--- title: "Travis McPeak -- SecOps Makes Developers Lives Easier" url: https://appsecpodcast.com/travis-mcpeak-secops-makes-developers-lives-easier/ date: 2018-12-18 duration_seconds: 1315 guests: ["Travis McPeak"] topics: ["DevSecOps and CI/CD"] audio: https://www.buzzsprout.com/1730684/episodes/8122659-travis-mcpeak-secops-makes-developers-lives-easier.mp3 transcript: true --- # Travis McPeak -- SecOps Makes Developers Lives Easier *December 18, 2018 · 22 min* with [Travis McPeak](https://appsecpodcast.com/guests/travis-mcpeak/) on [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122659-travis-mcpeak-secops-makes-developers-lives-easier.mp3) ## Show notes What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis describes finding repetitive work or problems that cannot scale manually, then deciding whether to use an existing solution or build automation. They also discuss learning paths, books, and OWASP involvement. The conversation makes the operational side of security tangible: give teams dependable controls and useful context while reducing the everyday friction of doing the right thing. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Travis McPeak: → [Travis McPeak on LinkedIn](https://www.linkedin.com/in/travismcpeak/) Mentioned in this episode: → [RepoKid](https://github.com/Netflix/repokid) → [Lemur](https://github.com/Netflix/lemur) → [Security Monkey (archived project)](https://github.com/Netflix/security_monkey) → [Bandit](https://github.com/PyCQA/bandit) → [The Tangled Web](https://nostarch.com/tangledweb) Chapters: 00:00 SecOps that helps developers with Travis McPeak 01:17 Travis’s security origin story 03:25 A security book worth sharing 04:05 Defining SecOps and introducing RepoKid 05:16 Removing permissions and managing exceptions 06:20 Security signals and incident response 08:20 Making certificate provisioning easier with Lemur 10:29 Language-specific tools and broader controls 11:52 Asset visibility with Security Monkey 13:02 Automatically correcting cloud permissions 14:32 How an operational problem becomes a tool 15:51 Where application security testing fits 17:22 Learning SecOps through community and practice ## Transcript *4,163 words · assemblyai* **0:02 Chris Romeo:** Hey folks, this is season 4, episode 21 of the Application Security Podcast. On this episode, we are joined by Travis McPeak, and he talks to us about SecOps and how SecOps makes developers' lives easier. This is another one of the interviews that I did out at AppSecUSA, and we hope you enjoy. **0:22 Travis McPeak:** The Application Security Podcast. **0:31 Chris Romeo:** Security Podcast. Here we go. Hey folks, welcome again to the Application Security Podcast, and once again we are coming to you from AppSec USA, and we are joined by Travis McPeak, who is actually the person who is one of the main folks behind AppSec USA and also a big player. And even, are you chapter leader for the West Bay Area? **1:17** Yes. **1:17 Chris Romeo:** Okay, all right. So, um, yeah, so Travis, we always start this interview process off by asking people, what's your security origin story, or how did you find yourself going down this application security path? **1:29 Travis McPeak:** Oh, I love that question. Yeah, so when I was a kid, I have always been fascinated with security. I ended up very lucky that it became the field it is today. I'd be probably doing it even if I didn't get paid very much. But, you know, obviously it's hot now. When I was a kid, I would do things like go around the house and gather up all the locks and keys and put them in a big pile. You know, I didn't even know what they were yet. I just thought they were cool. At one point, my parents had put a password on the computer because I'm sure I was doing something bad and they wanted to punish me. And it turned out that their password wasn't very good. One time my mom unlocked the computer so I could do something, and I saw that there was only 2 keys that were wet after she'd been doing the dishes. It was W and the Enter key. So my mom had picked a password of W, and I managed to cleverly deduce that, and I maintained persistence for months. **2:17 Chris Romeo:** Good old shoulder surfing always comes through for the win, right? **2:23** Wow. **2:24 Chris Romeo:** And so then kind of where'd you go from there as far as, did you study computer science at college or what's your background? **2:30 Travis McPeak:** Yep, computer science in undergrad, and then there was a program, Information Assurance, at Santa Clara University, and that was a good way to kind of do more formal security studying. I had some good courses there. We had a, you know, web application security hands-on thing, a, you know, exploit kind of thing where you learn about buffer overflows and all that good stuff. Read a ton of books on the side. You know, I've always been interested in social engineering. How does that work? You know, Mitnick's books and stuff like that. And then also began pretty heavily from an early age programming. I did C, did some Java in school, and then discovered that I loved Python. **3:08 Chris Romeo:** That seems to be the most popular language on Earth at the moment, Python. **3:13 Travis McPeak:** Especially for security folks. It's so easy to prototype an idea you have. You can just spin it up, get it working in a couple hours, you know, whereas a lower-level language you might spend days setting up the same thing. **3:23** Yeah. **3:25 Chris Romeo:** So you mentioned you've read a whole lot of books and things. I'm just curious, this is completely off the cuff, but what's the book that you've given to most other people with a security background? **3:34 Travis McPeak:** I love Tangled Web. I love that book too. Just the level of depth that he goes into in that book is mind-blowing. You know, you see somebody apply that much rigor to the field, you know, with that much And I just love it. **3:45 Chris Romeo:** Yeah, I agree. I've given that one. That's probably number 2 on my list. I've still— Gene Kim's original DevOps book is probably the one I've given the most. Yeah, just because I think that's like the best book because it's fictional and like you really get into the story. Like no one else has really been able to capture that, taking a business idea and get you into the story. **4:03 Travis McPeak:** Yeah, I agree. I love that book. **4:05 Chris Romeo:** So your— when I look at your Twitter profile, it says SecOps. And on the podcast here, we've talked to a lot of different people about the whole DevSecOps movement. We had Julian Vahent on recently talking about his new book. And, and so, but when I saw SecOps, that just kind of caught my attention because it wasn't DevSecOps, it wasn't— and so from your perspective, when you say SecOps is your specialty or what you focus on, what does that actually mean? **4:32 Travis McPeak:** The way I see it is basically how do we operationalize a security model that allows us to get certain assurances and controls that we need to have to feel comfortable with the product. And then at the same time allow developers to do what they need to do. And that whole operational flow is kind of what I mean with SecOps. So some of the things that we'll do is I have a project called RepoKid that uses data about our AWS services, what's being used, and will, if you haven't used a certain permission in a given time, it will remove that permission and we can operationalize it. So instead of doing these policy reviews like you'd have to do in an old-school model, we can actually just use data and make those changes automatically at scale. **5:16 Chris Romeo:** And so that's automated. It automatically goes through and just checks, it waits a certain amount of time, and then, so there's no manual kickoff of that? **5:27 Travis McPeak:** Completely automated. **5:28 Chris Romeo:** Okay, wow. And then, so you have more of a manual process when you add permissions back in then? **5:33 Travis McPeak:** Yes, and there's some tooling for that as well. The idea is to get all of that down to either no touch or very little touch so that if we have something that takes us an hour to do, then obviously if 1,000 people need it, we're going to be doing not much else except for this thing over and over again. So anytime we see friction points like that, we see automation opportunities. **5:54 Chris Romeo:** So can you do— so can something be manual and still be SecOps? **6:00 Travis McPeak:** Sure, totally, yeah. We have a lot of manual processes as well. So the more operational nature of, you know, hey, we have a high-value application and we need to make sure that it's dialed in with the right permissions. We'll still do architecture reviews. That kind of like falls under the SecOps umbrella for us as well. **6:20 Chris Romeo:** So is SecOps— I'm trying to wrap my brain around this idea of SecOps kind of from your perspective. And so I guess let's kind of— let's back up a little bit and I'm going to kind of come at this from more of a, I guess, traditional AppSec perspective. So where does secure development lifecycle fit in SecOps? **6:40 Travis McPeak:** Sure, yeah, let me give you— I won't answer your question right now. I'll give another example to kind of like help solidify what I'm talking about. So you have all of these signals, right? You have all these tools that you either have built in-house or you bought or whatever, and they're providing you with signals. And the job is to take all the signals, filter out the noise, and come up with things that you actually want to action. And then once you have a signal that you want to action, you know, okay, I have this tool, GuardDuty is telling me about something that looks like it might be serious. How do I go and investigate that? How do I have the data that I need to make an intelligent decision about whether this thing it's telling me is an actual problem or whether it's a false positive? **7:22 Chris Romeo:** So SecOps is a— so it's for the developers, but it's also for the incident response function. to be able to— so SecOps is setting me up to have the data I need in the event that we do have a problem. Exactly. **7:38** Okay. **7:40 Chris Romeo:** So repo— so I guess SecOps is, when I start to think about that from kind of the secure development lifecycle perspective, it's almost like it's in the kind of release and deploy kind of portion of a bigger model. **7:56** It's not— **7:56 Chris Romeo:** so you don't really care about security requirements, for example. in SecOps, or do you? **8:01 Travis McPeak:** We don't care as much about security requirements in applications. We have security— the way that my team does it is we have security requirements in our cloud infrastructure. Our team is a little bit confusingly named, but generally our wheelhouse and bread and butter is cloud infrastructure and things related to that. **8:20 Chris Romeo:** Okay, so this is more of the kind of on the infrastructure side of— but you still have to play in that you're You know, you're the deployment piece of the DevOps world. Okay, so that definitely makes sense. And so, I mean, what else, you know, we had this example of RepoKid that you talked about. I mean, what else do you have to do to make developers' lives easy? Or is that your goal? I guess let me back up. Is that your goal? Are you trying to make their lives truly easy or allow them to get their job done? **8:52 Travis McPeak:** Both of those things, yeah. In fact, it's a success requirement for our team to At bare minimum, not introduce friction for developers. Our best success cases are when we can actually make life easier, as you mentioned. So one of the favorite examples that I have is a tool called Lemur that does automatic certificate provisioning. **9:11** Hmm. **9:11 Travis McPeak:** Now think about a developer that wants to set up TLS for their service. They need to go and Google, how do I actually create the certificate? What cipher suite should I choose for it? What does a strong password look like? Where do I even store that password? These are things that developers don't wanna have to worry about, and if they do, then they might make a mistake with it. **9:31** Yeah. **9:31 Travis McPeak:** So Lemur was actually born out of a case where we, like everybody else, had Heartbleed. I wasn't there at the time, but the team that was, was dealing with Heartbleed, and they needed to rotate all the certificates. Like, oh, where are all those certificates? Where are the keys? You know, like everywhere else, you have passwords taped under someone's desk, and certificates you don't even know who owns it. And so Lemur was kind of this convenience tool where it makes it really easy for developers. You click a button, you tell it what you want, and then it goes and puts it on your load balancer for you. **10:06 Chris Romeo:** Now, so that's language-specific or language-non-specific? **10:11 Travis McPeak:** Sorry, I don't understand the question. **10:12 Chris Romeo:** So I mean, I guess, so it doesn't matter what language I'm writing my applications in or anything. Lemur is something that kind of sits at the infrastructure level. **10:21 Travis McPeak:** Correct. **10:21 Chris Romeo:** And so it works, it doesn't matter if I write it in Go or Python or Java or whatever. This is kind of on more of the operational side. **10:29 Travis McPeak:** Exactly, yeah. And those are really nice projects too where, you know, unfortunately one of the things in my background is I wrote Bandit. And Bandit's great, it's a Python static analysis light tool, but Bandit only works for Python. And then if you have Ruby, then you have Breakman and you have to put all these tools together. But the solutions like this where it's just, you write one thing and it works across all the applications are really nice leverage points. **10:54 Chris Romeo:** Yeah, and that's, I mean, like you said, this is something that people get wrong all the time. Like at least once a day in a big company, somebody's gonna try to solve that problem and they're gonna do something wrong. They're gonna create a certificate that's an SSL certificate, which we don't want people to use anymore. After the break, Travis explains how SecOps adds value. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Travis, what other things would you like folks to know about things that you have operationalized? **11:52 Travis McPeak:** So Security Monkey is a great example. You know, for us, we have multiple AWS accounts, lots of resources, and Security Monkey serves a couple of functions, but probably the most important is that it's just asset inventory. So, you know, these are the S3 buckets we have, and here's the difference in historical revisions for that. You know, something changed 2 days ago, what was that? Security Monkey will continuously monitor all of our accounts for all these assets and then track the version that you currently have, and then you can go back and see when did it change. **12:26 Chris Romeo:** And so that's basically like a web It's like a web app, it has a web app front end to it. **12:32 Travis McPeak:** Totally. **12:33 Chris Romeo:** And then allows you to— it does all this collection. And, you know, when you think about S3 and you think about all the times we hear about people with their S3 buckets that are incorrectly configured, so is Security Monkey doing some of that configuration check for you as well to make sure you're not leaving it wide open where people can— somebody on the public internet could just go and access it? **12:53 Travis McPeak:** Exactly, yeah. Once you actually have the state of your inventory Then you can look for misconfigurations and alert those, and in some cases even fix them automatically. **13:02 Chris Romeo:** Yeah, I was going to ask that as kind of my next question. So from a SecOps perspective, when you're all about automation and lowering friction, in this case, so you're saying that this actually could go and fix your S3 configuration directly. So it knows it has all of the right permissions on AWS, for example, to be able to go in and actually make an adjustment to an S3 privilege or S3 permissions to protect the system? **13:30 Travis McPeak:** It can be configured in a couple ways. Security Monkey, the default permissions are mainly view, so it can just see the resources you have and it can't make changes. One of the things we've operationalized is a queue enforcer. So if you've— something that we've seen developers accidentally do is make their queue open to the world. And we have an enforcement mechanism that will actually just go through and close that automatically. **13:52 Chris Romeo:** When you say queue, is that an AWS-specific thing? Like, are you— what do you mean by queue? **13:57 Travis McPeak:** Yes, the Simple Queue Service is an Amazon primitive that they give you to just provide a queue. **14:03 Chris Romeo:** Okay, so the developers are accessing it programmatically, and they're not— when they create it, they're not setting the right permissions on it, they're just leaving like defaults or something? **14:12 Travis McPeak:** Correct. Yeah, in some cases, you know, Amazon's very good. It's very powerful. It's also very easy to make mistakes, especially if you're not sure what you're doing or you haven't used the service before. And so what we'll see is these cases where developers didn't mean to make it public, and in that case we can just fix it for them and then usually reach out and find out, you know, if they're confused or if we can help them in some way. **14:32 Chris Romeo:** So when you have— so I think of these individual tools are kind of the end result. Walk me through kind of the process for how you see something that eventually ends up being a tool, right? Because you must see things like these tools. You didn't sit on a whiteboard and say, what are all the operational tools we could potentially do, right? There was a problem somewhere that you saw. And so can you just walk me through kind of the process or your— the way you think through those to end up actually creating a tool? **15:02 Travis McPeak:** Sure, yeah. So it's usually born out of either something where we spend a lot of time doing something over and over and over again and we see an obvious case where automation can help, or there's a problem that we want to solve that we couldn't actually scale up to manually. And so either, in either of those cases, automation is going to be a clear way to go. And then, you know, we don't, we would prefer not to build something ourselves if there's something that exists already that we can use. And so at that point, normally we go, okay, what are the alternatives? Where can we find something that'll take care of our need? If there's something there, then probably just buy it. If there's not, then we start thinking about, okay, what can we do in this space? You know, how much time would it take? Think through, you know, the investment that we're going to make in that space, how it fits with our strategic goals, and from there then we'll start, you know, architecting something. **15:51 Chris Romeo:** And so what's the role of things like, you know, traditional kind of application security testing tools Are those on your radar screen as somebody who's focused on SecOps, meaning SAST and DAST and IAST? And I always feel like I have to say, oh my, at the end of those because why do we have all these 4 vendors out there? Like, can we make some other— something other than a 4-letter acronym to describe our tools in AppSec? I don't know how many times I've said that here. But is that, you know, are those sets of tools bumping up against SecOps or are those something that's completely kind of in a different category? different stack of things to worry about. **16:29 Travis McPeak:** We definitely think about them, but we're fortunate enough to have another team that's very talented that focuses more on those kind of problems. I've definitely done it in my past, but it's not part of my current role. **16:39 Chris Romeo:** Okay, so in a highly functioning SecOps organization, you're not really focused on code quality and those types of things. That's something that's going to be done somewhere else when you're operating at a high nature like this. **16:53 Travis McPeak:** I think it just depends on the organizational choices you've made. In my particular role, the organization's been divided that way, but I think that there's definitely room to have these kinds of considerations in your process. Obviously, if you're a startup and you're a one-man shop, one-woman shop, then you're going to wear all the hats. At that point, it makes sense to do that consideration in line with the stuff I'm talking about. **17:16 Chris Romeo:** Yeah, you kind of have to at that point. do whatever you have to do to be successful, right? **17:21 Travis McPeak:** Yep. **17:22 Chris Romeo:** So where does— as somebody who's a practitioner of SecOps, if let's say we have a listener out there, maybe somebody who's in college right now and they're thinking, wow, this sounds really cool, I want to learn how to do this. What do you recommend that that person who might have a little bit of AppSec knowledge but really not a lot of SecOps knowledge, how do they even get started? Is there training somewhere that they can go to do this? Is it on-the-job type of stuff that has to happen, or where do we learn more Oh, I love that question because that gives me a great opportunity to shill for OWASP. **17:56 Travis McPeak:** You can totally become involved in your local OWASP chapter. There's a ton of resources. You can meet people that are doing that kind of work. And the other thing that I wish that somebody told me earlier in my career is that becoming involved in an open source project and contributing is a great way to get your foot in the door. **18:10 Chris Romeo:** Mm-hmm. **18:10 Travis McPeak:** You know, go find one of these tools that you think is exciting, try and install it, see if there's any, you know, changes that you can make to the the manual or the README, there's definitely changes, you know, some kind of enhancement that anybody can do that would be very welcome to the developers and maintainers of that project. So getting involved in open source is a great way to do it. **18:29 Chris Romeo:** Yeah, and that's something that we certainly make that recommendation all the time here because we want to, you know, we love OWASP and we want to see everybody get involved in it. Are there any particular blogs or anything or any sites or things that you go to for SecOps-related stuff, like industry-related stuff that we could point people to? **18:49 Travis McPeak:** Nothing specific. You know, I do my daily rotation of Hacker News and Reddit NetSec like everybody else, but yeah, I don't know of any particular resources. **18:57 Chris Romeo:** There's nothing specific to SecOps then? Okay, cool. And has anybody written the book on SecOps? Is it even— does even such a thing exist? **19:05 Travis McPeak:** I don't know. **19:05 Chris Romeo:** I don't think I've ever seen one that was SecOps-specific. **19:08 Travis McPeak:** There must be, but I'm not aware of them. **19:10 Chris Romeo:** Okay, well, maybe you got to go write one now. You know, everybody should write a book, right? **19:13 Travis McPeak:** Good idea. **19:14 Chris Romeo:** Yeah, so tell us a little bit about the OWASP Bay Area chapter here. I know we got a lot of listeners who are around this area and probably a bunch of them that are already there with you, but tell us just a little bit about OWASP Bay Area. **19:27 Travis McPeak:** Oh, awesome. Yeah, so we have been operating for quite a while. We have a few leaders, and so we're very lucky that we have lots of resources. There's companies that want to host us. We have great speakers. Speakers in this area. And our primary product is just a regular meetup. So show up, meet some cool people, you know, drink some beer, eat pizza, and just listen to cool talks. And then in addition to that, we have a hands-on Hacker Thursday event, which one of our leaders, Prashant, has put together in the last year. And those have been extremely, extremely popular. They're basically just a hands-on way to learn some new things. So you'll have an instructor come in. They're an expert. They'll spend 2.5 hours walking you through this new thing that you want to learn. And then at the end of the day, you've learned a new skill, you've met some people, all good times. **20:12 Chris Romeo:** And what are those— I'm just— I run the Raleigh-Durham chapter, so what are the topics that he's covering, Prashant's covering in 2.5 hours? **20:20 Travis McPeak:** Oh, we have— so first of all, it's not Prashant himself, it'll be instructors that we bring in. **20:26** Oh, okay. **20:26 Travis McPeak:** But yeah, so we have, you know, iPhone application security is one that we have coming up. We had one on microcontrollers and, you know, making your own rubber ducky. That was one that was— I saw that one. **20:39 Chris Romeo:** People were talking about that on Twitter. **20:40 Travis McPeak:** Yeah, that was very popular. One of our chapter leaders actually ran that one. Just anything you can think of, you know, like how to do source code review is one. **20:48** Okay. **20:48 Travis McPeak:** Yeah, everything under the sun. **20:51 Chris Romeo:** Okay, that's neat. And then so there's the regular meetup, there's the hands-on Hacker Thursdays, and then there's obviously The chance for folks, or when the conference comes to the West Coast, I'm assuming that the Bay Area chapter is involved in some degree for the West Coast version. **21:06 Travis McPeak:** I should definitely plug AppSec Cali for anybody that's not been. That's a great conference. **21:11 Chris Romeo:** Okay, and that's coming up in when? **21:12** January. **21:13 Chris Romeo:** January 2019. All right, Travis, thanks for taking the time to share your experiences in SecOps, and thank you for continuing to work with OWASP along the way. I hope you have a great rest of your conference. **21:24 Travis McPeak:** Thanks for having me on. I really appreciate it. **21:26** Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/travis-mcpeak-secops-makes-developers-lives-easier/