Views on Software Security – Techstrong Research Review EP 14
Mitch and Mike go through their thoughts on software security, which was the subject of their DevOps Asia Summit talk, which was postponed to July. They also introduce a new segment called, “What’s your beef?” Mitch goes off on T-mobile for their (lack of) API security posture.
Transcript
here Hey everybody, Mike Rothman here general manager of tech strong research with my pal Mitch Ashley Mitch. How are you? Good good, everybody.
Great to be here with you as well and happy or this is Friday for us. But who are you happy? What do you do?
I know I am. I'm the lens cleaner on the camera. Yes, we're just research if you know with tech strong group and principal with my contacts drawing researching and she camera cleaner.
So yes Chief so that is one of those Vehicles. Yeah any given time we may have to record it's one of those days. That's what I like it.
I like um, welcome to the text wrong research review. Yeah. We I think we missed last week.
So, you know, we do something, you know, it's like I can't even remember two days ago. So I I Florida State some. Yeah, it was something.
Oh, yeah. We were doing something so so we're back. And in fact, we were actually supposed to be on our way to Asia.
All right son on Monday actually so that the idea was to go out there for the devops Asia Summit which has been postponed. So I am actually going out to Asia anyway, but the devops Asia Summit has been postponed but Mitch and I were gonna do a talk about software security basically, you know kind of give our perspective on on the trends and and I'm where we saw things going. So we figured you know, what if we can't do it in Asia we can bring agent to you.
So we're gonna talk and and rap a little bit for maybe 15 or so minutes about software security really where it is and and obviously why it's important. I'll give you the highlights of what we eventually we'll talk about in Asia when that conference gets rescheduled. Again in July so so that's the word been so so what do you think man?
You know, it's Social Security seems to have become a thing. But to be honest with you, I may be a little skeptical right because I've been doing this a long time first-time color first time. Skeptica.
That's oh yeah, right. Okay, so I may be a little skeptical about this right and and I think a lot of that just comes to the fact that application security right secure sdlc, you know application testing, you know, all of these things have been so and such an obvious need for so long and yet we've always struggled as an industry to get anything done besides put a box in front of a network and and use you know, kind of network based or network based approach. So why is it different this time?
What what are the callous? I mean again, let's kind of back up a little bit and go. All right.
We know it's a we're not going to sell you on that. Why are the solutions that are available today, you know more tangible applicable and and have a you know, hopefully a better chance of success than we've had in the past. Well, you know, we you know you and I you and I've been in an era of we scan it right?
We see look first cross-site scripting we look for whatever right? We took even through through scanners and vulnerable software detection and things like that and then preventative measures that doesn't secure the software itself. It just points out or block blocks things.
Right and I think this ship the focus has shifted to How can we actually create more secure software or make it more secure while we're creating? You know, I like to use the analogy of you don't you don't manufacture a car and as soon as it comes off the line say we should put airbags on that right? It's kind of too late right?
It's right that's gonna be a pretty damn ugly car. So you do have to design it in but mine into the software. Yes, you have to do it there, but I think it's about the process of how you create software and that's started to bring security engineers and software engineers and Architects sort of into the same room.
Maybe they're still in the corners of the room, or maybe they're kind of congregating up front and starting to talk. Maybe they're working together. I think that's one factor.
I think the other one is just you can't sort of bump around in that room without elbowing software. Everything is software. Everything is soft.
I mean, it isn't the back office. It's the front the side. Yeah out in the mobile foundation everywhere, right, you know kind of the digital experience.
I mean, everything is software based exactly. Like if you know, are you gonna you're gonna not gonna swim in a pool of just terribly unsecure software you've got to do something about it. So I think it's gotten a lot more attention for several reasons.
Yeah, you know I also throw the differences in application architecture in there right in that you know, we're a lot more API Centric now or a lot more microservices-centric now and and that kind of forces us because we're integrating and you know a bunch of folks push back on one I said, well, you know, we compose our applications we assemble our applications now as opposed to coding them, you know, some people say we still coach 70% some people say we still call 40% The reality is your coding some piece of it you're leveraging other folks code in terms of libraries and components for other pieces of it and the libraries and components are things that are really kind of outside of our control. So we have to figure out a way and that's where our supply chain vulnerabilities are. We have to figure out a way to more effectively track what those components are what those libraries have in them and make sure that we're on top of it when it becomes vulnerable because we've learned this before right back to the jet database, you know amount of thousand years ago you Which which kind of spurred I love you and Melissa and a bunch of these other, you know, kind of early self-directuating our self proliferating attacks.
And that's just giving way to solar winds and all secure and and you know kind of a whole variety of other, you know, kind of supply chain type attacks now so so I think folks understand a little bit more about how software is made and where it's vulnerable. Creating a little bit more urgency in terms of starting to address that so I I think that's definitely helped, you know, kind of shine the spotlight on the fact that we do have to solve it. But again, why is this not just you know, again more, you know kind of veneer right more polishing the turd so to speak and and kind of lipstick on the pig I guess a little bit more politically correct way of saying that but why is it gonna be different this time again?
I keep getting back to the state. Why is it going to be different? You know, that's a great.
I mean, we're still we still have what cross-site scripting and SQL injection and then the top 10 Etc. Today so we still can't get away from some things. You know, I I think Mike you're definitely you're dead on about soccer architecture and how this change with microservices and apis.
And you know, it's kind of like Hardware Electronics everything miniature Rises same thing happens with software architecture. Everything gets smaller, right and then but there's you know, Millions more pieces of it or thousands or tens of thousands. So it gets more much more complex.
I don't know if the analogy holds up. But you know in the hardware world, I used to work in the pki business digital certificates for Wi-Fi and cable modems and stuff like that. And there are there are literally dozens maybe more maybe hundreds now digital certificates subsystems of subsystems of subsystems from different manufacturers all plug together doesn't look like a breadboard anymore, but they are essentially when they're assembled lots of pieces from lots of different places not unlike what we do in software and you know, they have supply chain Integrity, right?
How do I know? I'm putting their right thing. It isn't a black market piece.
It isn't copied and that's kind of what we're dealing. Now within the software world is yes, our own software architectures and proliferation of apis and there's a lot of good good parts of doing that but we're also assembling a lot more subcomponents that aren't ours a lot more open source, a lot of SAS applications a lot of back in stuff. Maybe Legacy or older a lot of newer and it's it's features and capabilities on the phone.
You name it. It's so many parts. I think that's the complexity.
That's also yeah kind of raising the oh the I don't know if I want to say that we're scared now because it's like, oh my God, it's kind of cats out of the bag but it is the attack surface I guess is the right way to say it is so much bigger today. So you've got to figure out you know, if you're the risk officer or the siso or whatever. It's like, what are we doing?
Yeah. I I still come back to the I've seen this movie before right and and again, I keep traveling I was why is it different this time? Well, I I have an idea right so I do have an idea.
I don't know that It ultimately results in the outcomes that we really want which is that we actually do have you know kind of this ability to protect our software and we're building in protections and we have shared accountability between you know, the developers and operations people and the security folks and we're all pulling in the same direction that's still seems like a bridge too far, but the theme of our RSA conference this year so we are doing again devops days at RSA and RSA conference again on Monday of conference week is devops is now devsecops. Right. So when we think about that backup that it's not just you know, folks know more about it.
They understand application architectures changed and you know, we're assembling or composing these applications and we've got you know, the potential to introduce vulnerabilities or exploits and in the form of supply chain attacks from that's the point now, we're also building things in a different way, right? We're building things in a way that takes a lot of the do I have to make a conscious choice about something out of the mix, right? If we're integrating some of these pieces some of these Technologies some of these capabilities into the pipeline for how code goes from repository through, you know, validation and integration validation testing and ultimately deployed out through production.
A lot of these things just happen. Right. So that's a huge step words, you know, it's not a matter of somebody's got to integrate.
It's not a matter. Someone's gonna press the button it. Happened.
Now what happens after you get something that says hey, we got a Defector. We got a security issue, you know, you've got to deal with it. That's a different issue.
Right? But the fact that we're moving towards more of a Dev SEC Ops motion and you're starting to see the vendors that do the pipelines talk a lot more about security build a lot more about you know security capabilities in their environment and I'm looking at you get lab right? I'm looking at you Jay frog right, you know kind of these, you know Cloud bees, right, you know, these companies get up and crap, you know, they kind of big dog in those space, right?
They're building these capabilities into their pipeline type of environment and that means it's there and we still got to do something with it and we still got to fix the stuff when we find things but at least it seems that we're a lot closer to looking now and I think that's a huge, you know, kind of step forward, you know, from where I said it is and it's a it's a it's a flip from Check and detect right which is the world. We've lived in Forever, you know since the beginning right now. Let me check this backup.
Let me check this code that's going out rather that went out right to while it's in the process. Well, it's in the flow of being worked on created assembled integrated tested Etc multiple points in that process again, I'm back to process right we will always create security issues software. It has security issues.
I believe is even even chat GPT can't generate text that doesn't have a grammar error in it. I prove that on LinkedIn the other day. Yeah, there will always be security issues and soccer.
We just have to assume that no matter how good we are creating it. It's just how do we how do we Rectify it? And where do we catch it?
And the other the other thing that's changed is it can't be manual. It can't be a person that stops and does something and says maybe they say has this happened, but they people can't catch it. It's have all the Is happening being created flowing by smaller bits flowing through much more quickly.
People can't check it. We can't have you know inspector 12 look at it and say, you know fruit Loom shipped that ship that there it just people can't do it has to be automated and it can't be the developers job. It's the developer's job and you know shift left and it can't be The developers going to do security for us.
I think well, I have to be to be clear. It it we have to shift left to some degree. What we can't do is Put all of the accountability for that on the developer and that's what I mean shift left can't mean the developer will take care of it resident it, you know, it has to be and again, I mean, I think that the whole concept of Dev SEC Ops really does kind of underline the concept that we're talking many years.
Everybody's got shared accountability shared responsibility to ensure that the code that ends up getting deployed and delivering value to customers is secure and is protected and we're just talking about the front end of it, right? You know, there's also a bunch of runtime stuff you've got to do as well. And so, you know, we can open up a whole can of worms on on kind of runtime stuff.
You still wanna use software of course, right? And we still want to front end, you know, kind of these application Stacks with ways to detect malicious activities. You mentioned crochet scripting you're not getting ready your wife anytime soon, right?
You're not getting rid of API Gateway in the layered insecurity capabilities anytime soon. Right? I mean we need this stuff even if we're better at securing kind of the code in development right in that pipeline.
We still have to protect the runtime. So I mean containers are all code too. Right?
So we've got to have one time monitoring in our container environment. So it's not an either or thing right? It's both we want to integrate it in from the time you're doing repository.
Hopefully within your IDE to find, you know, kind of just stupid stuff that you're gonna do we want to do security validation and testing when we go through integration through deployment and we want to front end these applications with protection capabilities to get rid of things like denial service or you know, again kind of buffer overflowing and some of this stuff that you're not brain surgery attacks, but it'll still lock your damn application down if you're not careful and and if you don't pay attention to those things, so yeah, we we do see progress. I don't want to be clear about. Oh, yeah progress.
He did the fact that we have security engineers and software Engineers working on the problem maybe together maybe in the same space as huge and the fact that security you've heard me say this before the fact that security has turned the page and said we need to know something about what's going on in software and how we secure. It may not be the software experts, but we're gonna figure out how to help Is massive, you know, I think the other thing I've been thinking about Mike. And I don't know if this would have come up in our talk but you know, I run our infrastructure and you know, we do some development law not a lot a little bit of development here, but we use a lot of Technology as part of tech strong and all the sites and services and events and all that stuff.
And of course we constantly get notifications. There's a vulnerability in this plugin in WordPress is a vulnerability in this Library, you know, we think we're you're using it or it's a library that some piece of whatever you use uses and you know, I could spend my whole day chasing down in in every one of those and seeing if it's something that we have to worry about so I just came out to folks on my team and they go do that and I'm just kidding but you know in a way that no you actually you're not kidding, but Trying to make myself feel better. But yes, that's what I do.
It's sort of that's got to be that's got to be solved too. Right? So those notifications from trusted sources need to flow into the software creation process and say we're gonna flip out this library or this Plug-In or we're gonna test this in the next pass for you.
This is happening by the way, you know, and that has to be part of this too because we can't manually follow every piece of every chip and software chip in our software Hardware, you know analogy to through the whole process. It's just not humanly possible now, and and I think that what you really alluding to is, you know, kind of the last school that I wanted to talk about, right we talk about, you know, kind of building it in on the front end, you know through the pipeline really get into a deaf Secaucus motion. We talked a little bit about, you know, kind of front ending and some of the runtime capabilities that you need in your prod environment to ensure that Again, the applications aren't being misused and the last you know, really leg of that stool is kind of cultural accountability.
Mmm, right so it's it's really making sure that again you're it's okay to break the build if you have a huge problem. It's okay. We have to have some mechanism to deal with the defects that we find again may not be your defect right that really pisses off developers.
There's a library that you know kind of is is again turned out to be vulnerable, you know walk for show off for Jay whatever, you know kind of component you're using in the latest, you know iteration of that. That's not your fault. Right, but your code is gonna get bounced back and you got to kind of go through the whole process again, and that's irritating and I get it.
But it's the stuff that we have to do and we have to be okay breaking bills. We have to be okay, you know kind of forcing stuff to go through the testing process again when things are found to be vulnerable. We have to be okay with service levels and service level of objectives for how quickly we're gonna fix some of these things because the idea of the security defects below to the bottom of every, you know spring because it's just not that interesting to folks we can't have that right we can't have that.
We have to be in a situation where we can fix these things and again, I mean, I think that that's a logical next Evolution to where we're going with these deaf set up some ocean. So let's get it built in what store to understand that then we start chipping away at the cultural things and the security folks still do they run time stuff? Because that's what we've always done and I think that's a lot of what our day to day.
Hands-On stuff is gonna be when I think to my earlier Point as much as that flows into the process as much of his automated. Okay, then it doesn't fall to the bottom to list every time right some of it happens because it needs to happen. Right and it may stop the bill at point where it stops the building things get fixed shockingly enough, right?
It's the well, we can't do that or all we've got to ship it or you know, or this is you know critical feature for customer and we have to you know, do that that's what you get into again some of these you know, what turnout in hindsight to be bad decisions at the time. You just like I'm just trying to get stuff done right? I'm trying to get code deployed.
I'm trying to make a customer happy and you know hindsight, you know after you know, your stuff is all over Eastern Europe. You're just like, oh maybe that was it great, you know idea. I want to add a new segment to our to our review and that is you know, I gotta beef.
All right. What's your beef if you I can't but I was just astounded it couldn't believe it that I heard that in the T-Mobile. You know reach we weren't breached.
We weren't hacked. It was an API. Oh my God.
I don't ever want to hear that again. That was the most ignorant statement in an S1 or whatever their annual for whatever was yeah. It was it was able someone it was it was so I I was insultry about this in you know, I kind of covered API, you know issue and I wrote some on Boulevard and you know, I kind of objected more to their framing of it as API abuse as opposed to you know, it's again, it's kind of like victim shaming at that point.
It's just like, oh I wasn't to blame. No dude if you leave your door open and somebody takes your stuff that's you right. And again, we don't have a lot more details, but you know, I'm pretty sure it had to do with you know, apis that they didn't know about or having protected adequately leave the door open somebody comes in and loot your house and You know, you're shocked on your shop that somebody would do that.
I'm shot don't be shocked right people have been stealing stuff from other people for about 3,000 years. So this is no different than that. Leave your door open.
Somebody's gonna come in and take your stuff. Um, but framing it in a way that it's API use as opposed to, you know, the fact that we had poor practice in terms of protecting our API. That was that was pretty offensive to me because there were people who suffer like real abuse.
Okay? Yeah that, you know, just manipulating that term in order to you know, try to elicit some measure sympathy. Yeah, not buying that one not buying that so we're on the same page.
It's just Come on people. We were not stupid. We know what it was awesome.
I usually very positive personal. That was one that I just kind of like, okay, please I'll get this guy. He might right new Happy might for the last couple of years has been you know, I I do have my moments.
Yeah, you know for for sure I definitely have my moments so okay so good. So that's all I got to be segment. If if you happen to have been in Singapore on Friday and you had a time machine and you know, we're able to pull this thing off.
This is probably a bit of what you would have seen. We may have been a little bit more structured. We probably would have had some memes just because I can't do it.
You're the meaning for sure. Yeah means in there. So so we would have had some memes but this is really the topics that we would talk about.
So when we're back in July calm because we're gonna have new stuff to talk about, you know, kind of once we get there now, I don't know who's gonna end up going but but they are planning to do the devops. Good Summit in on July of this year. But what I can tell you where we will be we will be at RSA.
I'm going to talk. I'm pretty sure Mitch is doing a talk. So we are all going to be there for Deaf secops days in in at the RSA conference.
We're doing Tech strong con. That's March 16th. I'm doing both the panel and a talk about, you know, kind of how security can impact digital transformation and then really Ai and we're gonna do a panel on, you know, kind of the impact of ML and AI, you know on security practice.
So there's a lot of stuff going on. I'll be doing a couple of talk in a panel on cloud native and Cloud native architecture and how that's changing the Nature's software and now we build it and the impact to digital transformation. That's right.
So good conference. Yeah, by the way, thanks for everybody who came to predict that was kick, you know what event I mean it was the the people That we had speaking on those panels just phenomenal. So you can check that out.
We have that up on Textron TV actually video it to the Textron conferences. You'll see predict and you can watch it there but it's it's pretty amazing. It's awesome.
Now, we're pleased with that again. There's just so much good stuff going on at text from obviously all of our learning events, you know, five to eight happen, you know every week where we've got really cool topics. You've got all sorts of interviews on text from TV.
So suffice to say there's no lack of content to you know, keep you busy from that standpoint and help you stay on top of what's happening in a pretty complicated technology will so with that Mitch any party thoughts. We already heard your beef. So I don't need to know no more beefs, but for the year thoughts no, it's you know, I think we we still live in a world of best laid plans of mice and men right?
You know, it's it's the same goes Things change so who knows we may be in you may be coming back from Singapore and I'll be going who knows where else it's just that world that we're in and the good thing is, you know, we're all kind of used to being flexible and adjusting and I think that's sort of how we are about technology these days right this vulnerability this issue pops up this new chat GPT or whatever showing up on the horizon and that's a call. So what keeps it interesting. So I think for me I'm just grateful we can go places now very true grow a long time.
We couldn't go places and that totally sucked. So I am, you know, very pleased to be, you know in Asia, you know, hopefully I'll go back soon gonna be doing your we're gonna be doing so there's just a lot of stuff going on which is which is really fantastic. So we're excited to come out see you excited to interact excited to continue to generate a whole mess of content and excited to engage so let us know what you want to see right?
Let us know. What kind of research you know would make a difference in how you do things? We've certainly got ideas but we're are always welcome to get feedback from everybody.
So with that we will sign off everybody enjoy, you know kind of the week ahead and we may what we may try to figure out while I'm away some way to you know, string something together, but we may or may not you know kind of have one next week. But but we certainly will that week after that. We'll do our best we can do our best.
All right. Take Everybody Take Care folks. See you soon.





