Securing the Future: Insights into Software Supply Chain Security with Marina Moore – Techstrong Unplugged EP38
Marina Moore, a recent PhD graduate and security researcher at Adira, discusses the evolving landscape of cybersecurity. Marina shares her journey from a math-loving student to co-chair of CNCF’s Technical Advisory Group for Security. They explore topics like the Update Framework (TUF), software supply chain security, and the challenges of container isolation in multi-tenant environments. Marina also reflects on her experiences navigating open-source communities as a woman in tech and her passion for creating welcoming, inclusive spaces.
Transcript
Welcome back to Text On Unplugged. My name is Cassandra Chin, and today we have Marina Moore. Hi.
Wanna be here? Short introduction. Yeah.
So, um, my name is Marina Moore. Um, I recently graduated with a PhD in computer science. Um, currently working with a company called Adera on, um, on some, um, container isolation work.
Um, before that I was doing a lot in the software supply chain security space. I'm also a co-chair of, um, ccf F'S tag, security technical advisory group for security. So how did you get into technology?
Yeah, so I, um, I, I was always into math as a kid. I really loved, you know, the looking at the puzzles and solving, solving problems. Um, and so I had a, a math teacher, a calculus teacher in high school who first kind of, um, turned me onto this whole idea of computer science and I really liked, you know, that puzzle, puzzle, problem solving aspect of it.
Um, ended up majoring in computer science in college and, you know, have stuck with it ever since, I guess. So you really enjoyed computer science since? Yeah, I, I, yes.
I still love it. So, And you're involved with, like you said, the security, like Yeah. TAG security.
Tag security, yeah. So how is that going? That that's going great?
Yeah, it's, um, so tag security, it's um, it's part of the, the CNCF, so it kind of sits underneath the C-N-C-F-T or C. What we do is we kind of work with, um, projects within the CNCF and just anywhere kind of in, in the community, um, who are interested in security, doing things like security outreach to projects, um, security assessments, where we work directly with projects to kind of, um, help improve the security posture as well as general guidance in the form of, um, white papers and other kind of materials that projects can use to, to learn more and improve their securities. The CCF F program?
Yeah, it's run through the CNCF, um, kind of designed to mostly to help the C NCF F projects and kind of, um, do through those communities, but also, you know, it applies elsewhere as well, so, so you wanna like, help projects get better security? Yeah, exactly. So kind of, um, 'cause some of the CNC projects really focus on security and so they're thinking about it all the time, but it's important for everybody, right?
And so like we we're trying to provide those resources to make it easy and accessible to all the projects. What are some common winters in helping get better? Yeah, so, um, the, the, I think the two biggest things that for, for projects is, um, because security is so, it's so specific to what the project is.
Like do they have storage things that need to be secured or is it, you know, you know, network security, like which piece of it needs to be done? And so, um, we have different white papers and kind of those different fields of security. And so often I'll point people to one of those white papers that's relevant right to the area they're interested in.
'cause it just has a lot more detail. Um, and the other thing I guess is, um, those hands-on security assessments with projects, which really just like let kind of security experts in our group sit down with maintainers of the project and really talk about and learn more about the security of their project and well, as well as any potential improvements there. That sounds like a really, so like, help people out with their security.
Yeah, it's super rewarding. It's great to see, um, you, it's great to see when stuff comes together and, um, yeah, it's really a great community of folks. So what other communities are you passionate about?
Yeah, so there's um, an open source project called, um, the update framework or t um, which I am, am very passionate about. Um, it's a project for secure software update and delivery and it's also been used for secure delivery of things like cryptographic keys and software supply chain, um, metadata, things like SBOs or attestations. Um, and it's just a really interesting project that has a lot of, I think, potential growth and potential ways to kind of help improve the security of, of all these different systems.
So I've really, really enjoyed working on that. If you don't mind me asking, like how do you overcome the challenges of like being a woman in technology? Yeah, it, it's always tricky I think when, when, um, especially like open source communities where you show up to a Zoom call for the first time and you realize that you're the, um, like the only non-male person in, in the room.
And so, um, one thing that, a couple things that I found super helpful are are finding those allies, right? So, um, there, there are always people, I mean not always, but C NCF F has a great community that there are often, um, those, those folks that, that will help stand up for you, that you can, that like I've been able to get to know and who have like, you know, made sure that I had the chance to say what I needed to say and been part of the communities. So I think that's the first thing is finding those allies.
And then the second thing is kind of knowing when to, knowing when to quit, right? If a community is not welcoming, um, knowing when to just kind of move on and, and, and find those faces which do exist, which are very welcoming. So, so like a really fair point.
So like there is a point where you need to move on. Yeah, exactly. And I think you are prioritizing like your own safety and mental health as well as, you know, doing those contributions.
So it was important. Have you experienced anything breast similar or have friends or like, um, nothing. Nothing like, um, let's see, like nothing like explicitly, um, I think there's a lot of kinda like smaller things, microaggressions or like, you know, moments where it just feels less welcoming.
Um, I think those definitely have had happened. Um, but yeah. But you're talking with me today.
We're talkier so we doing well. Yeah, exactly. We, we made it through.
So, um, do you wanna talk more about like the security working groups and like how you're passionate about it? Yeah, so, um, let's see. I, I guess the, um, there's a lot of different work groups within tag security that do kind of different, those different fields of security.
I've been very involved in the, the software supply chain security working group, which actually just last week released a, um, a new version of our software supply chain Best practices white paper, which we're, we're pretty excited about. We're really trying to help find that kind of on ramp for software supply chain security for folks who've heard the term, but I'm not really sure how it applies to their project. So, um, that was a big focus of that effort is getting that kind of, kind of on ramp there.
Um, so that's, that was super exciting. Um, yeah. Um, have you been in, like, so did you have a lot of like community and things going on in university?
Yeah, so especially in my undergrad I had a, a fantastic kind of cybersecurity club that I, um, that I was a part of. Um, and it was one of the cool things about that was we got to, we did, we had weekly meetings and the way the meetings were formatted was that, um, different people in the club would like just present about something in cybersecurity. So you have to like learn about something and then present it to other people, um, which I think was a really cool opportunity to both learn from other people in the group who knew a lot of really cool stuff, but also kind of force yourself to dive deep into, into different topics to be able to present them.
So that was really fun and just a great group of folks to, to learn with. So do you find yourselves doing a lot of presenting? Um, a little bit, yeah.
I guess I guess it, I guess it's happened by accident. It, it wasn't something that I like really. I, it's not really something that I seek out.
I think I, I tend to, to be more, um, I dunno, I guess, I guess naturally my natural state would be sitting behind a computer, but, but it's great to work with other people and share information with them and so I think I've ended up doing a lot of kind of presentation type stuff, um, just, just because I like that part of it. So, so where Q Con today, what do you find yourself doing here? Mostly catching up with people.
So, um, I've been super lucky to be able to come to, uh, K Con for the past, I don't know, at least the past five years I think. And so, and every year there's just more people that I've met, either through Coup Con or through all the other, um, CNCF work that, um, and this is the only time I see them in person, so it's just fantastic to get to catch up with folks in person and really have that kind of in-person community, which to kind of build up, up on, on top of that virtual, you know, community that's also great, but yeah, snowball effect where you know more and more people. It is, yeah.
Yeah, the first time I came I probably knew like three people at the whole conference, which is a little bit overwhelming. Um, but then you meet, you know, you meet one person and they introduce you to their friends and then all of a sudden you like, keep running into people, you know, so it, yeah, it does happen. This that's really great.
I like the community coming, we just keep, it's each other. Yeah. Um, and there's all kinds of people working on great, great stuff.
So it's cool to see how it all, like, conferences like this are so cool for seeing how all the different things people are working on can fit together into, in really cool new ways. So what are some of the parts you like about coupon's Community? I think that really that it's, it's really welcoming, um, to, to newcomers and also to, um, you know, folks who've been here for a while.
It's, um, yeah, it's a big open community. I mean, you know, it's a large community, lots of different people in it, but I think for the most part everyone's super nice and welcoming. Um, and there's really just a lot of interesting problems that people are solving too.
Right. So lots of cool things to talk about. Have you seen any problems at this cube coupon?
Which interests you? Yeah, I think, oh, this coupon, I think there's a lot of discussion about, um, kind of AI ML in the cloud and kind of use of GPUs, I think. Um, another thing that I've been thinking about a lot recently is that kind of container isolation and kind of how we can improve, um, security of this kind of multi-tenant, um, container, container workloads.
Like basically when a lot of different people are using the same cloud environment, how can we make that more secure? Um, let's see. Yeah, it's only getting started so I'm sure there'll be more so, and like we can go back home.
What's your day to day life like for your work? Yeah, so, um, right now I am, um, I'm working at this company called Adera as a security researcher. And so I'm doing kind of product validation and security work with them, learning a lot about that kind of container isolation problem and kind of, um, GPU isolation as well.
And just kind of learning about that problem space and kind of turning that into, you know, something that's useful. So, so something that you enjoy? It is, yeah.
I really like, I really like learning new things and exploring, exploring big problems and, and, and understanding systems. So that's kind of, that's what brings me joy. So I'd like you have some really interesting perspectives.
Thanks. So thank you for chatting with me today, marina. Yeah.
Thank you for having me.
