Security, Open Source, and Hands-On Learning with Justin Cappos – Techstrong Unplugged EP36
Justin Cappos is an NYU professor and creator of multiple Linux Foundation projects, including CNCF’s TUF and in-toto. Justin shares his journey into security, the critical role of hands-on learning in education, and the collaborative nature of open source. From teaching students to unlock physical security devices to designing secure software systems, Justin emphasizes the importance of curiosity, teamwork, and diversity in solving complex problems.
Transcript
Welcome back to Textron Unplugged. My name is Cassandra Chin, and today we're here with Justin Cappos. And you're the owner of five C and CF Projects, and you're also a university professor?
Yeah, just, just to correct it, five Linux Foundation projects, but not, uh, five C ncf, F two or in the CCF ft. And in Toto we have one optain that is, uh, inside the JDF and two open SSF projects, SBA, and get tough. Um, and I'm just one of the creators of these, uh, projects.
There's a lot of other students and other people that have done tremendous things with these. Do you wanna talk about maybe your time as like a professor, some interests? Sure.
Um, one of the things I really like about being a professor is that I basically get to do whatever I want almost all the time. Um, now sometimes I need to do things like go and teach a class on a day that maybe I'm not feeling like teaching that subject, um, or, you know, have to work on a research paper that I'm tired of. But in general, I mostly get to do what I want to do and have fun with it.
Um, and I think that's really important because I think if you're gonna be really effective in things like education, you have to also make it enjoyable. Um, I was actually the CubeCon host to CNCF Kids Day, and it's usually the weekend before CubeCon and I'm like one of the instructors. So I can kind of relate that.
Like I have to have, be having fun if I want the kids to have fun. Right? And, and so one of the things that I try to do is when I, uh, teach concepts in my introductory security class, um, I don't just sit and give a dry lecture for two and a half hours every week.
Um, we try to do more hands-on. Uh, they learn things like, um, how to open combination locks that they don't know the combination to. Um, but they have a legal right to open, of course.
Um, they learn to do things like getting get into n NYU's buildings without, uh, showing their id. And, um, you know, we do things like, uh, I even use things like card magic to teach different things related to deception or other stuff like that. So I think, um, if you do more engaging topics with students, rather than just put up a slide and say, this is what a side channel is, this is how it works.
But if you can do something, um, more visually interesting and more memorable, then I think students learn it a lot better. Suddenly. I'm really wishing I could be a part of your class.
Well, you still can. So, um, you could feel free to go and, and sign up, uh, apply to NYU. We'd love to have you as a student.
It's interesting, like you say you teach them how to, like open doors, locks, how does that work? Um, so most combination locks like bike locks and luggage locks, and then like the master locks that you have on your locker, um, they all work using slightly different principles. But one of the things that I think is the fundamental key to a lot of things in security is that once you understand the principles by how something works, you can often find ways to make it do things that the designers did not intend it to be able to do.
And those weaknesses, those vulnerabilities are what lets us, as you know, security people understand how to attack things. And so, uh, you know, the way that I learned all of this wasn't that I went and took a class on how to become a bike thief or something like that, you know, um, what I did is I literally, uh, was on the London Underground, uh, was getting on the London Underground, and I wanted to have a luggage lock. So I bought a luggage lock and I started to play around with it.
And I found that by the time I'd, you know, traveled on the underground for 45 minutes to get off at my stop, I could put the lock behind my back and mixed it up and then open it without having to look at the dials. And I thought, wow, you know, I just wasted 15 pounds on this, you know, garbage lock. But then I, I started to buy other locks and I found that if I play with them for a little bit, I could do the same.
And so it's, it's almost like kind of a fun challenge now where if I go to a hotel and I'm bored and they have a safe in the hotel, I try to see like, you know, Hey, can I open it without, can I lock it and not know the combination and open the safe? And in many cases you can, there, these systems are not actually that well designed, not as well designed as you might think. Uh, just wondering, does they tele charge you if you can't open it again?
Uh, no. Um, at least I've never been charged, uh, for a situation like that. Uh, they, the safes that they use in hotels, just like, uh, the door locks, they have master keys and master ways to get into them.
In fact, there's often a little port on the safe that you can plug into and, uh, unlock them. And sometimes you can find information about that online, how to do that. Good to know.
Um, so do you wanna talk about some of the projects at the CNCF? Sure. I, I'd love to.
Um, so one of the most longstanding projects I've been involved with is a project called The Tough Project. And, um, actually back when I was a graduate student, I was building a package manager a way to install software and Linux systems that was being used on, um, uh, on a system that we didn't call it the cloud at the time, but, uh, because it was earlier than that term was being used, but was basically the first ever academic cloud that existed. And, um, I built this package manager and did a bunch of things with, you know, to optimize it for the cloud.
So I built like the first cloud specific package manager. And one of the things that I did is I made it so that if multiple systems, um, would go and install packages on the same, uh, computer, they wouldn't end up with downloading the same software over and over and over again. They wouldn't end up with a bunch of different copies of it on disk and things like that.
And because this sort of shifts the threat model, I also had to think a lot about what happens when you have a man in the middle, like a mirror or another party become a malicious attacker. And so, um, when I did my design for the package manager I created called Stork for this, um, I later went and looked at the Linux package managers and realized they were all vulnerable to different attacks that Stork was protecting against. And so, um, I wrote a paper about it and thinking, you know, oh, I'm, I'm a good academic, I wrote a paper.
Of course everyone in the world is gonna read my paper and fix all their problems. Um, that wasn't true as, as you know, is probably obvious. But, um, at the time I was sort of proud that I'd made this contribution.
And then after this, uh, some folks from the tour project reached out to me and said, Hey, we have big problems with our system tour, which is a way to browse the internet, um, anonymously. Uh, and, and so people can't tell where you're coming from or where your traffic is going to. It's not this web browser.
Yeah, it's like an anonym, an anonymization network and protocol and system. It's used by millions of people every day. If you use a browser like Brave, um, you can go in, in brave and actually just click to open a private browsing window through tour.
And if you go and say like, what's my ip? It might tell you, you have an IP in the Netherlands, or you have an IP in India, or you have an IP in some other place that you're not. Um, and so anyway, uh, so some of those folks came and tried to understand how to build a better version of their updater, and they spent some time with me, and afterwards they gave a design.
And myself and an undergraduate who I had been working with took a look at their design and we found a whole bunch of security problems and we said, wait a minute. If it's this hard for these experts like super, you know, hardcore security experts to do something like this, we need to make it easier. And so we started the tough project, which was a way to be effectively like a library or something that people can drop in that solves this problem.
And so they don't have to reinvent that technology themselves. Um, and so I, I think it's, you know, it's really important and I think there's a lot of, really, one of the key lessons here is, is that I wasn't like born a security expert in package managers, or I wasn't born a security expert at all. It's just something that anybody with the right kind of mindset and taking up time and effort can really help themselves become that and make a really positive difference.
Do you like ever get your students involved with your projects? Oh, absolutely. Um, there's no project that I think I've ever done that, um, didn't have substantial effort from students.
I, I like to work with people and it's really a team sport. Security's a team sport. You need as many viewpoints and you need things like this, uh, like perspectives.
Um, and so, uh, my students are heavily involved in all the projects that I'm doing. In fact, I've had multiple students, even people who got their PhDs after, you know, roughly five, six years of work by doing repeated improvements on systems. Like tough, for instance, um, one of my students, marina Moore got, uh, you know, published a bunch of papers, made a bunch of improvements and helped it to be, for instance, widely used in automotive.
Lots of automakers, um, lots of internet of things, devices like medical devices and devices inside factories all use effectively a variant of tough because of a lot of her efforts and efforts from others in our community. I think that's really great how, like, it's not just a solo effort, it's really about community and you get people involved. Yes.
And a big part of that is, you know, the more voices and the more different perspectives, sometimes you can really attack problems from directions that you weren't really thinking about. So diversity is, is super important. Uh, do you wanna talk about some of your other projects?
Um, sure. Uh, let's see. I, in fact, I'll tell you about a project that's not A-C-N-C-F project that has an interesting lesson.
So, um, I was, this is, I don't know, 10 years ago or so, uh, one of the big problems at that time was all these password database databases were getting breached and they were getting compromised. Now it happens so frequently that people have almost stopped paying attention to it and just assumed that this is happening. And so, uh, number one pro tip for anybody out there is use a password manager.
Um, don't remember passwords. Just use a password manager. You need to remember one password.
And then all your other websites you use can have randomly generated passwords for them that you never need to know what they are. Uh, anyway, so at that time, what I did is I had thought of this, uh, way using cryptography to make password databases much harder to crack. And I went and I took, uh, one of my, uh, at that time was just starting out as a PhD student is now actually has graduated, um, you know, he's now a professor at Purdue actually.
Um, but, uh, he, he and I like worked together and built this thing and there was a summer camp where we had high school students come in and participate. And we had this high school student who was quite mathematically focused. He really under, you know, really understood mathematical aspects of things in a very deep way.
And he asked us a pretty fundamental question about the system that we built and said, doesn't it have this property? And we're like, no, it doesn't have this property. Um, we built the system.
I mean, we invented it if we would know if it did. And then later that day, we both thought about it a while and we realized that the high school student was right, that he was actually teaching us things about a system that we had designed, that we were the, you know, the foremost experts in the world on 'cause we built it. And so, um, there's lots of examples like that where people can go and make a really positive difference.
You don't have to always have super deep technical skills in every area. Sometimes just poking around, learning more, finding an area and going, going far into it. Um, you can accomplish things that are otherwise like very difficult, um, for others to do.
It's, you can really make a difference. I think that's really an interesting perspective that like, you can still learn from other people even if you're considered the expert. Sure.
I mean, you have to, there's no one who, anyone who says they're an expert but isn't open to having their mind changed, is not gonna be an expert for long if they ever were. So Yes, I can definitely believe that. Yes.
Um, I really learned a great deal from you. So thank you Justin. Oh, thank you so much.
This was a lot of fun.
