Seamless Development Security with DryRun Security’s James Wickett
James Wickett, the CEO and co-founder of DryRun Security, discusses the company’s recent emergence from stealth and introduces its innovative approach to making security a seamless and efficient part of the development process.
Transcript
This is Techstrong tv. Hey everyone, welcome back here to Techstrong tv. You know, it's always a good day when one of your friends starts a company that comes outta stuff.
You're happy for 'em, you're happy for them. And I, I couldn't be happier to have my friend James Wicked on with us today. Who, uh, his, his baby, his his brainchild, his his, I guess it's the first company you've co-founded like this.
That's right. That's James. That's right.
Yep. Yep. Just came out of stealth, uh, last week, late last week.
It's called Dry Run Security. James is gonna tell us all about it as well as himself. Ladies and gentlemen, James Wickett.
Hey, James. How are you man? Hey, how you doing, Alan?
Good to see you. Thanks for having me on the show. It's good to have you on.
James. Look, I, I, you know, for people who are into kinda what's become DevSecOps and, and the DevOps scene, and maybe you're familiar with the Austin DevOps days, they all know who James Wickett are, is there's only one. Uh, but there's a lot of, let's hope, let's hope, yeah.
That we know of. But there's a lot of people out here who don't know who James Wicked is, so we can't even start talking about dry run security. I think until we kind of nail that down, share your story a little bit, James.
Yeah. You know, I've, I've been in the, uh, the technology space, living in the host of Texas area for about 20 years now. And, uh, always kind of been in this like spot between like operations and security.
Uh, my, I, uh, you were talking about IBM uh, before the call, but I, I worked, I interned at IBM, got my first job over at National Instruments here in Austin, and really was kind of on the, the web systems team. We we're doing kind of SRE type of duties at that point, trying to figure out how to, how to, how to do this. And, um, after some time we, we kind of helped start the DevOps, uh, days conference here in Austin.
I helped with some, some application security stuff with Oasp and, and Lascon in those days. And really, like, Austin was kind of this like, it's kind of weird to think of now, but Austin was kind of a flyover country, uh, right. It wasn't, it wasn't really as blossoming with, uh, tech as it is today.
And so really, um, was able to just build out most of, uh, most of my career here in Austin. Uh, but then I, I went to work at Signal Sciences as the first engineer, uh, when they started in 2014 and helped build that, that company and really be a part of that. So, uh, that was a lot of fun.
So I've always kind of been in this, like, this Venn diagram of like development and operations and security. Like, I've always kind of lived in between those worlds kind of having, uh, functions and jobs, uh, around that. And so, uh, yeah, so that's, that's, uh, where I'm, so I don't know any other, any other data.
Like I got two kids. They're, they're great, you know, and, uh, mm-Hmm. My wife and I we're celebrating 20 years this year, so, I dunno.
Fantastic man. Congratulations. Yes.
And you're right, Austin was weird and it is weird, and it takes pride in being Austin's weird, right? They, they get those shirts all over, keep Austin weird. com, and that was back in 2014 mm-hmm.
2013, right? This whole concept of DevSecOps, well, it wasn't really much of a concept still, right? I don't even know if we called it DevSecOps back then.
A lot of people use the term rugged DevOps to talk about, uh, what today we think of as DevSecOps. And, and what was interesting is, I, I remember the first time we did the DevOps connected RSAC, that first year we did it, it was probably 2015, I'm going to guess. Okay.
Um, probably 2015. Uh, we had Gene Kim and Josh Corman and yourself there, and I don't think we used the term DevSecOps. I think we might still use the term rugged DevOps at that point.
Yeah. And of course that was something you pioneered. Yeah, I, I, yeah, I think that's because we were like all trying to stumble for words to figure out what this thing was that we were doing.
And like, just like DevOps had kind of come around and, and we were sort of pulling on those strings, and I think maybe part of being in Austin we're, we sort of consider ourselves like, uh, um, at least at that time, we were like, Hey, we're like kind of the, the blue collar of tech, right? So like our DevOps, our DevOps stuff was like, really, like with, with Dell's influence and some, some other, you know, enterprises here, we were like, okay, we, we want to talk about security. So even from day one outta the gate of Austin, uh, DevOps, our two keynote speakers, uh, were, uh, Nick Galbrath, who later, uh, founded Signal Scientist Signal Science.
Yep. And, and, uh, James Turnbull, uh, who's also security, uh, pro, you know, and so sure focused on security like day one here in Austin, even though security wasn't really part of DevOps, it wasn't a thing that was a, that was a part of the conversation at that, that moment. And the R Rugged stuff was kind of coming out of the, uh, Josh Corman, uh, Jeff Williams, some other folks had kind of been talking about this idea of rugged software and like building software that lasts and it's, that has this, uh, um, has all those qualities that we, that we think about good software.
And so we, so really rugged DevOps is just an attempt to like stab at like, what, what are we talking about here? It's like we're building software and like, how does, how does security fit into this? Because we, we didn't want to just have security be another thing.
Like we we're, we like the aspirational qualities of rugged and how that was going. So yeah, there were really, I think early days we were really trying to just figure, figure, figure it out. Like we knew we were describing a new way of working, we just didn't know what to call it yet, or where the industry would land on the term that, that it would be Excellent.
Um, so let's fast forward now though. Yeah. I guess it was about, I don't even know if it was a year, but in co since Covid, my timeframes have screwed up.
That's all. Alright. All us.
It's hard. Yeah. Um, but I guess it was maybe a year ago you had mentioned to me you had this great idea for a company that you were gonna explore.
Um, and today, you know, we announced dry run security, which is it, and you're CEO and co-founder. Well, let, let's start with who, who's the other founders here or the other co-founders? Yeah, my co-founder is Ken Johnson.
Uh, Ken Johnson, uh, ran internal security over at GitHub for, for many years. Uh, we've known each other for, uh, about a decade. Uh, he's the original developer on Rails go to Vulnerable Rails application.
That's kinda how we became friends. I was, I was running the OAS meeting in, in Austin, and I, I called him up, I was like, I need a, I need you to be a speaker at this event, and, uh, I don't have any money to pay for your plane ticket. You, you, you okay with that?
And he's like, yeah, oh, okay, sure. You know, but, um, so I was like 2010 or 11 or so Mm-Hmm. And so that, that was really fun that, that we were able to kind of, you know, do that and, and, uh, and kind of join our, start our friendship, uh, there.
So, um, yeah, we, we really were trying to build a product that made security, uh, delightful for developers. Something that that made developers more efficient, that helped kinda put security data. Uh, we, we call it contextual security analysis, puts that right in front of them as they're writing code.
And so that's been our, our vision with the company. We've been in more of a closed beta private beta for the last few months, and we've had, uh, customers kind of working through it and trying it out. And then now we to, you know, we're, we're just announcing that we're in the GitHub app marketplace, and so we're in, we're still in beta, but we're in more of an open beta where more people can, can join in, try it out, um, and it goes, uh, it, it sits right inside of your, inside of your GitHub, so it installs just as a easy GitHub app.
Excellent. Excellent. And, and that, you know, does that qualify it as a GI ops kind of a product then?
Or you haven't really thought about that? Yeah, we, I mean, GI Ops kind of has like some opinion of like how, how a GI ops flow should work. Um, we really have just as much as we can made it so that it's all about the developers' experience.
So, um, it's not inside of their id. Um, it's, but it's whenever they're merging in code, whenever they make they issue A form, it's when code gets committed. Yeah.
It's at that point, right? Because we, we believe in the world where people are using copilot and, and other type of tools like that in ID to kind of get rid of some of those easy to find bugs that are, you know, syntax related or, or, uh, checks like that. We're looking at other things like, is this commit?
Does, is it, is it complicated? Is it touching brittle files? Is it, uh, uh, is it manipulating off in a way that that, that you wouldn't expect?
Um, is it, is it, are some, uh, developers working on this where they haven't really worked on this code base before? You know, that kind of stuff. So we're looking at, well, the contextual security analysis is, is broader and we're continuing to build out the vision and build that into the product for how it's gonna work.
But, um, we think about every, every commit or every, every PR that we're looking at, we're looking at five, uh, five key factors that we're analyzing. It's the surface, the language, and the framework. It's written in the intent, the detections behind it and the environment.
So we kind of look at this, so we call it the slide model. So it's easy to remember and to think about like how we're, we're building this. So, so listening to what you're saying, James, but at some level, don't you need a view of like multiple commits to see how make sure these are all playing nice together and everything?
Yeah. Yeah. So when, when people, like a poor request could be as simple as like one commit, or it could be a, uh, several commits all batched together from one or multiple developers.
Also, port requests in some organizations can kind of take a life of their own, right? So it's like we submit the port request and maybe we failed some checks, or we needed to add some new features, or it didn't pass everything. Like, um, every time you make any of those changes, dry run security is rein, instantiated and reruns those checks to keep validating.
So like if, let's say as commits, uh, move in and out of a poll request, like we kind of keep that bit of work in the conversation right there in front of the development team. We're also doing this in seconds. So it's not like you have to wait, uh, you know, we don't have, we're not bloating your build time and added a bunch, bunch of inefficiency, uh, for developers, which happens with a lot of security tools.
Uh, that, that's one of the unfortunate things about the shift left is that we took, um, tools kind of built for a previous era, previous, uh, uh, you know, previous user model, right? So somebody doing pen tests or whatever, we took those and we've shifted them left without really like speeding them up for the speed of development. And so now you have bloated build times and you, you'd bes well, you probably wouldn't be surprised you talked to a lot of people, but you go to a lot of organizations and they're like, yeah, and it's like all I'm have like 15 security tools, and now everybody's like batching their commits and they're not able to be as nimble and agile as they as they wanted to be.
And you know, if anything that, that the agile and the DevOps movement has taught us is like, we gotta, we can't batch commit. It's like that is a, that is a, you know, year after year we've found that is, that is a bad thing, right? And so, um, yeah, so we, you know, so we don't want security to be a part of making that, that worse and putting that in the system there.
And so, um, I'm not saying all shift left is bad, but, uh, shift left sometimes, uh, without qualifications and, uh, where you're just sort of like putting burden, uh, back to developers that really, you know, you're, that was the security teams previously. That's where you end up having more of the problems in in organizations that have done that. You know, it's funny you speak, you mentioned Jeff Williams, you speak to Jeff Williams, you know, and he's a contrast security now, right?
Yeah. Uh, and he calls, I think he calls it Shift everywhere, right? Him and Larry, who are also Larry Maseroni are a contrast.
They say shift everywhere. Um, I I think look, shift Left has gotten a bit of a bad rap. It was a great concept.
Yeah. Right? Think about it.
Let's move. It's very logical. It makes sense.
Let's Move security further back earlier into the development process so we could catch these things earlier and, and make, you know, it's cheaper when you get 'em earlier. I think one of the problems we ran into James or not, not a, you know what, that's the wrong, I'm sorry. It's not a problem.
We ran into, one of the lessons we've learned is that the people who we're shifting left to the developers, the testers, the DevOps engineers, they're concerned about security. No one wants to have insecure code, but they're not security professionals. At best, we try to make them our security champions, which, you know, it's kind of like wearing a badge that says, I give a crap about security.
But in, in, in being champions, we shouldn't equate that or burden those people into being Security Pros, right? There's only, you know, you've gotta have tools that are designed for them at their level, at their kind of expertise, at their give a crap spaces, right? They, they're not, they're not security people.
They, they don't look at it that way. Yeah. So I think that's one of the things that kind of hurt us, not hurt us, but the, one of the lessons we've learned with Shift Left is you wanna build security tools for developers, or you want developers and testers and stuff to be more security conscious.
They're not security people, they care, but you gotta give them tools that make sense for them. Yeah. Yeah.
It, you know, we, we have to speak, uh, the developer's language, right? And it needs to right where, right at code checkin, you know, when you're, when you're giving 'em like the output of these tools and these CVEs and these high medium lows and these risk matrixes and stuff, they're like, what, what, what does that even mean? Right.
But yeah, you're right. I, I believe that developers deeply care about security because developers deeply care about quality and, and security and quality are tightly linked. And, um, the, but you know, one of the, you know, the DevSecOps survey that happens, uh, you know, that, that, uh, Sonatype ran many years Sure.
Still run. It's like, one of the things that have always been interesting findings for me out of that is like half the developers are like, yeah, I want to do it, but I don't have enough time. Well, what that, that's a sign, that's a, that's not, um, it's not necessarily even a sign of like, oh, I'm just too much, too, too busy.
It's like, the stuff you've given to me doesn't even make sense. Like, I don't even know how to deal with that. And then, um, and then like another, what one out of five says they, the developers were always responding like, I don't even know what's security wants for me.
I like, it's just too confusing for me to even understand what they're, what they're trying to say. Right. And, and, you know, developers are the smartest people on average in your organization, right?
They actually went to school for the job that they're doing. They've, they've been craft, they've been in their craft for years and years and years and, and security has kind of loaded them and put that burden on them of like decoupling, like, you know, this, uh, you know, word, um, you know, acronym soup and stuff of like, there's these cvs and they got this thing, and it's like, it just doesn't, it just doesn't relate to the activity that they're doing Just complicating their life, which is already complicated. So I, you know, hindsight's always 2020, right?
Yeah. But as I sit here today, why that was obvious, I don't know why we didn't recognize it before. We were so busy.
Rah rah, pushing that. Let's get back to dry run though. So you guys, you know, you look, you're basically looking at code at Commit.
You are, you're comparing it. Um, it sounds like you're diagnosing, is there an AI component to this? Or like, how are you, you know, how are you diagnosing?
Yeah, we break up everything across that, that slide model. And then we're looking for like, does this code like expand routes? Is it touching sensitive functions?
Is it looking at files? And we have different, different ways that we do that. Some deterministic, some probabilistic.
We use some AI components, uh, mixed in there. Uh, we think is like, you are kind of adding in a security buddy, like a security code reviewer buddy, security experts, if you will, into your, into your pull request. So it's like, we want to be a resource for developers, and it comes back, and then you can also chat with your security buddy and, and ask questions.
Uh, you know, that if it's like, if there's a finding or if there's a problem, like you can, you can start to get some triage and, uh, you know, we're working on training and building that up with our, uh, with our data and our knowledge base to kind of help, help, uh, you know, make that useful for developers. So it's continuing that, that, that part's continuing to grow. Absolutely.
Um, James, we're, we're running a little low on time. Last topic I wanna bring is, all right, someone's out here who says, Hey, you know, James Wicked's a great guy. This sounds cool.
I want to give it a spin. Is it in, is it, is it in GA yet? Is it still in like a beta or how, how do people engage?
Yeah, We're still, we're still in beta, but we are inviting new people to join us. So if you go to dry run Security, there's an install button right there. Uh, you have to have a GitHub account.
We only run inside of GitHub. Um, if you, or if you're saying, well, my company won't let me put on a GitHub, you could put on your personal GitHub and try it out, and then, and then we could, we could talk, uh, or if you're like, oh, I'm only in GitLab, or, or something else, you know, you click the, you can set up a demo time with us and we can chat and see like what, how we could help and how we could fit with you. But yeah, it's, it's, um, uh, it's, it's ready to go and, and, uh, we are, we, we do have a small, like, wait list, uh, functionality, but we're moving people off the rate, rate wait list on a pretty rapid clip, uh, nowadays.
Excellent. And I would assume support for some of the other gits and repositories will be coming shortly then, huh? Yeah, we have, we have some of that on our roadmap.
It sort of depends on, um, what people are using and what they're interested in, um, and, and what they're, uh, kind of where, where customers are kind of falling in. Right. But that's, um, but we're kind of putting that off for now.
But, um, you know, we see, we, we see GitHub as our first, uh, place to start And then dry run security. Yeah. Um, at this point, is it a, a charge, is it a free model still while it's in beta?
What are the plans here in terms of commercializing? Yeah. Right now it's in beta and it's free.
Um, and we'll, we'll always have some component of it, component of it that's gonna be free. Um, and while we'll have some upgrade options for like, uh, enterprises and, and folks that are wanting to like, get, get some, uh, more advanced, uh, features out of it. Um, so yeah.
So it should, we'll have something that we'll always be in the free category. Got it. security.
Yep. That's right. com and it'll, it'll take you there too.
security is, is is us. Very cool. James, congratulations on this.
I know you, you've sweated and toiled and worked on this a long time and it, and it's good. You know, it's kinda like owning a boat, right? The best two days of a boat, the day you buy it and the day you sell it.
Yeah. Um, kinda like that with secure with companies as well when you're an entrepreneur. Yeah.
Coming outta stealth is a big day, man. Congratulations. Yeah.
Well, thanks. Thanks, Alan. We appreciate it.
And, uh, you know, uh, thanks for having me over on your boat. Yeah, anytime. Um, all right, James, you'll come back on though and keep us posted, okay.
Will do. Alrighty. James Wickett, CEO Co-founder, dry Run Security.
com. Either one takes you to the same site. Uh, we're gonna take a break here on Textron.
We'll be right back.