Pynt vs OWASP with Tzvika Shneider
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I've got a, well, it's a new company for our audience to introduce you to. Their name is Pint, and I'm really happy to be talking with their CEO and Co-founder Spika Schneider. Spika, welcome to Tech Drunk tv.
How are you? I'm good. I'm doing well.
And, uh, thank you for having me today. I'm really excited, you know, to talk to you and tell you all about our journey in Pint and and, and what's the future for us. Absolutely.
You know what, spika, before we get to pint, let's talk about speaker a little bit. Tell us your story. Yeah, so maybe I'll shortly introduce myself.
So my name is Ika Schneider, uh, um, 37. I have two kids and I'm being involved with cyber security and engineering. Since I remember myself, I'm really, really in the young age, um, been doing more professional, I would say, engineering cybersecurity since I was 18.
I have, I had a really long service in the intelligence force in the IDF in Israel. I have few. I was involved in a few, uh, very interesting startups.
And in my last role before starting Pint, I was heading the cybersecurity division at Harman. Uh, and where there we were responsible for both, I was responsible for both product security, uh, making sure that Harmon products are being released and secured way, as well as the security product. So building products for Harman, um, in, in the security, in the automotive security space.
So with that, with few Good, you know, good friends, um, from that journey, we decided to start pint, um, with a mission actually, you know, to solve the gap between the security products and product security, and making sure we're solving all the problems, you know, in cybersecurity where we actual starts, um, in the coding level, in the development phase. So I would say, uh, um, this is kinda, you know, uh, summarize about myself and, and the way we got to Pinett when we started Pinett. By the way, we're not that new, but it's not very old, right?
We are two years old. Mm-Hmm. Yeah.
Two years ago. So, speak. I, I've, I've interviewed many, many entrepreneurs, startups, CEOs, co-founders, founders.
Everyone thinks that, at least in some small way, some people think in a big way, but at least in some small way, what they're doing is gonna have a very positive impact on the world, on in some way. Maybe it's the developers, maybe it's the cyber world, you know, or something else with you and your fellow co-founders. Well, you mentioned kind of what was driving it a little bit, but in what way did you think it was, it's important, right?
It's something that's important. Yeah. So, you know, like, um, something are important to the world, I would say, um, like, um, climate and saving ti trees, but, uh, you know, again, our economic and our world running, running our environment.
But I think the modern world run on software and for us, um, really making sure that software is secured for day one as you develop, that was our task. But we wanted to do it differently. We wanted to do it big.
Like, you know, everybody talks about, um, let's have some cybersecurity products and shift them left into development processes. You'll see. But we did something different.
What we did is, um, we developed the most and then cybersecurity solution in the world of API security, by the way, we skipped it a bit. Um, but Pint is focused on API security when a API security company, um, in, in our vision, in our vision, uh, we wanted to have a very advanced cybersecurity solution, uh, on the one hand, on the other hand, making it accessible when it actually start, when to the people that actually don't have intent to cybersecurity, but they really what matters? 'cause, because the issue and the fix, um, starts and ends with them, which is more the, you know, the developers, the DevOps, um, the qa.
So we had the teeth. So we actually really developed that, you know, product and did kind of a PLG community motion. Um, and I can say that to date, we have more than, you know, thousands of users that almost near to 100 countries.
It means that what we solving is indeed a global problem, right? We, we know, we have all the understanding of what, of the issues, uh, with different companies all over the world. So if you're talking about, you know, um, making an impact and saving the world, let's say we're really focused on a global problem.
And the problem is that, uh, um, you know, after having that layer of, of the physical things, you know, like as you mentioned, you know, saving the earth and, and trees, you know, above that, uh, um, we have the world running that, the other layer running on software, right? So our mission was, um, to really solve that from day one. And because of our experience by the way that we had to gather as a team at Harmon, um, really being, being that we talked about that, you know, solving the gap between developers and security teams.
So we were in the middle, we were that gap. So from that, we really, you know, started the journey of let's put a product, um, that solving a very advanced security issue, which is API security. And everybody talks about API security because APIs are everywhere.
And, and, you know, we don't, we, we are not in that pitch. Like, luckily enough, I don't need to convince anyone regarding the problem space and APIs. Everybody knows, you know, everybody knows the world run on software and software are being exposed by APIs today, and it's only growing.
So we combined, you know, um, um, that mission as well with our technology expertise and our technology expertise is based on attacks for validation. Okay? So what we're doing, we're doing proactive security.
We are attacking the APIs and in the development process already making sure, and, and then, you know, handing the developer the actual fixes, and then making sure you deliver secure applications to production, but not on some theoretical scans or, or theoretical checks, whether if, you know, if the, the stars will be in a certain order, this and that can happen. We're actually doing the attacks and finding if your app is exploitable. Um, um, and I think that's really what allowed us to gain a lot of traction and get to gain a lot of project product maturity, um, and to really, you know, um, um, improve that game.
So, um, if I need, like, you know, to, if I can, you know, summarize your question. So I think that we wanted to do like a shift left security, but take an another challenge. The challenge is doing, you know, attack based and also, uh, make it accessible to developers, qa, DevOps, where you know, it actually where it actually matters.
Because in the end, you know, the whole chase between security and developers, and this is not, and this is the new challenge for a lot of cybersecurity companies. Uh, everybody absolutely solve the gap between developers and security owners, and we'll talk about it. com for, for years, right?
For a couple years there's been some, there's been some companies who, you know, kind of pioneered the space. Mm-Hmm. No name security, salt Security, traceable ai.
And, and I will tell you, when they first came on here and we spoke API security was not a well known. Like people got that everything was talking via APIs. But recently we've seen data, I, I think it was CloudFlare came out with a, uh, a survey, you know, something like 50%, maybe more than 50% of all the internet data today is really APIs.
82%. Yeah. 82% according to Akamai Is, uh, Akamai, right?
Well, CL was the less was API related, right? Uh, communication, API to API. And so this really became an issue.
And, and then of course, the OAS came out with their top 10 API vulnerabilities, right? Like, they didn't have enough, they didn't change the old vulnerabilities enough, but that's another story. So that really kind of brought it, I think that did a lot to bring it to people's attention, saying, Hey, wait a second.
This is a potential really big problem here, right? This is a really big surface, so to speak, attack surface that we need to, to control. So, you know, all of a sudden now everybody gets serious about it.
And, and where these APIs are being configured and, and built in is, is, you're right. It's part of that software pipeline, right? It's part of that development cycle.
Yeah. So how Is, what Pint is doing different though? How is, what Pint is doing better?
So, so let me address it. You know, um, one by one, first we talked about, uh, you know, the rise of, um, not just APIs API security, but I think it's kind of, you know, tied to each other. Like, because everybody talks about AI for a while, right?
Again, not a year now two, not a five, not six year about ai, but they just booming happening right now with those enabler of, um, lms, et cetera. So if you're looking on APIs, so they were always there, at least, you know, at the beginning. But somethings happen, um, whether, if it's on the business side, regulations and tech stack that made API be, you know, most of the internet.
And it starts with even the technical part. Everybody moved from monolith coding and software to microservices. And microservices are a API based talk to each other by API based, whether it's internal or external.
Um, the second thing, there, there are a lot of high regulation right now, like, you know, with FinTech, with open, with open banking, PSD two, uh, with Fire for Healthcare, that really, um, regulates API and the way you need to expose APIs. So that also, you know, brought API, uh, to be much, much more popular. And I think, uh, the, the most, uh, important thing here as well, that, um, that the cloud adoption got increased highly even, you know, even if you compare before covid after Covid, so now everybody's in the cloud, everybody wanna write software.
Um, you know, you have a lot of developers in the world, like, uh, you have a lot of code, you have a lot of tools that are doing like no code or low code, No code, no code yet. Then create APIs and, and, and it's like, you know, just imagine your app, your organization as a house, and the API are the doors, right? So now we have the ability to add a lot of doors, to add a lot of windows all the time for us.
Like, uh, we don't, I don't need, uh, in the software world, you know, like, I don't want to go from the, um, main door to the bedroom if I can go straight to get a new door to the bathroom. So I think all, all of that all together, uh, um, really the result is that our API are everywhere. So now you a second part for the second part of your question.
Um, and there are companies, some good companies that are doing security, uh, the company you mentioned there are good companies. I think that what we different the, for that specific companies that, um, we're doing something completely different. They are focused on runtime production after the fact, uh, mostly for discovery, what asset they have in runtime production.
And if something tried to do something, if someone tried to do something to my API in production, in runtime, uh, and then if something happens or we need a medicine, we need to, you know, fix it, uh, we are more going on the side of the vaccine. I would say, um, we already in the development process, make sure you deliver secured APIs so already, uh, and, and, and the also the approach is, is, uh, is a bit different, you know, passive in runtime production versus our approach, which is, you know, active, we're trying to attack mm-Hmm. Trying to find real threats.
And I don't say it's, it's, it's, you know, um, it's better. I think it's in a way compliment, co complimentary. Complimentary, yeah.
Uh, um, there are good companies, uh, good founders. I know them. Um, I think that the, the approach is, is different.
The approach is very different. And I strongly believe, you know, um, our approach is the approach that a organization need to start with. Uh, you know, before you, you're working on medicine, just make sure you don't have that problem.
Um, and, and one of the challenges to do it, this is why you have a lot of, a lot of, you know, um, cloud providers and vendors in production insecurity, because people kind of gave up on, on how we're gonna fix the problem as we develop. 'cause no one, no one wants to, you know, delay the development process, okay? The most important thing in any organization, that's, that's, that's get it straight.
It's not security. It's not security. Security should be an enabler.
It's not the security. You don't get money for your security. You get money for your business.
And, uh, but security is important, right? It's very important. It's tied to it.
Um, and, and it look like, like a mission impossible. Like how do I fix the problem of the developers that they don't give, you know, they don't care about security. They don't have a strong intent, but still thi this is the only you know, way to do it.
And, and the current situation, what happened, I would say in general, in application security, uh, if we'll continue that analogy of, you know, medicine and vitamins, et cetera. So it just took about, you know, um, um, parent and kids. So you have a vitamin, yeah, right?
You wanna sell to your kids that in the end, uh, you want to, you wanna make kids, children use the vitamins. So they might, you make it like a teddy bear, it's sweet, uh, um, um, they hear about it from the friends in the kindergarten in school, et cetera. But in the end, the buyer, you know, the, the, the actual ownership is the security owner, right?
The parents, they care about it. Like it's their motivations, it's their intent. The kid doesn't have any intent to take the vitamin.
Um, so this is kind of, you know, the, the, the, the PLG motion. But what happens to the insecurity is that the parents go to the pharmacy by the vitamin drinking itself, and then it doesn't solve the problem. So to solve that problem, you need to, to, to make sure you integrate it in the first place, you know, where the development happen.
And the challenges is to make sure that you automate whatever you can. And each one of the persona should handle what they should. For example, developer doesn't wanna be security expert, right?
They want it, they don't wanna handle it at all. You should create, you should create, um, a, a feeling like an issue that you explain why it's a bug and why it's a, it's like a logical bug and it should be fixed, you know, already. Uh, It's, you explain it as quality, right?
In DevSecOps, that's what developers are interested in. I've never met a developer who says, I don't want quality code. I don't develop quality, I develop track.
You know, but they all want quality. And, and that's what it is. Yeah.
It's, it's, you pass by, you know, the, the once there was a very, a very, you understand what is the difference between bugs, quality and security issues? Mm-Hmm. Um, 'cause security issues back then, oh, I left the port open, or, you know, something around that.
But today, on everything, the software, there's a blur line between quality and security. They're really tight. And, and, and It's synonymous Is like a business logic issue.
Mm-Hmm. A business logic. It's quality of security, you know?
So there's a blur, blur line around it. And I think that today, uh, um, this is why you see also the rising of API security issues and API security vendors. And for your third part of your question regarding oasp, so, um, OASP, um, is, is we're very lucky to have Oass, right?
And it's a nonprofit organization. I'm setting up standard for the old ecosystem. It's like the Bible of the old ecosystem in, in some way.
Um, and, and they are working, um, really hard. And they defined, yes, API top 10. Uh, and, and they did a very good job.
Um, we did recently, we conducted like a, you know, our own, our own research of saying, okay, what we learned from, you know, thousands of users, more than around 100 countries. Um, and if our conclusion is very similar to the, oh, top 10, this is what made up, you know, working on our own research, like, uh, we call it like pine versus source, but it's not really, versus like, we in favor of us, we just wanna challenge, uh, us, you know, result and the way they handle API security today. So we find, you know, a few, few major, I would say, um, um, differences, uh, between what we founded at what OSC is doing, but I think it's a good thing that Oasp is coming and, you know, defining the standard and, and making sure, like making sure everyone are aware of that problem.
Well, as I said earlier, I, I think them coming out with, it gave credence to this being a real thing to this being a real market, to this being a real issue, right? It, it, it, it made it real for, in a lot of people's eyes. But I'm, I'm interested in where do you guys see the difference based upon what you see versus awas?
Because, you know, there, there's room for difference there. What, where do you see the differences? Well, um, you know, in the end, um, we have few main differences, uh, in, in our result.
I would say, uh, I I would say the first one and the most, probably, probably, um, I wouldn't say major one. All, all of them are kind of, uh, um, majors. The first one is they removed, for example, the whole, you know, injection category from API, uh, although from our research, um, injection is the second most popular vulnerability we found.
When I say injection, by the way, just to define it, is code injection, remote injection, SQL injection. Sure. No injection.
It's a way, uh, it's a way someone that should not do any harm to your API in database are able to inject you code or information. And from that, you know, um, um, do the next step of the hack, et cetera. So, and this is, you know, the, the, the, it's like the nineties problem, you know what I'm saying?
It's like, it's like old problem. You, you, you should, It, it's legacy. It's legacy.
You, you should have thought, like if I'll talk to you, you say like, oh, that doesn't exist anymore in the wild, but this is the most second popular in us, decided to remove it because they say, no, it's already in the generic oasp top 10, right? With not api. Well, they were try, so to be fair to oass, they were trying to make this separate than the regular oasp.
I know you're right. But since it's the second most, you know, um, popular and in the end, if pharmacies, so, and everybody looks and ask like the Bible, because there's no, like a second to ask. There's not a second to ask.
Um, so, and if I'll, you know, create an API secure problem, I might think that I don't need to take care of injection. So, you know, and, and, and we understood here, it's very popular and this is the most, one of the easiest thing to fix. If you give it attention, attention, you're in the first place.
Um, so that's a first. That's first thing. Um, second, I think the problem with us today that it's too generic and it's not actionable.
It's like too generic. Um, everything is like, there is like the broken umbrella, broken notification, broken authorization, and in each one you can get dozens Variations. But really, instead of being all these different things, it's just, they're all something's broken.
And that, you know, yeah. That's one of 10, not five of 10 or three of 10 or whatever. Mm-Hmm.
I agree. So, So here we actually, you know, split it and, and we say, okay, um, you wanna build an a p to get a problem? This is what the word suffer from.
Uh, and, and, you know, and, and, and the way we conducted that research, it's actually from, uh, you know, all the development phase part, it's not on production runtime, to be honest. 95% of the attacks, cyber attacks in the world, as, you know, go under the radar. Nobody knows about it.
Nobody knows about it. Um, but since we're doing proactive testing, so what we see is what we get, you know, like what we find is real. Um, so this way, this way we could get to that conclusion, you know, that, um, one injections very important.
Second, you know, the, the, the broken umbrella. Uh, um, and, and third, yeah, we have, you know, few other findings that are here and there yet, but maybe, you know, that's not the place to go that deep technical. But I would say, uh, uh, if I can summarize it, I think again, oh, is doing a great job, um, of, of really making, creating a standard.
I think they have some, um, gaps in the API security research. We're happy to work with 'em on that. Um, we're in touch with them.
Uh, and, uh, in the end, our case, we wanted to, you know, um, make another awareness. So API security, you know, top 10 of OP is, is, is great for, you know, education if you wanna build like a high level security program. But we honestly, like, what's the reality?
So we did like, you know, find top 10 because it's really based on, on traffic data. By the way, oas, the way they did their research is not collecting data. Like they ask vendors to send data, and they have like, you know, round tables That that's always been a, a week of like a soft underbelly of it, right?
It it's dependent on what they, the inputs of the data where they're coming in from. Yeah. But I wanna emphasize, and I know the new OAS chairman who is, by the way from Israel as well, they do a really good job.
No, look, I, I'm familiar with OAS from when they launched it when they first was founded. I, I, you know, they've done great work. They've, and, and in many ways, the whole web application spaces, you know, where would we be without them?
And Volunteering. And volunteering also, which is very important. Yeah.
All right. That's nothing for people who didn't really make money on it. Mm-Hmm.
Speak. We are running low on time. If you don't mind, I wanna pivot a little bit.
People who say, yes, I'm API, security's important to us, I don't love what we're doing right now. Now how could, how would they interact? How do they kind of find out more about pint?
How do they maybe get a demo or a test? Mm-Hmm. Or something, you know, that they can get their hands on here?
I think that, you know, most of our users today, um, came I would say organic bottom up. Uh, because how we started, we did like integration to already testing and development popular tools, for example, you know, postman rest assured vs code, et cetera. Mm-Hmm.
io. PYNT. It's like a pint, like the beer, but with a y.
Yes. I gotcha. Uh, um, yeah, you know, we, we, we looked for four letters.
Uh, name No, I'm kidding. It's Not easy. It's not easy finding four letter domains.
No, it's a good Name. Good name. Yeah.
Is there, is there a, uh, is there like a free version? People could use a free Trial? What, How we started to see how we go, you know, the, the, the first thousands of users, um, we have like a, now it's for like a free tier.
We have a free tier. You can use it like, uh, you know, forever. It's limited.
It's limited, uh, by the number of API endpoints, at least to the point that this session is recorded. Uh, uh, it's limited by number of a points, um, endpoints. Um, um, we have a free tier, our website or LinkedIn.
We have Community Slack channel with hundreds of people, you know, supporting each other. So what we, you, what we really did, you know, it's kind of like the, the, um, PLG bottom up, um, to gain more traction and product maturity Sure. Et cetera.
Um, but no, It's a pop, it's a popular model. Has been now for a while. Of course, Our most champions and, you know, and, and our champions are application security.
Our security owners, we interact with them, we talk to them. Um, so from a website, um, to LinkedIn to marketplaces, um, you can, you know, hear about Pint and, and I will leave all the details of the decision for us to share. Absolutely.
Well, we'll have them in the notes here as well. Sweet. I want to thank you for coming on Text Trunk tv.
First time, hopefully not the last, come back and visit us. Um, will you guys be at RSA or Black Hat or anything like That? Yeah, I think we'll be in RSA, um, um, you know, looking forward for, to cropper to as well.
Uh, we'll be in RSA, um, cool. For sure. All right.
We'll be there. Maybe we'll see you live there. We can follow up this conversation 100%.
All right. Thank you, Helen, for My pleasure. Speaker Schneider, CEO co-Founder of Pint.
io. Go check it out. Uh, if API security AppSec is important for developers, security people, you know, this is a big thing we, we talk a lot about here.
Check 'em out on Pint. We're gonna take a break on Techstrong. We'll be back in a minute.
Thank You.