--- title: "Elissa Shevinsky — Static Analysis early and often" url: https://appsecpodcast.com/elissa-shevinsky-static-analysis-early-and-often/ date: 2019-08-19 duration_seconds: 1752 guests: ["Elissa Shevinsky"] topics: ["Security Testing", "Careers in AppSec"] audio: https://www.buzzsprout.com/1730684/episodes/8122632-elissa-shevinsky-static-analysis-early-and-often.mp3 transcript: true --- # Elissa Shevinsky — Static Analysis early and often *August 19, 2019 · 29 min* with [Elissa Shevinsky](https://appsecpodcast.com/guests/elissa-shevinsky/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Careers in AppSec](https://appsecpodcast.com/topics/careers/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122632-elissa-shevinsky-static-analysis-early-and-often.mp3) ## Show notes Security testing is more likely to happen when it fits the way developers already work. Elissa Shevinsky, then CEO of Faster Than Light, joins Chris and Robert to discuss static analysis, startup lessons, and making security easier to adopt. She explains how her entrepreneurial path led into security and how mentors helped her navigate unfamiliar problems. The conversation then turns to what static analysis can tell developers, when to run it, and why slow or confusing feedback limits its usefulness. Elissa connects security findings with code quality and describes the challenge of communicating their value to people outside security. Her practical theme is to test early and often while reducing the effort required to make testing routine. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Elissa Shevinsky: → [Elissa Shevinsky on LinkedIn](https://www.linkedin.com/in/elissashevinsky/) Mentioned in this episode: → [Faster Than Light — historical project repositories](https://github.com/faster-than-light) → [FindBugs — historical Java analyzer](https://findbugs.sourceforge.net/) → [Techstars London](https://www.techstars.com/accelerators/london) Chapters: 00:00 Static analysis early and often with Elissa Shevinsky 02:01 Elissa’s path into software and security 06:26 Lessons from security startups 07:51 The value of mentoring 09:15 Paying mentoring forward 12:52 The Techstars London experience 14:15 What static analysis does 16:35 Making findings useful to developers 17:45 When to run static analysis 19:16 Testing in frequent deployment cycles 22:23 Making security fit everyday work 25:06 Security and code quality 25:42 Practical testing habits 26:41 Closing advice ## Transcript *5,010 words · assemblyai* **0:01 Chris Romeo:** Elissa Shevinsky is CEO at Faster Than Light. She's had a storied career as an entrepreneur with Brave, Everyday Health, and Geek Corps. We discuss Elissa's origin story, security startups, and the value of mentoring to her career. Then we get into static analysis and how we make security easier for people so that security gets done. Just a side note, Security Journey will be at Global AppSec DC, September 11th through the 13th. So if you're at the conference, make sure you stop by the booth and say hi. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, Hands-on and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. **1:31 Robert Hurlbut:** Hello folks, this is another episode of the Application Security Podcast. This is Robert Hurlbut, Threat Modeling Architect, and I'm joined here by my co-host Chris. **2:01 Chris Romeo:** Hey, this is Chris Romeo, CEO of Security Journey and also co-host of the Application Security Podcast. **2:07 Robert Hurlbut:** All right, and also today we're joined by Alyssa Shevinsky. Alyssa, Alyssa, thanks for joining us. **2:16 Elissa Shevinsky:** It's great to be here. **2:17 Robert Hurlbut:** Yeah. So tell us about your security origin story. That's usually how we start. Yours is a little bit different, I think, than some others, but curious to know. Let us know. **2:27 Elissa Shevinsky:** Yeah, for sure. A lot of people come to security as hackers or they're penetration testers, whereas I really came at it from a very different point of view. I was already a founder, I was already making a lot of things, but I wasn't really thinking about security or aware of security. But I had this idea to build a better user face for OkCupid, and I wanted to do it as a prototype, as a demo. There are different reasons why we were very confident that OkCupid wouldn't be mad at us about it. I was actually dating someone in the C-level at the organization, and then we had connections to someone who, like one of the owners, Barry Diller, whoever it was. And so we felt pretty confident that we could go and kind of push the boundaries here. And my team and I built this like gray hat hack on top of OkCupid. So we could take OkCupid and organize it kind of like Gmail priority inbox. This was in 2011, 2012 when Gmail priority inbox had just come out. So that was my introduction to what is SQL injection, because we were doing these things. You should say something now because I feel a little funny. **3:47 Robert Hurlbut:** No, it sounds fantastic. So basically, you were looking at OkCupid and you were trying to figure out how to improve it for users, but that led you down to some security aspects of it. **4:00 Elissa Shevinsky:** That's exactly it. So what we had to do, was the user would give us their OkCupid credentials, they would type it in. We made it look like there was an OkCupid login, and then we would go and send that back to OkCupid and kind of make OkCupid think we were the user, and we would like download and grab everything and represent it to our users in a new format. So like OkCupid didn't have an API, but we were making it like as if they did. Does that make sense? **4:28 Robert Hurlbut:** It makes a lot of sense. I've seen similar attacks actually like that. Wow, okay. But was that— **4:35 Elissa Shevinsky:** With the user's consent, right? So someone would say, hey, I think this is a cool idea, I'll try it out. We did some really cool stuff for women especially. Women at the time on OkCupid, they would get so many messages it would be really overwhelming. We did a grammar check for them. We did a distance check for them if someone was in their location. We removed any dirty words if they didn't want that. These are real problems on dating sites that weren't being addressed. Now, actually, a lot of dating sites have implemented these ideas. These ideas, they made sense at the time. That was my introduction to security, was unintentionally breaking some of these rules. That's how I got to know some really interesting people who'd been involved in PGP back in the day. Gene Hoffman and also now Brett Thomas is my co-founder now at Faster Than Light. and John Callas, who became my mentor for quite some time. So through my interest in trying to build this interesting prototype of a better OkCupid, I got exposed to what is information security and how does it work and who are the major players. A lot of it was Gene Hoffman taking an interest in me and introducing me to all of these people. Then that became very fruitful in my next startup, Glimpse, where we were building end-to-end encrypted messaging. Now, once you're building end-to-end encrypted messaging, end-to-end encrypted ephemeral messaging. So once you're doing that, now you're like really in the security scene. And I was getting invited to speak at DEF CON and invited to speak at ShmooCon. And I didn't even know what I was in for, but people were really excited and interested in what we were doing because we were like just so sincere about privacy. **6:26 Robert Hurlbut:** Oh, very cool, very cool. And so one of the things I think that led you to is maybe an interest as well as some work in security startups as well. Is that right? **6:36 Elissa Shevinsky:** Yeah, that's exactly right. So I'd been in startups before that. My first startup, I was a research intern at Geek Corps in 1999, and I was a QA tester among some more interesting roles at Everyday Health in 2003. I helped launch Daily Steel. So I'd done all this really interesting startup work, but none of it had been security. But then with this OKCupid experiment and then with Glimpse, I became really, really passionate about security. I discovered it and just it fit with everything that I care about, this idea of making things better, of being really detail-oriented, of defending and protecting user data and privacy and just like all these things that I really care about, like building software in the most ethical way, being uncompromising in the promises we make to our users, all of these things. So, I just fell in love with it. And it took me on this journey where, you know, I'm still here today. And some of that has been looking at security and saying, I'm just so in love with this field. And some of it is looking at this space and saying, hey, I have something really valuable I can contribute. You know, I should stay here and try and see what I can do that's useful. **7:51 Chris Romeo:** So what was the, uh, kind of the benefit of mentoring? I know you mentioned that, that you had a couple different mentors, and this is a topic that we find ourselves talking about quite a bit, but I'm curious as to, to learn a little bit more about how mentoring positively impacted your career trajectory. **8:08 Elissa Shevinsky:** I'm so certain that I wouldn't be here if I hadn't had mentors and champions. just straight up, because you need people to cheerlead you along and to make things possible. Gene Hoffman, for example, introduced me to John Callas, and then John Callas introduced me to other people, and they both taught me so much. I came to really understand the ethos and the ethics and what it means to be in information security because These folks are spending time with me and explaining to me and helping me along the way. And some of that means things like investments or recommendations. And some of it is just you learn from people by being around them, you know, and when they correct you in a very loving and friendly way. So I think It's just so important to mentor and champion people. I just feel emotional about it. I don't even know how to express this thing. It's so important. **9:15 Chris Romeo:** So has that led to you actively mentoring and looking for people to mentor now as kind of a pay it forward type of thing? **9:24 Elissa Shevinsky:** Yeah, I think it's so important. And I think, no, I know I'm finally at a space in my career where I feel settled enough and where I've learned enough that I can definitely give back. It's hard to give back when you're unsettled. It's hard to give back when you're not in a good space. But I'm in a really great space right now. I have an intern, Kenneth, who works with me at Faster Than Light. And he's my mentee. He's my number one mentee. We spend a lot of time every day where I'll wake up and be like, all right, what are we going to do today? And Kenneth will work on the same project with me. And I'll come at it from my point of view as a CEO and someone who's been doing this for you know, 20 years in some cases, and he'll come at it from the perspective of someone who's been doing it for like 1 hour. But he's really smart and he knows things that I don't know, and he helps me get so many things done. I mean, I'm on this podcast in part because he helped me take on this project of reaching out to be on more podcasts, and it's been really, really rewarding, really meaningful. I think There's a limit as to how many people someone can truly mentor or champion in a deep way, which is why sometimes really popular people don't always have the time. So I think we need to figure out how do we spread that more. **10:46 Chris Romeo:** Yeah, and one of the things that— I got some advice from somebody, from a mentor of mine, about the whole mentoring thing. And I realized that this is what he had actually been doing with me and it kind of kind of made me go, hmm, this is a good approach to it. But his approach is always, if you ask him, if you want to sit down with him or something, and then, you know, he'll do that first conversation with you and then he gives you homework. **11:11 Elissa Shevinsky:** Yes. **11:12 Chris Romeo:** And if you don't do the homework, then when you come back to him and say, hey, can we— **11:17 Robert Hurlbut:** can I get together and kind of pick your brain again? **11:19 Chris Romeo:** He's like, hey, did you finish the, you know, what we talked about in the first meeting? And if the answer is no, then he doesn't schedule the meeting. He just says, hey, that's right. I gave you some things to think about here and, and go ahead and take a look at those. He kind of reaffirms the idea of, hey, take a look at those things we talked about and then reach back out after you feel like you got an answer. And so, it really put the onus on me as the mentee to have to do the work. And it was good stuff. I mean, I got to the end of the process, I was like, wow, I'm glad I did this. But it was just a different way to think about mentoring too because we're all pretty busy people, right? We have day jobs and everything, but we have a passion to want to help other people and share our experiences. And that was just one way that he He kind of taught me about how to prioritize and help people get the most out of the available time I have. **12:06 Elissa Shevinsky:** As you're saying that, I'm thinking about the process I'm going through here at Techstars London, where we have what's called Mentor Madness, and I met with— was it 10? I met with like 10 people today who are mentors to the program, and in most cases where it's a good fit, we do get some kind of homework and we have to follow up about it. And that's, I think, even at, you know, as you, even as you get to be at a more senior level and you're mentored by more senior people, we still get homework. And that's really important. It's a way to show we're sincere and that we're gonna put the work in. I think about that when I mentor people. You know, I wanna know that it's time well spent. I wanna know that it matters to them. I think, yeah, that's exactly right. **12:52 Chris Romeo:** Yeah, definitely. So what is Techstars London? **12:55 Elissa Shevinsky:** Techstars is this accelerator program and they have offices and programs all over the world. Even though I was based in New York, I chose to come out to London because it just felt like such a good fit with this program. They don't accept a lot of companies. They had something like 1,200 applications and took 10 companies, so I feel just overwhelmingly grateful. to be here. And a big part of Techstars London is this mentorship concept where you meet a lot of potential mentors and you end up working closely with a small number of them. And I'm sure a lot of that will involve them giving me homework assignments and me doing it, and in some cases me asking them for things and them doing it, like, you know, maybe an introduction or for them to review something and give me feedback. And they also have a gift first mentality. So, you know, there are a lot of different programs in entrepreneurship and in information security, and this is the first time I've encountered something where it's so explicitly about give first. So it's, it's, for me, that's really, really nice. I, I think it feels like there's really this underpinning of ethics and of community here. **14:09 Robert Hurlbut:** So, Alyssa, I want to change topics here slightly. Um, one of the things we've talked about— **14:14 Elissa Shevinsky:** Oh yeah, we did get a little off topic here. **14:15 Robert Hurlbut:** No, no, no, no worries at all. No worries. No, I just wanted to get into our main topic here today, which is on static analysis. So that's something you've been passionate about. Tell us, what is static analysis? **14:28 Elissa Shevinsky:** Yeah, and you know, a lot of my passion— I'm interested in static analysis, and I've certainly— so much of my life right now is dedicated to it. I have a startup that's building static analysis tools, but a lot of what I really worry about is making security easier. for people and making sure that people are doing security. Static analysis is a method of computer program debugging that is done by examining the code without actually executing the program. And so what we do generally is scan the code, and the code gets scanned for things that are likely vulnerabilities. In some cases, they're almost certainly vulnerabilities, but in all cases, you need a developer to actually look at the error messages that are generated and determine if a fix is necessary. Does that make sense? **15:18 Robert Hurlbut:** Yeah, absolutely. One of the number one things I hear sometimes that people say, when you said that developers still need to look at the report, they still need to verify, is that sometimes they'll come back and say, well, there's a lot of false positives here. It found something, I don't think that's a real vulnerability or something like that. Do you hear that often as well? **15:42 Elissa Shevinsky:** Oh my goodness, all the time. We came to this because we did have a consulting firm and we were doing static analysis as a service. Companies would hire us to run static analysis and then give them the report along with helping them assess fixes. I saw a lot of times where the companies would come back and say basically won't fix, and in most cases that was legitimate. So maybe the error message would say, quote unquote, use of assembly code, and that, you know, that's a red flag. But if you have a company like the 0x Project and they've been really thoughtful in their use of assembly, it's not a problem. But there are other instances where the company just doesn't want to fix it, and it doesn't really mean that there's no vulnerability. They just, you know, they've just chosen to accept the risk. **16:35 Chris Romeo:** Right. **16:35 Robert Hurlbut:** Which really, I guess it comes down to that, right? So there's that trade-off sometimes. But I think that— well, actually, let's talk about what are some of the benefits of static analysis. I think you may have touched on it, but what is it providing for those developers who get those reports? **16:51 Elissa Shevinsky:** Yeah. Well, those developers are right when they say that there's a lot of noise and that there's a lot of red flags, but if you don't do static analysis, if you don't do these types of tests, then you could miss a number of vulnerabilities that really are there, and you could ship code with these vulnerabilities. That could mean devastating things for your company or for your customers. It could mean that you've left the door open for a hacker to come and steal data or steal money or do some devious thing that you don't want. really important to do proper security checks even though it's time-consuming. The benefit is you're providing some level of assurance that, you know, these errors aren't present. There's certainly— it's not the only tool. You need to have a whole arsenal, but static analysis does quite a bit of work here. **17:45 Robert Hurlbut:** In terms of, you know, running it, I mean, is there any challenges that developers face? When do they run static analysis? Any recommendations there? **17:58 Elissa Shevinsky:** Yeah. And actually, I'm really interested in discovering more about how static analysis fits into the pipeline of different types of companies. Obviously, there's a certain amount that I know, but I'm in the process now of seeing like what's the full range. So I'd love for people to find me. We can talk about how to reach me after the show, but I'm really interested in talking to people about how they're doing static analysis If anyone has an interest or would wanna talk to me about it. In general, the challenge for an individual developer doing static analysis is you have to set up and configure open-source tools, or you have to pay for and set up and configure paid tools. And both are kind of a headache. On the corporate side, static analysis really, if you have a large codebase, it can take 8 hours or more to run. And so, you have these companies and they wanna be agile, they wanna ship daily, and they want to have continuous integration, and, like, all the buzzwords that are actually— there's good reasons why companies wanna do all of this. And it's hard to have continuous integration and be agile with an 8-hour process that's, like, there as a bottleneck. **19:05 Robert Hurlbut:** Right. **19:05 Elissa Shevinsky:** So, I think I'm still in this process of discovery, like, what are all the problems that people have with static analysis? But those are the two really big ones that I found so far. **19:16 Robert Hurlbut:** I'm curious on that one. Yeah, the 8-hour, especially in an Agile process or methodology. Yeah, I'm curious about solutions to that as well and what has worked for different teams when they've seen that. I know in my own experience, and this has been a few years ago when I was working on a team, and what we would do or what they would do is that they would set aside It was sort of a— what do they call it— water Scrumfall. It was, you know, more waterfall than anything else, but we pretended that it was Agile and had Scrum meetings and such. And so basically deploying was not every night, not every hour or anything like that. It was, you know, every few weeks or something like that at the end of a sprint or sometimes even longer. We might take to actually get a release out. That's when they would run the static analysis as that last part before a full deployment. But when you're in a situation where you're running deployments all the time, yeah, very curious about how does it fit into that lifecycle? **20:27 Elissa Shevinsky:** Yeah. Well, what I'm seeing right now is that we're really in this moment where large companies are starting to rip out their current infrastructure and then replace it with new things. So we're seeing that companies are trying to look and figure out how do they solve this problem. So one way that— there's one large company and someone inside told me what their plan was. They have some ginormous codebase and they plan to just break it into 5 chunks just to take the codebase and make it smaller. So that's certainly one approach. You have this huge codebase, it just takes too long to run, just like, Okay, figure out how to make the codebase, like not one codebase, make it 5 codebases. And then there's different tools that you can use. So we built a tool that uses Docker to run the scans in parallel, which I think is very innovative. This came from Brett, my mentor who was my security mentor and now he's working with me. So there was a certain genius to that. I think that solves the problem really nicely, right? So instead of waiting for one scan to run, then you do the next scan, then the next scan, just run them all. at the same time. And so also some of these companies are looking at how to use Docker and use containers to speed up this process. I don't know if they're planning to use parallelization, but I've definitely heard people throw around, you know, the term they're going to use Docker as a way to make this faster. **21:46 Robert Hurlbut:** Yeah, very nice. Yeah, I was thinking as you were mentioning that, you know, one of the architectures that I see often, or maybe last few years anyway, at different teams is microservices. So you're dividing everything into very small discrete libraries or services. And so yeah, if you did the same thing where you're just simply scanning all those, and if you can do them concurrently, even better. So yeah, it sounds like some, some interesting solutions, potential solutions. **22:17 Elissa Shevinsky:** So yeah, and anything that makes it easier to do your security testing, right? I'm all for it. **22:23 Robert Hurlbut:** Right, right. Well, that— and I think that's the End goal here, right? We want to— we want— obviously we know we need to do it, right? But how do you make sure that it works within the structure, within the goals, within, you know, your daily— you know, the work that you're doing every day, that it's just another part of everything that you're doing and it's not trying to take away, but it's really actually adding value? **22:52 Elissa Shevinsky:** Yeah. Yeah, security is never trying to take away. It's just, it's a challenge to express and explain the value of like why security? Why does security matter if you don't already inherently like have the feeling like you're a security person? And that's something that I'm thinking about a lot now as I do storytelling to people about security. You know, I'm meeting people every day that want to know what I'm doing. I'm trying to explain to them, well, you know, I make the security tool. Okay, tell me about that. Why does it matter? Give me examples. And I'm trying to think of, like, what are the examples in people's lives? And they're reading about the breaches in the news. They're reading that companies are fined. They're reading that people lose their jobs, like, on the executive level. So, that's something that's been on my mind a lot. And I guess also, like, switching modes and thinking about some of the core values of your podcast, I'm really interested in how people who are more junior in their software development careers can start to learn security. **23:47 Robert Hurlbut:** Yeah. **23:48 Elissa Shevinsky:** And one thing that I've been encouraging is for people who are junior developers to learn static analysis, just because that's a space that I know, but there's probably a lot of other things like this as a way for them to level up, you know, as a way for them to stand out and just become better developers and, like, get interesting jobs. **24:04 Robert Hurlbut:** Yeah, I think that's great. Not just wait or just give this to the more advanced senior team members, but But yeah, start early. We want everybody to really understand the importance of security, so start early. I think that's a great idea. **24:24 Elissa Shevinsky:** There's also an aspect of static analysis that isn't really security, and I don't really talk about so much because I mostly care about the security part. But static analysis will show you formatting errors and all ranges of ways to just improve your code. So if you're a junior person and you're running this security test, You look at FindBugs, for example, which runs on Java, they have a category that's just like dodgy code. It's dodgy code. So I think for junior people, they can come to static analysis for the formatting and for the other glow-ups and stay for fixing your SQL injection. **25:06 Robert Hurlbut:** Yeah. I've actually, in my career in security and development on both sides, different times I've focused on code quality. I know some others, Dennis Cruz, for example, will focus on both and says secure code is actually good quality code too. If you're treating it appropriately, it makes sense. I could definitely see that nice benefit of a static analysis for security that could also improve their code in general as well. **25:38 Elissa Shevinsky:** Yeah, I think that's 100% right. **25:42 Robert Hurlbut:** So what are some best practices? We've talked about quite a few things here, but what are some other best practices here for static analysis? **25:50 Elissa Shevinsky:** You know, I think there's something to be said for just running it more frequently. I guess it depends on how often you're shipping code, but one of the things that I'm hoping to see as we start to shift towards like static analysis being faster, it's just static analysis being more frequent. My worry is that people just don't do it at all. That's certainly true for the individual developers and when people are writing, say, in Python and it feels like it's not so necessary. Let me see how I can say this delicately or nicely. I was scanning a bunch of open source code today and I found a mess of stuff. You know, so it's— I think it's really important just that people do it. I think the best practice is just to do it. **26:41 Robert Hurlbut:** Well said, well said. Um, any, any last thoughts as we, uh, wrap up our conversation? Really enjoyed this. Any last thoughts today? **26:51 Elissa Shevinsky:** Uh, I just want to inspire people to come into the field, you know. Like, I was a political science major and now I am CEO of this company that is in this like really incredible program. And I'm working with the CTO who previously was protecting 200 million credit cards at his last company. And so, if I can get from where I was to here, I know anyone else can do it. It's just you have to have a lot of hustle. I never gave up. I always knew that I really wanted to be making software. at a certain point, I knew I really wanted to be making secure software and security software. And if this is what you love, just stick with it. And also, I have a little bit of room to mentor one or two more people, but I'm going to give you homework. So, you can follow up with me, find me by my name on LinkedIn or Twitter or Facebook, and I'd be happy to help, but you're going to have to do those assignments. **27:48 Robert Hurlbut:** Oh, great, great. And then you're going to be out at DEF CON? I won't. **27:54 Elissa Shevinsky:** So I love DEF CON and I go almost every year, but I'm in London for this program. It's so intense. Oh, right. **28:01 Robert Hurlbut:** Okay. **28:01 Elissa Shevinsky:** Yeah. So they're setting up like 10 meetings every day. So I'm not there this year, but I have to give a shout out. Like, one of my best friends, Tanya Janka, is doing just so many talks and I'm really excited and I hope everyone will go and cheerlead her and tell her that I sent you. **28:19 Robert Hurlbut:** Definitely will. Definitely will. Okay, well, Alyssa, again, thank you for being with us today, and we'll definitely consider your advice: run static analysis often. **28:31 Elissa Shevinsky:** Thank you so much for having me on the show. **28:37 Chris Romeo:** Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stone Von Kartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/elissa-shevinsky-static-analysis-early-and-often/