A Conversation with Liz Rice, Chief Open Source Officer at Isovalent – Tech.Strong.Women EP 15
In this episode of Tech. Strong. Women., hosts Jodi Ashley and Tracy Ragan talk with Liz Rice, chief open source officer at Isovalent, about extended Berkeley Packet Filter (eBPF) and its impact on the open source ecosystem and observability, the challenges open source developers face with the upcoming Cyber Resilience Act legislation and the significant impact AI has on open source. Rice will discuss how AI opens up numerous opportunities for further automation and optimization of open source development, integration and delivery all along the SDLC. Finally, Rice explores how the modern remote, work-from-anywhere technology landscape will empower more women and underrepresented groups to pursue tech careers.
Transcript
Hi everybody. Thanks for joining us for another episode of tech strong women where we feature amazing women doing amazing things in Tech. I'm Jody Ashley executive producer here at Tech strong, and I'm here with my co-host Tracy Reagan.
Creator and CEO of deploy Hub. And you know in her free time, she's busy working with the Linux Foundation where she sits on the boards of the open ssf and the CDF technical oversight committee. Sounds like fun.
Before I introduced today's guests. I want to give you a quick update about what's happening here at techstrom. Be sure to register for Textron con 2023 virtual event on March 16th speaker submissions are still open and we always love sponsors.
Tech strong will also be hosting our annual devops connect devsecops day at rsac in San Francisco on April 24th, and be sure to look for us on broadcast alley all week where we'll be live streaming stop by and say hi. com and be sure to tune in every day to Tech strong TV for great shows and interviews. Hey Tracy, what's on your mind today?
Well Jody, you know. First of all, it's going to be here and I'm really excited for today's guests. Liz rice is amazing and she's in the security space and it's timely because you know, we talked about a few months back probably early in the show.
We talked about the Biden administration's requirement for submitting software bill of materials or S bombs with your software. If you're doing business with the US government, which by the way is a very reasonable request even though many companies May struggle with it. It is a reasonable request.
I we've always been waiting for the other shooter drop and in this past week, we heard it did so now we have the European cyber resiliency Act. I've read through it. It's not as straightforward as an executive order that says hey s bombs are needed.
It's far more detailed and I have few some concerns about the open source community and how the open source Community are is going to comply with some of the requirements and it does have a list of the kinds of software that they're going to be worried about. So it may not apply to all open source tools or open source packages. But anyway, it's out there and people should be aware of what Europe is doing now to help Safeguard European software and what gets installed in European environments around security.
So the starting to get heated up this discussion around security and software security and supply chain security when it comes to software is is getting pretty real and I'm hoping that we can get some insights from Liz on this. Awesome. All right, well.
Tracy already, let the cat out of the bag. That's right, Liz. I'm gonna let you tell us what you're doing what you're up to and and just give us an introduction about you.
So, okay. Well Festival thanks for having me. My name is Liz rice.
My job title is Chief open source officer with ISO valence and I surveillance is the company that originally created the cilium project which is now part of the cncf. And it's based on ebpf which is a technology that I'm super excited about. So, I'm just Tracy mentioned.
I'm been involved in sort of security side of things for quite a while. We can use evpf for some really interesting security related things. And as we recording I'm kind of preparing for the cloud native security conference, which is next week probably.
A week or two ago by the time you actually see the recording but yes, so things like supply chain is I am absolutely confident is going to be a huge topic of conversation there and I think bbpf will be as well. So what's your thoughts on this cybersecurity resilience? Oh, yeah.
Say impact open source. Should we be worried? Yeah, so actually another role I have another hat that I wear I'm on the board of an organization called open UK, which is all about using open technology open source, open Hardware data more in society and a big part of that is related to policy.
Now. I'm you know a lawyer I'm a technologist but I get to hear, you know, some of the opinions of people who much more kind of knowledgeable in that area than I am and I know Amanda Brock who's the CEO on of open UK was talking about how at least in an early draft of that at there was or there appear to be some confusion about the if you if you release open source software, you're releasing it into the wild and letting people use it, but you're not going to take liability for it. Nobody's going to take liability unless there's some kind of commercial Arrangement and I think that at least in the earlier draft from what I understood.
It was kind of confusing that. You know the liability that you know open source project is going to be able to take responsibility for you know, or liability for something. That's an open source piece of code.
So yeah, I think that might still need to be ironed out. I'm not sure. It drives down deeper into even commercial packages who are using open source packages because now the commercial packages they're gonna basically be saying they're going to take liability for the open source packages that they're consuming.
It isn't that right. How did I don't think that's awful in the sense that whoever is the commercial company who's going to take that liability on and they're gonna have to decide what you know, what risk that involves and whether they're being paid enough to take that risk. They get to choose whether they're using open source components or not.
They I think it will help to encourage good practice because although no open source project in its right mind will take liability. That doesn't mean that they can't do good practices and that they can't have things like software better material. So things like the cncf is really encouraging projects to incorporate more of these dependency management practices and s-bombs and and All this good stuff that is coming up.
Now the tooling that we're starting to have around. tracking your dependencies open source projects can do that and you know that I think that's a very good thing and then commercial projects that depend on them can can make decisions about you know, okay, does it have you know and open ssf? Scorecard.
Yes the school card project. Yeah, the openness escort. Yeah, so I think things like that will help commercial projects understand the kind of risk.
They might be taking, you know, I kind of feel like, you know, we're the open ssf. We really have to get our our ducks in a row or geese in a row. That's it.
But it's gonna take us a while to build out these practices and I just hope that open source will still be consumed because I think it's a you know, open sources taken us a very long way and look kubernetes is open source, we're going to sakes. So how do we you know, it's gonna be interesting over the next and safe three years and how we're navigating it and the impact that open source will have with these new with these new acts and you know, we still have other regions China is certainly to follow And you know what what they're going to say. So it just makes it scarier and scarier to use external unknown code.
And that is that describes open source, especially packages, you know, maybe not tools, you know, like We have an artilliest project that manages and consumes s bombs. We have kubernetes. Those may not be as Jenkins other tools backstage.
There's all kinds of great kind of devops tooling that you use to build out your software, but what you're delivering and the packages it's being included in it. I feel like we're going to see an impact in the in the future in terms of Commercial Code that is being, you know, we're talking about cots space basically that we were that we're selling to other companies an entire package, especially if you're selling into your European market, That there's going to be a concern about and putting open source in there. So maybe there's going to be a lot more work for coding or tools like co-pilot where you take Snippets.
Right. Yeah, I think it's good. Is it gonna be a disruption there just is the worst outcome and I barely even want to say this idea around but the worst outcome would be like Not necessarily just copilot.
I don't want to point the finger at any given implementation but AI generated software that creates a commercial variant of something that's essentially copied from the open source project and that that would be Awful, I think how will AI in general affect. Open source. I mean, I'm not an expert, but I'm All the stuff that's going on right now.
It's aiai. Does this AI does that? It scares me.
Waiting is how like at a superficial level. It can be really quite accurate, you know, you can read these amazing. That's what's articles you think.
Wow. That's 90% right, but it's the 10% that's wrong. That's Dangerous and that's I mean that's got to be true in code as well.
Right? We're gonna see we're gonna see more code. Automation tools, I don't know what you want to call it more code like more more solutions like co-pilot.
You know, we just started hearing about what does it chat GPT you that's all I'm getting. Do you want to talk about this? Do you want to talk about a chat chat chat.
That's all we're getting bombarded with on my end right now and it's like wow scary. Not you know not my answer would be not necessarily. I think it's a very interesting application for AI.
Will we be able to see through it soon enough? Yeah, we'll learn humans are good at pattern matching too professors will be able to go. Oh, yeah, that that's definitely not written by the student.
I know better. So I think that we'll see through that I certainly won't it just evolve. Every time I think we're seeing through it.
It's like that there was a big thing this week about a university. Was it Wharton and somebody used it to write a paper and the paper was great, but they said that the the English used in it was so perfect. You could tell that is that it was fake information was great, but the grammar was so spot on there like yeah, no human wrote this no human wrote it right especially now, they're gonna throw in Dumb words and you know, though, you know, it's been a big topic of conversation in my household in general.
Well, I think in the coding World we're going to see something similar but what I believe what what I foresee happening are tools like I get I'll just keep bringing in a co-pilot where instead of having open source packages that we're consuming. They're going to have those modules that they've now have absorbed and they are pushing forward and they're going to have the ownership of that now so co-pilot will have the licensing for that under some I don't know how it licensed the code but it's generating code just like chat whatever it is GPT or whatever it is. And I and I think that was that at the same time at all to cross the ultimate source market in terms of consumable packages like hey Trace, let's stop for a sec because you're Mike went out.
Yeah. We can kind of hear you but you sound like you're in the other room. I think you moved in it much.
I got excited and I know so back and start your thought over and we'll get it edited. No big deal. Okay.
So what when we talk about things like code generation, what's what I believe will happen is that these packages that are commonly used that people consume as an open source will be included in the code generation. so they no longer will be coming from an open source library that you pull from some some location some some repository and that is how we're going to address things like the Cyber the Cyber resiliency act because then the company will consume will that's sending out the software will be the producers of it even though they used a Something that's generating code. I think it's going to be some really interesting intellectual property discussions and cases where you know, if AI didn't make everything up completely from scratch, you know, it's Learned by looking at other code and you know, I've I've seen some if I use evpf as an example.
I've seen some little paragraphs of text about ebpf that people have generated, you know in at work, you know kind of for fun, you know, like let's see what it says about. And you can recognize some of the phrases you can see that this is exactly what we say. We've said this phrase over and over and over again and the AI has picked it up and you know, maybe that's not quite our intellectual property, but there's going to be some point where you know, copilot or an alternative Is it infringing other people's copyright by you know regurgitating?
Lines of code algorithms whatever, you know, whatever whatever level we want to think about that. You know, sometimes if you look at other people's got a bit, like you said, you know, you can spot when somebody's copied an essay or if it wasn't there work. Yeah, we kind of start seeing AI generated code.
That's really just infringing other people's copyright. I would say yes. No, yes, must be real income stream for years.
Yeah, we'll see we will see well done. The bigger question is let's take a pool to see when the first lawsuit happens and it is going it is going to disrupt the software developer though. We are starting to see a shift in everybody's not coding writing every single line of code.
And that's why open source has been so popular and as these kinds of tools become more more accepted, I think that the role of the software developer has will be will change we'll get good at putting together the pieces like a Lego set And at the same time, you know. That might be good for women who are at home working from home. Street competing have women working from home back in the early days.
So yeah. Yeah and and not a lot of women go and take software classes. They don't take they don't they don't take programming classes.
I think it's less than 10% in most universities of women in it taking software classes and learning to code. However, they may very well be able to pick up. Fairly quickly from a junior level, you know to your program coding and be able to use these tools and maybe the industry will shift and more women will become part of it because they want a job that they can do from home and raise their kids.
It's kind of like when I was a kid my neighbor. Her mother worked from home and I thought it was the coolest thing but she was a she typed like 130 words a minute and she sat with the headphones on and she typed up all at one doctor's notes for the entire day and somebody would deliver his his notes and his recordings and she would sit in tight and I thought it was awesome because mom was there all the time right and she could get up do laundry cook for us do whatever she needed to do to be a mom and she still had a job and I always thought that was just amazing. So that will happen for women when my kids were little.
Yeah. I absolutely did that but it but technology evolved the job. I was doing away it started out by driving to a truck and picking up documents to to enter every day and I stayed home with my two kids then the documents became a CD.
We'd pick up a CD and then it became an online. enter situation where we'd pull it up and we'd enter from the document and then it went away because the system could scan and recognize it all and they didn't need us at all that happened over about a five-year period but I did that from home so I could stay home with my kids till they were school age. Exactly and I think a lot of women want to do that.
when I was a kid when I was kind of learning to type and yeah, I did learn to time upon a typewriter and my my mum was a psychiatrist and she actually had me typing up her not some you know, and which I really enjoyed because I was typing and you know but it was I don't know how many times I must have and she specialized in old people as well. So I must have typed the word dementia. thousands of times and it turned out I was spelling it wrong.
I spent spelled it t u r e at the end like thousands of people. I heard the word I just assumed that was almost that's it. So that's on the typewriter right?
So, how did you go from a teen spelling? Dementia wrong to software? Did you did you take a seat computer science in college?
I actually took Engineering in college, but I was already really into computers before I did that. you know we had Said x 18 this tiny little 1K Ram machine just did basic and when we first got it, I was a bit disappointed because what I really wanted was like a video game and this computer arrived and I thought I'll make the most of it and then I talked myself programming and that was it and I I always knew I was gonna work with computers. So I didn't want to do computer science as a degree just because the engineering course look more interesting and a bit broader that was quite interested in things like Electronics as well, and and I wanted to be quite practical but so there was an element of Programming and logic and things in my degree, but it wasn't a computer science degree.
Yeah, I wanted to build cars. All right. Yeah, and my mother said what are you gonna move to Detroit?
And then I was in California. It was like maybe that's not the best career for me. It was like don't they build cars in California?
She's like all the big companies are in Detroit. So I I changed a business math and most of that was computer stuff. Okay.
Yeah, but engineering was what I was interested in. so Detroit was where the last kubecon was and I thought it was actually a really great place. I you know, it was really welcoming.
I was only there for like, you know a few days but and it was definitely and It had a variety of different neighborhoods. Let's say but you know given how negative a lot of people had been beforehand like actually, you know, this is nice. This is a lot of people have been incredibly welcoming.
I'm glad to hear that, you know, it's probably going through a Revival a CSC used to be in Detroit. They were one of those big tall buildings. So they had a technology sector that they were slowly kind of trying to bring around before.
The late I guess it was probably 1990s early 2000s where they really started going through. It's pretty heavy recession. Hmm.
So after you have time don't times but so yeah it was It was I thought as a visitor it was it was a good place to visit. Yeah, our team really enjoyed it as well Tech strong had a Had a group there doing video and and they really had a good time as well good. So let's tell us about Cube content.
Was there anything really cool that you learned or anything that you want to share? Oh trying to remember. What was what was big back then that was in November.
Yeah, so long ago another year. So one of the things that was really fun for me was and so silly in Project has been you know growing we hit the button on a PR to apply for graduation. So that'll be a massive step and we had our first ever and kind of in-person community meeting because pandemic, we haven't been able to do it really before and it we honestly didn't know how many people would show up to this project meeting because you know, it's it was one of the pre pre-event days.
We didn't know how many people would be in town and there's loads of these co-located events. And we put up a sign-up sheet and there wasn't a huge amount of activity on the sign up sheets. We thought well worst case, you know this quite a few maintainers here and we'll Get on with some work or something will be will be fine.
And then people just kept arriving and showing up and we had like a packed room. We had to keep going and getting more chairs, which was Brilliant, you know seeing people wanting to get but some of them came with like I've got this particular issue. I really want to you know, get into the nitty-gritty of or other people who are just like I absolutely was interesting.
Can you tell me what it is? You know, so it's really great. Why don't you do that for us?
Because I'm not sure that the we've really clarified the project that you're working on. Yeah, sure. And it's incubating at the cncf it is.
Yeah, and it is based on this technology called ebpf which we can come to in a minute and it is really observability networking and security for Cloud native not necessarily even just kubernetes. Although the vast majority of people are using it in kubernetes environments, but we do have some people using it and things like Standalone load balances replacing some like physical boxes for load balances and yet The Amazing Power of it is really based on ebpf Which is this technology that allows you to run? programs within the kernel so you can hook into different events, which could be things like a network packet arriving and different points in the network stack and you can change the behavior of the kernel when these events occur, so you can do things like get a network packet and modify it and send it somewhere else so we can use it in psyllium to do things like bypass some parts of the network stack that aren't necessary for cloud native networking.
So it makes performance better. We can do things like Network policy. So very efficiently in the kernel checking whether or not a given Network packet or connection is In or out of policy and if it's not in policy, but just throw it away doesn't happen.
It's a super powerful and really interesting because you get into the kind of Nitty Gritty of the kernel and and you know, how is this networking stat really working and things like that? So yeah, I'm finally really fascinating. Well when you talk about code that's that deep in the stack open source code that deep in the stack.
I have to go back to I wonder how the Cyber resiliency Act is going to impact that level of code. I hope that when you figure that out, you're you're the attorney that you're that you guys might work with or somebody could write a blog on it because that's the kind of stuff I'm talking about. You know, how is that going to be impacted?
Because I'm sure that that's going to be in the list. I think one of the list everybody is running everybody. So many people are so many organizations are running on Linux, you know Linux is like, yes now maybe they're buying it all through, you know distributions like red hat so that somebody is taking some liability.
But yeah it you know, It's big and complicated piece of code. Exactly and you know with a you know with kind of This Global recession receipt at generally when we see a recession the use of Open Source Code spikes. When we are flush with cash people are going out and buying commercial things.
But as soon as they are cutting their budgets, they start relying on open source. So we have this we have three kind of this intersection of three things that are impacting our industry right now one is this potential of Open Source being consumed more because of the recession two, people are moving to kubernetes and a microservices environment and three. We have a problem with our open source here all happening at the same time.
It is a very impactful time and it's a very interesting time to be in software especially on open source projects. Do you think this, you know, the perception of security, you know, what's happened is a lot of these problems have come to life. It's not like there are new security.
Well, they're all need security from but an awful lot of them have been around for a long time. They've just been discovered just being realized we have it's a security Awakening. Yes.
Yes exactly. So I wouldn't want people to sort of think. Oh, you know because people are using open source things have become less secure.
I think actually the opposite is true because there is more kind of a light being shown on those projects and there are more people's eyes on that code. It's just that we've got a lot more awareness now of When security I mean a decade ago people lost your data, they didn't really even have to tell you about it. Whereas now it's you know, it's a big deal.
They really have to tell you when it was your date. You know, I think things like the CRA and the Biden administration's esperan requirements their guidelines. They are, you know, the guardrails and we should have been looking at doing these things quite some time ago, but There wasn't before the security Awakening before log for jail.
Let's just make it clear. Nobody really cared to talk about it security was sort of like testing, you know, it's like yeah, we'll get to it. It's true.
I think testers have always been forgotten Heroes and security people are the same way, but now we've gotten some light to the problem and you know when you put shine light on a problem, we generally get it solved. It's just going to take us a while. So you said before we get oh, go ahead Trace.
No, go ahead. I was gonna say before we get too far along because we're gonna be winding up shortly. I want to hear some more about your new book.
Yeah, so I mentioned about ebpf and how I am fascinated. Right and I have been writing a book about it. It's called learning ebpf it is really a dive into kind of How you can get started with evpf programming.
It's really? I am a huge believer in seeing something concrete, you know writing some code making something happen in order to understand what you know what it's based on. I'm not.
Someone who learns very well from looking at you know boxes and lines. I want to see code and I want to see what happens. So using kind of starting from a hello world going through lots of different examples.
I'm hoping to convey some of the power of what ebpf is and if people do want to write their own program. I think not that many people will really need to write their own evpf code. But if they want to explore it, they might find they really want to get involved and great and even if they just go I'm just doing this so I can understand it even better.
What's the name? And when will it be released? Yes, so it's the title is learning evpf.
It's coming out through O'Reilly. They're the publisher. com.
And then the full book has just gone into production. So literally I've been looking at copy editors sort of changing the font on different terms and so on you're down to the really fun part. Yeah, we're getting really close now and the hope is that it will be out.
Yeah, it was originally scheduled to be in June but we're well ahead of schedule. I think it'll be out probably in March maybe April and I'm really hoping we're gonna get physical copies that we can give away at cubecon in Amsterdam That's my kind of dream and winners keep calm and when is that? It's the middle of April.
I think Cuban in Amsterdam. Yeah. Yeah coupon and Amsterdam is it's the week the week before RSA and that's why I know so it's the week of the 10th, I believe that no, I'm sorry the 17th of the 21st.
Because our team's going over there and then they're flying straight from Amsterdam to San Francisco. Yeah for RSA. So yeah, it's gonna be a busy time.
I'm only going to RSA. So yeah. But yeah, that's gonna be fun.
I'm guessing you'll be there Liz so you got to look for look for Alan and Mike bazard and our oh you're gonna be over there in Amsterdam doing live streaming, I believe so that'll be fun. Yeah. Yeah good.
I think it'll be a really fun event. Sounds great City. And yeah, it's always it's always good to see the, you know the community.
It's I am a little bit conscious that travel budgets have been cut. So maybe won't be quite as busy as previous years, but I still think you know, it's the event in Cloud native really. So yeah hoping to catch up with lots of people there.
Yeah, it should be a lot of fun. Absolutely. I don't think I'll be there but I wish everybody a good time.
You make it to the Chicago one then later in the year. I don't know, you know, keep cons really big and for what we do. It's probably you know, we're just like a blip, you know, so it's a little too big for what we're doing and you know, we're part of the CD Foundation the open source project.
So I'm going to be at women in Silicon Valley that week but my partner will be at the cdcon and a few of our committers will be at cdcon. So that's what we really focus on is cdcon. Generally we would have gone to the function next week.
I think it is next week it is. Yeah. Yeah, but we're just conscious of travel.
We're a small startup. We don't can't go to everything. Yeah.
Well, Mike Liz said with the economy. It's not going to be covid that keeps people from traveling. It's gonna be budgets and interested about of traveling traveling is not has not been fun.
And at least in the US in the last six months been really it's been challenging. It'll be easier to drive. Well, I have I'm not gonna have to drive all the way from London to Seattle.
That would yeah it back on boats, right? That would be a Langer. I am thinking of seriously considering cycling from London to Amsterdam though for keep on so interesting.
Yeah. It's a little bit of logistics to sort of horror is that And depends where you catch the ferry because you do have to catch a fairy to get across the sea. Really.
Yeah. But I am looking a route that is probably only a total of about 150 miles on land and then 1560 and then an overnight Ferry there's a considerably longer route with a considerably shorter or considerably longer riding but considerably sure to Ferry Crossing. So you have to decide whether you want to do the long Rider the short right?
Yeah, it's more of a case of how long I'm gonna take over it and there's questions of things like how I'm gonna get my luggage though. One of my colleagues has volunteers to take a bag so actually because I'd be really fun now. Yeah, yeah, I think it'll be good and I've after I'm I've got a you know a couple of conferences over the next couple of weeks, but when I'm through that I know there's a group of people who are also interested in the idea of putting a ride together.
So if anybody's watching this and wants to join a ride from London to Amsterdam, yeah. English on on LinkedIn. Yeah LinkedIn.
Yeah, there's gonna be a group of writers and Amsterdam. Well, I said out loud now, so it's got to happen. Oh, yeah.
Thank you so much for being with us today. It was really fun getting to to meet you and chat with you and I'm sure we'll bring you back to Tech strong for some other fun stuff that we do here and sounds like you and Tracy all get to see each other in person, maybe sometimes soon at another event, but we really appreciate you being here with us today and pleasure. Yeah, I haven't.
Yes, there's fabulous catching up with you. Yeah, great to see. All right.
Well, thanks everyone for joining us today and stay tuned for more fun stuff on texts on TV.

