Nati Davidi, JFrog | Yalla DevOps 2022
At Yalla DevOps 2022, Alan spoke with Nati Davidi, SVP JFrog Security, about finding security issues and remediating them efficiently. Alan and Nati also discuss IoT, edge and security, and how these ideals have taken the cyber world by storm.
Transcript
This is Textron TV. Hey everyone. Welcome yalla y'allah devops here in Tel Aviv.
It's so good to be back in Israel. And in person at this it's a sold out event. I think 700 developers or devops people stronger here in yala devops is the it's actually the third yellow devops.
I think let me introduce you to my guess is the first time he's been in person on text drug TV, but well not eat. Davidi Nadi was the founder of a company acquired by Jay frog coach video. Yes security company called cyber now cyber company and I think we interviewed you within the first week within the first couple days and then we interviewed you again with the release of the product launch, but it's been a year now.
So let's let's start there before we jump in. I know we're supposed to stay on track, but let's start. How's the year been for you?
And first of all, it's amazing, you know, looking back 12 months and seeing that we were able to achieve everything that we dreamed of seeing the philosophy of house binary security combined with the artifactory capabilities and not only finding security issues. But also taking control over their mediation and mitigation is happening. We get an amazing feedback and our fortunately our fortunately enough all the look for Jay and sprinkles stuff that came in just in the exact time timing is everything exactly you had not just let's be clear you had nothing to do it.
Oh, no, but all right. So let us jump in though. You know that a big theme here at yalla.
This year is his iot Edge and security very important security and sort of I think show me said it in his in his keynote kind of moving that cicd. Mindset two new areas through the edge. Yeah to internet of things devops of things I think is the term you used but this presents problems with security because like everywhere else the security issues as we develop for iot and Edge.
How do we you and I both been in security a long time. Does it ever end do we ever make progress here? How do we how do we get better?
How can we do it better this time? First of all, it will never end unfortunately, but I think it's it's It's combining three things first comprehensiveness of the amount of things that you are doing and the talk with each other. Second actuality of data you need a data to be up to date every moment.
Because you cannot really win in this cat race with the attackers they will do things before you but if you have the data, yeah fast enough you can act accordingly and third maybe the most important one is collaboration. I mean we might have one of the best research teams around and 300 companies in this event or 30 having company this year and have also their great or the best research Labs if we collaborate to build a one single to source of truth that is open to the entire community. That would be a third very strong element.
Yeah. Sure. Great.
I agree. But you know, I I brought it up on my session the panel I was doing in there. Look, I got into devops because I thought it was the best thing to happen in security.
What a what a concept we were gonna shift left. We were gonna get developers involved in security and and the world would be a better place. And it's worked.
It's worked almost beyond my expectations. But now I asked myself are we asking too much of the developers? So the the general answer is today?
Yes, because of the fact that there are so many Niche solutions that we are asking him to execute on their code on a daily basis or an already or at least basis and by Nature these engines create or generates hundreds or thousands of entries which are not prioritized which is not imply whether the things are important to fix or not, which will not instruct the developer necessarily how to fix them. So if you plan to have like 70 17 working days a month to develop the next really suddenly have only seven because they need to deal with the Federal Credit. Regulations to make sure that the SLA is met and there's no CVS and suddenly he has the derivative of the executive order for May 2021 sitting only developed per table.
There is it's inevitable. Someone need to take all these aggregated fragmented solution and help you developer first prioritize second automate now, you can automate your mediation to some extent. I can't imagine developers allowing vendors coming changing the code on them without knowing what's happening.
But if you are doing it in an interactive smart manner if you are asking a developer, do you agree that this is a problem here is the proof that you agree. Yes. Here is the suggested solution would you commit it?
Yes, and then you give the control but it will take 30 seconds in of taking three hours. So it's a semi-automated approach with control of the developer with prioritization and I believe this is the only way To reduce dramatically the amount of work that they burden that we are putting on the developers these days absolutely. Let me ask you one another question, you know, we we've spent a lot of time over the last let's say 10 years eight years talking about software development life cycle.
That's the LLC but now we're talking more about software supply chain security. They're not necessarily the synonymous. They're not the same.
Correct. There's sdlc that's so forth. Supply chain security.
What do you think? Where do you think the differences? Where did they overlap?
I think that the differences are both in the depth in the spectrum of things supply chain security is a lot about things that are on top of the regular SDC are coming before the end. Yes, they'll see and after yes DLC, and yes, we'll see what's built in early the earlier days when the more than Technologies. Which creates many more gates along the way of pushing software into production and many more opportunities and bigger attack surface for their attackers to come in.
The regular typical SDS. You didn't take it in account, right the attacker Photoshop injecting himself into the process through an idea of the developer or through a build system is something that was taking an account but not in the wide enough and Broad enough aspects and same goes for open source come from library and sorry open repositories all the way to iot devices in production. These things are not covered in a more typical espnc approach.
Absolutely. Anyway, we have we have the head frog here ready to go next. Actually.
I don't know we have I would bring all three of you but I don't know if we have to set up do we have right? Do we have three mics now, too? All right.
My pleasure to see you. I talked to believe it's been a year. Yeah, it's because you success.





