Security Creators Network, Software Supply Chain, CISA digs open source – Security Boulevard Chats EP 17
Mitch and Alan discuss rebranding the Security Creators Network; CISA brings a new focus to open source; and Alan’s interview with OpenSSF governing board member Brian Fox (Sonatype) from KubeCon + CloudNativeCon Europe 2024.
Transcript
Hi everyone, this is Mitch Ashley. And I'm Alan Shiel. And you're listening to Security Boulevard Chats Out on the Boulevard.
Out on the Boulevard, yeah. Security. We've been doing this podcasting on security.
Not Hollywood, not Hollywood Boulevard though, Mitch, not Hollywood. Oh, yeah. That's with Celluloid Heroes.
No, that's a different song. Different different song. Except for Lola.
Um, Lola. Oh my gosh. Yeah.
LOLA. Okay. Anyway, Mitch, we're back.
We, I know we, we took a week or two off there as we were both out in Paris, you, the week before CubeCon Me the week after CubeCon. So altogether was a few weeks off. But, you know, security stands still for Noah.
There's of course been a lot going on. You remember how we used to say, um, you know, I took some time off in hiatus because we were on hiatus and we used, we were thought we were in Hyannis, but that's Cape Cod. Exactly.
Um, we've said that before, haven't we? Yeah. I feel like we're doing borsch melt comedy here.
Like with any Youngman or something. Take some, uh, Uhhuh. Um, anyway, so Mitch, you know, we're gonna talk about a few things, but one thing I did wanna mention is like every three week period, I bet you look at, I don't know if this was a tough three weeks or not, but there were a whole bunch of big breaches Oh, absolutely.
That were announced over the last couple weeks. Absolutely. Um, I remember we were talking about Textron Gang.
Um, one of the B breaches was getting in the middle of the, the payments to doctors with the health, health and human services. And yeah. That was a basically coming up the entire works for, I dunno if it's the entire industry, but, you know, a lot of things were, were stopped dead in their tracks.
And what was also interesting to me about that is the hacker that had had involved in doing this had been present, uh, contributing to an open source project over a period of time, kind of about two years developing up trust and Yeah. Becoming part of the community, whoever this person was or not, or deep, deep plant. Yep.
Yep, exactly. And, uh, a sleeper cell. Yeah.
So, woke up, you know, and, uh, suddenly, uh, deploying some, some malicious code along with, uh, the rest of the open source software and poof, you got a problem. I mean, I, I'd love at some point to see a post from one of that. Was that his intent all along?
Or did something turn, as I think we mentioned on the, uh, on the Textron gang, did they break his programming? Like Dr. Y Yey, whatever, from Dune, Dr.
Dr. Yey, from Dune Dr. No Programming.
Yeah. I don't know what happened, but Yeah. That went wrong quick.
But, you know, yeah. Under Seeker Home, uh, that's right. Uh, home Depot though also had a, a big breach.
I think one of the, at banks, banks had a big breach at t had a huge breach. There's been, you know, it just, for as much money as we spend, and as much as we talk about it, as much resources, sometimes, you know, insecurity, you and I get it right with my security friends out there, we just feel like, like shoveling sand against the tide some days. Right.
It, it is, it is also interesting that, you know, we're at a time now where two days later, we're not talking about any one of those, uh, two days after it happened. Right. How many times have we talked about at and AT&T's breach since the first day or so?
Yep. Happening, you know, it just, they just kind of roll off. 'cause they just keep coming and they keep coming.
You know what, it's a politician's dream, right? It's a 48 hour cycle, and then, you know, you start fresh again. Yep.
Crazy. The message to, anyway, moving on from that, Mitch, you know, and speaking of all these breaches, so much of it has been focused on software supply chain security. Mm-Hmm.
And, and when we talk software, supply chain security, make no mistake, they're talking about open source Right. Software part of it. Right.
It's a big part of it. These open source components that go into so many of our apps today. And recently, you know, the federal government, well, certainly since Joe Biden's been president Mm-Hmm.
Uh, CSA has put a big magnifying lens on the open source security and not always with a favorable kind of review, if you will. Right? Mm-Hmm.
But, but recently they, the, the folks at CISA came out with, uh, some new guidance and some new instructions on open source. This is an article, federal support for open source Security and Security Boulevard there, right? Yeah.
And, um, they're announcing a new initiative. Mitch, I, I know you know a bit about it. Why don't you kind of fill us in?
Yeah. They held, I think it was a two day invite only summit where they brought leaders from open source community as well as federal folks to talk about what can we do to, how can we put things in place to help us create a more secure environment for open source software development. Which in, in and of itself is a recognition of we're not getting rid of open source.
It may be one of the ways, I mean, open source is an issue because it's so widely used in some cases that if it does get compromised, you know, a lot of things do. Right. We have have several instances of that recently, but it's just a recognition of we need to do something to help lift up the security of open source teams.
So they had, um, they got together, I think they had people from the Rust Foundation, pi, um, oh, they were also talking too, by the way, uh, Python. They're also talking about some of the, um, rep, not just repositories, but also build tools that were part of where you pull down libraries. You know, they call 'em different things in different environments, was a big part of it.
'cause that's how some of these things get distributed and the importance of SBOs and, you know, kind of see where this takes off. But they also talked about tabletop exer exercises and why that's important. So if you're on an open source project, that's just as important to do it there, as it would be in your own application development.
So I, it seems like a pretty healthy conversation would've been interesting to listen in on it. I would enjoy that. Well, yeah.
And I'm sure more details of it will be coming out as well. But you know what, frankly, look, the, uh, cooperation of the federal, especially the folks at the good folks at CIS a with the community, has, I think really accelerated. Mm-Hmm.
Um, and, you know, we see this in the open SSF, the Open Source Security Foundation part of Linux Foundation working a lot on the SBO m software, supply chain security issues. Um, we also, uh, are are seeing it, uh, in the EU too. It's not just CII will tell you, it may even be more advanced over in Europe.
Mm-Hmm. I had a chance at CubeCon to sit down with Brian Fox, who of course is the CTO and one of the co-founders at Sonatype. Mm-Hmm.
But beyond that, Brian is very, very involved in the open source, very plugged in security. Yeah. And he, you know, he's testified at, at some of these things.
And I believe he was at that csa, uh, meetup as well as talking to a lot of the EU folks. I had a chance to sit down with Brian in CubeCon in Paris. Mm-Hmm.
And, and talk a little bit about the role government plays here in helping us, uh, make open source more secure, helping us with the s bombs, uh, helping us with our software, supply chain security. And, um, there was a time where I'd say, you know, keep the government out of our hair with this. That was when I had hair.
Um, but I'm from the government. I'm here today here to help. I'm here to help.
Right. But I think increasingly we're seeing the government as, as a necessary partner in this equation. They have the ability to make things happen.
They, you know, they don't necessarily favor the big guy over the little guy or the little guy over the big guy. They're kind of a, you know, equalizer there. And, and I think between the US government and what they're doing with Csar and some of the other us, you know, office offices, as well as what's going on in the eu, who, you know, seem to have a greater will to get something done than we do, um, I'm hoping we'll make a dent, we'll make a difference in, in making open source more secure.
You know, they're, they're not there to pick winners and losers. Right. Like you have in a competitive environment.
There's certain things that government can do better, uh, and do well when it comes to bringing Mm-Hmm. Parties together trying to work on solutions. It doesn't always happen.
It doesn't always work out. But I think in the terms of, in terms of security and maybe to some degree software, we'll see, hopefully open source software becomes another great example whereby bringing contributors together from all factions of who both develop and use open source, we have a better, more secure approach to it, kind of inform and support projects to do secure development, create the most secure software they can. Agreed.
Now we're gonna play your interview. Are we gonna enlist? Yeah.
You, because that was really good. You know what? I think this is a good time.
Here's, here's our Brian Fox interview at Q Con on government and open source software. Hello everyone. We're back here, live in Paris on the show floor of a buzzing, buzzing cube con.
As I said earlier, they're expecting about 13,000 people. Wow. This year, this will be the largest cube con ever.
Um, and I, you know, just looking around the floor, you guys are shooting out. I don't know what people can see. 'cause some of it's blurred, but it's a very busy floor.
I'm joined here by my friend Brian Fox. If you don't know Brian, uh, CTO at Sonatype Co-founder. Yeah.
Co-founder CTO at Sonatype. I've been interviewing Brian for a long time. 10 years minute.
Yeah. Maybe more. Yeah.
Um, but beyond his role at sonotype, Brian's probably one of the most influential community involved folks in especially on the security side of things. Right. Uh, Sonotype is a, oh, you guys a platinum or Diamond sponsor?
Some high sponsor of Q cards, but Brian, personally, you're involved with OSSF. That's right. finops Enos.
We're, we're involved. Enos. Yep.
Uh, I'm a governing board member of the open SSF and number, number of the committees there as well. So we're gonna talk about Sona type, and we're gonna talk about CNCF, but let's, let's first talk about things like open SSF. And you are, you're a board member.
I mean, there's obviously business reasons why you want to be on the board, but Brian, with you, it's, it's a passion as well. Let, let's talk about, I don't mean to embarrass you, but let's talk about that, you know, for a bit. What, what drives you to be involved like that?
Yeah, I mean, you know, it's been since 2011 probably, that, that, uh, those of us at sonotype have been observing this problem with what everybody talks about now, supply chain security. Mm-Hmm. Um, and so we've been on a mission for how many years is that?
13, 14 years at this point. Yep. To try to help large organizations do a better job of managing their open source dependencies from a security and license compliance and architecture risk.
Uh, we know that, um, doing a good job on this can lead to better outcomes for the company, but also makes them much more efficient. You know, so many people think about it, it's a tax, I have to do this to make things more secure. But we know that that's actually not true.
That, that it unlocks productivity. But the market in general has been very resistant to change. And it's just human nature.
Yeah. And so, you know, uh, the last couple of years we've been involved with others at the open SSF working with the US government, with cisa, with ONCD, trying to help really, you know, elevate the message, spread the word, and help work with the regulators. You know, after SolarWinds and log for a shell.
Um, a lot of people sat up and paid attention. Unfortunately, not all of that attention was, was, um, focused in the right area. And so that's what I've been spending a lot of time trying to help shape that policy, help inform the legislators so that we get, you know, sensible legislation that helps us all be better, not punitive legislation that could really undo things.
Well, I, I remember speaking to you, I guess it was last year, you know, we're here in Paris and, and so we shouldn't focus on maybe just US regulatory, uh, challenges, but the EU Yeah. Generally is a, a step or two ahead. They, they have more of a, a will, if you will, to do something, but they don't necessarily, and I, and I, it's not the eu I think it's all politicians and, you know, I'm here, I'm from the government and I'm here to help kind of thing.
Yeah. Um, they, they don't really understand the issues. Yes.
Right. They, they have good intentions. Yes.
But the road to hell is, is lying with good intentions, Paids with good intentions, right? Yes. Yes.
Uh, yeah. It's true that the legislators in, in the EU have moved quickly with the Cyber Resiliency Act, the product liability directives, the AI Act, all of that, I think generally is good. Many of us spent the last year, 2023, trying to help shape, um, and, and frankly undo a little bit of what the CRA that was focused on, because it was, it was focused on potentially, uh, punishing the open source maintainers, holding them liable for things that were out of their control.
And that just comes down from the misunderstanding of, of the policy makers, like from a, from moving the industry forward, trying to hold vendors accountable. I think they were spot on. Right.
The problem was, you have no leverage over open source maintainers outside of your jurisdiction. You can't hold them responsible in the same way. And the danger was potentially that open source could opt out of Europe.
It sounds crazy, but people were saying it, people were asking us, for example, at Maven Central, the repo that we run, you know, could you, could you potentially stop our stuff from being downloaded inside of the eu? So it was a very serious thing that I think that the policymakers didn't understand at first, and it took a lot of effort to kind of course correct that. So we're, we're within the open SSF.
We have, uh, you know, we're building further relationships with those folks in Brussels this year to try to help educate that, you know, on the US side, ONCD and CSA have been very involved in the community. We've had many, many, um, summits. In fact, I was just that one two weeks ago with csa, where they convened all of the package repository folks together.
And many of the other leaders in, in prominent foundations, Apache Eclipse, uh, open, SSF, to talk about the problem, the sustainable funding challenge that we all face. Right. So I think on the US side, they're doing a great job of getting informed actual regulatory action is slow at the moment.
On the eu it's almost the opposite. And so we need to kind of smooth those things out, and I think we'll be in a good shape. Excellent.
Good stuff. Good. Good.
Uh, got a briefing right here from Ryan. Um, Brian, if you don't mind, let, let's focus, pivot over now to Sonatype specifically. Sure.
As you mentioned, Sonatype has been the maintainer maintainers of Maven Central for as long as I forever, I think there's been a Maven Central, right? Yeah. Um, and as such, you, you know, you've been at the forefront of, you want to call it DevSecOps, you want to call it now, software, supply chain security, um, of, of, you know, this whole movement, what's new?
Is there new, right. Because I think part of the issue is you keep fighting that same battle. You keep fighting on the same battlefield.
Yeah. Yeah. But there's new, So I think fronts open.
I think the new thing this year, and it's, it's not new to me really, but it's new to the rest of the market ish, is, you know, the whole push for SBOs, right? So SBOs, we, we, it was a means to an end for us 11 years ago when we were trying to help organizations. Most of them didn't know what was in their software.
Unfortunately, many of them still don't and are struggling with it. You know, on the US side, they've been pushing the SBO m software bill of materials. If you don't know, um, you know, it, it's required for many government sales.
The FDA will won't even begin to look at approval of a new device without an SBO M as of October, I think. Right. So, so there's a lot of talk pushing that, you know, the, the legislation in the EU references it as well.
So it's, it's a worldwide phenomenon, not just the us. And so, you know, what I've observed in just the last year, um, is a major pivot. So about a year ago, I went to some sessions.
Everybody was kind of grappling with, why are they making us do this? It's really hard to do this. We don't know how to do this.
All for reasons that they would never want to tell their customers things. Like, we don't have anybody that knows how to maintain that software. We, we don't track what's in it.
Right. Things that, that would, I get it. Consumers would be horrified about.
That was the conversation last year. This year, the conversation, um, is more focused on, okay, I need to produce SBOs. I'm, I need to ask for SBOs for my vendors.
Um, so they, they've moved from sort of that denial, anger into acceptance. But I think people are still struggling with, okay, now I have all these SBOs, what am I supposed to do with it? Right?
And so that's why yesterday we, we launched, um, the sonotype SBO M manager, which is a, a version of our platform, um, that is focused on people that are procuring software in organizations, um, from many different vendors. Um, and also trying to have a clearinghouse to be able to provide their SBOs, both from their first party software, but also from their third party stack dependencies downstream to their, their, uh, customers as well. Sure.
Right. So there's a number of new workflows and use cases that, that are, are coming into play. And it's interesting 'cause the scale of this is much larger than even we expected.
You know, we're, we're used to organizations managing, you know, tens of thousands of applications, which is, is a lot. But the biggest organizations, 10,000, 20,000 is fairly normal. We've had those same organizations talk to us about a need to manage millions of SBOs, uh, which is, which is quite shocking.
Which brings up the point I wanted to make to you, it all sounds copacetic, right? What a great idea. We need to do this.
I just wanna let this go. I'm not sure if this gets picked up in our mics, but that's loud. But the, the, sometimes the devil's in the details.
And, and you know, what I saw, I, this is coming out of RSA last year. It'll be interesting to see. What I see at RSA this year is sort of a tower of Babel.
Of SBOs, right? So compatibility of SBO formats, because if sonotype has their format and Company Z has their format, and Company X has their format, and this reminds me, remember when RSS feeds first came out? Yeah.
Right? 0 Adam, and, and all these different formats. And so if you had an RSS feeder, if you weren't able to read all the different RSS formats, you needed six different readers.
Yeah. Uh, until a company called Feet Burner, if you remember, feet Burner normalized. That's right.
The RSS feeds. Do we have anything that's gonna normalize the SBOs? Yeah, I mean, that's, that's a use case of, of our tool.
Um, but the, there's really two main standards for SBOs. It's SPDX, which is a Linux Foundation, uh, project. And then Cyclone dx, uh, which is, uh, an OAS project.
0. Sonatype contributed, the first security profile extension for it, for example. Um, because specifically I didn't wanna invent our own bespoke Right, um, uh, Protocol.
'cause that doesn't help The cause That's right. Doesn't help the cause. And so there's really just those two main, and I think, you know, everybody has, uh, uh, come to accept that at this point.
And pretty much, I think all the tools are both able to consume and emit, uh, the different SBO m formats. Uh, so it's a little bit of extra work, but, you know, it's, it's, it's sort of a solved problem at the moment for people. So I don't think you need to get too worried about that.
I don't see any other standards coming along anytime soon. Uh, you know, we're, we're well past that. I hope not.
Yeah. No, I, I, that, that's, that's good news. Um, look, we've begun almost this whole interview.
We haven't mentioned ai Ai. I was wondering when you were gonna ask, I have to, yeah. I, I say ai, we get like money or something.
I don't know. Um, what, what role is AI gonna have on SBOs and so forth? Oh, you know, it's interesting.
You know, the, the, the conversation around SBOs has sort of, uh, you know, uh, fragmented in a, in a sense, and people are talking about crypto bombs, cloud bombs, AI bombs, right? Because you need to be able to potentially document and disclose what models, what the training set went into the models, right? So I think the bill of materials concept is here to stay, and there's gonna be many different extensions for different areas.
Um, you know, we've, interestingly, we've seen many of our, uh, customers asking us to help them manage the AI usage within their products. So, and from my perspective, it looks very much like 10, 15 years ago in open source, where we would talk to policy makers and they would say, we have a policy against it. We're not using it.
And then you go and look at what's in their applications or talk to the developers, and it's open source is everywhere. Everywhere. Well, the same exact thing is happening with AI and LLMs right now.
Yes. So, about a month or so ago, we added some new capabilities to help detect, uh, and recognize LLM AI components, AI rest calls, and be able to surface those so that then the governance engine we have in our platform can help, uh, the policy folks Charge There kind of reason about it. So, so ai, um, you know, is, is getting into the applications in a fairly large way that many people don't realize.
You know, I think the, the AI aspects of the whole industry will certainly help. Uh, the generative AI parts can help, um, you know, with some of the SBOs, you know, filling out descriptions that are rational. It's really good at those things.
You know, if you have a component, but you're not sure what the category is or what, how to describe it in the sbo m uh, you, you can use AI techniques to be able to, to help massage some of those things. Same thing in terms of trying to interpret it. So I think it's gonna be, you know, secretly underneath the hood in both the generative, you know, the, the export and the import of these different formats as, as we're sort of, you know, hanging around the periphery of the formats and, and what the humans can do.
Love it. Brian, we're about outta time. com.
That's right. org. Yeah.
Yep. I mean, we, we, we didn't touch on the, the state of the software supply chain report. That's an enduring one.
Um, When's that Coming in? October This year is the 10th year. That's right.
It's gonna be huge. And, you know, a lot of the research that we've done over the last 10 years is still completely relevant. Uh, you know, we tend to take a different look at the industry every year.
Um, so we're gonna be going back and looking at a lot of those key findings and trying to update them trends and summarize them. Um, you know, so the team's already hard at work on that. Very cool.
Um, trying to, trying to get that updated. com/sscr. Uh, so We'll see you at, at RSA.
That's Right. We'll see you at the open source summit coming up. I wanna say June in Seattle, is it?
Or April in Seattle? Uh, there's one in June. There's also one in a couple of weeks.
Uh, April in Seattle. In Seattle. Think we're gonna be, uh, That's right.
What are we doing here? I'm gonna be everywhere. I'm going to Dev Nexus.
I'm going to, uh, v calling. Yeah. I, no, you would tell you're great.
I, you know, God bless you. That's right. I picked my spots.
That's right. But anyway, Brian, thanks for what you do for the whole community and continued success with Sonatype. Thank you.
You know, Mitchell, I've known Brian for a bunch of years now and Mm-Hmm. What's funny is I wind up talking to him about non sonar type stuff, more than I talked to him about sonar type, to tell you the truth. But he is, he's really passionate.
He's a real advocate for open source security. And, uh, he is, he's made so many contributions, you know, directly and also through the organizations that he's a part of. So good stuff there.
One of the good ones definitely Great by the next. Yep. Thank you.
And, and again, all of our interviews from CubeCon are up at Techstrong tv. You did quite a bunch. I did some, Mike Ard did some and, uh, highly, highly recommend going to check them out.
Mitch, I wanna turn our focus, if you will, to RSA, um, just round the corner. I announced. Yep.
I announced something, uh, a couple days ago. You know, we started the Security Bloggers Network and then the security bloggers meetup. I guess it was 2004 or 2005.
Yeah. So 20 years ago. Yeah.
And for many, many years it was the best party for us and people like us at RSA. Right. Wednesday night, it was the peak of the week.
Peak of the week, yeah. Wednesday night, chill out, have a nice drink, meet with friends, marketing free zone. Mm-Hmm.
The last couple years with Covid it was harder and finding a venue to do it. And our good friend Anthony Freed, you know, where whichever company he was with, he tried to made available to US Space. Mm-Hmm.
But it was different. We were kind of sharing it and all that. So this year we, we announced the, uh, meetup is gonna be at the Tonga room, like Tonga Con.
Right. Which isn't happening this year. So we're gonna try to incorporate some of the Tonga Con stuff too.
Uh, but again, it's Wednesday night and, uh, there is an e uh, an Evite, not Evite an Eventbrite page where you can register for the party. You must register. You can't just walk in.
It's not that it costs money or anything, but we need to keep a control on things. Um, but along with that, though, we've changed the name of the security bloggers network to the Security Creators Network. Interesting.
Yep. And you know what, Mitchell, I'll give credit. This was Rich Mogul's idea a couple years ago, Billy.
I didn't realize that came from him. Yeah. Came from Rich.
Um, what was interesting is we saw, um, people don't blog like they did in 2003 and four and five. Right. It's also become more corporate and a lot of other things too.
It's not, well, the security bloggers now 'cause 350 plus blogs. A lot of them are corporate. Mm-Hmm.
Um, but that being said, just because they don't necessarily blog doesn't mean we don't create security themed content. Right. There's more security content than ever, whether it's in podcasts or videos or tiktoks or, or Twitter or, you know, people working for security companies who create eBooks and white papers and position papers, and people who write about security, whether it's from our friends at Cyber Risk Alliance or Tech Target, you know, Kelly and her team at Dark Reading and, and here at Security Boulevard and the bloggers network and everything.
So, and the other driving thing there, Mitchell, was increasingly over the last couple years, especially with covid, we have our core group of, of folks that we've been doing this party with all these years. Mm-Hmm. And it's great seeing them.
It is. But I feel like raising a glass and saying, here's to us and those like us damn few left. Yeah.
Another one lost in the war where, where's Joe? Well, no, some of them have retired and they don't do RSA anymore. Mm-Hmm.
Others, unfortunately are not here anymore. Yeah. Right.
We just, I think yesterday was, uh, well by the time this reads last week, by the time this place was a one, I think the one year anniversary, maybe it's two years of, of Mike Murray. Mike Murray. Yeah.
You know, passing away. And, and that was a kind of hole in the heart. Mike was a great guy, and I still don't understand the whole thing.
But anyway, we've lost a lot of really good people. Mm-Hmm. At the same time, the security community has grown so much, and it's time for fresh blood.
So a lot of great people have come along. For sure. Yeah.
No, and, you know, so I reached out to the folks at the Security Cybersecurity Marketing Society, not because I want marketing at the Security Creators Network. I really don't. I've spoken to Jennifer Gio on this, and, you know, she was, she wanted to make sure we kept our principles, which is this is a no marketing zone.
Right. And I, I almost really, I wasn't sure what to do because it is the cybersecurity marketing Mm-Hmm. Society.
But Gianna and the team there understand that this is a no marketing zone. This isn't about marketing. Right.
But we need Mitchell, we need fresh blood running this event. We need fresh blood in the security creators network. We need to embrace the change that's going on.
Mm-Hmm. I'm not opening membership to ai. Not yet.
Not yet. Anyway. We're gonna have their own society, I guess they can.
Right. Um, but that being said, I do wanna open the books to folks who are creating content around security. They're welcome here.
We want to have you here and we want you to come down and, and party. So say a little bit more, um, about, so if you're someone who's doing this, creating content like this or doing, you know, 'cause these the kind of folks we want to draw in, how would you describe that? Well, I think they are contributors to cybersecurity sites.
I mentioned a bunch of them. Mm-Hmm. I think they are people who podcast or vidcast or whatever it's called.
Uh, people who do go on TikTok and TWI or X or YouTube. Or YouTube. YouTube shorts.
Yeah. Or they just create security content as part of their everyday job. They're writing product marketing, a marketing material perhaps for the cybersecurity, you know, market.
If you create security con or security themed content, you're welcome. Thinking about giving presentations at conferences. Right.
You're pulling together content speakers at conferences for sure. Sure. For sure.
For sure. For sure. Workshops with people.
Right. You don't have to be a educators product person. Yep.
You don't have to be a product person. You're creating security related content. But again, no marketing zone, no sales.
We're here to talk cyber catch up form, friendships, form networking, support each other. And, and that's what this is about. Mm-Hmm.
Great. So continue to build community. Right?
That's what Yep. And I, I encourage, I encourage anyone listening to this who's at RSA, who fits that, go register for this. We'll try to put the Eventbrite, uh, address in, in the notes.
Um, also, we, we need sponsors for this, right? It mm-Hmm. This little hullabaloo will wind up costing every bit of $25,000.
Yeah. Not you. We need four or five sponsors to help defray the cost there.
So if you're listening to this and your company can sponsor, we'd love to have you. And again, it is a marketing free zone, but we'll, we'll give you a chance to say hello. We'll have your banner.
There's good will. No people appreciate it. Yep.
There's a lot of goodwill in this. And it, and it's, uh, look just from our core group, it's a pretty who's who of security, so, Mm-Hmm. Really excited with that.
Well, good. Really fantastic. Excited.
If people don't know about the Security Bloggers network, you can find that on Security Boulevard, which it became the home kind of for it. So I would imagine five years ago, the Security Creators Network is gonna continuous. Well, I think we've already changed the name over.
Oh, we did. Okay. Great.
Yes, we changed the name and the branding over to Creator's Network. Okay. Um, but staying on RSA for a second, Mitch, just a reminder that Monday of RSA week, you and Mark Miller will be hosting Mm-Hmm.
Our eighth or ninth annual DevOps Connect DevSecOps event. As I mentioned earlier. Uh, David Brin will be keynoting it, but we have an all-star lineup of, of speakers there.
And you're doing a panel. Mm-Hmm. With some leadership, AI and DevOps and Dev SecOps and Dev SecOps.
We have people, we have security leaders from Google Open ai, Microsoft, uh, who else? Tropic philanthropic. Exactly.
We, we have deepminds, which is I guess part of Google. Mm-Hmm. And a bunch more.
You can go check it out on the RSA site or I think if you go to Techstrong events, we probably have a, a lead in page for it there as well. Um, and not just Guy, there's a lot of innovators that are, that are speaking there. So I think folks will get a lot out of it.
By the way, we'll also be doing, uh, we'll be live at broadcast Alley all week streaming live interviews there. You can check us out. Come by and say hello.
I'm excited for RSA this year. Mitch Moscone West. Yeah.
It's, I kind of get the feeling last year was a lot better as things were coming back. Oh, yeah. I kind of feeling is gonna be the, maybe we're back kind of at RSA.
Well, I, you know, I spoke to Cecilia who, uh, Mar Ye who runs the Sandbox programs Mm-Hmm. Innovation programs. And she wouldn't commit to a number, but she said they're very, very happy with registrations.
Okay. At this point, I'm not gonna say that it isn't up there. Yep.
We'll, we'll see how it goes. Anyway, there's a Long Security boulevard today, Mitch, with the interview and everything, but I think it was a good one. It was a fantastic one.
And, uh, we appreciate people hanging with us while we were hanging out in hey hiatus for a few weeks there and coming back on and getting on the podcast with you all. So we appreciate you listening. Be sure and check out our other Textron, uh, podcasts that we have.
We have everything from AI and DevOps and a number of great topics. com and tell your friends about Security Boulevard. A lot of folks have listened to us over the years, and we appreciate everybody hanging with us and being a part of this conversation.
So, with that, shall we wrap it up? Wrap it up. Mitch, this has been Mitch Ashley and Alan Cheval, and you've been listening to another security chat on the Boulevard Security Boulevard Chats.
There we go.