Andrew Van Der Stock -- The New OWASP Top Ten
With Andrew van der Stock
Andrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode. We discuss the latest with the OWASP Top 10 Project, the importance of data collection, and the need for developer engagement.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 18 chapters
- 00:00Meet Andrew van der Stock: The New OWASP Top TenAudioVideo ↗
- 01:41We are about to go on a journey into the topicAudioVideo ↗
- 04:10Phone goes with you probably just for emergency purposes, but soAudioVideo ↗
- 07:27Probably get ways to deal with it, rightAudioVideo ↗
- 13:08Help me, help me remember what, what, what is the connectionAudioVideo ↗
- 15:29On the topic of OWASP Top 10, give us an updateAudioVideo ↗
- 17:16We talk about data and the need for data, I don'tAudioVideo ↗
- 20:58Then if— so the, the request for data is really moreAudioVideo ↗
- 21:56Now I'm curious. I want to dig a little deeper onAudioVideo ↗
- 26:00Are the downsides of, potential downsides of this data collection approachAudioVideo ↗
- 30:23That data weighted different in the model if it comes fromAudioVideo ↗
- 33:33Wrapping all of this kind of together, we've got the dataAudioVideo ↗
- 35:14I mean, or it used to be. Yeah. Or it usedAudioVideo ↗
- 36:24I can, I mean, just to second something you said aAudioVideo ↗
- 40:38Yeah. So you already jumped ahead to controversial opinion, but beforeAudioVideo ↗
- 42:23All right. Yes, we already talked about the controversial opinions. SoAudioVideo ↗
- 45:59Great. Last question is, what's your top book recommendation and whyAudioVideo ↗
- 50:12Andrew, what's, how about a key takeaway thenAudioVideo ↗
About this episode
Andrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode. We discuss the latest with the OWASP Top 10 Project, the importance of data collection, and the need for developer engagement. Andrew gives us the methodology behind building the OWASP Top 10, the significance of framework security, and much more. Andrew Vanderstock is a seasoned web application security specialist and enterprise security architect. He’s the executive director at OWASP, taking the foundation through organizational change and taking OWASP’s mission to the next level. Andrew has worked in the IT industry for over 25 years, has researched and developed the web application security and architecture fields since 1998.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
→ Learn more about Security Journey
Connect with Andrew van der Stock:
→ The Crown Road by Iain Banks
→ Edward Tufte
Resources
→ The Crown Road by Iain Banks
→ Edward Tufte
→ OWASP Top Ten Project
→ OWASP Developer Guide
→ PCI DSS
→ OWASP Top Ten for LLM Applications project homepage
→ RSA Conference
Actionable
From this conversation
- 22:31
Submit triaged findings with varied CWE coverage
We do like to see a spread of CWEs over the data we receive.
- 33:51
Prioritize every OWASP Top 10 category
But my message to everybody listening to this podcast is the order is unimportant. Do all of them because it's only 10 things.
- 37:26
Design applications for secure-by-default frameworks
I think developer education is overrated. And I think what we need to do is get to the frameworks and say to the frameworks, you need to fix these things based around the ASVS.
- 39:43
Capture negative access-control cases in user stories
What happens is that people don't think about the negative access control consequences. And so they don't write user stories that incorporate them.
- 50:22
Contribute CWE findings to the OWASP Top 10
If you have a collection of CWE data that is easily extractable, doesn't matter the size of the contribution. If you've got 10 apps, if you've got 100,000 apps, we'd love to talk to you.
Transcript · 52 min conversation
0:00Chris RomeoAndrew Vanderstock is a seasoned web application security specialist and enterprise security architect. He's the executive director at OWASP, taking the foundation through organizational change and taking OWASP's mission to the next level. Andrew has worked in the IT industry for over 25 years, has researched and developed the web application security and architecture fields since 1998. He's a lifetime member of OWASP, A former director and co-leads the OWASP Top 10 projects. An Australian expat of Melbourne and Sydney, he currently lives in the USA with his family. Andrew joined us to catch up on the happenings of the OWASP Top 10 project. We discuss how the project is going, data collection, and the methodology for building the Top 10. We even asked Andrew for one thing that he wishes he could change About the top 10. The Application Security Podcast is brought to you by Security Journey. Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
1:07Andrew van der StockLearn more at securityjourney.com.
1:08Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of DaVinci and a general partner at Curve Ventures. And as always, happy to be joined by my good friend Robert. Hey, Robert.
1:32Robert HurlbutHey, Chris. Yeah, Robert Hurlbut. I'm a principal application security architect and threat modeling lead at Acquia. And as you mentioned, always glad to be here.
1:41Chris RomeoWe are about to go on a journey into the topic Or at least the group is the topic that we've spent the most time on this podcast talking about, and that is OWASP. And so we're excited to have Andrew Vanderstock joining us for his third appearance, which by current calculations puts him into the top ten for number of number of visits to the podcast. There's a few people with five, maybe one or two with four, but you're. definitely in rare air with the group of people that have made a lot of appearances. And so, in case you want to catch Andrew's previous episodes, in January 2021, he did an episode with us called Taking Application Security to the Masses. And then in September 2017, I remember doing this interview live in Orlando, of all places. We had Andrew and Brian Glass talking about the future of the OWASP Top 10. And so that seems like it was many, many years ago, but only a few years ago. So, Andrew, instead of an origin story, because you've been with us as a guest a number of times before, this is my, what I'm affectionately referring to as Go Outside Initiative. And so I'm curious, what do you like to do that takes you away from computers and technology?
3:04Andrew van der StockWell, honestly, I love going on cruises. Like, the thing that I do the most is actually I play Elite Dangerous, which is a computer game, but that's the exact opposite of what you just asked. The game actually has tools, it has all sorts of things that you just need to use to be able to play it properly. But what I like to do is cruising because you are literally forced to be apart from your computer.
3:30Robert HurlbutYeah.
3:31Andrew van der StockPeople can't contact you. They can't call you. If you don't have a copy of your favorite book or your Kindle with you, the chances are that you're going to have to rely upon shipboard entertainment. Recently though, all of the cruise lines have actually started to adopt Starlink. So you could theoretically go on a cruise and do work, which is not the point of a cruise. The point of a cruise is to get norovirus.
4:02Chris RomeoSo, okay. So you're, you're going on a cruise and you're leaving computer behind at home.
4:09Andrew van der StockYes.
4:10Chris RomeoPhone goes with you probably just for emergency purposes, but so you're trying to stay off your phone and just, you're trying to have like a digital-free experience for the most part?
4:19Andrew van der StockYeah. Most modern cruise lines actually use apps on the phone to do your ordering of ship excursions and things like that. So you can't, get away from just leaving the phone at home. You do need to have it with you. They generally don't have a piece of paper that comes to your room every morning saying, you know, what are the excursions and what's the events happening on board today. You actually do need to use your phone for that. That's just modern cruising. So realistically, you do need your phone with you, but you don't have to use it all the time. In fact, I'm pretty bad at using my phone. As I mentioned when we were doing, before the introductions, I missed an important call today because I just wasn't looking at it.
5:04Chris RomeoThat's a good problem to have though, because you weren't spending every second picking up your phone and looking at it and seeing what was happening.
5:15Andrew van der StockSo yeah, that's cool. I gave up doom scrolling a couple of years ago. I actually stopped playing I stopped using Facebook pretty much about 2 years ago. It's been fantastic for my mental health. I do recommend it.
5:29Chris RomeoYeah, it is. It does seem like all of those apps are, their sole purpose is to try to get us to scroll, scroll. And if you look in public, like in airports, I love to do this and you just kind of walk down the terminal row and You just kind of look off to the side and you can see people, everybody just mindlessly. It's like a, you know, a commercial from 1984 by George Orwell or something like with people just engrossed into their technology devices. So, but that's great to hear, Andrew, that you have, you like to get out onto the cruise ships and that's a way that you get away from this world of technology that it seems like it's so engrossing to us.
6:18Andrew van der StockYeah, absolutely. That's also a great chance to reconnect with your family because, you know, you often feel like you neglect them during work times because, you know, I don't know about you guys, but we do work long hours and I must admit I don't really share a lot of TV shows and like my wife loves those life after lockup type TV shows and I, I can't stand them. Um, so because we both love cruising, uh, it's a chance for us to reconnect and it's fantastic.
6:52Robert HurlbutYeah. Excellent.
6:54Chris RomeoSo, so, so, uh, people should not get you a DVD set of Life After Lockup. Yeah. And send it to you for Christmas. That would be a terrible Christmas gift for Andrew Vanderstock.
7:07Andrew van der StockYeah, but it'd be a fantastic regift for my wife.
7:11Robert HurlbutVery good.
7:11Chris RomeoSo you might, you might take people up on it because you're like, oh, quickly, let me just change the name here, scratch it off. Your wife's like, why is your name scratched off on this tag here?
7:21Robert HurlbutOh, it's okay.
7:22Chris RomeoIt's fine. I wrote my name instead of yours. That's what I was trying to do.
7:26Robert HurlbutProbably get ways to deal with it, right? Yeah. So, uh, so Andrew, as we, uh, jump into our topic today, uh, I was wondering if you could remind us about the cinema booking system, which influenced the early top 10.
7:42Andrew van der StockYeah. So back in the— just to give people some history, the OWASP Top 10 is actually 21 years old. The first version came out in January 2003. The first version that most people are aware of actually came out in April of 2024— sorry, 2004. So the reality is that we're in the 20th to 21st anniversary of the OWASP Top 10. Dave Wickers and Jeff Williams created the first versions, but a lot of the work that we did on the developer guide was influenced with this particular gig that I did back then. And it's so long ago that that system doesn't exist anymore, but it was a fantastic system. It basically had one of everything in terms of application security. It had access control problems. It had, you know, direct object reference problems. It actually had mathematical problems. It had business logic problems. It was fantastic. So I love these sorts of apps because back in those days, you would run a scanner or something over it, and you'd find yourself looking for SQL injections and cross-site scripting manually. And of course it had those because, well, why wouldn't you back in the early days of application security have cross-site scripting and whatnot? But I loved looking deeper into apps and how they're built. And so that developed my love of application security. So in particular, this particular booking system was, it was a really interesting system. It was a very early online cinema booking experience. You know, this is 20-plus years ago. You would, I don't often think about, well, I just slap my $5 on the table and away I go and see a film. No, this was basically to allow you, like in Australia, we had this thing, or it's still a thing called Gold Class Cinemas. It's, they're fantastic. They, um, have lie-flat seats. They bring you alcohol and food during the actual movie. Uh, it's definitely a really wonderful way of actually seeing a film. Um, and so what they would do is they would sell you gift cards and, um, uh, packages and whatnot. And, uh, They were losing a little bit of money on this system and they didn't understand how that was even possible. So, well, there I go. I start looking into it and all of a sudden I see a pull-down menu with the quantity of tickets that you want to buy or whatever the case may be. And all of a sudden I realize I could just get rid of that as a pull-down and I could type a number in. So I typed in 0 and sure enough, it became 0. And I go, I wonder what happens if I put a negative number in? And sure enough, the price went down below zero. So what I had to do was play around with what I wanted in the basket until I got to about $2 for about $100 worth of stuff. Clicked, you know, update, and sure enough, it allowed me to actually check it out. So I did. 2 weeks later, I get in the mail, you know, the little coupons saying, you know, 2 cinema tickets and a complimentary food and drink thing for a certain value. And I just go, no way it worked. Anyway, the firm had actually implemented, they thought the problem was in the warehouse. They thought there's something in the warehouse. People were just taking these cards and giving them away to their friends. What was happening was people were doing exactly what I was doing. And it was such a simple fix. And it just simply came down to the fact that Java doesn't have unsigned integers. It has only signed integers. And so when I put in negative numbers, it just multiplied them through thinking there was no way you could possibly change anything because, you know, if you've got a pull-down menu. Well, yeah, that was fun. was eye-opening to the actual people that I was working for. And they were very nice. They actually let me keep the actual tickets and I had a really wonderful evening on them. So I really appreciate them. But you know what? Most of that ended up in the original developer guide. It was a fantastic experience, a wonderful client to work with. They fixed it really rapidly, which is something you don't always see. when you're in consulting. I think we've all been consultants over the time and sometimes clients are not always accepting of your findings, but they had a problem. I found their problems. And yeah, we went on to actually, some of my very first developer education came in as a result of that as well. Back in those days, you didn't need a computer science degree to become a web developer. In fact, most people were self-taught. And, um, I, uh, I, I might save that, uh, controversial topic for the controversial topic topic later. Don't burn it.
12:51Chris RomeoDon't burn it too early here because we'll ask you for another one.
12:54Robert HurlbutYeah.
12:55Chris RomeoIf you use it now.
12:56Andrew van der StockBut no, that was a wonderful experience. And, uh, many of the lessons that we learned during that particular, um, that engagement ended up in the Developer Guide.
13:07Chris RomeoSo help me, help me remember what, what, what is the connection between the Developer Guide and the OWASP Top 10? Is there kind of connective tissue between those things or has it been lost over time?
13:21Andrew van der StockNo, the Developer Guide was the thing that got going with OWASP in the very first thing. It was actually OWASP's first document that was ever published. Version 1.0 came out like 3 months after OWASP was formed. But I knew there was things that I knew that weren't in the developer guide. So I started helping out. So by the time that I was helping out on the developer guide, it was version 1.1, and I was responsible for version 2.0. That was a lot of work. I do not recommend having a full-time day job and then going home and then doing a full-time author job. I, if you've ever written a book, it's incredibly valuable experience, but it's also incredibly tiring. A lot of the things that were in the developer guide that I ended up documenting were things that ended up in the OWASP Top 10 and vice versa. So we didn't really have, like, today we've got access control, authentication, session management, input validation, these major topic headings, they weren't very well organized back then. It was literally a list of, here are some things you should try. So collecting them together and actually putting them into some sort of order actually helped both the top 10, and it also helped the developer guide. Because the OWASP Top 10 2020— 2004 came out, and it obviously had SQL injection at the top and, you know, worked its way down. It was really important to make sure the developer guide Had agreement, rough agreement with what the top 10 was saying. So, you know, we worked with Jeff and Dave to make sure that what they were saying was in the developer guide and vice versa. If we had some interesting things that maybe belong in the top 10 that there wasn't a lot of data for, that's one of the things that we'll talk about when we come to the construction of the top 10. The top 10's always had things that have been inserted that there isn't a lot of data for. Um, we had lots of discussions along those lines, but yeah, the first couple of versions, um, of the OWASP Top 10 were Dave and Jeff.
15:29Chris RomeoSo on the topic of OWASP Top 10, give us an update on the project, where it is, what's happening right now. I know it's, it's from a public perspective, it's been quiet since October, uh, 2021, right? I don't remember what month it came out in, but it's been, you know, there just, there hasn't been a lot of public kind of things happening. So give us an update on what's been happening behind the scenes.
15:55Andrew van der StockOkay. So the leaders have been meeting on and off. We are stuck. We need data. And that's my main purpose today is actually I'm begging folks for data. We had 550,000 apps worth of data then. We now have enough data to be able to say with some certainty, if we have 100,000 apps worth of data, we can extrapolate what's real, what's not, what is an outlier and help us normalize 100,000 apps worth of data. The problem is right now we don't have 100,000 apps worth of data. One of the things that's been the hallmark of the top 10 post-2017 is it is data-driven. We deliberately make room for 2 injected items so that we can have an opinion and some subjective things that are included. But Yeah. The other 8, they're real, they're data. And, you know, you can argue about what order they belong in, but you can't argue about their inclusion. So right now we are a little bit stuck. We're well behind schedule. We should be writing the OWASP Top 10 2024 right now. We wanted to publish it in September. I don't think we're gonna make that. We're probably gonna be hitting the November timeframe again.
17:15Chris RomeoSo, when we talk about data and the need for data, I don't want to assume that everybody knows what that means. So, let's unpack this idea of data. Like, when you use the word, you say, hey, we need data, what does that actually mean? What do you need?
17:29Andrew van der StockOkay. So, we need people from consultancies, people who run tools, people who run bug bounty programs, those sorts of things, What they will generally do is they'll have an app, they've done an assessment, and they will actually have a list of findings. In the list of findings, they will categorize— generally, most people do this, not all— they will generally put a CWE, a Common Weakness Enumeration number against it. Not everybody agrees with that categorization. For example, many people put in category 200, which is a catch-all. for a bunch of CVEs. We don't like that. Generally, the, you know, there's 1,200+ CWEs. If you can't figure out which of the 1,200 a particular vulnerability is, you haven't searched hard enough. I think, you know, but the problem is we do get a lot of information from people that say it's CWE-200. Well, now we need to unpack it a bit more. But when you've got enough data, it doesn't really matter. You can actually say, well, I'm just going to ignore the 200 and just bucket it, you know, as a tiebreaker or something like that. What we need is for people who've got this information, we need an Excel spreadsheet that basically describes the number of times you found a particular CWE across the number of apps that you've actually found them in. We really love boutiques who may only have 20 or 30 apps worth of findings, but you know what? They're so high quality because these are literally people who've manually gone and tested the application. They've triaged it, they've presented it to a customer, and the customer's agreed. It's as good as bug bounty data. Bug bounty data is actually remarkably high quality because they don't pay out for like a lot of the configuration items that you know, a lot of tools find. It's all triaged, it's all real. They've got the t-shirt or the $25. In some cases, they've got $100,000, whatever the case may be. But most people don't make a living from bug bounties. But the data we receive from bug bounty programs is actually remarkably solid. So much so that it's actually one of the ways that we judge whether a piece of data coming in actually is an outlier or not. Now, the problem with bug bounties is that they don't accept every single type of bug. And boutiques, you will see a very wide variety of bugs. Tools, if we accepted just tool data, like scans from source code tools or something like a Nessus scan or something like that, We would be overwhelmed, and we were at one stage overwhelmed with the insert tool vendor name top 8, because the only thing they found was 8 things. They're really good at finding it, but we all know tools have false positives. Was that actually triaged? Was that actually made real before we actually got that data? Because, you know, if we get 40,000 findings, or 8 items, those 8 items are ending up in the top 10. So we need to find a way to weight that. So there's a data normalization process that we use.
20:57Chris RomeoSo then if— so the, the request for data is really more than I just package up all of the scans that I've ever done and send them to you to pour through. So you don't want data that identifies the destination, for example, right? Like, I don't have to worry about anonymization of my data in this process with you.
21:29Andrew van der StockYeah, I mean, basically, if we get data that is overwhelmingly pointing towards a single tool, we'll do some work to, like, make it more anonymous. We're not interested in URLs. We are not interested in particular parameter names or anything like that. We're interested in the CWE number, the number of times you found it, and the number of apps you found it in.
21:52Chris RomeoOkay.
21:54Andrew van der StockGot it.
21:56Chris RomeoSo now I'm curious. I want to dig a little deeper on this as far as you mentioned, there's some data normalization. There's some other things that are happening here. Maybe walk us through an example of the steps that a piece of data goes through. And are there endpoints, are there places where the journey ends for a piece of data? Like, is there a place where data gets thrown out? Is there a place where a decision point, like, I'd love to get just a little more perspective on the steps you're going through to normalize this stuff.
22:31Andrew van der StockSure. So, One of the common complaints is that we don't get data from enough of different types of sources, but we have access to the same CISOs that everybody else has access to. One of the things that might start coming towards us is data that is, that maybe the people who gave us the data is only interested in 3 types of CWEs this year. I've actually worked for a client who was only interested in fixing cross-site scripting and SQL injection. And that gig was actually a really interesting gig because we were involved in fixing, not just finding, but fixing the SQL injections and cross-site scripting. And we found, you know, thousands of it. But if you asked, if the top 10 asked for data from that year from that client, they would have, you would have received 3 CWEs, like CWE-79, CWE-80, we would almost certainly have to throw that data away. There's just not enough variety in the data to say that, you know, that's real. It's not that there's no other vulnerabilities, it's just not normal compared to the other sorts of data that we receive. We do like to see a spread of CWEs over the data we receive. We're not interested, like, again, if we get a consultancy who gives us 40 results representing every single engagement that they've done this year, that is a fantastic piece of information and we'll see a variety of CWEs and we know it's real. We'll just bucket it with all the others. What we do internally though is we do actually have, we ask people to describe the way that they collected that data. So we actually, call it humans assisted by tools, tools assisted by humans, and manual. The worst type of data that we can receive is actually scan data that hasn't been triaged. We generally can't use it.
24:35Robert HurlbutOkay.
24:38Andrew van der StockIt's the most voluminous, it's the hardest to normalize, and because we don't know if there's any false positives in there, it's the least valuable type of data. So the main data that we actually like is manual data, such as from bug bounty programs and boutiques. Humans assisted by tools. This is where a security program has a tool, like for example, Burp Suite, and you're manually driving the tool most of the time, but the tool is helping out in the background. They're doing passive scans, they're doing active scans of parameters and things like that. That's actually pretty high quality, especially if they've been triaged. The lesser quality tools are those that are generally like static code analysis tools, where, you know, it's part of a CI/CD process, and the code is run through the CI/CD process, the scan tool runs, thousands of results are generated, and then a human triages them. And because of the volume of findings, you generally find there's a lot of them, But you're starting to wonder just how many are real. And so we actually do have different weightings for those different buckets. And yeah, as I said, we tend to not use just scan data, raw scan data by itself.
26:00Chris RomeoWhat are the downsides of, potential downsides of this data collection approach?
26:11Andrew van der StockThe people who submit the data are self-selected.
26:12Robert HurlbutSo.
26:15Andrew van der StockI'd be, I'd really love to see every single boutique and every single consultancy and every single, you know, bug bounty program, everybody who has a large AppSec program, I'd love to basically say it was a point of pride to submit your data to the OWASP Top 10. At the moment, because we have so few sources, that self-selection often comes from people who have very mature AppSec programs. And so maybe the things we're seeing are from people who have well-tuned, well-resourced programs, and the CWEs aren't representative of what you might necessarily see elsewhere. Yeah.
27:01Chris RomeoAnd then I guess, The other challenge is that you don't, you only know, you're only analyzing the data for CWEs. And so if there is something new in our industry, you don't have a mechanism, like it's not going to be data-driven in the early days, at least because the tools won't know to find it. So most of the finding, And maybe some pen testers know about it, but, you know, that community tends to be, have people that are at different levels, different abilities. Um, so that seems like that is also, that's also a potential downside is that there could be, it could, there could be a lag while the industry catches up with stuff that's new to be able to get the data, to be able for you to be able to drive the data.
27:53Robert HurlbutYeah.
27:54Andrew van der StockOne of the biggest things we've definitely seen is that the SOF 10 can become self-referential because if people use it as their AppSec program, then people will find the things in the previous top 10. If they're doing PCI DSS and only PCI DSS, well, PCI DSS is based on the OWASP Top 10 2007. Now, I must admit, I haven't looked at the recent PCI DSS 4.0. I've heard that they've updated it quite considerably. I'm hopeful about that because quite frankly, the 2007 version of the OWASP Top 10 is considerably old. But if you're only looking for those things, well, it could become self-referential. And I think that's one of the reasons why we haven't seen a lot of change in the OWASP Top 10. Like, I was looking at the OWASP Top 10 2004 the other day. You know, we still have injections. We still have cross-site scripting and things like that. Dave and Jeff, with the information that they had at their firm at the time, which is Aspect Security, which has now been bought by a very large multinational, they had the data, but it was only their data. But it was interesting to see that that data has replicated itself throughout the history of the OS Top 10. And so one of the valid criticisms I think is the OS Top 10, and one of the reasons why we actually inject a couple of things into it, is it becomes very self-referential.
29:21Robert HurlbutYeah, and that's what I was wondering about, you know, in terms of, you said you do want to see other data. You want to see not just the top organizations maturity-wise and so forth submitting data, but others as well. So you get that good cross-section. It's not just representative of a certain type of organization that's giving you that data. So that's— Yeah.
29:49Andrew van der StockSo, I mean, the lower maturity programs would actually struggle to get the data that we need because it's going to be in PDFs rather than in a database. They're not going to have an application management platform. They're not going to have some form of, you know, the larger organizations are set up to give us this data. And that gives us a headline number of, oh, we've got 100,000 apps worth of data. That's fantastic. But as I said, I love hearing from boutiques who might give us 40 pieces of data. That data is gold.
30:22Chris RomeoIs that data weighted different in the model if it comes from a boutique?
30:27Andrew van der StockA little bit. We use it to prove that because there are so many different findings in the boutique data, we have to be careful of overweighting them. Because we may get 2 people who are really good at finding like SSRF and tools are terrible at it.
30:47Robert HurlbutYeah.
30:49Andrew van der StockAnd so we might end up putting SSRF in, which was an injection. Like we literally, I probably should describe the way that we've always included something subjective in the OWASP Top 10. I mean, I think that's important as well. Back in 2007, I put cross-site I put cross-site request forgery in. There was no data for it, but every app suffered from it. And I'm glad to say that that actually made a change in the industry because, you know, I don't know if you remember Sammy Is My Friend, probably the worst CSRF attack of all time, but the funniest one as well. Well, you know, we do need that opportunity to inject things, to keep things fresh, to Like this year, I believe that we'll actually be injecting stuff about the European CRA that harmonizes the way that software needs to be developed and supported and kept secure for its lifetime in Europe. And that distinctly pushes the, you know, you have no warranty. Well, in Europe, you absolutely will have the requirement to look after your software. So I'm expecting us to inject some CRA items into the OWASP Top 10 2024. Will it happen? I don't know. We rely upon, we survey on social media to find out what the community thinks. What Andrew van der Stock thinks is not important. I might put a survey out that lists 10 or 15 things that I think are important, But the community may disagree with me. But if we have a lot of people from Europe, they'll say they will select the CRA items. So we'll see. But yeah, the OWASP Top 10 has always had injection of things that we think are important. And logging and monitoring was the controversial one in 2017.
32:49Chris RomeoMm-hmm.
32:49Andrew van der StockBut if you've read the Verizon data breach reports ever since they started coming out 20-plus years ago, The idea that you can write an app that doesn't log is ridiculous. So everybody who gave us grief around logging and monitoring as being something, well, the people who definitely were upset by that were the people who couldn't scan for it. You actually had to ask the question, you had to ask the customer questions, and they don't like doing that. You have to deal with other humans. No, I don't want to deal with another human. Goodness gracious. Yeah. Um, yeah, I'm a hacker into my mom's basement.
33:30Robert HurlbutOkay.
33:32Chris RomeoSo wrapping all of this kind of together, we've got the data, you've done a bunch of analysis of it. What's the, what finally gets us to the order that we see? Okay. Like how do you pick the number one?
33:51Andrew van der StockIt's a battle to the death over 4 and a half hours or so. We spend a very, I won't say it's an acrimonious meeting, but I would say that people have hills they're prepared to die upon. I was actually pushing for maybe not including injections into the 2021 version, but when we pushed all the data together, including cross-site scripting, including SQL injection, and for all of the forms of injection together, It did end up in there. It was top 10, 2021. And then the question became, does it belong as number 1? That order is actually one of those things where we know that people do pay attention to. But my message to everybody listening to this podcast is the order is unimportant. Do all of them because it's only 10 things. Do all of them. And if you find that like, Injections is a big problem for you and it's still number 7, it doesn't matter. Just do them. Just do your best.
34:53Chris RomeoUnfortunately, I don't think people interpret it that way though, which I wish they do. And I agree with you. I agree with that. Like, these are the 10 most important things. Do them all. It doesn't matter what order they're in. But I think human nature says people are going to get caught up in, well, that's the number 1 thing on the list. And that's the most important thing.
35:14Robert HurlbutAnd I mean, or it used to be. Yeah. Or it used to be. So yeah, it used to be. So therefore it's not important anymore. You know?
35:21Chris RomeoYes. And that's what I would hate to see is like, oh, well, injections is number 7. Some percentage of the world will be like, that doesn't really matter that much anymore. When in fact, we know that if you don't practice input validation and output encoding and all these things, you're just going to keep building applications that suffer from injection attacks.
35:42Andrew van der StockAbsolutely. And realistically, the injected items that we put into it never appear at number 1 or number 2. But considering the fines that will associate with the CRA, maybe they should.
35:56Chris RomeoCould you take the numbers out? Could you just give us a top 10 list that doesn't have a, doesn't have a number 1, just has 10 things on a bullet list?
36:05Andrew van der StockControversial. Um, many people, including the CWE, actually categorize by the actual number. So we sort of need it.
36:14Chris RomeoOkay. I see.
36:17Robert HurlbutYeah. And it's a way of identifying, but, um, yeah, I can see that.
36:23Chris RomeoI can, I mean, just to second something you said a minute ago, I remember when, when CSRF went from 4, I believe you told me years ago, It actually went to number 13 when it moved off the list, but it still felt like a step forward. It felt like as an industry, we could say, hey, we did something, like something got better. The CSRF was, people understood what it was, people started to mitigate for it, and eventually the frameworks absorbed it. So, I mean, you really got to do something ridiculous to set up a CSRF in a framework-based application today. You gotta go turn a bunch of things off, man, you know, on purpose. And so that's really the ultimate goal. Like, is there another thing, Andrew, from your perspective? Like, what's the next one that we're closest to being able to celebrate victory on?
37:17Andrew van der StockInjections. My controversial take, I'm jumping forward one question. Okay.
37:26Robert HurlbutSure.
37:26Andrew van der StockI actually think developer education is overrated. And I think what we need to do is actually get to the frameworks and say to the frameworks, you need to fix these things based around the ASVS. Um, make sure your framework actually covers off these things by secure by design. Do you know why CSRF and injections are falling off? It's because the frameworks don't let you do it. You can still shoot yourself in the foot if you do it the hard way. But I've never met a developer who really wants to do it the hard way. They rely upon their frameworks.
37:56Chris RomeoMm-hmm.
37:56Andrew van der StockI, my controversial opinion is we need to get the frameworks to really, and to be, to be fair to them, the major ones that are in use actually do a really good job of the vast majority of the OWASP Top 10. It's just, I'd really like to see the same sort of focus on access control and authentication now. Because we're starting to see that that's starting to become much more important than it used to be because the other things that were traditionally in the top 10, like injection, CSRF, and, you know, all of those wonderful things that were easy to find, like security misconfigurations, are starting to go away because the frameworks are doing the right thing.
38:40Robert HurlbutYeah.
38:41Chris RomeoI think access control and authentication are going to be a harder framework fix. Just because with most languages, there's other pieces. It's not the framework that you rely upon to implement access control. There's, there's a lot of moving open source pieces. You know, when I think about like a Node.js JavaScript application, there's, there's multiple pieces that I can, I can get. And so maybe it means you got to get to all those other pieces. You need to get to the open source package maintainers and try to get a cohesive story to be built there. But I think it's a good step forward. I mean, it seems like it's something that you could achieve in 5 years, that there would be a decent chunk of moving forward. Because if, I mean, it feels like it's something like, well, why don't we just fix it in a year? It feels like it's a multi-year engagement to try to fix things at the source, it's gonna take time for them to catch up.
39:43Andrew van der StockSo access control is one of those functional business requirements that enterprise architects used to do, but people got rid of their enterprise architects. And so what happens is that people don't think about the negative access control consequences. And so they don't write user stories that incorporate them. And so the developers don't include them. The frameworks are absolutely like capable of implementing these negative access control stories. They just don't because nobody bothered to enumerate them. But I think that that's going to become like the business logic flaws of the future. People will be able to get in and do things they're not supposed to do. And because there's less surface area to attack, well, now people will spend more time looking at the access control and business logic. and see whether they can abuse that because people didn't, well, they didn't have enterprise architects anymore.
40:38Chris RomeoYeah. So you already jumped ahead to controversial opinion, but before we go to Robert's other, which will now be a 2-question segment, I gotta ask you this one. So what's one thing that you wish you could change about the Top 10? If you had a, if you had the ability to change something?
41:01Andrew van der StockI would like to see it to be a little bit more, I would like it to be shorter. I would like it to be no more than 15 pages long. I would like it to be more infographic heavy. The reality is, is that When we come to do translations of the OS Top 10, a lot of the things become very technical and there may not be words for what we're actually trying to describe. It'd be really good for us to be able to have a more visual approach to the Top 10. Dave tried to do that in 2013 with the PowerPoint version, but I thought it was a bit confusing in the iconography. And we never really kept it. And so the later versions didn't have, didn't continue with that at all. So yeah, I would like to see it shorter and I'd like to see it a little bit more visual.
42:02Chris RomeoYeah, that makes sense that, you know, when you start to think about all the languages that it's translated into and it's, it does make sense that simple is gonna be better and, and more visual is gonna be less translation. have to go into it. So, all right, with that, Robert, take us into the abridged lightning round.
42:23Robert HurlbutAll right. Yes, we already talked about the controversial opinions. So let's go into— so what would it say if you could display a single message on a billboard at the RSA or Black Hat conference?
42:37Andrew van der StockI've been thinking about this since the beginning of the actual episode where you popped it out and I'm just going, wow. Okay. So honestly, when I went to RSA this year, it was my first time at RSA and it's overwhelming. I do think the best messages that got through were the simple ones. So a few years ago, we were working on our message of our mission and OWASP has had a few missions in its time, but I do think we needed a simple and short and sweet vision statement. And the current one we've got is, and I'm, you know, so help come up with it, is no more insecure software. It's a big, hairy, audacious goal, and it says where we should be going and how do we get there. I think one of the things OWASP has been very successful at is helping people to actually make their secure, their software more secure. there's a lot of criticism of, you know, the fact that some of OWASP's projects are getting a little bit stale, a little bit old, like WebGoat and whatnot. The reality is though, the bread and butter of the application security world is actually to do the things that are a little bit boring, but we need to keep up. You know, we need to make sure that we're agile. We need to make sure that our processes aren't falling back into the waterfall engineering process, you know, stage gates and things like that. We don't want to do that. We have to respect the fact that most firms don't have enterprise architects anymore. So developers have to do that role. So we need to provide easy-to-understand reasons why. But I think one of the gaps that we've got at OWASP, and I think where we need to go in the future, everybody at RSA was jumping on the AI bandwagon.
44:29Robert HurlbutYeah. wagon.
44:31Andrew van der StockI honestly, it could be a fad. It could be something that is transformative and changes the world. We do have a few OWASP projects that are dealing with generative AI, like the OWASP Top 10 LLM. You'd be surprised at the number of people at RSA that actually came to me and said, hey, that was a fantastic top 10. So great work to the guys who were involved with that. But no more insecure software is so audacious, and we need to actually make sure that we set ourselves up for the next 20 years. And if that involves AI, great. If that doesn't involve AI, well, we've still got these huge areas like architecture, building software securely, making sure that we're in front of the developers at all times. One of the things that I've been working on recently is actually trying to make sure that we're actually in front of the developer community. We're doing articles with dev.to. We're making sure that we reach out. We went to PyCon recently. We really need to get more developers involved. There are 100 developers for every application security developer. And so we don't know the correct answer to how to develop software correctly. What we do know is this is how you can actually break software. How do we help each other and have a really constructive conversation with developers?
45:59Robert HurlbutGreat. Last question is, what's your top book recommendation and why do you find it valuable?
46:10Andrew van der StockI'm actually gonna go to a nonfiction book, The Crow Road by Iain Banks. is one of my favorite books. Um, I did, you can't see it. It's actually over there at the moment. Um, but it is a fantastic book that opens up. I'm not giving away the plot at all. Um, with his grandmother blowing up in a funeral home. Um, they forgot to take the pacemaker out. And it just gets better and better and better and better. The, the book is the most amazing book. It's a, it's a transformative book and it, it'll actually make you a fan of his writing. Unfortunately, he passed away way too early. And so he's only left us with about 25 books, but he's written award-winning literature, Crow Road is literature, and award-winning science fiction. I actually do think his literature is actually better than his science fiction. That's a controversial topic. But, you know, my favorite technical book would actually have to be the— have you ever seen the books by Edward Tufte?
47:29Robert HurlbutNo.
47:31Andrew van der StockOh my goodness. Wow. These are fantastic. This is a video podcast. This is just one of them. There's 5 books in total. And it's how to explain technical things in visual form. He's the person who created sparklines. He's the person who created Chart Junk, like literally get rid of 3D graphs in your Excel spreadsheets because they're garbage. like hot garbage and then explains exactly how that led to the Challenger disaster. So he has an entire chapter who's involved in the Challenger investigation, and it's because the information that was presented to NASA management was completely misleading, but absolutely 100% technically accurate. because the visual representation was just awful. And it killed people because, and, you know, set back a massive program because people were just misusing data. And back then you weren't doing it in computers, you were doing it with pencil and paper and whatnot. And he just showed that if Here is the simplest possible graph that says you should not have launched that day. And it's literally just, it's like, here's the launches and here's the number of failures that have been observed of O-ring seals. And here's where you are planning to launch. No, don't launch that day. It's literally one graph and it would've said to anybody who could actually have eyeballs, don't launch. So Edward Tufte.
49:28Chris RomeoEdward Tufte.
49:29Andrew van der StockHe is an amazing, amazing guy. Lots and lots of opinions, but they're valid opinions. And honestly, anybody who comes up with sparklines and has great ideas like that needs to be listened to. His books are amazing. They're They actually have foldouts. One of them is actually the Napoleon march to Moscow and back. And it shows how he lost his soldiers along the way from dysentery and disease and things like that. And the actual battle was inconsequential. He lost the battle because of the way that he had logistics. And it was so easily shown in this graph.
50:09Chris RomeoVery cool.
50:11Robert HurlbutYeah.
50:12Chris RomeoAndrew, what's, how about a key takeaway then? or a call to action? I think I know where you're going to go with this, but I'll throw it out anyway. Like, what's, what's your call to action coming out of this conversation?
50:22Andrew van der StockI would entirely love for you to give us data. If you have a collection of CWE data that is easily extractable, doesn't matter the size of the contribution. If you've got 10 apps, if you've got 100,000 apps, we'd love to talk to you. I'll be in Lisbon next week for AppSecEU. Happy to talk to you at that point. I'm available on OWASP Slack and easily available through various means, including X, I believe it's called this week. Just look for Vander AJ.
51:02Chris RomeoVery cool. Well, Andrew, thank you for all you do for the OWASP universe. Not only do you run various projects, but you're the executive director, which we didn't even really mention. We just thought people already knew it, but I'll say it anyway. So thank you for all you do for the community and for pushing things forward. We appreciate you and the rest of the team. I know there's a team behind the scenes at OWASP that's part of the foundation that makes it all come together. So thank you to them as well.
51:28Robert HurlbutThank you.
51:29Chris RomeoWe look forward to seeing this 2024 edition, and I'm just hoping that there's a, there's a Chris Romeo Item on the list in the top 10.
51:36Robert HurlbutYeah.
51:38Andrew van der StockWell, submit data.
51:39Chris RomeoNo, no. I just want you to name one after me. That's what I'm saying. I want to know.
51:43Robert HurlbutI want— The Chris Romeo number.
51:45Chris RomeoOh, thanks, Andrew.
51:49Andrew van der StockNo worries. Thank you.
8,156 words · transcript by assemblyai
More on API Security
View all episodes →- July 25, 2017 · 44 minDave Ferguson -- The OWASP Top 10 Proactive Controls
- May 30, 2017 · 31 minChris and Robert -- Controversy within the OWASP Top 10 RC
- September 17, 2021 · 30 minOWASP Top 10 2021 Peer Review