20Product: Is an AI Winter Approaching | The Future of AI Software Development: What is Real & What is BS | OpenAI: WTF is Going on & How Far Into Application Layer Do They Go | The Future Role of Software Engineers with Guy Podjarny
Guy Podjarny founded Tessl, Snyk and Blaze. Tessl is reimagining software development for the AI era and shaping AI Native Development. Snyk created and leads the Developer Security category, and is now a multi-billion dollar company with over 1,000 employees. Guy was previously CTO at Akamai (following its acquisition of Blaze), is an active angel investor, and co-hosts of the AI Native Dev podcast.
In Today's Episode with Guy Podjarny We Discuss:
03:02 Discussion on NVIDIA's Market Position
04:14 Will We See a Trough of Disillusionment in AI
07:36 The Future of AI Development and Specialized Models
10:17 Challenges and Opportunities in AI Dev Tools
17:41 Concerns About Closed vs. Open Development Platforms
21:27 Speculations on AI's Role in Application Layers
24:40 Google's Competitive Edge
25:28 IPO and M&A in the Trump Era
26:45 The Future Role of Software Developers
32:20 Security Challenges in AI Development
33:41 Spicy Questions and Charity Donations
36:05 Quickfire Round: Insights and Advice
How to Build in AI, Lessons From Early Days of Snyk with Founder Guy Podjarny
Guy Podjarny is the founder of Blaze, Snyk, and now Tessl. He’s spent decades building at the center of developers and security. His newest company Tessl is reimagining software development, helping shape a new paradigm he calls AI Native Development.
We talk through his four quadrant framework for building and investing in AI, plus go into the early days of Blaze and Snyk. He shares lessons on marketing to developers, hiring when no one wanted to work for him, overcoming multiple difficult funding rounds, and lessons from multiple M&A processes.
Timestamps:
(00:00) Intro
(02:21) The four quadrants of building and investing in AI
(14:59) Why AI startups are riskier than non-AI startups
(19:42) When to sell your company vs keep building
(24:57) Why hiring the early team is so hard
(26:32) Early marketing tricks from Guy’s first company, Blaze
(29:09) Strategies for using conferences to grow your brand
(33:33) Getting three days of free PR
(38:04) Moving to Ottawa
(42:11) Why Sales Engineer is an underrated founder stepping stone
(45:49) What he learned as CTO of Akamai
(48:31) Starting his third company Tessel, and why there’s no satisfaction without struggle
(50:41) How Snyk got started
(54:10) Creating developer-first security
(59:59) Secrets for developer marketing
(01:02:31) Why podcasts work so well for marketing
(01:06:26) Snyk’s failed Series A
Referenced
Tessl: https://tessl.io/
Snyk: https://snyk.io/
Charting Your AI Native Journey: https://www.tessl.io/blog/charting-your-ai-native-journey
Secure Developer Podcast: https://snyk.io/podcasts/the-secure-developer/
AI Native Dev Podcast: https://www.tessl.io/podcast
We didn’t mention it in the podcast, but Guy just announced the AI Native Dev Conference, a virtual conference on Thurs, November 21st. Join him + many others here https://ai-native-devcon.heysummit.com/
Follow Guy
Twitter: https://x.com/guypod
LinkedIn: https://uk.linkedin.com/in/guypo
Follow Turner
Twitter: https://twitter.com/TurnerNovak
LinkedIn: https://www.linkedin.com/in/turnernovak
Newsletter: https://www.thespl.it/
#205 Randall Degges: The Biggest Risks of AI-Generated Code (What Developers Need to Know!)
This episode is sponsored by Bloomreach.
Bloomreach is a cloud-based e-commerce experience platform and B2B service specializing in marketing automation, product discovery, and content management systems.
Check out Bloomreach: https://www.bloomreach.com
Explore Loomi AI: https://www.bloomreach.com/en/products/loomi
Other Bloomreach products: https://www.bloomreach.com/en/products
In this episode of the Eye on AI podcast, we sit down with Randall Degges, Head of Developer Relations and Security at Snyk, to uncover the impact of AI on cybersecurity and software development.
Randall shares his 20+ years of experience as a software developer and security expert, leading us through Snyk's innovative approach to developer security. We dive into how Snyk is changing vulnerability detection and code generation by leveraging a hybrid AI model—combining symbolic AI for accurate detection and generative AI for smart fixes.
We explore the challenges and opportunities of using AI in code security, discussing whether AI-generated code can ever fully replace human coders or if it's best suited as a powerful tool in a developer's arsenal. Randall also addresses the risks of AI hallucinations in code generation and how Snyk mitigates these through rigorous testing and validation.
Join us as we discuss the future of coding, the role of AI in software development, and how developers can stay ahead in this rapidly evolving landscape.
Don't forget to like, subscribe, and hit the notification bell for more expert insights into the latest AI and cybersecurity trends.
Stay Updated:
Craig Smith Twitter: https://twitter.com/craigss
Eye on A.I. Twitter: https://twitter.com/EyeOn_AI
(00:00) Preview and Intro
(00:34) Randall Degges Background
(01:33) The Role of AI in Security at Snyk
(03:28) Symbolic vs. Generative AI in Code Security
(04:57) How Snyk Uses Rule-Based AI for Detection
(06:48) Challenges with AI-Generated Code Fixes
(09:08) The Future of AI in Code Generation
(11:56) Integrating AI with Developer Tools
(16:06) Risks of AI-Generated Code and Internet Saturation
(22:25) The Hybrid AI Approach for Code Security
(26:31) Future of AI and Its Impact on Developers
(30:02) Snyk's Integration with IDEs and Research Initiatives
(33:48) Autonomous Fixes and the Future of AI in Development
(41:04) DeepCode AI Fix Engine and Snyk's ID Plugin
(46:38) Will AI Replace Developers?
(50:16) AI Readiness Report Insights
(52:59) Tech Layoffs and Opportunities in AI
How Snyk Gets Buy-In to Improve Security with Chen Gour Arie
Chen Gour Arie, Director of Engineering at Snyk, joins Corey on Screaming in the Cloud to discuss how his company, Enso Security, got acquired by Snyk and what drew him to Snyk’s mission as a partner. Chen expands on the challenges currently facing the security space, and shares what he feels are likely outcomes for challenges like improving compliance across value-add on security tools and the increasing scope of cybersecurity at such a relatively early phase of the industry’s development. Corey and Chen also discuss what makes Snyk so appealing to developers and why that was an important part of their growth strategy, as well as Chen’s take on recent security incidents that have hit the news.
About Chen
Chen is the Co-founder of Enso Security (part of Snyk) - the world's 1st ASPM platform. With decades of hands-on experience in cybersecurity and software development, Chen has focused his career on building effective application security tools and practices.
Links Referenced:
Snyk: https://snyk.io
Snyk AppRisk: https://snyk.io/product/snyk-apprisk/
Transcript
Announcer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.
Corey: Welcome to Screaming in the Cloud. I’m Corey Quinn. This promoted guest episode is brought to us by our friends at Snyk, and as a part of that they have given me someone rather distinct as far as career paths and trajectories go. Chen Gour Arie is currently a director of engineering over at Snyk, but in a previous life—read as about six months or so ago—he was a co-founder of Enso Security, which got acquired. Chen, thank you for joining me.
Chen: Thank you for having me, Corey.
Corey: So, I guess an interesting place to begin is, what has the past couple of years been like? And let’s dive in with, what is or was Enso Security?
Chen: Yeah. So, Enso started for me first as friendship because I joined the team that I was working with as a contractor for a while. There was such an excellent and interesting team with a very interesting environment. And then after a while, they asked me to join that team, and then I became part of the security team of a company called Wix.com.
It’s quite a large company, web do-it-yourself kind of platform, that you can build your own website with a presentation style kind of interface, and our job was to secure that. And we formed a very, very nice friendship throughout it, but we also gained a lot of experience because you work with such a large company, and you experience many challenges, including real-time attempts to penetrate, and the complexity of social engineering at large scale. You go through a lot of things. So, this was the start. And after a couple of years, we decided that we have some interesting ideas that can do good to the community in the cybersecurity industry, and we embarked on a new journey together to start Enso.
Corey: I can see why you aligned with Snyk. It sounds like a lot of what you were aimed at is very much in step with how they tend to approach things. I have a number of sponsors that I can say this about, but Snyk is a particularly fun one, in that, obviously, you folks pay me to run advertisements and featured guest episodes like this, which is appreciated, but we also pay you as a customer of Snyk because it does a lot of things that we find both incredibly useful and incredibly valuable. The thread that I’ve seen running through everything coming out of Snyk has been this concept of, I think, what some folks would say shifting left, but it comes down to the idea of flagging issues as early in the process as possible rather than trying to get someone to remember what they did three months ago, and oh, yeah, go back and address that. That alone has made it one of the best approaches to things that are truly important—and yes, I consider security to be one of those things—that I’ve seen in a while on the dev tool space.
Chen: Yeah, and this has been the mission of Snyk for a very long time. And when we started Enso, our mission was to help in some additional elements of the same problem space in introducing additional tools to help drive this shift left, this democratization of the security effort around and in the organization, and resolving some of the friction that is created with the, kind of, confusing ownership of security and software development. So, this was kind of the mission of Enso. The category introduced by it and the ASPM category to bring the notion of postural security, postural management to applications. And it really is a huge fit with the journey of Snyk, and we were very excited to be approached by them to join their journey and help them do further shift left and extend on problem space on the complexity of this collaboration between security and developers.
Corey: A question I have around this is that it seems to me that viewing security posture management from an application perspective, and then viewing other parts of it from a cloud provider perspective and other parts of it from a variety of different things—you know, go to RSA and walk up and down the endless rows of booths, and you know, look at the 12 different things that they’re all selling because it’s all the same stuff around 12 categories or so, with different companies and logos and the rest—it feels like, on some level, that can lead very quickly to a fractured security posture where, well this is the app side of the security, and then we have the infrastructure security folks, but those groups don’t really collaborate because they’re separate and distinct. How do you square that circle?
Chen: Yeah, it’s not an easy problem, and I think that the North Star of many vendors exists this notion of sometimes I think we call it CNAP or something that will unify all of it. Cloud as a solution, and the offering that exists with cloud computing enables a lot of it, enables a lot of this unification, but we have to remember that the industry is young. The software security industry in general is young. If we will look at any other industry with that size, all of them have much more history and time to mature. And inside this industry, the security itself is even younger.
It has become a real problem much later than then when software started. It has become a huge problem when cloud emerged and became, like, the huge deal that it is now. And when more and more businesses are based on digital services, and more people are writing software, a lot of it is young, and it needs time to mature, and it’s time to get to—to accomplish some big parts like this unification that you are pointing out missing.
Corey: I have to confess my own bias here. A lot of the stuff that I build is very small-scale, leverages serverless technologies heavily, and even when I’m dealing with things like the CDK, where I start to have my application and the infrastructure that powers it coalesce into the same sort of thing, it becomes increasingly difficult, if not outright impossible for some of these config...
Taking a Hybrid AI Approach to Security at Snyk with Randall Degges
Randall Degges, Head of Developer Relations & Community at Snyk, joins Corey on Screaming in the Cloud to discuss Snyk’s innovative AI strategy and why developers don’t need to be afraid of security. Randall explains the difference between Large Language Models and Symbolic AI, and how combining those two approaches creates more accurate security tooling. Corey and Randall also discuss the FUD phenomenon to selling security tools, and Randall expands on why Snyk doesn’t take that approach. Randall also shares some background on how he went from being a happy Snyk user to a full-time Snyk employee.
About Randall
Randall runs Developer Relations & Community at Snyk, where he works on security research, development, and education. In his spare time, Randall writes articles and gives talks advocating for security best practices. Randall also builds and contributes to various open-source security tools.
Randall's realms of expertise include Python, JavaScript, and Go development, web security, cryptography, and infrastructure security. Randall has been writing software for over 20 years and has built a number of popular API services and open-source tools.
Links Referenced:
Snyk: https://snyk.io/
Snyk blog: https://snyk.io/blog/
20VC: Why Being First To Market Does Not Matter, Why You Do Not Have Defensibility on Day 1, How to Analyse Market Size and Present it to Investors, Vitamins vs Painkillers; Do Vitamins Survive Recessions and Good vs Great Messaging with Guy Podjarny @ Sn
Guy Podjarny is the Founder of Snyk, the leading Developer Security platform, helping developers secure as they build. Guy was previously CTO at Akamai, co-founded Blaze.io (acquired by Akamai), and was the product manager of AppScan, the first AppSec scanner, through Sanctum, Watchfire and IBM. Guy is a public speaker, O'Reilly author, and an active early stage angel investor.
In Today's Episode with Guy Podjarny We Discuss:
1.) From Israeli Military to Founding a $10BN Company:
How Guy made his way into the world of startups from the Israeli military?
What is Guy running away from? Why does he hate tribalism so much?
Does Guy believe serial entrepreneurship is valuable or naivety of young founders is good?
2.) The Secret to Finding Product Market Fit:
Why does Guy believe PMF is a poorly defined term? How does Guy define PMF?
What are the single biggest mistakes founders make while searching for PMF?
What are the most important elements on messaging when it comes to PMF?
If you have a horizontal tool, how do you message and resonate with specific audiences?
3.) Defensibility and Being First to Market:
Does Guy believe that being the first to market is really that valuable?
Does Guy agree that investors expecting defensibility on day 1 is wrong?
Why does Guy think market leadership is way more important than first to market?
What are the true defensible moats that can be built early today?
4.) Lessons from 100 Angel Investments:
What have been the single biggest lessons for Guy from his 100 angel investments?
What are the biggest mistakes angels make when investing today?
How should founders present their market size to investors? Where do they go wrong?
Does Guy invest in both painkiller and vitamin businesses? How does he compare them?
Why is Boldstart Guy's favorite venture capital firm?
Security for Speed and Scale with Ashish Rajan
About Ashish
Ashish has over 13+yrs experience in the Cybersecurity industry with the last 7 focusing primarily helping Enterprise with managing security risk at scale in cloud first world and was the CISO of a global Cloud First Tech company in his last role. Ashish is also a keynote speaker and host of the widely poplar Cloud Security Podcast, a SANS trainer for Cloud Security & DevSecOps. Ashish currently works at Snyk as a Principal Cloud Security Advocate. He is a frequent contributor on topics related to public cloud transformation, Cloud Security, DevSecOps, Security Leadership, future Tech and the associated security challenges for practitioners and CISOs.
Links Referenced:
Cloud Security Podcast: https://cloudsecuritypodcast.tv/
Personal website: https://www.ashishrajan.com/
LinkedIn: https://www.linkedin.com/in/ashishrajan/
Twitter: https://twitter.com/hashishrajan
Cloud Security Podcast YouTube: https://www.youtube.com/c/CloudSecurityPodcast
Cloud Security Podcast LinkedIn: https://www.linkedin.com/company/cloud-security-podcast/
Snyk and the Complex World of Vulnerability Intelligence with Clinton Herget
About Clinton
Clinton Herget is Field CTO at Snyk, the leader is Developer Security. He focuses on helping Snyk's strategic customers on their journey to DevSecOps maturity. A seasoned technnologist, Cliton spent his 20-year career prior to Snyk as a web software developer, DevOps consultant, cloud solutions architect, and engineering director. Cluinton is passionate about empowering software engineering to do their best work in the chaotic cloud-native world, and is a frequent conference speaker, developer advocate, and technical thought leader.
Links Referenced:
Snyk: https://snyk.io/
duckbillgroup.com: https://duckbillgroup.com
How Snyk built a product-led growth juggernaut | Ben Williams (VP of Product at Snyk)
Ben Williams is VP of Product at Snyk, an industry-leading security platform for developers, last valued at $8.5b. He’s also a product and growth advisor with over 20 years of experience building and scaling high-performing product and growth teams. Through product-led growth, product-led sales, and community, Snyk rapidly scaled and won over the lucrative developer audience. In today’s episode, Ben shares the successful growth levers that helped Snyk get started, all of the details of how Snyk has structured their growth, product, and marketing teams and set them up for success in terms of cross-collaboration—and also how their initial plan for self-serve monetization fell flat. We go into Ben’s many useful tips for product-led growth, including his thoughts on free vs. paid versions, trials, and how to build amazing growth teams.
—
Find the full transcript here: https://www.lennysnewsletter.com/p/how-snyk-built-a-product-led-growth
—
Where to find Ben Williams:
• Twitter: https://twitter.com/semanticben
• LinkedIn: https://www.linkedin.com/in/semanticben/
—
Where to find Lenny:
• Newsletter: https://www.lennysnewsletter.com
• Twitter: https://twitter.com/lennysan
• LinkedIn: https://www.linkedin.com/in/lennyrachitsky/
—
Thank you to our wonderful sponsors for making this episode possible:
• Coda: https://coda.io/lenny
• Athletic Greens: https://athleticgreens.com/lenny
• Vanta: https://vanta.com/lenny
—
Referenced:
• Snyk: https://snyk.io/
• Weekly Team Impact & Learnings Review Template: https://docs.google.com/document/d/1GibNaJ4aONgp5Kg824NCionr1citHIDk3FLvMdkpX_Q/edit?usp=share_link
• Monthly Group Impact & Learnings Review Template: https://docs.google.com/presentation/d/1nQ18OTuRtc8urBnUWEObD_BlfdGDKlDDMFg8-G2GK7E/edit?usp=share_link
• Experiment Plan Template: https://docs.google.com/document/d/18LiGXKphGe1tUpZCQA20i4bJqf-S3kDbYnY4Pls_9kQ/edit?usp=share_link
• Vision & Mission Framework: https://docs.google.com/presentation/d/1CiRwscu-50lBr2c7yRLY_zXVzv5DCnYqNnS5Au83WC8/edit?usp=share_link
• Ed Sim’s newsletter: https://whatshot.substack.com/
• Tamar Yehoshua on Twitter: https://twitter.com/tyehoshua
• Julian Shapiro on Lenny’s Podcast: https://www.lennyspodcast.com/growth-tactics-retention-strategies-and-becoming-a-better-writer-julian-shapiro-demand-curve-hyper-webflow-techcrunch/
• Annie Duke’s website: https://www.annieduke.com/
• Elena Verna on Lenny’s Podcast: https://www.lennyspodcast.com/elena-verna-on-how-b2b-growth-is-changing-product-led-growth-product-led-sales-why-you-should-go-freemium-not-trial-what-features-to-make-free-and-much-more/
• Growth loops: https://www.reforge.com/blog/growth-loops
• Brian Balfour on using learnings: https://brianbalfour.com/growth-machine/maximize-learning
• Adam Fishman on Lenny’s Podcast: https://www.lennyspodcast.com/videos/how-to-build-a-high-performing-growth-team-adam-fishman-patreon-lyft-imperfect-foods/
• Amplitude: https://amplitude.com/
• FullStory: https://www.fullstory.com/
• User Interviews: https://www.userinterviews.com/
• User Testing: https://www.usertesting.com/
• Sprig: https://sprig.com/surveys
• Airtable: https://www.airtable.com/home/toolkit
• How to Measure Anything: Finding the Value of “Intangibles” in Business: https://www.amazon.com/dp/0470110120/
• Sprint: How to Solve Big Problems and Test New Ideas in Just Five Days: https://www.amazon.com/Sprint-Solve-Problems-Test-Ideas/dp/150112174X
• Make Time: How to Focus on What Matters Every Day: https://www.amazon.com/gp/product/B078QSCM3V/
• This Is How They Tell Me the World Ends: The Cyberweapons Arms Race: https://www.amazon.com/This-They-Tell-World-Ends/dp/1635576059
• Acquired podcast: https://www.acquired.fm/
• Turning Red on Disney+: https://www.disneyplus.com/movies/turning-red/4mFPCXJi7N2m
• Curb Your Enthusiasm on HBO: https://www.hbo.com/curb-your-enthusiasm
• Christine Itwaru’s blog: https://prodops.blog/
—
In this episode, we cover:
(04:44) Ben’s background
(07:27) What is Snyk, and what’s the current scale?
(08:45) Why Ben joined Snyk
(09:29) How Snyk got their first 100 users
(15:14) How Snyk used developer conferences and in-person meet-ups to launch
(19:23) How Snyk used GitHub as a growth lever
(23:50) Snyk Advisor, and other growth loops Snyk successfully used
(26:56) Snyk’s failed attempt at self-serve monetization
(31:21) How to win the hearts and minds of developers
(33:38) How adding sales and marketing teams helped Snyk gain momentum
(35:11) The evolution of Snyk’s growth team
(37:26) Snyk’s key areas of growth and how Ben solved tension between teams
(39:32) What is Snyk’s decision science team?
(40:59) Why Snyk has a growth marketer embedded on each team
(43:39) The importance of having an amazing SEO person
(46:21) Advice on building growth teams
(51:32) Ben’s vision and mission framework
(53:53) More on the growth process and experimentation
(56:04) Using learnings as a path to impact
(57:32) Growth strategy
(1:02:26) Data in growth teams
(1:06:33) How Snyk socializes learnings
(1:10:05) How Snyk structures their product org
(1:13:15) Free vs. paid features and how to approach trials
(1:18:57) Activation milestones at Snyk
(1:23:05) The most valuable tools for Snyk’s growth team
(1:25:21) Lightning round
—
Production and marketing by https://penname.co/. For inquiries about sponsoring the podcast, email podcast@lennyrachitsky.com.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.lennysnewsletter.com/subscribe
SaaStr 534: Marketing Secrets to Hypergrowth from Building Elastic, Zuora, and Segment
Panelists:
Katrina Wong, VP Marketing and Demand Generation Segment
Asawari Samant, Head of Marketing, Anyscale
Jeffrey Yoshimura, CMO and Customer Experience Officer, Snyk
Three marketing leaders discuss the importance of community, data, and experimentation, as well as the do's and don'ts of using agencies.
This episode is an abbreviated version of the session. You can see the full session here: https://youtu.be/7wucuUQSQvQ
Blog post: https://www.saastr.com/marketing-secrets-to-hypergrowth-from-building-elastic-zuora-and-segment/
Want to join the SaaStr community? We're the 🌎largest community for B2B software.
Subscribe for weekly updates: https://www.saastr.com/subscribeform
Twitter: https://twitter.com/saastr
LinkedIn: https://www.linkedin.com/company/2724976
Quora Group: https://www.quora.com/q/cloud
Facebook: https://www.facebook.com/SaaStr/
Instagram: https://www.instagram.com/saastr/
Our North American Event: https://bit.ly/2OXeAYh
Our European Event: https://bit.ly/2OZTad8
“Snyk”ing into the Security Limelight with Clinton Herget
About Clinton
Clinton Herget is Principal Solutions Engineer at Snyk, where he focuses on helping our large enterprise and public sector clients on their journey to DevSecOps. A seasoned technologist, Clinton spent his 15+ year career prior to Snyk as a web software engineer, DevOps consultant, cloud solutions architect, and technical director in the systems integrator space, leading client delivery of complex agile technology solutions. Clinton is passionate about empowering software engineers and is a frequent conference speaker, developer advocate, and everything-as-code evangelist.
Links:
Try Snyk for free today at: https://snyk.co/Screaming-in-the-Cloud
Security and Snyk, with Kamil Potrec
Kamil Potrec is a Senior Security Engineer at Snyk, working on security around Kubernetes and cloud platforms. He joins the show to discuss how to think about securing your infrastructure, the different arts (and colors) of offensive and defensive security, and what not to lose sleep over.
Do you have something cool to share? Some questions? Let us know:
web: kubernetespodcast.com
mail: kubernetespodcast@google.com
twitter: @kubernetespod
Chatter of the week Episode 23, with Andrew Philips and Lars Wander
A pile of mail and a bike
News of the week Red Hat OpenShift 4.7 is GA
Fairwinds Insights 3.0
Envoy zero-day patched Istio security bulletin
Sysdig contributes Falco modules to the CNCF
StorageOS raises $10m in Series B
Platform9 raises $12.5m in Series D
CNCF relaunches Kubernetes Community Day with KCD Africa and Bengaluru
Links from the interview Offensive unit in American Football
Hand-egg
Red and blue teams
Unreal Tournament
Capture the flag
Kubernetes secrets Design document
Encrypting secrets at the application layer
Antivirus software
Tracer-tee
SolarWinds attack
Reflections on Trusting Trust by Ken Thompson
left-pad deleted from NPM
Snyk Open Source The open source parts
Snyk vulnerability database
MITRE CVE database
Kubernetes security at Snyk
Deploy only trusted containers to GKE
Application threat modeling
Kubernetes security best practices, including security context, AppArmor, gVisor etc
CVE-2020-8554: man-in-the-middle attack using ExternalIP services
CVE-2020-14386: packet socket vulnerability with user namespaces enabled Earlier related work: CVE-2017-7308 and CVE-2016-8655
Project Zero writeup
Rewrite it in Rust!
Kamil Potrec on LinkedIn
SaaStr 205: The Secret To Building A Truly Successful Freemium Product | The 3 Classes of Product & How To Think About Feature Prioritisation | A Framework For Building Strong Cross-Functional Communication Across Locations with Guy Podjarny, Founder & CE
Guy Podjarny is the Founder & CEO @ Snyk, the developer-first solution that automates finding and fixing vulnerabilities in your dependencies. To date, Guy has raised over $32m in VC funding from Snyk from some of the great of venture including Accel, GV, our friends at Boldstart and Canaan Partners, just to name a few. As for Guy, prior to Snyk, he was the CTO of Akamai's Web Performance Business following their acquisition of his startup, Blaze.io. Before founding Blaze, Guy built Web Application Security products, including the first Web App Firewall (AppShield), Dynamic Application Security Testing tool (AppScan) and Static Application Security Testing tool (AppScan Dev Edition). Fun fact on Guy, he is the holder of 18 patents related to security and performance.
In Today's Episode We Discuss:
How Guy made his way into the world of SaaS and came to found one of the hottest open source companies of our day in the form of Snyk?
How does Guy navigate between the difficult balance of going wide on market and shallow on product or narrow in market and deep in product? What is the decision-making process? What does Guy advise founders on feature prioritisation in the early days? Does Guy agree if you are not embarrassed by V1, you have shipped too late? How does support provide a feedback loop on what to build next?
Why does Guy believe that, "successful freemium requires giving away your secret sauce"? How can one give away enough secret sauce in freemium without giving away too much people don't buy? How does freemium fundamentally alter your relationship to revenue? Where does Guy see many going wrong when pursuing the freemium model?
How does Guy think about the problem of agency with developers using the product but having to sell to CIOs? What 2 things can be done to make this sell easier? What does Guy believe is the right framework to think about pricing through? Why is transparency in enterprise pricing not always optimal?
What does Guy believe is required to have strong and seamless communication across functions and locations? How has Guy seen this change over time and with increased locations? Where does Guy see many going wrong when trying to scale team across location?
Guy's 60 Second SaaStr:
How does Guy know when is the right time to hire your first sales person?
How did Guy learn to let go and trust his team?
What does Guy know now that he wishes he had known at the beginning?
Read the full transcript on our blog.
If you would like to find out more about the show and the guests presented, you can follow us on Twitter here:
Jason Lemkin
Harry Stebbings
SaaStr
Guy Podjarny