Protecting GitHub’s 100M Developers | Jacob DePriest VP, Deputy CSO

12 Dec 2023 · 37 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Dev Interrupted Podcast Episode Summary

Episode Information

  • Podcast Title: Dev Interrupted
  • Episode Title: Protecting GitHub’s 100M Developers
  • Host: Conor Bronsdon
  • Guest: Jacob DePriest, VP and Deputy Chief Security Officer at GitHub
  • Description: This episode explores GitHub's security measures, focusing on protecting over 100 million developers on its platform, the role of AI in security, and strategies for fostering customer trust while advocating for diversity in security teams.

---

Key Concepts & Discussions

Introduction to GitHub's Security

  • Role of Jacob DePriest: Jacob discusses his transition from the NSA to GitHub, emphasizing his experience in cybersecurity and the evolving landscape of security threats.
  • Security at GitHub: The internal security team is responsible for safeguarding user and product security, overseeing incident response, threat intelligence, and governance.

AI's Impact on Security

  • AI in Development: Jacob highlights how GitHub Copilot enhances developer efficiency by streamlining coding processes and reducing security risks through better code suggestions.
  • Future Prospects: AI is expected to shift security practices further left in the development workflow, allowing developers to focus on more complex challenges.

Trends in Cybersecurity

  • Security as a Differentiator: Companies are evaluated on how effectively their security teams handle threats, with customer trust becoming paramount.
  • Diversity in Security Teams: A diverse security team can bring varied perspectives, enhancing problem-solving and overall effectiveness in tackling security challenges.

Fundamental Security Practices

  • Focus on Fundamentals: Jacob emphasizes the importance of implementing basic security measures such as multi-factor authentication and regular security training for developers.
  • Collaboration with Engineering: Close partnership between security and engineering teams is crucial for building secure systems, ensuring that security integrates seamlessly into the development process.

Policy and Compliance

  • Policy as Code: The importance of understanding compliance implications and integrating them into development practices is discussed.
  • Continuous Compliance: Ensuring systems are compliant from the outset simplifies future audits and fosters a culture of security-first development.

Future Outlook

  • Emerging Threats: Jacob discusses the need for ongoing vigilance against evolving cybersecurity threats, particularly from nation-state actors.
  • Public-Private Partnerships: Collaboration between public institutions and private companies is essential for improving overall security in the tech ecosystem.

---

Advice for Engineering Leaders

  1. Engage with Security Teams: Develop strong relationships with security partners to understand their concerns and integrate their insights into the development process.
  2. Prioritize Fundamental Security Practices: Implement basic security measures rigorously to lay a strong foundation for more advanced security strategies.
  3. Embrace Continuous Learning: Encourage security training and knowledge-sharing to keep teams informed about potential threats and best practices.

---

Closing Thoughts

  • Jacob reinforces the importance of bringing security to the developers' workflow, asserting that effective collaboration can significantly enhance security measures while maintaining developer productivity.
  • The conversation concludes with a call to action for engineering leaders to prioritize security as an integral aspect of their development strategy.

---

Additional Resources

  • DORA Metrics Dashboard: [Get your free DORA dashboard](https://linearb.io/resources/free-dora?utm_source=Dev%20Interrupted&utm_medium=referral&utm_campaign=Dev+Interrupted+Podcast+-+Free+DORA)
  • DevOps Dozen Voting: [Vote for Dev Interrupted](https://devopsdozen.com/)
  • LinearB Free Trial: [Start Free Trial](https://linearb.io/start-free-trial?utm_source=podcast&utm_medium=referral&utm_campaign=devint-shownotes&utm_content=shownotes)

---

This summary encapsulates the key discussions and insights from the episode, providing a comprehensive overview of the critical role of security at GitHub and the evolving landscape of cybersecurity in the software development industry.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Internal security teams are starting to become a business differentiator as well for companies. So how your security team approaches threat actors, be they nation state or crypto miners or whatever it is, and how they talk about it, how they disclose it, what's the tone in the blogs, how quick is it, how transparent is it? But these things are starting to become not just nice to have, but expected from security teams and start to be things that like if you're evaluating a set of vendors for a choice to come help you out, you start to think about like, well, how are they approaching this? How do they tackle the security challenges and how do they think about it?

0:38And is that a team I want to partner with when things go bad? Because something's going to go bad. At some point. And who are you going to partner with to do it? Right. And so I think that's an interesting trend that I think we're seeing as well. Is your engineering team focused on efficiency but struggling with inaccessible or costly Dora metrics? Insights into the health of your engineering team don't have to be complicated or expensive. That's why Linear B is introducing free Dora metrics for all. Say goodbye to spreadsheets and manual tracking or paying for your Dora metrics. Linear B is giving away a free, comprehensive Dora dashboard packed with essential insights, including all four-key Dora metrics tailored to your team's data, industry standard benchmarks for gauging performance and setting data-driven goals, plus additional leading metrics including merge frequency and pull request size.

1:25Empower your team with the metrics they deserve. Sign up for your free Dora dashboard today at linearb.io slash Dora, or follow the link in the show notes. Hey, everyone. Welcome back to Dev Interrupted. I am your co-host, Connor Bronsden, and I'm delighted to be joined by Jacob DePriest. He is the VP and Deputy Chief Security Officer at GitHub. Jacob, welcome to Dev Interrupted. Yeah, thanks for having me. and really excited to talk to them. It's going to be a lot of fun. I've heard some incredible things like you help protect us from North Korean hackers. You spent 15 years at the NSA before your work at GitHub on the security side of things.

1:57And there's such an evolving threat area in this space currently and also opportunities. So very excited to dive in. And GitHub is obviously a company that needs no introduction to our audience. It's home to over 100 million developers and you're really responsible for leading the teams that keeps the platform, product and users, as well as customers safe. So I know you started that DevSecOps career long before GitHub with the NSA. And because of that experience, you're kind of the perfect person to talk to about how AI and these other trends are impacting the security space. You're joining us today live here at DevOps Enterprise Summit.

2:31If you're watching on YouTube, I highly recommend it. We're here in the DevSecOps Dome. It's a ton of fun. And you also gave a presentation, I believe today, on how AI is impacting developers through capabilities like GitHub Copilot, how AI is evolving the security space, and suggestions on how to move security into an AI-assisted future. So, I mean, that's the hot topic, right? Let's just dive in right there. Tell us about your talk. Yeah, so we started today talking about how DevOps and security really mix together and need to happen together, right? We can't have security without DevOps. As we think about the biggest security challenges that a lot of companies are facing, a lot of them tie back to the software development process, developer accounts, account security, they tied to supply chain, right?

3:18It's not just an easy way to point and say, like, there's this one area we got to focus on. It's the whole thing. And so, you know, today we talked through how all those things fit together and then a little bit of GitHub's journey, a little bit of my journey, and then how now that we have things like GitHub advanced security at GitHub, we've really been pushing to shift security left in the developer workflow. What's that look like now in 2023 and beyond as we're integrating AI into, you know, many aspects of the software development lifecycle. Yeah, I'll share. I previously worked in the Microsoft Services Organization on the cybersecurity, particularly around the thought leadership of what's coming trend-wise.

3:55And it's so interesting for me, having left that org, you know, four or five years ago now, to see these trends that we were seeing, the research that we're seeing, the things that people are thinking about start to be really real, particularly with AI, Copilot, all these new things coming out of GitHub. I'd love to get an overview from you around what security looks like at GitHub today. Yeah, so we kind of have, when I think about security at GitHub, I think about it as kind of two different angles. One is sort of internal and product facing, and then the other is what we are providing to the open source community and to our customers.

4:27And so on the internal side, that's the team I'm responsible for. We are running the day-to-day internal security for GitHub. And so that is things like our security operations team, so incident response, threat intelligence, threat detection and response, counter abuse. We have an amazing counter abuse team, you know, our identity and access management team, all that's in that security operations space. And then we have our product security team, and they're focused on making sure that the products that we ship out to customers and the community are safe, secure, and continue to be operated that way.

4:59And then we have our governance risk and compliance team, which is working through our company risk. They're working through our compliance programs, all our certifications. And then finally, we have a really interesting team, which I love being part of the security team and being part of GitHub is our security research team. They're really focused out at the community. So they're taking the tools and the talent that they have. We have some world-class researchers on the team. And they're going out and working with open source community, other researchers at other companies and universities. And they're looking for trends in vulnerability spaces.

5:29They're learning how to use things like CodeQL, which is our static analysis tool at GitHub as part of GitHub Advanced Security. And how to apply that at scale or at very specific popular open source packages and really kind of like raise the level of the security in the open source ecosystem. Thank you for that great overview. I'd love to dive into the research piece to start off. Yeah. Can you share a bit about what's been happening on the research team and what trends you're seeing or maybe examples of recent attacks you want to highlight? Yeah, sure. So like we start on the research side of things.

6:00I think it's really fascinating because, you know, supply chain is such a huge challenge, right? And we talk about open source and we talk about 100 million developers on the GitHub platform. How do you secure all the work that's happening there and all the different ecosystems and all the different dependencies that are happening? And so things like Dependent Bot and GitHub Advanced Security help in that. And we also have to be part of the community that's looking for those vulnerabilities and trying to make the core services that so many companies and packages use more secure. And so this team is out coaching and presenting and teaching and helping others learn how to do that inside their companies and for the community.

6:39But then they're also the ones out looking for interesting zero days that we then will responsibly disclose and, you know, get out and keep the community safe before they are exploited by threat actors. And so I think that's a really interesting thing on the on the broader security trend side of things. You know, we see the developer account as one of the core security kind of pillars in that supply chain attack landscape. And so what I mean by that is, you know, often it's not necessarily a zero day that a threat actor is going to get and go in through the front door. Right. Totally. That happens.

7:19But many, many times we're seeing social engineering campaigns. We're seeing phishing attacks. We're seeing all these things. And we have this really interesting, unique position in the ecosystem. And, you know, that's one of the reasons we are rolling out 2FA requirements for every developer who contributes code on GitHub. Multi-factor authentication is crucial. It is. And it's like the simplest add-on you can do to make it significantly harder for things to go wrong. And we support a lot of different kinds on GitHub. And we do that on purpose. I mean, you know, arguably it would be great if we could all kind of move to pass keys and things that are really more secure and reliable.

7:55But we have developers worldwide and not every one of those developers has access to the latest technology. Some of that technology is expensive. And so we really want to make sure that the developers in the open source community everywhere in the world from every background can use the platform. But it's really, really important that the people that are contributing code have 2FA turned on. And so that's why it was slightly controversial, but we made the decision to say, no, we're going to enforce this because it's that important. It's the right thing to do in the ecosystem. I think it's really interesting.

8:24You mentioned social engineering. So this is obviously like when we think about this, like one of the biggest vulnerabilities that we have is simple things like phishing attacks where, you know, someone, you know, clicks on the wrong link or gives their credentials out or, you know, you may get those texts where we're saying, ah, it's your CEO. I need you to buy Amazon gift cards or whatever it might be. We have a custom emoji inside GitHub for how many gift card scams that hubbers get every day. Oh, it's amazing. That's a very fun way to do it and make it a game to respond to and make people encouraged by it.

8:54And I'm fairly certain I mentioned the Vegas attack earlier, but I believe the initial vulnerability was they called IT and so they needed to reset someone's password. Yep. And that's how they got in this very simple social engineering. I think that's right, yeah. And it's a common story. Like, yes, as you mentioned, there are zero-day exploits. We need to pay attention to those who have massive systemic risk. But we also need to improve training. We need to improve, like, these basic security principles, like 2FA, like MFA, like you mentioned. How do you see those trends around training, the need for people to up-level around this, and for better systems affecting the future of security?

9:30Yeah, so I think the foundations are really the key here, right? Right. I mean, you know, it's fun at conferences and in books and other places to like talk about these really wild and esoteric emerging threats. But fundamentally, a lot of the core security principles are just getting to the basics. Like, let's do the basics well. So let's get 2FA turned on. You know, let's get secret scanning turned on. Let's get, you know, let's get these kind of core things there that threat actors continue to exploit over and over again. And we absolutely need to look to the future and the more advanced techniques as well.

10:03and, you know, it would be remiss to not do that. But I think sometimes we see teams get out ahead of themselves and they're focused on the advanced threats and they haven't put the basics in place, right? And so, you know, every time I talk to a partner, another CISO, another, you know, customer, one of the things I say is like, hey, have you turned on secret scanning yet? Like, is it on your open source repositories? And if they're advanced security user, do they have it on their internal repositories? Because we just see that also being a way that threat actors get in. Whether it's social engineering or stolen credential or whatever it is, they get into a developer's account.

10:42And normally, the risk of that is fairly low unless there's secrets in there. And if there's secrets in there, they can take those secrets often and pivot and do much more damage than they otherwise could have done. And so that's why we're so persistent in trying to talk about that and make those services even better. And we just rolled out push protection for secret scanning to all open source public repos on GitHub. So now everybody can use it so that it will stop the secrets before it even gets into the repos, which is even better. So you don't have to remediate it afterwards. This is a great topic because, I mean, I think it's something where we take relief from national defense, where we say, look, like compartmentalization of information is a crucial thing when it comes to nation states.

11:21If you look, I'm sure you obviously worked in the NSA for 15 years. Like you're very familiar with this. This is a crucial thing in warfare and simply like nation state actors. This is exactly what we're talking about here with secret scanning where it's like, hey, if there is crucial information on this account that could make other accounts vulnerable, like we need to be aware of it and be able to shut it down. And it's the same concepts kind of coming through. And a lot of businesses, though, don't realize how important that is or don't have the focus on it that maybe a national security group would.

11:52Yeah. And I think, you know, defense in depth and zero trust come into play as well. So it's, you know, it's not enough just to put one measure in place. You know, you want two-factor authentication and preferably strong biometric-backed two-factor authentication. And then you also want things like just-in-time access and then conditional access. Like, so is the laptop, did it do impossible travel? Did it log in from Boston and then Las Vegas within three hours? That's not likely. So like factoring all those things into every one of these just helps the IT departments and the security departments make better decisions, have less things they have to think about and be trained on, and it gets more automated and we can have more signals to think about as a security team.

12:33As you put it, these are the foundations we need to put in place. And a lot of folks like to build on top of that without actually putting the foundations fully in. I'm curious, you mentioned zero trust. Obviously, it's a really important concept that's being, I think, more and more discussed, whether that's zero knowledge proofs or other approaches here. Do you see zero trust being taken up by the community and actually leverage? Or is it something where a lot of folks are still resistant to actually taking this approach to security? Yeah, I think it's happening slowly but surely. I think the principles there of Zero Trust and things like secure by design, secure by default, I think all of those are starting.

13:08We're starting to see those in the products vendors are selling. We're starting to see those be just accepted best practices now. And so I think how far companies are in their journey is really dependent on what tech debt they had. Where did they start? Where are they coming from? You know, what's the culture? because the culture has such a huge, I think, impact to all these technical discussions. You know, is the culture ready to adopt some of these security things? Are they comfortable talking about, you know, just-in-time access and conditional access and, you know, dealing with that in terms of training and access?

13:41And so I think it's all coming together. I do think it's really important, though. I think allowing the, you know, least privilege in the right situations for developers, for IT administrators, for security administrators, right? Like having that in place, having the auditing in place, and then, you know, being able to reduce blast radius if something goes wrong. I think those are all the core principles that we're seeing come out of zero trust and come out of secure by design that just make sense and, you know, need to happen. And it's encouraging to see it happening now. I know, I think we, anyone in the security space would love to see it happening faster, but I think we often get distracted by some of these flashier trends that are also hugely impactful.

14:21One example is AI, which I know you featured in your heavily in your talk. Can you talk a bit about how AI is impacting the security space now as LLMs are now kind of public knowledge and spreading rapidly? Yeah, absolutely. So, you know, we think about this in a couple different ways and I think about it a couple different ways. So like with my security hat on thinking about AI and like how threat actors are adopting it or not adopting it, but then from a developer perspective, it's also having a huge impact, right? And so, you know, one of the things that we're seeing with Copilot is the GitHub Copilot, which is our in-editor auto-completion capability, is that developers are moving a lot faster.

14:57They're accepting a lot of the suggestions that are happening. They're even reporting that they're being more fulfilled, like 75 % more fulfilled, which is amazing. But one of the effects of that on security is the boilerplate code that developers are spending all that time on web search and on man pages and on docs doing. It's just happening. And then we've got security filtering as part of GitHub Copilot as well. And so it's blocking some of the basic security mistakes that a developer may or may not make. And so what they're able to do is spend more time on higher order problems. They're able to free up more time to look at things like SAS scanning tools or review dependency alerts and things like that.

15:39And so the net effect, I think, is we're seeing security shift further left than we ever thought possible with some of these tools. Well, you referenced the phrasing secure by design earlier, and I think this is a really crucial thing for the audience to understand because Microsoft and GitHub have been really investing in this for years now and saying like, this is a base level foundation for us. We're going to create security and bake it in from the very start of our products. And particularly now with AI being enabled through Copilot and these other usage is like it's it's exactly what has been thought of for a while now in the security space where AI and ML can be applied to ease the burden on individuals as far as simplifying code or simplifying analysis in some places.

16:16and then providing humans more signal, more information, and letting them focus on these key tasks where the human brain is really good at that strategic analysis and taking those insights going, okay, here's what to do next. And I think that's the really exciting thing for me is looking at how AI has also been baked into security technology and starting to understand that. And I know the flashier part is the LLMs, and frankly, Copilot too. Copilot's an incredible tool. But some of these very simple usages of just like, hey, we're going to help you identify risks faster than the human mind can necessarily find it, and then give you that signal are also really exciting to me.

16:48Yeah, absolutely. And I think there's also a whole element of refactoring code and like these kind of secondary like developer concerns as well that also have security impacts. And so, you know, how many times have, has a developer shown up to a new team? It's in a different language than they expected. They're bringing their old toolkit with them or the team is kind of mostly new and they're like, well, we don't want to code in this language. We want to move it to another. And, you know, that refactoring process, how many security vulnerabilities are introduced in there, how much time is lost that could have been spent on a secure architecture, secure model, where things like GitHub Copilot are just saying like, okay, we're going to take this super old COBOL function and we're just going to turn it into Rust and we're going to keep moving or whatever the language is.

17:32And so I think those are things that we aren't really going to understand the impacts of until we start to see the results at scale, but I think they're going to be pretty big. I'll say it's something LinearP is really looking into is like the impact of AI code. We're very fascinated to continue to bring out numbers on X or we're excited by it. Like to your point, it's such a massive potential. The signal we're getting from devs about happiness and fulfillment, these things that are so important to high performing teams, success, long term retention. It's really wonderful to see. How do you think Copilot can continue to be applied to that refactoring process?

18:03Because to your point, there's a lot of code that maybe has minor vulnerabilities throughout it. How can we leverage AI tooling to go back and solve some of this technical debt? The way we're thinking about it at GitHub is the in-editor auto-completion is just the beginning. And so we're looking to figure out how to apply Copilot and LLMs and this AI technology to every aspect of the developer workflow. And so you can kind of extrapolate and imagine as you're working on GitHub with through pull requests, issues, the security tools, having that AI helper in every stage of that, how powerful that could be.

18:36And so, you know, those are the things we're really looking at now. Now we're so excited about what that can do because then once you have all that context from a developer repo or some of the things Nicole Forsgren talked about yesterday in terms of being able to get even more context in and through the AI capability, some of the research Microsoft research is doing there, like the possibilities are really incredible with being able to accelerate even more complex tasks that developers are dealing with, but arguably things that still aren't providing direct company value, right? Like refactoring a repo or like upgrading to the latest, you know, service technology.

19:12It's the output. It's the user interfacing work that's going to provide the value to the customers and value to the company. It's not that kind of core work behind the scenes. And so we want developers focused on those bigger, harder, more challenging, you know, outcomes than we do some of these kind of core like day to day things that are maybe more boilerplate. But it's really interesting to see the early impacts because it's clear there's so much more potential here. I mean, I think I'm not the first person to say this, but everyone's going to have a copilot like thing in their life, whether you're a developer, whether you're a writer, like you're seeing this evolve all over the place.

19:48And it's very clear that we're going to just continue to have this AI tooling in here. And so I love that GitHub's taking this approach of saying, how can we inject this across the software development lifecycle? like, how can we understand the ROI and just free up the human brain to focus on higher order tasks? Because that's really what we want to get out of this, right? Like, let's leverage robots, bots to help us. And that's what we've been doing for years. And now we're just having more success with being able to pull those matrices together and say, okay, like, we can get more in depth, we have better data sets, we can understand more.

20:18So it's, it's an exciting time, honestly, I am, I can't wait to see where we're at in five years, because there's going to be so much incredible change. Yeah, I'm really excited. And, you know, I'm a little biased, but I think GitHub's a fun place to be in the middle of all this as well, because, you know, LLMs and AI have such a huge potential across so many sectors. But, you know, I've always been in the developer space and the DevOps space. And so I started out more in engineering leadership and DevOps and then have moved into the security space the last few years. So being able to like see all of that come together through some of these technologies at a place like GitHub is just really exciting.

20:52and being able to apply it at a scale with like 100 million developers and 90 of the top 100 fortune companies. There's some exciting things, I think, on the horizon. And we're already seeing them now. So some of the folks that have already adopted it are just coming back and are like incredible stories about productivity gains that their teams are seeing. I want to talk more about those trends, but you alluded to your background and I'd love to just feature that a bit for the audience because I think it's fascinating. Can you tell us a bit about your career journey and anything you're able to share about your time in the NSA?

21:21I think would be fascinating to hear about. Yeah, sure, sure. Yeah, so like you said, I was there 15 years. I started out in hardware and computer engineering, building software-defined radio systems. And so we were building the tools and the frameworks and the systems themselves as well. And so part of that that I loved was still building tools for other developers. And so it wasn't just the software-defined radio systems, but like how do you build a framework that's reusable? How do you build tools that other people can use? And we ended up open sourcing a lot of that, which was really fun as well.

21:50It was an interesting experience, open sourcing hundreds of thousands of lines of code from inside NSA. It took a while and I learned a lot. But it was a lot of fun. And so, you know, that's really when I started getting into Agile and, you know, what we now call DevOps and continuous integration, continuous delivery, and some of the concepts now that are just so kind of core to the software development industry. But, you know, leading engineering teams who are solving these hard problems was really how I started. And then when you think about doing that in a place like NSA, where the security requirements are critical, right?

22:28I mean, they're important to every company everywhere. But you think about some of the potential risk and things we had to think about when we were building these systems. We really had to bake in security into everything we were doing. And so I kind of learned that along with my DevOps journey as well, and then kind of pivoted into the open source space. And so, you know, one of the lessons and kind of the outcomes of open sourcing the work that we did inside the software defined radio group was how do we make this better? Like it was a little too long and a little too hard to do. So I started spending time trying to understand what those processes were.

23:03How can we make it faster? Working with other agencies and other departments to figure out how they were doing it and then building those processes into how we were doing it inside NSA. And then the thing that I realized through that through part of that process was we were missing an element. which was a developer experience team. And so without a developer experience team as like the nucleus to drive some of these decisions and momentum, it was difficult to see the success we wanted to see in the open source work. And so myself and a few other colleagues started the DevEx program. And we kind of did this entrepreneurial thing where we created a pitch deck.

Read the full transcript

23:38We created a financial plan, a contract plan, how many headcount we needed, what it was going to look like, what was the five-year roadmap. And then we did pitches to execs around the agency, essentially asking for money and funding and resources and also tying in the data back to like, here's how it makes developers more effective. Here's the value. Here's the tools they're using today. And here's what consolidation would bring us in terms of mission outcomes. And we were able to pull that team together. And we had a developer security team, which was super amazing. We had a productivity team, a DevOps pipeline team, and we just kind of kept going and building that.

24:11And so that was really just an amazing journey of kind of bringing the developer side of things and the security side of things together because we had to help developers at the agency do all this in a secure way. Hearing that, it really just makes sense that you're now at GitHub, right? Where it's like, okay, like I've gone this whole journey and now I'm going to say, let's protect even more developers across the world. Let's broaden this work and bring it out and continue to focus on the open source piece. So it's, I mean, this looking back in hindsight, I'm like, oh, your career just makes total sense here.

24:40Yeah, it's fun how that works in hindsight. Yeah, it is. You're like, oh, okay. But yeah, I totally agree. I mean, I think, you know, I loved working at the agency. The mission was great and it was really fulfilling. And when I was considering leaving, I was like, where could I possibly go that would have a really interesting mission that has this kind of impact? And, you know, wow, GitHub's been that place for me, which is awesome. Any highlights from your time working security at GitHub or the NSA that you want to share? I think there's some amazing stories in this space. We've alluded to a couple of examples, but what are the moments that really stick out for you?

25:11Is there a zero trust vulnerability that you solved? Is it a particular social engineering network that you've fought back against? Those stories, I think, are so powerful because they help evoke for engineering leaders who are listening why this matters. Yeah, so what's interesting is the stories that we have are kind of daily happening behind the scenes inside the GitHub security team, right? So we have a team that is continually combating abuse on the platform because we still offer a lot of free services. And that's fantastic for education and new developers getting started and small teams who are trying to do a startup.

25:45But it's also a challenge because they get abused by threat actors and people trying to take advantage of the compute that's there and things like that. And so, you know, the teams produce weekly reports every week and I read every single one of them. And just the stories that happened there of, hey, we took down this abuse campaign that was, you know, A, it was costing a lot of money. But B, it was really, you know, reducing the performance or the expectations of our customers and how that was happening on the platform. And they fixed that, right? And so that's like this daily occurrence. And then if we kind of go to the threat detection side of things and threat intelligence side of things, like a constantly working to keep the platform safe and keep our company safe, but also keep our customers safe.

26:27And so, you know, there's always something happening in the space. We have a lot of customers across a lot of industries. And so there's always a security incident somewhere in the industry. and often they come to us and say like, hey, what are you seeing? Like how, what happened to our GitHub, you know, accounts? Like, is everything good there? And, you know, we do what we can to help in those instances as well. And so, you know, I don't know that there's any like one story that captures that, but I think there's this shared responsibility in the security team and really almost all hubbers share this of showing up and just keeping the home of all developers safe.

27:01What's it going to take? What do we have to do to do that? Who do we have to partner with? It's not just us, right? We want to partner with the rest of the industry. We have to. Yeah, I think that's a really important point to bring up. And I know it's something that GitHub and Microsoft are both very invested in, which is this long-term security partnership across the whole industry and sharing research, sharing information. Because, I mean, threat actors continue to evolve every year. We're seeing the amount of cybersecurity attacks evolve every year, the cost of them evolve every year. And frankly, we can't do it alone.

27:33Yeah, absolutely. And I think, you know, one of the things that like tying back to my public service time, it's a public-private partnership too, right? So companies have to work together across all the different sectors, not just the tech sector, but finance and manufacturing and automotive. But also the public and private partnership is so important as well, is what are the governments learning that they can share with industry and vice versa? And how can we make each other's security programs better? How can we share the data we're seeing faster? and how can we just level up the entire industry, both private and public, in a faster, more productive way.

28:06Yeah, especially because we're starting to see more and more nation-state-supported hacker groups coming after companies and elsewhere trying to either siphon funds or secrets. It's such a problem that most smaller companies or even large ones can't protect against a nation-state on their own. And so this is where these alliances become so crucial. Yeah, it's really interesting too. There's another aspect of this that's, I think, starting to emerge over the last few years, which is internal security teams are starting to become a business differentiator as well for companies. So how your security team approaches threat actors, be they nation state or crypto miners or whatever it is, and how they talk about it, how they disclose it, what's the tone in the blogs, how quick is it, how transparent is it?

28:50Like these things are starting to become not just nice to have, but expected from security teams and start to be things that like, if you're evaluating a set of vendors for a choice to come help you out, you start to think about like, well, how are they approaching this? How do they tackle the security challenges and how do they think about it? And is that a team I want to partner with when things go bad? Because something's going to go bad at some point. And who are you going to partner with to do it, right? And so I think that's an interesting trend that I think we're seeing as well. If you were advising engineering leaders in the audience who maybe are building a cybersecurity team or are working with them closely about what their approach should be for their team around cybersecurity, what would you advise them?

29:32I think it probably comes down to three things. One, we already talked about, focus on the fundamentals. Don't skip the fundamentals. You know, don't skip leg day for those of you in fitness. And I think number two would be get educated, right? So if you're an engineering leader working with a security team, ask for a postmortem on a security incident. go sit in and listen to the gory details of the last red team exercise and understand what the red team did and how they did it like get smart on how threat actors be they like external threat actors or you know a red team internally are approaching your systems and understand how that that you can engineer towards a better solution and be more productive and learn from it exactly And then I think the third one comes down to a close partnership.

30:22So I was having a conversation with one of our engineering leaders at GitHub the other day, and we were talking about some core kind of fundamental approaches to security and engineering. And one of the things we're talking about is that engineering really has to drive the roadmap, the architecture, the vision for the product, along with their product partners. That's not securities to drive, right? As a security leader, particularly with a developer background, I don't want to drive the architecture of what we need to ship amazing co-pilot features to our customers. But what our team does need to do is come alongside those engineering leaders and architects and help design it in a safe way from the beginning.

30:59What are the guardrails? Okay, cool. We're going to do this automation to kick off a new service that developers can ship to customers quickly. Well, how is the default state of that more secure than it was last month? How do we evolve that and make those paths secure? How do we ensure we're baking in those fundamentals, those foundations from the very start when we're building products? That's right. Makes total sense. And that ties into compliance too, right? So compliance and things like SOC 2 and ISO are such a public attestation of your internal security program. And I think one of the things that coming alongside between security and engineering brings is the opportunity to have that continuous compliance happening.

31:35So if you've got a core set of approaches and systems that are already compliant, evolving those and building into those is a much more straightforward path than reinventing the wheel with every new system you ship. And so that's where that partnership comes into play, because that may not be something an engineer would think about at the beginning is how does this affect my compliance that a customer would see? I certainly never thought about that on engineering teams. And so that partnership becomes really important there when you can have a GRC person say like, hey, well, if we did it over here, it just it comes for free or at least comes with less cost.

32:10I think compliance is obviously such an important thing for us to consider as we as we take these steps forward, because no one wants to be at risk and we do need to put these foundations in place. I'm curious if you see the trend of policy as code around compliance becoming increasingly important or what you're seeing on that edge. I think it is important in the sense that having developers and the security teams understand all of the, not all of, but many of the implications of compliance, I think comes into play. The way we approach this at GitHub and the way I approach it is essentially compliance is that public view.

32:45It's almost like the attestation of what you're doing, but it's not the goal, right? The goal is security, right? We want secure systems that are resilient against attacks, that are resilient against supply chain attacks or threat actor attacks or whatever it is. And so the way we show that and demonstrate that is through the compliance program. And so those things are very intertwined, but we don't want to make a security decision or an engineering decision purely because it has a compliance outcome. But that's an artifact of a good security decision, if that makes sense. And so I think it's really important for us as we're partnering with engineering teams from the security side is to focus on the why.

33:21Why is this thing important that we go solve? What set of attacks could this prevent? Why is this a good security outcome? And oh, by the way, this also lends towards our compliance story, which is also really, really important in terms of customer trust and how we talk about this publicly. I love that you keep bringing it back to customer trust, too, because it's such an important element that I think we sometimes underestimate when we have these conversations. What other trends are you seeing or key elements do you think are coming in the security space over the next couple of years? We talked a little bit already about security teams being a differentiator, I think, in this space.

34:01I think it is because of customer trust. I think that when you have the opportunity to hear from security teams directly about the security posture, both what went wrong and what went well and what went wrong, you learn a lot about how a company approaches this. And so I think we're going to see more of that. I think we're also going to see more diverse security teams. I mean, at GitHub, we already see this. So like we have machine learning and AI experts on our counter abuse team because we need to. That's how we can keep up. We can't keep up any other way. And so, you know, having developers and analysts and AI experts in security teams, and I think also having security teams that are made up of people with different backgrounds, maybe a mix of, you know, legal and technical and non-technical backgrounds, I think is really important because it gives that diversity of thought and approach and it avoids a situation where you sort of end up in a corner of thinking that you didn't mean to, right?

34:57And so I think having a diverse security team is really important. So I think we're going to, we are seeing that. I mean, we're certainly seeing that at GitHub and we invest in that and think about that in our hiring, but I think we're going to see that trend continue. What would be your closing thoughts or advice for engineering leaders who are listening to this conversation. So we've talked about a lot of it today. I think get to know your security partners is one that I always love to pitch. I think the other one too is we really believe at GitHub, and I think it's true across a lot of the people that attend this conference in particular, that bringing security to where the developers are working is really, really important.

35:33And so understanding how developers work, how to keep them in flow state, how to keep their productivity high while bringing security to it, I think is just incredibly important. And that's one of the goals that we have with GitHub Copilot. It's definitely one of the goals we have at GitHub with our security products and then inside of our security team, even internally to GitHub security, we try and get our vulnerabilities and our vulnerable program and all the things that we find to help internal developers, we try and get it to developers in the way that they work in repos and full requests and issues.

36:05And so I think getting that relationship and collaboration happening where developers work is just critical to how we are going to continue to shift security left and improve security for all of our industries, but also the open source community. Awesome. That's a wonderful note to close on. And Jacob, thank you so much for joining us to share your expertise and talk through the approach GitHub's taking. It's fascinating to hear about. Really excited for this episode out. It's been great talking to you. Yeah, thanks for having me. This was a blast to talk through all this. Yeah, and if you ever want more information about stuff Jacob's doing or the team at GitHub, we'll feature it in our newsletter on Substack at devinterrupted.substack.com.

36:44Comes out every Tuesdays. We'll have this podcast plus more information in the newsletter. And we'll also have Thursday Deep Dimes. We'll talk about concepts like secure by design and many more. So definitely make sure you're checking out. If you're enjoying this podcast, you would probably enjoy our Substack. Thanks so much for listening, everyone. And we'll talk to you next week.

37:07It's a haha.

From the publisher

What does protecting the more than 100 million developers on GitHub’s platform take? And what can your team learn from GitHub’s impressive security posture? 

On this week’s episode, co-host Conor Bronsdon is joined by Jacob DePriest, VP and Deputy Chief Security Officer at GitHub. Join them as they discuss Jacob's journey from the NSA to GitHub, delving into how AI impacts the security space and the future of Copilot's ever-expanding capabilities.

The conversation also explores how enhancing customer trust, investing in diversity within security teams, and bringing security to where developers work are critical in improving security industry-wide.

Whether you’re protecting dozens of users or millions, Jacob has practical advice for engineering leaders everywhere.

Show Notes:

OFFERS

  • Start Free Trial: Get started with LinearB's AI productivity platform for free.
  • Book a Demo: Learn how you can ship faster, improve DevEx, and lead with confidence in the AI era.

LEARN ABOUT LINEARB

  • AI Code Reviews: Automate reviews to catch bugs, security risks, and performance issues before they hit production.
  • AI & Productivity Insights: Go beyond DORA with AI-powered recommendations and dashboards to measure and improve performance.
  • AI-Powered Workflow Automations: Use AI-generated PR descriptions, smart routing, and other automations to reduce developer toil.
  • MCP Server: Interact with your engineering data using natural language to build custom reports and get answers on the fly.

More from Dev Interrupted

All 208 episodes
Protecting GitHub’s 100M DevelopersDev Interrupted · 37 min
Listen in VO