DryRun Security Launch | James Wickett, CEO
DryRun Security, founded by technology veterans James Wickett and Ken Johnson, emerged from stealth to fix the disconnect between security and developers. James and Ken are creating a new security analysis tool to find potential bugs sooner than other security solutions on the market while better aligning with how developers work. Find out more at https://dryrun.security.
Transcript
This is techstrong tv. Hi everybody. I have a great pleasure being joined by James Wickett.
James, I won't say the name yet as co-founder and c e o of a company we're gonna talk about in just a minute. I'm gonna let him do the, the whole announcement, and that's what this, uh, interview, uh, discussions about a new company that he and, and a co-founder, uh, Ken Johnson are launching. So, James, welcome.
Tell people a little bit about yourself, kind of where you've come from, your background, and then tell us about fill in the blank new company you're launching. Okay. Yeah.
Well, hey, thanks. Thanks, Mitch for, uh, for having me on the show. Um, yeah, my, my name's James Wickett and I've been in the security industry in the dev DevOps SecOps kind of space for, for many years.
Uh, I, I've worked at some large enterprises in the past, but I've also worked at like startups like Signal Sciences and ver, uh, and just, uh, just launching our, our new, uh, company with, uh, Ken Johnson, my co-founder. It's called Dry Run Security. Uh, the idea is that you dry run all your security tests when we put the security testing as close as we can to the developer where their writing code and give them that security context, uh, instead of keeping it, uh, in the security department or, uh, you know, putting it in a spot that like is, is further down the pipeline, but put 'em right, right where they're writing code, um, and, and giving them that security context.
Uh, Mitch, one of the things that, that I've come to believe in my career, which is, is maybe a little crazy, is that I believe developers care about security full stuff. I mean, they, they don't wake up thinking, I'm gonna write some bad code today. No, they don't.
They don't do that, do they? Despite what the security people might think? Yeah.
Uh, yeah. An unnamed person at a, at, at RSA last year or last, uh, couple weeks ago, uh, was, was even saying jokingly oil developers, you know, they're right. They don't, they don't really care about security, you know, and I'm like, how, how is it that we're this far along and we still have that kind of, uh, breakdown of communication between developers and security?
Um, but no, I think security, uh, it, it probably comes from my, my other core belief and, and, uh, I'm sure you probably have it too, it's like security is a function of quality. Mm-hmm. And, and, uh, you know, no developer wants to write, you know, bad quality code.
They don't, they, they, they care about that. Um, all developers, uh, that I've ever met in my group, and re really smart, really with it, trying to like, um, build something that people cared about that was really safe for people to use. Uh, and so security just fits right in that.
Um, often we just give them, uh, you know, security as, as a, as a group. Like we kind of give them developers like weird paths on how to make their codes secure. And so we, um, we'll try to do, uh, training or we do compliance or there's some other, you know, functions that we try to overlay on top of the development practice.
Um, but we don't really meet developers where they are. And that's kind of been a breakdown in our industry. I think that's a, I think that's a fantastic way to look at it.
So, I haven't looked at the product, we haven't talked before, so I don't know much about it. My questions would be, I imagine you're probably right in the ide ide with the developer as they work, or is it in something conjunction? Kind of give us an idea of the flow.
Yeah, yeah. Drive run works. Yeah.
The main, the main way people inter interact with dry run security is through GitHub, like as a GitHub action GitHub app. Okay. Um, and we are, we are in kind of this kind of closed beta phase, so we're still working on it with customers as they, uh, use it.
And we, for, for certain languages and frameworks, we can do like deeper, deeper dive inspection of their, uh, their application. So, uh, some of the, like the node express, the JavaScript ecosystem, we have some further, um, dive down because a lot of the traditional security tools, um, suffer from like being able to do analysis with those type of languages. Either they miss a lot of stuff or there's a lot of false positives.
Uh, so that's where, uh, me and my co-founder Ken, uh, Johnson, really wanted to focus on, uh, kind of starting out at the gate. There Was a, it was a bit of a, I, I know that you're co-founder and came from Get Up, so it was a bit of a setup up question because just writing at the code that you're the point, you're creating your writing code, you're still missing a lot of context, a lot of software, a lot of calls to other things that aren't, aren't necessarily resonant on your computer and your id, whatever. It's really at that, uh, I guess check-in point or, you know, at the repository where now you have open source MyCode system calls, whatever it might be that you're, you know, you're accessing and that's where things can get introduced as well.
Yeah, that's right. Yeah. Yeah, Ken, um, Ken spent the last, uh, I guess five years over at, at, uh, GitHub running security over there.
Uh, he also teaches a lot of developers doing, doing security code review for them. And, you know, they face the problem at GitHub that, that, uh, that we see in the industry, uh, you know, at large, where you'll have, you know, a handful of applications, security experts in an organization, and you'll have, you know, thousands of developers. And so when, when you kind of face that, that numerical divide, it's like, okay, how do you know what to review?
You know, how, how do you, how do you scale that for an organization? And so whenever like a thousand poll requests are, you know, coming across your virtual desk every day, which ones do you do you pluck out and say, oh, what do we, what do we care about? And so, um, being able to give the, the context both to the application security teams or the, the people there, and then also developers, the things that they're working on, uh, might need to, you know, trigger further review or to, to be able to kind of surface, uh, those type of problems like that.
That's, those are some of the things we're looking at. So you can think of, um, you know, certain functions, uh, being used, uh, parts of the, uh, uh, part parts of the code path that may be sensitive that are being, you know, changed, uh, different types of routes that are being applied, or, uh, maybe you thought you were just adding in like a, a library, but then now you've inherited 35 new routes, you know, new attack surface just sort of popped online and you didn't really know that until, um, you know, instantiation of that, where it all got dynamically loaded. So, um, yeah.
So those are some of the, the, the things that we're looking at to kind of help give that, what we call this approach, contextual security analysis, we're able to do, uh, give that security context both to developers. And then, you know, there's other ways to trigger inside of the, the teams like, oh, look, this is something that we should, should care more about, like, put it to, you know, in their, uh, their chat tools and other places where they're, they're working. You know, I, I, I like, I like that term also because contextual apply, it also applies to not just your code, but the, all the things happening around Yeah.
The development team, right? Could be distributed, could be across the globe, could be you're all sitting in, you know, your own startup company or whatever it might be, but it isn't one person checking in the code that this, now let's check it and verify it. It's, lots of things are changing right up until bits and pieces get releases, major releases go out.
I'm curious, you're contextualizing, so are there in parts of the environment that you're also considering too? Yes, I'm running on Kubernetes, or I'm doing a serverless, I am the kind of thing now I know you're just starting, so you can't, you know, yeah. Check the box on everything, but kind of give us an idea of, of what kinds of things you're considering to look at those paths, the attack surface.
Yeah. I mean, we're, we're really starting, I mean, we, uh, both Ken and I come out of the application security bill, watch communities, uh, um, I spent, um, many years over at Signal Sciences, which is kind of reinventing and helping people reimagine how they use like a web application firewall. And so, um, I think a lot of our heart really sticks towards like the developer writing, writing, um, code inside of their, inside of their repo.
And then like, as it's brought up, like how does it look to the world, you know, at large. Um, yeah. So, so we haven't looked like infrastructure wide type stuff or cloud provider provider wide, um, that, that could be, that could be in scope in the future, but really we wanna provide a tool that's good for a developer in an organization working on an application.
And, um, but giving them the context of like, um, you know, the way authentication is done in, in an organization or like, uh, or like the stuff we mentioned earlier about routes or, or code paths or, um, you can even think about like code brittleness, like has it, has it been touched recently and how long ago? And by who? And kind of thinking through like, what, what, what is, you know, as a developer, like, I gotta, I got a ticket and it's like, I gotta, I gotta solve that ticket and maybe I have to, you know, go across several different APIs or work across different, you know, with different, uh, um, parts of our code base or depending on how you've broken up your, your, uh, uh, your setup there.
But being able to know like, oh, like if some of this code I'm changing is, is substantially different than the way we've, we've done it before, so mm-hmm. Uh, it's that kind of stuff that we wanna be able to surface to people. Um, You know what, what, what's interesting about that is, and why I asked it is, is I, as I continue to work with security people, oftentimes security folks will think about it from an in infrastructure perspective, right?
Because that's, on the one hand, whether it's a server or it's a network or application firewall, whatever. Yeah. Those are all things that are part of infrastructure.
Just like you might look at Kubernetes and kind of sort of the software stack, but the, the more recent trend with platform engineering developer productivity is we, I don't know if we forgot about the developer, but we forgot that we need to design things for them, you know, by developers, for developers to be used by developers. And, and that very much aligns with your approach. Yeah.
Yeah. I think that that really kind of fits what we're trying, trying to do here is put a, put a tool in their hands that's not, um, a, uh, that's gonna be delayed in the process, that doesn't like, you know, do do some sort of security assessment. Uh, we also got a lot of feedback from w from, uh, even, even like more security minded developers too.
It's like, keep checking for cross-site scripting. It's been three years, haven't ever seen it, but we have off problems all over the place, right? Because the, the move to microservices and the, the, you know, you know, componentizing, all of our AppSec like, there, there's just some real new kind of development paradigm problems that, um, that we have to, we have to look for.
And so as we're, uh, you know, doing like, uh, API security, uh, as far as like on the developer side, not, not in flight, but mm-hmm. Um, I, I think there's just a, there's a ton of stuff that can really add, uh, context to their, to their work. I know I keep using that word context, but that is, we, we feel like that's, that helps give like the better decision points to developers as they're actually, uh, creating and building.
Well, and just talking about trends in software, software architecture, API first, you know, yes folks, some folks have been doing it for a while, but I don't think on a wider scale that's much more of a being adopted type approach of, you know, consuming your own APIs as part of your application. And that brings a whole host of, you know, while you're developing as well as runtime, uh, things to take care of and consider as well. Tell me a little bit about the experience.
What's, what's the developer experience look like? Yeah, so the developer experience, like right now, as I mentioned, we're in kind of at a closed beta. security.
We're collecting people that are interested in the product, um, and then then kind of working with some of them to kind of get it started. Um, but as a developer uses it, like it's sitting inside their pipeline, it runs in inside of like, like a GitHub action, and it's able to both do detection on, uh, that code commit, but that code commit in context of the full application. So we think of it as like, instead of outside in testing, we kind of frame it as inside in like, we're, we're as a module drop in module inside the application for, for some language frameworks.
Um, and then you get that as a, uh, you get that feedback, right? And as a comment inside of your, your poll request, or you could maybe get it over into like a Slack, uh, message, right? So you're able to, uh, see that as you're, as, as you're developing, as you're building.
Um, yeah. Excellent. Um, are there specific languages in you're supporting right out of the gate or environments?
What, what sort of that list that subs that set of Yeah, you're In this list. That's what we're doing. Yeah.
Right. Right now we have some really cool stuff that we can do for Note Express. Uh, we're also working on some stuff for next js uh, and then we do have some stuff that's more generic that would work for, you know, no matter what language or what framework.
Cuz we know not everybody's gonna be running, you know, note Express, right? Or, or just any language framework combo. And most organizations are running, you know, a dozen or, or so, you know, plus of those.
Um, so we do have some generic stuff that we're working on as well, and we're, as we kind of get closer to like, announcing the product, uh, and pushing that out, like, we're gonna be really excited to, to let people in on that. Very cool. So you're, if you're doing a close beta, um, what, what kind of users, people, company, what, what makes a good for you for driver insecurity?
What, what's a good close beta user that you're looking for if folks are interested? Oh, yeah, yeah. If you're interested, uh, if you have Note Express, I think we can do, like I said, we could do some really cool, cool stuff there that, uh, nobody else can do right now on, on, uh, uh, the way we handle routes and we do some static, uh, assessment there.
That's, that's helpful. Um, and we're looking for, we find people that are really interested in us are, uh, either, um, people that are trying to move their AppSec, you know, uh, testing or, uh, analysis or however they're trying to put stuff closer to developers, so they're already moving that direction, uh, and we can kind of help, help with that. Um, we're, we're also, we are, for me, I'm also interested in people using njs.
I keep hearing a lot about the people using that. Uh, we've got a couple, um, you know, kind of early, early companies talking to us about it, but I'm, I'm collecting more like, all right, how, how big of a problem is this for people? Like, what are you seeing?
Um, and, and we really started out that Ken and I were discussing like, okay, where do we go? Right? Because we've done a lot of stuff with Go and Python, and we're like, well, this kind of, this ecosystem feels like there's a lot of new, new stuff that's happening.
And, and we, we love that. Um, but there's not enough security, um, testing, you know, foothold in that, that part of the organization. So mm-hmm.
That's kinda where we're, we're, uh, heading first. Okay. Very good.
Yeah. Well, um, so, so last thing and have, you know, as a, uh, founder, co-founder of some companies myself, I have a little bit of an idea what you're, what the experience is. Um, so why start a company right now, people who haven't done a company might say, oh, economic times are kind of weird and flaky.
Is this a good time to start a company? Actually think it's a great time, but what's your perspective on that? Yeah, yeah.
I was, uh, was excited to, uh, to start this with, uh, with Ken and, you know, we were walking around, uh, r s a, uh, a few weeks back and, and it's a, it's a feeling of like, security is still, it hasn't made the jump, like, kind of like you mentioned to developers, and I've been feeling that, uh, for a while. And it feels like th this is a time when people are looking for, uh, ways to help their developers. I know that like the, uh, you know, the market's tough, uh, what people are making, you know, different decisions on how they're spending their money as, as, uh, companies have a outcropping of AI and all this stuff that's going on.
Uh, but some of the, the basics here of like just getting security, uh, you know, you know, working with developers, uh, where, where they're working. I feel like that's just so critical. So, um, yeah, Ken and I have really thought like, let's just, let's go after this and let's make this happen.
Sometimes that economic disruption means disruption of, well, we can't do what we're doing now, or more of that. Let's look for another option, give you a great, good opportunity for entrepreneurs. So yeah, time.
Perfect. You, you know, and I've always think of this like, and the ratio I've seen holds fairly true. It's like for every a hundred developers, you have like one security person in an organization.
And so we can't, we can't hire our way out of this problem. There's just not enough, you know, headcount to go around as far as like application security professions and more and more stuff is moving to the application. Um, uh, as we're kind of seeing like the, the Rises platforms and a lot of the stuff we've mentioned, just even how people are consuming, you know, uh, serverless or, or Kubernetes, um, like, like the, the, the landscape is just moving straight into the application.
So I think AppSec, you know, o osp and, and AppSec really became a thing 20 years ago, but I think like the next 10, 15, 20 years is gonna be really even more important than AppSec than the first 20 ever were. Oh, absolutely. Just the change in architecture, proliferation of APIs, all of it.
Right? Yep. Opportunity.
Well, good. I wish you the very best. Um, I hope you or you and Ken will come on, uh, sometime after the announcement, maybe when you're ready to do a little bit of, bit of a demo.
Yeah. Show folks what you're doing and we can kind of dive into it some more. So congratulations on the announcement, the launch, and, uh, I wish you the best of success with your closed beta customers and when you come out of data.
Okay. All right, well, thanks Mitch. All right.
So website again. James, where do folks go? security.
All right. James Wickett and of course his partner Jen Ken Johnson. The, the missing, but I'm sure hardworking in the background.
Uh, good, good wish. Good luck. I'll bring him Next time.
Okay. Bring him along. Take him outta steal.
Thanks much. Okay. Thanks.