11 ms·
Welcoming Semmle to GitHub
- eatonphil 7y agoThe linked blog post [0] and the new security marketing page [1] both have a little more detail on what this actually means. Basically, Semmle offers a static analysis tool that operates on your source code as a graph (from what I understand) and points out bugs and security holes in your code. Github is now offering that for free on repos at all tiers. [0] https://github.blog/2019-09-18-securing-software-together/ https://github.blog/2019-09-18-securing-software-together/ [1] https://github.com/features/security https://github.com/features/security
- DannyBee 7y agoSemmle is basically datalog over source code. For what it works for, it works nice. But it is not a pancaea. Security vulnerability finding is almost certainly the wrong target for Semmle - I am unsure why they are trying to push that angle. There are much better stories in things like refactoring and understanding. (I say this having overseen a number of deployments for various reasons, some successful, some not)
- sneak 7y agoNothing is a panacea. Things that help move the needle without requiring tons of time or effort are useful and valuable. I'm really glad to see more efforts in this area.
- DannyBee 7y agoWhile it's true that there is no pancaea, Semmle will not move the needle on vulnerability finding. This I have extensive data on. (I mean this in terms of capability, not sudden popularity) It would move the needle on a bunch else. It is a good tool for sure (and im very happy for them), i just think they will disappoint people by pressing this particular narrative, and wouldn't do so with a different narrative
- intern4tional 7y agoI'd be curious as to why you think that. Are you able to provide more detail on that claim? I have extensive experience with Semmle and my experience drastically differs from you. With certain languages and a strong and diverse ruleset Semmle has it's strengths. In particular with native code (C, C++) and decent rules I have seen Semmle be very successful at finding certain classes of bugs.
- lvh 7y agoThe Datalog part is interesting! Do they have a bunch of rules to make graph queries work nicely, like Datomic pull syntax or maybe some pattern matching syntactic sugar? Is the underlying thing still an EAVT store? Is any of that information publicly available?
- dantiberian 7y agoIt looks like they have reasonable docs on their query language, in particular https://help.semmle.com/QL/learn-ql/about-ql.html#properties-of-ql https://help.semmle.com/QL/learn-ql/about-ql.html#properties... has some info on the QL language. https://help.semmle.com/lgtm-enterprise/user/help/generate-database.html https://help.semmle.com/lgtm-enterprise/user/help/generate-d... says "LGTM generates a database for each commit stored in a repository. Each database is a relational database that represents the structure of the codebase for a specific revision, or snapshot, of the code.", though a triple store could qualify as relational here. I couldn't find much more than that about the implementation details though.
- lvh 7y agoRight. I found those docs but they didn’t look like datalog queries at all. Of course that doesn’t mean they don’t compile down to datalog :)
- lawnchair_larry 7y agoI would love to hear more about this data, as everyone I know who has used it for vulnerability finding has very good things to say. Semmle have also demonstrated its capabilities with some high profile examples.
- UncleMeat 7y agoSemmle does not scale, both in terms of their index design and their overall system design. This makes it poorly suited for truly global program properties and much better suited for things like refactoring.
- muricula 7y agoIt's being run frequently across the entire Windows OS repo. I have heard there is more work to be done to make it scale better, but it can scale.
- intern4tional 7y agoAm Microsoft. Mountains were moved to make it scale, but that has been achieved. Semmle can scale with work - it just takes a lot of effort and code.
- lawnchair_larry 7y agoWhat had to be done to make it scale?
- mynegation 7y agoI was not part of this effort but I did scale another static analysis tool for industrial size codebases and have a patent on it. To simplify a bit you can think of most static analysis algorithms in terms of graph problems where nodes are statements and functions and edges are flow of control and calls. On large codebases the amount of edges, nodes, and calculated data is just too big to keep in memory. The trick is to break the graph intelligently into parts, calculate some sort of summary information for each of them, distributing between cpus or computers, move up to the supegraph of graphs and perform higher level calculations on it.
- DannyBee 7y agoYeah, I think that is at least one of the issues. For us, for what it provides, it is not worth the time/effort vs just building our own tools or other options.
- muricula 7y agoI've seen coworkers run semmle queries across the entire Windows OS codebase and find hundreds of issues which were/could result in security vulnerabilities. They've also leveraged it for variant analysis. If I'm not mistaken, the security teams are the largest internal users of Semmle at Microsoft. You're right though, it's not a panacea, and it could probably be great for other uses too.
- wglb 7y agoAny idea what the false positive rate is?
- tru3_power 7y agoIf you use the out of the box rules for any of these tools the false positive rate will usually be pretty high. The trick is to write custom rules that are more tailored to your code.
- wglb 7y agoSo how much is involved in writing the rules, and at the end of it, what is the net false positive?
- tru3_power 7y agoIt took me a few months to get decent results with a low false positive rate. We haven’t had the tooling in place long enough to give hard stats but our aim is to have a false positive rate of less than 25%. Another great thing that these tools provide (if the results are valid) is that they let more junior members of the team/developers not as familiar with security issues to be able to understand the vulnerabilities found as they display a nice call flow graph/diagram that’s shows source to sink.
- lawnchair_larry 7y agoYou’re wrong on that, security teams at the major tech companies love it, especially for variant analysis. Ask your coworkers at Google! One of which recently left to become Semmle’s Chief Security Officer.
- tptacek 7y agoFirst of all, Daniel Berlin is pretty senior at a reasonably large tech company a lot of us here have heard of. Secondly, I know Microsoft loves it, which is presumably where your telemetry comes from, and I know a lot of security people on Twitter are fans of the technology, but I've been asking around and "love it" is not the signal I'm getting from software security blue team people. "I installed it, I guess it does some stuff, we never think about it" is the modal feedback I've seen. I'm very interested in hearing success stories about this; the problem Semmle addresses is a huge part of the cost basis for my practice, and I'd love to hear that someone has gotten it working well.
- lawnchair_larry 7y agoIt’s absolutely useless in the wrong hands, so I don’t think you’d necessarily get a good signal by asking your average blue teamer. It’s a godsend for someone who spends a lot of time auditing code and has some experience writing code analysis tools. I mean think about it, if you wanted to write a query against the AST of a target, would you find that useful? Or in a given codebase, if you find one bug, would you like the ability to capture that in a query that can tell you if a similar mistake was made elsewhere? Out of the box, it isn’t going to give you much value. It’s the power of the query language, if it’s your job to do that, where you’ll see the benefits. But don’t take my word for it, just try it out. Their licensing model may be problematic for your use case though. I only vaguely understand what you do, but last I asked them about it, it’s not possible to get a personal license that a security person can use for multiple projects, and my read was that they had no interest in selling to individuals anytime soon.
- tptacek 7y agoI mean, queries against an AST is sort of standard security tooling; the difference appears to be that Semmle (1) properly assigns types in C/C++ and (2) exports that query language. (1) makes sense to me; (2) I don't know how much better I'd get than just hand-writing tree walkers.
- tru3_power 7y agoI was looking at it earlier and the query syntax seems awesome. I’ve spent the last few months writing custom rules (queries) for fortify sca- which is another static code analysis tool and I must say, Semmle seems like it’s a lot easier to use. Static code analysis tooling is never the end all be all for vulnerability research, but it does let you express vulnerability patterns for implementation type vulnerabilities and find them at a mass scale (that is if your rules/queries are legit).
- psygnisfive 7y ago> Security vulnerability finding is almost certainly the wrong target for Semmle CVE-2019-5876 CVE-2019-16230 CVE-2019-16231 CVE-2019-16232 CVE-2019-16233 CVE-2019-16234 CVE-2019-15026 CVE-2019-14192 CVE-2019-14193 CVE-2019-14194 CVE-2019-14195 CVE-2019-14196 CVE-2019-14197 CVE-2019-14198 CVE-2019-14199 CVE-2019-14200 CVE-2019-14201 CVE-2019-14202 CVE-2019-14203 CVE-2019-14204 CVE-2019-14437 CVE-2019-14438 CVE-2019-14438 CVE-2019-14498 CVE-2019-14535 CVE-2019-14534 CVE-2019-14533 CVE-2019-14776 CVE-2019-14778 CVE-2019-14779 CVE-2019-14777 CVE-2019-14970 CVE-2019-15119 CVE-2019-14524 CVE-2019-14523 CVE-2019-7307 CVE-2019-11476 CVE-2019-13115 CVE-2019-3570 CVE-2019-13110 CVE-2019-13112 CVE-2019-13113 CVE-2019-13108 CVE-2019-13109 CVE-2019-13111 CVE-2019-13114 CVE-2019-3560 CVE-2019-9721 CVE-2019-9718 CVE-2019-9717 CVE-2019-9720 CVE-2019-9719 CVE-2018-20222 CVE-2019-3828 CVE-2019-6986 CVE-2019-5414 CVE-2018-4460 CVE-2018-16491 CVE-2018-16489 CVE-2018-16490 CVE-2018-19476 CVE-2018-19477 CVE-2018-19475 CVE-2018-19134 CVE-2018-16472 CVE-2018-18820 CVE-2018-4407 CVE-2018-16487 CVE-2018-4259 CVE-2018-4286 CVE-2018-4287 CVE-2018-4288 CVE-2018-4291 CVE-2019-5413 CVE-2018-16461 CVE-2018-16469 CVE-2018-16486 CVE-2018-16460 CVE-2018-16492 CVE-2018-11776 CVE-2018-8018 CVE-2018-8294 CVE-2018-4249 CVE-2018-8013 CVE-2018-5388 CVE-2018-1295 CVE-2018-4136 CVE-2018-4160 CVE-2018-1000140 CVE-2017-15692 CVE-2017-15693 CVE-2017-13904 CVE-2017-15089 CVE-2018-6834 CVE-2018-6835 CVE-2017-15713 CVE-2017-12634 CVE-2017-13782 CVE-2017-7545 CVE-2017-14949 CVE-2017-14868 CVE-2017-8046 CVE-2017-8045 CVE-2017-9805 CVE-2017-1000207 CVE-2017-1000208 CVE-2017-12612 CVE-2017-0141 https://lgtm.com/security/ https://lgtm.com/security/
- wglb 7y agoHow would this list compare to other methods?
- DannyBee 7y agoUh, I'm not sure why you believe this is an effective retort, perhaps you would like to explain?
- captn3m0 7y ago>This list provides details about security vulnerabilities discovered by the Semmle Security Research Team using Semmle QL. Clearly, it works.
- Dirlewanger 7y agoSo I'm guessing they'll be merging what they have now with Semmie's tool? Because they've had the free vulnerability check for a while now.
- tptacek 7y agoDifferent things. Github has features that scan repos for "known-vulnerable" dependencies. They do not have features that scan for new vulnerabilities.
- thomasahle 7y agoYes and no. LGTM is about known vulnerabilities. It doesn't (currently) use artificial intelligence to discover new vulnerabilities, but it allows writing complicated yet efficient patterns for vulnerabilities found by human intelligence. So it's more advanced than simple "know bad dependencies", but it's also not quite "new vulnerabilities".
- tensor 7y agoAm I reading that right that it's only on public repositories though? For private repositories I guess you have to buy through Semmle directly (via call us pricing)?
- hanniabu 7y agoThis would make sense since Semmle would likely need access.
- throwaway744678 7y agoI'd be ready to put money on the fact that GitHub has access to all repositories, even private ones!
- deleted 7y ago[deleted]
- smudgymcscmudge 7y agoOf course they do, but they also have safeguards in place that prevent access without alerting auditors and eventually the repo owner.
- nickpsecurity 7y agoThe funny thing is I was working on a pitch to get Atlassian to buy them so they don't end up in Microsoft's hands. I thought integration with a repo company would be good since they could cross-sell it for code understanding and maintenance. Then I see this article. (sighs) At least I got it right on the type of company that would grab them. I'd push something else for security, though, to complement it. RV-Match is my favorite commercial one because they built on a formal semantics for C, it's set for low false positives, and they open source a lot of stuff. They have something for Java and smart contracts, too. Past that, what's good depends on what language you use.
- iainmerrick 7y agoWhy would Atlassian be better?
- nickpsecurity 7y agoThey were kind of a default since there's only a few huge ones. Main win: it's not Microsoft. MS already has lots of internal tools from MS Research they were wasting. They probably couldve built Semmle themselves. They're also a known patent troll. I don't know if Semmle's methods are patented, though. I'd rather a company like them not acquire them in favor of one that is constantly developing new services with no attempts to financially drain 3rd parties. Not to say good won't come out of Github integration given huge number of projects in it.
- tptacek 7y agoJust a small fraction of the industry's ongoing software development is done in C. Obvious, Google, Microsoft, Apple, and Mozilla still write a lot of it, but you don't acquire a whole company to address 4-and-change customers.
- nickpsecurity 7y agoThey'd have them retarget to what's popular post-acquisition in my concept. Especially among their paying customers. Keep adding languages or just useful things for it to look for.
- braindongle 7y agoThank you for the zero-indexed reference list. Brought a smile.
- chuckgreenman 7y agoInteresting to see the differences between Github and Gitlab's strategy in this arena. Github appears to be going the aqui-hire route with Semmle, dependabot, pullpanda etc, where as I don't think Gitlab's made an acquisition for a year or two.
- troydavis 7y agoGitLab published what they're interested in: https://about.gitlab.com/handbook/acquisitions/ https://about.gitlab.com/handbook/acquisitions/. It's an amazing, one-of-a-kind doc. One of their constraints (https://about.gitlab.com/handbook/acquisitions/#what-we-offer https://about.gitlab.com/handbook/acquisitions/#what-we-offe...) is quite limiting, though: > The total purchase price of the deal, paid in cash, will not exceed $1M and will be the total and only compensation for the entire deal.
- andrewprock 7y agoThey are looking at companies that: "Raised under $10M total investment funds, last round being over 3 years ago" This implies that in addition to self-funded ventures, they are looking for fire sales from failed start-ups.
- pnako 7y agoIt looks like they're buying (big) features, not complete solutions or companies. That's actually an interesting approach; I'm sure others do that, but maybe not as explicitly. It would allow a small team of hackers to have a decent exit without having to go through the whole startup road.
- claytonjy 7y agoGitlab hasn't generally seemed interested in these sorts of free scanning tools. I wonder if that's because their users are much more weighted towards private/self-hosted than Github's are? Because so little open source happens on Gitlab, they can't buy good PR through this kind of strategy like Github can.
- 7y ago
- archon810 7y agoSemmle's post: https://blog.semmle.com/secure-software-github-semmle/ https://blog.semmle.com/secure-software-github-semmle/.
- igammarays 7y agoI hate that these kinds of Orwellian phrases "Welcoming X to the Y Family" have now become idiomatic of corporate English. Ugh, no. There is no "family" involved here, not by any stretch of the word.
- javagram 7y agoTo be fair, if a “parent corporation” is a thing, then logically it has children and can be a corporate family.
- igammarays 7y agoIntent matters. The phrase "parent corporation" has no PR or emotional intent. "Welcoming X to Y family" has a clear emotive intent.
- andyfleming 7y agoMaybe the intent of the writer was to make the new hires feel welcome aboard to their new company. That's also not mutually exclusive of the emotive intent you are describing. What makes that Orwellian though?
- devmunchies 7y agoThe parent comment seems to be criticizing the higher-level corporate trend to use this lingo, and isn't talking about Friedman or Github specifically.
- deleted 7y ago[deleted]
- devmunchies 7y agoGithub has a cartoon cat-octopus all over the site I would expect as a baby toy. Clearly linked to "emotional intent" "Github is so fun, guys!" I think they've outgrown that style (the black and white one in the header is ok)
- pja 7y agoGithub has been really working on their source code analysis toolkit recently & this acquisition makes perfect sense as part of that strategy. Congratulations to Oege & the team.
- throwaway744678 7y ago> Human progress depends on the open source community. (Non native speaker here). Am I misunderstanding something, or is the author explaining that humanity can not progress without the open source community?
- networkimprov 7y agoThat's the meaning I took from it (USA native).
- mytailorisrich 7y agoThat's right. That's called hyperbole (with a 'e').
- sounds 7y agoAs the other comments point out, it's hyperbole. It's also an aspirational statement. Aspirational, as in, they wish that github would be the key factor in human progress. Maybe I can say that even plainer: to the leadership at github, the progress of the human race depends on github. The open source community depends on github. That's what it's implying. (The reader is left to identify that as wishful thinking.)
- rishicomplex 7y agoI've used semmle's tools at Google, they seemed pretty powerful.
- rishicomplex 7y ago"Human progress depends on the open source community." What a way to begin an article.
- chromeguy66 7y agoEspecially considering M$ owns GitHub
- dazbradbury 7y agoHuge congrats to Oege and the team at Semmle - couldn't be happier for a hugely passionate and smart individual (and a previous professor of mine!) Am sure this will bring some amazing advances to Github and thus a huge % of the developer community.
- notus 7y agoI spent way too long thinking that Semmie was just a badass programmer
- robbystk 7y agoSo this is the excuse they're using to build infrastructure to scan through everyone's code to find whatever they want.
- xvilka 7y agoFree hint for the GitLab - they can integrate a similar but open source tool - Infer[1]. Essentially it provides the similar features, just lacks a good interface to do so. They also have a query language, called AL[2]. It is way less polished than Semmle, but opensource and with a good potential. [1] https://github.com/facebook/infer https://github.com/facebook/infer [2] https://fbinfer.com/docs/linters.html https://fbinfer.com/docs/linters.html
- tom-jh 7y agoI've just tested their lgtm.com on our codebase: 1) identified str.replace('[ABC]+', '') correctly as a bug (looks like a regex but is string literal) 2) identified various unnecessary code that TypeScript overlooked 3) identified double-unescaping of html (this one would have probably gone unnoticed for years) And a bunch of other stuff. No actual vulnerability in our case, but still very useful. I'm enabling their checks on every future PR. This was TypeScript but they support the rest of our stack too (Python, Java). I wonder if this includes Kotlin - will try.
- tom-jh 7y agoTested, Kotlin is not supported, nor is Swift.
- z3t4 7y agoWould be cool if the tools would be made open source in order for everyone to get more security.
- fnord123 7y agoFirst project I look up on lgtm.com is rust.. Second alert I find is this: https://lgtm.com/projects/g/rust-lang/rust/snapshot/f5aa590b8ca98e925e5b1b975d7aef07e0c7a028/files/src/ci/docker/scripts/android-sdk-manager.py#x2e8f6c458bb40362:1 https://lgtm.com/projects/g/rust-lang/rust/snapshot/f5aa590b... exist_ok is available from python 3.2, so this isn't a good impression. https://docs.python.org/3.7/library/os.html#os.makedirs https://docs.python.org/3.7/library/os.html#os.makedirs