contributors are there.
How big is the community? Is it self-sufficient? Yeah, or and that's a big change from Again, when I came up where so I would say most of my careers have been spent on what I call the big brother open source and period where look most projects had one.
Sponsor owner manager, whatever. Yeah, and and they were responsible for the direction of the project as well as most of the code and when they offend it it was often and and I would say that's one of the things that you know, I really look for when we're picking projects that we want to engage in is whether they have a sustainable governance model because when you have one that's a sponsor-led project where you know, it's very clear who makes the decisions in this project and how how they're incentive model works. You know, I really appreciate organizations like the LF and the Open ssf putting in place open governance models where when multiple vendors want to collaborate on a solution.
We've got a place where we're all equals. We can all come to the table and bring our ideas and get the job done because when you have those projects where it's it's really unbalanced there is no guarantee that every stakeholder can get what they need to On through that project or that one stakeholder doesn't abuse. Abusive for their own personal gain.
Yeah, which is really and that's one of the beauties of the whole foundational. It's not just Linux Foundation. There are others, right?
Yeah other foundations, but it it's changed the game. Let's get real for a second again. You mentioned in Nebraska project.
Yeah. I would love to see a study almost like, you know, we see studies in early childhood development. I'd love to see a study in early open source project development because the fact of the matter is I've spoken to enough project.
creators sure to know really what happens is I would bet in nine times out of 10. They're working on something. They see what what's available out there really is not good.
Yeah, it's clunky. It's whatever it's it's proprietary whatever right and they said there's got to be a better way. Let's do something and make it available to everyone and it's generally a really small group.
It could be one person maybe two people right? And they and they develop something that works. I say.
Hey, let's put it out to the community. Maybe other people who have this problem, right? This is the anatomy or you know of an open source project.
And and so okay. So now communities let's sing and say Hey, you know this dude down in Nebraska. He came up with a solution to this problem that we've been banging our head on.
We should use that and then oh we use that we made an improvement. We should contribute it back. I mean that literally like from Little Pebbles giant Boulders, you know, absolutely this is how this works.
So where on this timeline Justin do you say okay? Hey, it's time for some open governance stuff here. Is a good question, I mean, you know, I look at a lot of the open source projects out there.
I like in the way that opensource projects become successful to being like a viral tiktok, right? You weren't planning on a million people using your software. You didn't expect that Google or Microsoft or one of these big firms is going to take it and run with it.
But it happens the algorithm, you know, you you struck lightning whatever the case may be. And you know, I think it's important that there's a maturity model for these projects. You know, we at GitHub have our GitHub sponsors system.
So when projects start to get more more successful and it's maintainers lean in more on developing open source, you know, we have a model for folks to chip in and fun to that person and allow them to do this more and more as their day job, but there's definitely that inflection point where you go. Okay, this is this is bigger than an individual this ought to be a project that goes to a foundation and you know, I look at the success of organizations like the cncf Where you know they've been really effective in convincing projects to go and add themselves and to join and and get that support and governance and what have you I think helps a lot of the maintainers that ultimately they want to be there writing code. They want to be doing the right things.
There may be not the sort of person that wants to run a committee and you know, that's that's the advantage that a lot of these organizations have. Yeah. No, I I that's a great point which is look a lot of these guys and gals and people who you know kick off and open source project aren't the you know, that's not their gig right governing your project and dealing with communities and all of that good stuff though.
They're often very much. you know the bread and butter of the communities, right the SE they're not like sort of a different species or something, correct? Um, so just I kind of confess other this white iPad sitting here other than being a stand from my mask.
I was supposed to open it and start a a watch to time this at 50 minutes. I don't know how long we've got but okay, but hey look at that, you know, but I'm not done if you don't mind hanging. I got like a time.
Yeah. Okay. So you mentioned the afro Omega project which I I'm Vaguely Familiar with with us.
That's why you know educate our audience a little bit Yeah. So it's it's a bit of a kitchen name, right? But the idea is that Um open source.
There's obviously there are really high profile projects that everybody's using so that could be your kubernetes your node project. You know, any of those things that are really high profile and those projects, you know, really benefit from Deep security research, you know, we want to take experts in the field and give them the right tools and tell them to go do all of the research to go and find vulnerabilities. And so that's the alpha side that is sort of like depth first on the most important projects, but obviously like we're not going to be able to scale that to the millions of Open Source projects that are in use across the entire software supply chain.
And so the other side of this project is to develop reusable tools and practices to go and do automated analysis and triage of automated scanning across millions of projects and you know, there are two big challenges with that first, you know, the triage process is currently very human and you need people That understand the code and understand their vulnerabilities. So we're developing out systems to make that more scalable so that yeah so that we can go to those projects, you know, the Nebraska project and say Hey, you know, we're a group of security researchers from the openssf and we've run a bunch of analysis and we found what we think is a real vulnerability and give them enough information that they can go and fix that love it. Um kind of reminds me almost of the seti project right?
We're just gonna harness this wide. Mad if you will but we need to order me the intelligence to you know, the sift through. Yeah, I love that.
Hey while we're here, you know, I want to make clear. What's your role with open ssf at this point? Yeah.
It's a great question. So, um right now I am just a general member I participate in all the tack calls. So tack is the technical advisory committee and you know, go there to help coordinate efforts between GitHub and the broader open ssf, you know, even without like an elected seat or what have you the governance model is such that anybody can show up at any time be involved and just help the organization be more successful.
They're a ton of projects that we really care deeply about there and you know, we're constantly looking for ways to support the team and make sure that we're getting the right outcomes on open source security. Well, you know interestingly one of the people we interviewed yesterday. was Eva black sure right from Microsoft and they you know, they spoke about I think they are on the tack if they are.
Yeah, they're one of the I think they're the vice chair. Yeah and keynote here today. Anyway, it was an interesting insight into how sort of attack is functioning.
Yeah, what's going there? So it's all good stuff. Hey, I know we're overtime, but I'm not done.
Let's talk get GitHub. Yeah, of course. What's new with GitHub?
Oh we've been doing so many things on open source security here lately a couple things. I'm really proud of back in February. We announced that we've opened our advisory database up as a full open source project great.
And so, you know, one of the problems with the CV program today is everyone publishes CVS, they go through miter. They go through us or wherever else and the vast majority of cve's are not actionable. There's no Machinery of identity for the software that's affected.
And so we have a team of Engineers that go and look at all the CVS that come off the feed and add meditate that allows us to drive alerts great. This is Important process but when you've got humans involved they're going to be mistakes. They're going to be opportunities to fix things especially as the threat landscape evolves on cve's in the days and weeks after they're released and so we've got a system in place.
Now where anybody can go and make Improvement requests. We still maintain that project. But you know at this point what we want to do is open the world for anyone to create actionable mappings for free ease and the other project we recently did sort of on the vein of software bill of materials is a new API for our dependency graph that allows people to Submit information about the dependencies they detected at build time which is incredibly important you you're logged for Jay the maven ecosystem Java overall.
A lot of those projects are not fully statically analyzable. And so if you don't know when you built it all the things that got loaded transitively you've got no chance at doing security Assurance later. So this is a important step that allows us to plug that Gap and drive the right alerts in the right outcomes for all those projects.
Love it. You know, I Had to call there. He want to know my concern with the whole last bomb thing, please yeah, everybody in their mom is recognizing this.
I mean the White House shown a light on it. Sure. I love to hear what you guys are doing.
I've heard. Dozen different as bomb kind of because I was at RSA. Yeah, as you are a couple weeks ago.
I hope we don't step on each other and just make a lot of noise here. Yeah without really coming up with. An industry recognized standard.
Yeah that we could all use and you know kind of circle the wagons around. I mean the challenge with s bomb is you know, there's a risk of it becoming just a chore without good outcomes. Yeah from my perspective.
It's an interchange format. If you can get every tool in the tool chain every build tool every package manager to Output an interoperable description of all the software that they touched and included in this that goes a long way to helping security Assurance tools alert and respond to vulnerabilities later, but the only way that works is if the data in the s bomb is machine readable. It's actionable and it's cataloged in a way that allows it to be queried later.
We run the risk right now of having a lot of people take a compliance check box where they say. I Cobble together in s-bomb and delivered this Farm check exactly, but they're not useful because if you don't write the right, so I I think they become like the the labels on the mattresses that if you take off it's a federal offense exactly. Right?
But other than that whoever reads what's on those labels? Yeah, and and you know, there are two different consumer groups for these they're the folks that are producing them that hopefully you're using them to power and internal security process, whether that's using, you know dependent on alerts or some other tooling and then they're the software consumers that are actually buying the software. Both audiences care about the state of what they're deploying and today that you know across the ecosystem everything's super immature, you know, one of the things I'm pushing for this week in a meeting with a bunch of folks from the language communities is production of s bombs at the source because today it's manual and it's not useful.
But if we can get it at the source, then we have, you know, truly the opportunity to build that software in at every step of the supply chain. I really hope so Matt. That's the goal.
Yep. Anyway, hey, we've taken more of your time. I apologize for monopolizing you like this, but it's great to see you in person.
Absolutely. I hope to see you in person more events in the future and we can still do zooms out too. Yeah.
All right pleasure as always always Justin Hutchings. Well, not only with GitHub but also Just a regular member of the ossf doing his job doing his duty here for the community. We're going to take a break.
We're live in Austin at the Linux Foundation open source. Summit will be back in a moment.