Incognito unicorns.
There are many companies like these in security space. Another company I can think of is Rubrik. All these large security companies under the radar success.
Incognito unicorns.
There are many companies like these in security space. Another company I can think of is Rubrik. All these large security companies under the radar success.
https://www.bleepingcomputer.com/news/security/rubrik-rotate...
https://www.bleepingcomputer.com/news/security/rubrik-confir...
This one is straight up embarrassing:
https://techcrunch.com/2019/01/29/rubrik-data-leak/
> The exposed server wasn’t protected with a password, allowing access to anyone who knew where to find the server.
So much about "zero trust", at this point it's nothing but a marketing term and has lost it's true meaning
It's more likely backroom kickbacks (and/or mossad) than invisible unicorn.
Does it protect stuff? Somewhat.
Is it the best product out there - no.
Are CISOs happy? CSPM is mostly a checklist item in their bucket to things to do.
It depends on what kind of security you are working in. Most of the people in CSPM, CNAPP world have heard their name.
It is product built for cloud security/devsecops folks.
Would we (i.e. anyone not in the intelligence space) know how intelligence service-y software would look like ? . Aren't all such organizations trained and designed to be inconspicuous and in places we are unlikely to expect.
Also, if you've worked with Israeli government cybersecurity teams, they aren't much different in caliber from the kind you'd find at the NSA, GCHQ, or Netherlands.
I (and most here) wouldn't really know what that caliber is in these other organizations either to compare
What we do hear is of how the Hubble's tech stack is hand me down previous gen(i.e. 70s) spy satellites or exploits like Stuxnet, Pegasus or the recent pager supply chain attacks. On pure technical level those are all pretty impressive things well beyond what I or even anyone I may personally know do.
There of course is definitely certain amount of propaganda that would project much higher capability than reality, being mindful of that misdirection and the visible evidence, we civilians can only reasonably conclude that we will never have a clue what these organizations can or cannot actually do.
To save others looking up what 'suave arsim' meant:
1. suave -- a normal English the word for charming/confident
2. "arsim" [1] -- apparently a former ethnic slur for Mizrahi Jews [2] now repurposed to mean crude, loud and brash (which sound to me like the equivalent of the British slang term 'chav').
And saying "Mossad"-this/"Mossad"-that just feels like it's increasingly being used as a dogwhistle.
https://undercodenews.com/from-idf-intelligence-to-a-2b-goog...
A lot of the 8200 hype is just hype though, because Gili Ranaan and Shlomo Kramer became billionaires earlier than alumni from the other cyber units.
AquaSec is built by an Isreali company and looks and feels much like any other SaaS product.
Imagine if you found an authentication backdoor - a way to impersonate any account and you could start sucking down data. You do it for 5 billion people and charged google $6.40 per person not to put it on Tor.
$32 billion would be a steal.
Old but relevant - https://scheerpost.com/2022/11/01/revealed-the-former-israel...
No they aren't.
I've been a cybersecurity SWE, PM, and VC for a decade at this point and I've almost never found any relevant security or enterprise SaaS related content on HN.
For a hot second (around 2018-2019) there was solid conversations around eBPF, io_uring, or cloud posture management, but that doesn't happen on here anymore.
Same with MLOps and ML Infra as well - almost no one on here understands Infiniband, RDMA, or BLAS
The tech industry is MASSIVE - and most people are only clued into their own little niche. And according to HN, the only tech companies that exist are FAANG, Nvidia, Tesla, TSMC, and BYD.
Cybersecurity goes hand-in-hand with IT, DBA, Networking, DevOps, and OS/Systems Programming - all functions that were previously looked down upon over the last 15-20 years.
Furthermore, most American CS programs made OS internals, Computer Architecture, or Distributed Systems optional, so the junior portion of the ecosystem doesn't exist in the US anymore.
FWIW "here" could mean "in this thread". It's pretty normal (and very visible here) that threads about X attract people working in X. I'm not sure this is happening here, I work in IT security but I clicked the thread because 32B caught my eye.
Most of their competitors, like Palo Alto, have a very convoluted offering from gluing together several acquisitions. Wiz is very cohesive with a much nicer API and great UX, which is very underrated in the security space imo.
I have zero trust in Google’s promise to keep supporting the tool for multiple clouds or maintain the high quality of product design that makes Wiz great. It’s great for my job security, but I’d call it a net loss for the industry.
I actually don't care for Wiz's UX.
If you're a manager and just want to get an idea of what your security posture looks like, it's great. They have a million dashboards for you.
But if you're an AppSec Engineer that just wants to see which EC2 instances have which CVEs, it's kind of a pain in the pass and takes way too many clicks.
There's a single button I click that'll list all my VMs, then a single click (usually a middle click to open a new tab) to view all the CVEs in each VM.
That is the space
The performance matters much less than the UI
And the UI sucks because if you know what your doing you can type a command
But the people who write the cheques do not know that, and equate UI with GUI
So we get Azure (where I found this)
Squinting mousing and clicking a dozen times to do the equivalent of one rsync command....
IT security a very wide field. For example, a lot of positions in IT security are actually about compliance (i.e. lots of documentation), and ensuring the rollout of all necessary application patches in the whole company.
Sometimes the simpler explanation is the correct one.
I never even looked at a CSPM, and from my point of view[1] CSPMs are a tool only relevant for a small part of security teams focused on enterprise cloud security. Today is the first time I heard of Wiz.
edit Actually my partner works in policy/compliance/legal side of security, and I'm pretty sure she never heard of Wiz too.
[1] I wrote this only to stress how different people in the same field can see things differently.
I suppose if your company prefers to build over buy, you won’t be exposed to the kind of knowledge and vocabulary that buyers in the space use to orient themselves.
Here are some things that counter this:
https://users.ece.cmu.edu/~adrian/731-sp04/readings/Ptacek-N...: A paper that rocked the security industry at the time.
Tptacek also was cofounder of Matasano, now part of NCC; also cofounder of Latacora.
More info: https://sockpuppet.org/me/
Also the co-author of https://cryptopals.com/, https://microcorruption.com/login.
The author of https://www.latacora.com/blog/2018/04/03/cryptographic-right..., https://sockpuppet.org/blog/2015/01/15/against-dnssec/, https://sockpuppet.org/stuff/dnssec-qa.html,
These are about what I call hard-core security, hardly insanely niche, and hardly lacking critical knowledge.
What is a CSPM? Some cloud monitoring tool? What does it provide over open-source security and monitoring tools with years of field use that would make me invest time into it? Also, have these tools been thoroughly audited, scanned, fuzzed, and pentested by reputable people like some of the open source tools we've been using? Since tools are part of the attack surface, do these tools themselves increase or reduce it?
Serious questions since you think I should be very knowledgeable about these tools. My tech stack just works with minimal maintenance. So, I'd have to lose time on more important or fun stuff to even study CSPM or Wiz. Not counting setting it up.
1.) Most people here are likely not in security.
2.) I’m only adjacent to security but have heard of Wiz. If you work in security and haven’t, are you sure you’re good enough to subject us to your opinion?
For some reason I picked this hill to die on in this thread. I work in IT security for a long time, and I have never heard of Wiz. My focus is malware reverse engineering and adjacent subfields. I have no interest in anything Cloud.
"are you sure you’re good enough to subject us to your opinion" feels a bit dismissive.
I’d also bet on this being more of a kickback, rather than an invisible unicorn. Between a visible elephant (Trump/Israel) and an invisible unicorn, betting on an elephant is more reasonable.