Secure Code Warrior in the Age of AI with Pieter Danhieux
Secure Code Warrior’s Chief Executive Officer, Chairman, and Co-Founder Pieter Danhieux explains his transition from offensive cybersecurity to promoting secure software development. Founded in 2015, Secure Code Warrior aims to help developers build secure code from the start, a practice Danhieux and host Alan Shimel agree is more effective than fixing vulnerabilities later. The two also discuss the impact of AI on software development, noting that while AI increases coding speed and accessibility for more people, the security of AI-generated code still lags. They emphasize the growing need for developers to master secure coding practices amidst these technological advancements.
Transcript
Hey everyone. Welcome back here to Tech Shark tv. You know, I, when I first saw the time we were recording this interview, I felt bad for my, my, uh, guest here today.
He's a friend of mine. He is been on text, on TV over the years, a couple of, more than a couple of times, but he's based kind of on the other side of the world a bit. And it's usually, you know, to have him on in the middle of the day means it's the middle of the night, but he's in California today, so it all works out.
Let he introduce you to Peter Hu. Uh, Peter, of course is the CEO chairman and co-founder for Secure Code Warrior. Peter, welcome back to Techstrong tv.
It's great to have you. Oh, thanks so much for having me. I'm very grateful to be here in, uh, nice sunny California.
Uh, a good 40 hour flat from Australia, but I'm happy to be here. It it, did you say 40 hours? 14, sorry.
14 0, 14, yeah, that's about right. 'cause we're about five hours from five to six hours from California here, and it's about 19, 20 hours though. You know, there aren't that many nonstops nonstop.
You gotta go up to like New York and there is a Qantas I think that goes into Sydney nonstop, and that's about a 20, 21 hour flight or something like that. Um, I've taken it, it's a long flight. That's a long flight, but it is nonstop.
Anyway, Peter, I'm glad that we don't have you up in the middle of the night. I, I appreciate you coming on. For people who maybe this is their first time seeing you and maybe even hearing about Secure, secure Code Warrior, let's talk about kind of your journey.
What led you, what path did you take to co-found and, you know, lead Secure Code Warrior? Yeah, a long story like I started in cybersecurity in the early two thousands. Like I was mostly on the offensive side of cybersecurity.
I co-founded the Hacker Conference of Bru Con, uh, over in Europe, um, and I think after and teach it Forde Sand Institute. And my goal was always to kind of teach people on how to break into systems. Now, having done that for about 15 years, in 2015, I realized that I need to help the people that are actually building the software, because very often it allowed me to, it allowed me on my team to break in, to steal data out to do what all these malicious packers are doing.
And we were always being able to kind of draw it back down to a problem in the software. Like somebody or something kind of wrote a piece of software and they were using the wrong library, they were losing load function calls, and as a result, somebody was able to exploit this weakness and gain access and try access to a system. And that's why I said, okay, I need to stop teaching people how to hack and I need to start helping people how to build software in, uh, in a secure way.
And, and that's how Secure Code Warrior was founded in 2015. And our whole mission, uh, is and still is today, is to help software developers to build code in the most secure way as possible. Excellent.
You know, in many ways I kind of mimics my own journey a little bit, right? I, uh, got into security in the late nine, late 1990s, late nineties. I remember Sands Institute, my good friend Steven Northcut, I don't know if you were there when Steven was there.
I'm still friends with Steven on Facebook at communicate with him all the time. And those were the heydays. I mean, sands was where you went to learn security.
We didn't have cybersecurity majors coming outta college and stuff like that. You went to Sans and it wasn't cheap, but it was great courses and they had great conferences around the courses. I had co-founded still Secure back then.
And, you know, we were a big, big supporter. We used to buy those big blow up like yoga balls and put 'em in all the Sands classrooms instead of chairs for people to, to sit. We used to tell people we were the company with the big balls.
Um, and it worked. We, we had a good time there that, you know, the reason I really got into DevOps was the same reason you shifted left, which is you realize if we could get the security problems in the code when they're coding it before it's deployed, it's a hell of a lot easier and cheaper to fix there than, you know, trying to kind of stick your finger in the d**e of, of, you know, uh, well once it's already out there. So I, I appreciate the, the, the journey.
You talked a little bit about kind of the mission of Secure Code Warrior and, and how it came about, but of course that was like 2015, it's grown since then, right? The world has changed a little since then. We're gonna talk about AI because how could you not talk about ai?
Of course everyone has an AI strategy, but talk a little bit, Peter, how the, how the market has changed and how the mission of Secure Code Warrior maybe has expanded since 2015, right? What's going on? Yeah, so there's probably like two big things that I've seen happening over the world with my customers is that is first of all that everybody is writing code these days.
Like a software development is not anymore like the gigs that are summer sitting in certain department, but every bar, everybody has the ability to build an application. And I think with ai, that's even go to accelerate even faster. So the definition of who is a software developer is kind of a changing from people that are full-time writing code.
But nowadays it's also, uh, people that are, uh, analysts, financial analysts in companies, they can write code data analysts or can write code like anyone has the ability to start using Python and JavaScript to kind of build, build applications. I think what is going to happen is with AI and the, the ability of AI to generate applications, think about the vibe coding, like even more people are going to be able to build and deploy applications in seconds. Like, I'm not sure if you saw the announcement of Open AI yesterday.
Um, they released something, uh, the uh, uh, agent SAK, where I think in minutes you can deploy an application into production. And so my opinion will have more people building applications than ever before. I thought you were gonna say the, the announcement of them maybe taking up to a 10% stake a MD with warrants and, and buying all these chips and the week before, the a hundred billion dollar deal with, with Nvidia and stuff like that.
Open AI is certainly, you know, in, in the news all over, but you bring up something that's very important. At the end of the day, we talk about hardware and hardware is cool and sexy. Again, it wasn't sexy for a long time, but the real test for success will be are people using the software, right?
And video's, secret sauce, sauces, CUDA, and all that whole software ecosystem they've built around using GPUs. Open AI is on a similar quest of getting the developers, the AI developers, the AI engineers to use their software. But of course, Peter, as we've seen, security isn't always top of mind with these things, right?
A lot of times it's it's the end of the train rather than the front. Yeah, and I think like if you, if you look at the, the, the different models that are out there today, um, they, they have evolved a lot in their abilities to build code. Like if you would think at, um, chat TPT two years ago, even 12 months ago, they weren't like the level of coding they could provide were really junior level coding like an intern.
They could code like an intern. Now we're now 12 months later and the ability to build code is much, much better and much, much higher now. And I would say they probably match the level of a senior or a principal developer, uh, that you can build COVID.
I think, however, from a security perspective, we are still, we're still kind of behind where I think we're still at that junior intern level where the code that is being generated by these different models often still has mistakes in it that shouldn't be there. And it's not, it's kind of normal because they've been trained on publicly available data and of course there's a lot of bad sample and bad coding patterns available on the, on the internet. Now I do think that is going to change over time.
It's gonna take us maybe another 12 or 24 months, maybe 36 months to get the, the security of those models or their ability to generate secure code to get that up to scratch. But I think at the moment we're still kind of of faced with, there's different models that have different level of security competencies in coding in Java or COBOL or any of those coding languages. Agreed.
I know, I have to agree with you. Um, now there's another school of thought, Peter that says you, you need AI to fight AI kind of thing, right? So, you know, the bad guys are using ai, uh, in, in every way imaginable to make their malware better, to find more vulnerabilities, to improve their phishing attempts have ransomware, everything, what Secure Code Warrior doing.
So our belief is that if you take a developer that knows about the dangers of working with AI that knows about secure coding and secure coding patterns, and you combine that human with a great LLM, like an LLM that is good in, uh, secure code generation in Java or in c or in c plus plus or whatever you use, if you have that combination in our organization, you will get the productivity gains that everybody is hoping for, which means much more code, much more faster and more secure. We also think that the opposite is true, right? Take a developer that is not aware of the danger that, uh, or the, the pitfall of an LLM and that is maybe not aware about some of the insecure coding patterns and secure coding patterns, and you combine that developer with an LLM that is maybe not as strong in secure coding in a certain coding language, I think we will create the complete opposite effect of what we want.
We'll have 10 times the amount of code with 10 times the amount of technical debt and misery in it. And I think we, we want to be able to change that. We wanna make sure that everybody kind of falls at that first category where you have a great hu that knows the dangers of ai AI and you combine that with an LLM that knows about secure code generation in different coding languages because that's the productivity gain I think that everybody is looking for.
Yeah, I, I agree with you. I agree with you Peter. I, I, you know, I, I did text Strong Gang today, had a few more conversations today, this whole week, and I think, you know, we were both around, as you said, the early two thousands.
com bubble as you were as well, aren't we in an AI bubble, Peter, our, you know, are we out in front of our skis a little bit in, in terms of what the hype is and the amount of money being tossed in here, right? Are we thinking enough about security? Is the functionality there, right?
I I saw a, a Twitter post or ex post whatever the other day. Um, if you look at the amount of money just in the US being invested in ai, it's roughly the size of Singapore's economy, but if you look at the amount of revenue being generated, it's roughly the size of Somalia's economy, but there's a little disparity here. Well, I think you've answered the question yourself, right?
I think I, I, I think there is opportunity, right? There's absolute opportunity and I think everybody is trying to kind of get into, get in it. Does that mean that things are going to explode and blow up and maybe lots of companies will go down because of ai most likely, but like all of these investors are making bets and I'm sure that some of them will work out and some of them won't.
Um, so yes, you could, you could, like what I see is opportunity. There's an absolute big opportunity for AI to disrupt existing technologies, disrupt the way on how we work today. Um, and yeah, this may be a little bit of over investment, but I'm sure that'll that'll correct themselves over time Is people are always willing to soak up extra running, right?
That, that's for sure. Um, Peter, beyond the, the trust agent and ai, what else is in store with Secure Code Warrior? For us, it's really important with SEW Trust Agent AI to kind of stay on that pathway of how can we help the future developer, right?
And the future developer is one that is either using AI as a, uh, as a pair programmer, so somebody that kind sits in the ID with them and kind of helps them providing code snippet, providing guidance, providing advice on helper, build thingss up to the developer that is Vibe Coding, which is the one that just send the instruction to the LLM and it builds an application itself. And we to stay very close to that developer and making sure that, um, we release features and tools that will help them to enable safe adoption of AI within our organization. What was really surprising to me is that if you ask the question to any size of an organization, how much of your code today is being assisted or written by an LLM, very often they don't know the answer.
Um, they, they, they might have a rough idea, but they can't really show data or really, really tell me, well, 20% of our code is written being written by Chat ccpt and 10% is being written by deepsea. That visibility is not there. And I think with SEW Trust H HD ai, we're hoping to provide the CISO with that visibility so they can actually see, um, which applications are being modified by which, which type of LLM and and, and who is the developer using those LM.
So it's basically the link between developers, ai, and the real software applications and that you can kind of see that link and then also control and govern some of those, uh, aspects of it. Fair enough. Peter, we didn't mention what's the website for Secure Code Warrior?
com. I, it's too long. We need to shorten it to SCW Doo, but we'll, we'll figure that out.
com. com. Yeah, I mean, I assume people can get all the information on the SEW Trust agent there.
Yes, we have our, our, our product demos, our videos, um, it's, it's all on the website. So if, uh, yeah, it's definitely there. How long are you in the states for?
Um, I'm only here for about three days, but I am back in about two weeks. Like one of the downsides of building a company out of Australia is that you have to be in the place where your customers are, which is the us And so I am very offering, doing the lag between Sydney, LA Sydney, San Francisco, Sydney, Dallas. It's, uh, unfortunate every, every month, month on the app or so, You know what, but you do get to live in near Sydney.
I love it there. One of my favorite places in the world. Peter, thanks for coming up here on Techstrong TV and, and giving us the latest scoop on what's happening with Secure Code Worry, the SEW Trust agent, the state of the AI and security market, continued success, and we'll see you soon, I hope.
Awesome. Thank you very much, AAM. Thank you.
We're gonna take a break here on Tech Drunk tv. We'll be back in just a moment.