Feb 13, 2011

Another OWASP Paperware Project, Anyone?

Summing up the OWASP 2011 Summit I fear OWASP is becoming more and more paperware and less and less software. On the Summit's fixed schedule we had 15 technical sessions and 27 non-technical sessions (my interpretation). That's almost two thirds non-tech.

The only guys I saw actually coding at the summit were people we had invited and that are not OWASP leaders (Powerpoint slides with code do not qualify as coding). At the same time OWASP is getting desperate about not reaching developers.

The solution is in my opinion to cut down on paperware, pdfs, Powerpoint presentations, guidelines, and policies. Developers want code, not Word documents. I tried to bring this up during the OWASP Secure Coding Practice session but failed to convey my view. Who would have thought a coding guide did not contain code?

If you hand a document to a developer that says "Do canonicalization" you will not get canonicalization in the application. But if you hand a developer code snippets in a relevant language that show a couple of instances of canonicalization problems and how the solution could look you will get a change.

So, why do we still have all these guidelines and policies that talk about code? I believe the reason is that the authors don't know how to program. Guys writing appsec guidelines typically cannot code themselves and developers can smell it a mile away.

Do you believe OWASP needs to reach developers?
Are you right now working in a word processor rather than an IDE?
Stop!

Developers believe in other developers and working code. You want to change how they play? Get in their game.

Security People vs Developers

"Developers don't know shit about security". That may very well have been the most retweeted quote from the 2011 OWASP Summit. I heard it from stage firsthand and I wrote the original tweet about it, adding "Well, I got news. You don't know shit about development".

I truly believe this is one of OWASP's biggest problems. I hear it all over the place – frustrated appsec people claiming that developers and managers are ignorant, lazy, or untrained since they don't prioritize security. But it's we, the appsec people who are ignorant, lazy, and untrained! And that's why we're failing in developer outreach. We keep going to our own conferences, pushing Powerpoint slides, discussing unsexy web 1.5 code, and still think we're on the top of the hill. We're at the bottom, guys!

I've done surveys with 200+ developers to figure out how security is prioritized. In general, this is the picture:

Software Priorities According to Developers
  1. Functions and features as specified or envisioned
  2. Performance
  3. Usability
  4. Uptime
  5. Maintainability
  6. Security

When I tell appsec people this they typically go "Yeah! See, that's the problem. We should be much higher on that list!" No. No, no, no. We belong at level six and unless we appreciate and understand how security fits in with functions, performance, usability, uptime, and maintainability we will keep being ignored by developers.

Why? Well, a featureless system is useless. A security feature that hits performance notably is out. A system with poor usability will bring no business so usability is above security. "Uptime, hey that's a security thing!" No. Just because DoS attacks hit your uptime doesn't mean we own the issue. Many things affect uptime such as release and deploy cycles, maintainability, caching, scalability, configuration, and patching (no, not just security patching). Finally, maintainability affects ROI much more than security in the general case. Thus, security == level six.

Appsec friends, let 2011 be the year where you go to training to learn what's important in software and where security fits in the big picture. Then we won't hear anymore jokes on ignorant developers in 2012. Instead we'll be humble and get things done.

New OWASP Board – My 10 Questions

At the OWASP 2011 Summit I attended some of the sessions on OWASP Bylaws and OWASP Governance. I agree we need to update and define roles and duties but there are more urgent issues.

Discussing the board is complicated if you're not natively English speaking. Asian, South American, and European OWASPers tend to know English appsec terms but they do not know the nuances in what's being said about governance. This effectively means only English speaking people will define how OWASP should be governed and mainly English speaking people will run for the board. Today the board consists of 4 Americans, 1 Irish, 1 Portuguese living in London, and 1 Belgian. That is neither representative nor good for OWASP.

I'd like to see the OWASP board grow more diverse. Therefore I will ask the questions below to the members who run for the board. Note, this is not a requirements list, rather parameters I'd like to see diversity in.

  1. Which human languages do you speak?
  2. In which parts of the world have you lived at least 3 months?
  3. Have you shipped production code? How long ago?
  4. Please provide a list of web technologies you consider yourself proficient in (markup, styling, scripting, server-side code, server configuration and operational setup ...)
  5. What is your typical appsec role (pentester, trainer, developer, project manager ...)? Are you a consultant, vendor, or do you have an appsec role within an organization?
  6. Please provide a list of appsec activities you consider yourself proficient in (code auditing, threat modeling, SDLC implementation ...)
  7. Have you run or are you running an OWASP chapter? Which?
  8. Have you run or are you running any OWASP projects? Which?
  9. Do you have a college or university degree? (No requirement, I just want the right mix)
  10. Do you have a postgraduate degree? (I'd like to have at least one on the board)

There are no correct or preferred answers to the questions above. I only want to ensure we have people from as many parts of the appsec community as possible. For me that's more important than knowing all the English terms in our bylaws or policies.

Jan 27, 2011

65,000 New Jobs in Sweden 2011

Sweden is in a better economic and fiscal shape than most other OECD countries, says OECD. That situation means labor demand is growing and The Swedish Public Employment Service today announced its predictions for empoyment in 2011.

"A total of 65,000 more are expected to get jobs during the year and the number of occupations where there is a shortage of labor is increasing steadily. Most difficult for employers to find staff will be in the computer professions, engineering professions and construction trades because there are too few trained."

Here's their press release in Swedish. You can translate it with Google.

If you have IT skills – welcome to Sweden!

Jan 26, 2011

Countdown Challenge for OWASP Summit

The official OWASP Summit Challenge is out – a JavaScript fighting arena where your script should show its name more prominently than its competitors. The first round attracted 8 contestants and "dross" scored the first point. Check out all the scripts and the next round of competition: http://makeXORbreak.com

The challenge starts the countdown to one of the most important meetings in application security history. February 8-11 we invite you all to join round-table discussions with industry and research leaders on how to solve XSS and enhance browser security, which appsec metrics work, security of HTML5 and EcmaScript 5 and more. We truly believe that crucial things can happen in a social, productivity-oriented environment. That's why OWASP is going all-in on the Summit.

Google will be there. Mozilla will be there. Microsoft will be there. Facebook will be there. PayPal will be there. Apache will be there. The world's top appsec companies will be there. The authors of (my) favorite appsec books will be there.

OWASP Summit 2011

Best thing of all? You are most welcome to join!

Jan 7, 2011

Running Civ IV on HFS+ Case-Sensitive

This post is completely unrelated to application security but since I struggled for two hours not finding my specific solution anywhere I just though I'd post ...

How I got Civ IV working on my Mac OS X with case-sensitive file system (HFS+ case-sensitive).

The basic trick is to create a new case-insensitive disk image using the disk utility tool in /Applications/Utilities. Do it with the following specs (taken from this blog post):
  • Name: caseinsensitive (or any other lower-case name of your liking)
  • Size: Custom 30 Gb (it will only use up the space you need anyway)
  • Format: Mac OS Extended journaled (i e not case-sensitive)
  • Encryption: None
  • Partitions: No partition map
  • Image format: Sparse bundle disk image (this makes sure you only use the space necessary)

Now you uninstall Civ IV from your regular drive (most probably from /Applications) by deleting these folders and files:
  • "Civilization IV Gold" folder which contains the game applications
  • "home folder\Documents\Civilization IV" folder
  • "home folder\Documents\Civilization IV Warlords" folder if you have Civ IV Gold Ed.
  • "home folder\Library\Application Support\Civilization IV" folder
  • "home folder\Library\Application Support\Civilization IV Warlords" folder if you have Civ IV Gold Ed.
  • "home folder\Library\Preferences\com.aspyr.civ4.plist" file
  • "home folder\Library\Preferences\com.aspyr.civ4warlords.plist" file if you have Civ IV Gold Ed.

Then you install Civ IV from your DVD to the newly created disk image named "caseinsensitive". I additionally created a folder structure on the new disk image using these shell commands (don't know if they're needed):
  • mkdir /Volumes/caseinsensitive/Documents/
  • mkdir /Volumes/caseinsensitive/Documents/Civilization\ IV
  • mkdir /Volumes/caseinsensitive/Library
  • mkdir /Volumes/caseinsensitive/Library/Preferences
  • mkdir /Volumes/caseinsensitive/Library/Application\ Support
  • mkdir /Volumes/caseinsensitive/Library/Application\ Support/Civilization\ IV

Finally you just start Civ IV from the new disk image. Happy gaming!

Dec 13, 2010

Java regexp for Unicode letters

Just to get this out there ...

Java regular expression for matching all Unicode letters:
Pattern p = Pattern.compile("\\p{L}*");