Skip to content
AppSec PodcastThe Application Security Podcast — home
44 min

Jeff Williams -- The History of OWASP

with Jeff Williams

on OWASP Top 10, OWASP Projects, Software Supply Chain and Vulnerabilities and Exploits

Audio hosted by Buzzsprout. Nothing loads until you press play.

Chris talks with Jeff Williams about the History of OWASP and where it came from. 

You can find Jeff on Twitter @planetlevel

Mentioned in this episode

Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.

Transcript

7,427 words · assemblyai

0:01Chris RomeoGood morning, good evening, or good afternoon, wherever you find yourself in this fine world. This is Chris from the Application Security Podcast, and you've reached season 4, episode 18. This episode is called The History of OWASP. We have explored various projects and different angles on the world of OWASP, but I found that I really couldn't answer the question, where does OWASP come from? And so we spoke with Jeff Williams, who was around in the beginning of OWASP, and asked him to share the story of the origin of OWASP. We hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. And this week I am joined by a special guest, somebody who I've known for a long time in the world of security, who was actually around and was already doing security when I actually got into this, this fun thing that we call security. And this is Jeff Williams. And Jeff, I'm going to kick off and just go right into, as our listeners have come to enjoy, what is your security origin story and where do you come from in the world of security?

1:39Jeff WilliamsHey, Chris. Well, thanks for having me. I was just trying to think when we first met. When did you join ARCA?

1:46Chris RomeoApril 1st, 1997.

1:49Jeff WilliamsApril Fool's Day. So we're at 21 years now.

1:53Chris RomeoYep.

1:53Jeff WilliamsThat's not bad. So, you know, I got started in computers around 1983 in high school, and what got me into security actually was, if you remember back in those days, you'd get, you know, software games and stuff on floppy disks, and they tried to copy protect them. And there were a whole bunch of different schemes at that time for copy protecting stuff. I just found it to be the best puzzle in the world. The software has to run, so there's got to be a way of forcing it to load. For me, it was just working backwards through the mousetraps to figure out how to get the— crack the copy protection and make copies of the software. It wasn't like I was distributing it or anything, but I just didn't like the fact that it was copy protected. So I learned a lot about, you know, assembly language and operating systems and loaders and all sorts of stuff like that. And that, that's just kind of how I got into security. Then I went to, you know, eventually went to college. I studied a lot of computer science and didn't do a ton of security in college because it just wasn't a thing.

3:09Chris RomeoYep.

3:09Jeff WilliamsBut then I went— my first software job, I joined TRW, and I was assigned to a classified project building a system for the Navy that was B2-level security. You know, maybe your listeners don't know, there used to be this thing called the Orange Book. B2 security is really high. There's only a couple levels higher than that. B2 means that that system is formally modeled. You've got a security model that's represented in a formal logic and mathematically proven. Nothing these days goes to that level.

3:45Chris RomeoNot even close.

3:46Jeff WilliamsWe have lost a ton of what we used to know about security, actually. But through that project anyway, I got exposed to security and I really liked it. You get to touch all different parts of a system, and I am kind of ADD, so I like moving from thing to thing anyway. So it was a good way for me to touch a lot of parts of an application and then move on to the next thing.

4:11Chris RomeoAnd then, so how— so then that, that wasn't ARCA though, right? That was TRW.

4:20Jeff WilliamsThat was TRW. So actually then, uh, after I got to be an expert in something called a compartmented mode workstation, which was, uh, this multi-level secure operating system that was around for, I don't know, a decade or so. There was Trusted Solaris for a while, maybe some of the folks on the call remember. But at the beginning of that, there were actually 5 different compartmented mode workstations. And so I got to be expert in that, and I got hired by a security company called Arca Systems, which was really a cool company. I feel like I got an opportunity to work with and learn from the guys that were great at high assurance.

4:56Chris RomeoYep.

4:57Jeff WilliamsAnd what's weird is that company got bought by Exodus Communications, which is, you know, a data center company, or was a data center company, and going super fast and really didn't have a good match with the high assurance world. So we had these few years where we were trying to figure out like, how do we apply these principles from these high assurance, high security computing techniques to modern internet systems? And, you know, some of the folks at Aspect got really irritated and couldn't do it. At ARCA got really irritated and couldn't do it. And some folks, I think, like the application security team that we started, just dove in and said, okay, well, let's figure it out. Let's figure out a way to get get some kind of assurance into modern web-based software.

5:44Chris RomeoYeah, and it's, it's, uh, I kind of went the, you know, being with you at Arca and then being a part of that acquisition at Exodus, I kind of went the traveling consultant side of the business and had a chance to work on the incident response team. And so I think that was a great opportunity for all of us. And now that I look back, it's like, Wow, look at how much we grew though as a result of that company buying us, which like even at the time we were all like, this doesn't even make sense. I mean, this is an internet company. We're all gonna be billionaires. But, you know, of course we're not billionaires, but—

6:20Jeff WilliamsRight.

6:22Chris RomeoThat part kind of broke out. But yeah, great opportunity for a lot of us at that time to really grow. And you kind of look at that group of people that came outta ARCA and you can trace those people across the government, across various commercial entities, and even on the consulting side. Yeah, it was just a great overall culture, great overall company. And just, it's a model that I know I carry forward. I know you do the same. Like, how do we recreate this is how we're always thinking when we build companies and stuff. And so, I know then you came out of Exodus, you ended up starting Aspect Security, which a lot of people will have heard of before doing the consulting thing. And then it was onto this new thing called Contrast, right?

7:04Jeff WilliamsYeah, exactly. So, you know, I spent a dozen years at Aspect doing application security consulting with some of the biggest companies in the world and working on some of the world's most critical applications. And we did a lot of great things, one of which was to do a lot of work at OWASP. And, you know, that, that for us was just a great way to show off our talent while doing great things for the world. And so I really loved that time. Then we had an idea for a new way to do application security from inside the app, more like an AppDynamics for security and not for performance, and that became Contrast. Maybe we'll talk about that at some point.

7:47Chris RomeoYeah. I mean, kind of the real premise I had for this conversation is that I know you just mentioned OWASP and the fact that when you were operating Aspect Security, you guys were doing a lot of work with the world of OWASP. And so, I'm a relatively newcomer in the grand scheme of OWASP. I mean, I've certainly always known what it was and was aware of it, but it's only been the last couple years where I've really actually gotten actively involved as far as leading a chapter. And I had a chance to participate on the latest version of Proactive Controls. And so, Kind of getting plugged in. And so kind of led me to the question, like, I wonder where this whole thing started. Where did this whole thing come from? There's got to be an origin story to this OWASP thing.

8:36Yeah.

8:36Chris RomeoAnd so if you can kind of, you know, take us on the Wayback Machine here and go as far back as you can to kind of what you think of as the beginning of OWASP and kind of just start to tell us that story, I think there's, I think there's a lot of value in, in as OWASP people now knowing where we came from may even help us as we look into the future.

8:55Jeff WilliamsWell, the first I heard of it was when Chuck Fleeger said, hey, there's this thing called OWASP that you ought to check out. Chuck, as you know, is the author of Security in Computing. Some of you may have used his textbook in school. But he pointed me at it and said, you should go check it out. So I went and took a look and it was like a mailing list in those days. There were, I don't know, maybe 15 or 20 folks on the mailing list just talking about building an application security guide. That was the first big project at OWASP, and they produced the first version of the OWASP Guide was created in those days. It was all just kicked around on mailing lists, and there was not really a website. I followed along for a few months, and then someone posted a message about creating a vulnerable application to learn AppSec from. As it happens, I had built one for my training classes. It wasn't yet called WebGoat, it was just the environment that I used in my class. But I thought about it for a minute and I thought, Well, Aspect could keep this environment to itself and try and sell it and so on, or we could make it free and open. I was worried that if OWASP just went and built one, then there would be no point in ours. Nobody would use ours. I was like, let's just contribute it and see what happens. That was our first major donation of open source to OWASP was WebGoat, and it was fairly similar to the WebGoat that you see today. It had several dozen lessons all designed to help you understand different vulnerabilities and learn to test them. We put it out there and the response was fantastic. Tons of people were commenting on how much we understood about AppSec and just how fun it was to use that. To this day, I still meet tons of people who say, oh yeah, WebGoat, I got into AppSec because of WebGoat. Yeah, that's awesome.

11:13Chris RomeoAwesome. So what year are we in right here now?

11:16Jeff WilliamsThat's like 2002.

11:18Chris Romeo2002.

11:19Jeff WilliamsYeah. And the end of 2002. And so that went so well that that same year, end of 2002, at Aspect, I was going to a bunch of companies and government agencies and talking to them about AppSec. And if you remember, in those days, the big thing was the SANS Top 20.

11:42Chris RomeoYep.

11:42Jeff WilliamsAnd so I just kept getting this response like, yeah, sort of understand what you're saying, but we're working on the SANS Top 20 right now. And they were much more concerned with network security than AppSec. And I just thought to myself, I was like, we need a top 10 of our own. And so I just came home and, you know, in a few days and over the course of about a couple weeks, you know, bringing in some other folks at Aspect, And OWASP, we just put together the first version of the OWASP Top 10.

12:11Chris RomeoWhich— this was— does this actually have a— did it have a year attached to it, or was it just the Top 10?

12:16Jeff WilliamsWell, we drafted it in 2002, and then the first release was in early 2003.

12:22Chris RomeoOkay. Was it called 2003, or was it just the Top 10?

12:25Jeff WilliamsOh, it was the Top 10 because it was the first one.

12:27Chris RomeoI love it.

12:28Jeff WilliamsSo we put it out there, and the response was unbelievable. We got Slashdotted. And it took down OWASP. At that point, we stood up a couple of web servers and it totally obliterated us for like 3 or 4 days. But it was amazing attention for the project. And so, again, everything at OWASP was kind of this combination of like what's great for the world and what's great for people personally, both on the personal development side and career side, and maybe even on their, you know, if they are running a company or they're part of a company, maybe even for the company. And I feel like, uh, you know, this just met all of those criteria. It was good for me, it was good for Aspect, it was good for the community, it was good for, you know, folks out there trying to learn about Aspect, uh, AppSec. So, um, you know, that was another great experience that we had. And, you know, I spent the better part of the next year going around to tons of companies, telling them about application security, talking to them about the top 10 and what they should do, how to start an AppSec program and build what they— they probably didn't have anything at that point. If you remember, those were the days when you could pretty much just fire up Achilles or WebScarab and do a little bit of testing and you would find the same stuff every time, cross-site scripting, SQL injection. There wasn't CSRF yet. You would find a a ton of lack of caching headers and all the same kind of stuff. Actually, now that I think about it, we're still kind of in that time. Problems have changed slightly but not really very much. Actually, if you look at the top 10 now, it's almost the same as it was back then.

14:22Chris RomeoYeah. I mean, a few things have come, a few things have gone along the way. I guess early in that, with that first top 10 being put together, Is this just a bunch of people sitting around a table going, let's just— let's think about what we've seen, what has been our experiences? I mean, because it's not like you had a data source or anything that you could go to. I can't imagine at that point there wasn't, you know, it's hard to— you know, we just— we're just getting to the point now where we have decent data sources to be able to draw, you know, the future, you know, the new versions of the top 10 like the one that was done in 2017. So—

14:55Jeff WilliamsYeah.

14:56Chris RomeoIs this just a conversation with a bunch of folks around the table going, hey, what do we— what do we think we're really seeing?

15:02Jeff WilliamsYeah, and I mean, it was based on our experiences. It was mostly folks from Aspect, but, you know, there's a few other folks that reviewed it at that time. But it was based on a few years of consulting experience working with lots of web apps, but it wasn't really database.

15:21Yeah.

15:21Jeff WilliamsAnd I want to take a second and just comment on that because I think it's actually a little bit dangerous to be totally based on data.

15:30Chris RomeoYep.

15:31Jeff WilliamsProblem is that data is, you know, really backwards looking. And frankly, you know, Josh Corman and other folks talk about this. If you're, if you're looking backwards, and you've got some standard based on the things that you're seeing now, or more likely, you know, 2 or 3 years ago, you're not really getting in front of the threat. At best, you're sort of slightly lagging behind Metasploit.

15:56Chris RomeoYeah.

15:57Jeff WilliamsAnd so I think it's important that we look forward. We should be protecting our applications against the threats that are 5 or 10 years out because our applications that we're building today are probably going to still be in service in 5 to 10 years. So we need to think hard about the future and what's coming and not just look at the threats of Yesterday or last year.

16:22Chris RomeoYeah, that's one of the things I like in conversations I had with the OWASP Top 10 team that was putting together the 2017 edition. They took that data, but they also did some— they also had some community polling, or for lack of a better idea, like the ability for community participation as far as what are the things that you're seeing that you think are really potential challenges. And so, yeah, I mean, I think there's a balance between those 2 things, but I get what you're saying completely about, you know, if we completely focus on the data, then we could miss some new thing that somebody's thought up and, you know, is going to zing us within a year or 2 from now.

17:05Jeff WilliamsWell, you know, back in the day it was easier when there weren't as many people involved in the OWASP Top 10, wasn't such an important standard that so many people depend on. But, you know, there was— it wasn't easy. That process was full of a lot of controversy. You know, we put in some things in the top 10 that I think are really important, but weren't supported by the data in 2017. And, you know, I thought that was the right thing to do. And, you know, there's, there's so many contingencies now with vested interest in the top 10 that it's actually, it's really a difficult process. Yeah.

17:48Chris RomeoI totally agree. And having seen just kind of the outside, an outside looking in view with maybe a little bit more depth, it does certainly is a challenge to do that and try and prevent any of the outside interests from kind of having a kind of, you know, bringing it into some, you know, influencing it in some way that, you know.

18:10Jeff WilliamsYeah, it's tricky.

18:12Chris RomeoIt's tough. Yeah. So the top 10 is out. It's taking the world, but did it take the world by storm or did it just kind of take the people that were interested in it by storm?

18:23Jeff WilliamsWell, at the time, we thought it was taking the world by storm because we had hundreds of thousands of downloads. But that's not— at that time, there were probably 10 million developers in the world. Today, there's over 20 million developers in the world. We reached a lot of people with it, but Over the years, it's become clear that the OWASP Top 10 was just getting started at that point. Now it gets millions of downloads every year. It's become a much bigger deal, but we thought we were killing it.

18:55Chris RomeoYeah, I bet you that I could see how it's had an impact every year. Like you said, the impact has likely grown bigger and bigger as it's 'Cause you think about what is the document that everybody points to? If you ask just general people in tech or developers, most people at this point have heard about the OWASP Top 10. Maybe they can't explain it to you, but at least they'll say, hey, yeah, their net promoter score would be like, I don't know if they'd recommend it, but they'd at least say, I know what it is and I've heard of this thing along the way.

19:31Jeff WilliamsThe hard thing for me is that I'm not really a big fan of top 10 lists or even that whole approach to security. I was trying to raise awareness and unfortunately, actually, I think in a lot of ways the OWASP Top 10 created a ceiling. I was trying to create a floor. I thought, oh, we'll put these top 10 out there and then companies will get their head around those and they'll fix them and we'll stamp out SQL injection and then we'll add some new things to the list. Over time, we'll raise the bar. But the problem is that hasn't happened. I think every company I work with still, they still have kind of the same issues in AppSec that they had back then. Failure to do basic blocking and tackling is the biggest problem facing the industry, and that's after 20 years of trying. So ultimately, is the Top 10 a success?

20:27Chris RomeoYeah, that's— yeah, I mean, that's— and I don't know that I have a good answer to that question, but I do have a kind of a common joke I use all the time, and that is is, you know, why don't we just focus on the OWASP Top 1, create a new document, and when we, when we figure— when we get that one done and we put it away, then we can start kind of moving forward and, and worry about the next couple of things.

20:48Jeff WilliamsBut, um, yeah, I actually don't think that's a joke. I've worked with some companies that way, and we said, hey, you know what, we've got a serious SQL injection problem, let's stamp it out. And we did. We pushed them, you know, just to establish, you know, great database abstraction layers and worked that across the company, and we stamped it out in a couple of other things in less than a year. Then we went on to some of the other things. Over time, that company has one of the best AppSec programs in the world. I have 100% confidence that they will never have a SQL injection problem.

21:25Chris RomeoYeah, it would be—

21:27Jeff WilliamsI just don't see how it could possibly happen.

21:29Chris RomeoWe need more stories like that. We need more companies that take that approach. And maybe that's the actual approach that they should be taking is—

21:36Jeff WilliamsActually, that's the key to DevSecOps. I mean, to really, to just sort of, if you think of DevOps as a process, as sort of creating flow by knocking off little pieces of work and pushing them through the process and delivering them all the way, security needs to reinvent itself in the model of DevOps. And I've been doing some writing about that. DevSecOps ref card that I wrote for DZone. That's a good introduction to that approach.

22:02Chris RomeoYeah, and I think that's— yeah, I mean, it makes sense. It's about so much that's done in security is about making things more complicated and more difficult. And I know that you think very similar to me in that, how can we make it more simple? Let's not make things complicated because complicated means things just don't happen. But if you go simple, you have a chance of of having some amount of success. So, after the break, we explore the current status of OWASP as an organization. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. As we return back to the interview, the top 10 is out, the year is 2003, and the question for Jeff is, is there an organization yet behind OWASP? What about a board of directors?

23:15Jeff WilliamsNot at all. Mark Kerfe was the guy that started the mailing list originally, and he was still in charge at the beginning of 2003. We decided as a group— it's just a mailing list and a couple of servers. The servers were actually under some guy's— it was in a cage in a data center in Atlanta. They weren't authorized. Let's just say that. They were in someone else's cage. If you remember, this is about the time the dot-com crash is happening. Eventually, the companies whose cage we were crashed in went out of business and stopped paying their data center bills. The data center company actually reclaimed all the servers in that environment, and they took OS offline. I had this very funny call where I'm on the phone with their lawyer. I'm like, yeah, look, our servers got caught up in this thing. We're the good guys. We're open source. We don't have any money or anything, so you can't squeeze any blood from this stone. How about just giving us our servers back? The lawyer's like, I understand what you're saying. No. We lost those servers, never got them back. We had to start over.

24:34Chris RomeoThey're in a warehouse. They're in a warehouse somewhere.

24:35Jeff WilliamsSo, uh, it was about that time we had our first conference. We, we did a conference up in, uh, New Jersey at NGIT. And, uh, it was a great conference, a bunch of great speakers and, uh, all focused on AppSec. And it was really sort of the first conference ever exclusively focused on AppSec.

24:56Chris RomeoWas this— was it AppSec USA or did it have a different name?

24:59Jeff WilliamsWell, we didn't call it AppSec USA yet because we didn't know that we were international really. We hadn't really figured that out. That came a little later. We had this great conference. Mark Herfrey started getting frustrated with the slowness of OWASP at that time and asked me to take over as global chair. I loved OWASP. We were fairly heavily invested. I was running a company, so I didn't really want to run OWASP too.

25:26Okay.

25:26Jeff WilliamsBut we were pretty heavily invested in it, so I said, okay, I'm going to take over. My goal was to make OWASP self-sustaining. I took over and I said, all right, well, we got to fix the website because we're in disarray there. We got MediaWiki and we set that up as the OWASP website. The idea there was to foster contribution. We had spent a little while trying to build our own XML-based CMS as a demonstration of what secure programming could be.

25:58Chris RomeoYeah.

25:59Jeff WilliamsBut that was a disaster. It was way out of our league given our resources.

26:04Yeah.

26:05Jeff WilliamsWe got MediaWiki, we set that up, that started going. We set up a board of directors and some governance processes. We created the OWASP Foundation, which is a 501 charity that's actually the actual organization of OWASP. We transferred things like the brand and all the IP and the servers and so on, all that to the foundation. We set up a couple of other programs. We started the OWASP Conferences Program, and that's where AppSecUSA came from. We started doing conferences around the world. This was all volunteer-based, right? No one gets paid anything. But the conferences started generating so much revenue that we really actually— we weren't charging much. We were only charging like $50 a person. But we didn't have any expenses because we had no employees or anything. So we started piling up some money to do good things. We started the OWASP Chapters Program, and that was fun because, you know, I was getting calls from all over the world from people that wanted to start chapters. Like, I didn't know where Hyderabad was, but I got a call from somebody there. And they wanted to start a chapter, and I was like, well, you know, Do you want to just join with the other India chapter? They are like, oh, no, that is 9 hours by bus. I am like, oh, yeah, okay. Well, you need to be a separate chapter. We grew this international organization with a couple of base principles. At core, our mission was to make application security visible so that people could make informed decisions about risk. That is actually a little bit subtle. The goal there is to fix the software market, because when AppSec is visible, then buyers and sellers both have the same information and they can transact fairly. But currently software is, uh, super asymmetric. Most people who use software have no idea about the security that's in it. And I'll give you an example. Do you bank online?

28:06Chris RomeoI'm gonna wish I said no, but I'm gonna have to say yes, to be truthful.

28:10Jeff WilliamsEveryone says that you have to basically. Even if you don't bank online, really your stuff is online anyway. I bet you don't know very much about who wrote that code, how they tested it, what tools they used, were the developers trained, what open source components are they using, what other AppSec processes do they use to make sure that thing is secure?

28:29Chris RomeoI would say I know none of that about my bank.

28:32Jeff WilliamsIs that not terrifying? You're trusting all your finances to that.

28:35Chris RomeoJeff, I have to go to sleep tonight at some point. Now, I'm going to be sitting here pacing around my house going, how's my money doing?

28:43Jeff WilliamsWell, I'm going to come back to this theme, but unfortunately, even after 20 years of OWASP and trying to improve things, we are still in the Stone Ages of application security. We're not anywhere near where we were in the Orange Book days. I think we've gone, you know, we've made massive technological advancements and things have gotten massively more complicated and so on, but in terms of security and assurance, we're nowhere close to where we were back then. So we still got a long way to go, and this is a strong plea to folks out there in the field. You can make massive contributions to application security. You can be Galileo. You can be, I don't know, whoever you want to be. Elon Musk. I don't care. Whoever you want to be of application security, there's still plenty of room to go innovate and change the way that we build software with regard to security.

29:46Chris RomeoYeah, that's a great call to action though to let people— we definitely need more people. There's just so much room, like you said, for additional growth here. I think we've come a long way in the world of application security, and I just did a talk this past year where I, it's called, I'm gonna play it for our listeners at some point, but it's called Building an AppSec Program Based on OWASP, so basically with a budget of zero.

30:13Jeff WilliamsYeah.

30:14Chris RomeoAnd so I got it, what I did is I went and I looked at every project in the OWASP universe and analyzed, and one of the things, one of the big realizations I had is there are some really cool things that are happening in the world of OWASP, that nobody has any idea about. They're just not marketed at all.

30:31Jeff WilliamsThat's right.

30:33Chris RomeoLike, really, like, I don't know, do you know Defect Dojo?

30:35Jeff WilliamsYeah, it's fantastic.

30:37Chris RomeoDid you know the number of plugins that Defect Dojo has?

30:40Jeff WilliamsI don't, but it's probably staggering.

30:43Chris RomeoIt's about 50. You know how I found it? I went deep into the documents, and I talked to the project leaders about that, of that. Matt Tesaro, I saw at AppSec USA, and I mentioned it to him. And so Yeah. I'm not picking on them at all. I mean, we're— I'm just saying, like, that is a huge marketing point that, that I didn't know. And the only reason I found it is because I was doing this research and I went deep into the doc. I was— it was like the bottom of their documentation.

31:06Jeff WilliamsYeah.

31:06Chris RomeoWhere they had the list. And I'm like, they have all these, like, commercial vulnerability scanners that they take inputs from and DAST tools and, and open source tools. And I'm like, wow, this is really cool. But But nobody— I don't think most people even know that this tool, much less what this tool does, but the depth of integrations that it has with other, even commercial tools.

31:28Jeff WilliamsYeah, that's right. So one of the major failings of OWASP is that it doesn't do nearly enough to promote the really good stuff that's going on inside OWASP. I'm concerned that OWASP has lost its way a little bit. We had the idea that— remember, I stepped down as OWASP chair, I don't know, 7 or 8 years ago. Is that right? Yeah, it must be. Well, more like 5 maybe. I don't know. We always had this idea that OWASP should be a platform, that these great projects like DefectDojo, they should live on top of the OWASP platform, which should give them support. It should help them build community, help them market their products. not financially contribute to building the thing. We thought all that work should be volunteer, but there's plenty of things that open source projects really struggle with in terms of setting up infrastructure and promoting their product and so on. Those are the kinds of things that OASP, I think, really should be doing. I was dismayed to see that there are 20 big, hairy, audacious goal was to offer 4 training sessions for developers. I think they said of, was it 200 each or something like that?

32:56Yeah.

32:57Jeff WilliamsBut imagine that, their huge goal for the year is to train 800 developers out of the 20 million developers in the world. I was like, how does that make any difference? Like, OSPF has got to focus on things that could potentially really change things. They're not going to launch commercial products, but they could be the incubator for those projects.

33:20Chris RomeoYeah, I mean, I look at something— I mean, how much do you know Dependency Check and Dependency Check?

33:26Jeff WilliamsI love it. I recommend it all the time.

33:27Chris RomeoI do too. But, and I mean, I'll say, Pound for pound, I think those are as good as anything I can buy commercially at this point. But I don't know that they get enough— I don't know that they actually get the traction because— and I don't know if they suffer— if it's the same problem as Defect Dojo where they're just missing some of the, you know, the marketing flair to get the word out about them. I know, I know Steve and Jeremy from that— those projects from Track and Check, they do a good job of, of, of marketing and getting the word out about kind of those things, but Yeah, I mean, another, another great example of technology that's just really high-end stuff, and with a little bit of marketing behind them, they could go even further than they have now.

34:11Jeff WilliamsYeah, well, I've learned a lot about marketing in the past few years. It is really tough. I mean, you know, there's 1,000 security companies at RSA every year, all spending tons of VC money on booths and flyers and beer parties and all that stuff. And security folks get overwhelmed. You can't spend time with 1,000 commercial products, much less another 500 open source projects. Not many people could do what you did and go through the OWASP site and sift out the gems.

34:46Chris RomeoYeah. So, I mean, there's got to be a solution for this. I don't know that we'll have the solution I know they are working on it.

34:57Jeff WilliamsI know one of the things Matt Tesaro wants to do is to separate the wiki from the website so that we can use the wiki as a place to do work, a place to manage projects and so on, but it's not like the public-facing thing. There'd be like a real website with product pages for each of the— at least for each of the flagship projects at OWASP.

35:16Chris RomeoYeah, I mean, that would be a giant step forward. from kind of where we are now and, and selling those, those projects and their value statements to, you know, individuals that are looking for ways to bolster their program. So, yeah, I mean, this is— I mean, it's, it's, you know, and my hat, my hat's off to everybody that participates in the OWASP universe here. And I want to make sure that people— and I'm pretty sure you feel the same way. I mean, I want to make sure people know we're not, we're not, you know, we're not trying to pick on anybody or anything here. You know, we love this organization. We know there's a lot of passionate people that do as well.

35:48Yeah.

35:49Chris RomeoAnd that there's a lot of volunteerism that's going into the things that are here. And so nothing that, nothing that we see, say is really meant to as a slight to people. It's really about, you know, we're just talking about how do we get, how can we make this thing better in the future?

36:02Jeff WilliamsOh yeah, absolutely.

36:05Chris RomeoSo real quick before we wrap up this conversation for today, so tell us, let me tell our listeners a little bit about kind of this whole Contrast thing, because I've been a supporter of Contrast and tried to bring it into different environments, as you know, where I've worked in the past and things. So yeah, just give us a quick overview as far as kind of what Contrast is and kind of how it plays in the AppSec world.

36:32Jeff WilliamsYeah, sure. So, you know, in a nutshell, I spent 15 years doing manual penetration testing, manual code review, and had tons of experience with all the different tools on the market. Frankly, we didn't really think that they provided very much value. In fact, for most of our engagements, we decided not to use those tools and to do the work manually because what we found was we could find more interesting vulnerabilities faster by not running the tools. Tools just generated too many false alarms, took too long to set up and tailor for applications, and the results that come out just, you know, they didn't They didn't justify the work that we were putting in. We had an idea for a new way of identifying vulnerabilities within applications. We thought if we could get inside the app and see what was going on inside and observe it, we could much more accurately identify vulnerabilities. Then later, we decided that we could also use that same technique to identify attacks and prevent vulnerabilities from being exploited. So we pushed down that road. We launched the company after several years of research. We launched the company 4 years ago, and we have brought this technique to market. So to use Contrast, you take our agent just like you would take an AppDynamics agent or a New Relic agent or something for performance. You take our agent and add it to your application environment. Then it just goes to work in the background. So you add this agent once, it takes, you know, a minute, and then as you use your application during development, as you test your application in QA or CI/CD, Contrast is in the background looking for vulnerabilities. You don't need to have any expertise in security, you just use your application normally and Contrast will show you where the vulnerabilities are. And then in production, Contrast provides RASP or Runtime Application Self-Protection. That means that it can prevent vulnerabilities from being exploited at runtime. This is incredibly powerful capability for organizations. I'll give you an example. Last year, there were probably 7 or 8 different Struts and Spring expression language injection vulnerabilities.

38:52Chris RomeoYeah.

38:53Jeff WilliamsOur customers were protected through all of that because Contrast makes expression language injection impossible. We've sandboxed the expression language evaluation engines inside Java environments so that nothing dangerous can happen while in the course of evaluating an expression. You can't open files, you can't launch native processes, you can't make socket connections. All those things are prevented. All you can really do is just evaluate expressions, which is what it was supposed to be in the first place. Those combination of things together, we provide vulnerability detection, that's Gartner's acronym is IAST or Interactive Application Security Testing, plus RASP, and plus we also add the dependency check stuff where we analyze open-source libraries for vulnerabilities as well. All that we can deliver in a simple agent that drops in and becomes just part of your infrastructure, It fits really well with DevOps and we're seeing incredible uptake by the market. Folks that are getting rid of their static tools, changing the way they do pen testing to not test for the simple stuff that Contrast can handle for them. They're covering a broader array of applications and they're doing it all in real time. I think one of the coolest things about it is you're just programming along and all of a sudden you'll get an alert that says, hey, you just introduced a SQL injection vulnerability. Let me show you what you need to do to fix it. It gives you all the details, so it shows you exactly how data could flow through your application without being escaped or parameterized in a way that would have stopped SQL injection. It shows you exactly the line of code where to fix it. It is just a different way of working. It really goes back to what we were talking about before, that DevSecOps mindset where you are taking little pieces of work and executing them and delivering them 100% into production. That's what we want to get to with security is where we can enable development teams to push code through into production with no experts involved.

41:13Yeah.

41:13Jeff WilliamsYou can automate a SaaS tool so that it'll run the SaaS scan, but you still have to spend a ton of human time going through that report and weeding out the false positives and choosing which ones are real and all that. What we want is high confidence that things are secure as we're pushing stuff into production in real time.

41:33Chris RomeoYeah, that's definitely a great goal. I know that I've talked to various people that are using your solution, and I know just from looking at it that it's definitely a solid approach to AppSec. And so, I want to invite you to come back in the future. I'd love for our listeners to hear what we'll call kind of the Application Security Podcast Startup Edition. There's other famous podcasts about startups, but I'd love to have you kind of come back and tell the story about Contrast and kind of give people a little bit of that perspective. I know there's a lot of potential entrepreneurs out there floating around, and I think they'd love to hear that story. And we can kind of hear how the how the product kind of fit into that as well, because I think that's, that's some important lessons I'm sure you can share about things you've, uh, you've experienced and, uh, can help people to avoid some of those same challenges perhaps in the future.

42:30Jeff WilliamsOh, that'd be a lot of fun. I've, you know, I, I was a consultant for my whole life, so starting a product company 4 years ago, there was a lot of learning that I've gone through, made a lot of mistakes and learned a ton. So that'd be fun to talk about.

42:45Chris RomeoSo we'll leave that as a teaser for the, for the next time for folks. So, Jeff, thanks for taking the time today and kind of walking down the OWASP memory lane with us here. I know it, it definitely helps, helps me to get some perspective on where OWASP is coming from, knowing those roots. And I look forward to having that next conversation for AppSec Podcast Startup Edition.

43:06Jeff WilliamsThanks, Chris.

43:07Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.org.

More on OWASP Projects