Transitioning to AppSec and Tackling API Security with Mend’s Chris Lindsey at RSA Conference 2024
Chris Lindsey, a former developer turned application security evangelist at Mend.io, discusses his transition and the importance of proactive security measures in today’s fast-paced development landscape, particularly focusing on API security challenges. With insights drawn from his experience in healthcare systems, Lindsay emphasizes the need for developers to understand and implement secure coding practices, highlighting Mend’s approach of seamlessly integrating security testing into the development pipeline. Through education, collaboration, and tool integration, Mend aims to empower developers to build secure applications while minimizing friction in their workflow.
Transcript
This is Textron tv. Hi, everybody. Mitch Ashley here at RSAC 2024 in San Francisco.
The great pleasure of being joined by Chris Lindsay, who is, uh, application security evangelist. Mm-Hmm. With men.
Welcome to the evangelist world. I know that's a recent, fairly recent change for you, so, Yes. Thank you, Mitch.
Thank you. How's it going? How's it going?
Stepping out in front of the code instead of behind the code? Well, you know, after 35 years of just being heads down, just, you know, keeping your head, you know, under, you know, in the sand, you know, it, it's, it's refreshing to be out, you know, in the sun and getting some vitamin D and getting the chance to actually go around and talk about, you know, good security practices and things. What, what, what was it about this role that you said, that's what I would like to do next?
How, how did you make that change? Well, It was actually easy for me because a lot of the projects that I've been part of for years and years have been projects where you have to really be absolutely secure a medication prescribing system, think about the different things if the data could get stolen, and, you know, the different aspects, medications, diagnosis, allergies, I mean, all this stuff it, right? Yeah.
You know, and, and, and before, so most of the work I've done over the years have always been kind of in healthcare. So security's always been in the forefront the last three years when, uh, leading up, well, I've been at men for two years, but leading up to that for three years, I ran a program at a very large enterprise where I put it all together from scratch. Mm-Hmm.
And it was very successful. And the thing that I found was, when I was building the program, I didn't have anybody to go reach out to. I, I didn't know any communities.
And I looked, I looked around to see, Hey, how, where should I, what should I be thinking about? And so really I just kind of changed it and said, okay, I'm a developer at heart. What would I need to know, like for APIs for all the different things that are out there, SQL injection, which I'm already aware of long before the tools, you know, what kind of things could, you know, should I implement?
And so I started putting together the security wheel, and after I, I, I brought in MEND as one of my vendors. And you know, you always have that one day where you're just like, yeah, I think I'm, I'm ready for a change. Mm-Hmm.
I, uh, I reached out to Mend and, and I came over and, and I worked with their post-sales and helping so many customers learn and, and, and use our system. But beyond that, I would always talk about what are you doing in your program that's helping or not helping you? And I would always throw my advice out.
Hmm. And so it was one of those things where I realized there, there was a need and a job opening came up with in the company where they're like, Hey, we're looking for an evangelist. And I'm like, pick me.
Pick me. I'd like to step forward. You, you know, we all think about technology moving at such a vast space, especially with ai, that kind of accelerating things as well.
Do you see, since you were doing the job day to day Mm-Hmm. Your transition to this, do you see, oh, there's lots of new challenges and problems, or sometimes it's kind of just a lot of the same things people or other people have been struggling with maybe that you had to address, uh, in your role and now you could help them with an evangelist? Is it more one than the other?
Actually, it's both. Both, okay. I mean, yeah, when you look at it, you have your day-to-day problems if your developers, and one of the things I talk about frequently is education and training for your developers.
If they're not writing secure software, the problem becomes, they're just gonna keep adding more and more security debt to the projects that they're working on. You can have all the tools in the world that say, Hey, you've got more and more, you know, vulnerabilities that you're writing. But if your developers don't understand that they're creating vulnerabilities, they're just gonna keep creating them.
Mm-Hmm. And one of the things that I, I also, in the last couple years, I speak at VIP dinners with a lot of CISOs. And a question that I would frequently ask is, technology is rapidly advancing.
And then, this was actually before the AI came out, the AI train. It was Already, It was already in motion, but, but publicly, it, it hadn't really kind of come out to the surface like it has today. And I would always ask the question, technology's moving so fast, and you have these kids, I call it the Minecraft generation, because these kids will sit there and just hack and hack on these blocks trying to build something.
And now these kids are going, Hey, look, I can break into something. I can do something. And they're starting to put the pieces together.
And so your script kitties are starting to become a little bit more advanced. Or you look at the technologies, I could do a ransomware as a service or, you know, entry as a service or brute force as a service. And so now if I really wanted to break into somewhere, I could easily do it.
So I'd always ask the CISOs or the VIPs, what are you doing to try to combat that? Mm-Hmm. And it would always be funny 'cause everybody would be silent.
And I'm like, okay, no recordings going on here. And then it's not A test. We're Not a test.
I mean, but once you started talking about it, it was obvious that there was a need. And what, today, yesterday at the panel, we, we, I, we, I brought it up, but you have AI ethical hacking tools, and the question becomes what makes it ethical? Because a hack is a hack, doesn't matter.
And, you know, I joked about, you know, top Gun Maverick, you know, how good is the plane? It doesn't matter. It's the pilot in the box.
Mm-Hmm. And in this case, it's the guy at the keyboard. Are they ethical?
Are they not? Or are they kind of in the gray area? What's The intent and what's the outcome?
Right. Yeah, Absolutely. Absolutely.
But it, you know, it, I think back just a year or two, we weren't really, I've always been waiting, when are we gonna start talking about AppSec Mm-Hmm. And software security at RSAC instead of the course, the, the big, uh, kind of sea of, of network security. And that seemed to about a couple of years ago, especially last year, you really saw the tide turn Mm-Hmm.
In, in terms of, not everyone was talking about it, but it was part of the conversation. Did you see much difference between the last year and this year? Has it accelerated?
Oh, absolutely. People are starting to actually understand that security matters. You know, when you start looking at APIs, APIs, you can have all these tools to kind of help you, but the reality is, it kind of goes back if you're a multi-tenant system, for those who don't know that, that means multi, like your bank account.
I log in, you log in, we have different accounts, different data. But if you're not coding it properly, I could go in and take, you know, and and run a query, a nice request package in there and get a nice response with your data. If, if I put, you know, if you're not coding it right, there's Not much in there.
So you won't, won't help you on Mike now Mine either. So we're in good hands. We're in good hands.
But the thing is, is with security, you're hearing more and more of breaches. And when you start looking at why were they breached and how were they breached, API is one of the primary reasons why people are losing their data. And I can tell you from a lot of companies that I've talked to, and I've just, you know, in general conversations around here, people aren't properly logging where the requests are coming from on the medication system At telemetry.
Right? Absolutely. Absolutely.
If, if, you know that someone should be logging in from Georgia and they are logged in from Georgia, but somebody logs in from California 30 minutes later, it's not Star Trek, we don't have transporters. So Yeah. Different Bruce.
Yeah. Yeah. It's, it's gotta be, Talk a little bit about, um, you know, no, no developer comes to work and says, I'm gonna write some security vulnerabilities today.
You know, I'm just feeling a little saucy. Uh, so, you know, it's, that isn't done by intention. I mean, developers are asked to do a lot under a lot of pressure, a lot of short deadlines, and sometimes it's don't know.
I didn't know I was doing that. Right. I didn't know there's a more secure way to do that.
Other times it's just, you know, kind of doing a lot of things that, uh, very quickly, why are APIs, what, what is it about APIs and API security, um, that is either tricky or maybe kind of easy to miss things, kinda how do you look at that? Why, why is that? I mean, I know it's a big volume of our track, right?
So it's a great attack surface for the bad guys, right? But is it, I mean, why isn't it easy to, to secure APIs? Well, I mean, I call it notepad inheritance, right?
You find a method, I, I need to create a new method. I, I I need to create a new put or a new get, or a new something. And so I just go, oh, well, there's a method already that has, you know, similar thing.
I just copy it and I paste it and do a little modification, and I'm up and running and good. Right? Now the problem is, is when I did that copy and paste, did I grab something that was secured or insecure?
Now all of a sudden I'm saying, Hey, I have one vulnerability, you know, a method that's all vulnerable with five or six things. And now I've just replicated that across the board. And so one of the, you know, that, that's one of 'em, one of the aspects, but the other aspect that really plays into it, and, and I really, I, I, I have David Noss to, uh, to blame for this.
Um, but when we were writing APIs way back in the early two thousands, early, early, early on with soap, we always, always validated every aspect of the request that came in. And if you have a method that exceeded, let's say I have a, a, uh, input that's 15 characters, but let's say I have something greater than 15 characters, most people today go, oh, well, I'll just truncate it at 15. So it gets into the database.
Can't be any bad stuff in that 15. Absolutely. I mean, the UI doesn't allow more than 15, I don't know.
So Like, gastric from, you know, whatever. Right. So, you know, really when you're looking at it, the validation step is usually Skift or overlooked.
And even the AI tools today, you can go and ask, Hey, go create all these test cases for me. And they will, but they still don't include all the security pieces down to that layer or that level that really matter. If you have something that exceeds that 15 characters, guess what?
Somebody did, a man in the middle, somebody did something malicious, log it, throw it out. Don't try to fix it, throw it away because it's just not right. Very cool.
Yeah. It, it is just like anything that you're right. Well, especially today, APIs are so, it isn't just that there's a lot of traffic.
They're very prevalent in our applications. They aren't the kind of the how hard outer shell that control the few things that go in and out. It's how we build apps, right, right.
For services, et cetera. So tell us a little bit of what's happening at mend, what's kind of cool things that, that you're working on and, and maybe that's happening here at RSAC that is interesting to people that are working on AppSec. Yeah, we're, we're doing amazing things.
Um, RSEA, we're one of the older ones that have been out for a long time, which also makes us a lot more mature. We have the ability to scale at unprecedented levels. I mean, massive.
We, we can take a repository with over a million, you know, and it's just crazy plus. And, you know, you look at what we're doing in sast and the level and granularity and the things that we're able to do there and, and the speed and the performance. But a lot of this actually lives within GitHub or Bitbucket or the different environment.
So when you get the results, when you check in your code, it kicks off the scans, but you don't have to leave that environment. It's, it's where the developers are. And one of the biggest things, and I'll kind of go down a little bit of a, a hole if that's okay.
Sure. But I was on a panel once where I was, the panel was asked, Hey, we have a pipeline in the build pipeline, we have our security, we have a hot fix that needs to go out the door. Is it okay to bypass security?
And the three people prior to me said, no, you have to go through security. It has to be there. And it gets to me, and I think you've already kind of known me or you guys a little bit.
Absolutely. You can bypass it in the pipeline, but you need to kick it off when you commit the code into the repository, because now you're running parallel, you're running asynchronously, that scans running, you're going through qa, you got the build, you're going through qa, and then it re gets back together and you can say, Hey, you know, I didn't have to wait that 45 minutes for security run or whatever. I have the results.
We know we're good. We can go to production. Or we know what we're, what we have as far as vulnerabilities go.
And so we can make that decision. Is the risk worth it? You know, depending on what it is, and then go forward.
Great. And we're doing amazing things in container and, and other areas. There's a lot of cool stuff that we're getting ready to, you know, talk about.
I can't talk about it today, but a lot of really amazing stuff. I don't know if I get the folks here to tackle you. Maybe we'll get a little bit of that.
Yeah, yeah. Absolutely. Absolutely.
You know, it, it, it's, it's interesting because APIs are so prevalent and it's very easy to copy code. It's very easy to, of course you can write it from scratch and maybe you do or don't make mistakes in it. Um, but because of the quantity that we're using you, the friction of applying a security tool or process to the work that developers are doing, you know, they're famous for saying, eh, that's, that's getting in my way.
Exactly. That's getting in my way. I'm not doing that.
Or I'll find a way around that 'cause I gotta get my stuff done. So I would imagine that experience of being in market, working in, in the CICD pipeline, you know, doing all the security testing, you know, you're not, you're, you're still there for a reason, right? Yes.
Yes. If you haven't been kicked out by the developers. Absolutely.
Absolutely. Well, and, and it goes back to if the developers understand how to write good, clean, secure code, now your tools become kinda like a regression test. Here's what your, your your, your vulnerability or your, your thread or your risk tolerance.
You know, here's where you stand as far as a risk goes. Now you can make decisions based on that. If you're going in, if you're a security team.
And I actually had this early on, uh, with one of the groups that I worked with. We had somebody on our security team that wasn't a developer and, and let me, all security teams should have a developer on staff. Definitely for the AppSec.
Yeah. Yeah. Because the guy on this team was like, there's this finding it's massive and we need to stop the presses.
And I looked at it, it was a command execution, which is critical, but it's on a console application. Mm-Hmm. Well you're already at the terminal or the command prompt or the PowerShell, it doesn't matter.
You're already on the box. You're technically compromised on the box 'cause you're there. We had a problem before we got to that issue.
Exactly. Now if it's web-based, we need another conversation. Mm-Hmm.
Very good. Well, um, Chris, thank you for, uh, to mend and to you for sponsoring and being part of DevSecOps Connect. Yesterday on Monday, we had a great crowd, over a thousand people coming in to hear about DevSecOps and DevOps and AI and the impact and a lot of the work that's being done across the board.
I mean, many aspects of it. We had pretty wide ranging discussion. So yeah.
Appreciate men and you being part of that, it was a great success. Thank You. I, I appreciate the invite and it was a great time and met a lot of great people.
Very good. Well, Chris Lindsay, who is a, uh, application security evangelist, the right person to talk to, 'cause you know, he is walked several miles into the shoes of an application developer and security testing and making sure you're releasing secure codes. So be sure to check out Mend and, uh, we look forward to talking with you again.
Awesome. Thank you Chris. Lindsay, thank you very much.
We'll be back with another fantastic interview just like this one.