DJ Schleen, Yahoo | RSA Conference 2023
The use of third-party components in complex software has made it difficult for organizations to keep track of all external code, which poses significant risks. The Software Bill of Materials (SBOM) is a document or collection of documents that provides an inventory of all the components and dependencies in software. SBOMs can help identify security vulnerabilities, ensure compliance, and manage risks associated with third-party components. DaBOM is a podcast series that explores SBOMs’ potential solutions to the problem of transparency and traceability in software development, with industry experts discussing their experiences and opinions on SBOMs.
Transcript
This is texturing TV. Welcome back to rsac here in San Francisco 2023. Now all the interviews we do are are amazing.
We enjoy talking with great people some of them even stand out even more they've kind of friends and Friends of our community and I'm joined by one of those folks DJ schlane great. Welcome to have you here man. Thanks for having me.
I appreciate the opportunity to always always and DJ's well known in the industry with as a distinguished security architect right with yeah. All right with with Yahoo. Well introduce yourself tell people about yourself.
Oh, man. So DJ shalene. Yeah again, I'm a distinguished security architect with Yahoo, and a group called The paranoids.
We like to label our security organization like groups been around for years and I've always been interested in joining them. So last year the opportunity to join the team and take care of domain security architecture paranoid security architecture there and Have a long history of talking about devsecops devops for the last 10 years and have been involved the community doing a lot of talks reference architectures and just general guidance on on how to practically Implement these things. It's one thing to talk about the philosophy around devops or the philosophy around s bombs.
It's another thing to actually give guidance on like this is what you can tangently do to make this all happen how to do it and what you've learned from experience of doing especially at a large scale. Yeah a couple of that job. Yep, and you know that in the before that and some subsidiaries of United Healthcare, so spend a lot of time in health care industry trying to figure out how to you know, apply security inside of our cicd pipelines and then wanted to share that information.
We appreciate both sharing and and security. Well you do to talk earlier this week at the day devops connective SEC Ops conference at Tech strong holds About your talk a little bit of what we're discussing. It was a fun conversation.
It was fun. I always call talks conversations because it's like you're talking to the audience, right the people who are attending it was a talk called myths and realities of software bill of materials and I had been doing a lot of research and s-bombs going back almost 10 years actually 2014 is where this whole Story started and so the talk started off discussing that story about looking for Heartbleed back in the day and you know spending 24 hours straight trying to figure out where this was at our infrastructure sending a spreadsheets to people trying to get some information back. And of course all the spreadsheets came back completely empty.
So I thought at the time there has to be a better way from the supply chain. To understand where things are and if they're secure an odd or if they're vulnerabilities there and you know fast forward to today now, we have software bill of materials. We have more of a interest around inventory and what I wanted to do with the conference yesterday is have a talk.
Talking a little bit about the things that are right and the things that are misconceptions about software Bill materials. So give us a summary of both. I'd love to hear you.
I had to miss it because I was doing it other fun things with some other interviews. But yeah, give us a kind of a recap. Oh man.
Well, we're gonna be broadcasting these I believe in June so, you know whole time and we'll stay here in here. It's a link to register so you can see the whole thing. Absolutely and but you know a couple of myths one that really stands out is that I've heard a lot on my podcast of asked people about it.
There's this misconception that software composition analysis is just at F-bomb because you can find out components right and vulnerabilities, but it's more than that. There's versions of components. There's license information agpl GPL license stay away from it right file information, like you might have fonts and files and you know, if you look at C, it doesn't really have these third party components that you bring in so you have to have this inventory of the files and so try to dispel that myth a little bit.
And the other method is that you can't do anything with these right now because it's too early and the reality is your developers are probably generating these things already. But what we're missing is the application of the technology and we're starting to get there. We're doing some things right now to utilize different components to bring it to that together to come up with a strategy of how to deal with these so I shared a bit of that as well interesting you're hitting right on something.
I've thought a lot about which is Press bombs are great. But it's the start of something. It's not the end of something.
Yeah, absolutely. It's It solves a problem or it strives to solve a problem and have this. Communication of openness between a vendor and between a consumer products, you know, the government agencies that request them and a software vendors who are selling to the government.
That's a start of it. but there's a whole bunch of other issues around it that we're still trying to work out like are these There's privacy in there too. Like you might be exchanging Secret Sauce like this is how my software is composed.
You have it, right? So there's the same CIA Triad that we have to figure out, you know, confidentiality integrity and availability of these s bombs and how we deal with them and that's unfortunately right now contractual agreements when we start talking or Avengers because even thinking in some cases like job where you stop okay obvious skate code and okay, maybe a nest bomb is not going to be using formative all the time, right? It could be so like if you get an s bomb from your vendors and I think that's the number one place to start is if you're doing third party risk assessments get a software Bill materials from your vendor so that you can infer a lot of information from so you can say they're five versions behind on this component.
So we know the complexity of that component if there's a, you know, a zero day or some kind of vulnerability with that component, it's gonna take them a long period of time to actually remediate and respond to that issue if that's the case. Is that a risk that we want to take on as an organization purchasing that software. So there's things like that.
There's also the vulnerability information but really it's inventory meets security and I think that that's something that's gonna add value. It's just how we sort it out and how we communicate that value to different stakeholders. Another thing I wondered is do you think we can infer from what we see in the s bomb about the practices of an organization?
Like that example, maybe there's 10 of those right in their software. Not just one or you can kind of see the age and how up-to-date elements are that might be maybe you don't make final judgments about it. But I'd sure ask a lot more questions.
I saw some high-risk things and a lot of them. Absolutely. You know, you do a vulnerability scan on it.
You're only as good as your last vulnerability scan, but there's there's a format that can come out of an s-bombs known as vulnerability disclosure report and it's a kind of s bomb. It uses the same formats the same structure Cyclone DX, for example, you can has a structure that you can populate with it. When you get those vulnerability reports, if you have a freshness Arrangement, so your vendor creates a new version of an s bomb you have it you keep scanning it.
You can see the the drift and the improvement over time so you can see if you're addressing these issues, but you can also see if they're upgrading their software at the same time a lot of developers traditionally pin their software versions and there's an illusion of safety in real liability around that but if you're on the latest, you're no more secure than you are with attackers knowing, you know, the software five versions ago. So it's it's cat and mouse game. But yeah, you can definitely get a lot more information not just by receiving a s bomb but continuously receiving them and analyzing the the change over time.
Excellent. Well, we've been talking about s-bombs. Let's talk about the bomb the podcast here what's going on with that?
Oh, you know it's as part of as part of this journey tip for inventory and security. I got really interested in talking to people about it in the industry seeing what's happening and sharing that with listeners. I think it's really important to peel back the layers a little bit.
So I've been talking to Industry leaders from sisa. So Alan Friedman was on the show last week Shannon Leets the creator of the word devsecops. She was on the show us aired today actually and finding out their stories about You know the in the government's case that consists like what the guidance is why it came out talking to Steve springett about the format Cyclone DX and not just what it does.
But how did it even get here? What's the underlying story behind these things and I have a plethora of guests coming up that are talking about different aspects. Like how do I measure quality of these and then practitioners where you can talk with them and say what are you doing with these today?
I've been collecting espombs from vendors for years and it's been a very interesting journey and I want to find out how other people in the industry are dealing with that. So we don't know where the whole story is going with the bomb, but we do know that we're going to start peeling back the layers of the onion and really get to the the point where we're following this movement as it gets created and as it grows, Just knowing a little bit about you the kind of roles that you play. You know, how you think about problems what's sort of the next?
Problem out there that you're thinking about like, okay. This is what I want to start spending some time working on. Well right of the many of them I should say I think we all know that that problem is it's been all over the news lately.
It's called artificial intelligence and generative Ai and you know large language models. That's an interesting one because it almost was like an industry atomic bomb. Now when the World Wide Web came out.
And we started it was a slow growth right even mobile devices when they hit the iPhone came out in 2007. It was a slow growth to get applications on and you couldn't put applications on it right away. It was a very It took a lot of time to do it AI comes out and it's like bam now you can have things coded, you know for you.
Now, you can have the ability to take all the wealth of knowledge you have in an organization put it in one place and and have the ability to have a natural language question about it. So imagine having someone say How do I create a secure VPN between Microsoft Azure and gcp using the policies we have in our organization and it just coming out the answer. So I think it's gonna be a revolutionary technology.
And I think it's caught us all off guard. We're now we have to come up with a security policies and the practices and the procedures and the guidance of how to responsibly use this technology and not leak or intellectual property and not train a model out there. So all of a sudden they're competitors have our solution to a problem.
So That's I think gonna take a lot of my time up, but at the same time, you know s-bomb is a passion and some of the software that's coming out there. I spent some spare time with double our bomber which is sort of the name influence for the bomb, which is an open source software vulnerability scanner for S bombs. Very cool.
You know, it's in my theory about AI I did a little bit of work and Ai and ladys shows how old I am mostly a list from prologue and some really neural net stuff. And nothing like what we have today, but you know, even then Marvin Minsky's book Society of Mind was that was all that work. We're emulating human thinking and during my career.
There's times like okay is this it? They said was gonna happen then it hasn't quite yet. Okay.
We're seeing more expert systems. We're seeing machine learning. With large language models because I think of the ease and accessibility of it and you've got the compute the data and all the things that we can do with that and now it feels like okay.
This is it this is when a I really is taking a foot home it I think it is and we're gonna get to the point where and it's even happening with auto GPT and allowing AI Bots to execute code which is scary enough as it is right to be blasca, you know an AI. Bought to optimize Itself by 5% memory footprint and then continue doing that and all of a sudden it's going to start creating its code and compressing it. Like there's just when people talk about the singularity you always laugh you're like this is science fiction, right?
But More's law is already destroyed like it's not every year the technology doubles. It's pretty much every minute. It's gonna be every second.
Once you start getting some more of these Technologies, you know, these computers think 24 hours a day or can you know, we're sleeping eight hours a day and we're playing hopefully eight other hours today and then we're working eight hours. So the the eight hour rule These things don't sleep. It's injury intriguing things that people think of like is it yesterday?
I can't remember who told me about, you know, writing some code with chat GPT until it writes and python code and of course, it includes packages from libraries from whatever and saying well, I want you to write it without any dependencies. On your rights the whole thing. Oh, yeah.
Oh my gosh, you know what? What else can we do? I mean that's just a simple thing.
But you know the complexity of for me to go out and figure that would be a big project. You know think about some of the old technical debt or technical code that we have that you know. Joe left 15 years ago and he has this code that's been maintained here hasn't been maintained.
What does it do? Right you take that code throw that chat GPT and say explain what this does or we write it for? Yeah, exactly converted to another language, but it will tell you exactly what that code is meant to do and explain it enough that you could you know, as a developer coming in.
There's no more excuse that well, I don't understand that code. So I have to just completely rewrite it. You know, now there might be and I ability to leverage some of these things and improve them because we can instantly understand the context against all comes down to context.
I think this coming challenge you want to work on is already work. Yeah. It's it's taking up a lot of time lately and you know, the focus gets shift you might have some strategic initiatives that you have to work on and all of a sudden you get this, you know, new thing and I don't I think it's impressive that this just hit.
Everything and everybody's thinking about this. I definitely need to walk around the Expo floor here at RSA and see if people are thinking about it or if they're you know, the reaction time didn't hit yet to get it all yeah how they think we're gonna use it or maybe you know, they're not there yet. Well DJ it's been fantastic was to talk with you sure and check out the bomb the the podcast I assume it's on all the platforms and all the you name it good places Spotify.
It's on Amazon music audible. Of course Apple podcasts great and we look forward and I think it's June is when the depths devops connect the virtual version is going to be available. So that in a lot of other great folks speaking.
So check it out there. Thanks again. We'll be back with another great guest.
Okay, I can't promise as good as GJ, but almost maybe it's good.





