Open Source Trends, Vulnerabilities — And Corrections

The New Stack · Intermediate ·📰 AI News & Updates ·7y ago

Key Takeaways

The video discusses open source trends, vulnerabilities, and corrections, highlighting the importance of engaging with the open source community to ensure security and stability, with tools such as Docker and Java being used to manage and patch vulnerabilities.

Full Transcript

hey Tim hey Alex oh yeah we hate one from your booth to the second floor third floor if out a corner just kind of set up people look at you a little bit about oh I'm actually waiting for someone to show up and just kind of like do one of these things do something just because yeah because of course so you guys just did a survey I'm hearing Tamaki and listen topsis and Tim you've been saying but on the road a lot I guess you've been on the road I think almost a reflection of this it's almost a reflection on the survey you just did as well kind of the research results this survey that you've done on you know your customers and you know nobody users of software components as I understand yeah so that what we released today is the open source security and risk assessment okay this is our fourth edition of this report and so effectively a reflection of the use of open source the composition of open source building up today's application stack so if I'm in a commercial application I'm not just writing my own code I guess I am but I'm going to using libraries that are available from the source I'm going to be building on top of frameworks that are available to me that give me all of the value that I want to have while allowing me to uni and whatever my three mission set is so that's the basis of the the Oscar org and so it looks at what we are the block that audit services team have seen in the real world in C type activity okay ceremony visa type activity are one of your targets so we have one extra business so that's one aspect of our business someone wants to go in a fly or a company brand they're going to spend X number of tens or hundreds of millions of dollars on this they want to have some aspect of confidence it says you know what the IP that I'm buying is what I understand it to be I know that if its course is going to be part of the equation today what's the line between what is the unique IP versus the open-source components that are in here what is development acumen how old it is because I did these patch properly where do they come from are they still being maintained a lot of these types of questions are the things that we can answer and of course do I have appropriate licenses their provenance behind this code that allows me to go forward and say aha I'm going to execute this so so what are you finding is the code is the code working out there the code is very much working out there we're seeing a growth in open source adoption we have an uptick in the number of open source components per codebase last year was pretty significant we saw a decrease in the number of vulnerabilities that were unpatched those are all positives yes we did see our share of negatives as you kind of would expect yeah um one of the most notable being that we had a pretty substantial number of components that were just ancient they were half four years old there was no development activity last couple years and with the velocity of everything today that is truly ancient and the chance I thought libro is a oh no I'm gonna give you an even better example give you an even better example in a second but what we found it is that when we peel back the onion people think that there's a vendor that there's this vendor of open source custom thinking how would you bring software libraries of one form or another into your supply chain it's like well I go to Microsoft and I buy the code by the compiler that comes with these things and Microsoft knows that again I exist because I bought this shop dates to I kind of push networks and shifting the paradigm to being an engaged one is really where we're seeing the companies that did well and improving things understood that I have to be engaged within the Oakland Swiss community I have to be willing to invest develop the time to understand what the latest and greatest evolutionary genetics or so theoretically you can't ignore the community Taron open source components you absolutely have to be part of the community you have to understand what your critical components are shock check otherwise you end up in here's the really interest there's what were your Friday yeah community one community one we actually had a component that we FreeBSD was like three Persian three three had a vulnerability that was disposed in 1990 all right so half of the developers at this conference were probably not even born when this vulnerability was disposed what was it it was vulnerability in the was a buffer overflow okay in how termcat was processed turn cap give us a give us every ability of a text-based remote well those tax base terminal did have a place in the market back in nineteen ninety exactly those little workstations and so this was very simply a straight-up buffer overflow if you put the wrong amount of data into it if you put too much text into it just go fine exactly and so FreeBSD much more modern versions are available today was what was working yeah one of the other problems that we see a thing if it ain't broke don't fix is I find him selling used to just find them just way back in the plaza so this was still in use housing uses it was quite literally this is the platform on which the software is being deployed hmm and at the end of the day it wasn't broken hmm so nobody saw any real need to update it and yes it probably fell in their minds into the legacy camp but this is probably the assets although they acquired and so there's so many songs exactly how do you update from that times on my side it's like the nineties the 2000s were great well now approaching 2020 and we have server list and now we have server less and the paradigm shifts all the way through and so one of the biggest things that we saw in terms of just the components and use jQuery rules the waste when it comes to web-based applications we saw no ended versions there easy chambers if it's everywhere there were Forks upon forks upon forks of jQuery and ok it's the way the world sees to build their web based applications mmm second second biggest thing was an actual so it was in the jackson code the data bind issue where they the community attempted to fix the issue three separate times three separate times it was basically how do i d-- serialized data we serve in a polymorphic men so in other words I have this data set that's coming in from something else and I want to deserialize it and I have enough knowledge to be able to perform this task no turns out that there was a security issue with it they patched it didn't realize the scope of it passed it a second time still ran into a problem decided that it was probably a whole lot easier if they refactored the code and so we saw separate code bases with each of those three vulnerabilities in an unpatched state again that's a case of not necessarily being engaged within the Jackson community to know that this is what's happening and that there might be exposure what was Jackson I go Jackson is part of a data binding set of libraries how can I do transformation of Java data structures into and that couldn't adds more relevant now yeah give me no and it has historically yes what are some emerging Travis then do you see coming out of your own research so the the core thing that we see is that the more modern new code bases target so if it's targeting an IOT device or if s targeting say a mobile application what we see is that the overall let's call it acumen is much better but the velocity of development now starts to prioritize new feature functions over keeping up-to-date with whatever they had relying security and development velocity V of this most components okay so we see the mid sugar velocity as a is it as an issue so if you got C fast or is it SS think is what it means so if you say have 300 components that are open source in your project and they're all independently evolving and they're all potentially independently going to issue updates or security fixes or whatnot knowing when to go and take what set of patches becomes a hurdle to challenge more so when you think about how there might be incompatible patches so it's not a case of hey I'm going to have a patch library someplace and I'm going to pull from an amount really going to be able to patch it yeah yeah so and this gets back to the vendor mentality that a lot of people have yeah we're gonna fix it the vendor will fix it or there's one patch out there so let's say that you have a vulnerability that's an open SSL and there's redhawks version of it there's IBM's version of this canonicus version of it in their substrate nice and simple four scenarios can you take a patch that the Debian community created and that nominally might be compatible with Ubuntu and apply it to Reddit might work might not work can you take an upstream patch and apply it to read has version type in SSL might work might not work but in the vendor centric world there's only what would come from whoever were paying the money to and because open-source doesn't necessarily have a change of currency they don't know how to obtain those patches or where they should be coming from that's also one of the big things that we saw how did container technology is fare kind of in your your findings did you learn anything we just have this incident you know with docker hub and I then the connection is just time it's just the kind of where we are right now this happened last weekend so in this particular analysis that we did we weren't specifically looking at container technologies what we've historically seen is that organizations view the base image in a container as quote somebody else's and so they worry about their coat and oh I've got a base image that just works and if you actually peel back the onion and ask them a question what's in that Basin range why do you require these userspace components what we end up with is it works it does what I needed to do but does it have extra stuff is it potentially configured correctly in a secure manner whatever correctly might be in that industry that requirement well I'm really worried about my application that's somebody else's development and at that level it becomes a trust factor so we like the official images that are available backup but even if you take an official image that was probably updated a few weeks ago and that official image might not have all the latest patches and so you have to make certain that your docker file is taking care of whatever your match management strategy is otherwise you can get out of date just as easily as having VST from 29th uh-huh and it really is a question of awareness right so that organization that was to tend to have that old version of BSD they didn't see the problem it worked for them and did what they needed it to do much in the same way as that's the context exactly the base images kind of is historically something that no one really wants to take responsibility for our many response / correct and so Dockers done a pretty good job of taking responsibility for some of it mm-hmm and is working with various open source communities to have the official versions have them appropriately security tested have them appropriately signed and those are all important steps but those are all pointer timing events so if I go and I take that container image that I'm going to use it's my base image from a few weeks ago if I'm not aware what's in there there could be a very serious vulnerability that is available to malicious act and if that awareness that we really want to highlight open source is good powers the world but you have to manage it appropriately otherwise you could be caught off guard Disney visas yeah becomes greater she T is continuous integration continuous delivery systems go up as well with auto builds and I mean how how well you keep updated right versus Roth one versus you know this is a lot to it exactly and so understanding exactly what the capabilities are so let's say that you had a library that only understood it off you on any longer bring it up to a more modern environment you're probably not going to be able to just drop it in that place and have everything work you're going to have to refactor your code in some capacity in order to do the right things and actually process two things directly and so for that level of complexity gets more difficult to progress with when you're further out of date so if you take that example of code that had been patched and had no development for two years was that actually a main master branch that the code originated from or was that someone stork and that someone did what they needed to make their application work and so with that level of doneness and community engagement that's really the hallmark of right if it comes down to kind of like how branching do you get exactly like I the canonical example that I use in a lot of my talks is in my house I assert that there's probably close to a dozen different versions of OpenSSL between phones and thermostats and DVRs or TVs and so forth most of them all have no way of knowing exactly what version they are because it's opaque it's coming from say my satellite provider my TV that sort of thing but there's also no single catch oh this is interesting so tell us a little bit conclusion on the study and you know what are your what are your plans now we continued to do the research are you is this an annual exercise its historical from some black text days it is historical from Black Codes days this is the fourth version of it and we're going to continue doing it on an annual basis what we see in terms of core conclusions number one you can't patch something that you don't know you have so forget the whole tooling side of the equation if you don't have at least a reasonably up-to-date inventory of whatever's in the code you can't even make a determination as to this is an important community for me to engage with this is something that I need to be managing differently those are questions you can't assess once you have that inventory then it needs to be the responsibility of somebody to develop and implement policy to keep things up to date four digits the security aspect of it just keeping it up to date so that as you have the potential to do so you can yeah and then the the last piece of this is very much engage with the communities because the communities are there but they don't push information they have it's a pull mechanism and open source if they don't know that you're dependent upon this they have no way of letting you know that hey you know what we've decided that we're end-of-life in effectively aversion to of something and we're going to put all of our energy into first with great and if you don't know that's happening you could be left holding something you didn't and so so I guess it doesn't like how do you you know what are your proxies for keeping in touch because you need proxies at some point and so that's where the prioritization really comes in like if you're using a lot of doctor technology that's fantastic do you want to be an upstream talker and work with the movie project awesome let's get some of the developers engaged in it maybe it's also an opportunity to say is it worth paying Gawker the company to actually relieve some of that risk because this particular organization have two semester support exactly and same thing with a red cat or an IBM and you can proxy through them a lot of the source governments and then contain and control the pieces thank you for the answer Jim thank you very much for taking some time to talk it's been a lot of fun you know I appreciate you know you having the patients here but this is nice enough for that I like it oh yeah it's nice and quiet up here not too many people have come by yeah yeah they haven't interrupted us or me alright well thanks a lot

Original Description

The fourth-edition “2019 Open Source Security and Risk Analysis” Synopsis recently released revealed a number of trends relating to open source security, licensing and compliance. Many of the trends proved to be positive — but there is also some negative. Among the misconceptions is a common misunderstanding of how open source code is used and shared. "Once you pull back the onion, what we've found it is that people often think that if there's a vendor of open source. They are accustomed to thinking about how to bring in software libraries in one form or another into your supply chain," Tim Mackey, principal security strategist for the Synopsis Security Research Center,  said. "'They say, well, I go to Microsoft and I buy the code, and I buy the compiler that comes with these things. And Microsoft knows I exist because I bought this...I kind of push back and say 'that's not how open source works.'" In this interview recorded during Dockercon in San Francisco, hosted by Alex Williams, The New Stack founder and editor in chief, Mackey discussed other findings of the report, after having also taken the pulse of the open source community today.
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from The New Stack · The New Stack · 0 of 60

← Previous Next →
1 What's Next for the Cloud Foundry Foundation in 2017 with Executive Director Abby Kearns
What's Next for the Cloud Foundry Foundation in 2017 with Executive Director Abby Kearns
The New Stack
2 How Unikernels Can Better Defend against DDoS Attacks
How Unikernels Can Better Defend against DDoS Attacks
The New Stack
3 Weaveworks is Bringing Horizontal Scaling to Prometheus
Weaveworks is Bringing Horizontal Scaling to Prometheus
The New Stack
4 TNS Analysts Thanksgiving Special: The Evolution of Kubernetes and the Container Ecosystem
TNS Analysts Thanksgiving Special: The Evolution of Kubernetes and the Container Ecosystem
The New Stack
5 How Rancher Labs is Seeing Kubernetes Put to Work in Production
How Rancher Labs is Seeing Kubernetes Put to Work in Production
The New Stack
6 SAP Tests Kubernetes for Cloud-Native Enterprise Software Deployments
SAP Tests Kubernetes for Cloud-Native Enterprise Software Deployments
The New Stack
7 Event Marketing for Today's Developer Evangelists and Community Managers
Event Marketing for Today's Developer Evangelists and Community Managers
The New Stack
8 NodeSource Introduces Certified Modules to Improve Node.js Security
NodeSource Introduces Certified Modules to Improve Node.js Security
The New Stack
9 How Lightstep is Illuminating the Case for Distributed Tracing
How Lightstep is Illuminating the Case for Distributed Tracing
The New Stack
10 How OpenStack Aims to be More Inclusive without being Exclusive
How OpenStack Aims to be More Inclusive without being Exclusive
The New Stack
11 How Shuttlecloud Saves Time and Money by Monitoring with Prometheus
How Shuttlecloud Saves Time and Money by Monitoring with Prometheus
The New Stack
12 Creating Analytics-Driven Solutions for Operational Visibility
Creating Analytics-Driven Solutions for Operational Visibility
The New Stack
13 Understanding the Application Pattern for Effective Monitoring
Understanding the Application Pattern for Effective Monitoring
The New Stack
14 Building On Docker's Native Monitoring Functionality
Building On Docker's Native Monitoring Functionality
The New Stack
15 The Importance of Having Visibility Into Containers
The Importance of Having Visibility Into Containers
The New Stack
16 How Getting Your Project in the CNCF Just Got Easier
How Getting Your Project in the CNCF Just Got Easier
The New Stack
17 Tectonic Summit Pancake Breakfast: How to Sell Kubernetes to the Hypervisor-Minded
Tectonic Summit Pancake Breakfast: How to Sell Kubernetes to the Hypervisor-Minded
The New Stack
18 The Buzz at Tectonic Summit 2016 in New York City
The Buzz at Tectonic Summit 2016 in New York City
The New Stack
19 Bringing Clarity to the Future of Node.js Modules
Bringing Clarity to the Future of Node.js Modules
The New Stack
20 How FluentD Can Help Monitor Microservice Architectures Through Unified Logging
How FluentD Can Help Monitor Microservice Architectures Through Unified Logging
The New Stack
21 Reshaping Front End Development with Warehouse.ai
Reshaping Front End Development with Warehouse.ai
The New Stack
22 2016 Year End Wrap-Up: Discussing Docker, OpenStack, and Open Source
2016 Year End Wrap-Up: Discussing Docker, OpenStack, and Open Source
The New Stack
23 Here's Why You Should Build a Robot Using Node.JS: Because You Can
Here's Why You Should Build a Robot Using Node.JS: Because You Can
The New Stack
24 How the Node.js Foundation is Utilizing Participatory Governance Models
How the Node.js Foundation is Utilizing Participatory Governance Models
The New Stack
25 Set Up an MongoDB Replica Set in Less Than an Hour Using Bitnami Packages
Set Up an MongoDB Replica Set in Less Than an Hour Using Bitnami Packages
The New Stack
26 Determining Who Bears the Burden of Ensuring NPM Module Security
Determining Who Bears the Burden of Ensuring NPM Module Security
The New Stack
27 How Intel Snap uses Telemetry and Kubernetes to Drive Enterprise Efficiency
How Intel Snap uses Telemetry and Kubernetes to Drive Enterprise Efficiency
The New Stack
28 How the NFL Scored a Touchdown with its Open Source React Framework Wildcat
How the NFL Scored a Touchdown with its Open Source React Framework Wildcat
The New Stack
29 Aporeto CEO Dimitri Stiliadis: When it Comes to Security, Context is King
Aporeto CEO Dimitri Stiliadis: When it Comes to Security, Context is King
The New Stack
30 The Buzz at Node.JS Interactive
The Buzz at Node.JS Interactive
The New Stack
31 Why Going Serverless Doesn't Mean 'No Ops'
Why Going Serverless Doesn't Mean 'No Ops'
The New Stack
32 How Node.js is Transforming Today's Enterprises
How Node.js is Transforming Today's Enterprises
The New Stack
33 JJ Asghar Interview
JJ Asghar Interview
The New Stack
34 How Capital One is Using APIs to Streamline Auto Financing
How Capital One is Using APIs to Streamline Auto Financing
The New Stack
35 SXSW 2017: How Machine Learning Differs From Regular Programming
SXSW 2017: How Machine Learning Differs From Regular Programming
The New Stack
36 SXSW 2017: Data-Driven Applications with Capital One DevExchange's Hydrograph
SXSW 2017: Data-Driven Applications with Capital One DevExchange's Hydrograph
The New Stack
37 SXSW 2017: How Good Engineers Make Bad Business Decisions
SXSW 2017: How Good Engineers Make Bad Business Decisions
The New Stack
38 CloudNativeCon & KubeCon EU Pancake Breakfast 2017: Kubernetes and the Multi-Cloud
CloudNativeCon & KubeCon EU Pancake Breakfast 2017: Kubernetes and the Multi-Cloud
The New Stack
39 CNCF Executive Director Dan Kohn: What's Next for CNCF in 2017
CNCF Executive Director Dan Kohn: What's Next for CNCF in 2017
The New Stack
40 Exploring the Latest Container Runtime Projects in the CNCF
Exploring the Latest Container Runtime Projects in the CNCF
The New Stack
41 Exploring the Future of the Kubernetes Ecosystem
Exploring the Future of the Kubernetes Ecosystem
The New Stack
42 Kubernetes and Continuous Deployment
Kubernetes and Continuous Deployment
The New Stack
43 Kris Nova of Deis at CouldNativecon/Kubecon in Berlin
Kris Nova of Deis at CouldNativecon/Kubecon in Berlin
The New Stack
44 Docker's Quest for Simplicity with the Evolution of Containerd
Docker's Quest for Simplicity with the Evolution of Containerd
The New Stack
45 Developers First: The Cloud Foundry Service Broker API and Kubernetes
Developers First: The Cloud Foundry Service Broker API and Kubernetes
The New Stack
46 Mapping the Future of CoreOS's rkt in the CNCF
Mapping the Future of CoreOS's rkt in the CNCF
The New Stack
47 Red Hat and Dell EMC: Two Perspectives from DockerCon
Red Hat and Dell EMC: Two Perspectives from DockerCon
The New Stack
48 Capital One Opened its APIs to Third-Party Developers — Here’s What They Learned
Capital One Opened its APIs to Third-Party Developers — Here’s What They Learned
The New Stack
49 SUSE Joins the CNCF, Brings Kubernetes to OpenStack Cloud 7
SUSE Joins the CNCF, Brings Kubernetes to OpenStack Cloud 7
The New Stack
50 How Capital One Brings Open Source To The  Banking Industry
How Capital One Brings Open Source To The Banking Industry
The New Stack
51 OSCON Is Coming Back To Portland, A Show Wrapup With Co-Chair Kelsey Hightower
OSCON Is Coming Back To Portland, A Show Wrapup With Co-Chair Kelsey Hightower
The New Stack
52 Dev Or Ops Doesn’t Matter, You Need Observability
Dev Or Ops Doesn’t Matter, You Need Observability
The New Stack
53 Taking The Next Steps In Developing An Open Source Culture
Taking The Next Steps In Developing An Open Source Culture
The New Stack
54 SXSW 2017: How Capital One Became Technology-First With Open Source
SXSW 2017: How Capital One Became Technology-First With Open Source
The New Stack
55 Apcera   Old Apps Spanning New Clouds
Apcera Old Apps Spanning New Clouds
The New Stack
56 Provenance: The Peace of Mind Chef Habitat Seeks to Deliver
Provenance: The Peace of Mind Chef Habitat Seeks to Deliver
The New Stack
57 InSpec: Human Readable, Automated Compliance
InSpec: Human Readable, Automated Compliance
The New Stack
58 The Evolution of SAP HANA Express
The Evolution of SAP HANA Express
The New Stack
59 Women Engineers Who Inspire And Never Give Up
Women Engineers Who Inspire And Never Give Up
The New Stack
60 Three Perspectives on the Evolution of Container Security
Three Perspectives on the Evolution of Container Security
The New Stack

The video discusses the importance of engaging with the open source community to ensure security and stability, and highlights the need for inventory management and community engagement to manage open source dependencies and risks. It also emphasizes the importance of prioritizing security and development velocity.

Key Takeaways
  1. Engage with open source communities to stay up-to-date with security patches
  2. Use tools such as Docker to manage and patch vulnerabilities
  3. Prioritize security and development velocity
  4. Use inventory management to determine which open source projects to engage with
  5. Consider paying for support to alleviate risk
💡 Ignoring open source vulnerabilities can lead to serious security risks, and engaging with open source communities is key to managing security and development velocity.

Related Reads

📰
HEMN Technologies
Learn how HEMN Technologies is redefining the approach to AI adoption in businesses, focusing on a more proactive and innovative strategy rather than just adapting to AI.
Medium · AI
📰
Google and Ford are funding a push into the trades, the jobs their AI can’t do
Google and Ford are funding a push into trades jobs that AI can't do, highlighting the need for skilled workers in areas like electrician and technician roles
The Next Web AI
📰
$130 Billion In AI Data Centers Stalled. The Bottleneck Is Consent
$130 billion in AI data center projects are stalled due to local opposition, highlighting the need for developers to prioritize community consent
Forbes Innovation
📰
Global Trade Dynamics Q3 2026 — Geopolitical & Macroeconomic Analysis
Analyze global trade dynamics using AI and data analysis to understand geopolitical and macroeconomic trends
Dev.to AI
Up next
This 1 SEO Fix Helped This Site Recovers From Google Core Update
Techjackie
Watch →