Security

Software security needs a new perspective

Comment

Image Credits: optimarc (opens in a new window) / Shutterstock (opens in a new window)

Ben Dickson

Contributor

Ben Dickson is a software engineer and the founder of TechTalks.

More posts from Ben Dickson

Source code bugs have been a constant in the software industry since the dawn of computers — and have ever been a major source of attacks, exploits and security incidents. Presently, with virtually every aspect of our lives and daily business becoming connected and dependent on software in one way or another, the potential destructiveness of software bugs has become orders of magnitude more dramatic than it used to be, say, 20 years ago.

Juniper, Fortinet, AMX, Socat, Linux Mint and VTech are just some of the companies providing network- and Internet-related services that have been recently hit with vulnerabilities in the source code of their products, directly putting the security and privacy of millions of users at risk.

This reality reflects the fact that source code security technologies and practices have unfortunately not kept pace with the progress of technology, and it warrants the need to change the perspective and perception of source code security, which should be to discover and root out serious vulnerabilities and flaws before software is released.

Millions of users are falling victim to network software bugs every year

Web applications and networking software are especially sensitive to source code vulnerabilities, because they both can be exploited remotely and potentially provide attackers with a beachhead to move laterally across a network and conduct other, more dangerous attacks. Web applications are especially critical as they are easier to breach and continue to be an attractive target for hackers.

The mid-November hack of websites belonging to giant toy maker VTech, which resulted in the theft of personal information belonging to more than 5 million users, was carried out by exploiting a SQL injection (SQLi) vulnerability in the site’s source code. SQLi is one of the most trivial and yet dangerous types of attacks that can be carried out against web servers.

A more recent web application hack was that of the official Linux Mint distribution website, which hackers silently compromised in February in order to upload and distribute a backdoored version of the OS. By the time the breach was discovered and patched, thousands of infected copies of Linux had been downloaded by unfortunate users.

Last December, networking giant Juniper revealed it had discovered two mysterious backdoors in the software running on its firewalls, which could effectively be exploited to decrypt protected data passing through its firewalls. The amount of damage dealt could not be assessed because the vulnerability had been running for months. But given the fact that the tech firm is a main provider to the likes of AT&T, Verizon, NATO and the U.S. government, one can expect the numbers to be soaring in the millions.

Another relevant case that surfaced on the heels of Juniper’s backdoor was that of its competitor Fortinet, which was found to have embedded a hardcoded password in its FortiOS software that gave SSH access to servers running it. SSH is the interface used to remotely administer servers.

Audio-visual conferencing gear provider AMX also made the headlines earlier this year, after Austrian research firm SEC Consult reported the discovery of “deliberate backdoor” embedded in its NX-1200 controller product, which the firm claimed was a maintenance feature but could be used to gain remote administrative access to the product. AMX products are widely used by the U.S. government and military.

In all cases, the discovered vulnerabilities were simple and straightforward bugs that could’ve easily been identified and rooted out before it became damaging. Yet inadequate practices and insufficient tools have contributed to the exploits slipping by the developers.

The problem with current source code security solutions

Traditional methods are usually dependent on security audit professionals who are hired to peruse application code and test it in action in order to discover vulnerabilities and make recommendations for mitigating threats. Likewise, the tools used in these processes are disparate and tailored for security auditors and not developers. These types of procedures and tools are only applicable to large software development firms and would eliminate smaller companies that do engage in coding, but on a smaller scale.

This model has many flaws and limitations, including the requirement that application development be either complete or well underway before it can be tested, which makes the safeguarding process a reactive one, at best. Also, depending on periodical or one-time security audits will only put the application to test at specific points in time and will fail to provide source code security throughout the entire life cycle of the application.

This approach also has drawbacks from an economic standpoint, because correcting application bugs in the production phase instead of development can prove to be both time-consuming and expensive. And when in a rush to meet release deadlines, developers and publishers are wont to cut back on the more thorough testing that comes at the end of the development process.

New approaches to addressing bugs in software

A successful approach to source code security would be one that is holistic and easy to use, which could be integrated into the processes of all firms and labs that are involved in software development, regardless of the limits of their resources and budget. New code security tools should enable developers to identify and root out security holes as they’re coding, not after they’re finished.

bugScout and bugBlast, two application testing tools recently released by Spanish cybersecurity startup Buguroo, are hoping to achieve such a goal.

“bugScout is an SAST [static application security testing] tool developed by our team of security audit experts,” explains Pablo de la Riva Ferrezuelo, CTO and founder of Buguroo, “but it has been created to be adjusted to users across the spectrum. So it can be used by coders with little security knowledge or security auditors with little coding knowledge, or anyone who falls in-between.”

Basically, bugScout is a service that blends in with your development environment and constantly analyzes your application’s source code as you develop it, using different methods and information gathered from different standards.

Ferrezuelo believes that bugScout will address challenges caused by previous SASTs, “which generate a lot of false positives and require the assistance of many experienced security auditors,” he explains. “It will also lower development costs,” he adds, “by starting the flaw identification process early in the development life cycle instead of waiting for the application to be feature complete before putting it to test.”

bugScout’s sibling, bugBlast, is a next-generation appsec management platform that unifies many types of vulnerability testing tools with real-time intelligence to test the application, its hosting infrastructure and its third-party service providers against known threats and malicious behavior patterns at runtime during development and after it goes into production.

Both tools are available as cloud-based services and standalone installations.

The U.S.-based LGS Innovations is another technology firm that intends to tackle source code security issues with its newly announced CodeGuardian solution.

As Kevin Kelly, CEO of LGS Innovations explains, “CodeGuardian fills the void left by current security solutions, which, taken individually, aren’t complete and comprehensive and require expertise to be used effectively.”

CodeGuardian is a technical solution embedded into existing products to enhance security defensiveness; it hardens network devices by removing known vulnerabilities and inoculating the software source code and binary executable to enhance overall network security.

The solution uses proprietary technology and processes to identify and eliminate vulnerabilities and backdoors in a network component’s source code. It also uses diversification techniques to generate and distribute various binary images of the same software to further reduce the possibility of uniformly applied cyberattacks against a product line.

CodeGuardian is already being used by Alcatel-Lucent Enterprise to secure software solutions within their OmniSwitch family of networking equipment.

The future of coding vulnerabilities

The increasing number of connected devices and the huge amount of software that is being developed on a daily basis will continue to generate and introduce new attack vectors and exploit opportunities for malicious hackers. The rise of the Internet of Things (IoT) and propagation of minimal embedded systems across home and business networks will cause further challenges.

If we are to face and overcome these challenges, we need a new vision for source code security and solutions that will help us identify and mitigate threats proactively before they inflict damage.

More TechCrunch

Ember has partnered with HSBC in the U.K. so that the bank’s business customers can access Ember’s services from their online accounts.

Embedded finance is still trendy as accounting automation startup Ember partners with HSBC UK

Kudos uses AI to figure out consumer spending habits so it can then provide more personalized financial advice, like maximizing rewards and utilizing credit effectively.

Kudos lands $10M for an AI smart wallet that picks the best credit card for purchases

The EU’s warning comes after Microsoft failed to respond to a legally binding request for information that focused on its generative AI tools.

EU warns Microsoft it could be fined billions over missing GenAI risk info

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies

OpenAI has reached a deal with Reddit to use the social news site’s data for training AI models. In a blog post on OpenAI’s press relations site, the company said…

OpenAI inks deal to train AI on Reddit data

X users will now be able to discover posts from new Communities that are trending directly from an Explore tab within the section.

X pushes more users to Communities

For Mark Zuckerberg’s 40th birthday, his wife got him a photoshoot. Zuckerberg gives the camera a sly smile as he sits amid a carefully crafted re-creation of his childhood bedroom.…

Mark Zuckerberg’s makeover: Midlife crisis or carefully crafted rebrand?

Strava announced a slew of features, including AI to weed out leaderboard cheats, a new ‘family’ subscription plan, dark mode and more.

Strava taps AI to weed out leaderboard cheats, unveils ‘family’ plan, dark mode and more

We all fall down sometimes. Astronauts are no exception. You need to be in peak physical condition for space travel, but bulky space suits and lower gravity levels can be…

Astronauts fall over. Robotic limbs can help them back up.

Microsoft will launch its custom Cobalt 100 chips to customers as a public preview at its Build conference next week, TechCrunch has learned. In an analyst briefing ahead of Build,…

Microsoft’s custom Cobalt chips will come to Azure next week

What a wild week for transportation news! It was a smorgasbord of news that seemed to touch every sector and theme in transportation.

Tesla keeps cutting jobs and the feds probe Waymo

Sony Music Group has sent letters to more than 700 tech companies and music streaming services to warn them not to use its music to train AI without explicit permission.…

Sony Music warns tech companies over ‘unauthorized’ use of its content to train AI

Winston Chi, Butter’s founder and CEO, told TechCrunch that “most parties, including our investors and us, are making money” from the exit.

GrubMarket buys Butter to give its food distribution tech an AI boost

The investor lawsuit is related to Bolt securing a $30 million personal loan to Ryan Breslow, which was later defaulted on.

Bolt founder Ryan Breslow wants to settle an investor lawsuit by returning $37 million worth of shares

Meta, the parent company of Facebook, launched an enterprise version of the prominent social network in 2015. It always seemed like a stretch for a company built on a consumer…

With the end of Workplace, it’s fair to wonder if Meta was ever serious about the enterprise

X, formerly Twitter, turned TweetDeck into X Pro and pushed it behind a paywall. But there is a new column-based social media tool in town, and it’s from Instagram Threads.…

Meta Threads is testing pinned columns on the web, similar to the old TweetDeck

As part of 2024’s Accessibility Awareness Day, Google is showing off some updates to Android that should be useful to folks with mobility or vision impairments. Project Gameface allows gamers…

Google expands hands-free and eyes-free interfaces on Android

A hacker listed the data allegedly breached from Samco on a known cybercrime forum.

Hacker claims theft of India’s Samco account data

A top European privacy watchdog is investigating following the recent breaches of Dell customers’ personal information, TechCrunch has learned.  Ireland’s Data Protection Commission (DPC) deputy commissioner Graham Doyle confirmed to…

Ireland privacy watchdog confirms Dell data breach investigation

Ampere and Qualcomm aren’t the most obvious of partners. Both, after all, offer Arm-based chips for running data center servers (though Qualcomm’s largest market remains mobile). But as the two…

Ampere teams up with Qualcomm to launch an Arm-based AI server

At Google’s I/O developer conference, the company made its case to developers — and to some extent, consumers — why its bets on AI are ahead of rivals. At the…

Google I/O was an AI evolution, not a revolution

TechCrunch Disrupt has always been the ultimate convergence point for all things startup and tech. In the bustling world of innovation, it serves as the “big top” tent, where entrepreneurs,…

Meet the Magnificent Six: A tour of the stages at Disrupt 2024

There’s apparently a lot of demand for an on-demand handyperson. Khosla Ventures and Pear VC have just tripled down on their investment in Honey Homes, which offers up a dedicated…

Khosla Ventures, Pear VC triple down on Honey Homes, a smart way to hire a handyman

TikTok is testing the ability for users to upload 60-minute videos, the company confirmed to TechCrunch on Thursday. The feature is available to a limited group of users in select…

TikTok tests 60-minute video uploads as it continues to take on YouTube

Flock Safety is a multibillion-dollar startup that’s got eyes everywhere. As of Wednesday, with the company’s new Solar Condor cameras, those eyes are solar-powered and use wireless 5G networks to…

Flock Safety’s solar-powered cameras could make surveillance more widespread

Since he was very young, Bar Mor knew that he would inevitably do something with real estate. His family was involved in all types of real estate projects, from ground-up…

Agora raises $34M Series B to keep building the Carta for real estate

Poshmark, the social commerce site that lets people buy and sell new and used items to each other, launched a paid marketing tool on Thursday, giving sellers the ability to…

Poshmark’s ‘Promoted Closet’ tool lets sellers boost all their listings at once

Google is launching a Gemini add-on for educational institutes through Google Workspace.

Google adds Gemini to its Education suite

More money for the generative AI boom: Y Combinator-backed developer infrastructure startup Recall.ai announced Thursday it has raised a $10 million Series A funding round, bringing its total raised to over…

YC-backed Recall.ai gets $10M Series A to help companies use virtual meeting data