Skip to main content
Greg Vanore

Greg Vanore

Director of Software Engineering at Hunter Strategy, based in Greater Philadelphia.

Sep 3, 2026

34:42
the quarter, six weeks into the quarter when you're threat modeling a certain feature and realize, "Oh boy, we have a bigger problem here." That becomes an issue contractually, like you said.
34:54
Yeah.
34:55
Uh, s- so on a negative example side, I worked for, on a project for an agency that used a third-party tool t- for basically a, a content management system.
35:08
We'll just call it that, trying to be vague here.
35:10
And the content management system did have all sorts of security protections when you went through their UI, and similarly to what you were saying, Xander, with the developers saying, "Well, users can't do that, so therefore I don't have to worry about it." Someone in the third-party product determined that to make it integrate with other tools, they would add a WebDAV layer.
35:32
Well, all of the security was built into the user interface layer, so the WebDAV layer essentially kind of, you know, went around the back end and served all the content inside the system without any kind of permissions checks.
35:46
And we had been in production for a number of years, and we just kind of randomly, accidentally discovered this ourselves while using the product.
39:08
Greg, I'll let you go first.
4:07
And so why do you think, uh, so first off, let's just define what does that mean in, in your experience? And why do you think DoD was so careful to include that in its definition?
4:18
Well, I haven't read DoD's definition.
4:20
I'll have to let Nate answer that part.
4:22
But the contributor license agreement is basically when you submit to an open source project that has one of these, you have to agree to assign them copyright of your code, which allows them to relicense it as they see fit.
4:35
So, you know, you've seen controversial projects like Terraform most recently turn and relicense itself as a business source license and other projects as well.
4:46
I think Elasticsearch was one of the first.
4:48
And there's a little bit of an interesting thing going on there because usually what we view in this country of public tax dollar spends uh belongs to the public even if that's dod and so if you sign a contributor license agreement you are essentially giving uh the the fruits of that labor to a privately owned company but that's being done outside the oversight of the contracting process so i think it's really uh It may be not well understood by DOD CIO, but if you are engaging in those sort of things, like if you have to sign a CLA to contribute upstream, you're kind of like making a decision about giving tax funded works to a private institution, which can then profit from it.

9 MINS LATER

14:54
software has to be maintained is where they go with that.
38:30
... resources, like, let's just say resources, then it's not profit or anything, it's just from a resources perspective, am I getting more out than I'm putting in?
38:40
Yeah.
38:41
Yeah.
38:42
If you have a...
38:44
If you, when you, you build a microservice architecture, and you do it right and you have good observability, including, you know, distributed logging and tracing, and when you have a problem in production, you can solve that in 10 minutes versus spending three days solving it.
39:01
You know, these things, these things really affect the cost of the team and your ability to respond to change, all those things.
39:08
You know, these, these should not be discounted.
40:45
'Cause I didn't know.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.