Wolfgang Goerlich -- Security beyond vulnerabilities
with Wolfgang Goerlich
on Threat Modeling, Security Culture, Privacy and Compliance and Careers in AppSec
Audio hosted by Buzzsprout. Nothing loads until you press play.
J. Wolfgang Goerlich is an Advisory CISO for Cisco Secure. He has been responsible for IT and IT security in the healthcare and financial services verticals. Wolfgang has led advisory and assessment practices for cybersecurity consulting firms.
Wolf joins us to talk about some security things that will stretch your mind, like security beyond vulnerabilities, how apps intended functionality can be misused, data privacy, and nudges and behavior science.
Wolf challenged my thinking in this episode and pointed out a new area of threat modeling I had never considered. We hope you enjoy this conversation with… J. Wolfgang Goerlich.
Mentioned in this episode
Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.
Transcript
7,288 words · assemblyai
0:00Chris RomeoJay Wolfgang Goerlich is an advisory CISO for Cisco Secure. He has been responsible for IT and IT security in the healthcare and financial services verticals. Wolfgang has led advisory and assessment practices for cybersecurity consulting firms. Wolf joins us to talk about some security things that are going to stretch your mind, like security beyond vulnerabilities, how applications' intended functionality can be misused, data privacy, and nudges in the field of behavior science. Wolf challenged my thinking in this episode and pointed out a new area of threat modeling that I had never considered. We hope you enjoyed this conversation with Jay Wolfgang Goerlich.
0:41Robert HurlbutThe Application Security Podcast is brought to you by Security Journey. We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. Learn more at securityjourney.com.
0:54Chris RomeoHey, folks. Welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the Chief Security Officer at Security Journey and a co-founder of that company. And Robert is traveling the great United States somewhere today. And so, I'm flying solo here. I'm super excited for this conversation because the guest that I'm about to introduce to you, I had the joy of meeting Wolf at Converge, which is a conference around Detroit. And it was about 6 or 7 years ago, maybe even a little bit more. I had just started Security Journey. I was a brand-new company just out doing consulting. I grew up in Saginaw, Michigan, and I was like, they have a security conference in Detroit? I will get to go to the great state of Michigan to, you know, be a part of some security event that brings the, you know, 2 things that I love together there. And so, I had a chance to meet Wolf. This interview, I guess, has been 7 or 8 years in the making because I was really looking forward to hearing all of the insights that he has for us. And so, Wolff, our audience is used to, right off the start, hearing our guests' security origin story. And I'm actually on the edge of my seat because I haven't heard your origin story. I'm curious to see, how did you get to this world of security?
2:13Wolfgang GoerlichYeah. So, first off, so great to be here. And I like that you started with Converge because With Converge, what we were trying to do was bring together the convergence of developers and security professionals because we recognized, hey, everything that developers are excited about, 2 years later, all the security people are panicking about. So, if we can shorten that cycle, we'll be in a much better place. So, how did I get from, you know, being a kid to that point? I tell people that I mentor, the young folks are like, tell me where you started. I'm like, You need to understand, kids, the way I got into this field is now illegal. And I was like, oh, it's illegal. And but like most everything with me, it's a mostly boring story. Back in the '90s, back when the movie Hackers was still in the theaters, original run, I had the soundtrack. It was great. I was very excited. I was on BBSs. I was trying to figure out how to get into systems. And I would be like, how do you be a hacker? And they're like, well, you You need to get root in sysadmin. I'm like, well, how do you do that? They're like, well, you need to like, you know, dress up and lie to someone so they give it to you. I'm like, I'm not very good at that. Like, well, what else do you do? Like, well, you need to call up and pretend you're an executive and lie, and then they'll give it to you. I'm like, I'm not very good at that. I don't really like the phone. I mean, who of our generation likes to be on the phone anyways? That's just— that doesn't make sense. And so, what else do you do? Well, you write code that interception. I'm like, ah, I can program. And so I started off doing some code, writing some small programs. And at the time, I had a part-time job at a local hospital. And I was helping this hospital, these nurses who were building their IT network, their very first network. This is digital transformation, back when digital transformation meant taking away typewriters from very cranky nurses. And the network goes live, the nurse who was in charge of the project quit, because she wanted to help people, not build IT. The director of nursing pulled me into her office and she goes, I've been watching you. And I'm like, oh no, what did I do? Where did I go wrong? And she goes, I know what you've been doing. I'm like, oh no, like, I don't think— like, my BBS handles change all the time. I don't— and I go, what's going on? And she goes, and I want you to do it here full-time. Would you be, you know, in charge of our IT system? And then I realized this was a job interview. Not me getting punished. So this woman was this Texan, you know, spitting nails woman who had moved to Michigan. I was not used to anyone like her. She would walk into a room and everyone was terrified. But I knew this was my chance. And I remembered my training— training being very liberally used in that sentence. And I said, look, to do this, I have one demand. And the minute I said demand, I knew that was the wrong thing because I felt the temperature in the room get a little colder. I swear I heard a tin whistle and saw like sagebrush blowing by. I'm like, I'm gonna get killed. And after a long pregnant pause, she goes, what is it? And I said, I need root and sysadmin. And I didn't really know what that was. And she didn't really know what that was. But she said yes. And suddenly I was responsible for a whole hospital system's IT and way in over my head. So I started out on the blue team. I started out on the defensive team. And I started out in a way that really a teenager could do these days, not with HIPAA, not with regulations, not with how mature IT is. But it was a rare moment in time where you could do that. You could walk in and if you're smart and you were a little bit personable and you were a little bit pushy, I would say, you could get ahead.
5:56Chris RomeoVery, very cool. It's funny, I have a very similar origin story, but mine was in the university system. So, I went to a community college. college. I got dropped into that environment. They were like— I literally went for an interview to be a library kind of book checker. And the dean of the library comes out and he says, don't I— my mom was a professor at this university. He's like, don't I know you? I'm like, yeah, I've kind of grown up here. He's like, do you know anything about computers? I'm like, yeah. He's like, come in here. And so, I went from potentially almost being a library book checker. Remember when they used to have people at the university library that would scan the cards and everything to being dropped into an IT lab filled with goodies that they had no idea what to do with. They said, your job is to open boxes and turn things on and figure out what they do. And so, I mean, talk about a playground. And I'm very thankful for that moment. And it's, you know, it sounds like the hospital environment was the foundation of your career because I'm guessing they let you do some of the same things I was doing, which was figure things out because there was nobody there who could say, Okay, follow me. Here's what you have to do. They were like, just go do stuff, make things, but, you know, figure out how to make all these things work together.
7:11Wolfgang GoerlichAbsolutely. It was all self-taught. It was all self-directed. And there was no mentoring, there's no guiding. And so one of the things, maybe what, about a decade after that, I would say, a little bit more, I started to really want to give back and mentor and coach. And I started a security meetup, started From there, we went into B-Sides. We started the Converge Conference. After that, I ran an apprenticeship for a while where we put a number of people through an apprenticeship program because I always was so grateful for that opportunity. So, one, I wanted to give others that opportunity, but two, I was so hungry as a young person for someone who could say, no, really, don't do it that way. Do it this way. You know, I know you're banging your head against the wall. It's because you need to know this other thing. Right? Here's a paper. Here's a video. Go forth and do. So, in my career, I've always looked for ways to give back and try to help people both get started and also progress.
8:15Chris RomeoAnd that's a really important part of our industry. And it's a part that not enough people are embracing is being able to give back. And I've told this story on the podcast as well, but I'm going to tell it again because I love these people. The first security company I worked for, It was filled with— this is back in 1997. So, it was filled with people that had come out of the NSA. We had the ex-chief scientist of the NSA that had been chief scientist for 25 years.
8:41Robert HurlbutWow.
8:42Chris RomeoI was like 21 years old. I had no idea what that meant. I would go in this guy's office and ask him what I realize now are some of the just really ridiculous questions that I should have found another source for. And he would patiently draw on his whiteboard and show diagrams. His name is Marv Schaefer. He would draw diagrams and things and he would bring it all together. And it was like, now I look back and I say, like, I was literally standing on the backs of giants in this environment.
9:09Wolfgang GoerlichOh, yeah.
9:09Chris RomeoI didn't even know, but they taught me the importance of doing the same thing you are, like, you know, being willing to pour into people and answer questions and help people get further along. And so, I'm curious now. I mean, I know we're going to talk about Security Beyond Vulnerabilities, but you've mentioned mentoring a couple of times, and it is something that we need to get better at within our industry. We all do. You know, in your experience, what are, what are some tips that you would share for people out there? Let's say, let's just make a hypothetical. Somebody who's never really done any mentoring before with anybody, like, what would you tell them about how to get started? And what are— what's the foundational thing that we can help them be, be successful in bringing someone else along with them?
9:53Wolfgang GoerlichYeah, and that's a really good question because when I was doing the apprenticeship, One of the things that I thought was, hey, if I'm mentoring someone, once they get so good, they'll automatically know how to mentor somebody else and it'll be great. And it occurred to me, and it hadn't occurred to me in the past, and this is so simple, but I don't know why I hadn't thought about it. It occurred to me that mentoring really is a skill like any other, and it's a skill that you've got to practice, you've got to work on, and so forth. So that's Such a good question. I think there's a few different things. One is make sure that when you're mentoring, you're mentoring from the standpoint of giving back, right? Mentoring from the standpoint of giving back and really contributing, not from the, oh, I want to look how great I am and share my stories. I see a lot of that go wrong. So, Make sure you're putting the other person first. Make sure you're listening. A lot of mentors think that their goal is to tell the person all the things. And I know I started off by saying, I want to tell everyone, you're banging your head over here, check out over there. But there is a certain value of letting someone bang their head for a little bit. There's a certain value of letting people discover these things. I recently read a book, The Coaching Habit. Say Less, Ask More, and Change the Way. And I think it's Michael Stanier is the author, if I recall correctly. And so, if you're, if you're like, hey, how do you, how does that work? Grab that book. It's a great framework to get you started. So, put the other person first, listen, and also have an outcome. A lot of mentoring relationships I see that end up starting strong and go sideways are because it wasn't clear what the mentee was trying to get out of it. So oftentimes, I think it's very important and pertinent to say, all right, if we were to meet 6 times, what do you want to leave with? Where do you want to go? What are we working towards? So that you're putting their needs first and you're really outcome-focused. I think if you combine all those things, deliver a good outcome, listen more than you speak, and put the other person first, you're going to be in a good spot to be a mentor.
12:15Chris RomeoYeah. Very cool. One of the things I learned from— it wasn't in the world of mentoring from a security perspective, but going through the startup journey, it's always nice to have different mentors that you can reach out to at different times. And I learned this and I've applied this. I was going to meet with a guy that had sold a couple of companies and was very engaged in kind of the capital markets and stuff. And he gave me a homework assignment at the end of the mentoring session. And he said, hey, just when you finish this, when you finish the homework, let me know and we'll meet again and we'll sit down and go through it. And so, I went back. I spent the next week kind of working through it. It was great questions about modeling the business into the future. And then, I emailed him again and I said, hey, I'm ready. I've gone through this thing. And he goes, great. And so, we set up another session and I get there and he said, you know, Not very, very many people come back to this next session because they don't— they're not willing to put in the work. They just want to talk to me, but they don't want to work. And he's like, he was like, you know, you went away and did the work. And so, this is me being a mentee. And I didn't know any different. Like, you know, he asked me some great questions and I went back and modeled it in spreadsheets and got together. But so, that's one of the things I've taken away too is if someone wants me to mentor them, I love to do it. But like you and everybody else, like we have a limited amount of time. And so, I want people to— I want them to put some effort forth. Like I want to see them do something. I don't give busywork. I don't mean that. But I want to give them some work, things they can work on according to that outcome, that goal that you were describing so that they can— when we get back together, we have something to talk about. It's not just, you know, how's your time at work been? Because there's far better people than I to coach you on the daily movements within work, right? Like, that's probably not my level of expertise. But so, yeah, I mean, that's— and I love the fact you've got that passion, though, and you've had that for a long time to be able to bring people along. We need more of that in our industry. We need more people thinking this way like you are.
14:21Wolfgang GoerlichWell, thank you.
14:23Robert HurlbutHow do you create security champions? Security Journey brings together 2 powerful approaches to provide application security education to help developers become security champions and produce safer applications. Security Journey training content extends beyond developers to reach the entire SDLC, creating a security-first organization. Learn more about our enterprise security training at securityjourney.com.
14:47Chris RomeoLet's talk about this idea of security beyond vulnerabilities, because I'm really curious to understand, first of all, what do you mean when you say security beyond vulnerabilities? Let's start there.
15:03Wolfgang GoerlichYeah, so one of the things that I like to think about as a security professional, and if you are trying to think long-term, if you're trying to think strategic, I'd encourage you to ask this question. What if the major problem that most people are working on right now was solved tomorrow? What would be the next problem to work on? And so one day I was thinking about this in terms of software vulnerabilities, right? Because we spend so much time doing static analysis and dynamic analysis and manual testing and automated testing.
15:32Robert HurlbutYeah.
15:32Wolfgang GoerlichWhat would happen if all the vulnerabilities were fixed? And something occurred to me that I don't hear many people talk about, and that is the following. We spend a lot of time threat modeling for what happens when an adversary is misusing our applications. What we don't spend much time threat modeling is what happens when a person is using our application and its intended feature set for malicious things.
16:03Chris RomeoHmm.
16:04Wolfgang GoerlichSo, I'll give you a really good example. I was meeting with a— I do some product advisory work. So, I was having a conversation with an organization. They've since fixed this, but I won't name them. This was many years ago. They were working on basically help desk software, and they had this agent that would run on the desktop. And the security guy was talking me through it. He's like, this is great. If anyone has a problem, our help desk can hop on, they can turn on the camera, they can turn on the microphone, they can interact with the person, and they can solve the problems. And I was like, okay, that, that is the intended feature. That sounds, that sounds helpful for the intended outcome you mentioned. Who's working in your, your frontline help desk? It's a whole bunch of college kids, right? Of course. Frontline help desk people. All right, great, great. And, and these laptops, who owns these laptops? Well, it's, you know, the people throughout the company, this, that, and the other. I said, what happens if you've got a very curious— I'll just use the word curious— 20-something guy who recognizes that there's some very attractive girl in one of these businesses? And suddenly you could see that he never thought about this. Oh, So yeah, so what's to stop anyone from turning on these cameras and microphones without anyone knowing or interacting? He's like, oh. So you can immediately see how this can go sideways. We see other things in major applications all the time. Banking is a really good one. If you are on an account and you add your spouse to the account, and now the spouse and you are separating, which is something that we all go through in this country, there's not good rules for how that account is split up, for how that ownership is enacted. There's been many cases where the primary account holder has just locked out the other spouse out of all their funds. Now you say, well, wait a minute, that's clearly an abuse of those privileges. But also it's clearly the application working as intended. You are the application owner, you're, or the account owner, you're able to make those decisions. If you think about some of the software that's been deployed to students, which is really just wrinkles me, to frontline workers during the pandemic, where we're effectively time tracking when people are on their computers and tracking what they're looking at and other sort of stuff, that is software working as intended. Clearly, from a privacy and human rights perspective, we can talk about whether or not that is abuse, and there can be a line of questioning around that. So all this is to say, we need to fix vulnerabilities. But I also think as IT has become more prevalent, as applications have become more prevalent, we need to think about how the applications we're creating and the functionality we're enabling can be with legitimate functions and no use of exploits, can be used in harmful ways. And I think if we start paying more attention to those security vectors that are leveraging legitimate functions, we're going to be able to protect a lot more people than just simply saying, okay, well, you know, that's someone else's problem, right? Well, we'll let other people worry about that. Yeah, I think we have an obligation to get involved.
19:35Chris RomeoYeah. And as somebody who thinks about threat a lot, spend a lot of time thinking about threat modeling, teaching threat modeling, doing threat modeling. I tend to fall into the same category that you just described. Like, my primary focus is bad people coming to us from some vector trying to do something to take advantage of a flaw or design challenge or something that we had inside of our system. I very seldom think about the kind of abuse cases, I guess, is a way we could think about this where somebody's using legitimate functionality to try to do something. And so, I'm trying to think like the 2 examples you gave were excellent. They were very much on the privacy side. But I'm thinking about like— and let me bounce this off you. Tell me if this fits in the same category. Let's say you have a financial institution. They allow some type of transfer of funds between different places.
20:32Wolfgang GoerlichMm-hmm.
20:34Chris Romeocriminal organizations able to use the transfer of funds liberally to effectively launder money. They're using a legitimate function that's been there. Is that still— is that in the same category that you're thinking about here?
20:45Wolfgang GoerlichI would say so. So it's interesting you bring that up because financial services have actually gotten better at that. You guys, you may have seen me talk about this or lecture on this maybe 4 years ago where I was talking about money laundering scams. Where you say, hey, do you want a job? Okay, congratulations, you've got a job. Give me all the information to set up your direct deposit and look for the funds. And you're going to get a small portion of funds that move in. That's going to be indication that the project started. And then the adversaries would go and they would do like invoice scams or those types of scams. Or, hey, you know, if you pay this $10 million invoice accounts payable right now to this brand-new site we just set up, we'll give you a 10% discount. And so those funds would come into that, you know, not correct, not accurate, not legal site. And then once those funds were in, they'd be split up to all the money mules who think that they're on a job, but they're not. And then the adversaries would withdraw the money out of those people's accounts and funnel it down. This was a pretty consistent and common attack pattern late 2010s. Around that time, the major banks got wind of it and got much more rigorous around stopping those types of things and being able to reclaim those funds. Because originally, they weren't— there was nothing you could do. I saw whole people's livelihoods ruined because their nest egg was the same account that they linked up to this money mule and then it was emptied.
22:16Chris RomeoHmm.
22:17Wolfgang GoerlichIn recent years, banks have thought about this, have seen this attack, have put in place controls. So now what happens, circa '21, '22, depending on when you're listening to this, now what happens is they're like, hey, congratulations, you got the job. And those scammers are like, oh, by the way, we're going to reimburse you for a laptop. Can you please set up a prepaid account or can you buy these gift cards? And it's moved towards a gift card scam because that's where the weakness is now in the financial services. So, all this to say, yes. However, it took a lot of crime and a lot of activity for the banks to model that and repair that. One of the things I'm thinking about when I talk about security beyond vulnerabilities is thinking about that before we have a whole bunch of people's lives ruined and hopefully putting those controls in place.
23:10Chris RomeoYeah. And so, When I think about threat modeling from a security perspective, I have methodologies like STRIDE. I have CWE that I can use as a foundational data source to help me expand my thinking about different types of challenges. I have Lindon from a privacy perspective that just gives me an easy mnemonic and methodology to go through. When I'm thinking about security beyond vulnerabilities here, do I— is this something that I just have to brainstorm?
23:41Wolfgang GoerlichYeah.
23:42Chris Romeomy way into this? Like, I just have to think up like we're doing here, we're kind of thinking through without— or is there any type of repository you've ever seen of these types of threats that could help somebody get started?
23:53Wolfgang GoerlichYeah, I think at the moment it's brainstorming. It's very much like when you and I first met where threat modeling was where we didn't have the repositories, we didn't have the MITRE ATT&CK framework. It was, okay, let's think through what bad guys can do. But turning that on its head, let's think through what legitimate users can do to abuse the software packages we use. It will be intriguing to see activities like MITRE take this on. You mentioned the Linden Framework. I don't know if you've seen this or not, but MITRE is working on a privacy framework where they're threat modeling out attacks to privacy.
24:28Chris RomeoYeah.
24:28Wolfgang GoerlichSo that is interesting to see. I sat through a great workshop earlier this year, and that's not out public yet, but it's coming. But to your point, there isn't a good repository. If you are— if you're building products and you like books like me, I would suggest, for example, starting with Design for Safety. So Design for Safety is a book by Eva Penzimoog, and that walks through some of the considerations, some of the things that threat actors would do. and really susses out some of the common attack patterns of legitimate users, again, using our software packages. But you bring up a really good point. We need to have a clearinghouse for this.
25:16Chris RomeoYeah, because I think of like the impact STRIDE had on security-focused, technical-focused threat modeling. Like most people outgrow it over a period of time, but it's still a good foundational layer to help you understand where we're And so, I'll be on the lookout. I'm going to check out that MITRE Privacy Framework when it's available as well because that could be part of the solution to this as well.
25:39Wolfgang GoerlichAnd I think you just gave me an idea for my next project, so thank you for that.
25:43Chris RomeoThat's good. I can't wait to consume the output of it and maybe even contribute a little bit. So, I got another statement here that you shared with me in advance that I want to unpack a little bit, and that was, data we don't store is data criminals can't steal. And so, we've been on this privacy thread. I have a feeling this is going to help us kind of maybe put together a little mitigation for some of the things that we talked about already.
26:06Wolfgang GoerlichYeah. That is one of my fundamental precepts of all this, right? Why are we asking for so much data? I had a great conversation with a data privacy officer and consultant recently. And she's like, so, the last time you signed up for something, were you asked your birthday? I'm like, yeah, you know, of course. She goes, well, why was that? And I'm like, I don't know, maybe they need to like do demographics or something. She goes, yeah, that's exactly right. So why not ask your age range? Why ask the specificity of your birthday? If you're doing data classification or slicing your market by geo, why ask for your street address? Why not ask for your county? Oftentimes, we know that our data science teams and our analytics teams are going to be slicing and dicing. So, we ask for very, very specific things. But of course, in doing so, we create the conditions that adversaries can steal that data and can create problems. One of my favorite projects I did late 2010s was with a bank, and we went through and effectively removed every credit card from everything, both structured and unstructured data, and replaced that with a stub, you know, basically formatting-preserving encryption, but a stub where you could still use it, you could still run your analytics, you could still do anything, but if it was stolen, didn't translate to anything that a criminal could monetize. So yeah, this is a really good precept I follow: data we don't store as data criminals can't steal. We saw this In the attack, I think it was LastPass, where LastPass doesn't store anyone's real passwords. They don't store any of those encryption keys. They just build the infrastructure so you can do that. So when an attack happens and suddenly you've got access to a certain portion of LastPass, everyone's passwords aren't exposed.
28:05Chris RomeoWhy?
28:05Wolfgang GoerlichBecause they never stored them in the first place. So it's those types of things that can really protect from not only the threats beyond vulnerabilities, but also, of course, whenever there's an exploited vulnerability.
28:20Chris RomeoAnd so then, the mitigation that we're recommending is really exactly what you had in the precept. Don't store. Like, don't store data that you don't need. Have a good reasoning and reckoning for why you have to store a piece of data. And I've heard about people embedding that into their process as well. right into whatever they use from like technical documentation. They have like a question that comes up that says, why do you need to store this data?
28:47Robert HurlbutYeah.
28:48Chris RomeoAnd an engineer has to have a good reason. And if they don't have a good reason, then we know the feature definition gets changed because ultimately privacy is about limiting the dataset that's available there. And so, being able to drive that from an engineering perspective can be a powerful approach, as well.
29:05Wolfgang GoerlichI'll give you one other example. You know, I'm with— my day job is with Cisco, and I spend a lot of time with Duo Security. Duo Security recently rolled out a feature. Now, here's the problem. I need to know if someone is at home so that I can provide them a better security experience, right? If you're at home and in a trusted location, trusted device, why are you MFAing a dozen times a day? Let's ask once, maybe twice. But I don't want to ask for a street address. I don't ask for GPS. I don't want to use your IP address where I can trace that down. All those sort of things open you up to risk. So the team over there, and this has now been patented, the team over there created a Wi-Fi fingerprint. So they can look at all the networks around you, fingerprint it, and use that as a unique location. So if you move or Something radically changes. You know, you go to the coffee shop, they know that, but it doesn't store any data. It can't say, here's the name of the Wi-Fi network. It can't store, you know, here's the location of it. All we know is you're where you normally are at home, and now something has changed. And that's a really good example of what I'm talking about— having the data so we can make the right decision, but having the data in a format that if it gets stolen, gets lost, is in the wind, doesn't expose people to risk.
30:23Chris RomeoYeah. And that's just another example of making security so that it's not a barrier, which is— there's been a lot of talk in the industry, and I feel like we're going in that direction and we're going to get there. You know, you start thinking about password lists and things like that. Like, we can get to a world where we have all the protections that let us sleep at night as security people, but the user has a solid experience where security is not a constant blockage to them doing what they need to do. And so it sounds like that's a great feature that Duo has created to go down that path towards, let's make security more— I hate to say usable, but let's make security more usable. That's ultimately what we're talking about here.
31:05Wolfgang GoerlichYeah, there's long been a principle at Duo that our goal is to frustrate the adversary, not frustrate the user.
31:14Chris Romeouser. Hmm.
31:15Wolfgang GoerlichAnd I think that drives a lot of downstream decisions. I have a security design framework I use when I'm coaching directors or CISOs to build security programs. And one of the things, and when I say this, you're going to be like, yeah, of course, but it oftentimes is very eye-opening. If you look at the path an adversary takes through a threat model, through everything we talked about, if you look at the path the adversary takes, and separate that from the path that a typical user takes, their user journey throughout your application. There are controls that we can put all along that adversary path that never touch that user path. But until we look at both paths, that's not always entirely clear, right? Because we think, oh, someone's logging in, so here's where we need to insert that. No, no, no. If you separate those paths and think thoughtfully about where those controls intercept both of those things, you can really create an experience that is very impactful for the criminal and very light on the person.
32:12Chris RomeoThat's really— that's great. That's great advice for just people building products in general, to model the adversary path against the user path and look for ways to make the adversary's life more difficult. I think that's a great way to approach this and think about it. So, I want to talk quickly for a second about this idea of nudges and behavior science because I know there's You know, there's been a lot of research that have been done. There's been books written, not about security and nudges, but this idea of nudges just from kind of a general human behavior perspective. So I'm curious to get your take on how do we wrap security or how does security fit into this idea that a lot of research has been done upon?
32:54Wolfgang GoerlichYeah, I've been working in this space for a few years. This goes back to not only security products, but also security programs. So, if you think about that path the person's taking, the ideal path that we want them to take throughout our application, throughout our security program, a nudge is anything that makes them want to continue on that path and move forward on that path. So, smart default, a simple indicator. Logging into this podcast, I've got Chrome, and right now I've got a little Chrome— little nudge saying, hey, update me. You're out of date. And I will. I absolutely will. But it's not the old hard, thou shalt not use this until it's updated, and please wait as I watch the percentage of my computer reboots, right? A nudge is something that is not in the way, gives the user choice and agency, but directs them down that path. Sludge, on, on, by contrast, is anything that adds friction or makes them want to abandon that path. And so, these are 2 things that we oftentimes don't think about. So much of security has been based on, back to the '90s, back when I got into this, a sense of control in the sense of the, you know, back to the hospital, the nurses really didn't have a choice. If I took away their typewriters, they didn't have a choice to go anywhere else, right? They had to use the computers I provided. And so much of security is based on that. But in today's world, with people working from everywhere, with different devices, with so many different application choices. The power is really back in the person, which I think is appropriate. But what that means is we need to create compelling experiences and security nudges and smart defaults that allow people to have that agency, make good decisions without relying on overt control and without relying on putting constraints on people. Why? Because decades of research across psychology, but also decades of experience in security has taught us what happens to a constrained person. They become creative. And what is a creative user to a security program? A dangerous user, right? These are the people who are going to work around or avoid or skirt. So, the use of nudges is a behavior science technique within our applications to keep users on the right path and help them make smart decisions.
35:20Chris RomeoYeah, I feel like this is almost a product management lesson about security is really what we've just experienced here talking about security beyond vulnerabilities and privacy and what data we should store and nudges and things. Like, this is for my product management friends out there. There's some good lessons to be learned here through this process. So, we're coming towards the end of our time here, but I'd love to hear a little bit about the project you're doing with— I know you've got a podcast, you've got a conference planned.
35:48Robert HurlbutYeah.
35:49Chris Romeofor next year, and I'd love to just make our audience aware of kind of what the things are that you're doing there.
35:55Wolfgang GoerlichSo, one of the things that's intrigued me back from, Chris, when you and I first met at Converge, is cybersecurity as applied to areas where it no longer is rarely applied, right? And early days, that was application development. We've made tremendous progress in that. What I've started thinking about a lot, and this goes back to everything we talked about here day is the cybersecurity principles applied to everyday life, specifically having relationships, finding your partners, dating, getting married, all those sort of things. The use of technology has become ubiquitous, and there's very rarely is there an area that is more personal to any of us than our relationships. So, my wife, who's a therapist and an author in this space, spends a lot of time on the relationship side. I spend a lot of time on the technology side. We've been collaborating on, as you mentioned, a podcast. There very well may be a book in the works. There'll be a conference in October 2023 in Detroit. And the The name for all this is securing sexuality. And the application is, what do we need to know as cybersecurity professionals about how these tools are being used to form relationships? And what do people who are forming relationships need to know from cybersecurity to protect themselves?
37:27Chris RomeoYeah. Wow. It seems that's an area that I think needs a lot of— it needs a lot more discussion and research and everything. So, that's awesome that y'all are doing, you're using a podcast and a potential conference in the future to be able to bring people together to have those conversations. And, you know, from where our world is right now, we need more of those types of conversations. We need to get back to the point where we get people together and we solve problems like we used to, you know, back in before 2019 or whatever.
37:56Wolfgang GoerlichAbsolutely.
37:57Chris RomeoSo, from a key takeaway perspective or a call to action, We talked about giving mentors or mentees homework. What do you want to kind of key takeaway for our audience? Is there something you want them to do coming out of this? Should they go look at something? Based on all of your experience and wisdom on these topics, what do you want people to do?
38:18Wolfgang GoerlichYeah, if you are responsible for securing applications, spend some of that time asking the question, how can this application be misused? And spend some time threat modeling that. If you are a product manager, when you are building your project and feature sets, spend some time thinking about how your tools can be misused and abused and think about ways to put those controls in. And across both of those domains, as you are thinking about security, please do look into behavior science because I believe behavior science is going to be the area of tremendous growth for security. We talked about nudges, affordances. There's a lot of different ways to slice and dice this, but at the end of the day, we have tremendous power as developers, as IT professionals, as cybersecurity experts. We have tremendous power because this technology is impacting and enabling every part of everyone's lives these days. And, with that, I think it's incumbent upon us to think about how to give people agency, give people freedom, and ensure that the applications we're building are contributing to a good life, not to a dystopia.
39:34Robert HurlbutWow.
39:36Chris RomeoThank you so much, Will, for sharing this knowledge and experiences and stuff with us and with the audience. And, like I said, in my mind, this has been 8 years in the making because I really I was looking forward to this conversation. So, thank you for that. And we'll do this again sometime soon in the future to talk about something completely different because I feel like you and I could probably talk for 4 hours in a row about this type of stuff and just keep going. But we'll, we'll stop here for today and look forward to having you on again in the future to talk about some other topics. So, thank you very much.
40:09Wolfgang GoerlichThanks so much.
40:12Robert HurlbutThe Application Security Podcast is brought to you by Security Journey. We provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics. Learn more at securityjourney.com.
More on Security Culture
- Jeevan Singh -- The Future of Application Security Engineers
Jeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
- David Quisenberry -- Building Security, People, and Programs
David Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making.
- Dustin Lehr -- Culture Change through Champions and Gamification
Dustin Lehr, Senior Director of Platform Security/Deputy CISO at Fivetran and Chief Solutions Officer at Katilyst Security, joins Robert and Chris to discuss security champions.