Steve Springett & Andrew van der Stock, OWASP | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone. We're back here live in Austin at the Linux Foundation open source Summit event.
These are third day but it's technically day two of the event we started on Monday. This is our OAS portion of the of our coverage. I'm really happy to be joined by my friend Andrew Vander Stark and you're welcome.
Good to see you and joining Andrew with me is a new person for me Steve spring it. Is that good indeed out also with? Oh watch gentlemen.
Welcome. Thanks for having us. Thank you.
So what brings owoss to open? Source Summit sbalms, that's bombs. We worked with the US government in particular on freedmen to set up a meeting between the spdx and Cyclone DX teams Cyclone DX is owoss s form standard.
It's heavily used in industry and Steve is our calculator of the Cyclone DX project India. It's cool. Yeah.
So tell us about the project and and kind of what what you know, what what's going on with it? Yeah. It's a s-bomb standard purpose built for a lot of the sky cyber security use cases handles license and intellectual property and those types of use cases as well.
But it's primarily focused on cybersecurity and there's a lot of different cyber security use cases that that we support. Huge focus on Automation and we've got really good adoption within the security Community most major SCA vendors already support Cyclone DX today. There's some is vendors and in Mobile vendors Etc that are supporting the standard.
So it's been pretty well adopted thus far we did some preliminary estimates in December last year conservatively. There's around a hundred thousand organizations today that have adopted Cyclone DX and we have some really interesting data some actual data on the usage of cyclone DX which is in the billions today. So it's a it's definitely being used in mass quantities in a large percentage of the population.
But even with 100,000 organizations, it's still small in comparison to the millions of organizations that exist. So there's still a lot of growth potential there actually 100. Johnson is an impressive number though.
I got to tell you so she was something relative. How long is Cyclone the X been around now? It was created in 2017.
All right release was in 2018. A lot of the research that went into Cyclone DX actually predates all of that going back to 2013 with some of the really early loss work that we were doing. Absolutely, you know, we were talking off camera about this event.
I had RSA with deaf set cops and we talked a little bit about that moms. People there are two friends. I think Andrew probably knows chancy wine.
Oh, yeah Chancey and Carolyn long and we had this discussion around that sponge and chancy made a very interesting observation that I haven't heard before that one of the things that we need to figure out to overcome wider adoption or to you know, enable wider adoption a best Farms. Is this notion of IP Right. So in other words if I give you the recipe to my software which a NetSpend may very well be What's the stop you from brewing your own?
Mm-hmm, right and it's fine it open. So it's because an open source that's kind of the the way we do things. It's not so fine.
Right not open. So even though the you know, the nod open source software may very well contain a ton of Open Source internet often does it's still a recipe. It's an IP issue.
I think honestly, we do the reference and presentation for open source, and if open sources then becomes more trusted them proprietary the market will follow so for my perspective, the reality is this we actually demonstrate you can get better security for life and Source software because of Open Source. Then not only do you have the freedom? You also know that this is somewhat trustworthy whereas if you have proprietary software and they don't want to give you the recipe.
Well, maybe I don't trust that. I can't use that in this particular scenario. Right and there is a you know, there's this distinction between like the recipe versus the raw ingredients, right?
You can look on the back of a Coke can and see the ingredients but you don't know formula exactly exactly. So we're not, you know, the intellectual property concerns and s-bomb can coexist. So I've struggling to several folks here in the last couple days around as bombs.
And as one would in any security themed conference these days and and you know, I when I'm afraid of is the unixation of s-bombs, right if we have too many standards too many flavors of s-bombs that aren't necessarily compatible. Are we gonna have a eunuch situation right where you need a different application spun up and you know, it's If you look at s bomb I kind of can equate it to like an automobile. Right?
Well, you can have an F-150 and you can have a Maserati right is one better than the other it really depends on what you want to use it for. Right? And I think that's bomb formats today or kind of that way.
You can use both formats simultaneously they both bring something, you know good to the table. We believe it. Oh lost that we bring a lot of the security use cases to the table.
That's kind of our main focus but spdx brings. It's it's strengths to the table as well. And you know organizations can adopt both and many security vendors can adopt both and they have adopted both.
Now. There's there are security vendors that can either do one format or the other now in the security space. It's typically Cyclone because we support a lot of the use cases that you know, the other format may not but organizations are free to adopt both of these formats and there is a certain amount of interop between the two there is there is to an extent but if you care about a lot of the other things that are not necessarily common between the formats they will in fact be lossy.
So so let's let's do some table setting if you don't mind for our audience. So cycle on the x is the oi standard. Spdx right who that's the Linux Foundation of Linux Foundation open ssf open.
That's not yeah. I always afraid I gave an actress in there somehow but open ssf that's their standard. You know, I'm reminded in the early days of RSS feeds.
We had RSS one RSS two Adam, you know, and it was a real pain in the butt right because you wanted to get an RSS read in a read all of your blogs or whatever and depending what RSS version used. It didn't work till a Feed burner came along and it kind of normalized right RSS feeds for everyone went up selling the Google for like 100 million dollars with no revenue and did koslo is this founder of that? He went on to be Twitter CEO for a while.
Yeah, but do we need a feed burner? There are translation. Tool, I mean, I hate to hear that we lose stuff in the in the sauce.
Yeah. I mean we're not ready to announce much about this meeting but that was the reason the reason why the meeting existed is to have a Frank and open discussion between the two teams and we really think the Linux foundation for inviting us here. That's good.
Yeah, so you heard it right here. First stay tuned. I think we're gonna see something hopefully come out of this that'll help us all as we kind of kind of rally behind maybe one standard or or more interoperability depending on whichever standard it is you want to pick for for your S farm needs now, you mentioned a hundred thousand.
Which boggles my mind a hundred thousand organizations using it already? What do you think the actual addressable Market is? There are many I don't know.
I mean it's going to be in the millions out of the 100,000 organizations that we've know of adopted it. We know that around 202 million components are represented in Cyclone DX every single month. And the way one tool specifically that was measured that analyzes and consumes these.
That equates to about 20 billion checks for components with known vulnerabilities every single month. That's just the data that we know about. And again, it's it's a substantial number.
It's big enough to know that this stuff works. It works in mass and we can operationalize this without a lot of effort but it's still small in comparison to the millions of organizations that exist and the interesting part about the Folks that are adopting a lot of this, you know the early adopters in this space. What I find in the oauth community is that the majority of them are using it for internal best practices?
They're not necessarily sharing these things out. Well, it's only maybe certainly within the last year with the White House in the right thing that we've seen this light where you know, it's become a thing right? I think before it was basically for internal practice and internal teams.
I think it'll really become. Common place in and you know de facto. When end user organizations when I go to buy software from you or I go to consume software from you.
I say I needed that spot even if it's for my compliance governance and stuff. I think you're actually that's exactly right and I think the US government here has a huge role fed ramp improve the cloud security for so many people absolutely and it didn't say you have to buy AWS. They didn't say you have to buy no, she said in federal certified.
Yeah, and that's why I think that's bombs need to go and I think honestly the the driving Factor here is the EO and that's what we're working on is how do we get the features we don't have in Cyclone DX. How do we get the interops that people who use both don't lose data and that's I think a really good thing. I agree.
I agree hundred percent no pressure. But when do you think we might see some side kinds of announcements of moving on this? Well, I'm hoping that we'll have a joint Announcement by the beginning of next week.
We made it really good commitments and I think honestly The worst part is to actually do the work. Well, that's always the easy part. Well, yeah, I know.
Well, I'll tell you this. I am back in our offices next week. I'd love to see it announcement or maybe we can grab somewhere from Linux foundation and one of both of you wanted to discuss this further where we chat to grab Allen freed me too.
That would be a great panel and that's why I think so Kate Stewart is looking the lady you need to talk to. All right, I'll reach out to her. Hey Beyond that's palms and you what else happening with Oasis?
Well, we have invalid by laws. And we're going to need all of our members to vote for it. And so we're actually working on a replacement by law package at the moment that gives the members what they want because we need the members to actually approve it.
So that's exciting. If you remember out there go vote for this, you know, the big we I see this in my homeowners association. No one goes to the meetings but no one will even fill out the proxy forms.
Yeah, so that you have a quorum to get things done a quorum to get things done. So don't let that happen here get the OS by Louis paste. Yep to do that in conjunction with our next directors election.
Very cool. Hey guys, thank you both for the you know, people don't realize it's a lot of work working for you know, what's a Linux foundation and just because they have the non-profit name on there doesn't mean everyone a works for free or be that people don't really bust their butts working on these things. So thank you both for what you're doing.
And you know, I hard you are on it, Andrew and Steve it sounds like you're doing a bang-up job. So thank you fine. All right.
All right. We're live here in Austin. We'll be back in a moment with our next guest.