AppSec Today with Sam Quakenbush and Loreli Cadapan | RSA Conference 2023
AppSec Today live from RSAC 2023, San Francisco: Sam Quakenbush and Loreli Cadapan join Mitch at RSAC to discuss the challenges of incorporating security into software development.
Transcript
This is texturung TV. Hey, welcome everybody. We are at rsac 2023 here in San Francisco.
This is a special segment that we're doing from broadcast alley. This is actually an episode of our show apsec today where we're talking about absec apps application security and it's great that we're doing this at rsac because absec is part of the security conversations, especially this year, which is what we're gonna talk about. io men, the men team works with tech strong put together topics and guests and how we're gonna put this show together.
So it's been a privilege working with men and we appreciate them being a sponsor of the show and is thought leaders they invite guests both practitioners and all people from other technology companies, which is a little bit of what our panel is made up of today. So thank you for being part of this and I'm excited to bring up this topic. So first let's do some introductions.
I'll let you each talk about yourself and your companies Sam. Do you want to start introduce yourself and tell us about men? Thanks.
So I'm Sam quake and Bush. I'm the senior director of field Innovation strategy at and IO what men does is we help the largest most complex organizations in the world solve their application security problems, and we do it with automation. Automation, okay.
That's a great start good good top again and of itself, thanks. Great lore line. I'm Lorelai.
I'm head of product at activestate and a minute Active safe for about a year and a half. But you know really I am a developer at heart started my career as a developer at active State we build technology for securing your software supply chain focusing on open source again, open source, very good. Awesome.
Well what I want to start out the topic with is I'm kind of shocked that the number of conversations. I've had. I know when I talk to you I'm going to talk about supply chain security.
I know you were gonna talk about absec so folks that I know I'm gonna have those conversations with this great. I'm surprised at how many people But I'm not saying it's the whole show is about accent but RSA it's part of the conversation and I've been wondering when is this going to happen? When are we gonna be talking seriously about software Security app security supply chain.
So hey, do you agree with that premise and why do you think that's happening? So you're your closest so you're the first first victim. Yes, it started Laura.
I do agree, especially in the last couple years with the cyber security attacks really starting to really become more up and you know front and center and even impacting the government for example getting into the sensitive data the government. I think the government is now also starting to catch on and putting in a lot of standards in place. So I think it's also from a software provider responsibility.
We need to take that to heart ensure that the consumers of the software that we're building. Secure and we're protecting the community as well and the consumers so I do agree that it has become more prevalent as a topic. interesting So for me, it's it's wild because I've been in absec what feels like forever but I would it's like it's always been the topic of mine but I would say definitely you're right on with the government right s-bomb s bomb is like top of mind for everyone because it's a mandate now, right?
So that's a part of application security and then I would say supply chain as much as I hate to say it for sure has pushed that to the Forefront because people are like, what are we building everything with and you know the bill of materials we have to give out. What if we upgrade into something malicious? Yeah, but improving Security in anything isn't one vector, right?
It's how you designed it how you supply it how you operate and build it what you put around it. There's so many aspects to it. It seems like one of the things we've been missing for the security teams is just know how to talk to developers.
Yeah, how to talk to software teams. I mean who wants to go to a software team and say I am from security? I'm here to help.
I don't know anything about what you do, but I'm here to tell you what you're supposed to do. Nobody likes to do that. I think we've seems like we've we've opened up the Lexicon that's bombs.
This one part of it. Everybody kind of gets that idea from manufacturing. It's not too hard to to learn.
What do you think the other things that are maybe it's regulation what's forcing that conversations? The forest is the right word. Maybe maybe that's two two pushy of over.
Yeah, I think that's the that's a difficult one right where Security Forces on and I think the at least the way that I approach it in the last, you know time I've been an app state is giving developers the information they need instead of making them wait for security right giving it to them. Like while they're coding like in a pull request right if they have that security information in a pull request. And they look at it there versus waiting doing a build and then some tool like blocking them.
That's that's not the way to go about it. It's really, you know, shifting security all the way to the left side. And then like what you said to your point empowering developers before they even commit codes.
Being able to know that the information getting the information that they need to make sure that they are using the right libraries for example, or the latest version of the library and so forth and I think also to your to your question about like why why now, right and I think the you have seen in the last year for example, the executive order mandate and the OMB really setting that for on the government agencies as well and in this standard and software secure secure software development framework, you know, in addition to your s bombs or there's also establishing that trust between the software provider and the consumer and that's about you know, your software attestation. How was your software built, you know the province of your software providing that in a testing to that and then I think the third one is also following a secure software development framework. Going down and starting establishing those four points of that ssdf, you know securing an establishing the organization preparing the organization for you know, roles and responsibilities tools and processes securing your software.
That's all about really the systems layer and the traceability of where you're getting all of your dependencies and how you're putting them into your software ensuring that you're delivering your software. That's secure. There's no vulnerabilities and then I think last but not least of course is the, you know, being proactive being able to remediate the vulnerabilities as they come risk management is so forth.
So a lot of those are starting to Bubble Up really and we're also seeing it from our customers and there's like, well I need this. How do you know, how can you help us secure our software so I think a lot of that is also coming from top down now as rather than you know, just yeah, okay. We need to secure our software.
We ultimately it's all about customers. Right? I mean you can show up with a great product and there's I don't know why we need that.
But what are you hearing from customers? What are they struggling with say, how do we do this? So I don't know if customers are struck at that say everyone's always struggles a little bit staying up to date like people don't start off developing with old dependencies, right?
It's just it's the constant never-ending staying up to date which the single best thing you can do is basically stay up to date with your open source libraries. And there's there's definitely free tools out there that you know, get up provides. We provide one.
I would say it's like this single best thing you can do. It's just get a reminder to stay up to date like a pull request. Hey, there's a new version out there.
Like that's definitely what customers I see struggle with. You know, it's interesting you both mentioned. I think you both mentioned kind of the pull request and one way to have introduce things into into a workflow or processes to be part of the process not necessarily.
Drastically change it. There's a complete new way. We're gonna do this now.
You don't do polka requests anymore. It's this and this is how you get scanned before anything ever happens or whatever but fitting into that development flow. I think it's a real adaptation adoption.
Plus if we can kind of not add to the cognitive load of developers and say yeah shifting left just doesn't mean we're piling more stuff on your plate or it's now your job, but it's not the security team's job. How do we do that? How do we make this?
Hopefully it's effortless as possible for the developers, but still accomplished with what we want to do. I mean does anyone ever like deny the windows patch or you know on your computer anymore that used to be a problem back in the day? That's true.
Maybe I want to wait till tonight, but that's the most exactly everyone everyone maintains and stays up to date with their you know their patches. That's the same thing for software development. That's what we have to do with our open source dependencies.
And you know providing the tools I think and the Integrations to be able to do that seamlessly for developers whether that's on the IDE whether that's in you know, like the pull requests are you know, depend the bot for example providing those resources for developers so that they don't have to think about it right or even having a for example a Walled Garden of you know, what dependencies can I pull in that is secure that's all we're already vetted out with a curated list of you know, dependencies or catalog that you can use. So I've seen also, you know companies really establishing those and asking for those where they need a curated list of dependencies. For example, I'm actually not a fan of the golden repo approach like oh let's let's have one single Source where everything's safe.
It's It's difficult to do it. If it's time consuming versus like just responsibly using open source, right and using tools to help make sure you're using secure ones that are out there versus trying to have like this Clearing House of okay, we've vetted all these you're good to go for any organ to do that. That's it's a lot of work.
That's it. Yeah now we're not in the manufacturing because we're in this repo. What were you exactly variations of what you all do is it is easier said than done and it does add some friction to developers where they wanted to deliver a fast.
and you know being proactive about it with certain tools and so forth because you can never really that's not the bullet. I don't think that's the Silver Bullet either. It's because you know you there's the day Zero vulnerabilities for example that you know, you won't know today, but maybe you'll you will in the future.
So yeah. What do you think? So if there's in the software world live talk about esplanes just starting point.
I just had to conversation with DJ slan who's talking who's talks a lot about s-bombs and he's got a whole podcast about it. And it's a starting point, right? It isn't the answer.
It isn't the okay. Now, we're secure we got it. That's fine.
Right? No you have is a digital something that says this is what our majority of have assets look like. How do we put that into action if you if what do you do with an s-bomb?
Hopefully have more than one you have one every time software changes, right? What's what do you steps you take to take advantage of the fact, you've got a process that generates it. You've asked a really really good question.
I think that's like the next that's the next question, right? Okay, you have the espan. What do you do with it?
How do you you know, how do you validate it? You know, what do you do to give you more information to that yourself for secure and I think that's definitely something that we're all trying to figure out. I have some ideas, you know, you've got your list of bill of materials, you know things that you can start looking into is of course does it, you know does each of your dependencies or open source dependencies, for example, are they compliant from a licensing perspective?
What are the vulnerabilities that are maybe attacking those specific versions of your dependencies and things like that. So I think those are some that can help the organization. I have more visibility about what your software is made of.
So I actually don't think esbomb is. Helpful for what it is what it does is actually just causes people to take a look. I mean if you think about like building a house what we're saying is an s-bomb is okay.
Now, we're gonna look at the materials that are used to build the house. But having a list of that doesn't make sure the house is built properly. Yeah, it could still have a really crappily build house.
Well, it does is make sure that you're like, oh well now that I have to provide this list, maybe we'll take a closer look at how we're building the house. Yeah, so I think esbomb and its current state is It's compliance. Right?
Like there's there's nothing super useful other than it's causing people to have attention on it, which is good in the overall thing. It's a start in that you have to know what you have in security world. What's the first thing you do take an inventory?
What do we have? Right. What are we trying to predict in a way?
It's that first step. Oh, yeah. What do we have?
Okay, that doesn't tell you what to do or how to protect her how to make it better the same thing in the software world, that's fine, right? We as an industry need to come together though on S bombs and like decide what format we all well as PDX versus Cyclone DX or Vex or what's the new hotness next week? We've only abilities in your ass bomb and we really need to come together and just like stick to one and say all right.
This is what we're all gonna decide. You're Sam's ready to like. Okay, let's quick.
Let's get to the next thing right exactly. I don't believe me there too. I'm there, too.
What what are the conversations you wish we were having at RSA now that at least app second and that's bombs and and open source security. Those things are topic of conversation. Where do we need to take the conversation next with?
security and software partners If you if you could wave your wand and your magic and say I wish I wish we were talking about this. This is the next thing for us to work on. Maybe it's working on what we do with that spots.
Yeah exactly. What do we do with them? I mean for me like the conversation he's I haven't having and I still have it is I think a lot of people getting an alert fatigue right at least people that are finally getting into abstract.
They're like, wow, there's a lot of alerts. These aren't really vulnerabilities. These are just suggestions on what may become a vulnerability.
I wish we were having more of a conversation as an industry on how we can focus You know, like I said, the easiest thing you do is stay up to date, right? It just gets rid of a lot of alerts. I mean when log for J happened Even though log4j was a big deal.
A lot of people weren't actually exploitable, but there was like this ciso mandate updated no matter what Yeah, I was definitely I guess it's an overreactions like we don't know what it is. So make sure you do blah. Yes.
Well, we spend a lot of effort certainly people had to do some people had to do that. But I think it was more of the we don't know just think could be everywhere. Yeah, it was but it wasn't right.
It's big So when you say alert fatigue That's a chronic condition for any sock right and people trying about AI being part of the solution also kind of Taken observability approach where you can do more data analytics to tie context together to alert. So when you're presented with something, you're not trying to figure out what the puzzle looks like, right you're giving some kind of path towards that but is that the kind of thing you're talking about helping you're you're beyond that if you think about like app SEC like grammar, right like grammar or spell check you're like, okay. Should I make sure that I fix all those red squigglies?
That's how I compare abstract. Right? Like if you're doing grammar.
Well, then everything will be good. But if You're if you're poorly structuring your sentences and paragraphs. You're not gonna have a good great paper.
So. You just need a case follow those good coding practices. It is it's following those good coding practices and also establishing a process for when something thus occur because we can never have a hundred percent Silver Bullet, you know, oh this will be securing a little always be a secure software.
And so how do we establish processes and tools such that we can act on it at a good, you know, a reasonable time frame is I think also something that we all could work together. I think that the theme for for RSA is what is it together Better Together farther together Better Together? Yeah, exactly.
So, how can we as an you know? as a responsible organization help every single, you know developer out there in an Empower them all the way up to the organizational level and like shifting that security responsibility or honest not on the open source developer, but really shifting it on the companies that are building the software that are selling the software is I think you know, how do you how do you Put that you know, how do you make sure that mentally that that's something that we all are thinking about? Take ownership of take ownership.
Yeah, what do you thinking about? Yeah, you brought you brought up Ai, and I'm like well as hopefully if AI is generating code for us. It's generating secure code.
So that'll be better. We hope I mean, I've played around with GitHub copilot versus Chad GPT and I'll be honest most of stuff that comes out of there. It's using open source code.
It's usually pretty good. It's interesting. Um, I did a thought experience.
Somebody told me about this the thought experiment where I had a generate some code to do some actions. And of course I want to use whatever libraries to do, you know requests include that just python. Said okay now rewrite it with no dependencies.
And see what it actually the road executable code. I mean it worked. So not that you're gonna say replace all my open source.
Oh no. Yeah. She generated code.
Yes, you can do that if you want. Good luck. Yeah, you're gonna be dead debugging that for a while, but it is an interesting thought to say.
Um is generative code maybe one of the tools that we say kind of replaces or augments code scanning right running through a generative code. Generate and say look for the vulnerabilities security errors in this code. Pointed at a lot of insecure code and it'll know it'll know what yeah.
Yeah. So hey, so AI. I mean you think there's other what other roles I mean, obviously the the alert fatigue is one that AI can play a role in and reducing.
You know all the nonsense, you know and putting context around the things that we need to see right? I think it'll be exciting to see what people do with AI and helping them prioritize. Like I think we've all like beat the cbss score to death like oh fix all those criticals fix all those highs, right?
Yeah critical for us, but we'll fix it because they're right exactly. I think it'll be interesting to see what people do with AI and hopefully find better ways to prioritize vulnerabilities or alerts. Interesting.
What how do you think Howard developers accept the focus on app security is this help much needed help. We've been we've been asking for tools and asking for people to kind of focus on this with this or is it still at that? Okay, it's more work or you're slowing me down.
You know, those are the first two criterias is something good or bad if it's more work or slow me down. It's always bad or usually we're developer. How is the acceptance and adoption from developer Community going?
Yeah, I think it's a it's a company the company thing depending on the culture of the company for sure like the companies that I see they're like being really successful are the ones that treat vulnerabilities or alerts, you know from security tools as bugs if you just treat it as a bug and work it into the same sprint. That's a great culture versus like, okay. Well, we're gonna have a whole Sprint.
We're just gonna devote it to security alerts. That's um doesn't usually work out. Well, no and usually those get shortened because we got other stuff.
Finally. We're gonna take a whole week. No, it's an hour.
Yeah, like okay fix it. Yeah. Absolutely.
I mean, I think it does add friction to a developer's, you know, day-to-day work because they just wanted to deliver fast. I've seen in my password developers realize that the version of an open source that they're using is older there's a newer version but they're afraid to update it because down the line in your cicd process. It may break whether that's functional, you know, testing and so forth.
So they're afraid of that right? So, how do we you know, how do we make it such that? They get you get that easier faster feedback loop.
And give them the confidence that yeah, I'll be able to upgrade this version before I go ahead and commit and there are definitely waste of doing that but it is like you to your to your point. It's something it depends on every organization and whether there's a process or tooling around that I'm smiling because since you brought it out, I'm gonna shamelessly plug a free tool that we provide children innovate. Yeah.
Yeah. Absolutely. I mean there's dependabot but renovate is absolutely out there and free and it provides you pull requests to stay up to date so well if you're saying that I'm gonna Active State salsa doing the same thing.
That's great. But that means we're onto something. Hey.
Free tools that allow people to stay up to date or get things done. Fantastic. Yeah, so I'm gonna ask you both for a parting thought before we wrap up so heads up so you can be thinking about it one of the things so I'm I wish list if I had a wish list of tool maybe there's something that does this.
I wish we would apply AI analytics to an upgrade to any piece of software that can tell us how serious is this going to be when I apply it to my code, you know my code, you know this open source project or this this new release of something. Is this a big deal or is this a probably going to flow through our ci/cd pipeline send it to your point with pretty low friction. I think that'd be a great day because then we can push things through we know what we're gonna need to spend time working on or have a pretty good idea.
Let's set the time to do the bigger projects so or like your party thought Yeah, my parting thought I do see a potential in having that incorporated into your network the AI and I think that is the next step to look into. and to speed up the process of developing software faster, right but secure Great, Sam. I mean this kind of bleeds into the functional testing space, right if we all just wrote better code they had more functional tests.
We could do that, but hopefully AI helps us, you know. Do something along those lines? All right, very cool.
Well, thank you both. Thank you to men as always for being a great partner putting the show together and and supporting a a cross tech company conversation. Yeah, I think that's the true sign of thought leaders that are like, let's get us together and talk about this stuff because we're all doing interesting things and maybe we're together we can figure out a few things good stuff Sam.
Thank you very much. Great lower life to be here with you. Again.
Thank you everybody for joining us for this episode of abstract today. com and of course check out our good friends that men that IO and our guest from active State as well. Thank you.
We'll be back with some more great interviews come in right away. So don't go anywhere.





