Code Patrol scrutinizes the month’s tech scene with code-colored glasses. Computer security industry veteran Lisa Vaas chats with guests about all things security — be it cybercrime, hacking, DevSecOps, and beyond — that collide with the code that runs the world.
CycloneDX — one of the most popular standards for describing the components of a software application, including source code binaries, libraries and containers — was created because modern software is a glued-together glob of third-party and open-source components that are rigged up “in complex and unique ways and integrated with original code to achieve the desired functionality,” as OWASP explains.
The situation as it currently stands: Software is a black box. Lord knows what those components are, nor whether secure processes were used to cobble the bits and pieces together, nor whether potentially vulnerable bits are even invoked by the application. There’s no manufacturing bill of materials to tell you how it was cooked up. There’s no cryptography bill of materials telling you if software employs feeble encryption algorithms — such as the soon-to-be-verboten Triple-DES, enabler of brute-force attacks.
All of this is why the Office of Management and Budget is requiring government agencies to collect cybersecurity attestations from the software providers whose services they use, and why OWASP is working to fill in all the blanks with a growing menu of Software Bill of Materials (SBOM) types.
In this episode, Steve Springett, chair of the OWASP CycloneDX core working group, talks about the changes introduced in CycloneDX 1.5, what they mean for software transparency, and what’s coming down the pike in the upcoming 1. 6 release. A teaser: One thing we can look forward to is the Cryptography Bill of Materials (CBOE), which will address whatever wonky cryptography gristle — like Triple-DES — is going into your software soup.
There’s been an ongoing trend to shift left in software development, to shift security testing to earlier in the development process. The rationale: The earlier in the software development life cycle that you find and eliminate the risk, the lower the cost to fix the issues and the shorter the time that your application is exposed. Although it still makes sense in some situations, there’s been pushback about blindly shifting left: It's become clear that there are right ways and wrong ways to do it.
In this Code Patrol episode, we asked two Application Security (AppSec) experts what happens when you shift left at the wrong time, at the wrong place in the development life cycle, and/or without getting communications ironed out.
Contrast Security Chief Technology Officer and Co-Founder Jeff Williams dives into the details with Chris Hughes, Chief Information Security Officer and Co-Founder of Aquia, a Service-Disabled, Veteran-Owned Small Business specializing in cloud and cybersecurity professional services. They drill down into how DevSecOps isn’t about shoving a tool into a pipeline. Rather, it’s about transforming the nitty-gritty work of security, which is still composed of big, monolithic tasks — such as pen testing — that are simply overwhelming. A big part of that transformation: breaking down departmental silos as you overhaul the culture. Their hope: That organizations will ease off the shift-left-or-die approach and instead adopt a new concept called Shift Smart: an approach that’s all about doing security at the point in the software development process when it makes the most sense, which might not be exactly the same for every kind of security role. “It might be different for checking encryption versus checking input validation or back-in connections or whatever,” Jeff says. Shift Smart is about doing security when it's the most cost-effective. Have a listen to hear about the techniques to do that.
Are your employees madly chatting with ChatGPT? Are you even aware of what company or customer data they might be feeding into the proliferation of generative AI gullets? Does your company still need to put a leash on the wild dog of generative AI? Because that’s exactly what Contrast Security has done: We’ve put up electric fencing around the precocious puppies that are rapidly growing into a gaggle of all-data-consuming, non-regulated, slobbery St. Bernards. On July 11, Contrast announced the launch of the Contrast Responsible AI Policy Project, a pioneering initiative in the realm of AI use. In our commitment to democratizing responsible AI practices, we open-sourced our company’s internal AI policy under the Creative Commons Attribution-ShareAlike 4.0 (CC BY-SA 4.0) license. Why? Because it’s essential that we keep our data and our customers’ data safe, and we know that other organizations are in the same boat. In this Code Patrol episode, we invited the authors of the policy — Contrast Chief Information Security Officer David Lindner and Sharron Reed Gavin, Contrast’s vice president of Operational Risk and Data Privacy Officer — to join us to discuss why they thought we needed a policy around responsible use of this exciting, rapidly evolving technology … and why they think you need one, too.
You’re jamming security, development and operations into a triple-decker sandwich that, in a perfect world, spreads security practices onto the software development and delivery processes and gets your software out the door more efficiently. What could possibly go wrong? Lots, says Jimmy Xu, leader of Trace3’s DevSecOps practice. But isn’t security like mayonnaise? Just glides right on? Nope, Xu says in our podcast, and you’ll find that out quickly if you’re trying to push responsibilities around without an open mindset and a good operating model. It all starts with communication, he says. You need the right frame of mind to talk to all the people whose lives you’ll be affecting: not just the developers who’ll be doing things outside of their normal routines, but also the security experts who want to offload tasks. It’s an exercise in building trust and empowering all the stakeholders.
Did he catch a walleye? No! He caught nothing! Did he crouch next to a hole drilled through 5’ ice on a -65° F morning anyway? Yes! Did we ask him why? No! We just figured this is what people from the Midwest do! To find out more about the guy who keeps Contrast phish-free and sometimes fish-free, check out the podcast.
Get ready to dive into the high-pressure world of technical support with true tales from the on-call support crypt! Join us as we sit down with seasoned software engineer Jacob Mages-Haskins as he reveals the secrets behind the scenes. From late-night emergencies to rapid troubleshooting, we uncover the reasons why getting stuck on the on-call support rotation is a nightmare for engineers. Before you start reliving your own support-call PTSD, be assured that things don’t have to be this bad. Have a listen as Mages-Haskins outlines valuable processes that can help the poor engineering sods who wind up on-call when the systems go bananas and the customers flood the business with their “WTH??” and “Help me!!!!” cries of despair.
Trigger warning: The proper pronunciation of “Log4j” is a hotly debated issue and one that’s fearlessly tackled in this episode. We didn’t know that until we sat down with Ben Goodman, Contrast Head of Strategic Alliances and Corporate Development, mastermind behind our exciting new MSSP launch, and highly opinionated amateur word pronunciation expert. Ben’s a synergy sizzler: He heads up the alliances/partnership team that’s always listening, learning and brainstorming ways to make our customers and partners flourish. And hang on, who jumped into the podcast? Why, it’s Rachael Mott, Senior Director, Strategic Technology Alliances, who couldn’t resist the chance to heckle and praise her boss, who sprinkles Ted Lasso-isms upon his team. Tune in: You’re either going to want to do business with these two, hang out and argue mispronunciation with them — or most likely both!
Kotlin is a modern statically typed programming language used by over 60% of professional Android developers that helps boost productivity, developer satisfaction and code safety. We take a look at Kotlin — its digital roots, why it rose to popularity and how you can use it in your application today, with Contrast Security’s own Senior Technical Product Marketing Manager, Utsav Maheswari.
Not all cybersecurity women’s roots are planted in silicon. Tara Ryan — Contrast’s CMO (aka our Chief Storyteller) — started out as a farmgirl in Fresno, known as the Midwest of California. Her tender young years were spent breathing in the concept of seed to shelf: cultivation that, fittingly enough, is automated by much of the software she’s worked on over the last 25 years. Take note that Tara is named after Ireland’s good, green Hill of Tara. Think terra firma, think earth, think “the Land of the Vikings,” but don’t think you can ignore her, even if, as is often the case, she’s the only woman in the room. In this episode, Tara shares her take on what it takes to succeed as a woman in tech and cybersecurity, including the rows she’s had to hoe and the lessons she’s harvested along the way.
In honor of Women's History Month, we're agog at the two shining tech stars featured in our latest episode. Megan Baker, IT & Security Lead at fintech Georgian, and our own Director of Product Security, Naomi Buckwalter, say they didn’t need encouragement to crush it in cybersec: They were simply born with the right wetware. One snippet of their advice on empowering she-geeks: Hire women because they’re good at what they do, not just because you need to tick off a checkbox.
What does the future hold for security assurance and software transparency? In this episode, we sit down with Contrast co-founder and CTO Jeff Williams and special guest Ron Ross, Fellow at the National Institute of Standards and Technology (NIST), to discuss the lack of transparency when it comes to software security. True, the government’s issuing new regulations and standards to shed some light into these traditionally murky waters, but what do the changes portend for your business? For the industry as a whole? Have a listen as these experts unpack the trends and implications of transparency.
As we all know, cyberattacks are increasingly prevalent. Financial institutions are especially at risk — after all, as bank robber Willie Sutton famously said, that’s where the money is. Cyberattacks have become more sophisticated, more destructive and more frequent. Financial institutions need to prepare for a future of digital uncertainty. Today we are joined by our own SVP of Cyber Strategy Tom Kellermann and special guest Derek Booth, Assistant to the Special-Agent-in-Charge of the U.S. Secret Service and Head of the Mountain West Cyber Fraud Task Force, to discuss cybersecurity threats facing the financial sector.
Contrast’s new partner alliance program is going to revolutionize how you scale security solutions. Integration with source code management, DevOps pipelines, API security solutions? Check, check, check — all that and more! The mastermind behind it all is Ben Goodman, Contrast Security SVP of Corporate Development and Strategic Alliances. He dropped in to explain the aim of the new Security Innovation Alliance (SIA) program: namely, to tie together the myriad parts of the security ecosystem so all your partners can focus on your business instead of patching things together with duct tape and paperclips.
You've got nothing to hide, right? Well, how about you prove it by slapping a label on your code so consumers know what's being done with their data while it's at rest, in transit and in use? Geoff Lane, head of U.S. policy at world-leading developer advocacy group Developers Alliance, joins Code Patrol to discuss the progress we're making towards a more transparent, data-driven industry — and how that transparency is essential to both consumer trust and keeping governments from flooding the industry with regulation.
Software supply chains are the new front line in cyber warfare. In this episode, we’re joined by Jerry Gamblin, Senior Director of Security Research at Kenna Security, along with our very own CISO David Lindner. Listen in as we discuss all the steps and measures critical to mitigating risk in this new era.
Federal agencies need access to best-in-class solutions that will modernize their applications and secure the APIs. But those solutions must be secure, agile and built for the future, which requires confident collaboration across agency boundaries and verticals. We invited Steve Orrin, Federal Chief Technology Officer at Intel Corporation, to address this issue and share his views on how IoT environments are being integrated with existing systems to ensure continuity.
We've all had enough of cyber attacks targeting our nation's critical infrastructure and public and private businesses. We need a strategy to combat the attackers head-on! We sit down with our own Senior Vice President of Cyber Strategy Tom Kellermann for a conversation on how organizations must ensure they're not only prepared to detect and report, but also to defend from within.
Do you swear to tell the truth about your secure software development, the whole truth and nothing but the truth? Get ready to bake: Our co-founder and CTO Jeff Williams says he doesn’t think most software producers can take the heat in the new transparency oven of the M-22-18 memo from the federal Office of Management and Budget.
Code Patrol scrutinizes the month’s tech scene with code-colored glasses. Computer security industry veteran Lisa Vaas chats with guests about all things security — be it cybercrime, hacking, DevSecOps, and beyond — that collide with the code that runs the world. Coming Fall 2022, follow us wherever you find podcasts.