Tracy Ragan, DeployHub | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone, this is Alan schommelwood live here at open source. Security Summit Linux Foundation Austin.
We've been here all day for two days now. Actually we've been here two days. Hope you are enjoying the coverage if you haven't quite got the gifts yet this next interview.
I think we'll drive it home this open. This OSS opensource. Summit has become all about open source security supply chain software supply chain security s bombs and I can't think of a better person to discuss it with than the one and only Tracy Reagan Tracy.
Welcome. Thank you Alan time. We're doing in person.
No we are this is our first postcode video person. Yes, so Tracy's been a staple during all these long months of covid, you know zooming in from her place in New Mexico. Sometimes I feel like we're keeping her from going out riding and doing whatever she does out there in New Mexico, but it's so good to see you in person.
Well, it really is very glad to be here. So You know, let me ask with this question then. What are you doing here?
Well, I came here. So this is the open source Summit. So this is about everything open source, but I was invited to speak on a panel at open source security Foundation day, which is the open ssf.
I know these all these open it can get can kind of confusing. Oh that's too and then I was invited to speak at the supply chain security con tomorrow. So today's kind of my day off.
I'm in the middle of between two and I've been attending some sessions and learning a lot. I love it. So Let's get something straight, right because there are a lot of owes a lot of s's and a lot of apps here.
yesterday the open source security Foundation ossf had their sort of conference within the bigger open source Summit. We had had our kind of a community day. I would call it.
Yes. That's a good way of I would call it, you know zero day conference, but that's bad insecure. Yeah.
And you are on the board of the I was I have been I was you know, I decided to throw my hat in the ring. I'm a member rep. So, you know, I have a history of being a member rep for open source foundations.
The first time I was a member rep was for the eclipse Foundation actually IBM reached out to me when the eclipse Foundation was first being started and asked if I would be the member rep and then I was the member up for the continuous delivery foundation and then we moved when they started talking esbombs. I'm like, oh we're over on the other side. Now we're going over to the open ssf because that's you know, kind of my thing and I went ahead and threw my hat in the ring and I got elected to be another member rep.
So, you know members out there I fight for you believe me. I'm constantly fighting for the members and okay, you do a great job you've done it and see you've done it in every organization, but I got to ask a question. Will you like the class president?
And yeah, no, I was not come on, you know, I wasn't never really I didn't want to do that. But when I was probably about I don't know my must have been 12. I started a club.
Oh, really? Yeah, I was into having a club you always never in high school. I was wondering will you like a sorority?
No God. No, I was a competitive gymnast. I had a horse.
I was taking music lessons and my parents kept me so busy I didn't have time to do any of that stuff but really but here you are. I mean if there's an organization Tracy Reagan, you're always willing to help I you know, I love open source and I believe in the community and right now I believe that real problem we have with solving these this difficult situation we find ourselves in with a ton of Open Source. I called it yesterday and my panel like, you know, I said, let's think about the open source and all of its connections and all this dependencies.
It really is a massive. It's like a Death Star And it really is a death star. So we need Community to come together to really talk about this we are in we are in such a flux right now between open source security, which we know we have a problem with and now Cloud native and microservices and a changing CD pipeline that there is this is time for discussion.
You know, I mean facetiously I thought you were the first person to talk to us about this in the last few days. In fact almost every person has and you know in listen and that's how I learned right? I I kind of like an ant or be with an antennas and I just take in all this information.
com devops has been so successful. in fundamentally changing the way we build software. right that we we've introduced this concept of software factories and Pipelines.
Microservices is part of that. I mean when you think back to when My very first company that I started in the 90s. When we would have to build software for a customer, you know project we would take on project and we was software developers and I think about what it was like to build software for those customers.
Versus how software it's done today. It's night and day right? We didn't I I didn't realize it back then.
I thought I was just young and stupid, but we were building bespoke custom. Applications or software for every project we did and every project we did. I mean there was no VB or even Visual Basic or anything like that every project.
It was coded was coded by hand. Yeah, and you didn't use a lot of Open Source or shared libraries. Oh, well, a lot of people wouldn't let you if they knew there was open source in there.
Oh, no. Yeah, exactly violates our licensing and our insurance and our this is all b*******. But anyway, You know, but when we when I think back to those days.
Versus way software is built today where I don't want to say it's Frankenstein, but you just you're pulling in stuff stitching and that's about a business agility and speed and being able to stand up new applications. As fast as possible is is the focus which is what started really pushing open source, because you know who wants to go if you already have beautiful graphs. You don't want to write them code you scratch just find something out alive, but this is It's accelerated.
I think devops in the whole agile. And you know, these kinds of things have accelerated that but it's also introduced the concept of Supply chain security. Yes who wrote it?
Is it secure it should I trust it? So we have so many options now. We have so much open source out there that we can borrow from now.
We're realizing that we really do need to and I hate using this analogy, but it's appropriate we need to be able to list our ingredients. Yep. And it comes, you know, I've been talking a few of the government folks because in that supply chain discussion, you know, I when I think about it, it's like what's the first thing we have to solve to me the first thing we have to solve if the houses on fire response.
We need to have a good way to create a response if there is something like another log for Jay. I don't want to hear about it because a new cve came up or I saw it on Twitter. I want to know in a better way.
And that you know, that's kind of my dream is that someday we will have a you know, that's what we're working with on artillas a unified place. So that you go and register. If you are you're written something open source, you go and register it you register who you are so that we can begin that trust story and you can begin tracking the s-bomb of that object that may be consuming other.
Open source product components which it's gonna do which is why we have this crazy dependency map and it's very difficult to sort out that you Traverse down. It's a rabbit hole you get to when you see all the different open source tools that you're using and then that one way down there may have been using log for J, which then it can expose you all the way up the chain. So it's a good it's a really good discussion for us to start having but to be quite honest we are starting to break that even though we're just now having this in a monolithic world microservices does change that a little bit.
Absolutely. So we're maybe things I think a complicates it. Hey quotes.
Now it you said oh, well it might have log for Jay way down here third party third party third party well with microservices and you have dozens of micro Services each one of them and so on and so on and so on right the problem becomes infinitely harder to solve you almost look at and say well I was just the only with one thing monolithic right here. Well, if you just deal with one component right here and break it down if we can get it broke down to individual components that you know, it's like going into Home Depot. There's if there's a giant store have parts and pieces and you go and find exactly what are you right one bite at a time.
So that's you got it. That's otherwise. It'll scare the crap out here you run away.
Sorry. Let me find the difference to me. I think everybody should be thinking out components.
We have a I want to call it a component-driven architecture because that's what we're moving into and components are consuming other components, but we have to start breaking those components apart and over time. This is not going to happen soon. But over time we have to start decoupling this because one what it may be the case that you didn't really need that library in there.
It was just stuck in there because somebody thought it needed to be there and then you have a vulnerability for no apparent reason and that does happen. There are there are dependencies that are un Necessary and this as soon as we start figuring out a way to centralize the data and be able to slowly break apart some of those components and decouple it especially if we do that for like the top 200 open source projects right open source libraries, then we'll start making progress. But I feel like we have to we have to take that on and we have to be absolutely we have to be accountable for it.
So To me. There's two things here. number one and I'm actually looking forward to talking to our friends from Jay frog about this is I really think when so many of these components Make their way into our software from being downloaded from repositories.
There's got to be some responsibility or not summer. There's got to be an advantage to repo owners who are more responsible about what gets downloaded from their repo. right Yes, but it's hard.
It's hard crazy everyone you placed a game but we've got to put there's gonna be choke points in on this. Yes. Well developers don't well, okay.
I'm not joking, but you know, there's gonna be Gates places where we can gate stuff and where we can regulate, you know, I I hesitate to agree with you because we thought so hard to break the gates down so we can move faster because again we get back to this is a business agility discussion is I feel it's more it's more like you accessibility and visibility and information and appropriately using the tools we have we're so much devops and tell intelligence underneath our automation. I think that's the deal and Reporting. Let's take something old.
Let's take struts to from Equifax. Right the Equifax culprit. Yeah.
I believe wasn't that in the sonotypervisitory nessus the problem with Equifax. Was they knew they had a problem but they had too many gates to get it to production. Yeah, and that that is an issue.
So there was about breaking down the gates. So we can't say once after Equifax people are still downloading and using that old version of struts. Why?
Why why is it even on the repo shouldn't there be? You know when you're using your browser and you go to a site that might be unsafe my wife will call me with this all the time. I got a message.
I'm going to an unsafe site, but I need to get to the site. My first thing is usually did you type the address right? But that being said why can't I digress?
Why can't we build why can't we build? A warning I believe that we should do that. I totally do and it seems a no-brainer is to me.
Yeah, and you have to keep you have to think of it as historical too. Yep, because you have to know what versions of that and that is, right. We are records indicate you downloaded this component, which is now been did whatever the word is the deprecated deprecated.
That was the word. I don't do that. It might hurt.
I know. Why can't we you know because there may be a dependency on that. There's somebody needs are you at least I made you aware of it.
And now you manage that I know I agree completely there should be there should be accessibility and hear this. She agrees completely I because that's what we're trying to do with artillious a central place for you to go and so that you can see for every version all the vulnerabilities so I can make that decision if I want to use that in the same way as right. We now make a decision.
If you want to put a mask on when you get on a plane, it's the same thing you have to be able to make that decision problem is there's not a central place to get that information and it's not historical. It's not often based on version. So you can't see the vulnerability.
You can't see the level of the vulnerability. It's it's you can find it if you work hard at it, but it's not just well the whole level of vulnerability thing is I think also Look, I was there with miter my friend Bob Martin from miter at RSA one year and that's the whole cve thing and raiding a vulnerabilities. What a great idea.
It was back that but what I've come to understand in the years since then that was 15 20 years ago what I've come to understand since then it's just because it's a critical vulnerability to me. It may not be a critical vulnerability to you for you may have done things that kind of Deflect the I might not be using it and something that has a high risk value or it may not be accessible to the outside world. It may be there's a there's a lot of reasons.
So it's very hard to say something is a high critical to everyone. It I think it depends I think and that you know, so I'm so I'm not a complete socialist right? Not quite I think individuals or individual organizations should have the ability to determine for themselves, but they have to have the data to do it.
Right and this is the problem. That's that's the data is the problem. It's out there but it's hard to find if you don't have something I already automated you're asking your developers to look for those vulnerabilities before they release it and they've got other things that they've got to do.
So we need it. We need it served easy to us. Were you we're becoming very lazy when it comes to to digging that kind of stuff up.
I mean, you know, if I if I'm on my phone and I go to download an app and it gives me any hassle. I just go find another I agree with you. So we have to make it we have to serve we have to serve the data up in a way that is in their face and it's easy to get to and that's that's the challenge and that starts with s bombs because you have to have the best bomb before you can find.
vulnerability, right you have to know what's in your package and to know what vulnerability to look for and that's even a challenge for some teams because if you're right if you've written a manual kind of Make process or build process or scripted process whatever. However you're building your packages, you need to include all of that scanning and you know call something like sift or Cyclone to create that information. And if somebody's not telling you to do it, it's probably not going to because you got other things to do you're developer, you know, right we have done an hours in the day.
So the automation is critical and it would be great to have some kind of again. My complaint continues to be if if we have a fire in, New Mexico. We have a incident response system that starts to handle it from the very beginning you somebody who is in charge of that right.
Now if we have a fire and software we don't have a central incident response more like Florida. He said it not me I live. Oh don't even work on that.
And that's again being getting the data having the data accessible and easy to access. Absolutely Tracy Reagan. It is a pleasure to see you pleasure.
I I always love doing these chats. I know you do but it's just nice to be in person with you and not have you up on my monitor in the studio there and we didn't park we didn't talk about continuous delivery. Though we did it and you know what?
I was surprised. I haven't seen more CDF presence why I wear my t-shirt. I see I do see you have that was two weeks ago.
Yes, it was and you know that there in the CD World things that you should be asking people as you're doing these interviews you start asking them about CD events. Because events are going to change the way our CD price not CD conferences events within that CD correctly, correct? Because think about this think about you want to add s bomb and vulnerability scans to your pipeline and you have 2,000 workflows that you have to update.
Are you really going to do it? No, no, you're not going to but if as we evolve through this we have to work on the Automation and the event City events having a single listener where everybody integrates in a similar way and there's a payload that you pass across based on an event like Cloud events that's going to prevent people from having to write these very imperative pipelines and it'll get us there faster. CD Adventure heard about it here first from my friend Tracy.
All right, we're gonna take a break. We'll be back. I think we've got some folks from IBM some folks from jayfrog still got plenty more to do today here in Austin.
We'll be right back.