[00:00.000 --> 00:01.920] Security afterthought syndrome. [00:03.040 --> 00:12.660] And I'm not in academia teaching currently, but security and computer science education is something I'm very personally passionate about. [00:13.940 --> 00:25.200] And this talk is about how to change how we teach computer science in general as a way of changing how people think about security. [00:25.200 --> 00:34.560] And I use environmental engineering as an example of how this could work, because they've had similar successes there. [00:34.800 --> 00:37.340] But anyways, on to the talk. [00:38.640 --> 00:41.220] So, the security afterthought syndrome. [00:41.460 --> 00:45.260] I don't know if anyone else has a snappy name for this, but this is what I call it. [00:45.420 --> 00:48.840] The thing where no one thinks about security until it's a problem. [00:50.040 --> 00:53.540] And, you know, you're all security professionals, so you all know what this is. [00:54.520 --> 01:04.140] And it's just, we get all these avoidable bugs that would have been easy things to fix in the design stages, but that become difficult or impossible to fix later on. [01:04.240 --> 01:09.360] Just like in the previous Chromecast talk, he was saying, well, at this stage, there's really nothing to do about it. [01:12.500 --> 01:20.020] And, you know, there's lots of attempts by educators to try and figure out how to redress this general attitude. [01:20.100 --> 01:23.720] But in order to fix a problem, you need to understand where it comes from. [01:23.780 --> 01:28.020] If you don't understand the source and what the underlying cause of a problem is, you're just addressing symptoms. [01:28.020 --> 01:32.780] So, the first question is, why is security an afterthought? [01:34.800 --> 01:39.340] And the security is an afterthought because we teach it that way. [01:40.260 --> 01:47.740] It's usually a separate elective topic that students take if they're interested in it when they get to their, like, junior or senior year. [01:48.560 --> 01:59.160] Which is good for creating specialists, but it's not how you get your average computer science undergraduate to have the security underpinnings they need for their work. [01:59.580 --> 02:04.980] And by then, everybody already has all their bad patterns and bad habits. [02:05.360 --> 02:11.160] And changing those after they've been set is way harder than teaching good habits from the get-go. [02:11.440 --> 02:13.400] So, then you're fighting an uphill battle. [02:15.420 --> 02:27.660] And students really don't see meaningful security content in the average undergraduate college program until the end of their undergraduate careers or just not at all. [02:29.640 --> 02:31.920] You know, so, of course, it's an afterthought. [02:33.220 --> 02:38.280] So, first, I've made some assertions about how computer science and security are taught. [02:38.620 --> 02:40.080] And they're pretty strong assertions. [02:40.180 --> 02:44.780] So, I wanted some data to back that up because, you know, it was my gut feeling. [02:44.960 --> 02:47.480] And it was what I knew based on my personal experience. [02:47.480 --> 02:49.860] But I'm a scientist and I like to have data. [02:50.580 --> 02:55.180] So, I surveyed a hundred different computer science department heads. [02:55.420 --> 02:58.500] I got 33 responses, which was a fabulous response rate. [02:58.560 --> 02:59.080] I was thrilled. [02:59.840 --> 03:05.480] And I asked them about how they prioritize security and integrate it into their curriculum. [03:05.660 --> 03:14.080] I mean, I asked them about some other things, too, because you don't want them to know that you're specifically interested in security, because then, oh, yes, of course we care about security. [03:17.180 --> 03:30.840] And a friend of mine who knows how to do these things lent me the psychology of survey response, which was very helpful in figuring out how to ask questions without being misleading or without tipping your hand too much about what you were actually trying to get out of it. [03:31.440 --> 03:35.000] So, if you need to collect any data like that yourself, I highly recommend it. [03:36.260 --> 03:38.240] But without further ado, the data. [03:38.240 --> 03:44.440] So, the first question I wanted to answer was how is security ranked with regards to other subjects? [03:45.300 --> 03:49.580] So, I had ten different undergraduate core subjects. [03:50.440 --> 03:56.800] And I asked the professors to pick the five that they viewed as the most important to include in the undergraduate curriculum. [03:57.440 --> 04:00.340] And some of you are already reacting to it. [04:01.220 --> 04:05.260] As you can see, I've got these ranked from most popular to least. [04:05.260 --> 04:09.800] And we've got algorithms and data structures came in at first, which is not surprising. [04:10.300 --> 04:13.660] Then software design, operating systems, programming languages. [04:13.980 --> 04:17.720] And security is number nine, and with only compilers after it. [04:17.820 --> 04:18.840] It was a terrible showing. [04:19.740 --> 04:23.360] And, you know, I mean, maybe not that surprising, but, oh, yeah. [04:25.080 --> 04:26.120] Other beat it. [04:26.340 --> 04:26.820] What? [04:27.760 --> 04:28.240] Other. [04:28.560 --> 04:30.520] You were right in topics, you know. [04:33.180 --> 04:35.920] Yeah, it was not a good day for security. [04:36.180 --> 04:42.980] But, and then the second question was asking, gathering similar data, but asking it differently. [04:43.720 --> 04:50.180] I gave them six topics and had them order them in terms of importance with one being most important, six being least. [04:50.740 --> 04:54.360] And, again, algorithms and data structures is clearly number one. [04:54.640 --> 04:58.020] And software design is clearly number two, almost unanimously. [04:58.740 --> 05:03.660] The rest of it's a bit of a muddle, but security is ranked fifth more often than anything else. [05:05.240 --> 05:07.800] And then the same data a different way. [05:07.960 --> 05:10.160] I'm just showing the mean importance rankings. [05:10.360 --> 05:13.160] And, again, you can see security is fifth. [05:13.520 --> 05:15.740] Its mean ranking was 4.7. [05:19.110 --> 05:19.670] Okay. [05:19.910 --> 05:24.190] And then another question is, how integrated is security into the general curriculum? [05:24.190 --> 05:31.510] Like, if people don't seek out that specific security course, how likely are they to see any security content at all? [05:32.090 --> 05:44.630] And so here I had them rate their curriculum with one being security is totally separate, five being security is totally integrated. [05:44.630 --> 05:55.230] And you can see, out of the 33 responses, we've got 12 totally separates, 10 mostly separates, and only two totally integrates. [05:55.750 --> 06:01.010] So, you know, for the most part, undergraduates really aren't seeing security content. [06:03.350 --> 06:10.330] And then my last question was, how applied versus theoretical is that security content? [06:10.730 --> 06:16.110] So, I have, along the x-axis, the integration ratings from the previous question. [06:16.350 --> 06:24.410] And then for multiple topics, I asked them to rate things from one to five, where one was totally theoretical and five was totally applied. [06:24.710 --> 06:31.430] And so the answers were mostly twos to fours, because nobody teaches something that's totally one or the other. [06:32.030 --> 06:38.830] But the, what you can see here is it gets more applied as y increases. [06:39.450 --> 06:43.470] So, as things get more integrated, they become more theoretical. [06:43.910 --> 06:51.290] In other words, when you start integrating security into the general curriculum, the security content gets dumbed down. [06:53.210 --> 06:59.110] So, and overall, security was the second most theoretical topic. [06:59.110 --> 07:02.070] The only thing that was more theory was algorithms. [07:04.310 --> 07:08.550] So, none of this is great, but none of it's that surprising either. [07:08.770 --> 07:10.190] Where does this leave us? [07:10.550 --> 07:14.450] Is that security is not highly prioritized. [07:14.690 --> 07:23.690] And it, when it is integrated into the curriculum, which is rare, it's usually in a more theoretical, abstract form. [07:23.690 --> 07:28.410] So, you know, that's why we're in the state we are in general. [07:29.250 --> 07:33.630] This just is a natural extension of how we teach the subject. [07:35.430 --> 07:43.050] And, like I said before, we have these separate security classes for students specifically interested in security. [07:43.450 --> 07:45.310] But, one, you're preaching to the choir. [07:45.410 --> 07:47.250] These are people who chose to take that class. [07:47.250 --> 07:49.590] They already value security to some extent or another. [07:49.590 --> 07:52.930] And that's, those are your future experts. [07:53.210 --> 07:55.250] That's not your average graduate. [07:55.250 --> 08:02.250] And that's not the people who keep putting out the terribly buggy stuff that causes all these problems. [08:02.890 --> 08:08.650] So, what we need is to integrate security into all these other courses. [08:09.090 --> 08:13.370] Security is a natural facet of pretty much every computer science topic. [08:13.370 --> 08:15.430] And it should be taught that way. [08:17.790 --> 08:19.890] This sounds like a pretty tall order. [08:20.190 --> 08:26.130] So, before I go too much further into it, why do I think this is worth it? [08:26.210 --> 08:27.330] And why do I think it will work? [08:28.010 --> 08:30.990] Because it worked in environmental engineering. [08:32.550 --> 08:36.010] So, at first this seems like a pretty big left turn. [08:36.430 --> 08:41.590] But environmental engineering and security actually have really similar origins as fields. [08:41.590 --> 08:46.370] In both cases, we had a lot of problems of a particular class. [08:46.590 --> 08:49.530] And then we made a field to address those problems. [08:49.850 --> 08:54.290] So, the fields themselves are, to some extent or another, afterthoughts. [08:54.850 --> 08:57.870] You know, it was just the whole, oh, this is all made of poison. [08:57.890 --> 09:00.090] We should figure out how to deal with that. [09:00.770 --> 09:00.910] You know? [09:04.070 --> 09:13.650] And so, the afterthought problem is just part of the natural growing pains of squeezing this new field into how we think about the overall subjects. [09:13.970 --> 09:16.450] But environmental engineering has been around longer. [09:16.630 --> 09:20.530] So, they've made more headway against their own afterthought problem than we have. [09:20.790 --> 09:22.830] And we can try and make use of that. [09:23.250 --> 09:25.810] And speed our integration up. [09:26.570 --> 09:42.790] The most interesting development there recently is that the Accreditation Board for Engineering and Technology added a one-line change to their requirements for accredited mechanical engineering and chemical engineering and all sorts of engineering fields. [09:43.470 --> 09:50.490] So that now, undergraduates need to come out with the ability to evaluate their designs for environmental impact. [09:51.070 --> 09:53.250] And it really is a one sentence change. [09:53.250 --> 09:57.610] But in terms of curriculum design, it's a really big deal. [09:57.610 --> 10:00.470] And people had to scramble a little bit to deal with this. [10:00.890 --> 10:15.830] But it makes sense because, you know, just like with security, if all those engineers are totally unaware of the environmental aspects of design, then they're going to keep putting out things that are causing all sorts of problems. [10:15.950 --> 10:21.390] And then the experts are just dealing with those messes instead of dealing with problems that are actually worthy of them. [10:24.530 --> 10:30.350] And so they had to change all these programs to deal with the new accreditation board requirements. [10:30.890 --> 10:34.530] And it's actually really changing attitudes. [10:35.390 --> 10:44.570] I have friends with an environmental engineer who was telling me that over the years he gets contacted periodically by students with questions about his previous publications. [10:44.910 --> 10:49.690] And it used to be that all those people were environmental engineer students. [10:49.690 --> 10:53.950] But now half the time they're environmental engineering students. [10:54.190 --> 10:58.830] But sometimes they're mechanical engineers or chemical engineers or even MBAs. [10:59.370 --> 11:04.850] And it's not that they're doing some special program or a minor or something like that. [11:04.850 --> 11:06.430] It's just part of their normal coursework. [11:07.230 --> 11:09.210] And, you know, he's thrilled by this. [11:10.110 --> 11:14.770] The other reason why attitudes are changing there is because of legislation. [11:14.770 --> 11:18.430] There's more and more laws coming out. [11:19.550 --> 11:21.950] I guess maybe more in the EU than here. [11:22.130 --> 11:27.610] But we're catching up, you know, legislating environmental aspects of manufacturing. [11:27.790 --> 11:30.350] You know, what are you allowed to put in your batteries and things like that. [11:30.950 --> 11:39.990] And it's becoming more of a liability for companies to hire engineers who don't know how to evaluate their designs for these sorts of issues. [11:39.990 --> 11:46.950] Because then they might run afoul of these laws and, you know, run into big expenses later. [11:48.110 --> 11:52.670] And right now there isn't an equivalent to this in computer science. [11:52.830 --> 11:55.710] But we shouldn't assume that's always going to be the case. [11:55.830 --> 12:05.990] Especially the longer security becomes the huge problem that it is, the more likely somebody's going to try regulation as a remediation tactic. [12:05.990 --> 12:08.910] And, you know, so, but... [12:09.610 --> 12:17.470] And as environmental design becomes more of a priority for employers, it becomes more of a priority for educators. [12:17.930 --> 12:20.470] Because, you know, you want your students to be able to get jobs. [12:22.550 --> 12:27.670] And then the other thing is that this isn't even really true just for engineering. [12:28.110 --> 12:30.970] One of my cousins is studying industrial design. [12:30.970 --> 12:39.330] And we went to go see this open house they were doing where all the students showed the projects they'd made for this class. [12:39.570 --> 12:47.270] And when they were all running through their checklist of the design features, one of the things all of them mentioned was how sustainable was it? [12:47.330 --> 12:48.550] How much waste was produced? [12:48.930 --> 12:53.190] How, you know, what is the environmental impact of manufacturing this thing? [12:53.190 --> 12:55.890] And it's not like the class was focused on that. [12:56.030 --> 13:00.110] It's just they've been taught that's something you have to think about in the design and prototype stage. [13:00.530 --> 13:03.450] Because it's too expensive to fix those problems later. [13:04.210 --> 13:07.870] And, you know, they don't come to that conclusion on their own. [13:07.930 --> 13:09.150] It's just because it's taught that way. [13:09.270 --> 13:11.530] And that's what we need in computer security. [13:11.890 --> 13:16.770] We need educators to make it clear to students that this is a priority. [13:16.770 --> 13:21.450] And, you know, that they learn the right habits earlier rather than later. [13:21.650 --> 13:23.170] And it's totally doable. [13:24.570 --> 13:26.610] But is anyone doing it yet? [13:27.450 --> 13:29.590] As far as I know, no. [13:29.750 --> 13:38.910] I mean, if you have any examples of this where people are teaching a fully integrated curriculum, then I'd love to hear about it and we can do that in the questions. [13:39.070 --> 13:41.750] But I wasn't able to find anything myself. [13:42.930 --> 13:48.230] And, you know, because I hadn't seen this idea presented anywhere else this morning, that's part of why I'm here doing this. [13:50.370 --> 14:01.850] But, and I also, when I couldn't find any curriculums that were actively taught doing this, I looked for, you know, policy documents or, you know, reports or curriculum guidelines and whatnot. [14:02.150 --> 14:07.550] And the closest thing I was able to find so far was the ACM CS 2013 guideline. [14:10.030 --> 14:15.090] So, ACM puts out a curriculum guideline every few years, the most recent one being the 2013. [14:15.690 --> 14:24.850] And this was actually the first year that they had a security knowledge area, which is pretty embarrassing, although at least they got there. [14:27.870 --> 14:35.770] And when they introduced it, they know that undergraduates always, already have to take a lot of courses and they didn't want to add to that number. [14:35.770 --> 14:41.550] So, they decided the best way to get that security content in there was to integrate it into all the other classes. [14:41.550 --> 14:46.370] So, it was the most integrated curriculum I've seen so far. [14:46.510 --> 14:51.690] And it wasn't bad, although they were integrating it for the, not maybe the right reasons. [14:52.030 --> 14:55.190] Like, they didn't understand why integration is a goal in and of itself. [14:55.630 --> 15:02.470] So, there's a few spots where things are included in a familiarity level rather than usage. [15:02.470 --> 15:06.270] And students need to use things in order to understand them. [15:06.750 --> 15:14.490] And a few cases where things were labeled as elective rather than core that really should be core skills. [15:14.710 --> 15:18.990] So, it's the best thing I've seen so far, but still needs work. [15:18.990 --> 15:33.150] And the biggest issue I had with it, not to beat it up too much, was that in the software engineering section, they describe secure software engineering as a non-functional requirement. [15:35.010 --> 15:37.870] And that is a real problem. [15:38.030 --> 15:42.170] I mean, it's one word, you know, so maybe you'd say I'm being too picky. [15:42.170 --> 15:44.570] But the... well, maybe not you guys, but... [15:46.790 --> 16:00.830] But that gets to the heart of the whole problem, which is this notion that we teach our students that if they give it this number and it outputs that one, then the code works. [16:01.730 --> 16:05.970] And, like, that for all their homeworks, that's how it's evaluated. [16:06.250 --> 16:10.550] We give it certain inputs, if it gives the right outputs, then you get the green check mark. [16:10.550 --> 16:21.650] And what you need to do is also have, you know, robustness and security as required features on all those homeworks. [16:21.730 --> 16:30.930] You know, the notion that... they need to learn that code only works if it also is robust and doesn't put its users at risk. [16:31.350 --> 16:35.390] That without those features, it doesn't get the green check mark. [16:38.270 --> 16:42.270] But, anyways, so, moving on from that. [16:44.250 --> 16:50.190] So, when I talk about this initially, it sounds like a redesign of the whole curriculum, which is pretty intimidating. [16:50.430 --> 16:52.910] But it doesn't always have to be huge changes. [16:52.930 --> 16:55.890] It can just be little tweaks to things. [16:56.450 --> 17:02.270] So, I took a couple homework assignments from classes that are actively taught. [17:02.270 --> 17:04.890] This first one's from UC San Diego. [17:05.590 --> 17:07.590] And it's from a networking class. [17:07.790 --> 17:09.070] So, they're talking about BGP. [17:09.390 --> 17:18.950] And they give them this network diagram and ask them various questions that are supposed to demonstrate the student's understanding of how BGP works. [17:19.150 --> 17:24.110] You know, so, if E wanted to get to B, what path would it take? [17:24.110 --> 17:26.710] Or, if F wanted to get to C, what path would it take? [17:26.870 --> 17:33.990] Or, if AS3 doesn't want its traffic to traverse AS4, how would they do that just using BGP? [17:34.150 --> 17:39.110] So, it's just things that illustrate the knowledge of the features of BGP. [17:39.410 --> 17:46.410] What's missing is the knowledge of the limits of BGP or the knowledge of the weaknesses of BGP. [17:46.410 --> 17:55.510] Because, the whole notion that we, for every tool we provide them, only teach them about its positive aspects is, frankly, ridiculous. [17:57.190 --> 18:01.630] So, you should also ask questions about traffic hijacking. [18:01.850 --> 18:07.050] You know, if AS1 wants to hijack traffic that's going to AS7, what would they advertise? [18:07.050 --> 18:17.170] Or, how can you make use of various well-meaning but misguided features of the tool? [18:17.390 --> 18:24.310] You know, like, this is something that students need to think about so that they just learn this particular mode of thought. [18:24.750 --> 18:34.330] And, you know, the first step to being able to evaluate the security impacts of their own designs is to be able to evaluate that in previous designs. [18:34.330 --> 18:38.510] It needs to be a skill they build up and this is how you would do that. [18:41.590 --> 18:44.710] Then, my second example problem is from an algorithms class. [18:44.930 --> 18:53.550] And this was just a really simple hash table problem where they're given a mod 13 hash function to apply to letters of the alphabet. [18:54.130 --> 19:00.350] And here, you don't even really have to change the question at all because they were already asking about worst case run times. [19:00.530 --> 19:07.790] It's just that when we talk about worst case run times in algorithms class, we present it as the thing that happens if you had really bad luck. [19:09.310 --> 19:15.850] And, you know, bad luck can be manufactured and that's something that they need to understand. [19:16.110 --> 19:22.070] You know, a worst case run time isn't just your bad day, it's also an attack vector. [19:22.870 --> 19:27.170] And, you know, that's the thing that... and so it's the same question. [19:27.170 --> 19:28.530] You just need to word it differently. [19:28.950 --> 19:38.010] You know, you need to present it as if an attacker wanted to slow operations down, what's the longest run time their denial of service attack could force? [19:38.450 --> 19:40.850] And how would you try to avoid that? [19:41.010 --> 19:47.290] And, you know, it's just getting them to think about the exact same things but with a different spin that puts them in a different mindset. [19:50.590 --> 19:52.790] Okay, so what needs to happen? [19:53.810 --> 20:04.090] One, security needs to be a part of every course because every computer science topic has security implications and security aspects to it. [20:04.330 --> 20:10.130] And taking those all out into some separate course is great, but it also needs to be there in the basics. [20:11.530 --> 20:14.490] And introducing a concept once isn't enough. [20:14.730 --> 20:18.650] You know, just saying, oh, we talked about that in that lecture, not good enough. [20:18.990 --> 20:22.610] You need to repeat things frequently in order for them to become reflex. [20:23.390 --> 20:33.130] And so every time you have a homework where students are programming, you know, security and robustness need to be on the required checklist. [20:33.470 --> 20:40.170] And every time you're discussing how a protocol works, you need to talk about its weaknesses and how it doesn't work. [20:40.710 --> 20:49.990] And every time you talk about worst case run times, you need to talk about how those can be manufactured and what things can you do to prevent that from being possible. [20:50.850 --> 20:59.770] You know, the...it's just about repetition and making sure that these things are drilled into the point where they just think about it by default. [21:02.390 --> 21:05.330] So...and the other thing is that this needs to be applied. [21:05.330 --> 21:06.590] You need to do it in the homework. [21:06.750 --> 21:13.830] It needs to be something that they've used and worked with because otherwise it's just not going to sink in. [21:15.790 --> 21:19.230] The...the best way to learn how something works is to learn how to break it. [21:20.490 --> 21:23.970] So, you know, this isn't even just about learning security. [21:24.170 --> 21:28.490] It's about them better learning about the things they're going to end up using later. [21:28.610 --> 21:32.550] You know, it improves their general understanding, not just their security understanding. [21:32.550 --> 21:43.070] And finally, this was actually something that was suggested to me by Ed Felton because they do this in one of the advanced programming classes over at Princeton. [21:44.930 --> 21:46.210] But...and it's great. [21:46.390 --> 22:00.190] Which is that anytime you have homework assignments that involve programming, whether it's security related or not, you should subject it to fuzzing and other automated security attacks and then the students lose points if they don't handle it well. [22:00.830 --> 22:06.010] You know, the students learn the best lesson through pain, at least a little bit. [22:06.570 --> 22:17.870] And, you know, if there aren't any penalties for failing at security in school, then they're not going to think there's any penalties for doing it badly when they leave school. [22:20.690 --> 22:21.290] Okay. [22:21.290 --> 22:26.370] So...and once again, it's important that it's application, not just theory. [22:26.630 --> 22:29.950] I mean, conceptual understanding is a great first step. [22:29.990 --> 22:34.330] But what makes something real to a student is working with it and using it. [22:34.470 --> 22:37.070] So it has to be put into practice. [22:38.370 --> 22:45.870] And as security becomes a bigger part of the curriculum, it's important to also teach people how to do security research legally and safely. [22:46.770 --> 22:52.990] Like, people who already have good security programs create sandboxes for their students to play around in. [22:53.510 --> 22:55.930] And that's great. [22:55.930 --> 23:01.390] But you also need to make sure that your students know what makes that sandbox different from the real world. [23:01.590 --> 23:06.530] What went into making it so they can make their own when they're not in your careful care anymore. [23:06.530 --> 23:12.170] And, you know, just understanding that it's a manufactured environment. [23:12.990 --> 23:16.350] Because, you know, intellectual curiosity is great and to be encouraged. [23:16.410 --> 23:26.850] But if people don't understand that that sandbox isn't the same as the real world, then sometimes they come out with a kind of, hey, what does this button do mentality that can get them into trouble later. [23:27.330 --> 23:31.310] And, you know, part of being a good educator is making sure your students are safe. [23:33.390 --> 23:38.010] But anyways, it's a little bit of a diversion, but I think an important one. [23:39.290 --> 23:49.170] Okay, so tweaking the core curriculum can have a big impact if we do it right and if we understand what end goal we're working towards. [23:50.750 --> 23:59.950] And folding security into the existing courses means you don't need to lose any other topics, make room for it, and it'll give the students a better understanding of those core topics. [24:00.890 --> 24:06.450] The way people are first taught to think about something is how they'll likely always think about it. [24:06.590 --> 24:09.390] It's really hard to change thought patterns after they've been set. [24:10.170 --> 24:20.610] And so anything that just tries to course correct and add security in after all those behaviors and bad patterns are there is going to be a losing battle. [24:20.750 --> 24:24.610] It's just way too much work and you're fighting against too much. [24:25.450 --> 24:30.670] So the only way to make security integral in people's work is to make it integral in their education. [24:33.090 --> 24:45.230] So back to that accreditation board thing, this one change in the curriculum requirements made a really big change in how this stuff is taught and how educators think about the topics. [24:45.230 --> 24:49.150] And it would just need to be a one-line change for computer science. [24:49.370 --> 24:54.450] Just computer science graduates must be able to evaluate the security of their designs. [24:54.830 --> 25:00.190] And just imagine if we had that, how much better this entire field would be. [25:02.990 --> 25:04.770] You'd find new things to do. [25:07.850 --> 25:12.570] I mean, you know, not everyone's going to always get it right, but at least they would be trying. [25:19.310 --> 25:24.650] And anyways, thanks my friend Neil for lending me that psychology of survey response book. [25:24.790 --> 25:25.190] It was great. [25:25.570 --> 25:31.110] And thank you to all the professors who answered my survey because it was the end of the semester and they did not have to do that. [25:33.150 --> 25:34.650] And on to questions. [25:44.060 --> 25:44.620] Thank you. [25:44.720 --> 25:45.320] Wonderful talk. [25:45.540 --> 25:45.920] Oh, great. [25:46.020 --> 25:46.100] Thanks. [25:46.100 --> 25:47.840] And I've been waiting to hear this stuff for years. [25:51.020 --> 25:56.460] One of the problems is that engineers have accreditation boards. [25:56.620 --> 25:57.300] They have licenses. [25:57.800 --> 26:01.440] There is no such comparison for people who work with computers. [26:01.440 --> 26:09.260] You can pick up anybody off the street who learned programming from the back of a 1993 Pascal book or something. [26:10.620 --> 26:17.940] And programming is the kind of thing that you can pick up pretty easily and actually get halfway decent results long before the problems turn up. [26:18.060 --> 26:29.580] So have you thought about how we could apply these things in a way that will actually stick and stick to not just the people who are accredited, but everybody else's programming. [26:29.740 --> 26:33.560] Because there's plenty of people programming there without degrees in CS or anything else computer related. [26:33.820 --> 26:52.860] I believe the first step, you know, if we don't have that accreditation board boost to get people motivated, is to find some professors who actually do understand security and get them working together to develop a new curriculum, you know, to update things, [26:52.980 --> 27:08.060] and then get buy-in from industry reps that have big hiring power by, you know, getting their seal of approval that we hire students from these programs before we hire students from the other programs. [27:08.200 --> 27:14.140] You know, it's something where it has to have money attached because that's why people do anything. [27:18.300 --> 27:23.840] So, funny, funny, you should be the worst example of, namely BGP. [27:25.700 --> 27:27.280] Well, it's an easy target. [27:27.420 --> 27:27.540] Right. [27:28.600 --> 27:29.100] Yes. [27:29.420 --> 27:32.200] And, you know, sort of a family habit. [27:32.760 --> 27:39.000] Well, you know, having taught BGP and pointed out the security thing is, yes, somebody else agrees. [27:41.400 --> 28:01.140] So, a fundamental problem with this change in the curriculum, and I don't have an answer, is how do you get the people who are doing the teaching, right, to, especially in some of the better schools, where you're not rewarded for teaching well, you're rewarded for how much grant money you bring in, [28:06.720 --> 28:08.540] to implement these changes. [28:09.040 --> 28:17.000] So, you know, those of us who have worked with security and teach occasionally, do this sort of thing, but... [28:17.000 --> 28:24.640] I do know that motivating any sort of major change with people with tenure can be a tricky proposition. [28:24.640 --> 28:33.500] And if you have any suggestions, they're welcome, but I think one thing is to get some grant money out there for doing this. [28:33.640 --> 28:42.120] There are organizations that would, you know, if the proposal was written right, give some grants for doing this sort of redesign. [28:43.260 --> 28:54.300] And then, I don't know, my best bet for the other thing, past that, is just to make it so that the students coming from these programs get hired. [28:54.300 --> 28:57.020] You know, like, to get buy-in from industry. [28:57.240 --> 28:58.700] But I don't... I don't know. [28:58.800 --> 29:00.000] Do you have any other suggestions? [29:00.140 --> 29:07.600] Well, that is... that's actually not a very good incentive, because there is such a lack of qualified individuals to hire already. [29:07.960 --> 29:08.060] Yeah. [29:08.180 --> 29:11.820] That we tend to overlook things like, oh, well, they didn't take a security course. [29:12.000 --> 29:13.100] Well, okay, they're learning. [29:13.340 --> 29:32.220] Well, and the other thing is that while we don't have the sort of legislation that they have for environmental engineering now, you know, there aren't laws that get a company in trouble if, you know, they fail miserably in their implementation, the longer things go the way they are, [29:32.300 --> 29:34.480] the more likely regulation is going to happen. [29:34.680 --> 29:38.680] So, at some point, it might just be something that people can't ignore anymore. [29:38.900 --> 29:39.920] I'm not saying we shouldn't do it. [29:40.020 --> 29:41.100] Well, of course we should be doing it. [29:41.720 --> 29:43.420] I'm just trying to figure out how to... [29:43.420 --> 29:47.780] And that's something I'm actively thinking on and trying to come up with approaches for. [29:47.940 --> 29:49.660] So, any input is welcome. [29:49.960 --> 29:52.840] But, yeah, it is a little hard to motivate. [29:53.080 --> 29:58.980] So, I think the first step is just to get people who are enlightened enough to be interested going as an example. [30:00.220 --> 30:02.440] You know, and then work from there. [30:02.640 --> 30:04.120] You know, you have to start somewhere. [30:04.420 --> 30:04.820] Thanks. [30:07.680 --> 30:08.080] Hey. [30:08.220 --> 30:08.420] Hey. [30:10.120 --> 30:15.280] So, as we're talking about some of this stuff and how it's important to, like, start off with this mindset. [30:15.860 --> 30:18.200] I just had, really not a question, but just a comment. [30:18.880 --> 30:27.460] I couldn't help but notice the similarities between this type of mindset of thinking about security and the mathematical proof concept. [30:27.660 --> 30:39.240] Because, you know, if you think about, like, okay, would you hire a graduate from a math school that all they had to do was figure out the right answer for a problem, but not say, here's why it's correct, here's why there aren't any holes in it, here's why it's not broken. [30:39.460 --> 30:39.740] Right. [30:39.740 --> 30:42.480] And that might be a useful metaphor in trying to pitch this to people. [30:42.480 --> 30:47.360] Because proofs are something that, like, you start out learning them in, like, geometry or something like that in sub-grade. [30:47.360 --> 30:52.360] And, like, they're just a completely different concept for you to wrap your mind around. [30:52.580 --> 30:58.380] And then, over time, you get used to that mindset and you get drilled into that this is the way that you have to think about things. [30:58.420 --> 31:00.140] And I think that there's a lot of similarities there. [31:00.260 --> 31:00.620] Yeah. [31:01.620 --> 31:04.960] The similarity to mathematical proofs works on a couple levels. [31:04.960 --> 31:07.800] Also because they don't have you prove something just once. [31:07.800 --> 31:15.800] They make you do it over and over again until you learn the patterns of it and you learn the sense for what direction you should probably go in initially. [31:16.220 --> 31:21.780] And, you know, part of that is just doing it enough to build up that instinct for it. [31:21.780 --> 31:30.440] And that's something that's needed in security, having, you know, done enough evaluations that you start to get that just internal sense of where you should probably start. [31:30.920 --> 31:33.900] And that's something that you can't just teach in one lecture. [31:34.080 --> 31:36.940] It has to be taught by doing it lots of times. [31:37.160 --> 31:41.300] And, yeah, so the mathematical proof analogy holds up very well. [31:41.500 --> 31:41.740] Cool. [31:42.100 --> 31:47.400] The only other thing I just wanted to comment on is you mentioned having people have, like, a place that they can do this. [31:47.500 --> 31:49.200] And I think that's really important. [31:49.360 --> 31:55.760] Like, for example, you know, at RPI we had operating systems teacher that taught us about fork bombs. [31:56.020 --> 32:02.180] But he said, hey, don't go and execute these on the RCS servers because they'll get mad at me for telling you guys. [32:03.060 --> 32:13.240] Giving people a place that they can experiment free of legal worries, free of worries that they're going to get in trouble for it, and say, hey, you know, here I've set up this process running on the server. [32:13.300 --> 32:16.440] See if you can, you know, inject SQL or something like that into it. [32:16.580 --> 32:17.920] I think is definitely... [32:18.700 --> 32:33.700] And I have a couple of personal funny stories from cases where students had that safe environment but missed the don't do this at home part of the lecture, which is also important. [32:35.420 --> 32:36.840] Did you have a question? [32:38.280 --> 32:40.160] Well, I have a comment. [32:42.200 --> 33:05.080] As I was watching your talk, I was kind of thinking I'm a little pessimistic about the state of the industry because I think the priority for a lot of working programmers is, like, just get something working, get something sellable, get something that your boss will get off your back about. [33:05.860 --> 33:11.940] And then, you know, at the end, worry about security if there's any extra budget, and there never is. [33:12.500 --> 33:18.860] Yeah, and I understand that schedule crunches and everything do lead to a lot of sloppy habits. [33:18.860 --> 33:26.240] But the way to address that is to change their internal definition of what does working mean. [33:26.640 --> 33:35.280] You know, to make it so that their does it working question isn't yes until they've actually considered the security of their design. [33:35.560 --> 33:40.800] And, you know, that's the part where I think education comes in. [33:40.800 --> 33:46.060] I mean, I think they just need to redefine that word. [33:47.720 --> 33:52.640] And, yeah, I mean, employers need to also, which is also a thing. [33:52.840 --> 33:53.260] But, yeah. [33:54.480 --> 34:10.780] Yeah, and to kind of underscore your own point, if you teach somebody this from day one, and they're going to stick with it for their life, then, you know, we'll get better quality software, and everybody will be happy with it. [34:11.220 --> 34:12.420] Yeah, I mean, it's just... [34:12.420 --> 34:15.360] So, I'm glad that you're thinking about this, because I don't have the time. [34:16.820 --> 34:18.040] Well, I'm doing my best. [34:19.620 --> 34:19.980] Thanks. [34:20.960 --> 34:21.580] Thank you. [34:23.420 --> 34:25.000] Well, I also want to thank you for this. [34:25.160 --> 34:26.540] This is very good. [34:27.420 --> 34:30.100] I'm teaching at a college, and I'm living with this all the time. [34:30.220 --> 34:30.480] Uh-huh. [34:30.600 --> 34:34.920] And, Dan Kaminsky said something about two years ago at a conference that really caught my attention. [34:35.040 --> 34:37.740] He said, go to developer cons and talk to those guys about security. [34:37.920 --> 34:40.400] So, I started doing that, and I was horrified. [34:40.820 --> 34:43.240] They just have no clue at all. [34:43.400 --> 34:47.960] They're up there afterwards telling me that one round of MD5 is fine for a password, and what am I talking about? [34:48.280 --> 34:54.420] And, um, the talk I just submitted said there is nothing in this talk that is not 15 years old. [34:54.520 --> 34:55.580] And they improved it, and they're flocking in. [34:55.660 --> 34:57.720] And I say, it's madness. [34:58.120 --> 34:58.480] Yeah. [34:58.680 --> 35:00.260] And I think this is what's going to change it. [35:00.420 --> 35:01.960] I mean, real convincing presentations like this. [35:01.960 --> 35:03.780] The curriculum stuff might be good too. [35:04.000 --> 35:04.940] I'm not, that's my appeal. [35:05.320 --> 35:07.480] But, um, I'm very impressed by this. [35:07.820 --> 35:11.460] And I, I see, um, there's another thing that I've seen happen because of this. [35:11.600 --> 35:14.400] The four-year colleges have no security in undergraduate at all. [35:14.600 --> 35:15.820] They think it's a master's curriculum. [35:16.020 --> 35:18.540] So, the effect is my students refuse to get four-year degrees. [35:18.880 --> 35:26.240] They cannot see any reason after a couple of classes, certifications, to not get in the field and get a job, and go get a degree which is as valuable for them as Latin. [35:27.520 --> 35:32.880] And what I'm seeing is, I don't understand, I can't convince them to get a four-year degree because I no longer believe it myself. [35:33.420 --> 35:37.300] I mean, I got a PhD, but as far as I can tell, there is no use for a four-year degree in the field of security. [35:37.580 --> 35:38.640] It's just a waste of your time. [35:38.860 --> 35:39.100] What do you think? [35:39.120 --> 35:45.080] And there's so much out there to learn, so we just, we need to make a curriculum that's worth their time. [35:45.420 --> 35:49.080] You know, wasting people's time is just, it's not right. [35:49.100 --> 35:52.420] And we need to make it worthy of being taught. [35:52.420 --> 35:59.660] Yeah, but there's something very strange here because the four-year degree has totally failed to notice that security is a problem. [36:00.280 --> 36:02.440] And how can anyone fail to miss that? [36:02.860 --> 36:04.420] I mean, how can they miss that? [36:04.540 --> 36:05.260] I'm confused. [36:05.440 --> 36:06.580] They've let themselves become obsolete. [36:07.260 --> 36:08.180] It's very strange. [36:08.380 --> 36:13.740] Well, and, you know, the way people learn things is the way they then teach them, so there's a certain amount of momentum. [36:14.020 --> 36:21.480] But whenever I was describing what my talk was about to people who weren't computer scientists, their first reaction was always, you mean they don't do that already? [36:21.820 --> 36:24.600] Like, it's always the, they're just shocked. [36:24.840 --> 36:28.000] And then they're, oh, well, I guess that's why I had to get a new Target credit card. [36:28.160 --> 36:29.920] You know, it's just the... [36:30.240 --> 36:31.880] No, you're absolutely right on the money. [36:32.000 --> 36:36.500] They do what they were told to in the book, they do what got them an A, and it's another generation of the same crap. [36:36.660 --> 36:37.200] We can all hack into it. [36:37.520 --> 36:39.260] Right, and of course they're going to do what we train them to do. [36:39.260 --> 36:40.840] I mean, it's just how it works. [36:41.100 --> 36:41.840] Well, thank you very much. [36:41.980 --> 36:42.340] Thank you. [36:43.720 --> 36:44.120] Hi. [36:46.200 --> 36:46.600] Hello. [36:46.900 --> 36:47.380] Oh, okay. [36:47.720 --> 36:49.660] So, good talk, first of all. [36:49.760 --> 36:50.020] Thanks. [36:50.280 --> 36:55.040] So this is not so much a question as a comment, but this is something I sort of thought about a decent amount. [36:56.420 --> 37:04.160] And part of it is just like, well, how do you like really effectively teach security even once it becomes a priority, because just by the nature of the subject, it's just a world of unknowns. [37:04.560 --> 37:20.360] But what I've sort of found in my experience is that there's a decent amount of overlap in terms of like just defensive programming and good programming habits, unrelated to security, that while improved security also improved the overall robustness and fault tolerance of the application. [37:20.460 --> 37:20.740] Oh, yeah. [37:20.740 --> 37:31.100] If you are, when you're accepting user input, you think like, not just because of security, but in terms of just general, this is how to make the software as robust and fault tolerant as possible. [37:31.240 --> 37:34.960] Right, because people are going to be using this and they do really bizarre things. [37:34.960 --> 37:43.760] So there's, it's almost doesn't exist like as this separate, like, like you say, as an afterthought, where you have to like, well, I've written it and now I have to evaluate it for security. [37:43.940 --> 37:48.160] Because if you're at that point, like maybe you just wrote kind of shitty code. [37:48.980 --> 37:59.380] And if you just, because it feels like in part of writing code that is robust and really handles all of the cases that you could really expect it, you can almost frame it in a different way. [37:59.380 --> 38:04.060] Not even in terms of security, but in terms of good defensive programming habits. [38:04.060 --> 38:04.580] Yeah. [38:04.680 --> 38:14.660] And I feel like that, in addition to giving people, like if they're learning to write software, the tools to write secure software, they're also just learning to write better software. [38:15.380 --> 38:18.740] So it's almost, it's the same thing, but sort of framed differently. [38:19.080 --> 38:20.700] But like I said, not really a question, but... [38:21.120 --> 38:21.540] Thanks. [38:22.160 --> 38:23.140] Liability is a subset. [38:23.980 --> 38:25.940] Security is a subset of reliability, really. [38:26.220 --> 38:30.240] Well, that's where PCI and companies that have to care about security. [38:34.350 --> 38:34.830] Hi. [38:35.010 --> 38:39.570] I was wondering of the 33 respondents, have you had a chance to share the data with them? [38:39.690 --> 38:43.790] And have they made any comments back, like apologies? [38:44.250 --> 38:57.550] Well, actually, part of how I got people to give me answers was that I said when I was done, I would send them the anonymized results so that they would have some sort of reason to respond to me. [38:57.550 --> 39:04.490] So I did send them all my responses, but that includes all the other questions I had that weren't security related. [39:04.770 --> 39:08.950] So I haven't told them why I was collecting the data or what the talk was. [39:09.050 --> 39:13.010] I was thinking maybe I'd send them a link now that it's out there. [39:15.650 --> 39:20.730] And, yeah, I don't know what the responses will be, but hopefully not too rude. [39:22.310 --> 39:24.890] Do you plan on sharing any responses? [39:25.210 --> 39:27.070] I mean, anonymized, of course, but... [39:27.070 --> 39:29.070] Oh, I don't know. [39:29.190 --> 39:41.610] I mean, I don't know what I would gain from that in terms of, I don't think it would make any friends or get me any extra buy-in from anybody, but it would probably piss somebody off that I need to deal with later. [39:42.670 --> 39:43.390] Fair enough. [39:43.550 --> 39:44.070] Thank you. [39:44.370 --> 39:44.910] But, yeah. [39:47.050 --> 39:47.690] Hi. [39:47.950 --> 39:48.510] Good talk. [39:48.810 --> 39:49.010] Thanks. [39:49.430 --> 39:53.790] So I'm an architect for enterprise software. [39:54.370 --> 39:58.630] One of the things that we've done is we've built our own training. [39:58.930 --> 40:08.190] It's pretty thorough, mainly because it doesn't seem to matter what level of education people have coming out of computer science. [40:08.370 --> 40:10.030] It's never the right stuff. [40:10.030 --> 40:13.890] And it's really usually around real-world application. [40:14.890 --> 40:28.470] One of the things I noticed, which we had the same problem in our area, I'm from the Cleveland, Ohio area, is there's always this misconception that non-functional requirements is a bad thing. [40:28.650 --> 40:30.990] It's really just a category of requirements. [40:31.050 --> 40:35.790] So functional meaning that it applies to the business of the software. [40:35.790 --> 40:43.290] So like we build financial software, so it, you know, functional requirements would relate to that financial stuff. [40:43.450 --> 40:53.770] So what we've done is we've tried to, we've been trying to be, some of the guys I work with, we've been part of this effort to try to rebrand it as quality factors. [40:55.030 --> 40:57.970] Because I think it calls out a little bit more what it's for. [40:57.970 --> 41:07.390] So when you talk about robustness or scalability or security and the other, you know, all those other topics, we brand them as quality factors. [41:07.570 --> 41:11.830] And I think, you know, I would encourage anyone out there to do the same thing. [41:11.830 --> 41:18.050] Because I think it makes it a little bit more clear that there are definitely factors of quality that apply to the software. [41:18.370 --> 41:18.510] Yeah. [41:18.770 --> 41:22.110] I mean, describing it as non-functional makes it sound optional. [41:22.110 --> 41:23.190] It sounds negative. [41:23.610 --> 41:23.730] Yeah. [41:24.030 --> 41:25.630] But there's still requirements, right? [41:25.750 --> 41:27.930] It's just non-functional requirements. [41:28.110 --> 41:31.110] Functional meaning applies to that business specifically. [41:31.730 --> 41:34.330] Non-functional meaning quality factor. [41:34.950 --> 41:35.670] But anyway. [41:35.970 --> 41:36.170] Yeah. [41:36.230 --> 41:36.790] It's a good tip. [41:36.950 --> 41:37.550] More of a comment. [41:39.830 --> 41:40.390] Hi again. [41:40.750 --> 41:41.250] I'm back again. [41:41.710 --> 41:47.550] So I just had one more thing that I, as I'm thinking about this, you know, I'm trying to think of like how I can help you sell. [41:47.770 --> 41:49.310] You know, how do you help sell this? [41:49.390 --> 41:49.870] How do you make it stick? [41:50.030 --> 41:50.090] Yeah. [41:50.090 --> 41:57.850] So one thing is, as people are talking about security and how they think about security, I couldn't help but think of like all these other things that are similar. [41:58.150 --> 42:03.870] So it pisses me off that I went through a four-year degree in computer science and nobody taught me about test-first design. [42:04.050 --> 42:04.590] No one. [42:04.750 --> 42:10.850] I didn't write a single unit test in four years of computer science degree. [42:11.130 --> 42:12.730] I had like a new Ivy screen. [42:12.930 --> 42:13.070] Right. [42:14.450 --> 42:20.010] So every day I write code and I don't write unit tests and I feel bad about it. [42:20.250 --> 42:24.670] Every day I write code and I don't think about security and I don't feel bad about it. [42:24.970 --> 42:26.290] That's I think where we need to change. [42:26.710 --> 42:28.790] Like I'm aware of that I should be doing code reviews. [42:28.870 --> 42:30.010] I should be doing TDD. [42:30.010 --> 42:32.270] I should be doing all these things. [42:32.750 --> 42:39.990] But security has, through one way or not, it hasn't made its way into my psyche as like, this is one of these things that I need to be doing. [42:40.190 --> 42:40.250] Yeah. [42:40.250 --> 42:47.150] So I think we need to rewrite computer science curriculum to teach test-driven design, to teach peer code review, to teach all these things. [42:47.210 --> 42:50.710] And I think like security is just, it's one of the major factors that needs to make in there. [42:50.710 --> 43:02.150] But I think a program that attempts to address some of these other places that the stuff that we're being taught in schools doesn't represent what you really need to do in the real world to build a quality product. [43:02.410 --> 43:02.810] Yeah. [43:02.810 --> 43:07.730] I think maybe putting security in there with these other things would help too. [43:08.150 --> 43:17.870] One of the, like the open-ended question at the end of the survey was one where I let people talk about what topics did they think were over or underrepresented in curriculums today. [43:18.650 --> 43:28.350] And a few people said that what they thought it was missing was the class that gives students the same experience they're going to have in the workforce. [43:28.750 --> 43:33.050] You know, the dealing with customers and doing the whole code development cycle. [43:33.410 --> 43:44.630] Of course, the same number of people exactly said that they thought that curriculums were getting too applied and needed to get back to including more of the theory and fundamentals. [43:45.030 --> 43:48.250] So, you know, a couple of different schools of thought there. [43:49.270 --> 43:52.510] But it is something that was already on a few of their minds. [43:52.650 --> 43:55.970] They just didn't necessarily include security in the list like you were saying. [43:56.310 --> 44:02.610] But if you said, like, okay, if I have the same functional requirements and you give me an extra time to do it, I'm probably going to add unit tests. [44:02.730 --> 44:05.410] I'm probably not going to say I'm going to spend that extra time on security. [44:06.010 --> 44:06.070] Yeah. [44:06.070 --> 44:08.690] I feel like it would be nice to have people start thinking about it. [44:09.670 --> 44:11.250] Did you have a question? [44:11.570 --> 44:11.730] Yeah. [44:11.990 --> 44:12.070] Yeah. [44:12.910 --> 44:14.370] First of all, that was a great talk. [44:14.570 --> 44:14.870] Thanks. [44:15.150 --> 44:16.070] I really enjoyed it. [44:16.870 --> 44:23.210] It seems obvious from listening to you that security needs to be a topic that is addressed in CS curriculums from day one. [44:24.410 --> 44:26.150] And I absolutely agree with it. [44:26.750 --> 44:34.070] What I'm wondering about is it seems like an easier topic to address as the curriculum gets more advanced. [44:34.070 --> 44:34.770] Mm-hm. [44:34.790 --> 44:39.110] But in the intro courses, it seems like it's a little bit harder to integrate. [44:39.270 --> 44:44.450] I wondered if you had specific ideas on how to integrate it with, like, say, like a CS1 course. [44:44.950 --> 44:51.930] Well, I mean, whatever technical content you're including, there's almost always a flip side to that coin. [44:52.830 --> 45:04.870] Like, just as you have to ramp up how technical the general CS content is, there have to be security components to it. [45:04.870 --> 45:18.330] I mean, even if it's just priming how they think about things so that they keep having that on their mental list of features. [45:18.610 --> 45:30.210] You know, that you keep mentioning security concepts enough that it becomes reflex that that's always part of that subject. [45:30.670 --> 45:43.630] You know, the, it's a little hard without specific examples, but, you know, the, but I think it's just important that you just keep it on their minds enough that they can't forget about it. [45:44.390 --> 45:54.050] You know, the, you know, the, I mean, everyone had topics in school that got repeated so often that they were like, oh, they're mentioning this again. [45:54.050 --> 45:56.070] How many times are we going to have to learn the same thing? [45:56.310 --> 46:02.070] And then later on you realize, oh, no, that's, I actually learned that one. [46:02.310 --> 46:10.390] Like, you know, the, it's, you know, as a student, you don't always understand why they keep beating that particular dead horse, but then later on. [46:10.630 --> 46:18.070] But I think it's just important to just keep mentioning it, even if you're not quite getting into the guts of things yet in that course. [46:18.070 --> 46:19.130] Okay, great. [46:19.310 --> 46:19.570] Thank you. [46:21.530 --> 46:24.590] So, uh, again, uh, very good talk. [46:24.730 --> 46:25.330] Thank you for that. [46:25.810 --> 46:27.730] Um, I'm with a company. [46:27.890 --> 46:30.090] We have around 800 developers. [46:30.250 --> 46:37.010] So, um, I'm actually dealing with the problem of having non-students. [46:37.210 --> 46:44.070] So programmers with years of experience also doing the very same problems. [46:45.810 --> 46:49.310] You know, the bad habits evolve over time. [46:49.550 --> 46:58.570] Um, and we also found that, um, for example, we use code scanners in, uh, some, uh, departments. [46:58.770 --> 47:06.650] And we can see when we get new employees by the number of bugs, it's, it's, it's directly related. [47:06.650 --> 47:11.190] And also this creates pain on the developer side. [47:11.350 --> 47:20.390] So if they have to fix, you know, annoying bugs, which are obviously non-functional bugs, uh, but they have to fix it. [47:20.510 --> 47:23.330] And it creates pain that changes the habits. [47:23.610 --> 47:23.810] Yeah. [47:23.950 --> 47:32.830] So it's more or less of, uh, um, you know, kicking asses the whole time, but it works. [47:32.950 --> 47:33.430] It works. [47:33.550 --> 47:36.630] And that's what I like on, on your, on your approach. [47:37.090 --> 47:37.490] Oh, thank you. [47:37.490 --> 47:41.650] With the, with the homeworks constantly checking for security problems. [47:41.950 --> 47:42.110] Yeah. [47:42.370 --> 47:42.650] Thank you. [47:44.350 --> 47:45.850] Don't forget to say it was a good talk. [47:46.210 --> 47:46.610] Yes. [47:47.530 --> 47:47.930] Yeah. [47:49.290 --> 47:51.530] It's like I'm posting to a hack on Usenet. [47:51.670 --> 47:53.310] I've got to like basically, oh, it's a good talk. [47:53.610 --> 47:55.050] And, uh, here's my OB hack. [47:55.210 --> 47:56.990] And by the way, here's my comment and question. [47:57.590 --> 47:59.870] Um, that's a little older than most of the folks here. [47:59.870 --> 48:11.510] Uh, environmental engineering wasn't mandated and put in until certain countries started to actually say, we are not accepting goods and services. [48:11.510 --> 48:13.750] And it started to have a particular impact. [48:13.910 --> 48:15.030] And this goes towards incentives. [48:15.030 --> 48:26.090] Uh, recently there was a ruling, and I think this was EU, um, where somebody said, uh, the company was held liable because the passwords were not encrypted. [48:26.290 --> 48:30.290] And that that liability became on the company rather than on the end users. [48:30.290 --> 48:42.050] So, the question here is, is there an incentive plan where we can get this in place as you mentioned, you know, kind of like out of the altruistic nature and getting the right professors? [48:42.490 --> 48:49.570] Or is it a case where we're going to have to wait for mandates and policy to come in and that this will happen naturally? [48:49.830 --> 48:57.170] I mean, it, eventually, if those sorts of mandates were in place, everyone would have to get whipped into shape. [48:57.170 --> 49:04.410] But it'd be nice to try to, um, do what we can to get there without being embarrassed into it. [49:04.730 --> 49:11.510] The, um, you know, the, just, just, I mean, nobody's really, as far as I know, tried this yet. [49:11.570 --> 49:13.990] So, it'd be nice to see if we can do it. [49:14.090 --> 49:23.330] And then, if everyone's too resistant and we can't get it in there, at least somebody, they have something to go back to whenever they're like, oh, shit, we need security now. [49:24.230 --> 49:24.670] Yeah. [49:24.670 --> 49:25.550] Thank you. [49:25.570 --> 49:25.990] Yeah. [49:26.190 --> 49:27.510] Can we get into that? [49:27.670 --> 49:32.890] I'm from the Netherlands and the parliament there have been discussing enforcing this stuff. [49:33.210 --> 49:33.410] Yeah. [49:33.830 --> 49:36.650] But it's impossible to do. [49:36.890 --> 49:38.450] I mean, who's going to do it? [49:39.330 --> 49:39.470] Yeah. [49:39.470 --> 49:40.210] That's the whole issue. [49:40.370 --> 49:42.330] That's why they didn't do it anyway. [49:42.790 --> 49:52.110] Well, and, um, whenever they do try to write some, uh, security regulations or legislature, there's nothing saying they'll do it right. [49:52.110 --> 49:53.930] But, you know, the, uh... [49:53.930 --> 49:55.650] Yeah, the enforcing part is the biggest issue. [49:56.030 --> 49:56.210] Yeah. [49:56.570 --> 49:58.490] Same thing happened in environmental engineering, too. [49:58.790 --> 49:59.530] A lot of pushback. [49:59.750 --> 50:00.130] Yeah, exactly. [50:00.190 --> 50:00.550] Yeah. [50:04.130 --> 50:14.310] There's lots of reasons why they're not doing it yet, but I think over time they'll end up just having to, uh, if it doesn't get fixed some other way. [50:14.550 --> 50:20.950] You know, they'll just, at some point it'll become too expensive for them to keep letting it go and they'll just try something. [50:21.490 --> 50:24.490] Whether it's the right something or not, I don't know, but... [50:24.490 --> 50:31.510] Um, oh, there's a hand over there, but, uh, why don't you go first since you're at the mic? [50:31.950 --> 50:32.210] Sure. [50:32.390 --> 50:32.570] Thanks. [50:33.150 --> 50:38.610] Uh, so I thought it was a great talk and, uh, it's probably gonna be my last talk of the night because I'm tired. [50:38.870 --> 50:39.710] Leave me on a good note. [50:39.870 --> 50:40.970] Why are you hopeful? [50:41.530 --> 50:47.490] Uh, aside from the Princeton thing, what have you seen that's been a good example of how schools do these kinds of things? [50:47.490 --> 50:55.630] Well, um, we've got several friends who are professors who try to do this in their little corners of the world. [50:55.970 --> 51:04.410] Um, uh, the, uh, um, the, actually West Point has a surprisingly good, uh, security, uh, program. [51:04.770 --> 51:13.250] And, uh, one of the professors from over there, um, was involved in getting what security content there is integrated into that ACM document. [51:13.250 --> 51:26.290] Um, and, uh, uh, we've, uh, um, Alex Halderman over at University of Michigan and, uh, um, Matt Blaze over at UPenn have both expressed interest in that. [51:26.430 --> 51:29.470] And with names like that attached, we could actually really do something. [51:29.490 --> 51:35.990] So we need to, I don't know, get on them and try and, uh, get them to do something more than say nice things. [51:35.990 --> 51:43.630] But, uh, they have expressed interest in it and, uh, um, they do try to teach these things in their little corners of academia. [51:44.650 --> 51:49.210] Um, but, uh, any other positive examples that people want to point to, point me to? [51:49.330 --> 51:56.330] I'd love to see because it would be nice to gather together all those like-minded people, pool efforts. [51:57.130 --> 51:58.770] Um, what was your question? [52:00.930 --> 52:02.670] I am married to him. [52:05.010 --> 52:06.490] Yes, I'm married to Mudge. [52:06.970 --> 52:10.510] He and I had a discussion, like, 15 or 20 years ago. [52:10.790 --> 52:11.890] Okay, well... [52:13.690 --> 52:16.670] I had started as a computer security major in 2003. [52:17.830 --> 52:19.410] I just recently left the position. [52:19.710 --> 52:23.730] But, um, the person you want to talk to is really Gene Stafford at Purdue. [52:28.050 --> 52:29.990] Mudge might have issues with that statement. [52:30.090 --> 52:31.230] I'm Mudge, but I don't endorse that. [52:33.970 --> 52:42.950] And the reason why is the big problem is we still have absolutely no idea how to define security in any kind of quantifier that may affect me. [52:43.630 --> 52:50.730] Well, and any effort to change how this curriculum gets designed would be, um, you'd have to quantify the success. [52:50.910 --> 52:53.730] So you'd have to, uh, oh, is it, is my time up? [52:53.910 --> 52:54.450] One minute. [52:54.450 --> 53:03.730] Okay, so you'd have to do some, uh, like, give the students some tests to take beforehand that show some particular level of security knowledge. [53:03.910 --> 53:07.990] And then after they've, like, you know, the next class goes through with the new curriculum. [53:08.170 --> 53:15.910] Like, you'd have to do something to show that you had quantifiable success with the redesign or else nobody has any reason to fund you. [53:16.290 --> 53:23.010] Uh, the, uh, um, you know, and, you know, just, uh, well, data's always good. [53:23.230 --> 53:23.770] I like data. [53:24.110 --> 53:25.910] Um, but anyways, my time's up. [53:26.170 --> 53:32.530] So anyone else who wants to talk, we can do that, uh, uh, elsewhere, uh, so that the next talk can get going. [53:32.530 --> 53:34.150] Thank you. [53:34.150 --> 53:34.770] Thank you. [53:39.920 --> 53:40.780] Thank you.