Demo: Cosmonic's WebAssembly Module for Security
Skills:
AI Security80%
Key Takeaways
The video demonstrates Cosmonic's WebAssembly Module for Security, showcasing its isolation and sandboxing capabilities at the file level, and discusses the benefits of WebAssembly in security, including its ability to prevent attacks and provide runtime level security. It also highlights the role of WebAssembly in composable distributed applications and its potential to become a ubiquitous tool in the future.
Full Transcript
[Music] and actions hey everyone here at the cloud native security conference hosted by the Linux Foundation we'll be doing demos here today and my first guest is Kevin Hoffman CTO and co-founder at cosmonic hi Kevin how are you doing pretty good you're going to give us a little demo as I understand so we're going to see cosmonic and I also want to hear about the advantages of webassembly with Cloud security okay and security overall we know that webassembly is allows for isolation and sandboxing we hear a lot of very traditional techniques being used by vendors in particular to approach security I would love to hear kind of this alternative view webassembly but let's take a look at cosmonic like you said one of the big benefits of webassembly is the sandbox and the isolation at the file level the web assembly module itself is completely isolated can't talk to the operating system uh can't talk to the host's memory uh that's all shared in sandbox that's all isolated and sandboxed and that's the the file level security then there's the runtime level security above that where you need a run time to run a web assembly model right and so whether that's a browser or whether that's uh you know like an edge mod runtime or wasm cloud or cosmonic those runtimes are responsible for enforcing higher level security and um the in the talk that I'm going through tomorrow in addition to the the core webassembly security the open source wasmcloud project adds another level of security on top of that and then uh cosmonic adds even more security as well as TurnKey hosting what is the uh do you think the deficiency in this approach that we're seeing with for instance with s-bombs for example yeah there's really two ways to to deal with this problem and it's either reactive or proactive right and a lot of the tools that we have now whether it's you know like the the docker notary or observability and management we we see when someone when the burglar is in the house you get notified when the door opens or the window breaks but there's nothing we can do really I mean there are precautions we can take but most of the time we're basically sitting back and waiting for someone to break in and then we catch them in the act right and what I like about the potential future that webassembly gives us is the fact that a vast majority of the attack vectors are just physically impossible on webassembly so instead of me sitting back and waiting to be told when someone's broken into my house I'm confident that under most conditions nobody's going to be able to break into my house anyway excellent well let's go through the cosmotic demo and perhaps you can provide some color on how this compares to other Solutions so for some context in case people aren't really all that familiar with webassembly uh what I have on this screen uh what I'm wiggling over here is a webassembly module that takes in a web request adds a number to a counter in a key value store and then gives me the data back so it's just a simple you know uh this is like your your classic hello world microservice the difference is that because this is a webassembly module I have an enormous amount of security built on top of that so when I when I click on this thing you'll see that this webassembly module has a public key which means it's been signed with uh you know asymmetric encryption so I can verify the issuer of every one of these webassembly modules I can verify when it was issued uh when the the signature expires all that stuff but in addition I can also verify that this thing is allowed to use a web server and it's allowed to use a key value store so you know you you sometimes you have tools at the really low level where you know you decide whether or not a microservice can use a particular socket or a particular Port yeah but at that level there's really nothing that tells you why it's using that Port okay some Services need access to TCP ports for benign reasons and so it's really hard to try without you know inspecting the content and all that stuff trying to block it at that level so at the webassembly runtime level we control whether or not this thing is allowed to use a web server or whether it's allowed to use a key Value Store okay and one of the other subtle benefits here is because this webassembly module can't actually talk to the operating system or you know make its own socket requests or have any interaction with the real Network it has to go through a um you could call it a side effect or a non-functional requirement but we we tend to refer to them as capabilities so this web server here is not actually part of my deployment product so in the the quote-unquote old way of doing things if I deploy a microservice the web server that I use is embedded in it the database that I use is embedded in it all of my dependencies are part of that package it's that phrase where you own your dependencies well in this case I can actually Swap this web server at runtime without my code ever knowing the difference I can swap in a real database for a test database or I can change from redis to Cassandra all at runtime because of the isolation from the webassembly module which you couldn't do in a traditional approaches but it will require a lot of configuration yeah so the way the the problem you generally have when you want to support something like that is if you're going to change from one database to another you have to go into your code change the client library and then refactor all of your stuff that used to the client library or you have to build all these you know bloated anti-corruption layers in the code but what we don't have to do is change our deployment artifact anymore and so in addition to you know like for the like the log for J vulnerability right right with that uh you know let's say there was uh vulnerability in one of these providers right now I can change that in the provider once and all of my deployed units uh that are currently running in production will automatically upgrade to the newest capability without me having to recompile refactor redesign or redeploy okay so is that the the the the foundation for what you offer at cosmonic yep so at the uh so at the bottom level you've got the core webassembly standards and then above that you have was implied the cncf open source project right that enables the um ability to build composable distributed applications out of webassembly modules right and then cosmotic lets you build them on uh infrastructure you don't have to manage and there's some other interesting stuff but you see how I've got this host here yeah this is an abstract concept of a host it's not actually like a physical thing it's not an easy two instance it's not a VM you can't even really say whether it's a firecracker or not but it's running inside cosmonic right if I if I had run this other command Cosmo up in my my on my laptop my laptop is now a part of cosmonic's infrastructure and I don't have to use complex tools like with kubernetes and uh telepresence and I don't have to deal with like vpns and proxies I can just stand up compute on my laptop verify that everything works move the compute into the cloud and then shut my laptop down and uh it's all set last question I have then is what's the barrier of entry for people with webassembly what what's going to tip it to like for do you think for for it to really kind of really take off and people see that value that you're talking about this may be uh an interesting opinion but I think when you're going to see that Tipping Point is when we no longer have web assembly dedicated conferences webassembly will be an implementation detail for right security and Dev tools and right and Cloud native and so it'll be you know just a check box you tick in vs code or something else okay once it hits that level of ubiquity then that's where the the Tipping Point's going to be we're already seeing some of the momentum gathered from uh you know companies like cosmonic and the evolution of some of the applications that you can run in the browser and so as more people start to realize webassembly is uh Cloud native tool more than a browser tool yeah and I think that's where yeah that's where the path is going to go Kevin thank you so much for taking the time oh no problem glad to be here if you like this video please give us a thumbs up and if you'd like to see more videos like this you can always subscribe to our YouTube channel we're on all the major social media platforms you can always find it's at the newestack.io we hope to see you soon foreign [Music]
Original Description
One of the big benefits of WebAssembly is the sandbox and the isolation.
“So even at its smallest level, at the file level, the WebAssembly module itself is completely isolated, can't talk to the operating system, can't talk to you. The host’s memory, that's all shared. And the sandbox, that's all isolated and sandboxed,” said Kevin Hoffman, chief technology officer at Cosmonic, during his demo presentation of the Cosmonic platform at February’s CloudNative SecurityCon in Seattle.
There’s the file level security and the runtime level security above that where you need a runtime to run a WebAssembly, Hoffman said. And that is where Cosmonic comes in. “WebAssembly will be an implementation detail for security and dev tools and cloud native and so it'll be just a checkbox you tick in VS code or something else.”
Check out Kevin’s demo and find out more about how Cosmonic, and other companies like it, are starting to realize WebAssembly is a cloud native tool more than a browser tool.
And, read the latest from Cosmonic’s Liam Randall about WebAssembly in the New Stack article “How WebAssembly Offers Secure Development through Sandboxing.” https://thenewstack.io/how-webassembly-offers-secure-development-through-sandboxing/
Kevin Hoffman (Linkedin): https://www.linkedin.com/in/%F0%9F%A6%80-kevin-hoffman-9252669/
Cosmonic website: https://cosmonic.com/
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from The New Stack · The New Stack · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
What's Next for the Cloud Foundry Foundation in 2017 with Executive Director Abby Kearns
The New Stack
How Unikernels Can Better Defend against DDoS Attacks
The New Stack
Weaveworks is Bringing Horizontal Scaling to Prometheus
The New Stack
TNS Analysts Thanksgiving Special: The Evolution of Kubernetes and the Container Ecosystem
The New Stack
How Rancher Labs is Seeing Kubernetes Put to Work in Production
The New Stack
SAP Tests Kubernetes for Cloud-Native Enterprise Software Deployments
The New Stack
Event Marketing for Today's Developer Evangelists and Community Managers
The New Stack
NodeSource Introduces Certified Modules to Improve Node.js Security
The New Stack
How Lightstep is Illuminating the Case for Distributed Tracing
The New Stack
How OpenStack Aims to be More Inclusive without being Exclusive
The New Stack
How Shuttlecloud Saves Time and Money by Monitoring with Prometheus
The New Stack
Creating Analytics-Driven Solutions for Operational Visibility
The New Stack
Understanding the Application Pattern for Effective Monitoring
The New Stack
Building On Docker's Native Monitoring Functionality
The New Stack
The Importance of Having Visibility Into Containers
The New Stack
How Getting Your Project in the CNCF Just Got Easier
The New Stack
Tectonic Summit Pancake Breakfast: How to Sell Kubernetes to the Hypervisor-Minded
The New Stack
The Buzz at Tectonic Summit 2016 in New York City
The New Stack
Bringing Clarity to the Future of Node.js Modules
The New Stack
How FluentD Can Help Monitor Microservice Architectures Through Unified Logging
The New Stack
Reshaping Front End Development with Warehouse.ai
The New Stack
2016 Year End Wrap-Up: Discussing Docker, OpenStack, and Open Source
The New Stack
Here's Why You Should Build a Robot Using Node.JS: Because You Can
The New Stack
How the Node.js Foundation is Utilizing Participatory Governance Models
The New Stack
Set Up an MongoDB Replica Set in Less Than an Hour Using Bitnami Packages
The New Stack
Determining Who Bears the Burden of Ensuring NPM Module Security
The New Stack
How Intel Snap uses Telemetry and Kubernetes to Drive Enterprise Efficiency
The New Stack
How the NFL Scored a Touchdown with its Open Source React Framework Wildcat
The New Stack
Aporeto CEO Dimitri Stiliadis: When it Comes to Security, Context is King
The New Stack
The Buzz at Node.JS Interactive
The New Stack
Why Going Serverless Doesn't Mean 'No Ops'
The New Stack
How Node.js is Transforming Today's Enterprises
The New Stack
JJ Asghar Interview
The New Stack
How Capital One is Using APIs to Streamline Auto Financing
The New Stack
SXSW 2017: How Machine Learning Differs From Regular Programming
The New Stack
SXSW 2017: Data-Driven Applications with Capital One DevExchange's Hydrograph
The New Stack
SXSW 2017: How Good Engineers Make Bad Business Decisions
The New Stack
CloudNativeCon & KubeCon EU Pancake Breakfast 2017: Kubernetes and the Multi-Cloud
The New Stack
CNCF Executive Director Dan Kohn: What's Next for CNCF in 2017
The New Stack
Exploring the Latest Container Runtime Projects in the CNCF
The New Stack
Exploring the Future of the Kubernetes Ecosystem
The New Stack
Kubernetes and Continuous Deployment
The New Stack
Kris Nova of Deis at CouldNativecon/Kubecon in Berlin
The New Stack
Docker's Quest for Simplicity with the Evolution of Containerd
The New Stack
Developers First: The Cloud Foundry Service Broker API and Kubernetes
The New Stack
Mapping the Future of CoreOS's rkt in the CNCF
The New Stack
Red Hat and Dell EMC: Two Perspectives from DockerCon
The New Stack
Capital One Opened its APIs to Third-Party Developers — Here’s What They Learned
The New Stack
SUSE Joins the CNCF, Brings Kubernetes to OpenStack Cloud 7
The New Stack
How Capital One Brings Open Source To The Banking Industry
The New Stack
OSCON Is Coming Back To Portland, A Show Wrapup With Co-Chair Kelsey Hightower
The New Stack
Dev Or Ops Doesn’t Matter, You Need Observability
The New Stack
Taking The Next Steps In Developing An Open Source Culture
The New Stack
SXSW 2017: How Capital One Became Technology-First With Open Source
The New Stack
Apcera Old Apps Spanning New Clouds
The New Stack
Provenance: The Peace of Mind Chef Habitat Seeks to Deliver
The New Stack
InSpec: Human Readable, Automated Compliance
The New Stack
The Evolution of SAP HANA Express
The New Stack
Women Engineers Who Inspire And Never Give Up
The New Stack
Three Perspectives on the Evolution of Container Security
The New Stack
More on: AI Security
View skill →
🎓
Tutor Explanation
DeepCamp AI