"You can either prioritize the pile or have a smaller pile. And I'd love to start with the smaller pile."
Maor (00:00.451)
Hello, everyone, and welcome. Thank you for joining us for another episode of Backline Unfiltered. I’m super excited and happy to have Knox with us today. I’ll let him introduce himself in a second, but Knox was the guy that welcomed us into Sysdig when Sysdig acquired a policy. I reported to him throughout my entire time at Sysdig and he happened to be one of the best bosses I ever had.
Go ahead, Knox, and introduce yourself. I don’t know how to follow that one, but I’m Knox, I’m a product manager at Google right now working on vulnerability management, security risks, and threat detection. was lucky enough to work with Aron and Mayor for two and a half, almost three good years at Sysdig, and happy to be here today.
Knox Anderson (00:36.083)
don’t know how to follow that one, but I’m Nox. I’m a product manager at Google right now working on vulnerability management, security risks, some threat detection. was lucky enough to work with Aran and Mayor for two and a half, almost three good years at Sysdig and happy to be here today.
Eran Leib (00:56.562)
Thank you.
Maor (00:56.897)
Awesome, and we do have a run, dear co-founder, as well on the call.
We’re going to talk a little bit today about cloud and vulnerability management and shared responsibility model and how that’s evolving over the years. Where do we want to start?
Knox Anderson (01:19.859)
Let’s kick off with vuln management.
Maor (01:20.206)
Let’s kick off with vulnerability management. Sounds good. We’ve been reading a lot. I’ve been reading a lot about vulnerability management over the past year. I’m reading everything from what vendors are saying and everything from what Gartner is saying. And we see, I think more so in the last year, how vulnerability management is kind of shifting from
vulnerability management or risk-based vulnerability management into exposure management. think exposure management is definitely becoming, I think, something that many care about. Why do you think vulnerability management really hasn’t scaled and needs to still evolve despite everything that we’ve seen over the last few years?
Knox Anderson (02:14.288)
Yeah, I mean, if you look at exposure management and why it’s becoming important, it’s just another prioritization vehicle. So it just keeps on moving where first it was, hey, how do I do discovery? And then how do I attach that to cloud risk and misconfig and then how do I make sure it’s publicly reachable? But the heart of the problem still hasn’t really been solved, which is someone needs to go and patch that mole.
Maor (02:14.594)
Yeah, I mean, if you look at exposure management and why it’s becoming important, it’s just another prioritization vehicle. So it just keeps on moving where at first it was, hey, how do I do discovery? And then how do I attach that to cloud risk and misconfig and then how do I make sure it’s publicly reachable? But the heart of the problem still hasn’t really been solved, which is someone needs to go and patch that mold.
Knox Anderson (02:43.664)
That’s where there’s still open space and opportunity. And many people are just looking at how do I prioritize? But whether it’s secure-based images, so there are no vulns, or having agentic or AI workflows, or building scanning into your code generation processes and trying to be free from vulns from the start, those are areas that are open now. But it’s really been a prioritization problem.
Maor (02:43.903)
That’s where there’s still open space and opportunity. And many people are just looking at how do I prioritize, but whether it’s secure based images, so there are no volumes or having agentic or AI workflows or building scanning into your code generation processes and trying to be free from bolts from the start. Those are areas that are open now, but it’s really been a prioritization problem.
Knox Anderson (03:12.434)
And now I think the next frontier is, okay, you know what to fix. How do you go fix it?
Maor (03:12.782)
And now I think the next frontier is, okay, you know what to fix. How do you go fix it? Yeah, I was at a very interesting event, an HSBC event a couple of days ago in San Francisco and sorry about the beep, we should edit it out. I was at a very interesting event in San Francisco and HSBC event and there was a panel of CISOs talking about
challenges they’re seeing and unable to kind of move away from. And when it came to vulnerability management, to your point, a lot of what I heard was we’re still mostly prioritizing. We’re still mostly prioritizing because we don’t have enough bandwidth to fix all of these voles. And there was like significant worry, I think across the room and across many topics that AI will just
make the problem way bigger over the next few years between AI generating new code that it’s still not considered fully safe or just bad actors using AI to find new vulnerabilities at a quicker pace, new exploits and so forth and so on. Do you see or hear some of these things?
Knox Anderson (04:37.189)
Yeah, I think the Verizon report backs that up with some of the cloud breaches where for years it’s always been stolen keys or credentials are what cause breaches. But this past year, exposed instances with Volns was appear to that. And so that’s what’s driving a lot of this discussion is like, Hey, more workloads are being deployed as software in the cloud. And when that happens, you’re going to have more exposed instances with Volns.
Maor (04:37.494)
Yeah, I think the Verizon report backs that up with some of the cloud breaches where for years it’s always been stolen keys or credentials are what cause breaches. But this past year, exposed instances with vaults was appear to that. And so that’s what’s driving a lot of this discussion is like, Hey, more workloads are being deployed at software in the club. And when that happens, you’re going to have more exposed instances with vaults.
Knox Anderson (05:08.323)
It’s definitely something that is becoming a higher priority now because it’s actually getting compromised. And so I don’t think that’s going to stop anytime soon as there’s more things that keep on getting deployed, whether it’s an agent, whether it’s the same app modernization that we’ve seen. And so now it’s just, how do you prevent that from the start or remediate it as quickly as possible?
Maor (05:08.637)
It’s definitely something that is becoming a higher priority now because it’s actually getting compromised. And so I don’t think that’s going to stop anytime soon as there’s more things that keep on getting deployed, whether it’s an agent, whether it’s the same app modernization that we’ve seen. And so now it’s just how you prevent that from the start or repeat it as quickly as possible. Yeah.
Eran Leib (05:36.688)
Yeah, we keep forgetting that, you know, like, uh, it’s not just us, you know, like software vendors that actually deploy stuff. Now you have all sorts of people that have zero knowledge about anything and they start, you know, like vibe coding and deploying stuff. Um, and I was just having this conversation with someone who told me, know, like, um, I had this whole thing written by, and, like, it’s a professional. I had this whole thing written by cloud code and I just like supervised.
Maor (05:37.952)
We keep forgetting that, you it’s not just us, you know, like software vendors that actually deploy stuff. Now you have all sorts of people that have zero knowledge about anything and they start on like vibe coding and deploy stuff. and I was just having this conversation with someone who told me, know, like, I had this whole thing written by, and not it’s professional. had this whole thing written by call code and I’m just like supervised.
Eran Leib (06:06.692)
But I mean, would you deploy something like that to production? know, like it’s sketchy.
Maor (06:07.158)
But I mean, would you deploy something like that to production? know, like it’s sketchy. Yeah. Kind of similar. My aunt is a doctor, but she’s a diabetic. And so she cloned some GitHub repo to help her insulin monitoring and things like that. And my brother and I are sitting talking to her and we’re like, there’s no way that
Knox Anderson (06:14.96)
Yeah. Um, kind of similar. My aunt is a doctor, but she’s a diabetic. And so she cloned some GitHub repo to help her insulin monitoring and things like that. And my brother and I are sitting talking to her and we’re like, there’s no way that any of this is done securely, safely reliability, and it’s tied to her insulin pump. Uh, so
Maor (06:34.668)
Any of this is done securely, safely, reliability, and it’s tied to your insulin pump. So there’ll just be more ways for these types of things to happen for any person. I don’t really know how you secure that right now. Yeah. At least two different CISOs at the event. Wednesday said that they’ve used one of those platforms to build something.
Knox Anderson (06:41.946)
there’ll just be more ways for these types of things to happen for any person. And I don’t really know how you secure that right now.
Eran Leib (06:52.92)
Yeah.
Maor (07:03.627)
for themselves or for their team. Like someone said, I needed to present at a board meeting and I was just missing some stuff and I just went and built it. And I came to the board meeting and like, what’s this tool? And just built it because I needed it. And to your point, it’s a security person. They know all the risks and yet the productivity gain sometimes are just hard to…
you know, hard to ignore, hard to resist.
Knox Anderson (07:36.836)
Yeah, I built a Strava app on lovable, which is pulling and it can plot data and do all that kind of stuff. But my API key is in plain text and, it’s, it’s a, it’s a Strava API key. There’s not that much risk that can come from it. And I know that’s a problem.
Maor (07:37.099)
Yeah, built a Strava app on Loveable, which is pulling and can plot data and do all that kind of stuff. But my API key is in plain text, but it’s a Strava API key. There’s not that much risk that can come from it. And I know that’s a problem.
Eran Leib (07:53.509)
sorry. Yeah, but you have enough knowledge about it to know not to put anything which would be too risky for you out there. Most people have no idea about that and they will deploy that in a heartbeat and push in data that should definitely not be out there.
Maor (07:58.535)
It’s You have enough knowledge about it to know not to put anything which would be too risky for you out there. Most people have no idea about that and they will deploy that in a heartbeat and pushing data that should definitely not be out there.
Knox Anderson (08:01.999)
Thanks
Maor (08:18.632)
So, know, I heard the comment and had the conversation about it. There’s point to be made, I think, about how many organizations are playing, quote unquote, experimenting, working on AI agents and all of that stuff, probably a lot. How many actually deployed in production at a significant scale?
Eran Leib (08:18.798)
That’s great.
Maor (08:47.294)
I don’t know if we’re at a point where it’s significant. It could be over the next year or two or three, but I think from that perspective, the risk is still probably coming and not there just yet.
Knox Anderson (09:06.766)
I think it’s coming quickly. It’s like all technology curves, it’s slow until it’s fast. And I think this one is moving very fast.
Maor (09:07.018)
I think it’s coming quickly. It’s like all technology curves. It’s slow until it’s fast. And I think this one is moving very fast. Moving very fast. think it’s like to your point, this will be fast and then super fast. It feels like a cliche to say it, but it’s probably true. It’s the fastest I’ve ever seen.
And I’ve been in this space since 1997, eight and it’s, don’t remember anything moving so quickly, but that could be just my memory. We’ve been in all three of us for eating together, but.
Eran Leib (09:48.078)
I have a funny question. It’s not that funny because we’ve been in, all three of us were in it together, but you’re like after you’ve been doing, you know, like vulnerability management for so long and probably, know, personally was involved in, you know, like redesigning this whole thing multiple times. If you had to build one from scratch today with everything that you know from your past and with everything that you have right now with AI, how would you do that?
Maor (09:59.752)
really personally was involved in redesigning this whole thing multiple times. If you had to build one from scratch today with everything that you know from your past and with everything that you have right now with AI, how would you do that?
Eran Leib (10:18.517)
And you don’t need to give us a detailed design.
Maor (10:18.897)
And you don’t need to give us a detailed design. For now. mean, we’ve all built it small times and there’s so many good open source offerings right now for scanning. At least for scanners, I don’t think you can go wrong with what’s out there today, whether it’s Trivii, Scalibur, and osv.dev from Google, SIFT from Anchor.
Knox Anderson (10:21.121)
Yeah,
I mean, we’ve all built this multiple times and there’s so many good open source offerings right now for scanning that at least for scanners, I don’t think you can go wrong with what’s out there today, whether it’s Trivy, Scalibur and osv.dev from Google, SIFT from Anchor. So I probably wouldn’t build a scanner. would focus on…
Maor (10:47.881)
So I probably wouldn’t build a scanner. would focus on how do you have predictable code generation with vulnerability context.
Knox Anderson (10:53.364)
How do you have predictable code generation with vulnerability context?
Eran Leib (11:02.688)
Okay.
Maor (11:02.813)
Yeah, I subscribe to that. think that scanning is almost a commodity at this point. And doesn’t matter if you’re scanning code or scanning hosts or scanning network or whatnot. I think you’re at a point where the scanner piece of vulnerability management is almost a commodity. I do think that one area where I still see difference in quality
Eran Leib (11:05.899)
Yeah.
Maor (11:30.855)
is the vulnerability knowledge base is like the data behind it. And I think some are better than others, but the scanning mechanics, think it’s pretty, it’s a commoditized by now. I think it’s worth thinking about it by the way, because we’ve been all doing it the same way quite a few years now. mean, since I think, like Twistlock and Aqua kind of kicked it off like 10 years ago, it’s been pretty much the same.
Eran Leib (11:44.397)
think it’s worth thinking about it, by the way, because we’ve been all doing it the same way for quite a few years now. I mean, since I think, like, Twistlock and Aqua kind of kicked it off like 10 years ago, it’s been pretty much the same. And maybe if we look at it in a different… I don’t have a good answer for that. And I’ve been involved in some of the same processes, like the two of you have been as well. But maybe we should think about it, maybe the process itself of how we discover…
Maor (11:58.761)
And you know, maybe if we look at it in a different, I don’t have a good answer for that. And I’ve been involved in the same things, the same processes, you know, like the two of you have been as well, but maybe we should think about it. Maybe the process itself or how we discover is flawed to start with. Cause part of what we’re doing and I, you know, like I’ve been in the corresponding HSBC innovation day that was here in New York. There’s a lot of complaints around.
Eran Leib (12:13.612)
is flawed to start with, because part of what we’re doing, and I’ve been in the corresponding HSBC Innovation Day that was here in New York, there’s a lot of complaints around, you know, like, there’s a lot of noise, right? Some of it is not actual vulnerabilities, know, like, we know that the Genti-KI can solve some of that because, like, it will try to solve it, and it’s not a question of, I have enough people to even analyze it?
Maor (12:28.777)
you know, like, there’s a lot of noise, right? Some of it is not actual vulnerabilities, you know, like, we know that the GenTK, I can solve some of that because people try to solve it and it’s not a question of do have enough people to even analyze it. But maybe if we don’t have garbage in, then we won’t have to deal with it. Then we can have, you know, other ways to handle it. So, took the thought.
Eran Leib (12:41.878)
But maybe if we don’t have garbage in, then we won’t have to deal with it. Then we can have other ways to handle it. So just a thought.
Knox Anderson (12:52.556)
Yeah, you can either prioritize the pile or have a smaller pile. And I’d love to start with the smaller pile.
Maor (12:52.806)
Yeah, you can either prioritize the pile or have a smaller pile and I’d love to start with a smaller pile.
Eran Leib (13:00.885)
windows.
Maor (13:02.875)
Is that because of bad scanning or bad data? I’m actually, I’m not sure.
Eran Leib (13:06.673)
Good question. I’m not sure
bad data where on the on the coding side because for example
Maor (13:11.869)
but data were on the coding side? When someone says false, like we know there is a lot of significant claims, I’ll say, about false positives, right? This is not real, this is not the real vulnerability. So is that like the scanner mechanics fault? Is that a data problem? Is that because…
It’s a theoretical issue that is not really real in a specific customer environment or specific code because of reachability issues or things like that. think like because some will go to the extent of saying 90 % of this is false positive, which, which feels like, don’t know.
Eran Leib (13:49.418)
I think that’s what you’re speaking.
Eran Leib (13:58.879)
They would say 87 % and a half, would believe them saying 90 % to generic. But yeah, think reachability solves some of it. But you know, like in some cases we’ve seen, it’s the mechanics of the scan itself, right? You rely on the fact that there is something that says, you have this package. You have no idea what it’s using. And then comes reachability that says, okay, you have all that and you’re using A, B, C, But at the end of the day, even, you know, like from a security perspective and you’re like,
Maor (14:06.28)
But yeah, think reachability is so subtle, but in some cases we’ve seen it’s the mechanics of the scan itself, You rely on the fact that there is something that says, you have this package. You have no idea what it’s using. And then comes reachability that says, okay, you have all that and you’re using ABCD. But at the end of the day, even from a security perspective, like we’ve been in security for long enough, even having the package and then someone…
Eran Leib (14:28.329)
we’ve been in security for long enough, even having the package and then you’re like someone might be using dynamic that you don’t see in the code and that utilizes that is an actual breach. And you won’t see it because in the reachability will say, you’re not using it, right? So there’s, it’s a double-edged sword saying, know, like, you’re not using it then it’s not, it’s not an actual vulnerability. You need to think about all this.
Maor (14:34.178)
might be using dynamic that you don’t see in the code and that utilizes that as an actual breach. And you won’t see it because in the reachability, we’ll say, you’re not using it, right? So there is a double-edged sword saying, you’re not using it then. It’s not an actual vulnerability. You need to think about all this. It’s still a negative theory as well, because stuff that you know dynamically, won’t even know about it.
Knox Anderson (14:54.283)
Yeah.
Yeah, it’s still…
Eran Leib (14:57.576)
By the way, false negatives is here as well, because stuff that you load dynamically, won’t even know about it. And I’ve seen examples of how you can hide vulnerabilities that are out there, and you’ll never see them because what?
Maor (15:04.23)
And I’ve seen examples of how you can hide vulnerabilities that are out there and you’ll never see them because what?
Knox Anderson (15:13.356)
Yeah, I mean, it still comes back to it’s too easy to build insecure software. so this is where I do think ChainGuard has made a difference in terms of just like start from as clean as possible of a slate. And then within Google, we see more and more customers adopting things like autopilot because you don’t need to manage the note. So that’s the best systemic way.
Maor (15:13.628)
Yeah, I mean, it still comes back to it’s too easy to build insecure software. And so this is where I do think Shingles has made a difference in terms of just like start from as clean as possible of the fleet. then within Google, we see more and more customers adopting things like autopilot because you don’t need to manage the note. So that’s the best systemic way.
Knox Anderson (15:42.955)
to kind of go in and attack this problem.
Maor (15:43.271)
to kind of go ahead and tackle this problem. Yeah. Yeah, I agree. I think they did a really nice job and it’s evident by the amount of competitors they’re having over the last six months or so. But yes, I agree with the premise. Like you need to start as clean as possible. And I remember, you know, my very early days of let’s have
Knox Anderson (15:56.586)
Mm-hmm.
Eran Leib (15:56.712)
Yeah.
Maor (16:12.774)
a secured Windows image for our data center and how hard it was to actually A, build a secure image and then B, make sure that whatever app you’re running on this image can actually run and it can’t because it needs that service that you blocked or that whatever that the policy prohibits and you need to go and open that particular one and from one thing leads to the other and it’s a mess from a security perspective and I know.
We spend a lot of effort just trying to manage this thing. So when I hear from you, people preferring to run on something managed because they don’t want to do that themselves, it just makes perfect sense.
Eran Leib (17:01.917)
Yeah, it will get you so far. You still need to manage it up because it will give you a foundation, which is great, by the way, but still, you know, like managing it in the process and you’re like updating over time when there’s an update to the image. All that is still not, it’s a good foundation, but the process itself needs to be in place and there’s still work around that.
Maor (17:02.246)
Yeah, it will get you so far. You still need to manage it up because it will give you a foundation, which is great, by the way, but still managing it in the process and updating over time when there’s an update to the image. All that is still not… It’s a good foundation, but the process itself needs to be in place and there’s still work around that. By the way, it’s interesting. There is a lot of…
Knox Anderson (17:25.386)
Definitely.
Maor (17:30.341)
talk over the last few years about cloud being too expensive organizations because it’s expensive. And there are even like few prominent VC voices, which I’m not going to name that are like predicting the doom of the cloud because it’s too expensive. And now customers are going back to build their own data centers because cloud is, that’s the problem. The problem is not the cost of the, you know, CPUs and the network cards and whatnot. The problem is the operational
cost, managing it, managing it and safely and at scale and waking up in the middle of the night when something breaks. I think these are the real costs that in the end of the day just slows organizations significantly. When someone can take this problem off their plate, it’s worth a lot of money, obviously. I don’t see the cloud being, you You don’t see the demise of the cloud? I don’t see the demise of the cloud, no.
Eran Leib (18:23.42)
You don’t see the demise of the cloud?
Knox Anderson (18:28.627)
Not at all.
Maor (18:28.646)
No, no, no. Remind me not to be an LP of one of those VCs. I’ll share some, you will be surprised. They’re very, very smart people that are obviously very smart at things that in 10 years, it will all go back to on-prem data centers. don’t see it happening.
Eran Leib (18:30.364)
Remind me not to be an LP of one of those VCs.
Eran Leib (18:49.523)
very, very big prophecy.
Maor (18:57.999)
Cool.
Maor (19:02.639)
Do we want to jump to the next topic?
Knox Anderson (19:06.185)
Yeah, sounds good.
Maor (19:06.457)
Yeah, sounds good. Where do you want, what do you prefer to start, Nox?
Knox Anderson (19:21.202)
I mean, we can start with the, how is the shared responsibility model changing or?
Maor (19:21.518)
I mean, we can start with the how is the shared responsibility model changing or.
Maor (19:33.742)
Okay.
Knox Anderson (19:36.56)
And yeah, but just since we can cut this out, the part.
Maor (19:36.893)
And yeah, but just since we can cut this up apart.
Knox Anderson (19:44.883)
that I’m just a little worried about is the stuff that I want to say, but probably it’s the wrong thing to say. Yeah. Yeah.
Maor (19:45.209)
that I’m just a little worried about some stuff that I want to say, but probably it’s the wrong thing to say. Even if you said something wrong, Aaron will share the recording with you and we will cut everything out. nothing will go, nothing will go live before you see it and say it’s fine. So don’t worry.
Knox Anderson (19:55.986)
Okay.
Eran Leib (19:57.032)
Feel free.
Damn.
Knox Anderson (20:02.355)
No guess.
Maor (20:06.468)
Cool, or rather you want to ask the question?
Maor (20:15.812)
So do we start with a big topic or do we go with one of these questions? I think we can start with a big topic. Okay. So let’s move on to the next topic. How is your responsibility model changing? mean, you are now in Google Cloud, so you’ve seen it both ways. Give us your thoughts about that.
Eran Leib (20:15.97)
So do we start with a big topic or do we go with one of the least questions?
Knox Anderson (20:21.308)
I think we can start with a big topic.
Eran Leib (20:23.239)
Okay, so let’s move on to the next topic. How is your responsibility model changing? I mean, you are now in Google Cloud, so you’ve seen it both ways. Give us your thoughts about that.
Knox Anderson (20:39.78)
I think the concept is great because it gives a clear separation of like, hey, what is my problem as a cloud provider? What is your problem as a customer? The thing that I’m seeing change over time, and this is across clouds, like if I spin up an agent on AWS, it might spin up another service that’s a Fargate container. I spin up something on Google and there’s a cloud run instance, or there’s a service that’s then backed by a VM.
Maor (20:39.877)
I think the concept is great because it gives a clear separation of like, Hey, what is my problem as a cloud provider? What is your problem as a customer? the thing that I’ve seen change over time, and this is across clouds. Like if I spin up an agent on, AWS, it might spin up another service. That’s a Fargate container, spin up something on Google and there’s a cloud run instance, or, there’s a service that’s then backed by a VM. And so.
Knox Anderson (21:09.544)
You end up with the cloud providers doing more and more to secure your infrastructure, which is great. But then across the services that you use, there’s more service dependencies and it’s easier to spin up services with dependencies. that kind of semantic knowledge, the understanding of relationships, I think is getting more important, especially as you’re spinning up more workloads, more services, more agents. And so
Maor (21:09.828)
You end up with the cloud providers doing more and more to secure your infrastructure, which is great. But then across the services that you use, there’s more service dependencies and it’s easier to spin up services with dependencies. that semantic knowledge, the understanding of relationships, I think is getting more important, especially as you’re spinning up more workloads, more services, more agents. And so
Knox Anderson (21:39.759)
knowing your downstream service dependencies, what underlying infrastructure that that might be running on, is it my responsibility or the cloud’s responsibility, that map has gotten more complex. And so I think that’s an opportunity both for us as cloud providers to make that easier for customers to understand, and then also for external products to do that across clouds.
Maor (21:40.031)
knowing your downstream service dependencies, what underlying infrastructure that might be running on, is it my responsibility or the cloud’s responsibility, that math has gotten more complex. And so I think that’s an opportunity both for us as cloud providers to make that easier for customers to understand, and then also for external products to do that across all of us. You think customers are aware of all these?
Eran Leib (22:05.435)
Do you think customers are aware of all these dependencies that they’re creating, or is it kind of goes under the radar for them?
Maor (22:08.363)
dependencies that they’re creating, know, like, is it kind of like goes like under the radar for them.
Eran Leib (22:16.005)
I don’t know if the dependencies, I don’t know if they know the level of complexity that it gets.
Knox Anderson (22:16.104)
I think they’re…
Maor (22:16.503)
I think they really know about the dependencies. I don’t know if they know the level of complexity. Yeah. Yeah. I think you’re always aware of it when you create the service. But then it’s like anything and the longer it runs, the more you forget about it. And so at the time of starting.
Knox Anderson (22:23.14)
Yeah, I think you’re always aware of it when you create the service. But then it’s like anything, the longer it runs, the more you forget about it. And so at the time of starting, it’s definitely something where it’s clear, hey, you’re spinning up this other service. It’s backed by this, or here’s this new VM. But if it’s
Maor (22:40.674)
It’s definitely something where it’s clear, hey, you’re spinning up this other service. It’s backed by this or here’s this new VM. But if it’s two months later and I’m interacting with an agent, I might not know that that other service is still there.
Knox Anderson (22:50.033)
two months later and I’m interacting with an agent, I might not know that that other service is still there.
Maor (22:58.755)
And I think it makes like it’s it’s fair to say just because you’re saying agents that agents will make it way worse because I think it would be interesting to like I’m just thinking out loud. It would be interesting to see how this concept of what can agent use and rely upon. How flexible do you make it or strict do you make it? But if you know
If we’re thinking we want to have flexibility with the agents in terms of what they can do and data they can access, then this problem becomes way bigger and way more dynamic. When you are writing code, it is interacting with other services. It’s somewhat, remember or not to your point, I agree, but it’s still somewhat consistent. But if it’s an LLM, it’s doing one thing today, it’s going to do something else tomorrow. It’s impossible to predict.
Eran Leib (23:57.158)
Yeah, nobody knows.
Maor (23:58.081)
Nobody knows. Yeah, and I think there’s identity systems and all those types of things that are put in place now to make sure those connections are as secure as possible. But back to it’s in the code. That’s the part that gets really complicated. It’s like before you used to be able to look at a static resources config and understand what it could do, what it’s related to. Like CSPM has been around for a long time. But if I’m building an agent,
Knox Anderson (24:00.357)
Yeah. And I think there’s identity systems and all those types of things that are put in place now to make sure those connections are as secure as possible. back to it’s in the code. That’s the part that gets really complicated. It’s like before you used to be able to look at a static resources config and understand what it can do, what it’s related to. Like CSBM has been around for a long time, but if I’m building an agent, like that’s in the compiled code.
Maor (24:27.692)
Like that’s in the compiled code. And so that standards like CSPM workflow that you had is no longer possible in this new world. Yeah, it’s a really good point. I think identity will definitely solve a lot of it. But in the end, like I still go back to… It could be that some of these agents would just have…
Knox Anderson (24:29.566)
And so that standard CSPM workflow that you had is no longer possible in this new world.
Maor (24:56.779)
they will have permissions, but they will have a lot of permissions because they will need to do a lot of things. So it will be policy controlled, but just the policy will be too permissive. But yeah, it’s just gonna be interesting. It’s, we always go back to the visibility issue in security, right? How do I know who’s talking to who and who’s doing what? And it’s always.
Eran Leib (25:23.269)
which also goes back very basic, so least permissive and security is kind of repeating itself. Nothing is new, just like we’re applying it in different areas.
Maor (25:25.227)
Very basic, so least permissive and security is come repeating itself. Nothing is new, just like we’re implying it in different areas.
Eran Leib (25:37.733)
If we keep everything and the visibility is there, like you can…
Maor (25:38.113)
we keep everything and the visibility is there, then… Do we really see any new security challenge with these things or it’s solving the same security problems on different technologies and different stacks?
Knox Anderson (25:54.694)
That’s a good question. Cause it’s like, if you look at it from the attacker side, it’s like, want sensitive data. And so the outcome of what you want is still the same. So it’s like before you do resource abuse to mine crypto. Now you get a token and you use that to send spam texts. So the end goal is the same.
Maor (25:54.975)
That’s a good question. Because it’s like, if you look at it from the attacker side, it’s like I want sensitive data. And so the outcome of what you want is still the same. So it’s like before you do resource abuse to mine crypto. Now you get a token and you use that to send spam text. So the end goal is the same.
Knox Anderson (26:22.0)
But it does feel different because the technology is so different.
Maor (26:22.293)
But it does feel different because the technology is so different. feel like two things that changed dramatically in the last, let’s say, 10, 15 years, that really influenced security dramatically is one is velocity. We used to keep saying it, you know, that when we started our careers, you know, like two years ago.
Eran Leib (26:27.3)
feel like two things that changed dramatically in the last, let’s say, 10, 15 years, that really influenced security dramatically is one is velocity. We used to keep saying it, you know, like that when we started our careers, you know, like two years ago.
It used to be, know, like that we, you know, people would release code like every, you know, like six months and it would go through security scanning and everything would, know, security could pull the trigger and say, okay, you stop. You know, like everything comes to a standstill. That’s no longer the case. So it kind of, you know, like the, velocity of, of development and release changed, like, and it, it means that you have to change the way the security behaves.
Maor (26:49.505)
It used to be that people would release code every six months and it would go through security scanning and everything. Security could pull the trigger and say, stop. Everything comes to a standstill. That’s no longer the case. So the velocity of development and release changed and it means that you have to change the way the security behaves. And that’s not new, but it’s affecting even more now.
Eran Leib (27:15.811)
And that’s not new, but it’s affecting even more now because there’s more code that is being developed and it just goes up. The second thing is the scale, which also relates to this, right? The amount of code that is out there that you need to handle is also dramatically bigger. So if you used to have a monolith that would not change too much and just in the edges, you would add some capabilities. Now everything is just like…
Maor (27:19.916)
because there’s more code that is being developed and it just goes up. The second thing is the scale, which also relates to this, right? The amount of code that is out there that you need to handle is also dramatically bigger. So if you used to have like a monolith that would not change too much and just in the edges you would add some capabilities. Now everything is just booming.
Eran Leib (27:45.112)
booming. And again, the end goal is the same. You want to secure everything, everything has to be visible, blah, blah. But you know, like the mechanics of how it works is different. So it’s not like history is repeating itself. It’s, I feel like now it’s, it’s opening up like a big fan.
Maor (27:48.297)
Again, the end goal is the same. You want to secure everything, everything needs to be visible, blah, blah. But the mechanics of how it works is different. So it’s not like history is repeating itself. I feel like now it’s opening up like a big fan. Yeah, I remember meeting with a customer at a telco early in the container waves. So this is probably eight years ago now.
Knox Anderson (28:08.175)
Yeah, I remember meeting with a customer at a telco early in the container wave. So this is probably eight years ago now. And they said change management used to be my best friend and now they’re gone. And I can’t imagine what they would say today. Like at least he used to kind of plug into a CI CD pipeline and like the shift left movement and all of that happened. But the
Maor (28:18.1)
They said, cage management used to be my best friend and now they’re gone. And I can’t imagine what they would say today. like at least use the kind of plug into a CI CD pipeline and like the shift left movement and all of that happened. But. Part of this a bit more of a struggle now is like, do you plug in? Maybe outside of the code repo, it’s, it’s, there’s not a, that’s probably the only place where you can say, Hey, I might have.
Knox Anderson (28:34.542)
Part that’s a bit more of a struggle now is like, where do you plug in?
Eran Leib (28:38.765)
Yeah. Anything that you do.
Knox Anderson (28:41.248)
outside of the code repo, it’s, it’s, there’s not a, that’s probably the only place where you can say, Hey, I might have decent coverage.
Maor (28:47.776)
I think we will have to… Sorry, go ahead. It will be interesting to see what will happen with securing the inference layer with AI.
Eran Leib (28:49.123)
Yeah. And even that is not enough, right? You’ll connect to the code, but the code is not everything because it’s running on something which is running on something which is short responsibility, all this stuff, know, like it’s not, not everything is under your control. So, but you rely on it.
Knox Anderson (28:55.14)
and
Maor (29:19.931)
because I’m just thinking the unpredictability nature of the attacks, right? Which you could potentially easily hide in the unpredictability nature of the underlying model. So hey, my agent is writing code now. That’s fine. Maybe it’s to write code. Maybe it’s not.
Knox Anderson (29:48.205)
Yeah, and.
Eran Leib (29:48.385)
My agent asked me for my credit card.
Maor (29:48.7)
Yeah, and my character, Anthropic added a new capability to Agent called Skills a couple weeks ago and says, agents are executing code and doing more things now. so what an agent can do is going to increase. And so it’s still early. But I couldn’t think of a more exciting space to work in. For sure. For sure.
Knox Anderson (29:51.971)
Anthropic added a new capability to Agent called Skills a couple of weeks ago. so agents are executing code and doing more things now. so what an agent can do is going to increase. And so it’s still early, but I couldn’t think of a more exciting space to work in. Yeah.
Maor (30:17.663)
It’s going to be very, very interesting. actually think I’m going back to my own question. I actually think that all of these things will probably introduce new types of security concerns that we never had to deal with in the past. So it will be interesting. More stuff for us to do over the next 10 or 20 years.
Eran Leib (30:42.338)
We’re so early on in our career, know, like Noc says that he met someone eight years ago. We just started like two years ago. He’s older than us.
Maor (30:47.084)
We just started like two years ago, he’s older than us.
Maor (30:53.875)
Cool. That’s very interesting. Do we want to talk about one more thing or do we feel we can wrap it up? I’m just looking at the questions. Probably, OK. Yeah.
Knox Anderson (31:06.979)
think we’re probably okay.
Eran Leib (31:09.922)
Yeah.
Knox Anderson (31:16.003)
else I’m getting blown up in a thread.
Eran Leib (31:20.128)
A what?
Knox Anderson (31:21.38)
There’s also a thread right now that’s just,
Maor (31:26.535)
work. Exploding. Yeah. There’s no slack, right? If I remember correctly. Yeah. Which is actually, there’s not good threading, which is one thing I really miss. Yeah. Awesome. Thank you very much, Knox, for joining us. This was a pleasure, as always. You still owe me dinner, which hopefully we can catch up on at some point. Thank you very much.
Knox Anderson (31:26.624)
Exploding. Yeah.
Knox Anderson (31:31.393)
No, not yet. Which is actually, there’s not good threading, which is one thing I really miss.
Maor (31:54.143)
And thank you everyone who joined in to listen for another episode of Backline Unfiltered. Thanks for having me. And Aron, you still owe me a Ruben. So I’ll see you in New York. OK, let’s go. I’m afraid of you. I can only rely on you for Ruben. Thanks, Bye bye. Thanks.
Knox Anderson (32:01.507)
Thanks for having me in Iran. You still owe me a Ruben. So I’ll see you New York.
Eran Leib (32:06.305)
Okay, let’s go. can all meet in the urban. Bye bye.
Knox Anderson (32:11.213)
See you guys.
Knox Anderson (32:14.839)
Thanks.