Skip to content
AppSec PodcastThe Application Security Podcast — home
22 min

Travis McPeak -- SecOps Makes Developers Lives Easier

With Travis McPeak

DevSecOps and CI/CD

What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 13 chapters
  1. 00:00SecOps that helps developers with Travis McPeakAudio
  2. 01:17Travis’s security origin storyAudio
  3. 03:25A security book worth sharingAudio
  4. 04:05Defining SecOps and introducing RepoKidAudio
  5. 05:16Removing permissions and managing exceptionsAudio

About this episode

What if a security team measured success partly by making developers’ work easier? Travis McPeak explains that approach to SecOps through concrete examples from Netflix’s cloud environment. RepoKid removes unused AWS permissions, Lemur simplifies certificate provisioning, and Security Monkey provides visibility into assets and configuration changes. Chris asks how those capabilities fit with the secure development lifecycle, incident response, and traditional application testing. Travis describes finding repetitive work or problems that cannot scale manually, then deciding whether to use an existing solution or build automation. They also discuss learning paths, books, and OWASP involvement. The conversation makes the operational side of security tangible: give teams dependable controls and useful context while reducing the everyday friction of doing the right thing.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Travis McPeak:
Travis McPeak on LinkedIn

Resources
RepoKid
Lemur
Security Monkey (archived project)
Bandit
The Tangled Web

Actionable

From this conversation

  1. Remove unused cloud permissions automatically

    If you haven't used a certain permission in a given time, it will remove that permission

    4:32
  2. Automate repetitive developer friction

    Anytime we see friction points like that, we see automation opportunities.

    5:33
  3. Maintain cloud asset and change inventory

    Security Monkey will continuously monitor all of our accounts for all these assets and then track the version that you currently have

    11:52
  4. Detect and remediate misconfigurations automatically

    Once you have the state of your inventory Then you can look for misconfigurations and alert those, and in some cases even fix them automatically.

    12:53
  5. Reuse existing solutions before building

    We would prefer not to build something ourselves if there's something that exists already that we can use.

    15:02
Transcript · 22 min conversation

0:02Chris RomeoHey folks, this is season 4, episode 21 of the Application Security Podcast. On this episode, we are joined by Travis McPeak, and he talks to us about SecOps and how SecOps makes developers' lives easier. This is another one of the interviews that I did out at AppSecUSA, and we hope you enjoy.

0:22Travis McPeakThe Application Security Podcast.

0:31Chris RomeoSecurity Podcast. Here we go. Hey folks, welcome again to the Application Security Podcast, and once again we are coming to you from AppSec USA, and we are joined by Travis McPeak, who is actually the person who is one of the main folks behind AppSec USA and also a big player. And even, are you chapter leader for the West Bay Area?

1:17Yes.

1:17Chris RomeoOkay, all right. So, um, yeah, so Travis, we always start this interview process off by asking people, what's your security origin story, or how did you find yourself going down this application security path?

1:29Travis McPeakOh, I love that question. Yeah, so when I was a kid, I have always been fascinated with security. I ended up very lucky that it became the field it is today. I'd be probably doing it even if I didn't get paid very much. But, you know, obviously it's hot now. When I was a kid, I would do things like go around the house and gather up all the locks and keys and put them in a big pile. You know, I didn't even know what they were yet. I just thought they were cool. At one point, my parents had put a password on the computer because I'm sure I was doing something bad and they wanted to punish me. And it turned out that their password wasn't very good. One time my mom unlocked the computer so I could do something, and I saw that there was only 2 keys that were wet after she'd been doing the dishes. It was W and the Enter key. So my mom had picked a password of W, and I managed to cleverly deduce that, and I maintained persistence for months.

2:17Chris RomeoGood old shoulder surfing always comes through for the win, right?

2:23Wow.

2:24Chris RomeoAnd so then kind of where'd you go from there as far as, did you study computer science at college or what's your background?

2:30Travis McPeakYep, computer science in undergrad, and then there was a program, Information Assurance, at Santa Clara University, and that was a good way to kind of do more formal security studying. I had some good courses there. We had a, you know, web application security hands-on thing, a, you know, exploit kind of thing where you learn about buffer overflows and all that good stuff. Read a ton of books on the side. You know, I've always been interested in social engineering. How does that work? You know, Mitnick's books and stuff like that. And then also began pretty heavily from an early age programming. I did C, did some Java in school, and then discovered that I loved Python.

3:08Chris RomeoThat seems to be the most popular language on Earth at the moment, Python.

3:13Travis McPeakEspecially for security folks. It's so easy to prototype an idea you have. You can just spin it up, get it working in a couple hours, you know, whereas a lower-level language you might spend days setting up the same thing.

3:23Yeah.

3:25Chris RomeoSo you mentioned you've read a whole lot of books and things. I'm just curious, this is completely off the cuff, but what's the book that you've given to most other people with a security background?

3:34Travis McPeakI love Tangled Web. I love that book too. Just the level of depth that he goes into in that book is mind-blowing. You know, you see somebody apply that much rigor to the field, you know, with that much And I just love it.

3:45Chris RomeoYeah, I agree. I've given that one. That's probably number 2 on my list. I've still— Gene Kim's original DevOps book is probably the one I've given the most. Yeah, just because I think that's like the best book because it's fictional and like you really get into the story. Like no one else has really been able to capture that, taking a business idea and get you into the story.

4:03Travis McPeakYeah, I agree. I love that book.

4:05Chris RomeoSo your— when I look at your Twitter profile, it says SecOps. And on the podcast here, we've talked to a lot of different people about the whole DevSecOps movement. We had Julian Vahent on recently talking about his new book. And, and so, but when I saw SecOps, that just kind of caught my attention because it wasn't DevSecOps, it wasn't— and so from your perspective, when you say SecOps is your specialty or what you focus on, what does that actually mean?

4:32Travis McPeakThe way I see it is basically how do we operationalize a security model that allows us to get certain assurances and controls that we need to have to feel comfortable with the product. And then at the same time allow developers to do what they need to do. And that whole operational flow is kind of what I mean with SecOps. So some of the things that we'll do is I have a project called RepoKid that uses data about our AWS services, what's being used, and will, if you haven't used a certain permission in a given time, it will remove that permission and we can operationalize it. So instead of doing these policy reviews like you'd have to do in an old-school model, we can actually just use data and make those changes automatically at scale.

5:16Chris RomeoAnd so that's automated. It automatically goes through and just checks, it waits a certain amount of time, and then, so there's no manual kickoff of that?

5:27Travis McPeakCompletely automated.

5:28Chris RomeoOkay, wow. And then, so you have more of a manual process when you add permissions back in then?

5:33Travis McPeakYes, and there's some tooling for that as well. The idea is to get all of that down to either no touch or very little touch so that if we have something that takes us an hour to do, then obviously if 1,000 people need it, we're going to be doing not much else except for this thing over and over again. So anytime we see friction points like that, we see automation opportunities.

5:54Chris RomeoSo can you do— so can something be manual and still be SecOps?

6:00Travis McPeakSure, totally, yeah. We have a lot of manual processes as well. So the more operational nature of, you know, hey, we have a high-value application and we need to make sure that it's dialed in with the right permissions. We'll still do architecture reviews. That kind of like falls under the SecOps umbrella for us as well.

6:20Chris RomeoSo is SecOps— I'm trying to wrap my brain around this idea of SecOps kind of from your perspective. And so I guess let's kind of— let's back up a little bit and I'm going to kind of come at this from more of a, I guess, traditional AppSec perspective. So where does secure development lifecycle fit in SecOps?

6:40Travis McPeakSure, yeah, let me give you— I won't answer your question right now. I'll give another example to kind of like help solidify what I'm talking about. So you have all of these signals, right? You have all these tools that you either have built in-house or you bought or whatever, and they're providing you with signals. And the job is to take all the signals, filter out the noise, and come up with things that you actually want to action. And then once you have a signal that you want to action, you know, okay, I have this tool, GuardDuty is telling me about something that looks like it might be serious. How do I go and investigate that? How do I have the data that I need to make an intelligent decision about whether this thing it's telling me is an actual problem or whether it's a false positive?

7:22Chris RomeoSo SecOps is a— so it's for the developers, but it's also for the incident response function. to be able to— so SecOps is setting me up to have the data I need in the event that we do have a problem. Exactly.

7:38Okay.

7:40Chris RomeoSo repo— so I guess SecOps is, when I start to think about that from kind of the secure development lifecycle perspective, it's almost like it's in the kind of release and deploy kind of portion of a bigger model.

7:56It's not—

7:56Chris Romeoso you don't really care about security requirements, for example. in SecOps, or do you?

8:01Travis McPeakWe don't care as much about security requirements in applications. We have security— the way that my team does it is we have security requirements in our cloud infrastructure. Our team is a little bit confusingly named, but generally our wheelhouse and bread and butter is cloud infrastructure and things related to that.

8:20Chris RomeoOkay, so this is more of the kind of on the infrastructure side of— but you still have to play in that you're You know, you're the deployment piece of the DevOps world. Okay, so that definitely makes sense. And so, I mean, what else, you know, we had this example of RepoKid that you talked about. I mean, what else do you have to do to make developers' lives easy? Or is that your goal? I guess let me back up. Is that your goal? Are you trying to make their lives truly easy or allow them to get their job done?

8:52Travis McPeakBoth of those things, yeah. In fact, it's a success requirement for our team to At bare minimum, not introduce friction for developers. Our best success cases are when we can actually make life easier, as you mentioned. So one of the favorite examples that I have is a tool called Lemur that does automatic certificate provisioning.

9:11Hmm.

9:11Travis McPeakNow think about a developer that wants to set up TLS for their service. They need to go and Google, how do I actually create the certificate? What cipher suite should I choose for it? What does a strong password look like? Where do I even store that password? These are things that developers don't wanna have to worry about, and if they do, then they might make a mistake with it.

9:31Yeah.

9:31Travis McPeakSo Lemur was actually born out of a case where we, like everybody else, had Heartbleed. I wasn't there at the time, but the team that was, was dealing with Heartbleed, and they needed to rotate all the certificates. Like, oh, where are all those certificates? Where are the keys? You know, like everywhere else, you have passwords taped under someone's desk, and certificates you don't even know who owns it. And so Lemur was kind of this convenience tool where it makes it really easy for developers. You click a button, you tell it what you want, and then it goes and puts it on your load balancer for you.

10:06Chris RomeoNow, so that's language-specific or language-non-specific?

10:11Travis McPeakSorry, I don't understand the question.

10:12Chris RomeoSo I mean, I guess, so it doesn't matter what language I'm writing my applications in or anything. Lemur is something that kind of sits at the infrastructure level.

10:21Travis McPeakCorrect.

10:21Chris RomeoAnd so it works, it doesn't matter if I write it in Go or Python or Java or whatever. This is kind of on more of the operational side.

10:29Travis McPeakExactly, yeah. And those are really nice projects too where, you know, unfortunately one of the things in my background is I wrote Bandit. And Bandit's great, it's a Python static analysis light tool, but Bandit only works for Python. And then if you have Ruby, then you have Breakman and you have to put all these tools together. But the solutions like this where it's just, you write one thing and it works across all the applications are really nice leverage points.

10:54Chris RomeoYeah, and that's, I mean, like you said, this is something that people get wrong all the time. Like at least once a day in a big company, somebody's gonna try to solve that problem and they're gonna do something wrong. They're gonna create a certificate that's an SSL certificate, which we don't want people to use anymore. After the break, Travis explains how SecOps adds value. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Travis, what other things would you like folks to know about things that you have operationalized?

11:52Travis McPeakSo Security Monkey is a great example. You know, for us, we have multiple AWS accounts, lots of resources, and Security Monkey serves a couple of functions, but probably the most important is that it's just asset inventory. So, you know, these are the S3 buckets we have, and here's the difference in historical revisions for that. You know, something changed 2 days ago, what was that? Security Monkey will continuously monitor all of our accounts for all these assets and then track the version that you currently have, and then you can go back and see when did it change.

12:26Chris RomeoAnd so that's basically like a web It's like a web app, it has a web app front end to it.

12:32Travis McPeakTotally.

12:33Chris RomeoAnd then allows you to— it does all this collection. And, you know, when you think about S3 and you think about all the times we hear about people with their S3 buckets that are incorrectly configured, so is Security Monkey doing some of that configuration check for you as well to make sure you're not leaving it wide open where people can— somebody on the public internet could just go and access it?

12:53Travis McPeakExactly, yeah. Once you actually have the state of your inventory Then you can look for misconfigurations and alert those, and in some cases even fix them automatically.

13:02Chris RomeoYeah, I was going to ask that as kind of my next question. So from a SecOps perspective, when you're all about automation and lowering friction, in this case, so you're saying that this actually could go and fix your S3 configuration directly. So it knows it has all of the right permissions on AWS, for example, to be able to go in and actually make an adjustment to an S3 privilege or S3 permissions to protect the system?

13:30Travis McPeakIt can be configured in a couple ways. Security Monkey, the default permissions are mainly view, so it can just see the resources you have and it can't make changes. One of the things we've operationalized is a queue enforcer. So if you've— something that we've seen developers accidentally do is make their queue open to the world. And we have an enforcement mechanism that will actually just go through and close that automatically.

13:52Chris RomeoWhen you say queue, is that an AWS-specific thing? Like, are you— what do you mean by queue?

13:57Travis McPeakYes, the Simple Queue Service is an Amazon primitive that they give you to just provide a queue.

14:03Chris RomeoOkay, so the developers are accessing it programmatically, and they're not— when they create it, they're not setting the right permissions on it, they're just leaving like defaults or something?

14:12Travis McPeakCorrect. Yeah, in some cases, you know, Amazon's very good. It's very powerful. It's also very easy to make mistakes, especially if you're not sure what you're doing or you haven't used the service before. And so what we'll see is these cases where developers didn't mean to make it public, and in that case we can just fix it for them and then usually reach out and find out, you know, if they're confused or if we can help them in some way.

14:32Chris RomeoSo when you have— so I think of these individual tools are kind of the end result. Walk me through kind of the process for how you see something that eventually ends up being a tool, right? Because you must see things like these tools. You didn't sit on a whiteboard and say, what are all the operational tools we could potentially do, right? There was a problem somewhere that you saw. And so can you just walk me through kind of the process or your— the way you think through those to end up actually creating a tool?

15:02Travis McPeakSure, yeah. So it's usually born out of either something where we spend a lot of time doing something over and over and over again and we see an obvious case where automation can help, or there's a problem that we want to solve that we couldn't actually scale up to manually. And so either, in either of those cases, automation is going to be a clear way to go. And then, you know, we don't, we would prefer not to build something ourselves if there's something that exists already that we can use. And so at that point, normally we go, okay, what are the alternatives? Where can we find something that'll take care of our need? If there's something there, then probably just buy it. If there's not, then we start thinking about, okay, what can we do in this space? You know, how much time would it take? Think through, you know, the investment that we're going to make in that space, how it fits with our strategic goals, and from there then we'll start, you know, architecting something.

15:51Chris RomeoAnd so what's the role of things like, you know, traditional kind of application security testing tools Are those on your radar screen as somebody who's focused on SecOps, meaning SAST and DAST and IAST? And I always feel like I have to say, oh my, at the end of those because why do we have all these 4 vendors out there? Like, can we make some other— something other than a 4-letter acronym to describe our tools in AppSec? I don't know how many times I've said that here. But is that, you know, are those sets of tools bumping up against SecOps or are those something that's completely kind of in a different category? different stack of things to worry about.

16:29Travis McPeakWe definitely think about them, but we're fortunate enough to have another team that's very talented that focuses more on those kind of problems. I've definitely done it in my past, but it's not part of my current role.

16:39Chris RomeoOkay, so in a highly functioning SecOps organization, you're not really focused on code quality and those types of things. That's something that's going to be done somewhere else when you're operating at a high nature like this.

16:53Travis McPeakI think it just depends on the organizational choices you've made. In my particular role, the organization's been divided that way, but I think that there's definitely room to have these kinds of considerations in your process. Obviously, if you're a startup and you're a one-man shop, one-woman shop, then you're going to wear all the hats. At that point, it makes sense to do that consideration in line with the stuff I'm talking about.

17:16Chris RomeoYeah, you kind of have to at that point. do whatever you have to do to be successful, right?

17:21Travis McPeakYep.

17:22Chris RomeoSo where does— as somebody who's a practitioner of SecOps, if let's say we have a listener out there, maybe somebody who's in college right now and they're thinking, wow, this sounds really cool, I want to learn how to do this. What do you recommend that that person who might have a little bit of AppSec knowledge but really not a lot of SecOps knowledge, how do they even get started? Is there training somewhere that they can go to do this? Is it on-the-job type of stuff that has to happen, or where do we learn more Oh, I love that question because that gives me a great opportunity to shill for OWASP.

17:56Travis McPeakYou can totally become involved in your local OWASP chapter. There's a ton of resources. You can meet people that are doing that kind of work. And the other thing that I wish that somebody told me earlier in my career is that becoming involved in an open source project and contributing is a great way to get your foot in the door.

18:10Chris RomeoMm-hmm.

18:10Travis McPeakYou know, go find one of these tools that you think is exciting, try and install it, see if there's any, you know, changes that you can make to the the manual or the README, there's definitely changes, you know, some kind of enhancement that anybody can do that would be very welcome to the developers and maintainers of that project. So getting involved in open source is a great way to do it.

18:29Chris RomeoYeah, and that's something that we certainly make that recommendation all the time here because we want to, you know, we love OWASP and we want to see everybody get involved in it. Are there any particular blogs or anything or any sites or things that you go to for SecOps-related stuff, like industry-related stuff that we could point people to?

18:49Travis McPeakNothing specific. You know, I do my daily rotation of Hacker News and Reddit NetSec like everybody else, but yeah, I don't know of any particular resources.

18:57Chris RomeoThere's nothing specific to SecOps then? Okay, cool. And has anybody written the book on SecOps? Is it even— does even such a thing exist?

19:05Travis McPeakI don't know.

19:05Chris RomeoI don't think I've ever seen one that was SecOps-specific.

19:08Travis McPeakThere must be, but I'm not aware of them.

19:10Chris RomeoOkay, well, maybe you got to go write one now. You know, everybody should write a book, right?

19:13Travis McPeakGood idea.

19:14Chris RomeoYeah, so tell us a little bit about the OWASP Bay Area chapter here. I know we got a lot of listeners who are around this area and probably a bunch of them that are already there with you, but tell us just a little bit about OWASP Bay Area.

19:27Travis McPeakOh, awesome. Yeah, so we have been operating for quite a while. We have a few leaders, and so we're very lucky that we have lots of resources. There's companies that want to host us. We have great speakers. Speakers in this area. And our primary product is just a regular meetup. So show up, meet some cool people, you know, drink some beer, eat pizza, and just listen to cool talks. And then in addition to that, we have a hands-on Hacker Thursday event, which one of our leaders, Prashant, has put together in the last year. And those have been extremely, extremely popular. They're basically just a hands-on way to learn some new things. So you'll have an instructor come in. They're an expert. They'll spend 2.5 hours walking you through this new thing that you want to learn. And then at the end of the day, you've learned a new skill, you've met some people, all good times.

20:12Chris RomeoAnd what are those— I'm just— I run the Raleigh-Durham chapter, so what are the topics that he's covering, Prashant's covering in 2.5 hours?

20:20Travis McPeakOh, we have— so first of all, it's not Prashant himself, it'll be instructors that we bring in.

20:26Oh, okay.

20:26Travis McPeakBut yeah, so we have, you know, iPhone application security is one that we have coming up. We had one on microcontrollers and, you know, making your own rubber ducky. That was one that was— I saw that one.

20:39Chris RomeoPeople were talking about that on Twitter.

20:40Travis McPeakYeah, that was very popular. One of our chapter leaders actually ran that one. Just anything you can think of, you know, like how to do source code review is one.

20:48Okay.

20:48Travis McPeakYeah, everything under the sun.

20:51Chris RomeoOkay, that's neat. And then so there's the regular meetup, there's the hands-on Hacker Thursdays, and then there's obviously The chance for folks, or when the conference comes to the West Coast, I'm assuming that the Bay Area chapter is involved in some degree for the West Coast version.

21:06Travis McPeakI should definitely plug AppSec Cali for anybody that's not been. That's a great conference.

21:11Chris RomeoOkay, and that's coming up in when?

21:12January.

21:13Chris RomeoJanuary 2019. All right, Travis, thanks for taking the time to share your experiences in SecOps, and thank you for continuing to work with OWASP along the way. I hope you have a great rest of your conference.

21:24Travis McPeakThanks for having me on. I really appreciate it.

21:26Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

4,163 words · transcript by assemblyai

More on DevSecOps and CI/CD

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.