--- title: "Mark Curphey -- The future of OWASP" url: https://appsecpodcast.com/mark-curphey-the-future-of-owasp/ date: 2022-12-13 duration_seconds: 2469 guests: ["Mark Curphey"] topics: ["OWASP Top 10", "OWASP Projects", "Security Testing", "Software Supply Chain"] audio: https://www.buzzsprout.com/1730684/episodes/11843073-mark-curphey-the-future-of-owasp.mp3 video: https://www.youtube.com/watch?v=decS7XMGcwk transcript: true --- # Mark Curphey -- The future of OWASP *December 13, 2022 · 41 min* with [Mark Curphey](https://appsecpodcast.com/guests/mark-curphey/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Software Supply Chain](https://appsecpodcast.com/topics/supply-chain/) [Audio](https://www.buzzsprout.com/1730684/episodes/11843073-mark-curphey-the-future-of-owasp.mp3) · [Video](https://www.youtube.com/watch?v=decS7XMGcwk) ## Show notes Mark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight. After running, he was elected and joined the OWASP Board of Directors. Hello, fine listeners from all over planet Earth. This is Chris Romeo, and I just wanted to let you know that you're in for a treat with this week's episode. This week we're joined by Mark Kerfe, and you may or may not have known, but Mark was involved in the creation of OWASP from the very early days. Now, Mark has been working in the background helping things happen over the few decades of OWASP, but he has recently run for and been elected to the OWASP Board of Directors. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Mark Curphey: → [Jeff Williams on LinkedIn](https://www.linkedin.com/in/planetlevel/) → [OWASP](https://owasp.org/) Mentioned in this episode: → [OWASP](https://owasp.org/) → [OWASP Top Ten](https://owasp.org/www-project-top-ten/) → [WebGoat](https://owasp.org/www-project-webgoat/) → [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/) → [ZAP](https://www.zaproxy.org/) → [OpenSSF](https://openssf.org/) → [Alpha-Omega](https://openssf.org/community/alpha-omega/) → [Sigstore](https://www.sigstore.dev/) → [CycloneDX](https://cyclonedx.org/) → [OWASP ModSecurity Core Rule Set](https://coreruleset.org/) → [Royal Holloway Information Security](https://www.royalholloway.ac.uk/research-and-education/departments-and-schools/information-security/studying-here/msc-information-and-cyber-security/) → [Ward Cunningham](http://c2.com/~ward/) → [Linux Foundation](https://www.linuxfoundation.org/) → [Mark Curphey](https://www.curphey.com/) → [OWASP Top Ten](https://www.owasp.org/index.php/OWASP_Top_Ten) → [OpenSSL](https://www.openssl.org/) → [Jeff Williams on LinkedIn](https://www.linkedin.com/in/planetlevel/) → [Christian Folini](https://www.christian-folini.ch/) Chapters: 00:00 Meet Mark Curphey: The future of OWASP 03:58 You're getting to university, you're in this kind of information security-focused 12:26 Would you say then was the first project 15:33 It definitely is fun to watch kind of where it's gotten 22:02 I think about, you know, kind of taking a different strategy 25:35 Yeah. No, that definitely makes sense. So, you know, when I 31:24 Cool. Let's transition and talk a little bit about the larger 35:06 There's a lot more moving pieces to it. So, When we 38:59 Yeah, that is a great goal for all of us to ## Transcript *8,101 words · assemblyai* **0:00 Chris Romeo:** Hello, fine listeners from all over planet Earth. This is Chris Romeo, and I just wanted to let you know that you're in for a treat with this week's episode. This week we're joined by Mark Kerfe, and you may or may not have known, but Mark was involved in the creation of OWASP from the very early days. Now, Mark has been working in the background helping things happen over the few decades of OWASP, but he has recently run for and been elected to the OWASP Board of Directors. And so this conversation, I wanted to hear the historical story. You know how much I like origin stories, but then I also wanted to understand Mark's vision for the future and how we can all be involved in that. And so I hope you enjoy this conversation with Mark Kerfe. **0:47 Robert Hurlbut:** The Application Security Podcast is brought to you by Security Journey. We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. Learn more at securityjourney.com. **1:00 Mark Curphey:** Hey, folks. **1:03 Chris Romeo:** Welcome to another episode of the Application Security Podcast. This is Chris Romeo, Chief Security Officer at Security Journey, and also co-host of the podcast. I am flying solo today because Robert is out once again traveling the great— somewhere in the great United States of America. But I'm super excited today to be joined by Mark Kerfe. And we're going to get into why you should know who Mark is, and we're going to get into all those details. I've really been looking forward to this conversation. But Mark, before we even jump in, we always start with security origin story. Our listeners are literally on the edge of whatever they're sitting in. They're sitting at the edge of it waiting to hear your security origin story. So, if you would share that with us. **1:48 Mark Curphey:** Yeah, for sure. So, I had a complete misspent youth, got thrown out of school, all sorts of things when I was young. Like, you grew up in the UK, basically just like drinking from the age of 15 and like whatever. So, I thought I was going to be a musician, all that sort of crazy crap. Wound up going back to university when I was 24 and did a mechanical engineering degree. And, whilst I was doing that in the 3rd year, I was doing computational fluid dynamics. So, basically modeling fluid flow over various things. It was my final dissertation project. And, in order to do that, you had to have this dongle. Okay, you probably remember dongles. It's a piece of hardware and you put it in the back of something. And honestly, this thing was like 3 grand. It was this company called Phoenix. It's a terrible piece of software and no student had it. Like, everyone was trying to pass it around, trying to finish their projects. So one weekend I thought, oh, I'll go figure out how it works. And so I figured out how it works. I replicated them and gave them out to all the students. And it was like, yeah, great. Like, if you want to protect software like that, you shouldn't— basically, you shouldn't have a return code that you can just go bypass all your checks. So it was like, oh, that's super cool. And then based on that, I then got the bug and wound up going to a place called Royal Holloway, which is in the UK. It's a prestigious uni, part of University of London, and they have run one of the first-ever information security courses in the world. It was essentially kind of partly through GCHQ, which is the UK equivalent of the NSA, and it was predominantly crypto. So, it was predominantly math-based crypto. It was in the math department. But that's— **3:16 Robert Hurlbut:** yeah. **3:16 Mark Curphey:** And then since then, everything kind of took off, and that was the bug that I've— have had for, I don't know what, 25, 30 years or so, right? So, yeah. **3:24 Chris Romeo:** So, I definitely remember dongles. Having one of my first or my first kind of IT-related job was in the university system supporting Autodesk labs. And you had to have these dongles. And so, yeah, I remember those days. I'm from that same era that you're coming from here as well. **3:42 Mark Curphey:** I shouldn't confess. I broke the AutoCAD ones as well. **3:45 Chris Romeo:** Yeah, yeah, yeah. **3:48 Mark Curphey:** Pirating software, perhaps. **3:50 Chris Romeo:** enough away from when the original events happened. **3:56 Mark Curphey:** Yeah, exactly. **3:58 Chris Romeo:** So, you're getting to university, you're in this kind of information security-focused kind of thing. How do you get to AppSec though? Where's the transition into the world of AppSec? Because I know you're from a time when there wasn't really an AppSec, like it wasn't a thing like it is now. **4:15 Mark Curphey:** Yeah, yeah, yeah. So, when you leave the Royal Holloway, you basically have 2 choices. You basically go work for GCHQ or you go get a real job, like, as my mother used to say, like, you know, she'd go work for the government, like, you're not going to get paid much. But so, I went to work in the City of London. I went to work in— I was actually a consulting company, but it was all the investment banks. So, spent a number of years there doing essentially all sorts of security for investment banks, like Dresdner Kleinwall Benson and things, and learned a huge amount, like, an amazing time, because that was in the late '90s where the excess of the city was there. And, you know, I got a million stories about trying to get traders to change passwords and stupid things like that, which is just In fact, the substory there is one trader picked up his laptop, picked up his desktop, threw it in the bin, and walked back and started carrying on trading. So, I mean, you have to be pretty tough in those kind of days. But anyway, I learned a lot of lessons. And then as part of that, I deployed ISS, Intrusion Detection System, in a bank, ING Beherings, so a Dutch bank that was bought by the bought Beherings Bank, which is the bank that almost went bankrupt because of essentially trading fraud. And the ISS guys came to me and said, we haven't our own people can't figure out how to go do this at the scale that you've done it. Why don't you come work in America with us? And so, I wound up working, essentially running a consulting team out of Atlanta. And I was very lucky to have a bunch of really talented people, one of which was Caleb Sima, who went on to create SpyDynamics, and Brian Christian, and they were on the team. And those guys were basically just early SQL injection, things like this. And it was just like, oh, wow, Here we are at ISS producing products that basically watch the wire or find vulnerabilities in operating systems. But when the smart consultants get in, it's all at the app layer. And we, our products couldn't protect anything against that. And so for me, the light bulb just went off. Like, that's the future. It's not this. It's like the big rush to the web has gone on. All of this stuff is going to bypass all this or make it not irrelevant, but less important. That's where you go focus. So I wound up taking a job in Charles Schwab in California running their AppSec program. And that was where the whole OWASP kind of thing kicked in. So, that was early 2000s, end of 2000, beginning of 2001. **6:31 Chris Romeo:** Yeah. You're making me nostalgic now. You said ISS. I was like, I haven't thought about an ISS intrusion detection system in a long time. **6:40 Mark Curphey:** And a company that— I was talking to someone that I was talking to, actually, I was with Ed Amoroso this morning. He was the former CISO of AT&T. And we were chatting about it and about how he originally bought RealSecure as well. I don't know if you remember that. **6:51 Chris Romeo:** So, yeah. Oh, RealSecure. Now, you're hitting me with all of these things from the late '90s. And because I was working at a web hosting company in those days where we were doing managed security in the early times, I'm afraid— I don't know if I could acknowledge this, but the way we did alerts is we would actually take the alert off from a managed security device and then email it to the analyst that was on. **7:15 Mark Curphey:** Yeah. **7:16 Chris Romeo:** Imagine in a world like the year 2022, A SOC in this modern day gets millions, tens of millions, hundreds of millions of events a day. And we were living in a world where an event would fire, it would kick off an email to a pager. In case it was the middle of the night, it would buzz on the pager. You'd have to be like, oh, I got to go look at this alert. **7:36 Mark Curphey:** Oh, well, look, the real secure underneath the hood was an Access database for a long time, right? Can you imagine that? Like, that was kind of what it was underneath the hood is ODBC connections and used to really struggle to get it connecting up to something bigger. So, like, yeah. We're living in a different world, right? **7:50 Chris Romeo:** Yeah. It's fun to think about the nostalgic nature of where security has come from and where we've landed right now with the modern approaches that we're taking. But so, you mentioned OWASP here. And so, on the AppSec Podcast, we've talked to Jeff Williams. We've heard kind of the origin story of OWASP from his perspective. But I think there's a lot of people that don't know the origin story as far as what you did with OWASP from the very beginning. And so, I know personally, and on behalf of my listeners, I want to hear that story. And so, please tell us about that. **8:27 Mark Curphey:** Yeah, for sure. So, I was moderating an application security list called Web AppSec. So, again, back in the old days, there used to be a mailing list called BugTrack, all run by Security Focus, and then there was one called Web AppSec. So, I was the moderator of that. We had about 4,000 people on the mailing list. And So, I think I started moderating that actually late '99 or something around that kind of era, maybe early 2000s. And then when I was running software security for Charles Schwab, the CIO came around the corner and said, hey, we're on the front page of the Wall Street Journal for a security problem. And we basically had a cross-site scripting problem. And essentially, 3 people complained about it. One was a vendor trying to sell me a product. The second one was his brother. And the third one was the journalist. The problem that happened, of course, because it got on the front page of the newspaper, the Journalist of Work Defender, but the CIO said, like, okay, I trust you, like, we pay for you, but, like, go point me to something that I can go back to the journalist and say, well, actually, like, this is best practice. Is this really a problem? And nothing existed. There were a bunch of people that I knew and trusted off of the Web App Sec List who were involved in OWASP in the very early days, not really involved anymore, but, you know, some of them worked at banks and other places. I just shot off an email. It's like, has anyone got anything? Like, you know, I need to go do this. They're like, no, I got the same freaking problem as well. Like, you know, and I swear it was probably the same vendor going and basically blackmailing pretty much everyone, but I don't know, whatever. Because we all seem to have the same problem at the same time. And so, it was like, okay, well, what's this? Like, I've written a piece of information internally, which was how to go secure things. And luckily, I had a very progressive boss. His name was Doug Merrill. He went on to be the first CIO at Google. And just said to Doug, hey, Doug, can I go take that piece of information information? And he said, yeah, go do what you want with it. Spent the weekend basically rewriting it, and then on the Monday or Tuesday or whatever, sent out an email. And it's like, hey, on the web appsec mailing list, look, we're going to create a project called OWASP. Here's the first kind of seed thing. Here's a website. We had a $20 hosting thing. I mean, you used to have to upload content through FTP at the time, and it was just an absolute, like I said, $20 of hosting and an HTML file. And that's what happened. It obviously caught the right time, right place at the right time, and got momentum. And then, over the space of a pretty short period of time, you had other people going, look, hey, I've got this problem. It's like, great, we'll go create a project around it, or go increase this. So, I mean, people like Andrew Vanderstock, who's the exec director now, I think rewrote my terrible OWASP guide, like, I don't know, a year or so later. You had people like Dan Cuthbert earlier on who were creating content. And some of those people are all— still around, but there's a lot of interesting things in the early days which didn't continue but have had a resurgence. So we had a project called WAS XML, I think it was. So it was basically a format to exchange vulnerability information. So of course now you've got VEX, but that was done early 2000s. We had Gabe Lawrence donated one of the very first web app firewalls called Stinger, which was way before there was a commercial business for it. He was just way too early. So, yeah, some very interesting kind of things in the early days. And then Jeff came along, I guess, a couple of years afterwards. Him and Dave Wickers had been actively contributing on the mailing list and various things. But, you know, and I think, you know, they came along with WebGoat, which Bruce Mayhew had written as part of Inside of AppSec. And I think, you know, that was a great project, really captured people's imaginations, was simple to go use and really simple to train. So, that was pretty awesome. And then, of course, the Top 10 was really the thing where which made it digestible for everyone. And so, that became a thing. And I had stepped down as chair, I think, in probably late 2002 or early 2003 when Jeff took over. And I think Jeff kind of shepherded it through to what, like 2010 or something like that? I forget the details. Yeah. **12:25 Chris Romeo:** So, what would you say then was the first project? Like, if you had to look in the timeline and say, what can claim to be the first OWASP project that was ever released? **12:36 Mark Curphey:** Oh, the first project was the guide, which I wrote the weekend before the announcement email. **12:41 Chris Romeo:** Okay. **12:42 Mark Curphey:** That was it, like T-minus 2 or 3 days, right? **12:46 Chris Romeo:** And that guide is the guide to the organization OWASP, or is this the— **12:51 Mark Curphey:** No, no, no. That was the OWASP guide to building secure web applications. Okay. **12:57 Chris Romeo:** And that had some sprinklings of what became the OWASP Top 10 included within it? **13:04 Mark Curphey:** It was really around things like don't do crypto in the DMZ. And it was kind of architectural guide stuff because it was essentially my standards that I had at Schwab for how to build secure software that was given out to all the developers. So, that was the kind of basis of it. I mean, it was a Word doc originally because it was taken from that internal thing. So, no, kind of the top 10 was created and honestly, kind of one of my challenges for the top 10 is, like, what is it a top 10 of? Like, is it the top 10 most prevalent things, top 10 most important things? No one necessarily knows. But, no, the top 10 was created, yeah, after that. I mean, that talked about, like, do input validation, like, don't trust the client, don't trust the users, but it didn't talk about things like cross-site scripting or anything specific. **13:53 Robert Hurlbut:** Yeah. **13:53 Mark Curphey:** It was more higher-level like classes of problems and guidance of how to think about building a system. So, I think if I can remember back, like, you know, logging, like, these are the types of things, like, it may be user events, it may be user management events, it may be these types of things, but, like, you need to think about, you know, logging and auditing, right? **14:12 Chris Romeo:** Okay. That's helpful to understand just to get that historical perspective there. How big is OWASP in those early days? It's like, can you count I'm not asking you to count exactly, but I mean, is it tens? Is it hundreds? Did you get towards 1,000 in your time here? What was the scale of this in the early days? **14:32 Mark Curphey:** Oh, gosh. Yeah. So, the first-ever conference that we did was at Stevens Institute in New Jersey. I mean, I'm in Lower Manhattan now. I think you can see it out of the window over there. And, a guy called Stan Buzek, again, unfortunately not involved anymore but ran it and Bill Howe organized it. No clue, like, we were going to turn— I don't think that, at that point, I don't think, you know, you didn't pay for anything. It was just like, you just rock up. And I think we had about 700 people rocked up to this thing. And it was like, you didn't know whether it was going to be 20 or 50. And like, I think that was the point where you realized, like, you know, okay. And I think a lot of it was because of where it was located, like, you had a lot of the Manhattan banks and things like that. But people were coming from all over the place. Yeah. And that's when I think you realized kind of there was momentum and traction and demand, of course. Like, I mean, that was the key, right? Like, people needed what was being produced and people were interested in what was being produced. So, yeah. Yeah. **15:33 Chris Romeo:** It definitely is fun to watch kind of where it's gotten to in the modern day. But let's kind of, on the timeline, you know, you were the chairman of the board in those early years as OWASP's forming. And then you turn, you know, Jeff and Dave and others kind of come in and take OWASP. And then there was probably, there's another generation even after them that kind of came in and the board became much more governing over everything that was happening at OWASP. So what brought you back into the fold here? You know, kind of, because you were, you know, say 2000, let's say 2003, 2004, 2002, like you, so it's been about 20 years though, right? Since you had an active role in it. Why come back to OWASP now? **16:20 Mark Curphey:** Yeah. So, great question. So, look, it's always been my baby, like, and I think always will be. And over the years, people always talk to me about it, right? Like, and I've always, you know, done it. And I'm also open about it. Like, anyone would take my call in AppSec because of what I did. And that's an amazing thing. Like, I don't, you know, that's why one of the things I'm, you know, when I encourage people to participate, it's like, pay it forward and it'll always pay you back. And so, there's always been this conversation with people who are asking for advice or just telling me things, and everything from like, hey, here's successes, to here's moaning and bitching. So, you've been the shoulder to cry on. So, it's not that I've been away, but when I worked at Microsoft, I was lucky enough to share an office with Ward Cunningham. Ward was the guy who created the wiki, and he was one of the patterns and practices guys, and the most lovely, lovely guy that you could ever wish to meet. Ward and I used to talk a lot about OWASP. And one of the things that had really somewhat frustrated me was that the original thing was, how do you produce guidance for developers? And it started to become an echo chamber, right? There were lots of AppSec people, AppSec consultants coming in, and they were talking about HTTP. They weren't talking about code, right? Like, this was wrong. Like, I can remember actually being at Stevens Institute and I said, like, how many people understand HTTP? And like the whole people's hand goes up. Like, how many people can write code? And like, The majority of people are like, not. It's like, this isn't application security. This is kind of network security. So, what Ward basically said to me is like, look, you can fight this thing, but the reality is communities find their own goal. And what generally happens is like, it will find its feet. And if that feet is not what you want, you go create something else or you step aside. And that's what he had done with the patterns and practices. Like, they were the guys who created Agile, right? him and Kent Beck and everything. And so, that's kind of what I did. It wasn't that, you know, you could carry on kind of fighting and trying to steer it around developers, but there's a momentum and there's a direction, and that's the reality. So, that's kind of how it's been, I guess, for the last, you know, 20 years or so. I did the 10th anniversary keynote, absolutely fantastic. Did the 20th one recently. And, you know, like I said, there's, you know, you can be both proud and not proud of something, that's perfectly fine. I have kids. I don't know if anyone else has kids. I'm incredibly proud of them most of the time, terrible some of the time. My kids are great, by the way. But it got to the point relatively recently where there were a few inflection points. So, the people coming to me telling me stuff was broken and moaning was becoming more and more. And they were people that I really trusted. They weren't They were people that were either really interested in the early days or people that I got to know a lot, and they were getting very frustrated by things. Then there was— I'd speak to a journalist, and the journalist basically, she said to me, what happened to OWASP? I was like, and it really hurt. It was like, what do you mean, what happened? She said, well, it used to be really influential, and now it's not anymore. What happened? I was like, well, I knew things had been changing, but I didn't think that that was the case. Those were inflection points. Then I started getting involved with Open Source Security Foundation. So I've known Jim Zemlin as president of the Linux Foundation for a long time. And I had been— so I helped build some strategy stuff for the Linux Foundation for security. And I led this, the SBOM piece actually for what we did to take to the White House. It was essentially an open source security mobilization plan. And what I saw happen over there was like, you know, when OpenSSL, when the first OpenSSL problem came, Jim literally raised $6 million in a weekend and gave it to the OpenSSL people to go and audit it. And you start looking at the impact that they're having, Sigstore and these other things, and you say, gosh, why doesn't OWASP? Why hasn't OWASP been able to have that impact? And one of the other things, like there's a project in OpenSSL called Alpha Omega, which is basically we're going to pay people to go audit open source code, find the problems and fix them. Like, God, we were talking about doing that in 2008. We can never make it happen. So, it struck me as like, okay, someone needs to go help this. And because I've kind of been around for a while and have a lot of relationships, it's like, I can go to people at Google, I can go to people at GitHub, and I can say, look, we need help, we need to go do this. And so, and I think that the project now needs some leadership. It's got to the point of being, essentially committee-driven. And, you know, and it needs to kind of someone to say, okay, like, these are the things that we need to focus on. Like, we need to have training. Like, the fact that OWASP has no Java security guidance, given Java is still one of the predominant languages used in important applications, is crazy. Like, we need to go fix these things. So, you can't rely on volunteers who work incredibly hard, but they do what they want to do. And that makes perfect sense. But you have to have some top-down leadership, and you have to have some ways to get top-down funding. to go make big things happen. And so that's, that's the kind of platform I kind of ran on. And that's what I'm, it's what I'm going to do. It's not like what I'm going to try and do. It's, it's what's going to happen. **21:31 Robert Hurlbut:** Are you struggling to measure the effectiveness of your secure code training? You're not alone. That's why we're proud to share that on average, Security Journey learners increase their knowledge an average of 33% and as much as Our diverse training content satisfies a variety of adult learning styles, from conversational training videos to hands-on secure coding activities, ensuring that learners are engaged no matter their learning style. Visit securityjourney.com to try our training today. **22:01 Chris Romeo:** So, when I think about, you know, kind of taking a different strategy of doing— trying to raise money and get some dedicated resources assigned to this, associated with this, like, what does that look like for the average contributor who is on that volunteer side? Like, is this— do you envision that there's a partnership between some dedicated resources that are working on a given project and the volunteers that are there? How does that all come together from your perspective? **22:35 Mark Curphey:** Well, look, I think there's a comp— like, first of all, everyone should be able to participate, right? And everyone should be able to make their contributions. But, you know, at the same time, we have to recognize there's important things to get done. And the ideal ask of everyone is like, go support the important things to get done. So, like, if you're an individual and you're wanting to figure out how do you make the most impact, it's like, if training is one of the most important things, which I believe it is, go contribute to the training. Like, there's enough GOATs out there. Like, we don't need another HackMe something. There's enough of them out there. Like, But what we do need to do is let's go build some really good guidance and development and training for developers. So, great, help contribute to that. You're a bunch of experts. The finance model of places like OSSF is, it's not like if you go to the OWASP page and donate, it's like, do you want to donate $5, $500? You go to the OSSF and it's like, look, premium membership is $270,000. And you're an organization, like, you're Google, like, this is what it's going to be. And then there's also the ability to say, okay, I want to give money and I want to ring-fence it. So, as an example, look, everyone's paying for developer training. Great. Let's go make free developer training. I'm going to put $100,000 towards that and I want to make sure it happens. So, my hope is like, great, we can go pay people to go do that. do that work. People are talented. People want to work on stuff. So, Simon Bennett is an example. What an amazing developer, what an amazing security guy. All the effort he's put into ZAP, we should be paying him to work on that full-time, and we should be paying him a commercial developer salary. **24:22 Chris Romeo:** Yeah. **24:23 Mark Curphey:** This is not like, okay, we'll give you some subsistence money. You could go get a top job in a top security company making loads of money, like, we got to have the best people doing the best things. Let's find a way to go pay them. And that's going to be true. I think that's true of training. It's true of, you know, other things. So, I view it as like, there's going to be this mix of people that want to contribute their best efforts. And that's great. We should make sure that they can go do those. And then there's a set of people who basically are, you know, in a commercial open source world where we can pay them. It just so happens the output is is open source. And then we can go fund things like Alpha Omega. Let's go fund people to go fix things. Let's go fund people to, you know, to do important work. And with that, you know, some people will get to do that as their full-time job. Some people can contribute, can carry on to contribute, but then hopefully we can channel a lot of those volunteers and best efforts in a way that we can have the biggest impact for the project and the world. not just lots and lots of little things, which, you know, whilst valuable in themselves, aren't like the way that OpenSSL is working. It's like, let's go shift this, let's go shift that, right? Let's go move big rocks. **25:34 Chris Romeo:** Yeah. No, that definitely makes sense. So, you know, when I think about funding models and whatnot, it just makes me think about, you know, from the commercial entities that have really benefited a lot from OWASP, Right? Like, I think about Christian Fellini and the core rule set. Like, it was, it was very eye-opening for me a few years ago when I heard him talking about all the commercial companies that use that as part of their service offering. And I don't know if it's gotten better as far as funding at that point. I don't think they were getting— he was getting a lot of funding, even though a lot of people were making a lot of money, taking their core rule set and transmitting it into or using it in, you know, WAF-style projects. And, you know, I think of Zap as another— you mentioned Simon. I mean, Zap is another example where There's companies that are using ZAP as their foundational layer, and then they're building value-add services on top of it. And so, like, any thoughts about kind of the folks that are using OWASP now as a platform for something commercial? How do they fit into this new kind of funding model you have in your mind? **26:42 Mark Curphey:** Well, I think— so, it's a tricky one, but, like, ultimately, you've got to figure out a way to make open source commercially viable. If you don't do it, you can't have people working full-time and raising the bar for everyone. That's true of Kubernetes. It's true of all of these projects. You've got a multiple set of people. You may have Google, like, look, we've got to do hosting. We're going to open source this thing, and that allows us to go put people behind it. You've also got people that are going to build products around it. You may have the Ranger guys in the Kubernetes world and other things like that. There's a set of people who contribute back into those things in a meaningful way. And it's important that those people are the ones who get— it's like you pay it forward, you need to get paid back. But if you are constantly on the take and you're not contributing, then the community needs to call that out. That's not okay. And so, you've got to figure out a way to make sure that the people who put the effort in get rewarded, And the people that aren't putting the effort in, you know, are called out. And part of that is in the purchase consumption thing, right? So, Simon is a good example. It's like Simon's now working for a commercial company that's built on Zapier. Why not? Like, you, everything you do goes back in to make a free version for everything else. That's fantastic. **28:06 Robert Hurlbut:** Yeah. **28:07 Mark Curphey:** But, you know, there are loads of other companies, like you said, that are just embedding this thing in. And they're essentially raping the ecosystem. That's not okay. That's just not okay. But you can't stop it. But what you can do is make sure that the community fosters and embraces the people that put the effort in. And those are the people that get the biggest and best rewards. And the other people, frankly, they're going to have to live with themselves. And if they're that type of people, then fine, go live with yourself. But let's make sure that the people that put the effort in get the rewards, right? Yeah. **28:43 Chris Romeo:** Yeah. And it, you know, it just makes me think of, you know, I'm always, I'm always in awe of the Simon Bennetts, the Jeremy Longs, the Steve Springetts, these, these people that have created things that they could have gone and made a lot of money with. Like, if they would have taken these things and built companies around them themselves, they could have made a lot of money. And so, I think as an industry, those people that are relying upon those things need to give back at a much better clip than they have in the past. And I like, I like the thought about, you know, this just needs to be better known in the who are good contributors to the ecosystem and who are not. Because, you know, this is— they're building a business on top of the sweat equity, sweat work of Jeremys and Steves and Christians and Simons and everybody. I'm not— I don't mean to exclude anybody. I'm grateful for everybody in the OWASP universe that's doing things. But those are just the ones that come to the top of mind for me. **29:35 Mark Curphey:** Yeah. But in a similar way, kind of what I've talked about is getting an investment fund. And so, I've been lucky. I'm kind of on my third startup now. One got acquired by Veracode. Second one, we'll see what happens. Third one's kind of now. And again, we're funded by top-tier VCs. So, I've got a real good ecosystem around this. And I've learned an awful lot around it. There's an opportunity for me to help Steve and help other people because, again, I think that that is— CycloneDX is a commercial-quality SCA, right? No doubt about that. And so, the open-source core model is a really good model that people will put investment behind. And that would enable Steve potentially, and I haven't talked to Steve specifically, but Steve would be a good example of someone I'd encourage to go do it. It's like, look, you got an amazing project. It's open source. It's got a massive following. The open-source core model would allow the core to become better. So, it's a benefit, it's a win for OWASP. It's a win for you. Let's help figure out how to make that happen. What that does is raise the bar and makes the project even better for OWASP, but it allows the person to get— who's put all of that work and all that effort into it to get paid back, and everyone's a winner. That open core model can be successful for everyone, but it has to be done in a way. It's not just, it has to be done in a way that is deliberate. Like, it doesn't happen on an ad hoc basis. Otherwise, what happens is you wind up with, like you said, loads of people, you know, essentially trying to rape the ecosystem, not giving back, and a few people basically, you know, doing all the work for those people. And that's not okay, right? Yeah. Yeah. **31:24 Chris Romeo:** Okay, cool. Let's transition and talk a little bit about the larger impact that OWASP can have for developers worldwide. So, you know, I think of that as almost a different category from funding and everything we've talked about so far. Like, how are we going to get this message to the average developer out there? Like, we talked earlier about, you know, OWASP and AppSec, and there's a lot of echo chamber happening, right? **31:52 Mark Curphey:** Mm-hmm. **31:52 Chris Romeo:** Like, a lot of times I go to the conferences and I'm talking to the same people. It's the people I love, so don't get me wrong, I love talking to those people, But how do we get this far and wide so that, you know, GitHub tracks the number of developers they think worldwide, it's like 27 million right now is their guess. How do we get this? How do we get OWASP to that group? **32:10 Mark Curphey:** Well, I think there's— so I think it is partly a funding thing. So if you go and look today at what the Education Committee have done, like, there isn't high-quality free online education at OWASP. It may be in little bits, but, like, you can't expect a developer to come there and go searching for stuff. Like, it's just not gonna happen. And I know Juice Shop is great, but why would a developer who comes there goes, oh, Juice Shop, it's education, obviously, right? There's 700 projects. So, we've gotta think about the experience and, like, who you're trying to serve. So, if you're trying to serve a developer, like, what are they— they have a limited set of time, they wanna go learn specific things, or they're told they have to go learn specific things. Let's go build the correct content for those guys. And then there are partnerships with people like GitHub. So, actually, next week, I've got a conversation with Abby, who runs the developer relations program. That's in their best interest, right? They want developers to go have security education. And so, you know, my ask, I don't know what's going to happen, my ask to her is like, let's go partner, OWASP and GitHub, like, let's go build free developer education for everyone. How do we make it happen? And so, I think there are ways of doing it. But, like, again, a lot of these things that are successful are top-down driven, right? They're not bottoms-up driven. So, that's why OSSF has been successful. It's like, great, let's go tackle this problem, code signing, or let's go tackle this problem, Alpha Omega. Let's go tackle other things. Great. We'll go raise the right money. We'll go get the right people in the room. We'll go make it happen. And it raises the bar for everyone. So, in terms of developer training, I think that's key. I think there's also some mindshift changes in some ways that have to happen. I've heard people talk about, let's educate developers at universities and go through that university system. That's fine, but you have to have people who teach comp sci degrees to tell you how to go do it. You have to have people who have created, who have gone through comp sci to tell you how to do it. So, again, there's this, you know, you have to listen to, like, how do CISOs want their developers to consume training? How do CTOs want their developers to consume training? What is that training content? Like, it's like building software. You can't go and create something and then hope it's going to meet people's needs. So, again, like, there's a set of things that we've got to do to figure out, you know, what training do we need for developers? How do we want to go deliver it? How do they want to measure it? How do they want to consume it? And then go figure out how to fund it and how to build that. And then, of course, continue to keep it updated, right? And maintained and like any piece of software responded to. So, yeah. It's no trivial task, right? **34:57 Chris Romeo:** Yeah. No, it's not. It's big. **34:59 Mark Curphey:** It's not creating a few sets of PowerPoints, right? **35:03 Robert Hurlbut:** No. **35:03 Mark Curphey:** It's just not what it is, right? **35:04 Robert Hurlbut:** Yeah. **35:05 Chris Romeo:** There's a lot more moving pieces to it. So, When we think about the individual AppSec enthusiasts out there that they already know of OWASP, they're bought into it. What can they do to help make this vision a reality? Like, if we were to give them some homework out there, because a lot of the folks that listen to this podcast are AppSec people, they know and love OWASP. How can they help in the mission that you've laid out here? **35:36 Mark Curphey:** So, I mean, look, the first thing is we've got to set the OWASP mission again. Like, we've got to reset it. So, the framework I've always used is you have a mission. So, that mission, you know, needs to be what OWASP is called. It used to be the Open Web Application Security Project. It should be the Open Worldwide Application Security Project. It's no longer just about the web. The second one is then what's the objective? So, if the objective is to improve the world's— the security of the world's software, Then, so that's M, O, then S of the T is what are the strategies for us to go do it? So one of those strategies is likely to be education. The other, let's provide the best-in-breed tools, right? So once you've got that, then what are the tactics, the T? So if the tactics are great, we're gonna provide online training. One tactic maybe we'll produce, you know, uni education. I personally think that's a long-term bet, and I don't think it should be one to be invested in. It's an idealistic one, but whatever. **36:30 Robert Hurlbut:** Yeah. **36:32 Mark Curphey:** So once we have those things, it's like, great, these are the tactics. Let's line up all these amazing people behind the tactics. So, you know, like I once saw this brilliant demo and it was like, it was a set of flies in a jar and then it was a piece of paper. And when all the flies were on the top of the piece of paper, they all got together and they could all raise the piece of paper, but any individual fly couldn't raise the piece of paper. So when you get people lined up, working against the same thing, big things can happen. But when you've got people spread out, like, it's hard. So, what we need to do is, you know, OWASP's got, what, 800 projects? It's like, you know, that's okay, but a lot of them are personal projects. A lot have been abandoned. But if we can harness a set of people on really important things, we could build a SAST tool. We can build a DAST tool. We've got SCA. Like, we can have an end-to-end toolchain. Right? Amazing. Like, that will be so good. Maybe we host it. I don't know. Maybe there's a fee for hosting and we can provide some value add there. Free training. Like, great. Let's go figure out what type of training it is. But again, the most important thing is, is like, you know, we need to figure out how to get the training for the most important thing, not necessarily the thing that we want to build. So, you know, apologies to PHP developers, but like building PHP training is just, It's not important these days. People are not building stuff on PHP that matter, that are building apps that really need to be secured. Of course, there are some out there, but, like, the stuff's on Java, it's on JavaScript, it's on Node, it's increasingly on Rust, right, and Go. **38:07 Robert Hurlbut:** Yeah. **38:08 Mark Curphey:** So, we've got to have that core stuff to raise the bar for the most people, and that means getting behind doing those things that we've got to do. So, I guess the ask is, like, you know, look, mobilize, I will help drive at the OWASP board a strat— you know, make sure we've got a clear mission, which I think is, is, is, it just needs a small tweak. Make sure we've got clear objectives so we know what are the things we're going to go after. Make sure we've got a set of strategies that we know that we're going to invest in. And then the tactical things are the projects to make that happen. And go pick up one of those projects and go drive one of those projects with us because you'll have the biggest impact. on the industry and it trickles back up. Like, you'll have the biggest project, biggest impact on the mission. And, you know, you should be able to feel proud about like, look, I raised security of the internet, like freaking awesome. **38:58 Chris Romeo:** Yeah, that is a great goal for all of us to get behind is that's the macro-level thing that we can do with the influence we have is we can ultimately make the security of software better for everybody in our lives. Because we're the ones that care about it. We all have lots of people in our lives that rely upon these pieces of technology. They don't know how it works. They don't know how it's secured. They don't even know what the right questions are to ask. That's where we come in, right? Right, right. So, Mark, it's been excellent to speak with you. I feel like I had heard of you forever and ever and just had never had a chance to hear how OWASP came together under your leadership there. And I'm super excited that you're back I know you've never really— you never really went away. You were there in the background kind of helping to make things happen. But I'm so glad that you're back kind of in front and center again, ready to take OWASP to the next generation. And so, it's been great to hear the history, but also your vision for where we're going. I look forward to watching you execute this over the next couple of years. **39:58 Mark Curphey:** I look forward to you helping get it executed, Chris, because you're going to be a key part of it as well, right? I mean, look, just to kind of end, like, it's like OWASP has an opportunity to improve. It's not that it's fundamentally broken, but, like, it can do better. And I think that's the key message is, like, look, let's all figure out how to make it have the impact that it should have, like, fulfill its potential. And I think that's the time for us to go do that now. And, like, you know, with the current climate of security, like, there is no time that it's more important for that to happen. So, yeah, it's going to be good. **40:35 Chris Romeo:** Definitely. All right, thanks, Mark. **40:37 Mark Curphey:** All right, take care. **40:40 Robert Hurlbut:** None of the top 50 university programs teach secure coding in their curriculum. At Security Journey, we help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. With over 400 up-to-date lessons created by industry-leading security experts and a programmatic approach that creates security champions, our programs has increased AppSec knowledge as much as 85%. Visit securityjourney.com to try our training today. --- Source: https://appsecpodcast.com/mark-curphey-the-future-of-owasp/