Skip to content
AppSec PodcastThe Application Security Podcast — home
27 min

Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer

With Ofer Maor

Security TestingVulnerabilities and Exploits

Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 13 chapters
  1. 00:00From penetration testing to AppSec with Ofer MaorAudio
  2. 01:08Ofer’s security origin storyAudio
  3. 03:04Why secure development is hardAudio
  4. 03:46Culture and risk managementAudio
  5. 06:30Balancing offensive and defensive workAudio

About this episode

Finding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications. Ofer Maor shares his transition from penetration testing into application security and the lessons he learned through security startups. He and Chris discuss culture, genuine risk management, and the industry’s attraction to offensive work. They explore delivering findings inside developers’ tools, the limits of dumping issues into a backlog, and the roles of interactive testing and runtime protection. Ofer explains how compensating controls can buy time without replacing the need to fix code. The episode closes with his OWASP involvement and board candidacy at the time of recording, connecting technical progress with the community needed to support it.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Ofer Maor:
Ofer Maor on LinkedIn

Resources
OWASP Israel community
OWASP Top 10

Actionable

From this conversation

  1. Run security checks in the IDE and after integration

    We need to get as much as we can early on in the IDE, but we need to do things that can happen later in the build as you integrate all the pieces together.

    13:39
  2. Make security findings actionable

    Part of the challenge we have to go through is getting results that are far more actionable.

    14:43
  3. Use layered protections while planning fixes

    Security needs to come in layers.

    20:56
Transcript · 27 min conversation

0:00Chris RomeoHey folks, season 4, episode 6 of the AppSec Podcast. On this episode, I'm joined by Ofer Meir, and Ofer tells us about his journey as a pentester transitioning into the world of application security, and also some of the experiences he had in working in various startups. Ofer's also running for the OWASP Board of Directors, and so we're happy to, uh, help him get the word out about his candidacy. Hope you enjoy.

0:32Robert HurlbutThe Application Security Podcast. Here we go.

0:58Chris RomeoHey folks, welcome to the AppSec Podcast, coming to you live from a room overlooking Westminster Abbey.

1:05Ofer MaorAbbey.

1:05Robert HurlbutAbbey, thank you.

1:06Chris RomeoI think I was struggling with that a little bit early.

1:08Robert HurlbutUm, you just heard Ofer, who is my guest in this interview. And, uh, Ofer, would you just tell the audience what is your security origin story? If there was a comic book What would episode 1 describe in your security life?

1:23Ofer MaorSo I've been doing security for over 20 years now, which I still can't believe myself. I started security while I was in the military. Okay. Did a bunch of IT stuff and started rolling into security and found it interesting, and so I stuck. And just after leaving the military, I joined a small security company that was in 2000, and I started doing application security pentesting when it was really just new.

1:52Robert HurlbutWow.

1:53Ofer MaorIt was a great time. We invented tons of new techniques and did a lot of stuff, and everything then was so easily hackable. And I think it's—

2:02Robert HurlbutI think it's easy now, right? Like, remember back in 2000?

2:05Ofer MaorIf, if I knew in 2000 all the things I know now, I could have done even much more.

2:11Robert HurlbutIsn't it funny how SQL injection still exists?

2:14Ofer MaorIt's amazing. I mean, it was amazing back then. It's amazing. It's 18 years gone and it's still almost the same.

2:21Robert HurlbutWe're still solving the same problems. So yeah. So then, so you're at the pen testing company and then where'd you go from there?

2:27Ofer MaorSo I joined Imperva in its early days. It was a good ride. Saw how hard doing a WAF is. And then I started my own pen testing company later.

2:40Robert HurlbutOkay.

2:40Ofer MaorCalled Hactix. Was a good run. We did it for a few years and then we sold it and spun off another company from that called Seeker.

2:48Robert HurlbutOkay.

2:49Ofer MaorAnd that was later acquired by Synopsys, which is where I am today.

2:52Robert HurlbutOkay.

2:53Ofer MaorSo I've had the chance of pretty much doing every side of this, attack, defense, secure development, penetration testing tools, penetration testing services. It's been a good ride.

3:04Chris RomeoYeah.

3:04Robert HurlbutSo what's the hardest Out of that list you just had of offense, defense, secure development, what do you think is the hardest part of that stack?

3:14Ofer MaorThe hardest part of that stack is getting development to be on board. All the rest is just different types of technologies. They're all hard because software is so complex and changing. It's not like networking, right? Firewalls came, Pretty simple. I mean, sure, there's a lot of technology there, but there's protocols, there's clear definitions. All the attempts to automate things in software are just much harder because there's a new way to do something in software every hour. Yeah.

3:46Robert HurlbutSo do you see this as a people problem then?

3:48Ofer MaorI, I think the hardest part is the people problem. There's a lot of problems, there's a lot of technology, but I think at the end of the day, and this is what I've always been telling We can come up with a lot of technologies, but at the end of the day, security problems are bugs in the code, and the only people that can fix them are the developers, and they have to be on board on doing that. And that is still a huge challenge in— and I'm gonna make up statistics here— 95% of the customers.

4:19Robert HurlbutYeah, no, that's my experience as well, is it's— this is a culture. problem first. When you get to the point where a security culture where developers understand why they need to care about this stuff, it just changes their whole perspective on when you ask them to do something. Right now we have this bad habit of we just hand them a static analysis report and there's 20,000 entries in that static analysis report and they look at it and they go, what am I supposed to do with this? Paper my kid's room at home?

4:48Ofer MaorYeah.

4:49Robert HurlbutAnd they throw it in the recycling bin. instead of we giving them one sheet of paper that has 3 issues where they can then go, oh, this looks like something I can actually do something with. So yeah, people problem.

4:58Ofer MaorSo, and I would say the other side of people problem is also on our side, on the security side. A lot of the people in security, as they come from a very technical background, they tend to see things in a very technical way. Oh, there's a vulnerability, you can hack that, and that's hackable. It's a black and white sort of thing. But the reality is businesses don't run in black and white. Businesses run on risk management.

5:23Robert HurlbutYep.

5:23Ofer MaorAnd security is just another risk. For us, sometimes it seems like this is the risk, but for the company, there's a lot of risk. Fixing security vulnerabilities slows down the business. That's a financial risk for the business. Not fixing introduces security risks. It's another risk. And we have to be smart about giving them enough data to know how much of a risk this is, not in a black and white sort of, yes, it can be hacked, yeah, but how likely it is, what value does it bring, and where—

5:55Robert HurlbutDo you think most security professionals, do you think they have that perspective of risk management, of true risk management?

6:00Ofer MaorUnfortunately, no. There are people that have it, but a lot of people don't. And you have to remember, security is a very young field compared to a lot of other fields. And it's been very hyped in the last 5, 6 years. So we have a lot of newcomers, and they learn all the technical stuff because that's what you're first of all expected to learn. But getting that maturity view of risk and understanding risk, that takes a longer path. I used to do the same mistakes too, 10 years ago, right?

6:29Robert HurlbutYep.

6:29Ofer MaorIt takes time.

6:30Robert HurlbutYeah, and I'm gonna go on record and make a lot of people mad here, but I think we put too much emphasis on offensive as an industry. versus defensive and the secure development things that you talked about there. And everybody wants to hack things. They want to be a pen tester. You know, all these— I talk to lots of different kids, as you probably do, coming out of college. And what does everybody want to do? I want to hack the planet, right? That's their goal. And it's like, we only need so many people that are truly offensive, and that's already a pretty full field.

6:59Ofer MaorBut it's cool. So I had a pen testing company, right? It was the coolest part of my career. I spent You know, every week I went and gave another lecture demoing cool stuff. We used to do, when we did Pentest, we used to record a video of the exploit we created. You go to a customer meeting, it's cool, right?

7:18Chris RomeoYeah.

7:18Ofer MaorBuilding secure development methodology is not cool. So that's part of one of the things that we have to deal with. But I agree with you, we need to help and enable developers to build secure code. This is the only way we're going to beat this problem and bring the risk to an acceptable level.

7:37Robert HurlbutYeah, because if we're sitting here in 20 more years and SQL injection is still number 1 on the— if the OWASP Top 10 still exists in 10 years or 20 years, like, what are we gonna— like, is that even gonna be a good thing? I don't think so. And so, yeah, SQL injection has got to be the way that we— we have to put that away. We have to put it behind us and I don't know, hopefully you and I are here in 20 more years at AppSecEU hanging out and we've got it all, all these things are figured out and we can all just get together and have a party.

8:06Ofer MaorYeah, I'm doubtful, but hopefully when we sit here in 20 years, we will be dealing with new problems instead of old problems.

8:16Robert HurlbutWe can only hope it's new problems and not the same ones that we have now. At least CSRF went away. From 2013 to 2017, so a little bit of progress has been made here in the world of AppSec.

8:29Ofer MaorYeah, it's, it's not clear though if it really went away or it just didn't make the cut.

8:36Robert HurlbutWell, they went— they, they, they got much more data-driven in 2017 and they started looking at— so it may have been that 2013 CSIRF was more of a feeling. I got a feeling this is kind of a bigger problem, but But then 2017, the numbers didn't really back it up. I think it fell to 12 or 13. I mean, it was, it's still not out of the whole realm. So, but yeah, that's definitely good to know. And I understand you're passionate about the challenges of software security testing and high speeds. Let's talk about that. So what are the challenges then of high-speed software security testing?

9:12Ofer MaorSo when you look at software security testing, the way it's been done over the last decade or 2, it's been a security-driven process that comes at some place during the development lifecycle, usually 2 weeks before it has to go to production, which is way too late. In more mature organizations, it comes earlier, sometimes in the QA phase. But what happens is the R&D delivers a sort of a version, the security team tests it, whether it's a static analysis or an external pen test, it doesn't even matter what the technology is, but it takes some time. Usually if it's a static analysis, they'll go through some false positive weeding and things like that. And then they deliver back PDF reports to the developers, which now go about fixing everything or the high-end critical or whatever the corporate policy is.

10:07Robert HurlbutOr nothing.

10:07Ofer MaorOr nothing, yeah. But this process, it's not great, but it's sort of working. But it's working when you have slow-paced development, when you launch a version or go to production once in 3 or 6 months. But as we look into faster development, this is becoming harder, right? So, you know, a few years ago everybody talked about Agile and Scrum and 3-week-long cycles, but now with CI and more importantly with CD, continuous continuous delivery, we're looking at organizations that are pushing on their cloud updates at the speed of hundreds a day, thousands a day sometimes. And in this world, the process I just described, it just doesn't work. It breaks. So there are different ways organizations are trying to go about it, but all of them that are trying to do what they did before, only faster, it just breaks. So they only test it every few cycles. So then you got a lot of stuff in production that hasn't been tested at all. Or they only test for the most critical vulnerabilities as part of the regular flow, so they don't get those, and then the later they do the rest. But we really need to shift the way we're working, right? Everybody talks about shift left.

11:26Robert HurlbutIt's the new cool thing here.

11:28Ofer MaorIt's the new cool thing, but, but But realistically, it is what we have to do, not because of the left. There is no more left in a CI/CD world. There's all, you know, this like infinity nice matrix, but it's about moving security testing as part of the continuous effort of the development team to building their software.

11:52Robert HurlbutSo what does that look like then? How do we make that— so that sounds like a good thing, sounds like a great principle that we should follow, but how do we make that actionable for people?

12:03Ofer MaorSo we need new technologies and we need technologies that are much more streamlined into whatever the developers are doing anyway. So it comes in a few forms. First of all, anything that does a test that works for hours or even half an hour that's already bad. It needs to be something that happens in the background as you code, as you test, whatever you do. And it needs to be something that gives you the results as part of the developer workflow, right? If I want the developer to look at a PDF report or another UI, it's gone.

12:41Robert HurlbutYep.

12:42Ofer MaorIt has to be something that's completely streamlined. So part of the things I'm working on are things where we are bringing for instance, static analysis to be something that works like a spell checker in your IDE and gives you the results in a bar in your IDE, right? Because that's in your development workflow.

13:01Robert HurlbutAnd yeah, that's something I've been preaching quite heavily is static analysis has been broken forever in the idea of— and I was at Cisco for 10 years. We had static analysis. I'm sure they still do. But it was static analysis of nightly builds. And you want to know how big of a pain in the neck that is to actually work with? It's almost impossible. Static analysis belongs in the IDE, just like you said with the spell checker. I should be coding along, and I do something, and bing, pops up a little thing that says, I don't know if you really want to do that. And maybe it's the 2001 kind of message that pops up and tells you, I don't think so.

13:39Ofer MaorI see you're trying to write a SQL injection. Do you need help with that? Yeah, but really what we're— so, but there is another side of that, right? We all want it to be like a spell checker, but the reality is that static analysis is a complex technology and not everything can be done with a spell checker. So we need to find the right balance. We need to get as much as we can early on in the IDE, but we also need to do things that can happen later in the build as you integrate all the pieces together.

14:09Chris RomeoSure.

14:11Ofer MaorI want to feed that back to the developer. So when he opens the code the next morning and, you know, it ran in the build, it still shows up on his IDE that this is the problem that they found yesterday. I used to preach for JIRA integration.

14:25Robert HurlbutYep.

14:26Ofer MaorBut this is— I mean, JIRA integration is last year's, and it's still good in some cases, of course, but I really want to see it in the IDE. I really want to see it as I code.

14:36Robert HurlbutYeah, I mean, and sometimes with JIRA integration too, you can end up, you You drop 10,000 JIRA defects or something and it's like, what are we gonna do with this?

14:43Ofer MaorBut that's a different story. Part of the challenge is that, and I work for a vendor today, right? But part of the challenge we have to go through is getting results that are far more actionable.

14:54Robert HurlbutYeah.

14:55Ofer MaorRight?

14:55Robert HurlbutYeah, we tend as an industry to value quantity over quality. Like, and I, the last time I evaluated tools was a few years ago And there was still a quantity over quality kind of a metric. And me personally, I don't really care about the quantity. I want that one-page version because I know developers, I work with developers all the time. You give them anything more than the one-page version, they're gonna just look at you and say, no thanks.

15:23Ofer MaorSo it's an interesting discussion. So when I started my product company, I had your approach. I just want to show them the really highest critical exploitable vulnerabilities. But what we found out as we went to customers is some customers appreciate it, others feel like, but why aren't you showing me all that stuff that was out there?

15:45Robert HurlbutThey want their money's worth.

15:45Ofer MaorIt's like, oh, we did a benchmark between you and 2 more products and, you know, they found more stuff. Yeah, of course they found more stuff. I'm trying not to overflow you, but the market has its, you know, its own needs and not all the security experts always think the same. And so—

16:02Chris RomeoTrue.

16:02Ofer MaorWe need to be able to give the customer the right way to tune that so we can find everything, but we can prioritize it correctly. And then, you know, as a customer, you can have this bar, sliding bar and say, oh, I just want the really exploitable ones or show me everything or show me something in the middle. And this is an area where we have to work too.

16:25Chris RomeoAfter the break, Ofer addresses IAST and how it fits into the developer flow. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Ofer's been talking about developers and security. Now he picks up with a discussion about IAST and how that fits in with the developer.

17:05Ofer MaorSo the other, the other part, which is obviously very close to my heart because it's what I've been doing for a lot of time, is what we call IAST, or Interactive Application Security Testing. But essentially dynamic testing that happens again in the background. So we don't wanna have a dedicated testing window and launching tons of requests and occupying a test server. We want something that sits on the server and analyzes the application as it's running.

17:35Robert HurlbutYep.

17:35Ofer MaorAnd finding vulnerabilities. And this is becoming ever more so important with more and more customers moving away from the whole notion of a test environment or a testing window. What we see is that a lot of these CD shops, they just do a very intense A/B or A/B/C/D testing.

17:55Robert HurlbutYeah.

17:56Ofer MaorWhere there's just one environment that has a lot of instances and every new feature gets rolled out to maybe one server at first with a very small portion of internal employees being routed to that. And then it slowly propagates. And there is no more room for a dedicated test automation window and things like that. And so we need to adapt again our technologies to support that. It has to be something that happens in the background, that happens as we go. And then once we have that, once we have static analysis and dynamic analysis that are fully streamlined into your workflow, We can still add the deeper analysis, a full pen test and things like that, that come at certain intervals to make sure we haven't missed anything or, well, not anything, but to further find things that may have slipped through the cracks, but we still get the majority and the core of the things through that.

18:54Robert HurlbutYeah, and so I'm also a big proponent of IAST and RASP and using these server-side technologies to be able to detect things. My fear, and I've started to hear some people that are going in this direction, is it's the firewall of the days of old where it's like, oh, we have a firewall, so we don't need to worry about SQL injection. Or, you know, in the days of old is we don't have to worry about that because we have a firewall. Well, if you do the same mentality with IAST and RASP, you're going to be in trouble. Like, I don't want my RASP to be the first line of defense against SQL injection. I want it to be the last where it saves my butt at the last second, and then I can trace back and figure out what else did I miss or where did my process break down. I don't know if you're seeing the same or if you've heard any of those same type of grumblings.

19:40Ofer MaorSo it's, it's of course a challenge, but I want to go one step back. I think there's a lot of confusion in the market, in the industry between IAST and RASP. They are often put in the same bucket. because they use fundamentally the same core analysis, which is instrumentation, but they're really very different technologies. They're very different solutions because IAST is a testing solution and RASP is a protection.

20:09Chris RomeoYep.

20:09Ofer MaorAnd so it's like saying DAST and WAF are the same thing because they both look at HTTP requests and responses, right?

20:16Chris RomeoYep.

20:17Ofer MaorRASP is supposed to see attacks even when they go after maybe non-vulnerable places, whereas IAST looks at vulnerabilities. 2 different things. So IAST is in no way creating a problem because it's just another way of testing in order to fix things in your code. I do agree that in some places people say, oh, I have RASP, you know, I'm secure now, I don't need to fix, or I have time to fix. I think from a risk management perspective, it's fine to make a decision where if I have RASP, I can take more time to fix things.

20:56Robert HurlbutYep.

20:56Ofer MaorI think saying I have RASP, I don't need to fix things is a wrong approach. But, you know, there's always gonna be that. And it's the same with everything. It's the same with firewalls, the same with any protection. Does protection make fixing redundant? I don't think so. Security needs to come in layers.

21:15Robert HurlbutYeah, and I love the fact that you brought that back to the risk management side. Like, I wish our industry all had that perspective where— because it is ultimately always risk management. It's a business decision, everything we do in security. But we tend to think about, well, no, we're the security professionals and we're the answer to any of the problems. No, the business has to make the decision ultimately, and the security is someone who enables the business to make the possible decision, not the other way around.

21:44Ofer MaorYeah, and you know, let's say you, you know, you have 500 cross-site scripting in your application and your developers say, well, to fix that I need to not release new features for the next 3 weeks. That's not good. So say, okay, I'll put RASP and then I'll put it in the backlog to fix them over the next 4 months as we do other things. You know, that's a reasonable decision to make. Cross-site scripting, as long as, especially if it's reflected, is not that dramatic risk, and I have something to reduce it. It's fair enough. Yep.

22:18Robert HurlbutNo, that makes sense. Okay, let's, uh, let's transition and talk a little bit, a little bit about the world of OWASP since we're at AppSecEU in London here. And, uh, maybe you hear the bells ringing in the background. I mean, we're, we're down, we're down in central London right now. And, uh, so So I understand you have some type of an announcement that you're gonna make here about your involvement in the OWASP universe. What does that look like?

22:40Ofer MaorSo I've been involved in OWASP for the past 15 years, pretty much ever since it started. I've done a bunch of roles. I was the chapter leader of Israel, I was part of the global committees when they were still intact, and now I've decided to run for the OWASP board in the upcoming elections.

22:58Robert HurlbutOkay, and when is that election gonna be?

23:00Ofer MaorIt's gonna be in the fall. They're gonna release calendar next week, and then we'll see exactly when the elections are. But generally, OWASP switches half of its board every year. So 4 people one year, 3 the other. This year is going to be 3 spots, I think. And so I will run. Okay.

23:19Robert HurlbutAnd you've had some involvement with the OWASP Israel— is it OWASP Tel Aviv is the chapter, or is it OWASP Israel?

23:27Ofer MaorIt's OWASP Israel. So Israel is geographically a pretty small country. You can drive from Tel Aviv to anywhere in Israel within 4 hours, and every— the majority of the population lives within 2 hours of Tel Aviv. So we figured it doesn't make sense to have more than one chapter in Israel.

23:44Robert HurlbutOkay.

23:44Ofer MaorSo I was the chapter leader for OWASP Israel for a lot of years. I've helped build the community. OWASP Israel is very community-oriented. We don't A lot of the people that participate and come to our events and meetings are not necessarily paying members, but our annual conference brings over 600 people every year.

24:05Chris RomeoYeah.

24:06Ofer MaorWhich is one of the largest regional events. We have over 1,200 people on our mailing list. It's a very active chapter. It's been good for many years. I've done that for a few years. I stepped down. I feel like there's room for change. Just like the board now is limited for 4 years. So I'm still helping the OSPA Israel chapter, but there are new people doing things.

24:32Robert HurlbutYeah, and I think that's a, that's a good approach to— it's all about succession leadership all the time in everything that we do. How do we bring in new people that'll push things, push more boundaries than we do in our role in something right now?

24:45Ofer MaorExactly.

24:46Robert HurlbutAnd there was, I know there was a little bit of, there was an issue with the AppSec EU conference, as far as it was supposed to be in Israel and, and for this year it got moved to London. I heard there was some good news that came out of some of the proceedings here at EU right now as far as things in the future. Do you have any insight on that?

25:06Ofer MaorYeah, so I, I was at the board meeting yesterday. There's been a decision going forward to change this whole notion of just AppSec EU or AppSec US. We want to have more global events.

25:20Robert HurlbutOkay.

25:21Ofer MaorAnd with less strong regional tie. In any case, starting next year, there will be at least 3, striving to 4 global events every year. And one of them next year will be in Tel Aviv instead of this year. There were some misunderstandings along the way, there were some problems, but we're putting all that behind us and we'll have a great event and Everybody's invited to come. It'll be beautiful weather and it will be by the beach. Aha!

25:48Robert HurlbutWell, that's— you already got my attention there, and I'll be sure to submit something for the CFP just for the fact that to be a part of that event, kind of as OWASP expands here into more, even more global events, I think that's awesome. Thanks for being with us to share your perspectives on the challenges of testing, and we wish you good luck in your run for the board seat here year. You're a front-runner in my mind right now. So thank you for taking the time and sharing with our audience.

26:14Ofer MaorWe really appreciate it. Thank you for having me. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

4,716 words · transcript by assemblyai

More on Vulnerabilities and Exploits

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.