5 Comments

Neatly put.

This post is a remarkable callout for enterprise security pundits and product marketers to jump in with their "casually smart" perspectives about the new paradigm shifting approach that works and accidentally coincides with what they are selling.

Should their absence be considered a hallmark for Substack readership/culture?

Expand full comment

Yeah, agreed here. How do we prevent unknown unknowns from materializing in the cloud like xenon poisoning in an RBMK reactor? Maybe Google or AWS should automatically report suspicious instances of currently used and also newly used service instances through some smart detection system?

Expand full comment

I think you make good points. These two areas of security are interrelated and dependent on one another. The software we make must be high quality to prevent it from leading to breaches of our customers and enterprise security must be high to prevent compromise of the environments used to build that software. In short, we need both and not just one or the other.

Expand full comment
author

...which is why I don't get invited to government panels on computer security

Expand full comment