Chris Robinson, Intel | OSS North America 2023
Join Mike Vizard in an engaging interview with Chris Robinson, director of security communications at Intel, as they discuss the mobilization plan for the Open Source Software Security Foundation (OpenSSF). As an industry group comprised of vendors, researchers, academics, and open source maintainers, the OpenSSF focuses on the value of open source security. Chris sheds light on the current progress of the mobilization plan, which aims to enhance and update the initiatives put forth by the foundation. They delve into the journey of the OpenSSF, highlighting the collaborative efforts and objectives of the group.
Transcript
This is Techstrong tv. Hello and welcome back to the Open Source Summit in Vancouver. We're here with C Rob from Intel, who also happens to be working on the mobilization plan for the open source software Security Foundation People.
I have to get my foundations kind of straight cuz it gets a little complicated sometimes. Indeed. See Rob, welcome to the show.
Well Thank, I'm glad to be here. Mike, We talked a little bit yesterday with some of the folks about what the Open ssf is up to. Mm-hmm.
What exactly is this mobilization plan? How far it is? I mean, I seem to remember there was a plan that somebody put out last year, Right?
That's it. I'm assuming it's been updated. That's what we're in the process of doing right now.
All Right. Well walk us through that. Where, where are we on the journey?
So the Open ssf is an industry group comprised of vendors like Intel that see value in open source security, researchers, academics, uh, open source maintainers. And we get together with the purpose of trying to uplift security for the whole ecosystem. And, um, as you might have heard, a lot of global regulators are really interested in cybersecurity and open source cybersecurity.
So the, uh, Biden White House in 2021 released an executive order on improving cybersecurity. And subsequently, uh, the White House has issued a couple additional, uh, executive orders and statements and strategies, but also a lot of other global regulators in Europe and Asia and all around the globe have done similar moves. So the, our mobilization plan was kind of a reaction initially to the initial White House order, but also it kind of generally encompasses all these regulations and it's outlines 10 points of how if we invest, uh, people process, uh, dollars, uh, infrastructure into these 10 different areas, we'll be able to significantly uplift the posture of security for open source for everybody.
Is this plan gonna be updated? I mean, as I understood it, the plan was kind of a reaction to log four J and everybody kind of losing their mind. Right?
So, so what parts of the plan have been implemented from last year? And then what do you think should be added to that? Or what are you guys talking about?
Mm-hmm. So right now we're in the me I, uh, have the unfortunate designation to help kind of head up the rewrite for the plan as we come up on the one year anniversary. So we're going through and right now taking an inventory of out of those 10 streams, how many folks have Honey volunteers of step forward, uh, to do work, or how many pledges have we gotten to help fund certain efforts?
And right now we've got about 50% of the 10 streams that have active activity and either have completed a rewrite and have a proposal for refined funding or are in early stages. Like we have a, a newest SIG is the memory safety sig, where it's, uh, we wanna rewrite older languages like c and c plus plus into more mod, either use new mod techniques or tooling or convert them to memory safe languages like roster Java. So that group just recently started about, restarted about two months ago.
So they're a little bit earlier on in their journey. But we're gonna holistically look at this plan and issue a rewrite. And our target is to get it done, uh, probably early June based off of vacation and travel conferences like this kind of get in the way of us actually getting together and doing some writing.
But, you know, overall we've seen, um, a lot of activity in areas like, uh, sbam with software, bill of materials. So we have a group that's very actively taking a survey across the whole software ecosystem of what, uh, closed and open source tools are available, trying to work with, uh, cisa and other regulators that are kind of helping set these standards. And so they've had a pretty decent amount of activity.
We have a couple projects, uh, alpha and Omega that are focused on the top 100 projects trying to improve their security. And then the bottom 10,000 trying to introduce automation and lessons learned from those higher projects and projects like that have had a pretty, a lot of success. And, uh, we just actually did a readout from our, uh, uh, group we work with called otif, uh, the open source, uh, Technology fund.
And they help actually help us do security audits for some of these larger foundations. And they did a readout and they actually had pretty significant engagement last year with, uh, the node JS community. They're partnering with Eclipse and other large foundations to help, uh, kind of go to those communities and find out what they need from their perspective for security and doing security audits or helping them find security experts to participate in the project.
Or, you know, uh, doing bug checks, you know, doing vulnerability scans, helping them out. Why would a large company like Intel kinda lend its support for this initiative? What should other companies be doing as they watch what Intel's doing?
Mm-hmm. Because it seems like, you know, this is a coalition of the willing, so more help is required. Very Much, uh, patches and people are always welcome.
Uh, Intel has been involved with opensource for over 20 years. We are the, uh, largest corporate contributor to the Lennox Kernel, have been for many, many years. So we, opensource is one of our key values.
We, we operate internally very much the open source way. So not only do we do a lot of contributions upstream, our products benefit from all these open source packages. So that's why we invest our time and our people and our dollars into, you know, adding value to things we get value from.
And, you know, we're not alone. A lot of large organizations across the ecosystem, red Hat, Microsoft, Google, Amazon, apple, you know, all of us. There's over a hundred members that participate in the foundation.
And, you know, where we need help is, you know, volunteers are always welcomed. This is primarily volunteer driven. Sometimes we have a, you know, a rallying cry, like the mobilization plan.
Um, but yeah, we need people to actually show up and help, uh, rewrite things or write code or help with documentation or work with global regulators or just go out and help educate maintainers and help provide them tools so they can do their jobs more securely and more frictionlessly. How do they get involved? Is there some meetup somewhere that you go to?
Or do I just send out an SOS and someone will find me? org is the foundation's website and from there you can get to all of our repos, every working group, uh, special interest group committee. We all have a publicly available GitHub repository.
All of our meetings are 100% open to the public and recorded and posted to YouTube. So if you're really bored and you wanna watch thousands of hours of people on Zoom calls, every single committee and project is out there for people to watch. And if you're inspired, you can participate and every working group will have a mailing list, a Slack channel that they can, um, participate in.
And we have, um, you know, mini notes that are typically stored up in GitHub. org is the great jumping off point. 0 will be available.
Right. Don't zoom bomb, be these people cuz they have skills and they'll find you. So be careful.
Um, as you think about this whole thing, what's been the reaction from the maintainers? Because a lot of the times, you know, there's big projects and little projects and the little projects are somebody's hobby and they're basically like, you know, it's not my job to worry about security for you. I didn't ask you to use my software, I was just doing this for fun.
Mm-hmm. Well, we, we try to be very sensitive to the maintainers cuz we understand any new task is additional unplanned work for them. Mm-hmm.
They haven't predicted it. And a lot of these developers don't have the right skills. They have never been trained or unaware of security concepts.
So we try to be very sensitive to their needs. And like, particularly with like Alpha Omega, we come in and we ask them, how can we help you? What tools, techniques, resources would make benefit your project, help you, you know, increase the quality of the software you're delivering?
And it, it, it varies. Uh, we do a lot of outreach maintainers. We, uh, have a, uh, our software securing software, repos working group actually did a maintainer summit where we had about 40, uh, kind of very well renowned maintainers throughout the industry from large and small projects.
And it was essentially a listening session. I was one of the facilitators where we had a kind of a series of questions and we would ask them, you know, topics like, how would you, how are you interested in improving the security of your project? What types of tools or resources do you need?
And that was, uh, very insightful. The developers reacted very positively that they appreciated the participation. And we don't ever want to kind of knock on the door we're, we're here from the open ssf, we're here to help and kind of impose things on them.
But we do try to have a lot of different creative techniques between tools, best practice guidance, and, uh, just kind of like a help and support groups. We do a lot of office hours where we're trying to nurture like new, uh, new developers into the community where, you know, ask us anything how to, how to do a pr, how to come in and get engaged with the project. And we do similar things for, um, uh, well maintained projects where whether it's one maintainer or 1000 Yes.
You know, anyone's welcome to help kinda learn from what we're doing. How automated can this get? Because at least in my experience, a lot of the mistakes are relatively routine and trivial.
They're just stuff that people didn't know and suddenly they're open to a SQL injection attack or whatever it may be. Yeah. So can't we, you know, use some sort of algorithm that will just identify that line of code and say, rip and replace with this line of code push button.
Yeah. Look, the, the ultimate solution is gonna be a blending of people, process and technology. Mm-hmm.
We have to teach people the right skills and the right things to look at. We have to provide them tools and automation, and then we need to provide 'em best practices guidance. Uh, so there is a significant effort.
So the, uh, again, the Alpha project is focused on those top 100 projects. And as they're engaging and learning from those communities, like right now they're doing an audit of open ssl. So as they are working with that community and they're doing scans, they take those learnings and wherever they can, they try to make automated free tools that are available to any developer.
And it's a lot of, you know, we can automate fuzzing and we can add automate, uh, static or dynamic analysis. So there's some things we can do, but it, it's challenging to automate, uh, teaching people like security architecture principles. Uh, and that's why we also have education classes that if somebody wants to learn some of these techniques and if they want to practice skills, like how do I avoid having a SQL injection?
We have a tool called skf. It's a hands-on lab that you can go in and they have coding exercises where it teaches you this is what, how a, what a SQL injection looks like in code. And you here's some exercises to try to teach yourself how to avoid doing that and identify it in code.
There are of course, more companies consuming open source software than creating it. Right. Do they have something of a moral obligation to help participate in this whole process because they are dependent upon it?
Uh, my personal opinion is absolutely, uh, that, that's how I got into open source. I came in from banking where I ran, um, a web security team, and then I ran the bank's, uh, critical systems that were primarily Unix and Linux based. And that's how I got the bug, uh, to get into, uh, red Hat and Linux.
And I fell part, you know, part of the reason I got into it is because I found my organization and myself personally found so much benefit from the software that's, I wanna find ways to give back, improve the ecosystem for everybody. So I I, I agree personally that I think if you are a user, and I think the SONOTYPE report said upwards of 80 to 90% of commercial enterprises use open source, and I think the 10% that reported, no, don't know. Uh, so I think if you are using it, you have some obligation to contribute and it, it could just be providing feedback.
Hey, I saw a typo in your read me file. It could be code, code contributions are great, but there's a lot of different ways that people could participate and give back to open source that they receive so much benefit from. And that runs the global economy today.
And that's why, again, Intel and the foundation, the other members feel very strongly about this. Wait, I, I'm shocked. Are you saying that the documentation for open source projects is a little sparse sometimes.
Sometimes engineers are really excited to do documentation. They put a lot of time into it. And that's why, again, if you're not a coder, you come in and that's, that's a huge help As we think this through.
Do the maintainers want to be paid to make their software more secure? Or do they really just want somebody to come in and help them do it and kind of have somebody like they can call like a SWAT team and say, Hey, help me fix this thing and then thank you and go home. It, It's a combination.
Uh, the Lennox Foundation did a report, um, I think they re updated it in 2022 and they did maintainer survey. And there are thousands of different motivations. So some developers, absolutely, they would love to get a paycheck.
Some of them like work for a company like Intel, and they are already paid to do that work in open source. Um, but you have a lot of academics that are, maybe they're doing a, uh, doctoral dissertations, they put some software out there, or they're trying to solve a unique problem. But there's a lot of different motivations.
And from our perspective, like your SWAT team idea, one of the elements of the mobilization plan is the creation of an open source security incident response team that would exactly be that. If a maintainer has, is gets a vulnerability reported to their project and they don't know what to do, this group of experts would be there as a resource and maybe help them write the patch. Uh, definitely negotiate with the researcher, um, help with writing an advisory, helped getting the word out once the patch is available.
So again, we want to be sensitive to how that project wants to engage with us. And, you know, some people want funding, some people want consultation, some people just want a man page to look at. It's just we gotta accommodate all that.
Can I not just, you know, mobilize a small army of high school and college students to go work on this Stuff? Absolutely. And that's another part of the mobilization plan is I lead on our education sig.
And a big part of that is finding and creating content to help, uh, not only teach developers how to do things more securely, teach operators how to manage and control and operate environments like Kubernetes securely. Um, but also we wanna teach managers how to work with developers and open source. But then another significant area where we want to help improve education is historically underserved communities, our de and i efforts, and then also, um, high schoolers or people that want to upskill or reskill.
So maybe I'm not a developer today by trade, but maybe I, I think it's cool. Well, I don't know how to do that. We wanna provide all these different learning paths, the ability to get access to that information.
So that's exactly it. And a lot of our efforts are focused on trying to bring in that next generation, because I'm getting old and I'm not gonna do this forever. I need to have people kind of, I know that we're gonna take the flag and charge after I'm gone.
All right folks. You heard it here. The new motto for open source software is if you see something, say something, call him.
Right. Hey, thanks buddy. Thank you Mike.
And we'll be back in a minute.




