Securing the Open Source Ecosystem with StackLock’s Craig McLuckie at OSS Seattle 2024
Craig McCluckie, CEO of StackLock, discusses his journey from working on Google’s Compute Engine to founding StackLock. Recognizing the importance of open source technologies like Kubernetes, he highlights the need to address the sustainability and security of the open source supply chain. StackLock aims to provide intelligence and policy enforcement services for open source communities, emphasizing the importance of building a safer and more sustainable ecosystem for technology development.
Transcript
This is Textron tv. Hi everyone. Welcome back to Open Source Summit here in Seattle, Washington 2024.
With the conversations we've had, the the range of topics, uh, it's just been fascinating. I'm really interested to dig in to, uh, with our next guest who's gonna be talking about Stack Lock and his company that he, uh, founded. I'm joined by Craig Leckey.
Hey, thanks for having me on. Welcome. Good to be chatting with you.
Um, love to have you talk a little bit about your background, the tie into open source and some things you've done. And then let's get into Stack Lock and what Yes, sounds great. What things you're doing.
Um, so, um, my background, I've, I've always been, uh, a kind of fan of open source, uh, technologies. Um, I had an opportunity to work at Google, um, where I operationalized a bunch of open source and, and, uh, you know, worked with my friend Joe better to build out what became Compute Engine, their infrastructure system software. So it was kind of early days of cloud, an important part of what was our, was fun ecosystem new, a fun little project.
Yeah. Little. And, uh, you know, we were a day dollar short in terms of go to market versus Amazon and Microsoft, who had some really strong enterprise, um, sales capabilities.
So we decided to do this crazy Hail Mary and build an open source project that would bring Google's style of operating to the border Walt, which was, uh, Kubernetes. Um, so we started the Kubernetes project and, uh, then started the Cloud Native Computing Foundation as a spiritual home to Kubernetes. Um, worked on a few other things at Google, and then decided to do a little startup.
Uh, it was a company called Hep Tier. We were only in business for a couple years, and then we joined forces with, uh, VMware to help them kind of modernize. I was gonna say, I remember, yeah, VMware some news about acquiring.
Yeah. We were acquired by, uh, VMware just a couple years into the journey. Super fun.
Got to work with Pat Elon, who's amazing. Uh, got to work with Raku, but the leader. Yeah, both are, are fantastic human beings.
And, uh, really joined that, uh, the, you know, kind of the, the mission to create Tan Zu, which was the, the portfolio of cloud native applications for VMware. Um, and then, um, that really got me kind of interested in, you know, open source has always been something I cared about. It's, uh, it's a very big part of the success of technologies like Kubernetes.
I don't think it could have happened, but for open source and community, open source particularly. Yeah. Just to, I mean, imagine if it wasn't open source thing that would be like, no, I don't think it would've gone in very, very different outcome.
Um, and so, you know, having seen that upfront and, uh, you know, being a part of that and, and just, you know, seeing so much value being created, it's been something I've been passionate about. So the other side of it has been, um, you know, this recognition, and this is something that's been eating at me for like five years. Well, like probably a little more than five years is z the entrepreneur's dilemma.
I need to start a company to solve this problem that I have other people messed have. And it was, and it was a problem that, like, I'd been talking about this since before the SolarWinds incident, which is like, Hey, we're using a lot of open source, but we don't really know where it's coming from. Mm-Hmm.
We just have this kind of like happy-go-lucky attitude towards the consumption of open source technologies. And we're not really paying that much attention to the, the point of origin, the sustainability of the communities, et cetera. And I got to see this up close and personal.
Like even in the, something like the Kubernetes ecosystem. Technology's like et CD absolutely critical to the success of the broader project Absolutely. under-invested in, as you know, from the big vendor perspective.
And this is something that just kinda like started to like get into my head and like percolate. And, uh, you know, when I had an opportunity to kind of, you know, reassess my life and decided, you know, what I wanted to do when I grow up, I do that. I decided that, uh, you know, there's nothing more fun than building companies.
And, uh, this just seemed like a problem that I was personally passionate about. Like, I don't know if Kubernetes made the world a better place. I couldn't tell you if it did.
I think it made computational resources more accessible. But I can tell you that, um, the world will be a worse place if we don't lock down the open source supply chain. Absolutely.
Um, there's just too much, you know, sort of risk there. And so Stack Block is in the business of doing two things. We build intelligence around open source software packages that are being consumed in the world, and we provide a framework whereby an organization can then apply policies around the consumption of those open source packages based on their specific needs attributes.
So an example might be, um, I want to, you know, consume something and I wanna make sure that it has the right licensing material associated. I wanna consume something, I wanna make sure it doesn't have CVEs, or increasingly I wanna consume something and I wanna make sure that there's a sustainable and supportive community behind it. Mm-Hmm.
And so being able to generate those heuristics and then create an open source community-centric platform that enables you to apply those heuristics across the SDLC is what SLOs are. You know, a traditional way of approaching part of that problem. Uh, software composition analysis, psychology decomposition, yeah.
Analysis is what you're really doing. But that doesn't address where all this coming from. How's it be, what's that community look like?
Sometimes we step kind of off the cliff, not realizing how far down it is when we sign up to use some open. And here's, here's the thing that's fascinating, 'cause you, you hit the nail on the head. SCA software composition analysis, software composition analysis as a science effectively is built around the idea that software is good if it doesn't have known vulnerabilities and software is bad, if it does have known vulnerabilities.
And increasingly, which year was that? So, and I like, it's just that's simply not true, right? Like the presence of A CVE doesn't tell you as much as you think it did because we've actually created these perverse incentives where researchers are rewarded for guess what, finding cvs.
So guess what they do? They find a lot of cvs Mm-Hmm. And sometimes the, those cvs aren't necessarily appropriately contextualized.
So the presence of a CV maybe doesn't tell you quite as much as, as you might think, but I'll tell you something else. The absence of A CVE doesn't tell you very much either. Mm.
It could mean that they, that thing that you're looking at is perfectly safe. It could also mean that it's, uh, completely neglected and no one's bothered to look at it for five years riddled with horses issues who don't know about, or it, it could mean that it's perfectly malicious. Ah, that it's a copy of something good that, um, a hostile state actor has taken, wrapped, added a little backdoor capability and republished pointing back to the original repo that it came from and called it Pans with a Z instead of Pans with an S and they're just waiting for you to download it.
How would you know xz familiar. Exactly. Right.
And so the, uh, you know, the XD is another great example. And like, you know, we, we just introduced a capability and like, this is, um, sometimes you get lucky with timing, um, and like odds we luck is a great thing and timing is a great thing for not. Um, and look, I, I don't want to be seen to be an ambulance chase.
Like I don't, and frankly, I just don't wanna chase ambulance. No, it's a, it's a problem. It needs to solve.
This is, you know, like, and, and, and look, this is a, a tough moment for the industry, right? Like this, the sea change where, uh, you know, we're no longer just looking at hostile actors that are sneaking around your neighborhood like a burglar looking for an open window, which is a cd. They're getting jobs at window manufacturing companies and patiently working to break the machinery that produces windows that the latches never close.
So they can clean out your whole neighborhood in one evening while everyone's out at a a, you know, a a ton event. Mm-Hmm. Um, and so, you know, when you look at that circumstance and you look at the, the sea change in terms of the way that hostile actors are, are operating, we need to move beyond the CVE as the primary currency for security.
We need something else that we can reason about. It's not enough to just have that as signal. We also need the ability to drive decision making across the SDLC, taking that as a key influence and factor.
I'm, I'm sure you're much more familiar than I am with some of the complexities of solving this. It seems like one of them is, it's not a static ecosystem that stops at a point in time. It's like a living organization that is constantly under change Yeah.
In unknown ways that that's, it would be tough for someone to fathom. And that's, and that's exactly right. And so, you know, when I look at this, it's, this is not an either or situation.
I'm often asked like, Hey, there's some really great work being done in the open source ecosystem. Like open SF has got some really awesome projects that are helping organizations, you know, build in more intrinsically secure ways. You look at something like, uh, the Scorecards project.
It's a good project. We need that. Yes.
And we also need a capabilities where, you know, something that feels a little bit more like Google's page rank, you know, the kind of thing that, you know, we're doing. Like, so an example of what we're doing at Stack Lock is we build a model of an open source ecosystem. So we basically look at, and we do statistical analysis.
We look at, you know, packages that we are known good. And we look at packages that are known bad. And we look for these intangible markers just using principle component analysis.
Like good packages sent out these markers, bad packages sent out these markers. Let's build a statistical model so we can, you know, sort of sort the wheat from the chaff in the most sort of gross terms. And then what we do is we look at the interplay between contributors and packages.
So we use that as effectively a a, a sort of seed score. And then we watch like, you know, hey, this project has these contributors. This is a well known, highly reputable project.
So the contributors that are working on it are probably well known, highly reputable contributors. So let's designate them as such by creating a weighted score which is associated with them. And then when they show up on another project, 'cause this is, this happens over the years Mm-Hmm.
Like, you now have evidence that they are good actors. Yeah. Yeah.
And so, you know, for instance, the, the new, uh, capability, we, we call it the, the trustee, um, the sort sort of OSS trust graph Mm-Hmm. Which is basically looking at this interplay between projects contributors and building these, these way. So in the case of something like xd, what we would've seen is, uh, you know, a maintainer under duress or under a strain.
A lot of the health markers we look for would've been absent to start off with. So it would've had a relatively low score to start off with. Unknown maintainer shows up and starts contributing because there are known that would've fooled the rating down further.
Now, they would've contributed over time, would've built their rating up. But now they start using these soft puppet accounts, which are entirely unknown. And, you know, large prs coming in from unknown accounts, that's a red flag that would've actually, you know, the way that we set this up, that would pull the rankings down even further, you know, across a certain threshold that then triggers an investigation.
You deploy an analyst to go and actually look at what's going on, because those are some pretty suspicious signals. So that's the kind of thing that we think needs to exist that we've been working on. Um, and the fact that we just happen to have it ready now is serendipitous.
But it, it fascinating. It sounds like, um, you know, instead of going down the SCAA path, yes, that's part of the solution, but you're actually informing a risk management process. Right.
And it's a very, this is a check mark, a source of the, it's not a, it's not a, it's not a Boolean thing. Yeah. It's like, um, you as an organization have a, a risk appetite, and your risk appetite probably isn't uniform.
Like, Hey, I have these highly regulated things. I have very low appetite for risk. I have these other things that are, you know, potentially less, you know, business critical.
Maybe that's a different risk profile. I have these things that are entirely experimental and I may eventually, you know, productize them. That's a different risk profile.
So being able to, as a, as a consumer form your own opinion around what your risk profile is, is important. But the thing that's I think even more important is you can't insert this late into the SDLC like this. Like, you know, developers, by the time they've created a merge request, they've fallen in love with their work.
Oh, yeah. Yeah. They're investing in it, right?
Because they're investing in it their, their time. Like sure, you've gotta be in the inner loop before you get into the outer loop of development. And so, you know, for instance, with what we're doing, we try to insert ourselves into the IDE.
So when you type import blah, that's when you get the little red squiggly saying like, Hey, that thing is probably not the one you're looking for. It's, there's another package which is very similar named, which is very popular, which is the one that you probably want that, that's the type of experience that we want to create. And then you need to, uh, find ways to introduce the controls into the SDLC so that it's not just, um, so it's not just, uh, you know, voluntary.
You, you, you need to have those kind of more robust controls where, you know, in the GitHub repo, you can basically assert these things potentially at the OCI Container registry. You can insert these things at the Kubernetes cluster, you can associate these things, and you, you kind of draw the connection across the whole SDLC back to, uh, that sort of source of origin, taking a systemic view of it. Man, you work on some pretty difficult problems, sir.
That's fine. It's fine. If it wasn't hard, it wouldn't be worth doing.
So let me grossly oversimplify this. Yeah. Are we, are we evolving, again, super simplifying it.
Are we evolving to a place where we, every open source project, maybe people working on open source kind of get their own Uber five star rating based on the set of scores? So maybe there's an incentive model that I'm aware of what that risk profile is by my actions and how I run the open source fraud. I, I want to kind of change it up a little bit because I, I, I don't want to, like, when you look at something like the xd, um, project, it's a critical piece of infrastructure.
Absolutely. And like, and saying XD like deserves a one star rating. Like it's, I I don't think it conveys the right sense.
Like it's, I would say it represents a critical point of risk for the industry that we need to draw attention to, and the mitigation to that risk needs to be bringing our collective resources to bear to address those things. Yes. It isn't a penalize that person.
It's Yeah. We, we can't penalize, we can't, we can't get into the situation where we get this sort of, um, this McCarthyism where we are like, um, you know, like we're, we're like, we, we, we, we we're, we're paralyzed with, with paranoia. Like, you know, we, we need to recognize that the safety in numbers, there's value and transparency.
There's, uh, you know, like many eyes on a system are gonna create better outcomes, and we need to pull together rather than allow what's happening with something like the xe um, incident to kind of pull us apart and, and kind of isolate us and, and create this sort of isolationist way of looking at the wall. And so, you know, the way I like to think of this is, uh, you know, you could look at it as like a, a Moody's bond rating, or you could look at it as a, as a, as a Google page rank for projects. But we don't want to necessarily use this to steer people away from, from things that are important.
We also want to use it to draw attention to the things that need more intrinsic support. Seems like there's a feedback loop there. Then it isn't just the assessment.
It's what's the action to take, not just avoidance where there may be higher risk. And that's, that's what I, that's what I like about, you know, like there's, there's a lot of, well-meaning people, and there's a lot of, well-meaning vendors. You look at people like Microsoft or Google, they're bringing a tremendous amount of resource to bear to address some of these issues for public good and for their own good too.
But, you know, like it's, it's, it's benefiting all of us. You look at organizations like the Linux Foundation, you know, they stand behind open source and they are well finance, well resourced that they can actually, you know, bring help. So I think for us, it's really a start like establishing a starting point where we're just driving awareness, driving transparency, helping people understand what decisions they're making, and, you know, helping them, you know, steer them towards decisions that are going to lead to more intrinsically sustainable outcomes across the board.
Whether that's sponsoring projects that need to be sponsored, or whether that's making the choice to include a specific library that has a healthy community behind it in a project that is important to them. Very cool. Um, you know, ear early in the, in the stage of a startup company, you said you've been around a, we're talking before about a year.
Yeah. Um, what are some, uh, as you envision what some of the potential outcomes might be, where to take the company? What, what do you think some of those are?
Well, for us right now, I mean, we're here to solve problems. You know, like we're, we're here to create value in the world, and if we create enough value in the world, hopefully that generates some commercial success down the line. But right now, honestly, the thing I care most about is can we help open source communities operate in a more safe and sustainable way?
Mm-Hmm. And so our focus right now is delivering services to communities that are, um, building this technology that's incredibly important to the world. So, uh, we have built a, a, uh, an intelligence service we call trustee, and we've built a policy enforcement service we called Minder, that are already, you know, two sides of the same coin.
Mm-Hmm. One, you know, generates insight into what's going on out there. The other helps you apply policies around it.
And we're making that available to open source communities writ large, and that will be free in perpetuity. We've just wanna support these communities and in supporting these communities as they start to adopt these technologies. It also generates really useful information about how those open source communities are operating.
So we'll just feed that back into the system and starts to generate these network effects. So the first kind of part of the journey for us, and this is, you know, we, we, we just announced these two offerings like very recently. Okay.
So we're just starting the process of actually engaging with open source communities. So the timing's impeccable. Um, we'll get through that.
And then, you know, obviously we're also gonna be looking at introducing, uh, capabilities for commercial customers. Yeah. Um, you know, sort of down, down the line.
Um, but for now it's, it's mostly just about, um, you know, simple free to use community centric technology. And then obviously if people are interested in a commercial conversation, always happy to have it. I'm a startup, you know, I am financially motivated at the end of the day.
Mm-Hmm. Um, but for now, we'd be very satisfied with just over the next few months helping a large number of open source communities operate more security. It is interesting.
One things entrepreneurs really get is there's a huge learning phase, right? Where you're out engaging with people you're looking to solve problems for, is it the right problem if, what are the approaches? And in your case, it's not only that, it's also taking that domain knowledge about those projects that you're working with.
And as you're extended to others, putting it in some form shape fashion, that's a product or service that commercialize you can those opportunities. So you're building that knowledge base as well as understanding the problems. Yes.
Super valued. Yeah. And I think it's, it's gonna be, it's gonna be fun.
Like it's, it's just, uh, it's the best job in the world. You can tell. You can tell you're, you're fascinated and enjoyed.
No, I just, I love doing this. It's, uh, you know, it's, I I do it for free. If you, it is one of the most fun phases Yeah.
Of, uh, building a company. And especially when you're, you get on that path and you validating what you think is the right direction to go and absolutely. Continue to grow.
Well, good stack lock. Craig mcl, good to be talking with you. Thanks for taking the time.
Um, let's engage again. I'd love to hear as you continue to, you know, learn and experimenting. Yeah, absolutely.
Always available for, uh, conversations. It'd be great. That's super fun journey.
Oh, it help us all inform us all as you're, uh, learning about this to build your company. So wish you the best of luck. Thank you.
Appreciate it. Alright. Thanks.
Having me on. Alright, take care. Alright.
Another great, another great interview. You know, coming from a totally different perspective than we have in some other interviews and people that are pro solving other tough problems they're passionate about. I mean, what better kind of folks to be working on those things.
So, thanks for joining us for these interviews. We'll have more coming. Stay tuned.