HNHacker News
TopNewBestAskShowJobs

david_obrien

55 karma · joined May 25, 2021

Startup founder of ARGOS Cloud Security @ https://argos-security.io
submissionscomments
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks, those are great tips and I've just implemented some of those.

Thanks again, this is super helpful!

david_obrien··on Show HN: I made a cloud security product that actually saves time
A wildcarded principle by itself doesn't mean too much. There are settings outside of the S3 bucket access policy that can mean "it doesn't matter what the bucket thinks".

This here is something other products typically don't check, and because of that create a lot of noise that a person has to check through. https://www.youtube.com/watch?v=kMi5PSyFu8s

Other products only look at properties in isolation. As I mentioned the SG rules only become security relevant if many other things in an environment are also true, ARGOS checks for those, others typically don't. Only one example of our "context awareness".

The diagram shows the "kill chain" of how someone could laterally move through your environment, again something others typically don't do.

I said it before, we don't find more, we help you find the ones in the noise that actually matter from a security point of view.

david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks for the further details.

Did you see the short video on the first page? It's a bit further down and might need to be pulled up. We have two other videos under "Resources/Videos" as well.

I am currently working on a "longer demo video" that shows ARGOS's full potential and differentiation.

david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks!

Based on my understanding of CloudGuard we differentiate again by the "automated investigation" we do. It's not just a "you have misconfigured this thing here" but then also "because of that misconfiguration this following resource is now exposed to the internet (we checked, it is!) and it's exposing these other resources as well, look, here's a diagram that shows you this."

This is what products like CloudGuard expect you to manually do. They approach security from a compliance point of view. "You are violating control XYZ from framework ABC, so you are less secure." Unfortunately, it's not that simple.

An AWS EC2 instance should not have a Security Group on it that allows RDP from the internet, that's true and should probably be flagged, but in itself is not a security issue. It only is if the EC2 has a public IP (or a public Load Balancer), the VPC has an internet gateway and there's no NACL blocking the traffic. This is just one part of what ARGOS checks, what others just don't and expect you to do manually, for each of their hundreds and thousands of critical detections.

david_obrien··on Show HN: I made a cloud security product that actually saves time
oh wow, never noticed. I will see if I can disable that. That's an odd one.
david_obrien··on Show HN: I made a cloud security product that actually saves time
I am indeed. I've seen those issues one too many times as a consultant, and I never got to really(!) fix them as I was only ever brought in as a band aid really, not strategically.

Yeah, CNAPP is the new acronym for where we probably best fit right now. I will continue checking out some of the other players.

I initially had a 14 day trial, then people (not potential customers) told me that would not be long enough, so I increased it to 30. That did not make a difference at all. Smaller companies still signed up and converted, larger companies "ignored" any time limits and just assume that those don't apply to them.

Based on all the comments now I wonder if I should have a "base" plan that has the cost on the website and an Enterprise / Custom plan with a "Contact us" button. I pretty much know what a customer costs "on average", so that's not difficult.

Curious, did you see the short demo video on the website? There is a short one on the main site "below the fold" and there are two more in the "Resources/Videos" section. I am working on a longer version that I can send out to potential customers instead of a demo initially. Yeah, I've seen and felt the "single pain of glass" many times :D

I'd love to take you up on that offer, thanks, a lot!

david_obrien··on Show HN: I made a cloud security product that actually saves time
I appreciate that comment, thanks. It does feel a bit like a catch22, that I am definitely trying to solve.

ARGOS does have early paying customers, and of course they are heavily discounted (and they know).

You mention not telling a price is an issue (and so have others, point taken), but also say I shouldn't focus on price right now. I'm trying not to. So, what's your recommendation? Should I remove the page? Rename it to something like "Plans" and not "Pricing"? But then I'm still not telling you how much it will be. I know how to deal with this when talking to someone, but what I'd be really interested in what you would expect on a website, knowing what you told me.

Seriously, thanks!

david_obrien··on Show HN: I made a cloud security product that actually saves time
I used to be a consultant building exactly those designs, limit the blast radius, have separate accounts etc.

"In the earlier days" of ARGOS that's exactly why I didn't charge per Account, but different ways (tried # of resources, then % of spend) and people were always confused.

Similar to the "take the price off the website" that customers told me, me charging per Account is also what customers asked me to do.

What do you think would a good unit be for a product like this? I'm happy to try anything really, as long as it helps companies be more secure.

david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks, I'll definitely look into that.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks for that detailed response. ARGOS definitely feels more like an Enterprise / larger SMB product, unfortunately, I think this is mostly due to where people are really feeling "the need" for cloud security. I had many conversations with smaller organisations / startups and most of them said that they could not spend money on something like cloud security (AV and Firewall was #1 spend in those conversations, very interesting) or sometimes even didn't believe that cloud security was a problem ("doesn't Microsoft/Amazon take care of this for me?").

So, as much as I'd like to help smaller organisations, it seems only at a certain size do people really recognise this as a problem.

What do you think? Also, what made the site "targeted at Enterprise" in your opinion?

Also, yes, ARGOS is, for now, only public cloud, no private cloud.

Thanks again.

david_obrien··on Show HN: I made a cloud security product that actually saves time
That bot is gone now. Thanks for letting me know.
david_obrien··on Show HN: I made a cloud security product that actually saves time
I had to "save a bit" on the web designer, sorry. Focus was more on the product. The chat bot should have already been removed. I will do that asap.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks for your comment. As I mentioned to others, I followed what other companies are doing and what actual customers (not just Enterprises) asked me to do.

If I just put a "contact us for pricing" button onto the website, would that make you check the rest out and potentially sign up for a trial?

Also, ARGOS is still early and the pricing, to be completely transparent, is still very custom depending on the value a company communicates to me. It's not meant as a trick, otherwise I wouldn't give out a free trial for 14 days to everybody without even asking for a credit card. It's genuinely a "I don't really know yet how much to charge as a baseline".

david_obrien··on Show HN: I made a cloud security product that actually saves time
Again, fair comment. Frankly, I'm still figuring out what this would be worth to smaller organisations. ARGOS really scales by AWS Account / Azure Subscription / GCP Project right now and I'm currently charging "for each...".

I know what Enterprises are paying for ARGOS and some larger SMB, but not clear on what value smaller orgs or even startups assign to this problem.

david_obrien··on Show HN: I made a cloud security product that actually saves time
It's a fair comment, and I used to have prices on the website and then actual customers, while they were on their way to becoming customers, told us to take the prices offline. Their procurement teams really didn't like prices on the website. Doomed if you do, doomed if you don't. The trial is completely free, we don't ask for a credit card, only when you decide to want to become a customer, you can actually see the self service prices in your ARGOS dashboard. Those prices are also available via the Azure/AWS marketplaces.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Great question. First, I feel most of the integrations (aside from Slack) are really asked for by Enterprises. Smaller orgs don't really ask for those. Roadmap is absolutely around context, even more context. We want to get to the point where we're almost a cloud security lake (can't come up with a better word) where we know about everything that happens in the environment and allow you to make decisions almost on the spot based on what we show you. (Lateral movement possibilities by an attacker, what is actually running on those workloads and in what versions, who/what has access to them, etc) We're also looking to make our remediation engine more intelligent (not AI), but potentially allow you to give us a script we should execute to remediate, or trigger some other SOAR engine even. Right now remediation is whatever we think is a good remediation (and rollback) for an issue, but that's not always what you might want. Does that give you a view into my mind for a roadmap?
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks. Yeah, our website needs to be clearer on the differentiator. Part of this Show HN was to also see if people "get" what ARGOS does.

Right now the path only takes network into account (no, we do not look at flow logs). Lateral movement via IAM roles is on the plan for next quarter.

david_obrien··on Show HN: I made a cloud security product that actually saves time
Probably too much reliance on web designers. ;) I'll take that feedback and make some changes.
david_obrien··on Show HN: I made a cloud security product that actually saves time
I'm British, so I'm aware of the retailer. Thanks for the warning, we've been assured by many legal professionals that this should not be an issue. We tell everybody that we are not associated with them and that we are actually named after Argos Panoptes (https://en.wikipedia.org/wiki/Argus_Panoptes), the all-seeing giant.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks for that feedback. We have MSSPs as partners already and the pricing there is pretty much "custom". I haven't thought about "individual security consultants" yet. I assume they would rather prefer a "point in time" scan to what we currently do (continuous scan).

I did actually think about reaching out to Rumble at some point. They seem to have figured out the whole "unauthenticated workload info" that I'd love to see within ARGOS.

david_obrien··on Show HN: I made a cloud security product that actually saves time
Fair call. I will definitely need to check that. It seems like Chrome and Edge don't show those warnings. I will install Firefox and check what's up. Thanks.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks. Appreciate the comment. Overall it's been in dev for the last 18 months with some paying, early customers across Australia and Europe for the last 12 months. It's a small team, really only 3 people (plus an intern). We want to be as lean as possible, not too much overhead with roles that aren't really required. As you've seen, the product is built to be mostly self-service by customers, no need to talk to us.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Apologies, that should be fixed now. Bit more traffic than anticipated.
david_obrien··on Show HN: I made a cloud security product that actually saves time
Thanks. CSPM products usually are great at finding any misconfiguration (compliance violation) in a cloud environment and mapping it to a Compliance framework. This is important, compliance I mean, but I've seen numerous organizations struggle to find actual security issues within all those "compliance violations". Don't get me wrong, configuring AWS Account contact details, resource tags and not underutilising resources is important, but not really a security issue.

ARGOS takes (currently) a subset of controls from well-known frameworks (like CIS, NIST, etc) and maps them to security frameworks like MITRE Att&Ck, but also automatically investigates each misconfiguration to see if there are other things in the environment exposed because of this one misconfiguration (i.e. "is an AWS RDS exposed because its SG allows access from an EC2 that is publicly exposed?") and then draws a diagram of the immediate environment around this misconfiguration, literally showing a "path" (cyber kill chain) that someone could walk if they were to make it into the environment.

ARGOS doesn't claim to find MORE things in an environment, we save you time where you'd have to manually investigate each alert, we show more context than just "here's a single misconfigured property" and we even have remediation baked into the platform.

Really, ARGOS probably doesn't 100% fit into the CSPM category. We have users that use a CSPM AND ARGOS.