Martin Knobloch -- OWASP, Reach Out; We Are Known and Misunderstood
With Martin Knobloch
OWASP is widely recognized, but do people understand the community behind its famous Top 10? Martin Knobloch, serving as the foundation’s board chair when this conversation was recorded in 2018, explains what the organization does and how volunteers make it work.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 13 chapters
- 00:00Understanding the OWASP communityAudio
- 01:31Martin’s security origin storyAudio
- 04:06What the OWASP board chair doesAudio
- 07:53OWASP’s mission and purposeAudio
- 08:52The educational value of the Testing GuideAudio
- 11:04The scale and passion of the volunteer communityAudio
- 14:48Working through community disagreementsAudio
- 16:34Measuring impact beyond OWASPAudio
- 19:45How OWASP changed as it grewAudio
- 21:20Supporting growth with staff and leadershipAudio
- 23:25Projects Martin is working onAudio
- 24:24Why attend an OWASP conference?Audio
- 28:44A challenge to reach outAudio
About this episode
OWASP is widely recognized, but do people understand the community behind its famous Top 10? Martin Knobloch, serving as the foundation’s board chair when this conversation was recorded in 2018, explains what the organization does and how volunteers make it work. He traces his journey from industrial control programming into software security, then describes board responsibilities, chapter leadership, and the educational value of OWASP projects. Chris and Robert explore how an open community handles disagreement, measures its impact, and reaches people outside its existing circle. Martin reflects on the organization’s growth, the role of staff, and the value of conferences for meeting contributors. His closing challenge is straightforward: reach out, share useful resources, and help more people participate in application security.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Martin Knobloch:
→ Martin Knobloch on LinkedIn
Resources
→ OWASP Foundation
→ OWASP Web Security Testing Guide
→ OWASP ASVS
Actionable
From this conversation
- 8:00
Use OWASP guidance to build and validate secure applications
OWASP was founded from developers for developers, how to write secure software, how to build secure applications.
- 9:05
Use the OWASP Testing Guide for security validation
The testing guide is how to validate the security.
- 17:00
Show developers how OWASP tools fit their delivery practices
When you tell them what is there, how you can use it, how you can use it in your environment, be it DevOps, DevSecOps, continuous delivery, continuous integration
Transcript · 31 min conversation
0:01Chris RomeoSeason 3, episode 20 of the AppSec Podcast has Robert and I interviewing Martin Knobloch from OWASP. Martin is the global chairman of the board for OWASP, and we talk about many things that exist in the OWASP universe. We talk about the organization, we talk about some of the history, and really opened my eyes a lot to where OWASP has come from and where it's going to in the future. So we hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. On this episode, we are going to talk about something that we love to talk about all the time, and that is OWASP. But we are joined by a special guest, and so Martin, would you go ahead and just introduce yourself?
1:19Martin KnoblochHi Chris, hi Robert. Yeah, I'm Martin Knobloch. Since 1st of January this year, 2018, I am the chairman of the board of the Global Foundation of OWASP.
1:31Chris RomeoAwesome. Thank you for, for being here. And I definitely want to dive in some more into what that actually means. But here on the AppSec Podcast, we always start with our guests' security superhero origin story. If there was a comic book about your life, In security, Martin, what would happen in episode number 1?
1:51Martin KnoblochYeah, actually, I'm a trained mechanic for injection molding machines, which is completely nothing to do with IT. I went to IT via PLC programming, robotics, and industrial area. And I taught myself Java and C programming. And I was kind of surprised because when you're injection molding and robotics, you have a Quite physical feedback. Something goes wrong when I went to web development in 1998. Yeah, 1998. Yeah, sorry. I was surprised how little controls and validation was for input and output and transactions because it makes a difference if it's a robotic arm or payment transaction or whatever goes from A to B. There's a point of no return. Everything should be safe. So, um, I, when I was studying in software development, then, uh, I changed a lot of jobs and finally got to a company and they said, okay, you want to do something about security, go ahead. And it was, uh, that was in 2005. And so I got in contact with OWASP in 2006 with my first OWASP conference in Europe, in Belgium back then. And I just got hooked by OWASP and it became my work. Yes, security, not OWASP, is still voluntary.
3:13Yeah.
3:14Chris RomeoWow. So, how do you get from, I guess, what was kind of the big thing that pushed you from working in the PLC world into the world of web? Was there any particular thing that just pushed you over and said, hey, I want to jump over and start working on web?
3:34Martin KnoblochIt was the whole development, the programming part. PLC programming I did for a small— yeah, I was responsible for robotics, but I wasn't allowed to program the PLCs. We had the programmer for that. So I was just the grease monkey, the mechanic, and I had to, yeah, work with it, but I was not allowed to program, even if I did a course for programming it.
3:57Ah.
3:57Martin KnoblochSo it was just more in the, yeah, my free time, I brought myself, as I said, programming, and yeah, I was hooked.
4:06Chris RomeoOkay, okay, I see. So you kind of transferred into the world of IT and then ultimately into what I like to call the OWASP universe, which tends to hook a lot of us once we get in and start working on it. So let's transition and start talking about all things OWASP here. And so You said that since the beginning of this year, you've been the chairman of the board for the OWASP Foundation. And so I'd love to learn more about what does that actually mean? And what is the job description for the chairman of the OWASP board?
4:42Martin KnoblochYeah, the job description, we have a nice wiki for that. And that's a good thing. And always, we have everything on the wiki. The best thing, if you don't know what you are looking for, you can't find it. Yep. So responsibility actually is, uh, we now, uh, we are lucky we have an executive director, uh, Kevin, uh, since last year November. So that, uh, um, OWASP from the board, it's more the guidance of the community. I always, uh, tend to say OWASP is community-driven, supported by the staff, and, uh, guided by the board. So we are— As board, I see we do the rules so that the OWASP game played nicely and clearly. I see rules as for a sport like soccer or American football. The rules are not there to limit the game, but to enable the game. I think that's the most important thing we have as a board, to enable the community to do the cool stuff they do.
5:36Chris RomeoSo you, I guess you kind of have, so there's monthly board meetings and things where you're looking at different issues that are impacting OWASP and you're making decisions about kind of, I guess, how detailed do you get into the decisions? Are you hearing things about individual projects and you're getting to kind of weigh in on that, or are you at a level kind of higher and above the individual project?
6:04Martin KnoblochYeah, I think the most board members, we are kind of addicted to OWASP. Nobody wants to be a volunteer Board member, if you don't have a connection or feeling with the community, I think that would be really, really bad. Like I did some little, I don't know, write some projects in the past, education projects. I was in the committees when we had them. I'm also the chapter leader of the Dutch, the Netherlands chapter. Okay. I'm involved in a lot of projects because in my time since 2006 that I'm involved with OASIS. I meet so many people, I hear projects in the summits we have at conferences. So I try to connect the projects. I'm not active participating in specific projects currently, but just to get them together, like the Security RAD, Security Requirements Automation Tool, was a good tool in the beginning. And then we have the OWASP Security Knowledge Framework, what's more for developers, how to Yeah, securely implement the required functionality. Those are projects, they are their own systems, right? But they are so much linked. So I get the people together, uh, I advise them, uh, sometimes they ask me to read it, but that's next to the board. So that's not the board responsibility. Um, in the board, uh, yeah, the monthly, uh, board meetings, the public meetings, that's, that's one visible part of, uh, the OWASP board. tasks. Of course, there's much more going on. As a chairman, as a treasurer, we are financially responsible. We have a secretary as well. Um, depending— we have 3 board members at large. So a lot of discussions goes actually not that visible as the public board meetings. Yeah.
7:53Chris RomeoSo I guess when, when you think about the mission of OWASP, What is— why does OWASP exist, kind of from your perspective?
8:00Martin KnoblochI think when we look back when OWASP was founded and how I got involved in OWASP, OWASP was founded from developers for developers, how to write secure software, how to build secure applications. I think that's our single line of resistance, and in this way, very unique. We are not into breaking. We have to understand how you break. Applications, but telling people for free, giving the tools and guides how to build secure applications. I think that's the single point of existence, and that's very important. And that makes OWASP, I think, beloved because that's the fun-based, independent, open-source community who gives you the tools and the guidelines, what you have to think about when you write application, how to implement it. securely and how to validate it securely.
8:52Chris RomeoWhat was the first OWASP project when you got involved after that first AppSec conference? What was the first OWASP project that you really started using yourself?
9:05Martin KnoblochBack then, 2006, I think we didn't have the ASPS back then. We had a testing guide. That was really great. The education project, because I was learning and I got involved in the education project, and that was the tool that hooked me most in the beginning. The testing guide is still available. I think a lot of people abuse it, like abusing the OWASP Top 10 for being a checklist. They're using the testing guide for being a guide for how to write secure software, whereby the testing guide is how to validate the security. I think that's one of my big missions, to clarify what project is what purpose.
9:55Chris RomeoYeah, and I've taken a look at the testing guide in the last few months, and I was surprised as to how much education actually exists inside of that document. I hadn't done a deep dive on it and I was like, wow, they actually explain a lot of different types of ATT&CKs and things, right? And they teach you how to test for them, but they also give you a lot of foundational education material. So I think that's a great resource for people above and beyond the testers of the world, but people that just want to learn more about all the different ATT&CK pieces that we—
10:33Martin KnoblochYeah, I think it's a testing perspective, why you should test, what is the expected outcome, and then the tools and the guidance how you can do it. And these days, the mobile testing guide, also a great document. So they worked really hard on it, so I'm really thankful. I think that's what got me hooked in the OWASP community. You meet so many people worldwide who are so passionate about the projects and giving their free time and passion for a project to make it for free available. That's really, really great.
11:03Yeah.
11:04Chris RomeoDo you have any idea how many people total are volunteers in the OWASP universe? Have you ever seen that number? I've never seen it thrown around. I'm just, I'm just curious.
11:15Martin KnoblochYeah, we have guesstimates, um, for, uh, we get more and more paying members, what's nice. But, uh, uh, I think there's, uh, just below 4,000 paying members, individual members, not, uh, counting the corporate members. But it goes into the 10,000s when you look how many chapters, 200 50+ chapters worldwide. Then it's depending on like, uh, in the UK every city has a chapter, like in the US where the cities are further apart than in Europe, almost every city has a chapter. In Germany, the whole Germany is one chapter. We have separated in a typical German way, Stammtische, where you go have a drink and talk about your hobby. Um, so many people, I think we counted and guesstimated like, uh, it's close to 10,000 people, uh, organizing chapter meetings, being involved in projects, organizing events, on and on. It's amazing.
12:12Chris RomeoYeah, that is quite amazing that we have that many, that many people. And I know from my experience, and Robert, I think you would probably agree with this, that everybody you meet in the OWASP universe, whether they are people at a conference or whether they're people that you're working with on an OWASP project, everybody shares a common love of application security and that passion. You jump on the Slack, the OWASP Slack, and you see it there. So, that's one of the things that's great about this organization is just that people are so passionate about the end goal of making software more secure. And so, what else is more fun?
12:53Martin KnoblochWhen I joined them in 2006, their first conference, I was a newbie. Just learned myself development was just yeah, but only seven years in development, and there is no hierarchy. It's not like oh this is this upsec rock star and this is the newbie. No, everybody's appreciated the same. That's really hooked me. There's no a board member. It's not more or less than every member who contributes. So this must be one community for strive for the same. If you're new, if you are there for many years. many years, it makes a difference. We are all together.
13:26Chris RomeoYeah. And everybody that we reached out to— so Robert and I were at AppSec USA last year, and we did a bunch of interviews for the podcast there. Everybody we reached out to said yes. We didn't get a single no. We talked to the OWASP Top 10, the new team, Andrew and the team there, about what was happening with Top 10. We talked to Jim and Katie about proactive controls. The list went on and on, but everybody wanted to talk about their stuff. So it was, it was a great place to be because people were so passionate and it was just coming out in the conference and in the hallway conversations and everything else.
14:01Martin KnoblochAnd everything you do with passion, I always say you get frustration. So it's normal because you're passionate about it. And of course the world is not going fast enough, and if it would be, it would not be fast enough anymore. Yeah. But then when I see people wherever I travel, OWASP members who are contributing and having love for OWASP, that really makes it worth all. And when I go to conferences talking about OWASP and people come up to me and say, oh yeah, sorry, I'm not a member, my company is not contributing membership, but thank you for OWASP. I think that's so rewarding. And the thank you I have to share with all the community who puts in the time. I'm a humble servant to the community as a board member because it's great. Unbelievable.
14:48Chris RomeoSo with the passion that comes from all of these application security professionals that love everything about OWASP and what they do, we also get some kind of, I don't know, bad feelings and things as people kind of get into arguments and things. What's, what's been your experience there? I mean, do you see that? Is that something that, that's, that's a big problem in the OWASP universe, or is that something that's just kind of happening in pockets and, and people are working through those type of issues?
15:25Martin KnoblochIt's a problem of— there's several problems. It's also about being a global community. They're very different from even being European. I'm a Northern European and German. I know people say we don't have much fun, but we are very direct. I may talk to a thousand Europeans, like Spanish or Italian. There's always a different culture, different conversation. And when you talk to each other, because they're very geographical, so far apart, you talk to each other via email, via Slack, and you don't really know somebody. And then sometimes it can be A comment can be taken wrongly, but it's not meant to be harsh. Stuff like that is very normal. I have been a complaint/spistleblower officer for almost 2 years in the past. And yes, we had some very serious cases. And for this organization this size, it's nothing. It's, yeah, it happens and will always happen. People are offended, but in general, it's nothing.
16:34Chris RomeoSo do you think that, you know, is OWASP meeting the objective that we have right now? Do you think that with all these 10,000 people that are kind of impacted by this, how do we measure the fact that we're making a difference? Is it even possible to measure the difference that we're making as an organization? And I'm thinking more about the people who are outside of OWASP. Yeah, I think so. that, that 10,000?
17:00Martin KnoblochYeah, I think we do. If I see the number of times we are mentioned, OWASP guides, OWASP tooling is used, how many downloads we have, for example, for the ZAP proxy, for governance documentation and guidelines, the reference to the OWASP ACS, the reference to the OWASP Testing Guide. I think that is the difference we make. So, we don't make ourselves a standard, but we became a standard because people adopted us because it was the best thing out there and still is. So, that's one thing. When I go to— I think in the past we had this development outreach because we kind of lagged behind. We had too many security people, and I think we kind of lost, but now we're regaining the connection to developers. And They all heard about OWASP, they all know about OWASP, but we have to go there and tell them what it's really about. That's one thing I have done in the past, and I really try to strive, and I support everybody who's doing it. We have a special outreach budget for that, for people who are traveling to conferences, talk about OWASP with the non-OWASP people. Yes, they all heard about it, but the thing is, developers, they hear about it, they hear about OWASP Top 10, And that's it. So when you tell them what is there, how you can use it, how you can use it in your environment, be it DevOps, DevSecOps, continuous delivery, continuous integration, then they really come back and say, oh, I need to know more about this tool, I need to know more about that tool. But we have 2 kinds of things. We have one, our responsibility to our community and our sponsors to being to increase and continuously improve our services and our maturity, but for a community to make it more enablement that they can do what they want, chapter meetings, the projects. And we have to spread the word more. We have to be able to help our community to reach out to the, actually, the end user of our projects, not only test, but also the developers.
19:05Chris RomeoYeah, and that's That seems like an area where we can all take that as a call to action as far as the awareness side. And I would agree that we do see the OWASP projects and documents and things mentioned all over the place. And I think that is a great metric of the impact that we're having across the industry. But I think there's a lot more that we can do through the connections that all of us, that we all have, the 10,000 people that are passionate about this stuff.
19:37Martin KnoblochRight.
19:38Chris RomeoI think most of us are doing that already. I think we are. It's hard to bottle up this passion that all of us have about—
19:45Martin KnoblochYeah.
19:45Chris RomeoFor this topic. We're out there telling other people about it and stuff. But I think that's definitely something that we can continue to get better at over time. So, I've been thinking about this, and I've only been involved in OWASP as a member. This is my first year as a member, but I've been in the world of security for a long time. And so I'm wondering, as somebody who got started in this OWASP world in 2006, how have you seen OWASP change from 2006 to 2018?
20:24Martin KnoblochIt grew immensely. When I look back at a conference I've been to, I think there were just about 200 people. The current AppSec EU conferences, there are around 600+ attendees. The OPSEC US, depending also on the location, we had a bit of a bummer last year with the hurricane in Orlando. But the New York conference, I think, were more than 1,000 people. It grew, it grew in members, it grew in projects, it grew in chapters, it grew every side. Every direction you looked, it And I think we as OWASP, we kind of from the organization staffing side, we lag behind the growth of OWASP. I think that's something we have to put a lot of effort in to keep up with the growing OWASP. But yeah, I think that's the most important thing. It just got bigger, if I can say so.
21:20Chris RomeoWhat are some things that you think of to help with growth? growth, maybe some ideas that you might have in terms of helping with that growth?
21:31Martin KnoblochYeah, I think, uh, yeah, we had an ED, Paul Ritchie, who unfortunately deceased some years ago, and we kind of lacked getting a new ED. And we, I think we didn't understand how important it was. We had some tries to solve that internally, and I'm really happy we have Karen as our executive director. Who is then helping the staff who are overloaded by work? And people don't realize we have last year only five staff members. For an organization like this, it's ridiculous small. And so Karen is professionalizing our services, streamlining people we need so the the staff it's. It takes time, it costs money, but that's a very important thing we do. So having more people available for the right job and, yeah, helping, that's one thing. So you cannot do everything by volunteering. Also for the people, I think, don't understand how much money, and it's transparent, our financials are transparent, goes through OWASP, all the chapters, all the management, all The, the, we have only one, actually 2 legal entities. That's the, yeah, the foundation in the US and a European entity. So every chapter who has a, does a contract, being a sponsor contract, being a location contract, goes via the foundation. And with 200+, 250+ chapters, can you imagine how many invoices only had to be handled? So that's where we have to grow. So the professionalizing on the staff, on the support, being able to have more mature support for the community. I'm curious if—
23:25Chris RomeoI know that organizing the OWASP and all the kinds of things that, as you just mentioned, some of the duties and some of the things that have to happen now as you grow. But I'm curious, are you working on any projects today?
23:41Martin KnoblochAs I said earlier, I'm not directly involved in leading any projects. I'm more on the— yeah, who calls it— the PR project. So I go and talk about the projects. I supported the Security Knowledge Framework a lot. I helped a bit on the Security Red project, I hope I may say. So yeah, it's not— I don't have the time anymore as I am chapter leader in the Netherlands. And luckily we have also a board now for 4 people. With all the things I do, unfortunately I miss that. As I miss development in my day job sometimes, I do security, I miss being involved in a project in OWASP sometimes.
24:24Chris RomeoSo with where we are right now, it's, you know, we're doing this, recording this interview in June 2000, uh, we're not June yet, I guess May, but almost June 2018. OWASP has a couple of, of big conferences that we've mentioned already. Um, the AppSec EU, which is the first week of this year, is the first week of July in London, and there's a mixture of training and, uh, and actual talks that'll be happening there and vendors and things. And then we have AppSec US in the October timeframe, early in October in San Jose. Robert and I have been to both of these conferences. We love them. But I guess, Martin, from your perspective, what's the benefit of somebody going to these events? What are they going to get out of attending AppSec EU or AppSec US, especially if it's somebody who's never been before?
25:19Martin KnoblochThere are 2 parts. As you said, we have the training days and the conference days. So prior to the conference, we have 3 days where we have— we are the service provider for training. So we don't— OWASP doesn't do services. But so we have a call for trainings, and we have a training selection committee. So we selected the most relevant trainings we think for security people and developers to help them in their day job. So that's 3 days, Monday to Wednesday. Wednesday in the conference week. And then during the 2 conference days, we have also the selection committee for the presentations, the talks. So we get, I think for the APSIG in London, we got 180 submissions for the talk from which we have to select less than 40 for the conference. So it's the information, we try to divide them in tracks for Builder, breaker, and defender. Um, it's, uh, yeah, it's knowledge everywhere. As you said, when you talk about, uh, then the people and talked about the— I think sometimes I think you even learn more when you just there in the coffee corner in the lunch breaks and talk to people. Uh, so when you compare the conference for a 2-day conference, the price, uh, even if it got more expensive than we have to be in the past, it's really still a cheap conference for content and the environment you get offered. Being in the talks, being in the breaks, meeting your peers. So, it's uptake all week if you want to.
26:58Chris RomeoYeah. And from my perspective, the networking alone is worth making the— if you don't live in London or San Jose, it's worth making the trip just to get to meet lots of people, because Martin, I'm gonna, I'm gonna second what you said earlier about the fact that there is no hierarchy here in OWASP in general, and especially at the conferences. You can walk up and talk to anybody.
27:24Martin KnoblochYes.
27:25Chris RomeoAnd there's nobody who is, who is too good to talk to anybody there. And, and I'm just saying that based on experience in walking up to people and, and, you know, maybe even being a little bit nervous about, oh, can I even talk to this person? This is somebody who's I've seen their stuff all over the internet, but you walk up and start talking to them and it's like there's no air of any— but nobody's better than anybody else. And so I think that's a great thing. And there's lots of conferences where the speakers are royalty and you feel like you can't talk to them because they're so important.
27:57Martin KnoblochWe do have sometimes— we try to have a speaker room so the speaker can prepare his talks because normally They are surrounded by everybody you know and some more. So we have to give them a break to prepare the talks, and when they have done the talks, to get back to strength. But we really encourage them not to stay in the speaker room. I think I've seen speaking conferences, and if the speaker area where they have the better lunch, the better drinks, not for ours. It's all the same. They need a space to prepare the talks, of course. But for the rest, it's everybody out there. We are one community. We don't have leaders. We don't have hierarchy, as you said. It's all us.
28:44Yeah.
28:44Chris RomeoSo we're coming to the end of our, our time here, Martin. And so I guess as a conclusion, or as a wrap-up here, what could you give us, like one, I guess, one challenge to the OWASP community? Because a lot of OWASP folks actually listen to the podcast here that are part of their local chapters and things. And I guess from your perspective as the chairman of the board right now, what's, what's one challenge that you would throw out to us that we can, that we can walk away and, and, uh, and, and do or go after?
29:13Martin KnoblochI think, uh, the challenge we all have is to reach out. Uh, as I said, ours is known widely inside the community, of course, but also outside, but also misunderstood sometimes. So reaching out to people who are not directly in contact with OWASP, because for example, developers, they have so many concerns, but just taking them out, the right thing, the bits OWASP can help them make their life easier. So to reach out, talk about OWASP, not only with the OWASP peers, but to everybody. I've been to so many conferences, I haven't bought any t-shirt for many years because— so I'm wearing an OWASP shirt for every day. Let's go in there and be OWASP and be a missionary for OWASP. That's something everybody in the community is.
30:01Chris RomeoYeah.
30:02Yeah.
30:03Chris RomeoAll right, Martin, thank you for taking the time and sharing a lot of your kind of history and knowledge and experience with OWASP. We definitely appreciate it and we look forward to seeing you face to face in one of the upcoming EU or US conferences for OWASP. So thank you very much.
30:21Martin KnoblochThank you, Chris. Thank you, Robert. Thanks for having me.
30:24Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.com. .appsecpodcast.org.
4,918 words · transcript by assemblyai
More on OWASP Top 10
View all episodes →- September 25, 2017 · 36 minAndrew van der Stock and Brian Glas -- The Future of the OWASP Top 10
- July 25, 2017 · 44 minDave Ferguson -- The OWASP Top 10 Proactive Controls
- November 10, 2021 · 40 minSimon Bennetts -- Using OWASP Zap across an Enterprise