Tanya Janca -- Secure Guardrails
With Tanya Janca
Secure DevelopmentSecurity TestingCloud and InfrastructurePrivacy and Compliance
Tanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security. Tanya is an award-winning public speaker and head of education at SEMGREP and the best-selling author of ‘Alice and Bob Learn Application Security’.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 22 chapters
- 00:00Meet Tanya Janca: Secure GuardrailsAudioVideo ↗
- 05:09Oh, that's so cool. So what, what are you excited aboutAudioVideo ↗
- 06:49Oh, that's great. That's, yeah, it's a, that's a fun thingAudioVideo ↗
- 10:05I was like, no, no, I'm good. And it was likeAudioVideo ↗
- 12:05So based on the example that you just shared there, NowAudioVideo ↗
- 15:55Would you like to use the wrapper libraryAudioVideo ↗
- 17:36Am I willing to break the buildAudioVideo ↗
- 19:41Oh, actually, you know whatAudioVideo ↗
- 22:39What's the role of making it easy with the paved roadAudioVideo ↗
- 24:58RightAudioVideo ↗
- 26:53Makes sense. Makes sense. That's, that's, uh, it's helpful just toAudioVideo ↗
- 30:18I have to go rotate the secret, yada, yada, yada, rightAudioVideo ↗
- 32:58Like, because getting into buildings when you should not is aAudioVideo ↗
- 34:18No, no, it's good. It's good. So I guess one moreAudioVideo ↗
- 37:48Someone else told me she did that and it said, thisAudioVideo ↗
- 40:19All right. One more guardrail topic. And this is one thatAudioVideo ↗
- 43:05RightAudioVideo ↗
- 46:24It's time for her to come back again. She has beenAudioVideo ↗
- 47:38NoAudioVideo ↗
- 50:13We've all gotten those though for, for plenty of times inAudioVideo ↗
- 53:34Um, and so then we talked about it and I'm likeAudioVideo ↗
- 57:14So I'm going to do the top programming frameworks as wellAudioVideo ↗
About this episode
Tanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security. Tanya is an award-winning public speaker and head of education at SEMGREP and the best-selling author of ‘Alice and Bob Learn Application Security’. Tanya shares her insights on creating secure software and teaching developers in this episode. Tanya Jenka, also known as She Hacks Purple, is the bestselling author of Alice and Bob Learn Application Security. She’s also the head of education and community at Semgrep, sharing content and training around teaching everyone to create secure software. Tanya’s been coding and working in IT for over 25 years.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
→ Learn more about Security Journey
Connect with Tanya Janca:
→ Tanya Janca on LinkedIn
→ Alice and Bob Learn Application Security
Resources
→ Alice and Bob Learn Application Security
→ Semgrep
→ Tanya Janca – What Secure Coding Really Means
→ The Expanse Series
→ Alice and Bob Learn Application Security
→ Tanya Janca (SheHacksPurple)
→ Azure DevOps
→ Microsoft Security Response Center (MSRC)
→ Microsoft Defender for Cloud
→ Content-Security-Policy (MDN)
→ Scott Helme
→ Kim Wuyts
→ Executive Order 14028
→ OWASP SAMM
Actionable
From this conversation
- 8:37
Use technical controls to redirect unsafe work
To me, a secure guardrail is some technical implementation that tries to get you— it tells you, hey, you're not doing what you should do from a security perspective.
- 9:23
Make secure defaults the easiest option
We try to make it a default in every opportunity so that it's easiest to do the thing we want you to do.
- 14:15
Block likely secrets from being committed
To be quite frank, if it looks like a secret, I'd like it to be in blocking mode, period, right?
Transcript · 1 hr 5 min conversation
0:00Chris RomeoTanya Jenka, also known as She Hacks Purple, is the bestselling author of Alice and Bob Learn Application Security. She's also the head of education and community at Semgrep, sharing content and training around teaching everyone to create secure software. Tanya's been coding and working in IT for over 25 years. She's won countless awards and has been everywhere from public service to tech giants, writing software, leading communities, founding companies, and securing all the things. She's an award-winning public speaker, an active blogger, and has delivered hundreds of talks on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives. Tanya joins us to discuss secure guardrails, the difference between guardrails and paved roads, creating secure guardrails, and we even unpack whether there's such a thing as a privacy guardrail.
0:54Robert HurlbutThe Application Security Podcast is brought to you by Security Journey.
0:58Tanya JancaWe help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
1:05Robert HurlbutLearn more at securityjourney.com.
1:06Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of Devichi, a general partner at Curve Ventures. Normally, I'm joined by my good friend, Robert Horvath, Robert was having some connectivity issues. I'm convinced he was trying to connect to this recording via a 2400 baud modem, and he just didn't have the settings right. For those people that remember, he had 7. I don't remember what the other option was. N zero. I don't remember what the N stood for, what you could change it to. But those that have been around a long time will get that joke. And if you ever used a modem and you made the settings wrong, super excited to have Tanya Jenkins, very well known. Across our industry here. And I did a little bit of calculating. This is Tanya's 4th appearance on the podcast, and that ties her with Jim Manico for most appearances. And she and Jim are, are one below the first place, Adam Szostak, who has made 5 appearances on the Application Security Podcast. But if you want to catch any of those other episodes that Tanya did with us over in the past, There was an episode on hacking APIs with DevSwap. There was another one on DevSwap, the movement. And then in October of '23, we talked about what secure coding really means. So if you want to go back and check out any of those, feel free to tap into all of the things we've talked about in the past, and you'll hear Tanya's origin story way back in that 2017 episode. So instead of an origin story, Tanya, I'm trying to reach out to the kind of lighter side of application security. And I want to encourage people to go outside. So what are your hobbies that you like to do that do not include technology?
3:02Robert HurlbutSo in 2022, I bought a hobby farm. And so before that, I was really obsessed with gardening. And I had dug up my front lawn and my back lawn, And made 17 raised beds with my significant other. And then we built 2 greenhouses together and it was like, there's no space left on any of the property at all that we're not growing something.
3:30Tanya JancaSo I was like, I think it's time to get some acres. And so, um, we have 3 really big greenhouses and we just bought a 4th one. And as I was telling you before we started recording, a very exciting gardening or farming milestone? We bought our first tractor.
3:48Robert HurlbutOh yeah, it's used and it's old and I have to learn to drive manual, but you're going to see cute pictures of me with a straw hat on it starting very soon.
3:57Chris RomeoOh, that's great. That's, uh, I also recently, I wouldn't say that I've gone down the farming route yet, but have bought some property and in the process of Spending a lot more time outside. So that's, I think there's a, there's a kind of an angle for all of us in technology here. You got to find something to do outside. You got to put the computer down. And I think I've said this before, but I'm going to say it again. When I hear about people that work in front of a computer for 8 hours a day, and then they switch to another computer to play games for 8 more hours, it's like, people, let's go outside. There's got to be something to do outside.
4:36Tanya JancaI have an Oura ring and it's, it measures my stress and it's really funny, Chris.
4:42Robert HurlbutSo I remember the first couple of times I saw it, I thought it was broken, but when I go into my garden, the stress meter, it's literally so low it can't measure any. Like it goes, it completely goes off the chart.
4:57Tanya JancaThere's no measurable stress.
4:58Robert HurlbutIt's like, you're so zen. And sometimes it's like, you're really zen right now. Keep that up.
5:03Tanya JancaI'm like, no problem. Why did you have to alert me? Aura, shut up.
5:07Robert HurlbutI'm in my garden.
5:08Chris RomeoOh, that's so cool. So what, what are you excited about that you're growing for this year? So I mean, it's like something new maybe.
5:16Robert HurlbutSo last year, actually the year before I started growing dahlias, last year I started growing lilies. And this year my partner and I cleared away a bunch of extra trees. And so now I have a 50-foot by maybe 70-foot dahlia garden. So we're talking like thousands of dahlias.
5:38Tanya JancaSo last year people came, I planted them because I think they're pretty. And this lady said, hey, could I buy some? And I'm like, obviously those are for sale.
5:46Robert HurlbutAnd before I knew it, I'd made $2,000 from like just clipping the extra flowers. And I still like having some for myself and friends and stuff. And so this year we're actually exerting effort to that end.
5:58Tanya JancaAnd my first lily and my first dahlia bloomed right before I left. And so I suspect I'm going to get back from San Francisco and be just like in this explosion of flowers. And I didn't used to like flowers, Chris.
6:12Robert HurlbutI was like, you can't eat them. What are they good for? And then, and then one day, like, I, my friends started growing them.
6:18Tanya JancaI'm like, they are really pretty.
6:19Robert HurlbutLike, I get it.
6:20Tanya JancaAnd then I cut some flowers and I gave them to my neighbor and the look in her face of like utter joy and happiness. She's like, for me?
6:29Robert HurlbutI'm like, yeah, Diane. And she just like, her face just like crumbled with happiness.
6:34Tanya JancaAnd so I discovered you could just give flowers to almost anyone and they're really happy. I'm like, what? Like, I've been doing this my whole life. I really like flowers. It turns out I'm full middle-aged woman now. I drink Coke Zero too.
6:48Chris RomeoOh, that's great. That's, yeah, it's a, that's a fun thing to share there about. It's a way to lighten up somebody else's day just by thinking of them. And I think it's a bit of a metaphor for just the current state of the world. People don't exert kindness and niceness towards other people. Like, I feel like they used to when I was growing up. And a lot of times people were yelling at me for things I was doing when I was growing up, but It seems like it was a different era though, right? Where people were more friendly, they were nicer to each other. And I think the pandemic, we lost a little bit of that, but you're bringing a little bit of it back at a time just by bringing flowers to, uh, to people around your community and, uh, putting smiles on people's faces. That's really cool.
7:33Tanya JancaThank you.
7:34Chris RomeoWell, I guess we should talk about application security in some regard. I mean, this is almost turned into the The, uh, technology, the, the Technologists That Farm podcast is almost what we, we turned into here, which would've been, I think, pretty interesting. I would've listened to that if somebody ever created it. But okay, I guess the, the topic you wanted to, to chat about now, and it's one that I've been thinking about quite a bit as well, is this idea of secure guardrails. And so I thought we'd start with just, let's just define this. Let's work up a definition. I think most people have probably heard the term, but I've really not seen really great definitions laid out. I've seen people say, well, this is a secure guardrail, but not really give me a definition. So, let's start there.
8:19Robert HurlbutOkay.
8:21Tanya JancaSo, it started, well, basically, at SemRep, someone was like, yeah, secure default, a secure guardrail.
8:30Robert HurlbutAnd I was like, those are not the same thing. And they kind of looked at me because I felt very strongly about that.
8:37Tanya JancaAnd to me, a secure guardrail is some sort of technical implementation that tries to get you— it tells you, hey, you're not doing what you should do from a security perspective. Go back to the paved road. Go back to the secure default or whatever the secure coding policy is.
8:56Robert HurlbutGo back.
8:56Tanya JancaSo, you've done something you shouldn't have done, and it's some sort of alert, or maybe there's a red squiggly in your IDE, or maybe it's blocking you.
9:05Robert Hurlbutfrom checking in your code 'cause there's a secret in there, whatever the thing is, but basically something to the effect of, you've gone down the wrong path.
9:17Tanya JancaWhere a secure default is, this is what we would like you to do. This is the most secure way to do the thing.
9:23Robert HurlbutWe try to make it a default in every opportunity so that it's easiest to do the thing we want you to do. So, the first time I ran up against one of these was when I was at Microsoft and I was making— so, I was on your podcast at the time and I was making really terrible demos, like terribly insecure demos, so that I could show off what not to do. And then we would fix it together and then show them what you should do.
9:52Tanya JancaAnd so, I checked in a connection string and Azure DevOps was like, hey, That looks like a connection string you're trying to check in, and there's a secret in there, and I don't think so.
10:05Robert HurlbutAnd I was like, no, no, I'm good. And it was like, mm-mm, no. And, you know, Azure DevOps and I had a little argument, and then I said, I'm a dev, so I won, right? I'm like, you think a technical control can stop me?
10:16Tanya JancaAnd so I checked it in, and then my boss calls me and he's like, Tanya, Azure just called me and told me you checked a secret into production. And like, oh, I'm developer relations.
10:30Robert HurlbutAll I do is make demos.
10:31Tanya JancaI'm not allowed to touch production.
10:33Robert HurlbutBut yes, I did check a pretend secret into a demo database with nothing in it except 2 records that are for my demo.
10:42Tanya JancaAnd I have a firewall around it, et cetera.
10:44Robert HurlbutAnd I'm like, but yeah, I did that. And then he's like, oh, Azure's angry with you. That's really funny.
10:49Tanya JancaLike you're making demos and you got it all upset. And then, I had a beep on my phone, and then Microsoft Security Incident Response team called me. Yeah, and they didn't find it funny like me and my boss did, that Azure was upset with me.
11:05Robert HurlbutAnd the fact that I triggered a real security incident with my pretend demo secrets was not a way to make friends or influence people. And I had to spend some time kind of earning back some trust there.
11:19Tanya JancaBut, but I, but it alerted me, hey, you're not doing what you should do. You're going off-roading, right?
11:26Robert HurlbutAnd I was like, I know I'm doing that. I am comfortable doing that because this is intentional. It's a demonstration of what not to do.
11:33Tanya JancaThe secret doesn't actually go anywhere, et cetera. But if it had been a real secret and it had been a mistake, it would've been pretty helpful, right? And that we would've avoided a real security incident.
11:45Robert HurlbutSo, so the idea of a guardrail is just, hey, that's not what we're—
11:51Tanya Jancathat's not what we do here.
11:53Robert HurlbutWe think you should do this. And so any sort of technical control that does that, just the same as like what real physical guardrails do on a road, right? It's like, it's clear, if you're hitting a guardrail, you've got a problem.
12:04Chris RomeoOkay, so based on the example that you just shared there, Now I'm wondering, are there 2 different types of guardrails? Or should there be 2 different types of guardrails? And I'm just totally making this up on the fly. Is there, or should there be a guardrail that is non-bypassable? Meaning, should there have been a guardrail that you couldn't get around? Like, and then there's one that is a little bit more fluid, that a lot like is what you experienced with the Azure DevOps example. Where you, it said you shouldn't do this, but then you kind of had a way to get around it. Like, is there, so are there 2 different types then in your mind?
12:46Robert HurlbutOkay. So that's a good question. And no one's asked me that before. So I'm going to be annoying and pass the question back to you.
12:54Tanya JancaDo you think there's a technical control that can stop a really good software developer?
12:59Chris RomeoI think there's a technical control that can stop 99 out of 100. Really good software developers, not 100 out of 100, but I think, I think there's, and when I, 'cause when I think about this issue, I think with the guardrail, it's supposed to be designed in such a way that you can't, like it gives you freedom in the middle. Like you could, you can drive in the, in the, the lane, you can go into the other lane to pass people. You can even go on the shoulder. And do something a little bit crazier, but you can't go off the side of the mountain though. Like you're, it's keeping you there. And so now I'm starting to think like, is it, is it a guardrail then if you were able to bypass the control? That's, and I'm really literally just noodling this live here. This isn't something I've spent a lot of time thinking about.
13:53Tanya JancaSo a real guardrail, like on a road, you can drive through it. It in by accident, if you're, you know, high speeds getting hit, et cetera, or on purpose, which I would think would be extremely rare, right?
14:10Robert HurlbutBut I would say that certain things I want in blocking mode.
14:15Tanya JancaLike, to be quite frank, if it looks like a secret, I'd really like it to be in blocking mode, period, right? Because Azure DevOps did not stop me.
14:24Chris RomeoYeah.
14:25Tanya JancaAnd what if I was just, what if I was belligerent and it was a real secret?
14:30Robert HurlbutAnd I was like, listen, you know, this is due today. I just gotta do it.
14:33Tanya JancaI'll switch the secret later. Right?
14:35Robert HurlbutUm, one of the other devs on my team, she was livestreaming and she accidentally showed her secret to everyone while she was livestreaming just by accident.
14:45Tanya JancaAnd she's like, oh no. Uh, and so she rotated it live and, and then hid the new secret successfully, right?
14:52Robert HurlbutMm-hmm.
14:53Tanya JancaBut she's like, that was the longest 30 seconds of my career where it was like, oh gosh, I hope my audience are not jerks today and trying, trying to do something. Right. And so, um, and, and all of her followers, like nothing happened. Everything was fine.
15:09Robert HurlbutRight.
15:09Tanya JancaBut if you could block a secret, I think that's something you would wanna block for sure. But there's some things where I think it's less important.
15:18Robert HurlbutSo you might wanna have a guardrail.
15:20Chris RomeoYeah.
15:21Tanya JancaSo let's say you have a coding guideline and you want everyone to use camelCase. If someone doesn't use camelCase, are you going to make their whole day terrible and like, be like, no, I'm sorry, you can't go to, you can't check your code in? Is it worth it?
15:37Robert HurlbutAre we going to create a lot of friction with our software developers if we have hundreds of things, but maybe there's hundreds of like Warnings, I'd like to give them like maybe a little squiggly line that's like, hey, you're using innerHTML.
15:52Tanya JancaThat's not advisable unless you use this wrapper library.
15:55Robert HurlbutWould you like to use the wrapper library?
15:57Tanya JancaWink, wink, wink.
15:58Robert HurlbutSo either please don't use this function or use it with the wrapper.
16:02Tanya JancaWe're not seeing that combination we want to see, right? And then if the developer doesn't do it, does that issue an alert for the security team to talk to them? Are they not allowed to check in their code?
16:14Robert HurlbutI think that.
16:15Tanya JancaThe more times you block a developer, the less likely they're going to be friendly with the security team, especially if it's like something that's not the end of the world.
16:25Robert HurlbutSo innerHTML, for those listening, is—
16:27Tanya Jancait's often the cause of cross-site scripting when it, when it's used without really good input validation or sanitization or escaping and then output encoding.
16:38Robert HurlbutSo you can have a really bad day.
16:39Tanya JancaIf you use it without a wrapper library.
16:43Robert HurlbutAnd so, but, but if you're using a wrapper library that your AppSec team built for you, maybe you're having a great day, right? So, I feel, I feel like that would be something worth blocking on, but maybe there's a lot of other things where it's like, do I wanna pick a fight with a developer about this?
17:01Tanya JancaI don't know if it's worth it.
17:02Robert HurlbutSo, I would say some blocking, some not blocking. Mm-hmm. So, Quite often, definitely blocking secrets when you check in.
17:11Tanya JancaI would say if I have an IDE plugin from a SaaS, have like those red squigglies to tell you all the things I don't like, all my feelings.
17:19Robert HurlbutBut then when you go to check the code in, maybe the CI/CD is like, I'm gonna break on innerHTML, but I'm not, I don't care about camelCase.
17:28Tanya JancaMaybe there'll be an email later of your poor form. Like, why are all your variables terribly named? Or whatever, right?
17:35Robert HurlbutBut am I willing to break the build? I don't know.
17:38Chris RomeoI could see some of that being dependent on the organization type, the vertical. Like, I could see financial organizations being very stringent because they just tend to be more stringent with their policies when it comes to everything that they do. But because they're protecting our money from being transferred to somebody else's account, that's the culture that exists in those places, but it's based on the amount of risk that they have in running their business. And so I could see some of those kind of, I like that idea of blocking versus, I don't want to call them open guardrails, but non, maybe non-blocking, I think might've been the word you used, blocking versus non-blocking. So I think that's something that makes sense to have that amount of Control, because there's some things, like you said, that are non-negotiable and there's other things that are, that are, that can be negotiated. Okay. Paved roads. So you hear guardrails and paved roads, and I think Netflix was one of the organizations that popularized both of these terms. From your perspective, what's, what is a paved road then? And then what's the, what's the difference and, and how do they work together or do they oppose each other? How do you see these? Working.
18:58Tanya JancaI would, I would say a paved road, in my opinion, is the same thing as a secure default. So it's the path we would really like them to follow. So as an example, we want you to not use innerHTML, or let's say like the with statement in JavaScript. We're like, hey, it's kind of dangerous. We'd prefer you not use it, like just at all. I don't care if there's a wrapper library, we'd just really like it if you didn't. Okay. So every time we see that, maybe there's other functions that we would rather direct you to, or maybe we're just like, no way, Jose. So the paved road does not have the with statement in it.
19:41Robert HurlbutOh, actually, you know what?
19:41Tanya JancaLet me give you a better example. Let's say there's a function you'd really like them to use instead. Okay. So like the, um, Speaking of some secure coding lessons I gave recently, but let's say we really want you to use certain security headers. That's on the paved road. The paved road is we use these security headers here at this org. That's what we do. And so we see, oh, you don't have those security headers in this code. That's weird. You're not, you're, you're off-roading. You're not on the paved road. We'd really like you to use these.
20:13Robert HurlbutAnd, and we use them in this way.
20:15Tanya JancaLike, let's say there's pre-made settings.
20:17Robert HurlbutSo.
20:18Tanya JancaWhen I teach secure coding, I actually have like a cheat sheet with literally exactly what I would prefer that you, you do so that they can just turn it into a policy. Granted, I open it at their desk, copy paste mindlessly for everything other than Content Security Policy header, which is more complex, but I still want you to use it.
20:36Robert HurlbutBut so it's like, this is the paved road.
20:39Tanya JancaThis is the road we'd like you to go down, the one that includes security headers. And so It's a, the default is that we do use them.
20:47Robert HurlbutAnd if you're not using them, maybe you need an exception, right?
20:51Tanya JancaLike maybe you need a written exception as to why you are not using HSTS or whatever it is.
20:58Robert HurlbutAnd like, if you're not, there better be a good reason. You know what I mean? Okay.
21:03Tanya JancaI feel strongly about security headers. Anyway, the point is, I'm a little obsessed. We, we in Scott Helm, we like I already went on this topic a lot, but the paved road being that this is a path that the security team has specifically planned out for you. So there's lots of coding that you're going to do all day long that the security team, like, we want it to be secure, but we haven't thought it all out because it's not important to us because there's no security control involved and there's no known bad functions. There's no design flaw or threat that we're aware of. So just freestyle, do whatever you want.
21:41Robert HurlbutBut, you know, let's say you're doing authentication.
21:43Tanya JancaIt's like, this is how we do it here. This is how we manage sessions here.
21:47Robert HurlbutThis is, you know, we don't cache sensitive data and we always classify our data and we label our data.
21:53Tanya JancaSo you should darn well know when you cache stuff, if you're caching something sensitive, right? And so if you see a bunch of data that's not labeled in the database, problem.
22:04Chris RomeoRight?
22:04Tanya JancaAnd so, the idea of the, in my opinion, the paved road is like, this is stuff we've planned out for you that's the best way to do it for, and like, that's from the security team. I bet that there's lots of senior developers who have style guides and other things that they want to see, and stuff they've built, like functions and that, or classes, whatever, libraries that they really want everyone to use. And it doesn't have to do with security, it has to do with speed, it has to do with style, whatever it is, right?
22:33Robert HurlbutYeah.
22:33Tanya JancaBecause I've worked at lots of places like that. And so the paved road, the way we want you to go.
22:38Chris RomeoWhat's the role of making it easy with the paved road from your perspective? Like, and we could just use the, we continue on the headers example, but how do you make headers, do we even dare go, how do you make content security policy a paved road so that it's something that's How can you make it easier for developers? Because I swear there's only like 5 people that understand it total in the world. Apparently you and Scott are 2 of them. I don't know who the other 3 are. They should stand up and raise their hand. But how do you, how do you package that up and make it easier?
23:13Robert HurlbutOkay. So one thing is training, right? You and I both do or have done lots of training.
23:21Tanya JancaSo you teach everyone about it. So content security policy header. the Swiss Army knife of security, right?
23:29Robert HurlbutIt does so many things. But usually what I do specifically, so all the other headers do one thing. Content Security Policy header, it does a whole bunch of cool things.
23:40Tanya JancaAnd so I generally start with the cross-site scripting defenses, 'cause it does more than this. It's great. But that's what I start with, because cross-site scripting sucks.
23:50Robert HurlbutAnd so, and I would like everyone to have less of it. including malicious actors.
23:55Tanya JancaAnd so I start with that. So I'm like, Content Security Policy header, it's like an SBOM for your app, right? It's a list of all the scripts. It's just an SBOM for your scripts, right? Any third-party things that you're going to let load part of your app, you got to list them out. And I've had developers complain about it, like, oh, do you have to, do you have to like be organized about the app you built? Well, maybe that was be terrible. Yeah, like, of course, you know what's in there. We're just asking you to actually document it because they, they built it, right? Um, and so educating them, making something easy.
24:37Robert HurlbutSo giving them an example of it being implemented, being an example of exactly the way you would like it to be implemented, like each part of the feature, each setting that you would like by default. I'm literally making a PDF.
24:49Tanya JancaSo when I teach after, I'm like, here's the PDF checklist for logs, what to log, what not to log. Here's the checklist for this. Here's the checklist for that.
24:58Robert HurlbutRight?
24:58Tanya JancaSo make it literally mindless if you can, so they can copy and paste or print it out, put it at their desk or whatever.
25:04Robert HurlbutAnd then for content security policy header, so scaling it can be a pain if, if you have not kept track of any of that in all your legacy stuff, I would say starting with every new Having Content Security Policy header.
25:20Tanya JancaSo every new app has it.
25:21Robert HurlbutAnd then as you open up old apps, so maybe once a year you do a pen test, maybe that's when CSP starts happening and you just implement the one feature, like listing the scripts.
25:31Tanya JancaAnd then maybe eventually you talk about forms, et cetera.
25:33Robert HurlbutRight. And like roll out the features one at a time.
25:37Tanya JancaI feel, I think earlier you asked like, why do we have to make it easy?
25:43Robert HurlbutAnd the reason is because otherwise it ain't getting done.
25:46Tanya JancaRight.
25:47Robert HurlbutRight? If we make it really hard, if we make sure there's a ton of friction, and we don't care about the usability on the side of the software developer, like, we're competing, Chris, you and I, as security folks, we're competing, we're competing with customers asking for features, we're competing with their boss telling them, hey, there's this backlog of whatever tickets you got to go do, we're competing with, like, all these other, like, the usability, the UX people, all this stuff. Right?
26:14Tanya JancaAnd we're just one of their many priorities. They're our only priority. They're— I'm sure you've heard this before, but like, I feel, and lots of us AppSec feel, they're our customers.
26:26Robert HurlbutAnd we are trying to help them make more secure apps.
26:30Tanya JancaAnd if we have a ton of friction and slow their work down, and especially if we seem not nice or respectful, it's just, Would you want to work with someone like that?
26:41Robert HurlbutNo. Would you? Would you like— and you have like 6 different groups all telling you things they need you to do.
26:47Tanya JancaThat guy's gonna be last, in my opinion, in experience.
26:52Chris RomeoMakes sense. Makes sense. That's, that's, uh, it's helpful just to differentiate guardrails, paved roads, putting all these pieces together. So now, let's talk about creating a secure guardrail. And we'll have to use a different example. I feel like we've talked about headers. People are, people are like, probably thinking of all these headers. But how about, how about another example? Like, what, how would we create a secure guardrail for something else?
27:19Robert HurlbutOkay, so you need a technical control to try to alert or stop the developer from doing the thing.
27:32Tanya JancaSo, some options.
27:33Robert HurlbutSo I worked at a SaaS company, so I realize I'm very biased, but SAST works really well, but there's lots of SAST, so you don't have to use ours. You can just use any SAST that lets you write custom rules, which is a whole lot of them. So let's say you have a coding guideline and there's certain, just these functions are no-nos.
27:51Tanya JancaSo like eval or exec, we don't want you using those, let's say.
27:58Robert HurlbutWe certainly don't want you passing a variable to them.
28:02Tanya JancaThe variables change.
28:04Robert HurlbutAnd so we have a guardrail.
28:07Tanya JancaSo we write a custom rule that looks for this list of functions that we don't like, we the security team fear.
28:14Robert HurlbutAnd then it just alerts you, hey, we don't use those functions here.
28:19Tanya JancaIf you're not sure what to do, come talk to the security team or whatever. Sometimes it's that this is the old function and this is the new function.
28:28Robert HurlbutI have a bunch of those. I'm writing my next book and I have what to do in various languages, but then I have a what not to do. And so it's like, don't use this function, literally use that one.
28:39Tanya JancaDon't use this one, use that one. It's the new one.
28:42Robert HurlbutUm, and, and so that would be great, like just giving them the advice that says, hey, so we saw you're using this, we don't use this here. Instead, we would prefer, like it says in the secure coding guideline that you agreed to when you worked here, that we use this one instead.
28:58Tanya JancaAnd almost all developers are like, oh, yeah.
29:03Robert HurlbutYou know what I mean? They're not— a lot of them, they'll get the warning, you know, if they have time to look at it. If for some reason they don't, like maybe they'll miss it, but they look at it and it's like, don't use this one, use this one. It does the same thing, especially if it has the same parameters. Yeah.
29:18Tanya JancaIt's very easy to switch out. It's a really low bar to ask them to hop over versus some other things security asks for, like, hey, could you implement OAuth instead of SAML?
29:31Chris RomeoOr, you know what I mean?
29:32Tanya JancaLike, could you switch this framework? Could you update this whole framework? Is that a problem?
29:37Robert HurlbutYeah, it is.
29:38Tanya JancaThat's some work, right? So anything that you would like them to do, If you, like, from a technical perspective, if you can think of a way to find it.
29:50Robert HurlbutSo custom SAST rules is one.
29:54Tanya JancaWhen they check their codes in, their code in, doing a pre-commit hook for secrets or pre-commit hook for something that's very high priority, because pre-commit means it's not been saved yet.
30:06Robert HurlbutAnd the magic of that, so like, let's say Tanya's connection string.
30:10Tanya Jancawas real, once we check the code in, then it goes into our history, and then that secret's spilled.
30:17Robert HurlbutThen I have to go rotate the secret, yada, yada, yada, right?
30:21Tanya JancaIf it's before it's checked in, it tells me I've made this boo-boo, I can stop it.
30:25Robert HurlbutI don't have to rotate the secret. I just have to fix my boo-boo.
30:29Tanya JancaIt can save some time and stop a security incident from happening. So other technical controls, So when I worked at Microsoft, they have this thing called— they've renamed it like 3 times when I worked there, and they've renamed it several times since I left.
30:45Robert HurlbutSo I think it's currently called Azure Defender.
30:49Tanya JancaBut basically, they have this list of recommendations. And the top one was always, if you can buy something in Azure, turn on MFA right now. Run, don't walk.
30:58Robert HurlbutAnd so what if when the developer logs in, it checks to see if they have MFA? What if for every single account that can change your CIs, like anything in your CI/CD, it checks that you have MFA enabled?
31:15Tanya JancaBecause risk. Have you seen the new OWASP Top 10 for CI/CDs?
31:21Robert HurlbutSo, I've seen some of those. I had not seen all of those. I saw this talk at BSides Vancouver about it, and I'd been meaning to read the documents. I'm like, great, I can just go to a talk and have this guy named Farshad tell me all about it.
31:31Tanya JancaIt's great.
31:32Robert HurlbutAnd it didn't even have all the disasters I've seen, right? And it has some—
31:37Tanya Jancahas 10 really terrible things.
31:39Robert HurlbutAnd so what if, you know, the first time they log into the CI/CD, it's like, you don't have MFA turned on, you're going to turn that on before you're allowed to configure a CI from now on.
31:52Tanya JancaThat's a guardrail, right?
31:54Robert HurlbutAnd then if you disable it, it's like, cool, you're logged out till you turn it back on.
32:00Tanya JancaAnd so all of these things can be guardrails, right? Like, it sounds odd, but things too, like in, um, we were talking about physical guardrails, like not on a road, but for instance, in a building.
32:13Robert HurlbutSo where the—
32:14Tanya JancaI did top secret work, I did counterterrorism work, and that's all I'm allowed to say. But we had all these different levels of security And I remember one of them was this turnstile, and you would go in and they'd have to recognize you, like visually recognize you. And so you'd already like done your badge, and you'd done this, and you'd done that.
32:35Robert HurlbutAnd then there was like a certain number of staff, and if they didn't know you, they inked you out of the turnstile.
32:41Tanya JancaAnd so guardrail.
32:45Robert HurlbutSo that's more like defense in depth, but we're trying to figure out what.
32:50Tanya Jancawhat could be a physical security guardrail other than a physical guardrail, like, that knocks you literally physically back onto the road.
32:57Robert HurlbutBut like, because getting into buildings when you should not is a whole thing. Mm-hmm. And when I visit the Semgrep office, it's like, what if someone ends up here that shouldn't? And we were talking about this morning, so the biggest IT company in Canada used to be called Nortel, and the Canadian government took them over, all their offices over.
33:24Tanya JancaThey had these huge campuses, and they found multiple listening devices in every single room. And now we know why they went out of business. Like, going to different places, like every competitor knew what they were doing. And so I, I was like, we should like sniff all our rooms, right?
33:43Robert HurlbutBecause I'm paranoid. And so it's like, do we have a thing where it's like, if you come in and you have something that looks like, like, then you're not allowed in? It's like, that looks like a listening device.
33:53Tanya JancaAlthough with phones, that's really hard.
33:55Robert HurlbutBut anyway, there's, but any sort of technical control that tries to knock you back into what you should be doing, like you didn't bring your badge today.
34:03Tanya JancaWell, I'm sorry, I guess you have to walk home. That's a big lesson.
34:06Robert HurlbutBut maybe you have to sign a document. Maybe you have to have someone lock, walk you in, whatever the thing is to encourage the correct behavior that we really want to see. I know that was a tangent.
34:17Tanya JancaI'm sorry.
34:17Chris RomeoNo, no, it's good. It's good. So I guess one more specific question on secure guardrails. And that is, when does it make sense to put a guardrail in place from day one? Or is this something that you have to kind of grow into?
34:38Robert HurlbutHmm. So that's another thing we were talking about internally. So I'm making this new course and I want to talk about how to act. So a lot of people at conferences talk about secure guardrails, but it's not like, this is how you do it. Because if we want people to do it, then we need to— some of them, they'll just go run off and do it.
35:01Tanya JancaBut a lot of people, if you show them how, you'll get more of the results.
35:05Robert HurlbutLike, if I want my devs to do this, I need to show them how.
35:08Tanya JancaAnd so, we are talking about that, and I feel that your AppSec program should have a certain level of maturity for how many you're gonna have, right?
35:18Robert HurlbutSo, I think for any organization ever, the first secure, the first 2 would be, you gotta have MFA if you're going, like, you have to have MFA if you're able to edit the CI, if you're able, to delete other people's code. If you, if you have administrative privileges on these extremely powerful systems, you have MFA or no. And the other one would be the secret check-in.
35:41Tanya JancaSo, I think every org could benefit from those, period. Even if your AppSec program's somewhat nonexistent, I feel it would offer value. But some are a lot more complex.
35:52Robert HurlbutLike, if you don't have a coding guideline, if you don't have, like, let's say your AppSec team is one pen tester who only gets to 10% of all your projects and doesn't really offer guidance at this point. 'Cause there, there are a lot of programs that are like that, and that's okay. That's okay that you're starting where you're at, right? Like, we have someone on staff that has this skillset, we're gonna start with this. But I don't think it would make sense to sit there and be like, all of these different things are, are banned and you should be doing something else. Like, maybe that's not gonna go well, or maybe, um, So, writing a secure, a wrapper library.
36:32Tanya JancaSo, developers write wrapper libraries for lots of reasons. So, let's say my C# app wants to call a C++ app because it needs to do some weird backend thing with an embedded system. Okay, so I'm gonna write a wrapper library so it can call that. That's cool.
36:48Robert HurlbutBut the AppSec team writing wrapper libraries for security reasons, like, that could be a big lift, especially if none of them know how to code.
36:54Tanya JancaAnd some AppSec teams, no one knows how to code, and that's okay.
36:57Robert HurlbutThey can offer value in other ways. Yeah.
36:59Tanya Jancaways.
37:00Robert HurlbutBut if you do have some that are nerd-errific, uh, like me, that wrote code for many more of their life than they did not, then it's like, okay, cool, I'm gonna write one where— so my friend Clint was telling me about this. He's like, so you tab off the line if you use this old MD5 hash that we did not want people using anymore, and you would tab off of it, and then the wrapper library would show up and change the name to really insecure MD5 hash, what you doing?
37:34Tanya JancaTo give this feedback right away. And like, the dev could continue on, right? But they're gonna see that like their eyes are telling them that just changed. That's weird. Oh, look what it says.
37:47Robert HurlbutSomeone else told me she did that and it said, this is why we can't have nice things. And she would just put that for every single function she didn't want them using. But if there's no AppSec team to go ask, what am I supposed to do instead? Then maybe you've just left the dev confused or insulted, right?
38:04Tanya JancaSo, I feel like you have to have a certain level of maturity for several different types of guardrails.
38:10Robert HurlbutSo, you want to make sure that you have a team that's gonna back you up and support the thing you're doing. And you are checking a secret into your code.
38:21Tanya JancaI'm hoping most developers are like, Okay, yeah, you're right. We know not to do that.
38:25Chris RomeoMm-hmm.
38:26Tanya JancaBut what if you don't have a secret management tool and they just are like, well, great, what do I do? 'Cause I, I was, I was teaching secure coding somewhere, Chris, and they're, they're like, okay, so we're supposed to check it into our secret management tool.
38:41Robert HurlbutAnd I was like, yeah. And they're like, we asked for one 2 years ago and it's been in option analysis with AppSec this whole time. And then the AppSec team all looked at the floor. And they're like, so what do we do, Tanya?
38:53Tanya JancaAnd I was like, okay, let's talk about less insecure options than putting it in clear text in your code, right? Because there, there are less bad things to do.
39:04Robert HurlbutAnd then the AppSec team after was like, yeah, that project kind of got left behind because of this and that.
39:11Tanya JancaAnd I'm like, I think it's pretty important.
39:13Robert HurlbutAnd like, and then we did like a little scan and they're like, But so if you don't have a secret management tool, and that's what you're doing, like, they need to know what to do after, like, like, if there's no secure default, if there's no answer, all you've done is caused a problem.
39:30Tanya JancaLike, our job is not—
39:31Robert Hurlbutso I have this discussion a lot, Chris.
39:34Tanya JancaOur job is not to find vulnerabilities. Our job is to reduce organizational risk in meaningful ways.
39:41Chris RomeoYeah.
39:42Tanya JancaI don't want to find 40,000 vulnerabilities. I'd much rather fix 5,000 than just find 40 and not fix any.
39:52Robert HurlbutAnd so, yeah, if we, we don't want to go rub their nose in something and then offer zero assistance.
39:58Tanya JancaSo a certain level of maturity, such that you can support each guardrail properly and socialize it and teach everyone about it before it whacks someone in the nose.
40:08Robert HurlbutI would, I would like to know it was coming before I get the slap on the wrist.
40:15Tanya JancaYeah.
40:18Chris RomeoAll right. One more guardrail topic. And this is one that I haven't heard anybody talk about yet. And this is the idea of a privacy guardrail. And so I'm curious, in your opinion, is that even something that you think is possible? And we take this idea of a guardrail and shift it from a secure guardrail to a private guardrail.
40:41Tanya JancaYes.
40:44Robert HurlbutAnd I love it.
40:46Tanya JancaSo I went to OWASP Global AppSec in early 2023 in Dublin, and I saw Kim Watts speak about it. So I'm a fan now. And I saw her speak about the idea of threat modeling privacy, and it kind of exploded my brain. And I went from Stride to Stripe from then on. So the P for privacy, and I was just like, I love it.
41:17Robert HurlbutAnd, um, and I am no privacy expert, just to be clear, but I'm a fan of privacy. Whenever I can now, I try to sprinkle it and add it on to the security mandate because it's like, I have their attention, let's do everything I can. And so I would say definitely there's some privacy things. So I was teaching earlier this week and I was talking about security headers and I was like, yeah, you can go to securityheaders.com. My friend Scott made this site and you can scan your site.
41:46Tanya JancaSo one of the devs did it like during the lesson and he pointed out, oh, we're missing these 3 headers at this company. And one of them was permissions policy, which is all the different HTML5 things like turning on your camera, turning on your microphone, etc.
42:04Robert HurlbutAnd I was telling them, okay, so you might think, oh, I'm not going to turn those on, so it doesn't matter. But like, I have a blog.
42:11Tanya JancaWhat if I have an ad and then the ad tries to turn it on? And then it's going to ask the user, hey, do you want to turn on your microphone? It's like, why does she hacks purple want to like Watch me while I read her blog. She's a creeper.
42:24Robert HurlbutSo it could just harm.
42:25Tanya JancaIt could harm your reputation. It harms your users' privacy, right?
42:29Robert HurlbutAnd so I was explaining how you could turn that off.
42:32Tanya JancaThe other thing was referrer policy, and I'm sorry to go back to security headers, but that's telling the next website the page that you were on, and maybe it's incredibly embarrassing medical problem dot com slash.
42:46Robert HurlbutI so definitely have positive test results that I have such medical condition. That is private.
42:53Tanya JancaThat's no one's business. Or what if you're on like a bankruptcy page or something else, like anything that's private? Maybe you're just going to like paint your brand new tractor purple and it's none of anyone's business.
43:05Robert HurlbutRight? It's like, hey, they don't get to see what shade of purple. It's a surprise.
43:12Tanya JancaWhatever it is, right? So one privacy guardrail could be, did you turn on these specific things? Another one would be names of variables. So names of variables are, like, to be quite frank, like, really revealing, right?
43:28Robert HurlbutAnd so maybe you could have a guardrail that's like, you're going to put this to the screen.
43:34Tanya JancaLike, I can see you're putting this to the screen.
43:36Robert HurlbutAnd it says, And it has like underscore sensitive, or, or it has, you know, date of birth, and date of birth is considered personally identifiable information. And like, we just don't put that on the screen here.
43:52Tanya JancaSo if you add a list of variable names or field names, like from the database or table names specifically, that are sensitive, maybe it rings an alert that maybe it's a soft guardrail, like we talked about.
44:04Robert HurlbutAnd it's like, you are putting this sensitive field from the database, or this variable name has a sensitive word in it, and we suspect there's sensitive data in it, and you're putting it to the screen.
44:15Tanya JancaAre you sure? Just like, remind them, right?
44:19Robert HurlbutIt just has a red squiggly, and then maybe you can accept it and say, ignore this, I do accept this risk, or I am aware that this is sensitive.
44:26Tanya JancaSo I feel like there could be privacy built into that, especially if you built that into the plan from the beginning.
44:34Robert HurlbutLike, when I wrote my first secure coding guideline, Chris, it sucked.
44:38Tanya JancaIt wasn't very good.
44:41Robert HurlbutIt wasn't very clear.
44:42Tanya JancaIt wasn't 100% actionable. Also, the developers are like, Silverlight? We don't use Silverlight, Tanya. What's wrong with you? You clearly searched this crap on the internet. But I'm getting better and better at it, and each one has been more and more useful, effective, actionable, et cetera. And so, if you wrote privacy, into a coding guideline, or if you built it into your secure system development lifecycle, you had a privacy software developed, like privacy-focused or privacy-informed, maybe, SDLC.
45:13Robert HurlbutLike, I feel like you really could do that, but you would need a person that advocates for that.
45:18Tanya JancaSo I'm trying to advocate for it more. I'm still, to be quite blunt, security obsessed, and I definitely miss things.
45:24Robert HurlbutBut Yeah, I—
45:27Tanya Jancasounds weird, but that talk by Kim really changed my opinion of a lot of things. Yeah, I should say thanks to her, probably.
45:36Chris RomeoNo, she's— Dr. Woods is incredible. She's one of our advisory board members for DaVinci, because we wanted to have her perspective on threat modeling and her expertise on privacy weigh into what we're trying to do. And so she's— I'm a big Big Kim Woods fan. So love that. I was in that talk as well. I remember that talk she did in Dublin. So it was amazing.
45:59Tanya JancaAnd maybe we should challenge her. It was a 3-minute.
46:01Chris RomeoYeah. It was the ice skip. Yep. So we'll challenge her to, to tackle this topic of privacy guardrails. I'll mention it to her next time, next time we chat and see if she'll carry it forward and maybe she can come back with something that will help us even more based on her expertise.
46:16Tanya JancaYou should have her on the show.
46:19Robert HurlbutAnd then I can watch the show. Selfish.
46:23Chris RomeoIt's time for her to come back again. She has been a little while. So, all right. So we got to transition to the lightning round. And normally this is Robert's thing. So I'm just going to make my way through it here. I think I can, I'll, I'll, I'll try to keep us on, on focus here. But first question in the lightning round is, what is your most controversial opinion on application security? And more importantly, why do you hold this view?
46:48Robert HurlbutSo, I think that the executive order that told everyone that they absolutely had to make SBOMs was a miss, because I do think SBOMs offer value, but I would much, much, much have preferred that instead they're— they said, you know, you have to do software composition analysis, and if there's critical vulnerabilities that are reachable, You have to either A, alert all your customers, or B, fix them within X number of days. That would have reduced organizational risk across our entire industry.
47:23Tanya JancaInstead, we have lots of people making these SBOMs, and some people are getting value out of it, and a lot of people aren't.
47:29Robert HurlbutLike, lots and lots of my customers are like, we worked our butts off to make them, and none of our customers want to look at them.
47:35Tanya JancaI'm like, did you see my SBOM? Would you like to see it?
47:37Chris RomeoNo?
47:38Robert HurlbutOkay.
47:39Tanya JancaAnd they, they worked really hard, and other security initiatives got dropped to meet this executive order. And I feel like if you're going to like throw the gauntlet down, I just—
47:51Robert Hurlbutthere's so many better things they could have thrown it at. And so that is my controversial take. And I'm sorry, Alan, who is probably upset with me, Alan Friedman, who talks about this a lot. Sorry, bud. Yeah, I still think you're great. I still think they offer value, but I think we could have hit harder and reduced risk more.
48:11Chris RomeoYeah, I'm with you. I agree. All right, how about a billboard message? If you could display a single message on a billboard at the RSA or Black Hat conference, what would that billboard say?
48:22Tanya JancaBe nice to software developers. It's a lot of us aren't.
48:28Robert HurlbutA lot of software developers They hate security folks. We make their lives very difficult.
48:33Chris RomeoWe're, we're friction.
48:36Tanya JancaThey are like, imagine them as a whole bunch of cats, and there are a lot of security folks that just walk up and pet 'em backwards all day long.
48:42Chris RomeoWhoa. Right?
48:46Tanya JancaAnd what if, what if we were just always like, we worked hard to get along, to reduce friction, to be respectful, to be helpful, instead of This is my mandate, I gotta get it done.
48:58Robert HurlbutWe think, how can I do this in a way where they still wanna have a coffee with me during coffee break? Like, they don't have to be my best friend, but when they see me, they smile and they certainly do not hide under their desk. 'Cause I, not my best day, but I remember once I saw the security person and we had like half desks, and then I just like shrunk down really quickly and my boss saw and he was like, Oh. And I was like, so busted right now. And he's like, stand up. And I was like, it's just Dr.
49:35Tanya JancaKnow's coming and he's just gonna derail one of my projects. I know it.
49:40Robert HurlbutAnd so, yeah, be nice to devs.
49:42Chris RomeoI got this, I got this view of like you as Neo in The Matrix in the first movie when he's hiding from the agent the first time and he's ducking behind And then, uh, Morpheus is telling you, okay, in 5 seconds, I want you to move to the other side of the hallway. Like, I'm imagining Tanya trying to move away from the, uh, the agent, security agent who's trying to come and find you.
50:04Tanya JancaOz was not impressed with me.
50:09Robert HurlbutI got like the, you are an immature child kind of look.
50:12Chris RomeoWe've all gotten those though for, for plenty of times in our career. If you're not pushing the envelope enough, if somebody's not a little bit annoyed with you. That's my theory of life. So how about a book recommendation? Anything you could share with the audience?
50:28Tanya JancaSo I wanted to—
50:33Robert HurlbutThe Expanse is the best sci-fi ever written, in my opinion, and I will, I will die on that hill. So if you want to read some sci-fi, and I love sci-fi, like tweet at me the sci-fi you like and I'll probably tell you I read it. Um, but definitely.
50:50Tanya JancaSo if you, if you want to relax and do some, like, listen to The Expanse and go garden on your tractor. Um, but before, um, we were talking, so the Canadian government released this parenting course through an app and it's free.
51:07Robert HurlbutAnd I'm going to find out the name so we can put it in the show notes. And, uh, I'm a stepmama and I want to be a good parent.
51:13Tanya JancaSo I like read all these parenting books and stuff. And the most impactful one of all of them.
51:17Robert HurlbutYeah.
51:18Tanya JancaI've been using this, this lesson on adults all the time. And it's, so if someone's super upset, what I used to do, which is what my parents did, I tried to solve their problem for them because I thought that's how you show you care. But it turns out that really effing annoys people. People do not appreciate that. It turns out what almost everyone wants is for you to understand how they feel and help them understand how they feel and know that you basically Like to validate their opinion is valid and that you understand how they feel and, and then they'll calm down and then they usually solve their problem right away. And so for instance, like, you know, my little one is crying and there is ice cream on the ground and I'm just like, I'll get you more ice cream, right? Like I solve it.
52:06Robert HurlbutBut instead I'm like, oh, that must, that must be so disappointing. And so we can do this with adults.
52:11Chris RomeoYeah.
52:12Robert HurlbutAnd I don't mean to be patronizing, but I mean, like, they come to our office and they're just like, you just broke my belt and it was a false positive.
52:22Tanya JancaAnd it's like, oh God, that's awful.
52:24Robert HurlbutThey're like, yeah.
52:25Tanya JancaI'm like, that, that must really make you frustrated.
52:30Robert HurlbutThey're like, yes.
52:31Tanya JancaI'm like, does it feel like we wasted your time? They're like, yeah, it really does. And I just, try to elaborate the, the thing, uh, and then they calm down and I'm like, I agree with you. Yeah, that sucks. Can we, can we fix it together?
52:48Robert HurlbutThey're like, yeah.
52:49Tanya JancaAnd then obviously you must actually then go do the action and fix the thing, right?
52:54Robert HurlbutYou can't be like, yeah, I'll buy you new ice cream.
52:56Tanya JancaPsych.
52:57Robert HurlbutAnd then, and then not do it. And, and it turns out this actually works really well with positive things.
53:03Tanya JancaSo like one of my friends got promoted. And I was like, do you feel like you finally got recognized and people finally appreciate you?
53:10Robert HurlbutShe's like, yeah. And like, I just kind of went through and she's like, it sounds weird, but I felt so much more proud.
53:18Tanya JancaLike, um, one of the women I mentor, she got accepted to a conference for the first time.
53:23Robert HurlbutAnd like, it's not a huge one. Like, she's like, oh, it's not a big one.
53:26Tanya JancaLike, when do you speak at? And I'm like, I speak at baby conferences too. And you better believe it. The first conference I did was not ginormous.
53:34Robert HurlbutUm, and so then we talked about it and I'm like, you know, isn't it cool this? And like, do you feel that? And at the end of the conversation, she's like, I feel so proud now.
53:43Tanya JancaI feel really, really proud and really good. And I wanna call my mom.
53:48Robert HurlbutAnd I just wasn't that psyched about it, but like, it hadn't really sunk in how I felt yet.
53:54Tanya JancaAnd she's like, how'd you do that?
53:56Robert HurlbutI'm like, parenting course.
53:57Chris RomeoThat's great advice. That's, uh, there's lessons to be learned.
54:02Tanya JancaAnd, and also that all this time where I kept trying to solve problems for people, it turns out that doesn't make people feel good.
54:11Robert HurlbutAnd if instead you like process all the feelings kind of together, and then you can come up with a solution that you both came up with together, so you feel, you both feel good about it, uh, that's like 100 times better, especially for like future relationship stuff. And I was like, oh man, I wish someone told me that when I was like 5.
54:29Chris RomeoYeah. No, that's good. It's good stuff to know. Good stuff to, to be able to reflect and, and then share with other people so they can put it into action. So, uh, then you mentioned the next book. What, uh, I haven't heard about the next book yet, so I'd love to know more about it.
54:45Robert HurlbutOkay. So I have submitted 9 chapters of Alice and Bob Learn Secure Coding. And I have 5 chapters left and I'm partway through one of them and I'm really humming now.
54:58Tanya JancaAnd I took 2 weeks off next month to just write and farm, obviously. Um, 'cause it's July, it's gonna be amazing. Yes.
55:06Robert HurlbutAnd I took another week in August because I'm gonna finish this book.
55:13Tanya JancaI swear, publisher, do not fire me.
55:16Robert HurlbutIf you listen. But, uh, so this book is gonna be similar to the first book with the idea that Alice and Bob have things happen to them.
55:24Tanya JancaAlice goes on a date with a pen tester. She does not go on another one because he does not tell the truth. But, um, the idea of explaining complex concepts in multiple ways with a story, with like a technical definition.
55:41Robert HurlbutI have less diagrams in this book, but way more stories. And so it covers, so the, it's got 3 parts.
55:49Tanya JancaAnd the first part, which is already written, completed, everything, is agnostic secure coding guidance.
55:56Robert HurlbutSo it applies to literally every language. And so it, it's not like in C#, do this. It's, it's very, um, high level. So we talk about, I talk about input validation for a lot of pages and then how after, if you must accept special characters, then you sanitize them out or escape them. And like, we wanna validate that we're accepting what we want, you know, what's an approved list versus a block list, why block lists suck so much, et cetera.
56:20Tanya JancaSo then section 2, which is the part I'm halfway done. Um, so I, I've done so far the top 10 programming languages, so the most popular, and I took a lot of surveys to figure out what everyone feels. So C, C++, C#, et cetera, Java, Python. Um, advice of what to do and what not to do for all of them.
56:44Robert HurlbutAnd so I've already started using that content to speak at conferences. So I'm speaking at AppSec PNW in Vancouver, um, June 16th or 17th. It's both days.
56:53Tanya JancaI forget which day. I think I'm speaking the 16th, but obviously go to both days, uh, for only $64. Anyway, I'm trying to help them promote the conference 'cause it's OWASP and I love OWASP.
57:04Robert HurlbutUm, but I'm, I'm gonna give a, a whole lesson about writing secure JavaScript.
57:08Tanya JancaAnd not using that with statement. And so that's section 2.
57:14Robert HurlbutAnd so I'm going to do the top programming frameworks as well. So like, what are some of the cool features you should be using and what are some that are no longer valid that you should not be using? Like Python 2, grow up. It's Python 3 now. Say goodbye. But, and then section 3 is a secure system development lifecycle. Oh, in section 2, I'm also going to cover big classes of bugs and not necessarily the OWASP Top 10, 'cause I feel like it's been covered to death, but like, what is a race condition? Like, what does that mean?
57:46Tanya JancaIt's like big ideas of, or, you know, what is authentication and, and when it's broken, what can go wrong? And like, how does it get broken? The most common, et cetera. And so, I'm, I'm not covering like CWEs really. It's more, it's a bit broader than that, but so that developers understand, oh, this is why there's steam coming out of Chris's ears when he is telling you he found this thing, that they understand why.
58:14Robert HurlbutBecause I feel like a lot of security folks, when we do education, will be like, oh, HTTP request smuggling, which is like super specific.
58:22Tanya JancaIt doesn't apply that often. And devs just can't memorize hundreds of bugs. But if we have them in big classes of the most important, like most damaging, terrifying types of bugs, I feel like that might go better. So we'll see if people like it or not. In the first book, I did the top 10, the OWASP top 10 risks to web applications for those who hide under rocks.
58:47Robert HurlbutUm, but yeah, I want—
58:49Tanya JancaI wanted to cover it in a, a new, different Tanya way, 'cause I've had a lot of people say like, oh, why don't you just cover Um, OWASP SAM, or why don't you just cover—
59:00Robert HurlbutI'm like, 'cause, 'cause OWASP SAM exists.
59:02Tanya JancaYou should read that. It's good. You should read it.
59:05Robert HurlbutBut someone wrote it already. I'm trying to write something new in a different way that might appeal to more people or might, um, teach them in a different way that clicks. And I'm, I, I'm not sure if we covered this before, Chris, but I'm dyslexic. Like, not a person that says they're dyslexic because they made a spelling error, but an actual dyslexic person. And so I learn differently.
59:27Tanya JancaMm-hmm.
59:28Robert HurlbutAnd so when I, I started doing training, I had already learned French as a second language, which is extraordinarily hard for dyslexic folks.
59:36Tanya JancaAnd so I went to a dyslexic school for adults and there's 21 different learning styles. And so I learned all about this and I was like, so that's why I don't learn when I take certain courses because they just do one style. And if that style's not my style, it's not gonna work for me. And so a lot of people need to hear about it and then do it, or they need to see it and then hear it. And so I try to do as many of those as I can to just try to get the message across, like, as much. So that's my main goal is just, I, I wanna try to help people write more secure code.
1:00:13Robert HurlbutAnd you do not write a book 'cause you wanna make money, Chris. Let me tell you, there are Walmart greeters out there making more per hour than I am writing this book.
1:00:20Tanya JancaBut, uh, I really want it to exist. Yeah. So I wish I, I have the fire under my butt now cuz I'm, I'm in the home stretch.
1:00:32Robert HurlbutI can do this. Yep.
1:00:35Tanya JancaAwesome.
1:00:35Chris RomeoWell, we look forward to seeing it hit the, hit the internet bookstores everywhere. Um, that'll be exciting and, uh, sounds like it could be before the end of 2024.
1:00:48Robert HurlbutNo, unfortunately. So I'm gonna finish it way, way, way before that. But the printing cycle at Wiley, there's a printing cycle in January and I, I'm gonna miss it because I'm not getting my book in by the end of June. I know it's gonna take into July and August, which means then it'll be March or April, but it should be ready for RSA. And I've already talked SynGrep into buying like hundreds of copies and giving them away. So.
1:01:11Chris RomeoOh, nice. Very cool. Very cool. So, just to kind of wrap up our conversation on guardrails, what would you say then is just a quick key takeaway that you can leave with the audience here? Maybe point them to something they can go for more information too.
1:01:30Robert HurlbutOkay.
1:01:32Tanya JancaSo, I would say, like, the key information is we all have things we wish devs would do. If you can pick out some really important ones, figure out if you can find a technical control to nudge them that way.
1:01:50Robert HurlbutIf you— if it's a custom SaaS rule, if it's, you know, when they check the code and it stops them, if it's a thing that pops up on the screen, whatever it is that you can do that is low friction, that can get those really important things It's worth doing. There's a really high return on investment, especially if you, you test it out just on one team, a team that likes you, get feedback, tune, tune, tune, and then roll it out. And then you get to—
1:02:20Tanya Jancaand then you just get to get that return on investment of like, oh, no one's using that terrible function that caused all those security incidents anymore. And that I feel this is proactive security. Yeah. Instead of just reacting and cleaning up messes, it's like, what if we stopped security incidents before they happened sometimes?
1:02:39Robert HurlbutUm, so I'd really like to stress that people should consider that. Um, I'm building, um, an online course that will be free. I don't know what it's called yet, but it's going to be like something like implementing secure guardrails. I don't know what it's going to be called yet, but basically I'm going to try to give like concrete examples of exactly how to do a couple of them.
1:03:01Tanya JancaAnd how to kind of look at your program, see where you're at, try to identify some. But I find the main thing, Chris, with guardrails is just ideas of what to make a guardrail about. So I'm really hoping, um, really hoping that I can encourage people by giving them super specific examples. And actually, um, so starting in July, I'm doing this thing called Rules with Tanya, where I'm just going to do like an open office hours for 2 hours on the internet each month.
1:03:29Robert HurlbutWhere I'm just gonna write custom rules.
1:03:32Tanya JancaAnd so if people wanna join me, you can, and I'm gonna tweet all about it and stuff. But the idea is, is then people can come and share their guardrail ideas with me and I can share them with them.
1:03:43Robert HurlbutAnd then every time someone has a great idea, I'm gonna write about it.
1:03:47Tanya JancaUm, so haha, I'm going to share cool ideas.
1:03:51Robert HurlbutAnd so I'm, I'm really hoping people actually join me because if I just hang out by myself, it will be awkward.
1:03:56Chris RomeoYeah.
1:03:59Tanya JancaWish me luck, Chris.
1:04:01Chris RomeoThe topic may switch to farming if you're just there by yourself.
1:04:05Tanya JancaSo you may not be able to get any answers. Well, then I'm just going to write Alice and Bob rules.
1:04:09Robert HurlbutI'll just write Alice and Bob rules. All the bad functions I don't want to see anymore, I'm just going to write them up.
1:04:15Chris RomeoPut them all down. Well, Tanya, it's always a treat to connect with you, to have a conversation. So this has been excellent just to dive into guardrails and paved roads and privacy and farming and tractors and all the things that we managed to cover here. So thanks for being a part of the show. And we look forward to your next visit. Well, I'll hold Adam off until we get you to number 5. So you're in the lead for, for tied for first place. So thanks for, for spending the time with us.
1:04:44Tanya JancaChris, I can't wait to see you at OWASP Global AppSec.
11,618 words · transcript by assemblyai
More like this
View all episodes →- November 29, 2021 · 36 minOchaun Marshall -- IaC and SAST
- April 30, 2021 · 49 minAaron Rinehart -- Security Chaos Engineering
- January 18, 2022 · 45 minKen Toler -- Blockchain, Cloud, and #AppSec