--- title: "Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People" url: https://appsecpodcast.com/matt-rose-software-supply-chain-security-means-many-different-things-to-different-people/ date: 2024-06-11 duration_seconds: 2774 season: 11 episode: 14 guests: ["Matt Rose"] topics: ["Threat Modeling", "Security Testing", "Software Supply Chain", "DevSecOps and CI/CD"] audio: https://www.buzzsprout.com/1730684/episodes/15227159-matt-rose-software-supply-chain-security-means-many-different-things-to-different-people.mp3 video: https://www.youtube.com/watch?v=zk-U3wne6OU transcript: true --- # Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People *June 11, 2024 · 46 min · Season 11, episode 14* with [Matt Rose](https://appsecpodcast.com/guests/matt-rose/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Software Supply Chain](https://appsecpodcast.com/topics/supply-chain/), [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/) [Audio](https://www.buzzsprout.com/1730684/episodes/15227159-matt-rose-software-supply-chain-security-means-many-different-things-to-different-people.mp3) · [Video](https://www.youtube.com/watch?v=zk-U3wne6OU) ## Show notes Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyond SCA, the relevance of threat modeling, and the potential risks and benefits of AI in security. Matt Rose is a technical AppSec testing leader with consistent accomplishments in sales and sales engineering management roles with more than 20 years of experience. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Matt Rose: → [LinkedIn](https://www.linkedin.com/in/francoisp/) → [The Application Security Program Handbook by Derek Fisher](https://www.manning.com/books/application-security-program-handbook) Mentioned in this episode: → [The Application Security Program Handbook by Derek Fisher](https://www.manning.com/books/application-security-program-handbook) → [ReversingLabs](https://www.reversinglabs.com/) → [YouTube video](https://youtu.be/DgmlHgNT-UM) → [Stephen E Ambrose](https://www.simonandschuster.com/authors/Stephen-E-Ambrose/1063454) → [Mark Frost](https://en.wikipedia.org/wiki/Mark_Frost) → [Fortify (OpenText)](https://www.opentext.com/products/static-application-security-testing) → [ChatGPT](https://chatgpt.com) → [Pixee](https://www.pixee.ai/) → [LinkedIn](https://www.linkedin.com/in/francoisp/) Chapters: 00:00 Meet Matt Rose: Software Supply Chain Security Means Many Different Things to Different People 03:53 Let me ask you this question. How good are you at 04:45 That's true. That is so true. That's, that's a good way 11:33 Yeah, 100%. And I like to think of weaknesses in the 14:56 You're, you just made me think of something. About when you 17:12 Yeah, it seems like, it seems like there's a perfect storm 19:09 I want to double-click on something that you mentioned earlier. And 22:10 I mean, I think that's more of a startup growth problem 24:55 It the first, is it the first thing you would like 28:15 Yeah, I've never actually seen anybody do it. I've heard DJ 30:38 About, uh, AI 34:39 Yeah, I'm not, I'm not ready to embrace auto-remediation at this 37:32 Yeah. And we're starting to see a whole cottage industry of 40:14 Absolutely. The second question is, what would it say if you 41:54 Our 3rd question is, uh, what's your top book recommendation and ## Transcript *8,800 words · assemblyai* **0:00 Chris Romeo:** Matt Rose is a technical AppSec testing leader with consistent accomplishments in sales and sales engineering management roles with more than 20 years of experience. He was a key thought leader for 2 AST vendors growing from the startup phase to major acquisitions, Fortify and Checkmarx. Also, he's an accomplished public speaker, has been quoted in 50+ AST industry media publications, and and has an extensive background in AppSec, object-oriented programming, multi-tier architecture design and implementation, and internet intranet development. Matt joins us to discuss how the software supply chain means different things to different people. We explore new avenues uncovered by the XZ compromise, and people spending too much time on the history of supply chain is a bit of a challenge for Matt. We also explore the concept of digital twins and how AI will impact The Application Security Podcast is brought to you by Security Journey. **1:00** Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization. Learn more at securityjourney.com. **1:10 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am the CEO of DaVinci, a general partner at Curve Ventures, and I also get to hang out with Robert, my friend, on this most awesome podcast. Robert, great to have you with us again, back from your travels around the globe, wherever that was on Earth. Right. Hey, yeah, Robert Hurlbut. I'm a principal application security architect and threat modeling lead at Acquia. And yes, glad to be back and looking forward to our talk today. Yeah, we're excited to have Matt Rose join us. I've had the, uh, the opportunity to sit on a webinar with Matt a number of months ago and, uh, found him to be a brilliant mind in the world of software supply chain security, probably a lot of other things too, but we just talked about software supply chain security in that context. But Matt, we always like to jump in and get right to your security origin story as fast as we can, just to, to lay the groundwork for our audience about where you're coming from. **2:22 Matt Rose:** No, absolutely. I mean, I can't believe I'm actually saying this, but it's a year that I've been in the space and I fell into it by accident. Got called by a recruiter, software engineer for years, and then a consulting, consulting lead to implement different types of softwares or applications. And I got a call about the security company and I'm like, well, I know firewalls, I know this stuff. Sure, let's talk about it. And it ended up being Fortify. In the early days of Fortify when they were still being incubated in Kleiner Perkins basement. And they had this scanning of the source code to find something called SQL injection and cross-site scripting. And I was like, all right, I'll take a look at it. And, uh, you know, long story short, I passed the tech screen and was with Fortify through acquisition by HP. And then I was with Checkmarx from the beginning days when they first started to build out in the US. And private equity purchase for over a billion dollars by H and F. Pretty much, I have no hair. Director Iran Asia Pacific. A lot of great all over my career, like you, Chris, and you, Robert. Kind of found myself because I'm a wealth of useless knowledge doing a lot of evangelistic public stirring the pot in terms of controversy about the industry, where it's been, where it's going. So yeah, that's about it. I mean, and thank you for your kind words. You know, I just, uh, uh, with a lot of useless stories and analogies all pent up in my head. **3:52 Chris Romeo:** So let me ask you this question. How good are you at Jeopardy? **3:58 Matt Rose:** Uh, I'm okay at Jeopardy. I really do well on the sports questions and some obscure categories. My wife is actually obsessed with uh, Jeopardy. So she watches it every night. So I, I hold my own. Uh, but there's some categories like, I have no idea what you're talking about. **4:15 Chris Romeo:** Yeah, I'm the same way. My wife is also a, uh, a, a rabid, uh, fan of Jeopardy. And, uh, just when you mentioned useless knowledge, that's what always gets thrown at me when I answer some obscure question that, you know, the, uh, 14th century blah, blah, blah. And I just take a guess. Like, I'm just, I'm just, I'm guessing from my my memory bank with whoever I think could be the possible person. She's like, how did you know that? **4:38 Matt Rose:** I'm like, I just guessed. **4:40 Chris Romeo:** That's all I do. Good guesses. **4:41 Matt Rose:** I always say, even a broken clock is right twice a day. **4:44 Chris Romeo:** That's true. That is so true. That's, that's a good way to look at our entire cybersecurity careers, I guess. That's a good way to describe a lot of, a lot of programs out there. So, uh, so Matt, let's, uh, let's, let's set the stage a little bit here as, as a place to start now that we've, we've heard kind of where you came from. Uh, your, your journey through, uh, the different, uh, companies and whatnot that you experienced. Software supply chain security, we think of it as a buzzword at this point. And what we see is it seems to mean different things to different people, depending on who we're talking to. And so we're curious to get a perspective on what's your definition of software supply chain security? That's— **5:28 Matt Rose:** how much time do we have? Because that's a, that's a long-winded answer to a question, but I'll try and make it as interesting. **5:34 Chris Romeo:** We have a lot of gigabytes of data in the cloud, and so it translates to hours. **5:38 Matt Rose:** So it's all about perception in the eyes of the beholder is what software supply chain security is. And it's, again, a buzzword in the industry, and people want to make themselves feel smart on top of things. So they just, you know, start talking about software supply chain security. But when you really peel it back, what is it? Are we dealing with malware? Are we dealing with tooling? Are we dealing with firmware, because a lot of times people immediately jump into, you know, the embedded space because they think of a physical supply chain, like an automotive supply chain or a medical device supply chain. They can't wrap their head around the supply chain associated with building an application or a piece of software with code that has no physical thing. And that's kind of the thing that people really kind of focus on, is either that tooling aspect or the firmware aspect, embedded space. Or malware itself. And then the, one of the big things that I think is, is really doing a disservice to the industry is that SCA has been deemed the software supply chain, um, security, uh, foundational technology. And the people on there, I'm assuming everybody knows SCA is software composition analysis. But again, if you only look for supply chain risk in the open source code, guess what? You're only going to find it in the open source code. Just like one of my biggest pet peeves is I hate shift left. I've been saying it for years. Uh, and the reason being is if you shift left, you only look for, find things on the left. In, in modern software development, whether that's a supply chain, uh, lens or an application security lens, you have to be shifting everywhere because that entity with cloud native, microservices development, all these things, people only work in their little island. They don't talk to other people. They're very antisocial. So, and I still am reading promotional material, marketing material, white papers that are like, in order to be successful, you have to shift left and it'll save you X amount of dollars to find it in the beginning. And I know you guys are big into threat modeling. When is the beginning? It's like, is the beginning the Big Bang of the first line of software that was ever written? Or is it just this continuous thing that we have to address? **7:43 Chris Romeo:** Yeah, and I was celebrating your dislike of shift left there. **7:49 Matt Rose:** I hate it. **7:49 Chris Romeo:** It's another one that I, uh, I tend to make a lot of fun of this. That's because, and I always come back to the concept is I agree with the concept, of course. Right. But in the 1990s, late 1990s, we called it building security in. Joe Jarzombek, that was at DHS, kind of groundbreaking work into embedding security into lifecycles. But this is in the late '90s. And shift left is just this, it's just a marketing term that has been repurposed and reused. And it even, you know, I did an analysis at one point and just searched around to see, and all the different shifts that people have now incorporated, just, okay. I've already, our audience has heard me have rants against that for far too many moments. So. **8:35 Matt Rose:** Well, I, you know, think about it this way too, a little, too quick little side note, tangent, tangential conversation. If you're shifting security left, how do you shift security left with one of your favorite technologies of DAST? How do you shift that left? How do you shift, uh, IAST, you know, left? You know, how do you do these things? You know, it doesn't make any sense because you need a running application for those type of things. You need something to actually look at it in a later stage. **9:01 Chris Romeo:** Yeah. **9:01 Matt Rose:** And that's where I feel like shifting left is not the answer. And I think, again, security should be shifted everywhere. But I like to shift everywhere, remediate left, because at the end of the day, you got to remediate on the left in the code typically. So it's remediation on the left, identification, or shifting everywhere. Yeah. **9:21 Chris Romeo:** And for me, threat modeling, uh, is the perfect approach to how we can consider security and privacy from the beginning of the process, which is really what we're trying to achieve here. And lots, lots of paper has been used to argue about how much it saves or whatnot. But I think common sense tells me that if I consider security and privacy, when we have a new idea about something we're going to build, instead of waiting until we push code into production, it's going to save me something. Like, it just, logic, it would defy logic to say it will be cheaper to wait until we finish this thing. **10:01** Yeah. **10:02 Chris Romeo:** And have to go through the rework process to include security than to do it upfront. And for me, that's where, that's where threat modeling really shines is one, it helps the developers. It helps the people that are building to get a framework around considering security and privacy, because we know that's one of the big struggles that exists in the world is people that are writing code and designing code don't have a security and privacy foundation yet. It's getting better. I've watched it get better for a number of years, but we're still not there yet. And so that's why threat modeling is, is really the ultimate solution in my mind, because it does carry us all the way through the lifecycle from this ideation stage where we can threat model somebody's idea all the way down until we have something in production. We could still do the same threat modeling consideration of production code. **10:49 Matt Rose:** Yeah, absolutely. And think about it this way. I mean, most of the Things you're looking for are vulnerability. And what are vulnerabilities? Going outside the bounds of the intended purpose or the intended functionality. So a STAST solution or whatever, STAR AST solution I like to call them, is looking at something structural. It's looking at ABC has to happen and here's a vulnerability and here's how you fix that vulnerability. But you can actually be much more proactive with that threat modeling approach to say, hypothetically, what could happen here? And then put in the checks, balances, protections at the appropriate place that's not as structured. It has to be a little more deep thinking in terms of, hey, what could go wrong and how could it go wrong? And let's bake that in from a secure-by-design standpoint. **11:32 Chris Romeo:** Yeah, 100%. And I like to think of weaknesses in the early stages before we meet, get to production, especially in the design phase, because for me, when we get a vulnerability, doesn't become a vulnerability until we have some code written down. But a weakness is something that can exist in a design structure. And so when we're in those early stages, we're looking for weaknesses and my mind. And then when we cross over into code, that's where we start searching for vulnerabilities because we don't have a good way to scan the design process at this point because the design process itself is, it is a design. It can be in so many different things. It can be in somebody's head. It can be a conversation that Robert and I have to design a feature that we don't even, we're not even writing it down. We're just talking about how we're going to design it. And so really for me, it's like, how do we get to those weaknesses? But then vulnerabilities become a thing that manifests. with any of those weaknesses that we don't properly catch. Sometimes we just miss some of them along the way too. I know, Robert, you were thinking about the XZ library. So what, what was the question you had on that? Yeah, just talk to us about that. I know it's a fairly recent or relatively recent thing that happened, but what new avenues were exposed through analyzing the XZ library compromise? **12:49 Matt Rose:** I'm not a total expert. Again, I've been doing a little bit of research in some other areas. But again, it's the biggest thing to think about any type of library that's compromised is what is in there? How did it get in there? And what is the path to success? I know, Chris, we talked about this. I mean, I won't mention it because I won't steal your thunder. You know, past software supply chain attacks are starting to get beat up and getting a little old. But it's staying diligent because people get, well, it hasn't happened in a while. Well, Why should I care about it? Why should I care about the software supply chain or malware or typo squatting? Nobody's really been dinged by this yet. So I really think that the process is to stay diligent as much as possible. But again, to be a little controversial within software supply chain, I just don't think people are taking it seriously. I mean, it's— these things are major when they happen, but they don't happen a lot. So people are like, hey, not my circus, not my monkey, one of my favorite sayings. Is, hey, I haven't been attacked. Other companies have been attacked, but I'm just going to wait it out because I don't want to spend the time, resources, or budget to actually address these things. And the biggest problem is that YaaS conversation, and that's my favorite acronym these days, is yet another security tool. We're overlaying these all over the place, automating, and now we've even got technologies, which I'm very pro, like application security posture management or cloud security posture management. I just think that people are so tired of it, and they're willing to bite the bullet. Because I'm seeing a lot of people talk about software supply chain security, but only the bleeding edge type of companies are taking it seriously. And I mean, what's your guys' thought on this? I mean, any of these things, it's just the same thing over and over again. There's a, there's a path that's never been seen before. It's novel, it's new, it's malware got into the build system, malware got into stealing credential, malware got in by I don't know, getting the credentials for a developer's code repo. These are all like social engineer type of activities that, Chris, you know, I think threat modeling goes hand in hand with. So I think that, that aspect of threat modeling with supply chain is, is much more tightly coupled than say a SaaS scanner like SAST or DAST or something like that. **14:54** Yeah. **14:56 Chris Romeo:** And you're, you just made me think of something. About when you were talking about this kind of rhythm of people will say, well, this can't happen to me. This is, this software supply chain is not going to be a problem for me. Uh, I started in security in 1997. So I got to, and Robert, we're, we're, we're from the same vintage as well. We got to watch the data, the same thing happened in the data breach world starting around, I feel like it was around 2001, 2002, where it really got moving. And you had the same thing. Somebody would get popped and then other people, and then you would go to management people and say, well, we need to start investing more in security. We need, we need to step up our game. Well, it has, it didn't happen here. Hasn't happened to us. So it feels like you're describing, like, there's almost like a parallel between the data breach, uh, of the 2000s leading up to 2010 or so and what's happened in software supply chain in the last number of years. It seems like we're in that same kind of rhythm right now. which we know how the data breach rhythm, eventually so many people got popped that people started to pay attention. So I mean, is that where the supply chain is going to go? Do you think? **16:03 Matt Rose:** I think so. I think it's got to become more streamlined in terms of the process. And, you know, I think the industry has to define it a lot better than it does, because, again, people latch on to buzzwords, they use them, they don't really understand them. And I think that supply chain and malware is a big problem, because think about it this way. With Normal application security or hacking attempts, they're trying to steal an individual's PII data, their credit card data, their name, Social Security number, DOB, whatever that thing is. But they got to go through a cycle of attack or the long con to get all that information, scraping social media, a data breach where they get a little bit of information. It's a lot of work and it's time consuming. It's more work, yes, for a software supply chain breach to find a way to get malware into some sort of build pipeline. to compromise it. But once you do it, you let that company propagate your malware, propagate your attack. So I think that the thing people have to realize is they are the target now because nobody wants to go the onesie-twosie route or, you know, hack Joe, Steve, and Bob when they can actually hack 10,000 people by just leveraging or compromising a piece of enterprise software or application. **17:12 Chris Romeo:** Yeah, it seems like, it seems like there's a perfect storm brewing. And it, it doesn't feel, it feels like a lot of people are on the canoe just paddling away going, it's going to be fine. It's going to be, uh, we're not going to get knocked over by this giant wave. But it's like if the camera pans back in the movie and we can see the little, the wave growing and picking up speed. And so I guess the question is, when is that going to, when's it going to hit? When's, when do you think it's going to hit? **17:41 Matt Rose:** I'll give you another analogy. It's Caddyshack. I don't think the hard stuff's coming down for a while. If you are a Caddyshack fan with the rain, I mean, I think it's you know the mandates from executive office and a lot of the governmental stuff I think is pushing it, and I think it's going to become cemented into anybody that wants to deal with DOD or civilian agencies, and then that'll trickle down and probably take a little while. But I'm thinking a year or two it'll become more mainstream. The problem is again we have so many tools. You go to RSA, you go to Black Hat, you got. So many vendors out there with so many different avenues of trying to do something. People are just overloaded. I mean, in my opinion, this is my opinion. If you want a secure application, secure software supply chain, you should have every one of these tools because they all do something really good. They, you know, even if it's 2% of the product, they all do something, but it's just not feasible. It's not feasible for the care and feeding, the budgets, the headcount to operate this stuff. So, and people are just overwhelmed with too many vulnerabilities these days, too many things to look through. And it's kind of like, all right, I'll do a little bit, I'll get my backlog down a little bit, but it's never going to be zero. And now you want to layer on more risk or more, an additional lens of risk with supply chain risk and malware and typo squatting and securing the pipeline. It's a lot for people to swallow. And that's why I think that people are struggling with it. They don't have time already. And you want to put fire on a smoldering, uh, gasoline on a smoldering fire. **19:08 Chris Romeo:** I want to double-click on something that you mentioned earlier. And I didn't, I didn't get a chance to, to, to address this earlier, but I do want to get, get some more context on your take on SCA. So you made a comment to the effect that almost like people think of SCA as software supply chain security, and there's so much more to it. So can you give us a little more context on that for somebody? Because let's imagine we've got some people listening. I know we do. We've got people at different stages of their AppSec journey. Some people are brand new to AppSec. Some people are, you know, decades and decades of experience. What, how would you address this to somebody that is one of the newbie, newer people perhaps that have, they've gone to conferences, they've heard people say SCA, you have to do SCA. What, how would you, what would you give them advice about, uh, in regards to SCA? **20:05 Matt Rose:** Yeah. Can you see my circle here? Because I mean, SCA is all, again, all these tools are important because they all serve a purpose. They're all good at what they're designed for. SCA was never designed to look for malware. It was look, uh, you know, designed to look for vulnerabilities or risky package inheritance. Reachability within the open source packages, and that's you know here's my little thing. Now I'll draw it over here so you can see it a little better. These are all pieces of the puzzle. So you have your open source, you have your first party code, you have COTS. These are all things you have to consider is all of these little different areas. And if you just say well, and this is the thing that people got caught up in and why SDA has become a household acronym, is that depending on what who you read is 60 to 90% of all modern software and applications are open source. Okay, that's a big number, a big sliding scale. I've seen it sometimes as much as like 40 to 90%. Even if it is 90%, you still have 10% of other things in there, the first-party code you've written, the POTS packages, APIs going out to do some sort of functionality or data retrieval. So if you're just using SDA as your your de facto standard of supply chain security, or application security, you're only basing risk in the open source package. There's many different things, as we've seen out there, with the first-party code, with the potential for malware being inserted, with user credentials being stolen. So don't think of SCA as the end-all be-all. And the proof is in the pudding that all of these major SCA vendors that have come in And initially had their marketing messaging and statements as all you need is SCA because blah blah blah, 60 to 90% is open source. Just secure the open source and you're good. All those vendors are now adding API scanning, SAST, manual pen testing. So they're basically contradicting themselves by adding these additional technologies because at the end of the day, beginning of the story was all you need is SCA. Do you agree with that? I mean, it just seems like. They're all growing to more of a platform play because they realize it's not— **22:09 Chris Romeo:** I mean, I think that's more of a startup growth problem than it is a, you know, when you, when you think about how crowded the SCA market became, I mean, we could probably sit here and come up with a list. There's probably 20 tools, SCA tools. And then if you start weaving in the open source, there's probably another 20. When you think about all the different tools that differ different, you know, there's, there's stuff for Node, there's stuff for Python, there's, There's various things. There's, there's npm audit, you know, from a Node Package Manager perspective that you can do without paying any money. So my gut says it's more of a growth, it's a startup growth problem as to why they're expanding beyond that than them not thinking the technology or thinking that their, their answer to the story is changing. It's tough to, it's tough to have 100% year over year growth in a market with That's, that's commoditizing itself just because of interest. And I know, Matt, you've been through a number of startups along the way in your journey. So like, what's your take on, like, what are your thoughts on that? Do you think I'm onto something here? **23:12 Matt Rose:** No, I am. I mean, it's just a question of, you know, buyer beware is what I'm saying. It's like, you know, early stage companies, they have the, the, I don't know, the holy grail technology, and then they start adding side dishes or other, other capabilities just to keep those lights on and grow the ARR for the company. But again, you know, same thing was sold with IAST. All you need is IAST, you don't need SAST. I mean, all these things are trying to contradict themselves. And that's why kind of having a platform play or a stitched-together best-of-breed application security initiative, all tied together by application security posture management is the way to go. Because again, if you hook your, hook your wagon up to one horse, you're not going to get there very fast. You need a team of horses to get there much faster. **24:01 Chris Romeo:** If we, if we just, let's, let's push all these star AST tools off to the side for a second and just laser focus in on what, what you think of as the software supply chain security market. What percentage do you think SCA gets you of the overall software supply chain security solution that a modern, a small or a medium-sized startup to a modern enterprise need, should have a strong software supply chain security program in using some type of technology. So how far does SCA get me? Is it 10%? Is it 50%? What do you think? **24:39 Matt Rose:** I'd say 30, 30 to 40, somewhere in there. Because again, you're not addressing malware, you're not addressing the tooling, So, I mean, it's definitely an important piece and it's a significant piece, but it, I don't, it's not gonna be 70, 80, 90% of the way there. I mean, based on— **24:55 Chris Romeo:** Is it the first, is it the first thing you would like, is it the, is it the low-hanging fruit of the software supply chain? Like the easiest thing to implement? Oh yeah. **25:04 Matt Rose:** I, I think it's, it's, that's why it was successful. It is easy. You just, you know, throw the open source packages at a SCA solution, you get your results, and that's pretty easy. It's pretty straightforward. But again, it's not like the graduate-level course, like threat modeling or something like that, which takes a little more time, resources, and expertise. I mean, you're not addressing malware with SCA. I mean, that's one of the things is, you know, at the end of the day, malware is the 3-headed scary monster in software supply chain risk. And it's, you know, you lock down the tooling to make sure that malware doesn't get in there. You lock down the credentials so malware doesn't get in there. So at the end of the day, it's malware. and then work backwards to the different avenue, whether that's, you know, a vulnerability or malware in an open source package, or your first-party code, or compromising your build, or even your code repo, or even, you know, your, your TPM, third-party risk management of malware gets into your network through something that you bought commercially. So again, it's like, it's malware is the tip of the spear, and then it kind of expands out like, like tentacles. **26:08 Chris Romeo:** Well, Matt, what are your thoughts on digital twins and use of those today? **26:18 Matt Rose:** So I think it's a graduate-level class to go through that whole process to actually do the care and feeding of 2 separate build pipelines to make sure that, you know, not only verifying one release versus another, you're basically looking at the pipeline potential. But again, not everybody has that or has the budget to support that. Only the bleeding blue-chip cybersecurity or Fortune, you know, whatever, 110 companies have that type of budget. And people like to talk about these things, but again, in practice, they're like, I wanna talk about digital twins or reproducible builds. The question is, okay, do you have that in place? Well, no. Okay, so how can we talk about it? And a real-world example I used to have when I was first with Fortify, Fortify had huge press releases and all these white papers about cross-tier data flow analysis, which at that time was a very cool concept. So you could basically follow a data flow from one type, one coding language to another, like say Java to JavaScript back to Java, and watch that flow of execution across languages when usually SAST scanners are unique to a language. You know, they have different scanners, but they actually do that cross-tier. People are like, oh my God, that is the coolest thing ever. I wanna see that. You know, they use the product, they scan the code and they don't find it. You know why? Because the structure doesn't exist. They don't have any specific calls that are actually doing a data flow that's somewhat dangerous from Java to JavaScript to Java. So they're like, well, why should I care about it? That's the thing is digital twins are reproducible builds. Why should, if you don't have the program in place or the initiative to do it, it's not even worth talking about. It's very valuable. But again, now you're, you're, you're responsible for the care and feeding of 2 clones of the same thing. I mean, what's your guys' thoughts on it? I mean, you probably see a lot of different examples. **28:14 Chris Romeo:** Yeah, I've never actually seen anybody do it. I've heard DJ Schleen talk about it in the past in the context, and I don't know if that means he's, he's he's achieved it, uh, in any of the companies, but I've never actually seen anybody that could prove that they were doing it at scale. You may have people that are able to do it from a one-off perspective. Oh yeah, we have this project that's, that's doing it. But you think about being able to do that across, you know, it's one thing if you're a startup that has one product, one SaaS platform that you're building everything through one pipeline. Okay. We can make a second pipeline. But if you have 500 different cloud-based applications, and then now you're trying to double the pipeline. And when I, the more I think about digital twins though, the more I think like, yes, it is a layer in the proverbial onion of defense in depth, right? Because we're adding another hoop that somebody has to jump through. But if they could jump through, if they can get into one pipeline, What's going to prevent them from getting into the other pipeline and just replicating the same thing? Or if you get a, if you get a downstream package compromise like XZ, where if it was, if it hadn't been found so fast and it was being propagated and both build pipelines are pulling the same trash in, they're going to come. So I'm starting to almost question the, well, I'm not even starting on almost, I'm starting to wonder. Is it worth the investment and the amount of headache that it puts into the process? Is it really moving the security needle that much forward for me? I'm starting to struggle to see how it is. **29:54 Matt Rose:** Yeah, I feel the same way. I mean, yeah, there's a time and place for everything. I mean, I just don't think it's worth the time, effort, and budget to do it. I mean, what's— how is that going to be any different than doing a diff of version 1.1 to 1.2? Now you're doing, you know, version 1.1 on build 1, build 1.1 on build 2, and now you're actually comparing, you know, horizontal and linear in terms of, you know, across this way of what each pipeline's producing and then comparing them to themselves. **30:24 Chris Romeo:** Yeah. **30:25 Matt Rose:** Again, we're dealing with YAST. Now we got another layer of, or, you know, alert fatigue. Now we're doing, giving an additional layer of investigation that's required. **30:37** Yeah. **30:37 Chris Romeo:** How about, uh, AI? As we know, everybody is gaga for AI in the world right now of, of every, every vertical, every industry, everybody's concerned AI is going to take away their job. Well, some people are. When we think about software supply chain security, what, what futuristic things does AI open up for us as possibilities? **31:04 Matt Rose:** I think it's that ability to get through that alert fatigue and use, you know, kind of the ability of AI to crunch a lot of information and say, hey, this, you know, blue cat, yellow dog, and a, you know, cloudy day typically means this. I mean, I'm just being facetious and trying to be humorous, but this associative things coming together has produced risk before. But even to take a step back, everyone's so gaga about AI and even writing code for you and vetting code. It's like the fox guarding the henhouse in my mind. I mean, AI is, if I'm not really off base, software in itself. It's not just like a box that, you know, is autonomous and thinks for itself and it's software in itself. **31:48 Chris Romeo:** Yeah. **31:48 Matt Rose:** And that software can be compromised just like the banking app or the e-commerce app or the ERP app, whatever that is. So now you're basically, you know, giving the keys to the castle on something that maybe compromised from a supply chain risk or an application security risk, uh, in the code level or even in the, uh, the large language model that it's leveraging. So, I mean, it's, you know, it's like the, the data's poisoned so people can have different ways attack the data or attack the software. So yes, there is very, um, amazing things that AI would do, but we can't even secure the applications that we're writing today. I mean, I've been doing this, you know, 20 years, Chris. Robert, you guys have too. We're still looking for SQL injection, cross-site scripting. I mean, we're still looking for privacy violations or, you know, dumping important PII data to log files. I mean, simple, stupid stuff. And now we're basically writing something that's going to do all that for you. Again, I think it's the fox guarding the henhouse. The checks and balances have to be even more stringent than what you do for securing that platform, those platforms above and beyond just normal applications for functionality. **32:54 Chris Romeo:** Yeah, I've started to refer to the AI as an intern. I think we need to give the AI, we need to treat the AI like an intern. We wouldn't give an intern the ability to push to production. We wouldn't give an intern the ability to commit code without it being very highly scrutinized by multiple people. Multiple other humans would be, and automated tools are run against code that an intern writes to ensure that they're not introducing some new security vulnerability or something that, uh, is part of the corpus of knowledge that we've assembled as an organization, then, and we, you know, managed to eradicate a particular type of issue that an intern may not know about. And so I think that's a, that's a safer way to compartmentalize or box the, what AI can do and what we allow it to do. Don't give it anything more. Don't give it any more permissions than you would give to an intern at this point. **33:47 Matt Rose:** Yeah, think about it this way too. The, you know, supply chain solutions, whether it's looking for malware or looking for vulnerabilities in packages or, you know, application security, looking for OWASP Top 10 type issues. One of the things being in the space and representing, you know, Fortify and Checkmarx and other companies was the concept of auto-remediation, which is a very scary thing. If you're talking about a, you know, lines of code and say you don't understand the whole story, compensating controls that aren't even part of the code base, or you have something that is a homegrown sanitization routine that's unique to your specific account number format. These solutions were never really allowed to do that auto-remediation because it was a risk. What if that auto-remediation missed something, and now you think you're secure, and you've just, you know, opened up the doors to the castle? Now we're doing that same thing for the auto-remediation, we're just calling it AI. **34:39 Chris Romeo:** Yeah, I'm not, I'm not ready to embrace auto-remediation at this point. I'm optimistic because I've seen some cool things by some different startups like Pixie and Mob are doing, they're doing some cool things. I'm not ready to turn it loose in my production environment yet at this point. I still want to see more testing and more evaluation going into what is it, what is it able to do? But I think to your earlier point, the alert fatigue is someplace that's That's burying every organization right now. Like everybody has got too many alerts being generated by too many blinky lights and too many beeps and stuff that are, that are coming into their, their environment. And so if we could use the AI to do what I think it's the best at doing, which is summarization, which is really the primary thing I use AI for, is take this text and summarize it down for me into 2 sentences so that I can I can get a general idea of what this block is looking at. If we extrapolate that out to, we've got 10,000 alerts coming in, it seems like the AI should be able to process those 10,000 alerts and summarize them in such a way that it improves the operating ability of the SOC analyst or the AppSec engineer so that they can have better— **36:03 Matt Rose:** Right. **36:04 Chris Romeo:** They can focus in on the things that are most important. And so that's, that's really, I, I think of AI is it's, it's the intern that makes you 20% better at doing your job. And I think that's where, that's where we're gonna be for the next number of years. Is there gonna be another jump into, you know, more of an artificial general intelligence? Yes, I think that's, that's coming in the future. But I think what we have now is not, it's not, uh, it's not that. It is, it's simply a summarization And I'm not ready to trust the code that comes out of it because I have seen nothing. I've seen nothing to say that it can write secure code. **36:40 Matt Rose:** No, it's, it's, again, it's, it's doing the spec, but it's not anticipating going outside the bounds of the intended purpose. And that's the thing I look at is, is it just, is it helping or is it hurting? But I think that processing of large amounts of data to summarize, to quantify, qualify, whatever you want to call it, is the best way to go. Um, and maybe there should be, you know, a ranking system or some sort of flagging system that, hey, yeah, you can write mundane code that, uh, you can allow it to write mundane code that, I don't know, creates job descriptions or something like that. But if it touches PII data, financial data, or any type of, uh, secrets manipulation, it's not allowed. You can't use it to generate code for that orchestra. So I think it's kind of like a separation of church and state. It can basically be used for the things that it's not really dangerous and the things that are dangerous, you keep it away from. **37:31 Chris Romeo:** Yeah. And we're starting to see a whole cottage industry of startups that are focused on access control and authorization at the LLM edge, which I think is, it's opening up a whole new market of how do we control the requests that go in? How do we, how do we ensure that The requests aren't doing something that is gonna generate a negative result. How do we check the results coming back outta the LLM? So I'm, I'm curious to see where that goes. I haven't seen anything yet that's, I, I haven't, you know, I don't, I don't think they're mature enough yet to, I think they're just kind of coming outta stealth, those companies that are doing that type of thing. But I'm excited to see where, where those, those organizations go. **38:17 Matt Rose:** All right. Agreed. **38:18 Chris Romeo:** I think it's time for the— we have a new sponsor of the lightning round. It's Robert's Lightning Round, sponsored by Robert. All right. So, we have 3 questions that we ask. The first one's the controversial one. What's your most controversial opinion on application security, and why do you hold this view? **38:39 Matt Rose:** People attach themselves to words, and Use them ad nauseam. Uh, the one, the shift left, we already touched on. My other favorite one was agile. Oh, we're agile DevOps. We're agile in, in our development, you know, and people just say it. I'm like, what are we talking about? Agile in what way? Are you like flexible or you just release a lot? Uh, the new term that is all over the place is posture. You know, everybody has really posture. You remember, you kid, you had the scoliosis test and see if your posture was good. That's what we're doing right now. Everyone's, we're checking everybody's scoliosis. Um, so it's these buzzwords. So it went from shift left to agile, now it's posture, and who knows what the next one's going to be? Because all of a sudden you just have 30 different flavors of posture. **39:22 Chris Romeo:** Let me, uh, let me interject this really quick story, uh, in regards to agile. So, uh, when I was at Cisco, agile was just becoming like a really big thing and it was so popular. And being part of the central security team, we were responsible for the secure development lifecycle and how does it adapt into various methodologies. And so I would go around and people would be like, oh yeah, we're using agile. I'd be like, oh yeah, cool. What does that mean? And every definition was, got different definitions from people. And, and it was just, it was a very, it was a very funny response because everybody thought they knew what it meant inside the same company. And they were all using different definitions and different words and different things. There was no standard to it. So that's, I I've seen that as well, Matt. **40:07 Matt Rose:** Yeah, it's— people just want to sound smart. **40:13** So. **40:13 Chris Romeo:** Absolutely. The second question is, what would it say if you could display a single message on a billboard at the RSA or Black Hat conference? **40:22 Matt Rose:** Is your AI real? So thinking about it that way, I know for a fact people market themselves, like a lot of startups will basically say, Hey, we've AI to vet this. Um, and, uh, you know, it's not really AI, it's artificial individuals in a back room poring over stuff and they're like, look at the magical AI did this. You know, this is like the Wizard of Oz, the man behind the curtain. So I would say is, you know, do the sniff test on your AI. Is it true AI or is it an artificial individual that is, you know, pretending to be the Wizard of Oz? **40:58 Chris Romeo:** Yeah. My, my My favorite question to ask companies now when, when I'll be evaluating a company that'll come and be looking for investment or something, you know, say, oh yeah, we're using AI. I'm like, oh really? What, what LLM, what model are you using? Well, we're using, uh, this one from OpenAI. Oh yeah. ChatGPT. You mean that one? Oh, okay. The one that's not proprietary to anything you're doing and really doesn't add any value to your company or to your, your, your total worth of, you know, what the, what the total amount the company's going to be worth in the future. So that's my favorite question to ask people is what model are you using? Because people aren't doing things from a proprietary nature. And if it's not proprietary, it doesn't add any value to the company. Yes, it might have a flashy feature or something, but if you're using ChatGPT to do it, just, I mean, I could do the same thing. You're training ChatGPT so that I can plug into it later and get the same, build the same feature for my platform. **41:51 Matt Rose:** Yep. All right. **41:54 Chris Romeo:** And our 3rd question is, uh, what's your top book recommendation and why do you find it valuable? **42:01 Matt Rose:** Well, a little nepotism here. It's Derek Fisher's The Application Security Program Handbook. I'm good friends with Derek, and he asked me to write the foreword on it. And everyone that I've talked to that has read it has really enjoyed the book. So I'd really push from a technology book is that Application Security Handbook, or Application Security Program Handbook, and I think it's by Manning. **42:26** Publishers. **42:27 Chris Romeo:** Derek's a friend of the show, so we've had, he's, he's done a couple, couple episodes with us before. So we actually— **42:32 Matt Rose:** Derek and I have done a bunch of stuff. He's a great guy. **42:34 Chris Romeo:** Yeah, we did the first episode after the book came out. Like the first one, first podcast he did just happened to be, we happened to have scheduled it. And so we got a chance to, to take a look at the book right when it first came out. So yeah, great book as well. Highly recommend it for people that are trying to understand the AppSec program and the way all the pieces go together. Good stuff. **42:52 Matt Rose:** For personal books, I mean, I love Stephen A. Ambrose's stuff about World War II and Mark Frost's about sports. So those are 2 other authors that people are into World War II stuff or sports type stories about golf and baseball. Those are 2 authors I'd look at. **43:07 Chris Romeo:** Very cool. Very cool. Well, Matt, we've come to the, to the end of our conversation here. And so any key takeaways or call to actions that you would like to leave our audience with? Some homework perhaps? **43:23 Matt Rose:** I think the biggest thing is people have to change the way they perceive or want to learn about technology. Um, it's something that I'm very passionate about. And this is, I've been doing some posts on LinkedIn and things like that, some unofficial polls to say, we need to change the way we digest information. There's just too much of it. And I hear, I know a lot of people that have early stage startups and they're like, I just can't get traction. Nobody knows who I am. No, you know, it's like I, I just did this amazing 30-page white paper. I'm doing webinars each week with XYZ. And I'm like, are they the same old, same old? You got to stand out and be different. And you got to actually have a different approach to solving problems. And the biggest thing that I see people do is they talk a lot, and they don't listen very much. So as you're moving and navigating the software supply chain or application security world, do it in a way that you can find things that are of interest without having to, you know, commit to reading that 30-page paper. There's a lot of great people, like we mentioned Derek Fisher, and, you know, you mentioned Chris Hughes. I think the best way to learn is through LinkedIn and follow a group of people that are good influencers. They release great stuff, and it's really interesting, and you learn things kind of organically, not in a forced way. **44:34 Chris Romeo:** Yeah, good point. I know I learn a lot, and I've been around this business for a long time, and I'm still learning new things from following people like The folks you just described, like Derek and Chris and a lot of other people, uh, that just write stuff on LinkedIn. 'Cause it, it's, it's a good way to get a, there's some things that I learned that I just didn't know that I needed to learn them or I was going to learn them today because they're not something I was searching out for. But I happened to see like Chris Hughes write something and I read it and I'm like, oh, very cool. Like this is a, this is something I didn't know before. Uh, and now I have a better understanding of it and it helps to just make me a well-rounded security professional. **45:13 Matt Rose:** Yeah, I look at it too. It's a good way to validate, you know, we all have epiphanies every day, usually over, I don't know, coffee or cereal or a sandwich. And then you have this epiphany and then to see somebody have that same epiphany that you respect, it's a good way to kind of do that validation within yourself. Because a lot of these things I read, I'm like, yep, I agree with that 100%. Or that's a different take. Maybe I should reassess the way I'd like to approach that. I think it's a crowdsourcing way to To learn things. **45:42 Chris Romeo:** Definitely. **45:42 Matt Rose:** Cool. **45:42 Chris Romeo:** Well, Matt, thanks for, uh, for being a guest here on the Application Security Podcast. We look forward to having you back for a future conversation about something else, and maybe we'll let you get a chance to even draw on your board more. Um, I wish I had the ability to draw on boards like that. I do think I've tried in the past many years ago, and I just, it just doesn't compute with the way my brain works. But, uh, so I love to, I love to see graphics and visualization. So yeah, all good stuff. **46:08 Matt Rose:** Awesome. **46:08 Chris Romeo:** And we'll, uh, we'll look forward to, to talking to you again in the future. **46:11 Matt Rose:** Well, thanks for having me, guys. --- Source: https://appsecpodcast.com/matt-rose-software-supply-chain-security-means-many-different-things-to-different-people/