Application Security – A.J. Grotto, Stanford University
A.J. Grotto from the Cyber Policy Center at Stanford University explains why application security is now a socio-economic issue.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with AJ Grotto who is with the Cyber policy center from Stanford and we're going to be talking about exactly what is the impact that all these new requirements from the federal government is are going to have on software providers and maybe what that means for larger Enterprises. Hey AJ, welcome the show. It's good to be here.
Thanks for having me. So the good news is the government's a lot more interested in this whole software development process. They are starting to put these regulations together.
They've been in various forms and effect for a year and ceases thrown out more awareness from folks about issues related to application security. But when we take a giant step back, once your sense of the ultimate impact, this is gonna be on the providers of software. What do they need to be thinking about and what needs to change?
Well, you know, obviously the goal of these measures is to make require federal agencies to demand more secure products from their vendors. And you know for a long time now, the broader sort of Enterprise ecosystem has has not demanded security the way that I think many of us. In the policy Community would prefer it's been kind of a long slog over the past say 15 20 years of incident after incident demonstrating real problems with with many of the dominant software out there and you know, the government historically has had a real challenge with with it is a difficult customer for vendors.
It's hard for the government to adopt new technology keep technology fresh and this this series of efforts that the Mind Administration has pursued really goes back to the Obama Administration. And so, you know across the Trump Administration into this Administration to get the government to band better security as part of sort of a broader call it refresh Of it procurement. Do you think therefore that the software Supply chains and the processes that we use to develop software or for all intents and purposes fundamentally broken and we're going to ask people to go back and kind of revisit that whole thing and then Well, you know, I I can only look at the the artifacts to the outputs of that process which aren't great, you know, and and you on the one hand, you know vulnerabilities are going to happen in software that that that's just the nature of the beast when you have complex systems, you know vulnerability.
We're never gonna get rid of vulnerabilities entirely that said, you know, if you just look at the you know, the ecosystem of software out there. There are some systems that are evidently more secure than others whether that's because they, you know, fewer vulnerabilities emerge whether that's because the systems themselves are easier for users to configure when usability is really a key part of security that doesn't get as much attention as sort of the focus on On you know vulnerabilities and and whatnot and you know the fact that that some do better than others suggest to me that there is room for improvement that there is an opportunity to raise the tide for all boats, which I think is is you know a real top goal for these actions. We've seen coming out of the administration.
A lot of the focus seems to be on software bill of materials otherwise known as the list of ingredients that are included in the software. And that's wonderful, I guess but to what degree? Is that going to be useful?
Do you think are we going to see systems put in place where organizations are gonna Red Light Green Light applications that they're going to consume based on. What's In Those s-bombs. Is that where we're headed possibly?
Yeah, you know and the other so there's this this this classic are you know a study in economics from the early 1970s by George akoloff who would later win the Nobel prize in economics for for this line of work where he the article involved a market for lemons and it's base the idea behind the articles that if you have a market where consumers have a hard time differentiating product quality Up poor quality products end up flooding that market because consumers aren't willing to to pay a premium for Quality. If they can't tell which products are more have more quality than others if consumers aren't willing to pay a premium for Quality. Then vendors are unwilling to invest additional resources.
It takes to produce quality products. And so you end up with a market flooded with what he called lemons one could argue that the software Market is very much as a lot of the characteristics of a market for lemons where the quality feature is security if consumers can't tell which products are more secure than others and their ability to choose a more secure product as obviously limited and so the the software building materials, I think really aimed trying to solve for that problem. It's it's to make sure that that's a major rationale for for it.
It's just to help purchas. And the government or other elsewhere make better to make more informed buying decisions. Now, the other benefit of an s-bomb is you know one's once a person is purchasing decision has been made in theory, you know, having a you know, a catalog of the different software libraries and components that are in a system ought to make it easier more straightforward.
I didn't say easy easier for organizations to understand when a vulnerability emerges whether their system is affected by that vulnerable is that they can make risk informed decisions about whether and hopefully when to patch that system All right. There are a lot of bills now floating around Congress that seem to be extensions of this activity that might be more broadly applied. We're starting to see the US Department of Commerce or the Chamber of Commerce?
That's it. The folks who are on the business side along with all kinds of agencies kind of starting a Lobby again some of those regulations because they're like basically saying so really intrusive and it will slow things down. I think it was Ronald Reagan who once said the nine most dangerous words in the English language or something the effect of hello.
I'm here from the government. I'm here to help. So how do we kind of get to something that's reasonable for everybody concern to maybe not have a market full of lemons, but not slow things down at the point where the rain at which innovation occurs starts to joke.
if if the government or in a position to purchase it at the very Cutting Edge. and you know, I would have more sympathy for that that critique but the government is is You know typically going to be purchasing technology that is not at The Cutting Edge. And so the argument for slowing down I think doesn't hold a ton of weight for me.
Now when we think about the broader sort of, you know, I mean, obviously the government's not the only customer of it in the country and in the world. There's an argument you made that look I mean. Innovation is important.
Right but there's more to Innovation than just new products. If we consider security to also be a valid and valuable domain for Innovation then and very at least regulations could actually help Drive innovation in that respect. Now, I'm you know, the devil's always in the details, you know, I'm a pragmatist when it when when it comes to you know regulation meaning that that I'm neither.
I look at it as a tool. Sometimes that tools the right tool for the job other times. It isn't and I think you know someone who is followed.
Um cyber security Now for for many years from a variety of different Vantage points, you know from the White House where I serve the National Security Council the Department of Commerce, you know, a federal Agency on the hill. I worked in the US Senate and now as a researcher the problem is getting worse not better. And so, you know, maybe maybe we should slow down right?
I mean maybe you know, there may be well being our argument for it and I I think you know, we've perhaps, you know over indexed on Innovation we're Innovation is understood as new features without necessarily, you know, focusing on some of the other quality attributes that matter like security and safety. So to that point do you think that we're having the equivalent of a Ralph Nader moment here where a software was unsafe at any speed and you know, we're basically, you know driving around at 60 miles an hour with no seatbelts and didn't crash right Unfortunately, I don't I you know, I've the other the other. you know sort of occupational hazard of having spent, you know, long time in this field is Every couple years there's an incident where sort of the puntocracy says.
Oh this is it right. This is the moment. This is the wake-up call and You know really nothing really changes at least in terms of a paradigm shift along the lines of what you know, what naders, you know book in the 1960s did which was to essentially spur Congress to create the national highway traffic safety administration.
It's a and I just I just don't I see a more incremental sort of process before us it's worth, you know sort of dwelling for a moment on why that might be the case. Obviously. There's you know, they're sort of an anti-regulatory political.
Um, you know stream in Washington and the country writ large and at that exists and so it's always going to be an uphill climb for Congress to authorize agencies to pursue new regulations. The other factor is an economic one, which is that you know whenever an organization or an actor is in a position to make risk decisions. And they don't bear the costs of those decisions.
Then they're incentive to buy down risk is small. If you go back to you know to the Ralph Nader to the 1960s when this happened when when you know, sort of the modern, you know, automobile safety regime occurred. It was really obvious.
You know who was injured by unsafe cars, right? It was you know, friends family members people could see it right and feel it and and you know, and so just the way that the costs were distributed hit home for America's really hard. In the case of software, you know if I mean oftentimes as we think about, you know vendors for example your companies that produce it.
You know oftentimes by cut by way of contract they offload liability for harm. They disclaim warranties onto the customer. And so unless the customer somehow demands more security.
Well, you know, the vendor has no has a smaller incentive to provide it in the case of you know, those customers oftentimes if a customer if an organization suffers a cyber incident Yeah, I mean they they are they bear some pain but oftentimes it may be if you think go back to the Equifax hack for a couple years ago. Obviously it hurt Equifax, but gosh, I mean it was you know, you and me and your listeners who you know in many ways sort of bore the brunt of that attack because it was our credit information that was compromised and you know, we bore that cost. Yeah, we had no agency over that risk decision and again whenever situations like that emerge the the incentives Um for action or I think are limited you see this time and time again, not just in software, but it just across the economy.
It's it's you know, if I can make it just a risk decision and not bear the cost of that risk decision. Like, why would I spend more pay more spend more resources to buy down risk doesn't doesn't benefit me. I don't barely cost.
So is the answer gonna be more regulations or is it more of a free market decision where you know, we just need the equivalent of Albert Finney to stand up and say I'm mad as hell and I'm not gonna take it anymore. I think it's I think it's a bit of all the above. I think you know, it's important.
I think it's separate this lemons problem, which has to do with consumers not having good information about security attributes. from sort of an underlying demand question Right. So the example you I use my teaching when I when I when I present this is, you know, imagine if you know there was a way if all the sudden software vendors decided to build a differentiate code developed by you know guys and gals of flip flops and hoodies for you know from those that don't is that all sudden gonna result in, you know, an outpouring of demand for software coded by guys and gals and so no, it's not.
I mean, you know, no one cares about that, right? So having more information doesn't start lead to better better, you know quality unless that quality is demanded still. And so, you know it starts with with Demand, right?
I mean customers of it have to demand better security and that's really I think you know what the administration is trying to do with with a lot of these actions over the last it's 12 18 months is a push the federal Enterprise towards demanding more security and then measures like the s bomb then help customers against the backdrop of higher, you know, demanding more security actually decide okay, which which products are more secure than others which products are going to be easier, you know for me and it administrator me a sizzo a CIO to administer and and throughout life cycle. All right, folks. You heard it here.
This game is moving beyond just whack a mole for vulnerabilities. It's becoming an economic conversation and it's going to impact just about everybody. Hey AJ.
Thanks for being on the show. Always. Thanks for having me.
Good to see you. All right back to you guys in the studio.