Shachar Menashe, JFrog | Yalla DevOps 2022
At Yalla DevOps 2022, Alan spoke with Shachar Menashe, senior director of security research at JFrog, about JFrog’s acquisition of Vdoo and how the merger has changed its scanning tendencies. Alan and Shachar also discuss JFrog’s shifted focus to cloud and open source, as well as the growing prevalence of supply chain attacks.
Transcript
This is texturung TV. Okay, we're back here at yala devops. It looks like maybe a coffee break tea time.
I don't know. There's people out here back again. Not too much noise though.
I'm happy to be joined right now by shakamut minesh. I yeah menachi Chicago's is a security researcher with Jay frog but he came to Jay Frog by way of their acquisition of Badoo, which is a security company. It was also base here in Tel Aviv.
True. Yeah. So Charlotte what first of all thank you for being on with us.
Sure. Second of all, let's talk a little bit about you know, what to do was is About yeah, it's part of Jay frog and maybe some of the research you're doing recently sure. Yeah, so it's a really interesting story actually with video.
We saw that there's a problem in the embedded world like iot and smart devices Etc that unlike all other software. It's being written with very low language code like CC plus, you know, and not you know go or JavaScript or whatever. It's prevalent today in the cloud.
And you know, these languages have a lot of security vulnerabilities much more than the other older and they've been more exploited security wasn't as important. But to be fair also the devices they were put on yeah, they weren't in many ways considered security threats. Yeah, but the problem is that you know, these devices became so ubiquitous that it's like you're security right?
Yeah, exactly like baby monitor security cameras not ovens you name it and these are all things that we've actually, you know researched and the heck to eventually So we actually understood that this world. Like I'm like the mobile world like phones are extremely secure and servers are super secure. But but this embedded world is like the weak link of all software basically.
So we said, okay, we gotta take care of that. So we wrote a product that specializes in scanning embedded binaries and basically like finding both like zero day vulnerabilities in it and known vulnerabilities and configuration issues and such. And the interesting thing is that eventually we saw that most of these techniques are also applicable to you know, not just embedded but also like Cloud native apps Etc.
And that's how we got to talk with, you know, Jay frog eventually we wanted to do a partnership where we don't scan embedded binaries because Jay frog we're all about the binary. Yeah again. Yeah, and we like we do where they only ones that actually were getting binaries as input.
So it was like a really good fit and we wanted to do a partnership but then we understood. Hey what if we just adapt we do stuff from scanning in bed to just more General like scanning Docker images and whatnot. And then we understood that it's worthwhile merge and that's what what happened.
Actually, I still think that we didn't get a chance to solve. The embedded problem and it's still like a huge problem. I believe I really hope there's gonna be more government compliance things about that and like regulations because they're still like most devices that are coming out, you know, if it's not Google or Amazon or things like that.
It's easy mode. I know but you know if history is any guide Generally, the the compliance and regulations are trailing indicators not leading indicators. Yeah.
So until you start having enough security incidents or some politician or some administrators. That's oh my goodness. We need to do something about this.
Yeah, right. It's never hey, we should get out ahead of this before it becomes a problem. Yeah, like unfortunately, I agree.
I just think that it's like a ticking Time Bomb, but it's like that. I agree with you. Yeah, and it's a shame because again with mobile phones, it's like really super secure if you want like, you know to buy a vulnerability on the black market or something like that for zero click.
I fall iPhone remote code execution. It's like I'm already. Yeah.
It's a million dollars because It's so secure right but for for embedded, it's like give me a couple days. You know, that's all it takes. Yeah, so it's a discrepancy that you know, we we need to fix sometime.
Yeah, but now in Jay Frog We because it's much more popular. We are focusing on you know, the cloud things and open source Etc not like embedded proprietor. Oh, yeah, it'll get hard again.
Let's talk about some of your most recent research. Sure. So mostly what's happening is supply chain attacks, like recently on attacks through like package repositories, like npm and Pipi.
They're like spiking in a crazy way because actually because of the same thing I said before because of the ROI for the attacker for an attacker to find actual zero day like again in iPhone or Windows or things things like that. It's crazy. It's again, in the market, it's like hundreds of thousands of dollars, but for a novice attacker to create a malicious package and just put it in npm and say oh this package is really good or actually do it with the type of squatting attack like instead of requests like which is a very popular python package call it request without the s and someone will install by mistake.
It's like free like literally and you know apple and Microsoft and whoever not were hacked by these attacks. So the ROI is just you know attackers are not going for crazy zero days anymore. They're going for this.
So our research team is think about a dozen new malicious packages each. Really? Yeah in npm and Pipi we're trying to see if other ecosystems are affected right now like Maven, we're not seeing malicious packages.
For example. Yeah, go also not much. So we're trying to figure out where the next attack is going to come from maybe nougat ruby gems like things like that.
But like this is the new easy attack Vector for sure. Crazy, yeah, so let me ask you we were talking early. I had Baruch and red here.
We're talking about Persia. Yeah, does that help? I mean that seems to help yeah and everything.
Yeah, because that gives you more content like it's a more concentrated view of the package ecosystem. And you know that whatever is on Persia is the signed and validated Etc. So if you're working with that, you know, you're you're good like you're there's not gonna be type of squatting there and these kind of attacks.
The challenge would be to get as many packages as possible there and validate them and make sure you know, there's nothing malicious Etc. But because it's a gated community versus you know, npm and pi and everything like that then yeah, it's a it's a solution, you know, it will solve it but You know, I'm hoping it will be adopted as much as possible, but it's not a solution for everybody for everybody. Yeah, so we need to solve it also in other ways.
But yeah, I really like the idea there. It's very sound cool. Yeah, so this acquisition went down.
Exit tomorrow is exactly one years one year already. Yeah, we're all about a year. Tomorrow's our birthday.
Yeah. What is what what gets you most excited going forward in this today? Yeah.
So the the coolest thing now that we're J frog is the scale. Because if we do, you know, we had dozens of customers, but here we have thousands. And I think we're doing some unique things like the contextual analysis.
And what what really excites me is, you know, I want to talk with customers and I want to hear that actually say said that oh, I had like a thousand CVS, you know showing with a basic scan, but now, you know with the contextual stuff with the Deep stuff. I understood I only need to fix 20 That's huge. Yeah.
Yeah for sure like that's and it's really hard like as a you know, I'm I'm a security researcher and like I was doing defensive stuff offensive stuff everything and one of the biggest challenges. both in defensive elephants was understanding, you know, you have this huge list of vulnerabilities what can actually use and for me like to be able to actually distill it for a customer and that the customer realizes that hey we cut down like now it's 1% of work. I still haven't gotten that exact feedback from a j-frock customer at least.
Ah, that's like my initial Milestone that I'm really looking forward to good. Yeah just to hear the customer like being really happy with that. Yeah, excellent event.
All right. Hey, we're gonna take a break. I won't check out first of all.
Congratulations on the year here. Thank you. Bob the great work.
We'll be looking for big things. Yeah. Thank you.
Okay. We're at yalla. We're gonna be right back here with another guest just a moment.





