Baruch Sadogursky and Fred Simon, JFrog | Yalla DevOps 2022
At Yalla DevOps 2022, Alan sat down with Fred Simon, co-founder and chief data scientist of JFrog, and Baruch Sadogursky, developer relations and DevOps advocacy at JFrog, to discuss DevOps and IoT. Alan, Fred and Baruch also dive into Project Pyrsia, which is JFrog’s open-source software community initiative.
Transcript
This is texturung TV. Hey, we're back at yalla. It's actually a little quieter.
I think everyone's in the session. All right, the sessions are great. I mean done.
Okay, don't break them that I yeah. Well, you would think that's what they come for, but I will tell you I was talking to Sharon's it's been earlier. You can underestimate.
The hallway track absolutely, right? Absolutely. And that is the one thing Baruch and I know you know too so many companies over the last two years trying to do virtual events.
Yeah hybrid virtual right right try to duplicate the hallway track now chat video chat. Yeah. Yeah.
No, it doesn't work doesn't work. It doesn't work not to say it doesn't work. And I think this is why the in-person events came back with vengeance because people missed it and yeah, you get the same learning.
Thank you very sessions anyway, right and let's pretend that people actually watch them when they have like all the distractions of things open and the TV exactly exactly. Right? So even the learning is less but networking online like does not exist right doesn't work.
You have to be there. You have to hug the people speak with them mingle was them mingling is the face-to-face activity. Absolutely and it brings the energy you feel the Hard to feel energy online.
The adrenaline doesn't get in when you watch sessions on your on your monitor. Yep. So here yalla.
We have like 700 people sold out look several things. I mean you we hit on one of them is the whole in-person thing right the move to as I think show me called it the devops of things right the edge and you know iot, I I call it the next Frontier the night. Yeah the next right here the next Computing Frontier, but I'm gonna tell you, you know in the last couple months.
I've been to cubecon and Linux sorts Linux Foundation open sorts, and all right. So if you to me the fuel that is fueling developers the whole ecosystem around the world is open source. Yes, right like never before the open store is every company is an open source company whether if you participate in open source if you're Any sponsors and open source project if the employees of the combat and deployers of the company participate in open source project, but most important.
Everybody are consumers of Open Source and there is no escape from it and it's worldwide. You cannot do any meaningful work and it without relying on open source projects of other people. Absolutely whatever you touch you do containers.
You do doctor open source, you do kubernetes open source, you do we get anything cloud-native, right? And it doesn't matter. Even you are three simple as plus developer embedded you the Boost it's open.
So there is no way you you can lock yourself out from open source and not be an open source company. No way. No, you can't you can't exist.
Yep. So I'm glad you agreed with me because now I want to talk about this person. Right right talk to us about it.
Here's the thing, right? So you consume open source, and you do because we said there is no way around it. And where does it come from?
Do you trust it? Is it available? Those would be like the three questions are on everybody's mind right because in the end of the day you take someone else's code.
And you plug it into your production system. Is it called good enough? Someone decided that you want to use this library.
Is this someone knows how to judge if this library is good enough. You might argue about the quality you rated you check their GitHub, whatever. You see the open issues.
You see the last commits. You see the velocity of the releases. There is some way that you can grade the quality of the open source project fine.
Maybe this great worth something. Maybe it's not How about security? This is it.
Very very complicated issue and I think naughty touched on he gave an example and his keynote how sophisticated attacks can be and he was watching the Israel intelligent officers sitting in the first road with the wind like you guys know, you guys know what it means, right? They are extremely complicated and your line developer that needs to judge whether this open sources is good or not. How can they Trust?
That there is no some kind of a very well hidden complicated sophisticated. So like vulnerability hidden in there lurking for those naive developers done to jump on this Library. You cannot expect developers to know all those things.
Yeah. These are someone in caliber not his caliber. And you go like okay now, it's your problem.
Go tell us if this if this open source is good enough or not and then not he goes like full. That's it crazy about security. Really turns it to Pieces plugged in all the research uses all the efforts and come and can come with an answer whether this library is secure or not.
The problem is it will take him two weeks a month to get to this conclusion, but we are not in the world in which the developer who wants to use this Library go away wait for two weeks for a month for this library to be approved f****** deal. Just thinking you some drive it is worse than that. It's like PCI now.
Do you know no one who is PCI Compliant was ever breach, of course because the moment you were breach, you know, why exactly It's the same thing. It was actually it's secure as of this moment doesn't mean it's gonna be secure the next moment one knows and whoever knows knows it in their Silo and way too late. Yeah exactly so solution.
So as all the previous solutions that we have in the last decade is obviously devops, obviously, obviously that It solves this problem as well. Why because we bring bring down silos. We bring the security people into conversation t-shaped empowered him fine.
Perfect. Now what it puts the security people though in an impossible no win situation because they're now part of this very Fast pacing group that wants to deliver faster and they come to them and say hey we need we need an answer is this Library good we need to use it today. And they're like, she's I have no idea dude.
That's the first time I see this code that might be so many ways in which the problem can be there and not only in the code, but also in all the supply chain of this library and all the other libraries this library library, depending on and then someone in some shady gin have library for feeds their forgot to renew their email domain and next thing, you know, Someone got this domain opens an email sends the recovery request get the login into their npm registry account and anything, you know, if you are, right. How how security people in the delve story can win? And one of the tools that can help them.
Is enlisting our belief is Project Pearson. I want to stop you right there because now we're gonna talk a little bit more about project piece. I'm gonna add that and for that we're gonna bring up Fred Simon who knows their stuff.
All right, and here we go. Oh here is red. Magic.
We've been here so Baruch or kidding inside. You very eloquently laid out the problem and it's a big problem. It's a bit and it has been a big problem.
It continues to be Fred you're here now to make the case for Persia. Why is Percy of the solution? So before I go to to Percy, I want to emphasize about the the experience and the experience of this problem when we actually launched bin tray one of the speech was why my mother is not using open source.
And one of the main reasons for it is it's actually very very hard for everyone to understand and to have a little bit of control and to know exactly what is coming in and what we saw in a recent year on global stage of Information Technology of the world is that decentralization is really a nice way to bring trust to people because there is no Central Authority and there is no sun Holland and formation. You don't need to trust me. It's free.
I mean we That we've been then begin a lot of experience with hey, you can trust us really no we don't. Why would you dress as we nice? We don't trust anyone.
Okay, it took us many years to get this to learn this lesson, but I think we're there now we understand and we actually preach now don't trust us really don't yeah. This is a big thing in security right zero trust exactly. Exactly.
Yeah start off at zero trust. So the where zero trust in Security is to identify every communication and every packet and where they come from but decentralization is more than zero trust decentralization is let's distribute the trust. Okay, let's let's say okay if if my friend if the friend of my friend or even the neighbors are all saying the same thing.
I'd probably gonna be okay graduation exactly among those who agreed that not only just by you know strange in numbers. Hey probably a lot of people say it's it's okay. It's okay.
There are actually different actors that gained their trust through reputation. Right? Right.
So if I'm on those peers that all agree that it's okay. It's not only me and my neighbor but also doctor registry all so nbm registry also maybe in Center also the producers of java and those who build those and all of them agree that it's a good thing then through this realization you have this trust. And again, this is a question for what we need to aim is security people see those trust.
We just very hard to gain because in their job description, so what exactly right so once we pause that the next good thing is since everybody agreed. It's a good thing and everybody. They have this good thing.
I don't have to go to the one point of failure. That might be down to get this good thing because everybody already have it. Yeah, this one's realization brings reliability because it's about coming from different places.
But there is one point about I need to be able automatically and this is what we saw now with blockchain and and Ledger and decentralized Ledger, which is readable by everyone and and reputable is that when my neighbors say that he did something he cannot come one week later and say no I never said that okay, it's proven. So every identity is identified and trusted on the communication Channel and everybody that puts something on the communication channel is say this thing at this time. We just 50% audience once you mentioned blockchain.
So let's bring those people back. And there is a lot of hype about web 3 block terrorists crime. There's also been a lot of bad exactly and wait exactly like that like happened in bed in the bad way and completely Justified right?
There is a lot of empty hype riding through that all this energy crap and what's not but the core of the technology is is solid. Only thing that we care about the part of the ability. Yes is The Ledger that cannot be hacked and it's there.
It's a good basis for everything else and all the hype up on top of it that we don't care about but The unhookable Ledger completely transparent that everyone can download to their machine and very fine. So actually what those binaries come from the source that they supposed to come and do what and and we have the chain of custody throughout the entire delivery. This is something that actually blockchain helps solving without the all the crap of three right?
So what we want describing, is that okay? I ask my friend I ask my neighbors. I ask my mom on the other side of the country or whatever.
If I have to do that for every software packages that I want to download and and try to take this decision. I didn't win anything. It's a freaking nightmare.
I I need automation. It's the same mind. I need the tools.
Yeah, and and I need the processes and this is what the transparency log is giving me. It's these ability to automate those kind of questions and automate this kind of trust validation and and Trust system into into the process so that I I have higher trust but High Automation and higher speed I need to be able to to move faster. Okay, if you yeah, I mean I get it today.
No, I get it today. We know so we sold number of problems. We provide all the benefits of being from Source because it is built for Source right not by us.
But but someone who everybody else trust and by and it means that we can trust them as well. So it's like we build from Source, but without the need to actually build something from source and We also protect the delivery itself, right the Supply Chain by showing you that there is a chain of custody that cannot be tampered with because again the technology that we work there is trusted and proven and you can actually look under the hood because it's all open source to trust the process. Once you trust the process you can trust the outcomes and this is how the security people in our devops world can actually keep the pace with everybody else without being the bottleneck.
Got it. Yeah. Let me ask you questions for our audience.
We're rubber meets the road. Let's take something like Glock for Jay. How would of course we all want to be a happy ending, but how would log for Jay How would percia Help have helped in the log for Jay situation.
So first of all, the information about something is wrong with the specific log 4G that version and those clock for the binaries that exist out there. You could have a malicious actor that does also that says those version are really really bad, but it's actually a malicious actor. So you identify clearly the source of the information and saying okay those look for them and then inside the system you can trace back because you know exactly what are the version we can trace back on on your system who is using it and where it is and and provided back now what gonna happen and what we want to promote is the fact that you trust and then source of information about the fact that you should not trust binary.
Okay, that that's the state exactly exactly. Right? We saw it.
It's okay. Look for Jay is actually very simple case look the when your ability and look for J is not of a new ability at all. It's actually it's not a big fat It's A Fine Design.
It's right your body. Is that the whole way it's exactly how it's supposed to work Microsoft used to say it's not a bug it's a feature and this is actually here. Now what happened?
And this is fascinating is that one morning the entire industry decided that this feature is too dangerous and needs to be considered even your ability right now. We we saw in the first hours or days when they hit the news we so kind of two two approaches the ones that run around in circle with their head on fire shouting. It's terrible we are doomed Is falling and the others who say no, it's a feature.
It works by Design just don't use it this way and you will be fine and those two it took days until they converge into something like yes, we know how to protect but it's better to have a new version in which this feature won't be available anymore. This is what happened with log furniture. Now where piercing comes to play.
Until this feature was decided to be bad. There is nothing for us to do. There is a version it has debatable feature.
It's fine. Once it explodes and this debate starts. Some people say no it's variable.
The other people say it's fine. We will have those two pieces of information inside. Piercia Network.
Some of the nodes will declare log for Jay particular version as terrible vulnerability. The other nodes will tell. Well, you know what, it's fine.
It's really works is designed. com. But you actually have this debate happening inside the network that provides your binaries, right and automatically without you making any thing.
In one day look for Jay was downloaded just fine because the majority of the nodes agreed that this is a valid version the next morning your network will fix itself to block the same binary. That was okay yesterday because the majority of the notes including the notes that you trust decided that okay. You know what you convince us is terrible.
Let's block it. So this use case is perfect to see how the information propagation not only happens on social but also happens in the bits and bites, you know inside the technology of your here was another big problem with log for Jay. a lot of organizations didn't know where it was.
They couldn't find how many instances yes. It was running and you know, the average organizations x amount applications. We release some open source tools for all those environment and application to be able to detect the same.
Also. We do that a lot our research team. So to help you scan your runtime your environment and find if you are vulnerable, right?
That's the runtime, but the The bills are completely safe with spearsia, right? Because in the next morning it will just stop building because it's okay the same artifact will suddenly be declared as vulnerable. But the picture is is actually Jeff Hogan the jayfrog platform for our customer.
They get most of that's already there. They get the picture. I give you another example strikes too.
That's true. Yep, right right six months after the Equifax. People are still down.
Of course, of course. Yes the bad version of course, right? That's exactly the same physics you use piercia the industry declared that these are the fact that bad done.
You don't need to do anything. You don't need to know about it at all. Wait, there is something fundamental about the package management system before Pierce here is that For package manager like Maven and PM and all this stuff.
Once you release a package, it's immutable it's package itself and it's made other time which dependency it has and which version and it's very fundamental to a maven inside them even so anybody and you build system once it's released in the public repository. It cannot change. You cannot add any more information, right?
It's not every change will generate a new one that the beauty of a beautiful exactly. So that's why the transparency log of piercia here is very very full because information about these binary continue to leave even after it's it's out there in the world and in really so you need to be able to add more meta time more information and this guy for more interesting scenaries and look for Jay the malicious scenario in which someone tries to hack the supply chain. There's What happened was look for Jake but someone but what happened with people putting up like with the wrong doctor, you know, a doctor could be naming.
Thank you mother name and double A instead of single and this kind of stuff. Now, this is completely out of his Persia because the Ledger will just show very clearly. The devil is an attempt of a mess.
It was that hacking right? So if we will see very clearly that this was an immutable binary up until there and then it changed it tries to keep the same name to confuse the users but The Ledger shows that it's broken and this is why you won't be able to do it again without even you need to research it or to read about it in the news and that's the big deal about it. Yeah.
Hopefully nobody might not my friend and not my neighbors and nobody will certify. I mean people that the thing is there is a lot of strength in. Child and called soci.
Okay, some people need to spend some time looking at what's going on on the open source environment and all those open source binaries. The problem is that if every developer that is all of them are using log 4G need to spend the same amount of time and energy certifying it's it's way too much. Okay here no one this called sourcing kind of environment that one guy that is authenticated identified and kind of trusted say something good about it.
It's already well the but you get to the critical mass situation where exactly I believe Fred Baruch. Okay. Remember Luke, I'm good.
So let me let me bring up another thing into something report all the problems all the world. We don't automate everything exactly. We automate all your problems exactly.
You know what today's Out so we live in the era of foundation. Yes with open source software. Yes, and so we look at something like percya very nice.
Does it only work with Jay frock? How do I know it doesn't as a rhetorical question we call it but you know, is there a plan to put Paris here with the Linux or the open source security Foundation see yourself from the start Pierce. We know that we cannot do it alone because it's right because it's right and we learn from our experience and flies and that yeah not open.
I promise you. I promise you the quote from Infinity Wars when panels when Loki suggests the Tanner should take him as a guide to conquer earth, right because he has a lot of experience with conquerors Thanos asks, if Loki considers a failure and experience and look he said I can see there experience experience. Okay, so we know have a lot of experience and we know that we cannot do it alone and piercia was never intended to be a project from the beginning and we have very important.
On the industry players that work all together not with us, but all together on Pierce and that Docker that deploy Hub. That's Oracle. That's Huawei everybody building it knowing that no one will own it because the second someone tries to own it it divisible purpose done that it's like throw it away.
Bring the next one. Right? And now what we all of us all those companies all the contributors try to do the next step is I think by the time this episode will go live.
We will already know the results of continuous delivery Foundation part of the Linux Foundation voting on whether they are the idea should be a part of the city. Very cool, right? Yeah.
So this is our hopes. They won't think is that is the place for us absolutely continuous deployment. It makes perfect sense.
It makes perfect sense and hopefully that will that will happen it actually hopefully it To happen, that's the temporary retireable thing. Right? Let's not mess up our time.
Like that doesn't fit in the blockchain because right away Fred won't be here that it's a it's a right behind preservation. It's the Sparkles. Yeah.
Exactly. No. No, we need Fred to be here in any possible future move diverse beautify.
I should be part of our lives a pure causality Link in the transparency log. No no Universe yalla. Alright, we didn't even follow.
You know, why stay tuned. We'll tell you if it made CDF. If not, they may never have been a friend.
Oh, no, thanks for we're gonna we're gonna we're gonna end it right there. We're at yellow devops still though. We're gonna be back with some more interviews in just a minute.





