Christopher “CRob” Robinson, Intel Corporation | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone back here live in Austin at the Linux Foundation open source, Summit. You know, we've had a very security heavy lineup this past week and for good reason security is top of Mind here everyone the open ssf, of course Monday was open ssf day, but it's been more than that more than Monday.
We really talked a lot about software supply chain thing. That's bombs and just securing open source software my next my next guest is Crab, chrome chrome, or see Rob? No.
No, you know, I had see Rob in my mind, and that's what messed me up. Let's go back to Chrome. Excuse me.
That's it. Just had a little thing myself. So Crow Crow was actually the MC of open ssf day on Monday.
I had an amazing hat. You did and you didn't wear it here. It's I came from outside with tacos, and it was all sweating and we just have two old guys here.
Anyway safety in numbers. Well, yeah, that's true. That's true where the Hat next time.
But anyway, first of all Chrome welcome man. Thank it's wonderful to be here. I'm excited to have this little chat.
We are excited to have you on here. So before we jump into Monday and open ssf day and that whole thing you you're with Intel I am full disclosure. What are you doing you day job so my day job I am the director of security Communications.
So primarily our function is as incidents happen. So there's a new vulnerability discovered or researchers find some report on our portfolio. I help kind of evaluate that and kind of determine how we're going to communicate it love it and your role within open ssf.
So I've been with the open ssf for over two years almost from the beginning and currently I am the working group lead for the developer best practices working group. Love it and the vulnerability disclosures working group. I'm I sit on the technical advisory committee.
So we help kind of shape steer the strategy for the foundation. I'm on the public policy and government Affairs committee, and I'm just now the owner of two brand new cigs special interest groups underneath the working group. So I'm in charge of the education Sig and the open source cert Sig.
So we're going to create a piece here for open source. It's beautiful man. That is really and let's talk about that sir.
Yeah, that'll be through Linux Foundation. Yeah, we are still so back in May the foundation and some contributors created the mobilization plan. I'm sure people have talked about it this week 10 point plan, right addressing trying to help respond to things like the White House Executive Order and it's a plan that says these 10 different work streams.
We feel we can improve the security posture of Open Source software and the open source cert was stream five and the idea is to try to find a collection of experts from around the industry that understand how to do incident response and also understand how to get things fixed within open source communities. So we're we have our first meeting for the Sig the first week of July and we're going to try to refine the initial plan and kind of spec it out and see how we want to react but I think ultimately it's going to be kind of a mentorship program for Upstream communities to teach them how to do incident response and help them, you know work with security researchers and reporters and also help make sure that they've got tools and process. In place so they can be successful.
I love it. Yeah, it is but let's be honest. This is this is a piece of work you cut out for yourself.
Right. Yes, I'm one of my other groups. I work with is a group called first the form of incident response and security teams, and I'm one of the authors of the piece art services framework.
So I have a little help so I understand, you know back on that right? We're gonna lean into that as kind of a model to start with and kind of see what we need to change to make it work for open source communities actually love that good thing. When do you think we might see something on this?
No, no pressure. No pressure. Oh definitely the meetings will be public.
So all of that will go up into YouTube. So you'll be able to observe the progress of the group. I expect we're gonna take probably at least a month to refine the current plan and it's a bit of proposal back to the governing board.
We think this is actionable. So hopefully before the end of the year maybe late fall, we'll actually be able to start taking action. I love it.
I love it. I got to ask you where's the name come from? So the name comes from Novell groupwise.
I'm that old. Yeah, so back in the day. Our network was run by an HP vax, but our email system plugged into the vax and you were limited by the characters of your eat your name.
So my name Chris Robinson, so his first level first letter first name next seven of your last so I ended up being crabenzo. And we hired a developer that walked in. He looked at it and he's like, ah krobenzo the crow, but chromosome that got shortened to Chrome.
Okay, like very close. So thank you. No, not Chrome.
That's right. Thank you. Novellas, right?
Man, those are interesting days. Remember that I love that stuff. I used to lie.
I was a Novell engineer for many years. That's when starts really meant something. It was certified Novell engineer man.
You were Yeah. Where are they now? Oh, they're gone.
Yeah, I think the last time I was out in, Utah. Well, I was I think it was 2005. I was out in Utah they were doing there was something they were working on.
They bought Susie and we thought that that would be pretty amazing to kind of incorporate some amazing tools. Absolutely. We thought that would be pretty awesome then.
Yeah, and yes was the best that we were hoping that through Sushi to be able to channel these tools and I get broader adoption. No, I I think for whatever reason the By elected there's a lot of companies from back in those days right that we think about indeed. Uh-huh.
I am. Yeah anyway. Let's hope my other working group.
So we have more but wait there's more we have more so the developer best practice is working group is spinning off an education sake. So a lot of the conference this week is talking about how we need to get more training and certification and education into the hands of developers. So again, we've created another kind of tiger team where we focusing on this and my friend Dr.
David wheeler, Daddy, Dave Miller David a Wheeler. He had a big announcement where we have existing body of material the secure coating fundamentals class, and he was able to Transform that into scorm. So now that anybody has a scorm learning management system as the ability to leverage this free developer secure software training.
Really. Yes. And that's the scorm if you have scorm you could leverage this free.
Yeah, there's some rules behind it. But yeah, absolutely it's plugged in we're looking to get that donated to higher education historically black colleges and universities. Yeah trade schools.
Like DeVry, we're trying to get this every people's hands. That's that's the thing to do. So that kid that kind of stuff gets me really excited.
I'll be honest with you, you know all too often. We're good in the tech industry performing a foundation and and a Sig and and Advisory Board. But rubber meets the road when you can teach people coming up, right so they come in with the right habits because you know, it's harder to teach the old dogs.
The new chicks, right? I can't I can't take the class. I know the brains full.
Yeah. I know I I hear you, but no But not only that look if you've been developing software for 25 years and I'm gonna come and tell you well, what you doing is wrong and I need you to start doing it this way. Now.
I'm gonna make some progress because no one wants to say I know everything and I'm not changing people don't say that but it's just almost subconsciously. It's a lot harder and definitely is and that's kind of informing our approach. So we have a traditional about 20 hours worth of traditional class material.
So we're looking at how we can transform that material into things like webinars and podcasts and maybe a boot camp. So maybe next year at the open source Summit. We might be able to offer training class where you walk in take the class and walk out with the certification and cool and then thinking about, you know, we have a lot of different Learners we have, you know brand new students.
We have people in the middle of their careers people are making career changes. So we have to kind of serve all these different situents and that's what we're trying that is one of the problems. Kind of the user Journeys.
We're trying to fulfill is this I'm existing developer. How do I gain new skills or refine what I have? It's your question.
Sorry I come from the security side of that some years and years. Nothing a man with putting the emphasis on developers developing more secure software, but shouldn't we also be developing? For security people to better secure open source software and the foundation itself does have many it's multi-pronged.
And so to help like a practitioner. We have things like our scorecard and all stars and there we have a project criticality score and actually just I there was a great session just a couple hours ago by one of my peers Jacque Chester and it was kind of If you're a risk guy, it was kind of based off of Open Fair which is a risk management methodology kind of explaining how we can evaluate open source projects share that information with Downstream consumers and risk management teams or procurement teams and kind of give them a while quantitative assessment of this is what risks you could incur by these projects. So if you have two projects that do the same thing one might have a higher or lower score.
We'll provide you the data that you could you know, make your own assessment off of that make your own judgment. So the foundation is also looking at just many different Avenues to get this out there focused on practitioners and developers and I hopefully by this kind of hydra-like approach it'll be successful. It'll stick.
You know what you just put as much stuff on the wall and whatever it's takes man hope so anyway, he crop right? I got it, right. Yep.
All right. Thank you for stopping by also. Thank you for all you do right?
I mean it's a community thing. These are not paid. Type of gigs, right?
Sure. Yeah. No and I thank you for your for your time and efforts on that.
Thank you very much. All right. Hey, keep up the great work.
We're gonna take a break. I think we've got another interview coming up in a moment and we're here live in Austin.