Josh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs and incidents. There are some new features we will need in both our hardware and software to ward off the state of things. Since those features are years away, what we need in the short term is shoring up our SDLC programs. Sal has some really good medical examples and analogies for this one. It's a huge problem but not insurmountable. <...
Transcript
Automatically generated from the audio. May contain errors.
Today, Open Source Security is talking to Sal Kimmick, a security architect. Sal, I've known for a while, and Sal gave me their book, and I think we're at KubeCon when you gave me your book. And I read it, and it's awesome, and you've got tons to talk about, so welcome to the
show, Sal. Yeah, thanks for having me. Let's talk some cybersecurity. It is crazier than it's ever been.
Actually, so before I hit record, I was talking to Sal about the book, and you You wrote the book last year. Yeah, yeah, I got it out. We're in 2026 right now.
Yeah, 2025. You wrote a bit about supply chain security and vulnerabilities and things like that. And I was actually, I was rereading the book over the weekend to get myself back in the right headspace.
And I'm like, why did Sal write this? You got a lot right. I mean, because everything is just completely bananas and on fire right now. And I don't know if I'm impressed or sad.
Yeah. Yeah. Well, this book was really interesting because I really wanted to understand what digital isolation is at every layer all the way down to the kernel originally. So I went out and I just talked to everybody I could. And unfortunately, when I talked to kernel maintainers, they said, Sal, the problem is actually the semiconductor supply chain. You have to write
that first. And I said, whoa, this is a really deep problem. But yeah, that was a lot of shared wisdom that went into that book. And I think the best way to know the next 30 years is going to look like is asking people
who looked at the last 30 years because they were there. That's wild. OK, so before we go on, I want to clarify. Your book is called Code, Chips, and Control.
And I know you're doing a ton of other work right now, too. But this one specifically, I do love this book. And it really resonated with me.
So anyway, I'm sorry. I'm sorry to interrupt. I just want to make sure you get the title. I'll put links to all this crap in the show
for anyone listening also. So, all right, so back to you, apologies. Yeah, well, I mean, it's such an interesting journey. And I think right now, a lot of what people are seeing in their news feeds is a lot of application layer on buyer security. And underneath that, there's a lot of really interesting security vectors. And I think
as soon as security gets below your control plane, whatever that looks like for you, We try not to think about it even though the risk is greater. So now I'm really interested in what are the solutions at lower layers that make it so that I can have confidence in my runtime no matter what I'm building because agentic makes that
really important. Okay. I want to maybe push back on something you just said where you talk about the layer of your control plane, which we all have a line we have to draw that just says
everything beneath this line, you know, thinking of our architecture as some, we'll use the XKCD tower maybe, but there's a point where we can have impact on the things above our line and there's functionally nothing we can do beneath it. And we all live our lives like this, like the power company is a great example of where our water supply coming from wherever we get water
for our homes, things like that, right? And you mentioned the things beneath the line we need to care about. But I think it's easy to say we need to care about them, but I don't know if we can. Yeah. So I think when I say care, I think what I am really interested in is there's a fundamental
unblocking. There's a kind of creativity that you can get in workplaces when security has been so primary to the practice that it allows you to. Right? So, sect up ops is where I started my career. And being able to work and really, really sanitize spaces while you're building really big, expensive things is important. Now, I think worrying
about observability and thinking of it as telemetry, I think the real actual problem with that is both where and what you want to look at, but also the fact that telemetry costs money. The kind of solutions that I am interested in are where would it not make sense to spend money on telemetry? And instead, where can I put a secure
primitive or a deterministic gait that ensures I don't need to observe that because I've guaranteed it in some other way. That's what you get to start thinking about when you go, when you look at chaos, wherever it's happening over a kernel, that's where it makes a lot of sense to step one layer down
or two layers down and see if you can secure that threat model at the base. Okay. The thing that just popped into my head, Sal, is I don't know if you're familiar. There's a person named Wendy Nather who I've been just kind of reading her things for, I
feel like decades at this point. It's been a long time. But Wendy has this concept they call the security poverty line, right? Where the vast majority of organizations, they basically are in security poverty, meaning
they're not paying their bills. They can't even feed themselves. So talking about things like deterministic hardware gates or various other, and this This is amazing ideas, I'll say.
But I think this is one of our challenges, right, is when people are function- literally starving to death, you know, security-wise, they don't care. They're going to draw that line of control as high as they can put it, even probably higher than it maybe should be, right?
And they are going to just maliciously ignore everything beneath it. And I'm curious, like, what do we even think of that? What can we even do about that? I mean, I feel this every day where everything is crazy and on fire.
It's like, what can I just not do right now? Because I don't have time to do, you know, I have 30 things to do and I have time to do 10 of them. What are the 10 I'm going to do? Yeah. Yeah.
So that is the security posture of a downstream consumer, not a midstream and not an upstream, right? So you are consuming a bunch of applications, your security risk over that surface area is reasonably large and increasing, right?
This is the opening of the episode. Open the player for the full interactive transcript with clickable words, translation and flashcards.
Open full transcriptAudio belongs to its publisher and is played from their feed. Rights holders can request removal — copyright & takedown policy












