Stephen Hendrick, Linux Foundation & Matt Jarvis, Snyk | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. We're back here live in Austin streaming out at you from the open source summit.
We're having a great time. This is our third day of coverage here though. Technically, it's only day two of the event.
It's a long story, but we'll talk about it later. Let me introduce you to our next two guest because this is a a conversation. I was really looking forward to to my left here is a gentleman who's been on on texture on TV a few times with us and talk to person great person.
He's the he's a VP of research. Yes for Linux Foundation Stephen Hendrick and Stephen welcome. Thanks.
Thanks Alan and joining Stephen and I from our friends at sneak matters and Matt if I'm not mistaking your head Dr. Developeration of developer relations. Welcome.
Thank you. So. Stephen and Matt presented was it yesterday?
Yeah. Yes on a new survey you guys recently announced and revealed and Report. Why don't you if you don't mind share whatever so open ssf is a very big project inside of Linux Foundation Brian as we've seen briandorf.
Yeah, and so at his request we went out and did a survey into sort of what's happening in the open source space as far as secure software development. So we put together a survey in March. We feel that it in April.
We wrote it up analystic wrote it up in May and had a produced in June and so it's being released here at the event. I think that happened yesterday morning. Yeah.
Yeah, we did in partnership with sneak right? So that's why we've been working together with the messaging on all this and it's it was not a surprise from the standpoint of what the results were, but it wasn't I was a little disappointed in kind of where we are at this point from the standpoint of the uptake of you know, the attention to security when it comes to open source. So anyway, so we've got information that talk a little bit about you know, where we are, you know how sort of to understand the context of the problem and then we have information about what people are doing about it.
And it's it's that's more exciting in many respects because good things are happening. I agree. So first of all, look, I think we're always disappointed when we do these surveys that we find out, you know beyond the lip service that gets paid to security what actually is going on under the covers and we're always wishing from hoping for more that being said, I I don't want to be pessimistic.
I I am of the glass half full opinion that we are doing. Better and more security now than we probably ever have done. Yeah.
Yeah five right that being said before we dive into it. I just want to really just quickly so open ssf. org is I believe the website.
Yeah, and I'm gonna assume that the report is there for anyone who wants to download it. That's right. Let's take let's say that up front for people at home following along.
Yeah, whether it's live. Well, you're watching this. It's on the sneak site.
It's Foundation side and it's on openness. Yeah, there's oh that's everywhere tonight. I think we might have covered it via sneak over on Security Boulevard.
I think I did some I did some press interviews on probably would be full flying out he is. Yeah so very well beyond our Security Boulevard, right but nevertheless it's out there for people. Yeah, let's dive in the what was some of the finding Steven sure.
Well, let's see what we'll start with this this whole issue of do organizations have an open source security policy. And what we found was 49% said they had one that's good. That's good.
34% did not and 70 17% We don't use over. So no just everybody uses of what 98% of organizations so and 17% said they don't know so we don't even know I don't know if they have one or not. So if you take put aside that don't knows at this point you got about a 60/40 split between use I don't have have a policy and don't have a policy.
I mean and if you look at a little more deeply into that, what you find is that small companies are more likely to not have a policy and that's not surprising. They have resource constrained. So it's harder for them to have cisos and ospos and policies be it for you just software development or open source software development so I can understand the challenges there.
So but the idea of when you even if you look at company size, we still end up with about 30% of large and very large organizations that don't have a policy for open source software development. So a couple of thoughts. first of all, I empathize with small SMB businesses wearing SMB business, but in today's day and age I may be it's when you're Hammer, everything looks like a nail but in today's day and age.
How do you not have Security policies. How do you not have security? You know?
Yeah. I mean, I I think that there's a couple of different things of play there. I mean, you know addressing addressing open source security, you know, is it it's more complex than it seems because it's not just about the the code itself.
You've kind of go to understand how open sources is is created how projects are governed because governance can have a big play into you know, whether with you look at some of those recent things around the sort of protest where movement where we've seen maintainers kind of go in row, you know, and this comes down a single maintain a governance projects and you need to take those things like governance into account if you're going to base your business on something right so but You just said and that's a completed a loaded question I would bet. If I was a betting man, right that a lot at the large Enterprise level you're 100% correct at the SMB level of us most of these people. A threshold question of where is your open source software, you know, it's 10 o'clock.
Where's your open so soft and a lot of them don't know because they're sasops companies. Hmm, right? They don't they don't have a server closet.
They're Cloud installation. It's this they're running on fast. That's right.
And so the beautiful part about sass is one of the nice things about that. You don't know what's behind the curtain. You just know you log in on the website and you it's got all your information there that you need.
Are they using an open source database. Are they using? You know, what?
What is what are they using behind the curtain? A lot of smaller companies don't know and as part of their due diligence, they don't dig that deep. So I I could again I can empathize the larger one the larger Enterprises though.
That's a problem. That is I think you know you in a lot of those larger Enterprises you you've got that kind of ingrain culture over a long time in terms of security and about how you consume software and you know, the hardest problem in security isn't really about technology at all, right, there's always about people and culture and I think you know, probably in a lot of larger organizations, you've got a kind of you know that sort of friction of Well, we've always done it like that. Well, you also have a lot of change going on from step on a house software is being developed.
Yeah sure and I think that's part of the problem as well, which is that, you know change it's changes always hard for people. Yeah, and especially with given the rapid evolution of tools and standards in essence around how we should do security for software. Yeah.
It's everything's changing so quickly. It's I think it's probably hard for people to keep up because we've got these two kind of things happening almost a perfect storm at the same time. We've got this massive rise in in supply chain attacks on open source, because you know, It's a victim of its own success, right and attackers have realized it's a lot easier to get into the supply chain than it is to to find zero days in in angular applications.
So you've got that going on where all of a sudden folks are going. Well, everything we do is based on open source, like what do I do about security? And then as Steve pointed out you've got this this ongoing massive transformation of how we develop software, right?
You know this super fast. Hi velocity I blame. Yeah, but well unless you do unless you can transform, you know, someone's going to eat your lunch, right?
Because there's some hungry competitive behind you who's disruptive and who's who does have a super fast software delivery pipeline. They can deliver new features. They know how to analyze the data and so for for a lot of big organizations, they've got these two big problems happening right at the same time because that change in software development requires a completely different approach to security, you know this face.
It it's the thing that sneaks about all the time about developer first. Look it let's say the Phoenix project for Gene Kim. Right and and that's based on a book called the goal.
Yeah, right and the thing about so the goal is about manufacturing but really the principle behind the goal and I think Gene tried to capture that in the Phoenix project. Is that look as soon as we kind of erase one bottle neck. We see that next.
Yeah neck right behind it and don't think that once you get rid of that bottle neck, right? Yeah sailing it's not we have massively revolutionarily. Speeded up the pace of software development.
We did it in large part by creating this this software Factory with pipeline. Yep, cicd devops kind of things. That in in the enabler of that was having this massive library of opens.
Yes indeed. That's right. This is that we can assemble into a very high quality software.
That's that's so man. We blew through that road block at 150 miles an hour and the wall we hit right after is wait a second. Now that's becoming a huge security problem.
Right? So for companies that are developing their own code. This is this a major thing, right?
Knowing that though and still telling me the 30% of the companies don't have a policy around it. Scary. Yeah, it is.
Well, let's we should we should talk about what people are doing about. Yeah. I'm trying to deal with this right?
Here's the good news. Yeah. So so we asked a question, which was okay.
So how do you intend to improve on the situation? What are you doing? And we had quite a long list of responses top of the list was organizations were looking for more intelligent tools.
From a step. We're kind of security Focus. So we're talking SCA SAS.
Siac, you know all The Usual Suspects and looking really to those those tools to be able to help them improve their security posture. So that was top of the list that was 59% and then right behind that a 52% was a strong desire to understand and essentially codify best practices for how to do secure software development. That was really encouraging because we know all about best practices.
Yep. No, exactly. You know what they all are in fact David wheeler had a left and so we had David a Wheeler.
Yeah, David a Wheeler we interviewed David yesterday and I will follow my mistake. Well, I I learned that it was the marks. Okay, but okay, but yes David.
Yeah. Yeah, I had lunch yesterday and we were talking about this because I said, you know how many best practices do you have? So, you know Canada all up.
He's got a hundred and fifty hundred and sixty. So that's kind of daunting and he said like the last 25 to get to the highest level can take in some cases years to master. So this is this is despite understanding what these best practices are.
It's still very challenging to wrap your head around what is necessary to be successful there. You'd be good and partly because you know as we would just talking about the that culture change is such a big part of how you make that transition from, you know, you kind of old school security is gatekeeper kind of function to this thing where we're all put it to the developers because the developers are the ones who've you know, you fix it at the developer eyeball before it's got anywhere near, you know, the chief. It's right.
They tend to 100x cheaper to do it there. And I mean we look at the other interesting thing here. This is slightly tangential to this but it's like how many developers there are in the world?
Right? And how many we anticipate that being, you know, there's something like I think the The the anticipation is something like 30 million developers in the world and there's only like a tiny proportion of security folk. So I go by GitHub accounts.
Right, there's about 70 plus million GitHub accounts right now. So let's assume it's not one to one. But I think it's safe to say is 40 to 45 million developers.
Probably growing it somewhere in the area of 10% Yeah and security you professionals on on growing at that rate. So Security Professionals are growing because we're starting to see look when I came up. You didn't have a cybersecurity major in college.
We're seeing schools churn out cybersecurity majors. Are they Security Professionals? I'll leave it to you.
But but there are people coming out here. Who want to work in security but not anywhere near I mean you're talking. Yeah in here's an interesting saying though I and I think it's what's turning up the heat on all of this is that this is getting major Focus From The White House.
Yeah from yeah federal government. The whole world is saying hey, this is a problem is a big problem. Well, you know, you got to do something.
You know, I did a report last year survey on esbombs. Yeah, and I gotta tell you that factor is right into this now, of course because you know, we did some stats in this survey on dependencies, you know, both direct and transitive and found really sort of low levels of strong strong security around, you know, organizations understanding the security posture of all these different dependencies and dependencies of dependencies. Yeah, you know, really Numbers there s bombs would go so far in helping sort all that out.
Yeah, because you know s-bombs are going to give you knowledge about the metadata. It's going to give you usability. So, you know that your license to use the stuff and it's going to know it was good.
If you trust that not only what you're looking at for metadata is non-falsified but also understanding quite clearly, you know, what's been fixed what hasn't been fixed from a vulnerability standpoint. So I'll tell you over the last two days here we well we've done a lot of interviews but no shortage of people talking about that's bomb and that's bomb Solutions. I I think we're gonna see just like everything else in technology.
We're gonna see sort of a Cambrian explosion of esbom solutions out there and then the market will figure out which ones make sense which ones dollar My fear is that we we think XS bombs are a Magic Bullet. Yeah, or for supply chain security because we have a tendency of doing that in security. You know, I mean, ultimately the I think the real challenge here is going to be the chain of trust part of that right?
Because what's an exponent at the end of the day, it's a text file with some yeah with some stuff. No, but you know, they're probably they're building from elaborate and X-Files in yeah. Yes take it's a lot of good metadata.
Yeah, but one more point I want to touch on though is that the number three issue from the standpoint of doing improvements to your software security posture was more automation. So IAC tools ended up ranking very highly from a standpoint of helping you address that particular need and just for our audience IAC infrastructure as code, right? Okay, so that that one actually surprised me because this whole idea of you know developers manual activities, not only that is a great way to in fight in problems.
And so more automation ultimately is better. We did some some work last year as part of our Cloud native application security report. And what was really interesting there was um, you know, we kind of use high levels of of development automation IE automated to see ICD pipelines and and all that stuff as a as a proxy for how far along your Cloud native Journey you are right.
I think it's a pretty reasonable proxy to take and in organizations with those high levels of deployment automation for a start. We see much higher levels of adoption of security tooling because automation gives you lots of places where you can hook in other automation, but most importantly we see massive reduction in the time to fix vulnerabilities because through directly through direct correlation, too. Okay, I've been yeah, I've been insecure you a long time.
We had a vulnerability. Motion and Company I founded back in 2005. and back then I there was a company called Hercules a citadel was the company Hercules was the product right they were doing You know, they were pushing automated remediation.
There's several companies today that have automated remediation for whatever reason up until now. organizations have been hesitant to adopt automated remediation because they're afraid it's gonna break something else if in a totally automated situation now, Doing this for the left in the in the development pipeline. If it's broken supposedly, that should come up in testing.
Yeah. Yeah. I mean we could face it.
This is again what we see when when companies adopt snake. It's like, you know, the the automated remediation part of in terms of automated fix PRS, you know is it's probably not where people start but very quickly they they go I I come there hesitant. Yeah, look there's a no-brainer.
Yeah, absolutely because it goes back when I said before blame blame devops, right if we are gonna want to make Cicd pipeline. We're going to automate building software. The answer cannot be that we're gonna manually do something correct.
Yeah. That's right. It just it doesn't work.
It's a disconnect. Yeah. I mean, I need an anti pattern in terms of velocity.
Right? I mean velocity is the the key differentiator for whether sort of businesses in the Cloud area are going to survive absolutely because and and if you don't have velocity, you know, but the left you probably here in security here. We should have learned over the last 25 years is if we are going to drag our heels and dig our heels in and say no no no.
No, you know what? The train leaves the station without you. Yeah, so either get on board and figure out yes, we can and here's how Or get out of the way right lead follow get out of the way security cannot be the drag right on this because velocity is done and what way we see folks who've successfully made this transition to to develop a first you see this sort of this change in in security teams from kind of being Gatekeepers to being enable.
Is that the paper I agree tool Smith. That's right there. Yeah, you just the just the the heart of it.
That's it. Steven anything else? So um, so What's the answer to this issue of not having a security policy?
I mean is it you need to start with a ciso? Do you start with an aspo do you need or at least part-time roles and people and organizations, you know in those functions if you were small, I mean, is that a We know I think not sure what the answer is but I mean it we need one. I think when people think about policies they think oh this needs to be like a hundred page document of some kind.
Yeah. This is it becomes overwhelming but really a policy can be a one line, right? And amen.
I mean, we we have this conversation a lot when people start to adopt security scanner, they've done no security scanning before and they scan this software and they go. Oh my god. I've got like 500 vulnerabilities.
What do I do? But you've got to just pick a starting point, right? And I mean usually, you know, a sensible place would be no critical vulnerabilities that have got a fixed in production.
Well, there's a policy right there right three lines. I and it's better than having he's here right? I've run into this first hand people they hear security policy.
They think I need the employee handbook. Yeah that comes from you know, that this thing, you know, it could be one page or five bullet points anything that's critical is Worthy to stop production anything not critical does not doesn't stop production, but guys to get fixed within 30 days. That's a policy and I mean there's plenty of great templated stuff.
Yeah, certainly arms of of usage of Open Source, you know the stuff by the way, I'd look really the ossf have a library of that kind of thing. Yeah. So you never really got a blank sheet of paper.
Right? Actually the good news is once you have policy then automation can follow pretty quickly. That's that's the right path.
You're right guys. We've got our next guest here in the wings. We could talk about this old day.
I'm sure I'd love to but it wouldn't be fair to that. Again. com.
Excuse me, or on the open ssf. org. Right is the website there Stephen good work again.
I love you surveys and very good. We are gonna take a quick break. We're gonna make up our next guest and we'll be right back here.
We're live in Austin.