Skip to content
AppSec PodcastThe Application Security Podcast — home
43 minSeason 11, episode 12

Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding

With Mark Curphey and Simon Bennetts

OWASP Top 10OWASP ProjectsSecurity TestingSoftware Supply Chain

ZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable? Project founder Simon Bennetts and OWASP co-founder Mark Curphey join Chris to examine the uncomfortable economics of widely used open-source security tools.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 11 chapters
  1. 00:00Sustaining ZAP and open-source securityAudioVideo ↗
  2. 00:35From OWASP to the Linux Foundation and independenceAudioVideo ↗
  3. 08:48Balancing CISO priorities with practitioner needsAudioVideo ↗
  4. 11:42Fifteen years of maintaining ZAPAudioVideo ↗
  5. 12:21The business challenges behind open-source projectsAudioVideo ↗

About this episode

ZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable? Project founder Simon Bennetts and OWASP co-founder Mark Curphey join Chris to examine the uncomfortable economics of widely used open-source security tools. Simon describes the nontechnical work behind maintaining ZAP, from community support to managing companies that build commercial offerings on top of it. Mark explores funding structures, foundations, and the incentives that leave critical infrastructure dependent on too few people. They connect those pressures to the XZ backdoor and ask whether licenses can require commercial users to contribute. The episode makes the sustainability problem concrete: open source may be free to consume, but healthy projects still require money, time, governance, and long-term institutional support.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Mark Curphey and Simon Bennetts:
Mark Curphey on LinkedIn
Simon Bennetts on LinkedIn
ZAP
The Software Security Project

Resources
ZAP
Linux Foundation
The Software Security Project
Crash Override
OpenSSL

Actionable

From this conversation

  1. Fund critical open-source security projects sustainably

    We need to make a commitment to them for a couple of years to make sure they've got enough breathing space.

    24:50
  2. Support the open source projects you profit from

    Let's keep the people making money out of it, figure out how to go support it because they should be held, let's hold them accountable for going and doing it.

    24:50
  3. Let maintainers control their roadmap

    They need to own this thing. They need to control their own, their own roadmap

    28:37
Transcript · 43 min conversation

0:00Chris RomeoMark Kerfe and Simon Bennetts are both past guests of the pod. They join me to discuss what's happened with ZAP, why they've moved away from the Linux Foundation, and where they plan to go. We explore the open source models and why funding is so challenging, even though companies build whole products riding the coattails of open source.

0:23The Application Security Podcast is brought to you by Security Journey. We help enterprises reduce vulnerabilities through application security education developers and everyone in the SDLC. Learn more at securityjourney.com.

0:35Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of DaVinci and also a general partner at Curve Ventures, and I am flying solo today for a conversation with Mark Kerfe and Simon Bennetts. We're going to talk about the journey that they've been on from OWASP to SSF to now an independent entity. Uh, and so with that, Mark, I'd love to just jump right in and let's start unpacking this story, maybe provide some context for people that, that may not have been paying as much attention, uh, when you were elected to the board for OWASP and then made the move out of OWASP, maybe just set the stage for people. as a foundation for the conversation.

1:27Yeah, sure. So, um, you know, to take a step back, um, I think it's fair to say there's some challenges around OWASP that, um, there's a certain model that they wanted to follow, which wasn't necessarily, well, isn't a model that can support a bunch of the flagship projects. Um, you know, the sort of things that they wanted to do is really this bottoms-up project model, very You know, essentially kind of no, um, program management, just a free-for-all from the bottoms up. But there's a lot of projects that really have kind of matured into these, you know, almost commercial kind of grade software. And, um, the, the leadership at OWASP, I think there's a lot of, um, disagreement around how they could update the, the model, right? To allow to put significant amounts of money into projects like ZAP as an example.

2:19Yeah.

2:21At the same time, you know, there were, and so I, you know, joined the board, kind of came pretty quick that it was not going to change. It's certainly not going to change anytime soon. And I, you know, I resigned from the board over a year ago and I think it's pretty much fair to say zero has changed despite this open letter. And Simon was one of the people that I was, you know, working with and very much kind of trying to figure out how to help at the time. So when that all went wrong, it was like, great, okay, let's go figure out, you know, how to create another community with the model that we think will, will work essentially. Um, and the, the initial obvious thing, or at least one of them to go and investigate, was to do it under the Linux Foundation. The Linux Foundation have a model, you know, Cloud Native Computing Foundation, the Open Source Software Foundation, the Linux Foundation itself. There's a whole bunch of these things that are under that, and they've got a great operating model. Where all the things in the background are taken care of, finance, payroll, legal, you know, they know their stuff, right? They've got in-house lawyers who understand intellectual property and, and how to do all of these sorts of things. And they have massive amounts of sponsorship coming through from the Microsofts, the Googles of the world. And we're talking hundreds of millions of dollars, right? Flowing through that thing. And so it made sense to say, okay, well, you know, there's a proven model over there. Let's go and investigate that. And the original agreement I had, you know, sort of handshake agreement with Jim Zahn then, who's the president of the Linux Foundation, who I've known for a long, long time, was let's just go do this thing as an independent, you know, foundation. You basically have full control over how this thing's going to work. You can create your own governance model and figure out how to create the type of community that we wanted. And so we partnered with, with Umkar, who is the executive director of the OSSF, who agreed to become the exec director of this new thing called the Software Security Project.

4:11And, you know, basically said, great, let's go get this done.

4:14And Onkar was fairly new as the EDE for OSSF. He had taken over from a guy called Brian Bellenkamp, who was the original Apache founder. And I think it's fair to say, you know, Onkar did it for all the right reasons, but he didn't understand really how to launch another foundation within, under, underneath the Linux Foundation umbrella. And so what transpired, unfortunately, was I guess what I'd describe as an awful lot of politics that happened. Um, there's a lot of people inside of OSSF who took Umbridge to another software security foundation, even though it's a completely different, you know, beast, right? One's focused on purely securing open source software. This was about how do you help people build secure software, support open source tools, a lot of other things. But the sort of process hadn't been, been understood and been followed. And so as a result, kind of in an absence of, of info, like the vacuum gets created and it just kind of created a lot of problems. Um, so we spent quite a lot of time trying to work through it. Um, frankly, I spent probably 6 months of trying to figure out, you know, how we can negotiate this and how we can make some compromises and how all these different things could kind of work together with everyone. And frankly, kind of one day I woke up and just realized like that we've made so many compromises to this that actually what we were trying to do is not what was originally there. You know, we were, we were so constrained around what we could do underneath the OSSF that there could never be any overlap. Um, and the reality is that there, there will be, right? There's, there's certain projects. Um, and so, you know, we agreed with, with Omkar that, you know, this isn't the right place to do it anymore for both, for both parties, totally amicably. Um, and really spent about a month or so unwinding because, you know, there were some things under their privacy policy and there's a couple of thousand people that had signed up to a mailing list under their privacy policy and all sorts of other things. So, so with that, you know, the most important thing for this whole thing is not to try and rush into it. It's about how do you set this thing up properly? Um, you know, and, and, you know, as an example of that, like one of the really important things here is how do we get a bunch of CISOs driving the priorities of this thing? It can't be scanning tools saying these are the top 10 issues. It's like, what are the genuine top 10 things that CISOs are doing so we can line up the industry to focus on advancing those problems? And again, kind of one of the challenges under that Linux Foundation model, it's you have to really become a member in order to participate. Well, a lot of the operational companies, you know, banks and things don't want to become members, right, in order to participate. But we have a great list of those companies, of those CISOs from really big companies there. So the point where we're at now is I think it has taken a long time and it's still taking a long time, but we now have a list of phenomenal CISOs. I think we'll probably have the panel of 10 of them. I won't have a governance play in this because the whole point is, is that the industry people should be governing this, this thing. They should be saying what's most important around how these things happen. Um, and I think we're pretty close now to having that list, um, of those top 10, which essentially will be the top 10, the 10 initial directors who will be the governance board. And then the first project of that will be creating a software security top 10. So that's the top 10 things that are the most important things for industry to go figure out how to solve. Um, we are not quite sure how That's going to be done, but it's likely to be kind of almost like the Oscars where there'll be a voting. Those 10 will kind of put together a set of nominations of maybe 20 or 30 things, and then it'll go out to other CISOs in the industry. And so there'll be a criteria around how that happens to make sure that, you know, industries are represented. You know, again, putting together the board for us, we've got to make sure we have gender diversity, industry diversity, racial diversity.

8:13Like we're trying to get all of that right from the start and it's not It's not easy.

8:17Um, but the same with a survey. So, you know, if 250 people come back, like it can't be, it needs to be healthcare, manufacturing, financial services, tech. It needs to be across the world so you can, and different size companies so you can slice and dice it.

8:31So it's not just like, oh yeah, those are the top 10 things for them.

8:34So that's, yeah, so that's where we are. I'm sorry, kind of long-winded, long-winded answer.

8:38I, I, I think fingers crossed we're coming to the end of that.

8:42Um, that process, but it's, for us, it's kind of more important that we get it right versus timing, if that makes sense.

8:47Chris RomeoYeah, definitely. Definitely makes sense. And, um, yeah, a lot of, a lot to unpack there in the story that you just told. Um, so before I, before I switch gears and talk to Simon about, uh, the technical challenges or non-technical challenges of open source, I'm just curious, you're talking about this new top 10 list, you're talking about it being CISO driven. How do you, how do you balance the practitioner side of what are the things that we need to fix versus the CISO side? Because I certainly value what the CISOs are dealing with and what they have to say. I don't know that I would say 100% they understand the issues that I would bucketize as AppSec, ProdSec, the things that are in the trenches.

9:33Yeah. So look, the CISOs ultimately are getting their AppSec leaders to go do the You know, do the work on behalf, right? Really, the CISOs are representing the company.

9:44But these are operational people, right?

9:45Who are, you know, protecting their products, protecting their services, protecting their issues. And I know talking to them all, they'll tell you what the consultants say is the biggest problems are actually not, right? In many cases. Now, of course, you know, they are and they're listening to them, right? They're paying them good money and they've got their ears open. But, you know, they, they just frankly aren't always the right, the right issues. The same with, you know, vendors, right? Of telling them, hey, you need this tool. Well, the reality is, you know, you don't need this tool, right? And so, you know, one of the big complaints about the OWASP Top 10 is ultimately it's, it's basically just a bunch of scanning vendors, scanning data, right? For the most part that comes back. And so you have circular causation of You know, you teach a tool to go do this. Well, guess what? The tool can then find more of that. And guess what? A year later, you got more of that thing, right? So, you know, is, but is that the most important thing they're dealing with? A lot of them will tell you, will tell you it's not, right? They're dealing with things like, you know, how do I do, you know, all this kind of modern social authentication? How do we truly manage identities across sites and things like that? So. You know, those are the type of things that I think hopefully we can rally the industry around as saying, look, these are people's top 10 problems that they're dealing with. And let's have, let's go figure out solutions for those things. So yeah, that's the hope. I mean, look, I think there's room for every model and everyone's going to have its positives and its negatives on that respect. But I think that, yeah. Yeah, personally, I think this is, this is going to help us focus on things that are driven by the problems that industry are trying to fix versus the things that services and vendor tools solve. So it's, you know, it's kind of like solution, you know, problem solution versus solution problem, right?

11:41Chris RomeoAll right, Simon, uh, want to, to get your take on a particular issue. Knowing that you're somebody who's run an open source project for, how many years have you run this project?

11:54Ooh, uh, I've released Zapier in 2010, actually started in 2009, but, uh, 2010 released when it really took off.

12:02Chris RomeoAlmost 15, almost 15 years at this point. So, so you're definitely a veteran of, uh, building open source and dealing with all the challenges.

12:11Yep. So I want to, I want to, but I want to, I want to not focus on the don't we?

12:173 of us have kind of gray beards.

12:20That's, it's telling, right?

12:21Chris RomeoWe've been hanging around this industry for a long time. Simon, from your perspective, uh, pushing all the technical challenges to the side, dealing with open source projects, what are the, what are kind of the business challenges that, that exist? And I think it's a, it's a weird way to describe it, but at the end of the day, an open source project that's successful like Zap is not a hobbyist project anymore because it's being depended on in various different things. You're running a small business almost as this project. And so what are the, what are the non-technical challenges that you have to deal with?

12:55Well, you're absolutely right. It's definitely not a hobbyist project anymore. ZAP is a very big project and, you know, partly our own fault because we're trying to solve big problems. We're trying to, you know, be the best DAST tool in the world. And we're competing with commercial companies that have hundreds of employees. And, you know, we've got the equivalent of 2 full-time people at the moment. And we're still giving a lot of the commercial companies a run for their money. But really, when you think about a tool like ZAP, an open source project, it is the same as a business. We don't have the same problem with sales. But there's, you know, you still have got to do marketing, you've still got to do support. You know, my background is very much from professional software development. So I know all about support and documentation and all these other things, which are absolutely critical. But one of the hardest things has always been getting enough people and enough time to work on ZAP. The problem is, as I said, you know, it's something you can't do in your spare time. We need a lot of people on this and to 2 is not enough. And, you know, we've got a lot of volunteers, but they're doing it in their own time. My initial hope was that we would, that companies would start embedding their employees and getting them working on ZAP for a significant amount of their working day. But that hasn't really happened. We've seen it occasionally. But so it really comes down to if we're going to have enough people working on ZAP to make it viable. We need to raise money somehow. And I'm going to hold my hand up and admit that I got it wrong. Um, I have not focused on the business side. I've not focused on the funding side. I had this weird idea that if you make an open source project that is really useful to loads of people, loads of companies, then something will turn up. You know, there will be companies that want to support it. And I think we've got a lot of goodwill. But the number of companies who are willing to put their hand in their pocket and actually make things happen is remarkably small. You know, uh, I mean, my work on ZAP was initially sponsored by Mozilla, which is brilliant. And that was, you know, something that was, uh, understood, but it was still only part of my job. I then got sponsored by a couple of startups, um, who are, you know, using, trying to use ZAP to make money. But they didn't, I think they didn't like competing with the free version of ZAP. And after that, you know, there's been nobody who has stepped forward. Well, one exception, and that's Crush Override and Mark's company, who basically stepped in and saved the day because ZAP was close to collapse at that point. You know, we cannot maintain ZAP as a, as a part-time thing. We need people working on it full time. We need more investment. And, you know, I've now had to kind of focus more on how we're actually going to get that investment with Mark's help. And, uh, it's not something I'm particularly good at and particularly enjoy doing, but it's one of these things you've got to do.

16:03Oh, you're doing great. You're off to a great start.

16:07Chris RomeoBut Zap has grown up, right, to a certain point now where you have to do it. There's no, there's no real other path forward other than downward, like even keeping your steady state is going to be a challenge with the, you know, what you've built right now.

16:25Definitely, you know, there's a huge amount just to keep where we are. And, you know, we've been saying for some time, or I've been saying for some time that ZAP is the world's most popular web scanner, including all the commercial scanners. No one's contradicted me, so it must be true. We know ZAP was started at least 6 million times last month. So, you know, we've got a lot of people out there, a lot of companies are relying on ZAP. And, you know, I have talked to VCs, I've talked to the venture capitalists and they said, yep, we'll throw money at you. But they also want these returns. They want, you know, they'll give us huge amounts and then they expect more and more back. And ZAP is really a community project and everyone who works on it wants it to be there for the community. We want it to be available to companies. who don't have the resources to pay, you know, what used to be excessive amounts for, you know, some of the commercial DAST scanners. And, you know, we want it to be there so that we actually help the industry by bringing those prices down. So even if you don't actually use ZAP, you benefit if you're using our competitors because they've got to compete. And, you know, I've heard people tell me off the record that they've, you know, using ZAP, they're using commercial scanners, and they're getting just as good results out of ZAP as they are for ones they're paying huge sums of money for. But they're not prepared to spend those, you know, smaller sums of money to support ZAP. If you get a pound for every, every time ZAP was started, you know, we'd be doing very well.

17:56Chris RomeoThat's a good— that's a model right there. Yep. Yeah. Right. One, uh, one pound, one British pound every time, uh, you start, uh, ZAP.

18:05Yep.

18:05Chris RomeoUh, would, would be a perfect funding model for you.

18:07So, absolutely.

18:08Chris RomeoOn the resource side, you know, we, our industry's been overrun by the XZ backdoor conversations and, and, and I'm curious, given you're the person I know that's got the most open source experience, what's, I mean, how did, how do you process that as far as what's ha— what's unfolded with that story about a developer volunteer who basically kind of worked their way into the process over a number of years? Like, is that like, how, how would funding solve that problem for, if, if that you were dealing with that with Zapier?

18:44Uh, well, I mean, you know, we, we've talked about all the different, you know, kind of things. Um, and one thing we, we are very aware of is that we have a responsibility to the industry. Um, so, you know, we're very careful about who we give permissions to. Um, we treat ZAP as something that is, yeah, is security critical. We actually have a bug bounty program. Uh, if you get a remote and RCE on ZAP, you'll get $1,000, and we've paid out a couple of times. Um, and, you know, we're aware that, say, you know, we can't manage to fund ZAP and, you know, we decide we can't do anymore. We're not going to sell it to the highest bidder because, you know, ZAP has an auto-update feature. Somebody could push malware to a huge number of really critical machines in the industry. So, you know, we're very aware that we have to be very careful what we do and who we let on board and what permissions we give them. Now, I think it's very difficult when you're talking about open source in general, because there's a wide range of projects from the very small to the very large. that a lot of businesses are dependent on. And, you know, I think it really shows the problem that companies are not investing in open source and not giving back. And you've got, you know, these individuals who are maintaining critical pieces of infrastructure and they're really stressed and they're overworked. So I can really understand how, you know, somebody in that position goes, okay, look, I don't want to do this anymore. Here's somebody who's saying they're going to do it. great, I'll just hand it over. Um, so that is something that I really don't blame developer for. I think that's a perfectly reasonable take. I think it's an industry problem that we're not investing and we're not supporting these people.

20:29Chris RomeoYeah. It's almost a case study in underfunding. This is what can happen. Okay, Simon, one more question for you before we move on, and that is, When you have an open source project like Zap and lots of companies are out there creating products based on it, like what, what is your, what's your feeling, I guess, towards them? Like, is this, are you happy that they're using Zap as their foundation? Are you a little annoyed? Like what's, I've always wondered how, how do you process that as somebody who is behind this Zap project?

21:08Yeah, well, I mean, again, this is probably my fault again, because I, I chose the Apache v2 license. Um, you know, I wanted ZAP to be a community project. I wanted people to use it. And I thought that if it was useful enough, people would support it. Um, so I'm always delighted to see companies using it, particularly when they're using it internally. But I was really hoping the companies that were building service, commercial services on top of ZAP would contribute back. You know, I thought they would contribute back, um, code fixes, new functionality, get involved. And that really hasn't happened or not to anything like the extent it needs to. And, uh, it's, that is frustrating. And that's something that, yeah, is, is a surprise because you'd have thought that, um, they would want to actually make the tool that they're they're using better, you'd have thought that they'd want to actually help improve it. And, uh, but, you know, are they then thinking, well, other people are using it. So, um, you know, that I'm helping my competitors, or in many cases, I suspect they see ZAP as a competitor. So certain companies seem to just want to take open source and use it and not give anything back, uh, which is kind of a, it's a bit of an abusive relationship really. You know, I think there's a response, a moral responsibility, if not a, I think a business responsibility as well. You know, I would have thought it would make sense to actually talk to the project teams of the open source projects you're using, but, you know, give them feedback and get support from, support them and get support from them as well. And I'm surprised how few of the companies building services on top of Zapier are actually doing that.

22:55Yeah.

22:55Chris RomeoOkay. Well, we'll, we'll come back around and talk a little bit more about kind of mid-sized companies and startups and their relationship with Zap. But first I want to get Mark, I want to get your take on where do we go in the future here with this funding model? Like what, what is this? What, what's the next generation of, of this approach look like? Because there's gotta be 9 more Simon around in the industry who are in a similar state and need help.

23:23Yeah.

23:23I mean, I think the answer is we don't know, but there's definitely more options to explore. You know, I would categorize Simon as, and Simon's team, Ricardo, et cetera, as they want to work on building software. Like they don't want to build a commercial business. And I think that's fundamentally different to a lot of other projects. They, you know, want to get to a certain size and that's happened, it's happening now with a lot of OWASP flagship projects. They want to go build businesses off it. They're doing it. That's absolutely fine. But Simon was not, you know, not in that situation. They just want to build the best products. They're engineers. And as Simon said, so the question is, how do you build a sustainable model for those people? And, you know, what we had done, you know, after that wasn't going to be possible through OWASP, we thought we had found that through, through the Linux Foundation when that funding was yanked. You know, I had a moral responsibility helping these guys and said, great, we'll just, we'll pay you until we figure it out. And it's probably a couple of months in and I had read an article and it was in the Sunday Times, which is a big newspaper over here. And it was about socially responsible marketing. And basically what they were saying is you can justify spending large amounts of money. It's not, you know, you don't go brand this thing. It's not that you're using this thing, but ultimately it'll come back to you. And, you know, that kind of thing is used by a lot of large companies that will say, great, we'll do environmental projects because it's socially responsible.

24:49people.

24:50And then of course, you know, you look at those companies and you say, wow, these are great companies because they're doing the right thing. And so I, you know, sat down with my partner and co-founder, John Viega, and we said, look, you know, we're a well-funded startup. We want to do the right thing. We've had a long history in open source. Like, why don't we, you know, apply that instead of going and sponsoring booths at RSA and DEF CON and, you know, all of the other marketing things that all of the traditional companies doing, let's go put our money there and let's hope that it comes back to us. And so, you know, the commitment that we've made to Simon and to Ricardo, I mean, it's a pretty big one. Like honestly, it's approaching, it's approaching 7 figures, right? This isn't like chucking 25 grand in at something. It's, you know, we need to make a commitment to them for a couple of years to make sure they've got enough breathing space. They've got enough air cover to go figure out how to make it You know, fund and make it sustainable in the long term. So let's go do that and let's figure out what the model is. And, you know, because they need, they need time. It's not, you can just say, great, you know, now we're going to do support or now we're going to do something else. It's, you know, they've been, they've been, you know, they've been off fumes for a long time and it's not fair to carry on and say, oh, here's a 3-month lifeline. Like, it's not, not really super helpful. So, you know, within that, what we're trying to help, you know, Simon and crew do is basically build a not-for-profit sustainable model and figure out what that is. Um, so there's a bunch of things to go, to go explore. You know, one, I'm sure Simon will talk about it now, is like maybe support will do it, right? Maybe you can offer enough support contracts that come back. Um, and, you know, and services, implementation services, you can get kind of close to the people that are using it and then benefit everyone coming back. And that's one potential model. I think we looked at 12, didn't we, Simon? We've got a spreadsheet of all 12 and we kind of said, here's an advantage, here's a disadvantage, here's an advantage, here's a disadvantage. We know that small sponsorships, they've been trying it for years, doesn't work. Like people putting 10 grand, 20 grand in basically for sponsorship with these startups, basically all they're buying is buying advertising space and then they get their advertising and then bugger off again. And that's not helping sustain stuff. So there's those, and then there's potential models like, you know, maybe it's going to have to be GPLs, in which case the people that are making serious money off of it are kind of going to be forced in order to give back. But ultimately, whatever the model is that comes up with, you know, the point is let's keep free users, the user base being able to use it for free. And let's keep the people making money out of it, figure out how to go support it because they should be held, let's hold them accountable for going and doing it. But exactly what the model does, I think it's fair to say, Simon, we don't know. We're in, what are we now? April, 3 months into a cycle and just trying to, you know, trying to figure it out. You know, I hope we do, but there's no guarantee that we do, but I hope we do. There's a lot of different options we can explore and yeah, we're going through and explore them. Exactly.

27:55Chris RomeoSo are you, would you say, or like, are you leaning towards Zap having it being its own foundation and being a separate entity, or is it, are you leaning towards it being part of some collaborative community? That's a big connection point.

28:10Yeah, no.

28:11So what we did is we set up a set of rules on this open source security foundation. So we basically said, you know, here, here are the rules from us, right? It has to be a nonprofit. Like, this isn't an incubation program. Like, we're not, we're not funding people to go build a commercial business out of this. Like, We're helping people to create, you know, non, uh, you know, sustainable nonprofit stuff. They own 100% of this thing. We're not controlling the roadmap.

28:35We're not spending anything into this thing.

28:37Like they need to own this thing. They need to control their own, their own roadmap, um, around it. We do have them work one day a week on other open source related projects. Um, the project Simon's working on right now, actually on, on the other day is actually trying to figure out how to improve Zap speed, right? And accuracy of configuration happens to be something we're interested in because we could potentially do it, but it's also open source. But that's kind of how that, you know, gets set up basically. And, you know, within that then, you know, obviously we've, we need to make sure that this responsible marketing stuff, you know, let's be honest, it's a massive investment. how can we make sure that we are best set up to at least get the goodwill back? So that does mean that one of the things we've said is that these small sponsorships where big logos there, that model of small sponsorship can't continue. So that has been stopped in the interim time. So yeah, I think that, I don't know if that answers the question.

29:44Chris RomeoYeah, no, it did.

29:47It did.

29:47Chris RomeoSo you guys had shared some examples with me when we were kind of getting ready to hit record in this conversation. And so we're certainly not going to talk about any names of anybody involved, but I think people need to understand from both of your perspectives how companies are using open source and how, how they're abusing open source, Simon, to use the terminology that you brought into the conversation here. And so I'd love for you to share some of those anonymous or anonymized stories, just so people have some perspective about how industry is abusing open source right now. And so hopefully we can see some change in the future if people become more aware of what the problem is.

30:32Yeah, I mean, it's clear that there's a lot of companies out there trying to make money out of ZAP scans online. You know, I mean, and you can understand why if you want, you know, DAST is something that is, you know, you can see how that's something that's desirable to companies. And we've really built a tool. It is not a solution. So companies come along and said, hey, let's provide some of this stuff. And, you know, I know one particular company who looked into creating their own DAST scanner. And they worked out it was really hard. So they had, they thought, okay, you know, let's find an open source one. And there aren't that many open source web scanners. I mean, there have been over the years. I keep a track on them. Very, very few get maintained. And, you know, they worked out that the only decent one around was ZAP. And so they started a company just around ZAP scans. They didn't get in touch with us. Um, you know, we found them, uh, and, you know, there's so many companies out there who are going, okay, we want to provide, you know, online scanning services. Just grab an open source one and we'll build on top of it and we'll rake the money in. Yeah, that's what they're doing. And they're generally, you know, some of them do get in touch. Some of them, you know, do say they want to work with us. Some of them have, um, you know, looking at getting support packages from us. So we do, so, you know, it tends to be the smaller startups, to be honest. We have a much better relationship with those. Um, the bigger companies, um, some very big companies out there who are using Zap, uh, have been, yeah, not helpful at all and not supportive at all. Uh, that's frustrating. You know, it's, if these companies were supportive, we could do so much better.

32:22Chris RomeoYeah.

32:23I mean, look, when, when we started, um, trying to explore different models, I started making loads of calls, right? And the calls were kind of on 2 parts. It was like one, almost dialing for dollars, right? Like, hey, I know you, I know you use that, give some money. And then the second one was genuinely kind of listening, like how, you know, how could, what would you pay for kind of thing? And it was pretty shocking. Like there was one, Simon was on the call, there was an API security vendor. who I know people inside who had told me that they're building it on top of Zapier. They had raised, I want to say, $80 million in their round. They were valued at $400 million. And the CEO sat there and absolutely livid. If you're going to GPL this, this is wrong. You can't be doing this. And you're thinking to yourself, like, okay, like even as an absolute minimum, like one engineer in Silicon Valley is going to cost you $200,000 or $250,000 a year.

33:18Chris RomeoYeah.

33:18And here you are complaining a fifth of that when you've just taken $80 million of funding. I mean, it was just mind-boggling that the audacity. And I mean, there's another one that we believe, um, someone internally has told me, but I'm not quite, quite as sure. You know, they're making $200 million of revenue a year and they've built a new product based on it as well. And their contribution, I think, was $20,000. It's like, really? And for that $20,000, they wanted their logo on the site. It's, you know, here's a project like this app, like Simon says, it's about 80,000 active users a month. It's run millions of times to secure critical infrastructure. And you've got people both using it to secure critical infrastructure and making money out of it. But these people aren't contributing in a fair way. Like, that's just not fair. That's just not fair. And, you know, we've seen XZ, we've seen OpenSSL, we've seen what happens when people don't maintain these things. You know, and those have been things, software that people rely on, but like, what's going to happen to a really important piece of software that people use to look at the assessment of stuff? It just, we've got to figure out how to turn the tables on that because it's just not right. It's just, it's just not right, period.

34:37Chris RomeoIs there a better open source license that you could do just a hard fork on Zap and move to a new model, which says that if you're going to commercialize the thing that we're building for free and making available for free, you're going to pay a tax on it? Like, I don't know. I don't know the answer to this, but is there a model that, is there a license that that does that today?

35:04Potentially. I mean, the, so, I mean, we, we've been very honest about this. So I've written blog posts about it on the ZAP blog. And, you know, initially we're going to start with things like support packages, consultancy, sponsored developments. We've said, if this doesn't work out, we're going to have to seriously look at relicensing ZAP. And, you know, so have one open source license and one commercial license. And as far as I can tell, the most obnoxious license as far as large corporates are concerned is AGPL v3. Um, so that's the one we'd probably go with. You know, it's still open source, but it is something that scares lawyers of big companies. And that's what it's going to take, I think. You know, um, so yeah, we would go with the, the most extreme open source. Um, license we, that is available if someone comes out with a one which is even more extreme than that, but still count as open source, we'd do that. You know, that's, that's—

36:05I mean, what, what's one of the important, yeah. I mean, one of the important things, Chris, is that Simon and crew own the copyright, which means they own the IP, so they get to license it. Of course, someone else can go fork, go fork it, but it's not them who has to fork it, right? They, they control kind of the, the destiny of it, and I think I think Simon and I, you know, Simon and I are kind of collaborators on what's the right model. And I think the thing that we talk about a lot is make sure that the users aren't the ones that get fucked. Like, excuse the bad language, but like, you know, it's like Atlassian, like one of their company mottos is don't fuck the customer. Don't fuck the users, right? It's the people that are hosting this, making money and not giving back that need to be held accountable. And If they're the ones that ultimately force it to the point where it's going to be put online for free and they can't do that, you know, it's, it's not the fault of ZAPD, right? Like, you know, it's, that's the fault of, that's the fault of them for not stepping up, that there was no other option. And, and so, yeah, I mean, I think, I think Simon's done an amazing job of working through that.

37:11We're offering you support first.

37:12We're offering you services. Like, great. Why don't you step up and pay for those things? And if we can get enough money to support us and grow the project a bit, fantastic. But if not, you know, we're going to have to take the nuclear option. And I think it is the last option, but, you know, maybe it's the one that, the only one that is actually going to, you know, going to everybody look at GPL. There's been an awful lot of software that is GPL'd that ultimately stops. And maybe that is the only model that will work. Yeah.

37:47Yeah.

37:47Chris RomeoI, I certainly hope the, the services and consultative model will do what you want and need it to do. I guess I'm a little bit of a pessimist when it comes to thinking that these companies are gonna all of a sudden wake up and, uh, and stop. All right. Well, I feel like we've covered a lot of ground in this conversation and, uh, I've really got a better understanding for the journey that Zap's been on for the last 18 months to maybe 2 years. And I'd love to end our conversation here with just a highlight, just a summary or a key takeaway, or maybe some guidance for our audience from both of you as far as what can they do to support Zap going forward. So Mark, let's go ahead and start with you.

38:32Sure. So, you know, from a Zap perspective, I think the most important thing that if you're using it, then, you know, and particularly using it to make money, then go do the responsible thing. It's, it's pretty much as simple as that. You know, if you would be using a commercial tool, you know, look at, look at it. Um, no one's asking you to pay the same as, as you would for a commercial tool, but pay something which is, which is fair. And if you are a vendor making a lot of money out of it, do the same. It's going to be on a different scale, but take a, take a look at it first. Is it the morally right, responsible thing? that you should be doing. But more importantly, business-wise, if you are, you know, you need to have something which is sustainable. If you didn't do that, you'd have to be building it yourself, and that's gonna cost, you know, a lot of money. I mean, this is, you know, the way to think about open source is it's a shared resource model where, you know, you pay less and everyone gets to benefit. And if you don't continue to do that and, you know, Zapier is forced to to GPL itself, then you're going to have to fund those developers anyway. So why not do it ahead of the curve? And it's a hard thing. It's like the environment. Of course, we all need to go do something towards it and we all know, and it is hard for people to act, but unless we all act collectively, then, you know, we're going to have a set of problems. So I think that's the most important thing to do. And then I think the second thing is we, if we can find models like we've done with this open source fellowship where we can use responsible marketing so that we can justify putting significant amounts of money into something, then if that model works, then we can help projects like Zap get off the ground. It's not clear that that's going to work. Like we've got to be able to see a return to justify it. We're a commercial venture-backed company, but we're not going you know, NASCAR's app and put, you know, adverts for what we are doing. The most important thing is to do the right thing and hope that the long game, it comes back to us as doing the right thing as the company. But if we can get that model working, though, you know, we can just go rinse and repeat. Both us, but also other security companies can rinse and repeat and build a sustainable, you know, not-for-profit open-source model, which is just gonna make it better for everyone. So yeah, the most immediate thing is if you're a ZAP user, or particularly if you're embedding it to make money, go, go do the right thing. Go, you know, support, support the ZAP crew. And then, you know, longer term, let's work collectively to figure out the model.

41:07Chris RomeoSimon, how about you?

41:10I'm going to keep it really nice and simple. Just go to zaproxy.org/support and Choose one of those options, get in touch. You know, the details are there. It's not exactly particularly a heavy selling job. I'm not very good at the marketing side. Uh, but yeah, we've got a lot of options, got support packages, consultancy, sponsored developments. Um, so, you know, if you want to support us, just get in touch. We're easy to find. I'm really easy to find. Get in touch and let's talk.

41:40Chris RomeoWell, thank you, uh, both of you for what you're doing here. I know, Simon, we've talked about ZAP a couple of times before on the podcast, and I've always tried to thank you from on behalf of our community, which I don't have the ability to do, but I do anyway. Uh, because you're, you are making a difference. You are, you are moving things forward. And Mark, thank you for what you're doing to drive things behind the scenes and try to, try to find a better way forward for Zap. I think what you guys are working on right now is crucial for the next 10, 20, 30 years of software. I just, people don't realize it yet, but, but the issue you're wrestling with is, is going to have an impact for long after we're all retired and sitting on a beach somewhere. Um, this is gonna have an impact, right? So thank you for what you're doing to move that forward and, uh, and keep, keep the fight, keep up the fight, keep moving forward. Yeah.

42:29Thanks for having us on.

42:30Yeah. Thank you very much, Chris.

8,024 words · transcript by assemblyai

More like this

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.