The Future of Security: Integrating Protection into AI Browsers
Vivek Ramachandran, Founder and CEO of SquareX explains the shift towards browser-native security solutions and the challenges of last mile attacks. The emergence of AI browsers and their security implications are discussed, highlighting the need for strong security measures. Square X focuses on integrating security into browsers to protect users while maintaining productivity, emphasizing the importance of ongoing security innovation.
Transcript
Hey everyone, it's Alan Schell. Welcome back here to another Tech Drunk TV segment. In this segment, I want to introduce you to Vivek Ram Charan.
Raman Chandran. I'll do the best we can. He's gonna say it better than me.
Vivek is the founder and CEO of a company called Square X, and let's welcome him here to Tech Drunk tv. Hi, Vivek, how are you? Uh, hi, Alan.
Thanks so much for having me on the show. Really excited and yeah, doing amazing today. Thank you.
Hey, say your name right for me, just so we get it. Vivek Ram. Ram Ram.
Okay. I just can't roll those Rs no matter how long I've been doing this. I can't roll the Rs.
Anyway, Vivek, as I mentioned, you're the founder and CEO of square X, and we're gonna talk about Square X in just a moment, but let's, let's hear a little bit how you came to found it, why you founded this company, what, what kind of drove you to found it and kinda a little bit of your journey along with that. Yeah, so Alan, you know, I started my cybersecurity journey almost 24 years back. And, uh, you know, I was very lucky that I kind of fell in love with this space in the very beginning when I just started my engineering.
So the first few years I worked for companies like Cisco Systems in their engineering team, building security products, but very quickly figured out that, you know, I somehow had a knack for breaking security. So then I shifted gears to security research, found a bunch of vulnerabilities. I've authored books, you know, which are still on Amazon, uh, spoken at DEFCON Black hat 20, 25 times.
And that was the time when I started my very first company where we ended up building a wireless monitoring device primarily for defense agencies to go about, you know, monitoring what's happening in the air. Uh, and from there on I went and, you know, founded my second company, pentest Academy. And the whole thought process was, this was 2011, and a lot of folks did not understand how attackers worked.
So pen tested Academy used to create these big labs for banks, financial institutions where they could have their red and glue teams, which is really their attacker and defender teams do these collaborative exercises. Uh, ran that for eight years. Eventually that got acquired by Providence Equity, uh, actually based on the East Coast.
Took a little bit of a break and then started Square X around two and a half years back. Uh, and the whole thesis really was, you know, Alan, when I was running pen tester, I was talking to all of these red teams and they used to come and tell me, Hey, Vivic, we are starting to see more and more attacks happen through the web browser. You know, because if you think about it, you know, people are spending all their time in their browsers, uh, you know, know doing transactions, doing work, you know, watching entertainment on Netflix and whatnot.
So the browser was starting to become the new computer, the new endpoint and attackers were taking note as well. So the inspiration behind Square X was if everything is moving into the web browser, then security should also become browser native and a first class browser citizen. Uh, while today, you know, everything sits outside the browser, right?
Your antiviruses, your eds and all or everything is outside. So we started with the thesis that why not build a product which can integrate with every browser on any device, and that is really a browser extension and that extension can monitor, detect attacks, block them, report back to the enterprise. Uh, so we were very lucky that Sequoia Southeast Asia put in the seat check and then send Ventures, you know, did a follow on series A round.
And in the last two and a half years, we've raised around 30 million. Uh, now we have customers, which are public market companies. We have one of the largest crypto exchanges deploying Square X.
And now we are actively, you know, PO ving at many Fortune 200 companies across various industries. Uh, because look, everyone has a browser. So anyone who worries about attackers, you know, unfortunately has to protect their browsers, and that's really what Square X is doing.
I love it. That was great, Vik. Thank you very much for that.
Before we jump, we're gonna talk about last mile attacks here in a minute, but before we do listening and, and I have, you're the first kind of browser security person I've spoken to since this problem or question popped in my mind. I don't even know if you're gonna be able to answer it, but if you can, I appreciate it. Everyone.
Today's talking about AI browsers, AI browsers, open AI has, I forget what it's called, not Opus Atlas. Atlas Atlas, excuse me. Yeah.
Atlas and Perplexity has one and yeah. And they're all coming out and, you know, is this going to be finally something that replaces Chrome? I don't know, is it really that big a difference?
I've spoken to a lot of people who use them and I get a big meh, you know, however, from a security point of view, yeah. Could it help? Is it better?
Is it worse? About the same? What do you think?
Yeah, Great question. So I think, you know, Alan, I'll start off with the first piece that you mentioned is, you know, are these browsers going to become ubiquitous? Right?
And the best way to answer is you might remember the time when TVs had just come out with microphone and cameras, and we all said, we will never buy one of those. Yeah. And, you know, a couple of years down, that's the only TV available with microphones and cameras.
Yeah, Absolutely. So I think exactly that way, what's going to happen is all browsers are going to become AI browsers. And what I mean by that is, with AI starting to get integrated in all products, whether it's Chrome or Edge or you know, perplexity, s Comet or Open AI's Atlas, everything is going to have that AI assistant run alongside with whatever the user is doing, help him, you know, go through massive amounts of information faster, automate a lot of his workflows and all of that.
So my current current, you know, vision around this whole industry is the only way that these AI companies can control the whole user experience is by owning the browser because they can never own the endpoint. Microsoft and Apple have already done that, so this is going to accelerate. Now, the second piece are these browsers secure?
Now, typical Silicon Valley, you know, they love to go ahead and release products, which are early because they love to iterate. And, and this is really the TNA of Silicon Valley, right? Uh, and this is no different in the case of Atlas Comet and all of these AI browsers.
So in the last couple of months since they've been released, attackers have started breaking these browsers down. We, ourselves, as a security company, have found multiple vulnerabilities. And just like in the early days when you had chat GPT, you know, go ahead and, and sometimes even say racist things and whatnot, at this point in time, AI browsers are pretty much breaking in similar ways, lot of attacks and lot of exploits.
Uh, my prediction is that, you know, similar to what happened with Chat GPT Gemini and all of that, there's going to be a lot of fast iteration and eventually these browsers will start becoming more stable and secure As of today, uh, I wouldn't say enterprises would be terribly excited to use these browsers, uh, because there's a lot more security plumbing to, you know, be built in, uh, for use in enterprise. Yeah. You know, Eve, I, I've been in security also before it was called Cyber, right?
Been in security 30 plus years, started a few security companies. Unfortunately, this is an all too familiar story for us, like you and I who've been in security, security is always an afterthought. Let's rush it out.
Let's get it out there. You know, I'm reminded I has to be. 15 years ago, I did a podcast, Mia, a friend of mine from Gartner and myself, and we had on the CEO of MongoDB and Couchbase, right?
This is when no SQL databases had just recently come out, and they were all the rage. And I, I asked these guys, I said, you know, a lot of people say no, SQL stands for no security. What are you gonna do about security?
And, and the audacity, they, they just, they plainly told me on the podcast, right? They said, look, we'll build in security when our customers demand security. Right now, they just want no SQL databases.
Yeah. Nothing has changed. Absolutely nothing has changed.
I want AI b browsers, what about the security? We'll worry about that. We'll get to it.
Yeah. It's, it's, you know, it's, it's frustrating. It's frustrating, but I, I think as security people, we learn to, okay, maybe they don't think they want it right now, but they do.
And what can we do to start hardening this, to preparing for it, et cetera. Um, anyway, let's pivot back to last mile attacks. I appreciate you giving us your insight on that, but you know, not everyone watching this, Vivek is a security person.
We have DevOps people and cloud native and uh, uh, all kinds, well obviously security, but AI folks and transformation and platform engineers. Um, not everyone knows what we mean when we say last mile attack. So why don't we start with that?
Why don't you define last mile attacks? Yeah, so Alan, you know, taking a step back, uh, primarily the security stack today, which is going ahead and securing all traffic coming from the endpoint, uh, is really part of this big, you know, industry acronym called S-E-S-S-E. Yeah.
And that's really where you have all the big companies, you know, uh, Palo Alto, Zscaler, uh, Netskope, whom not. And the whole idea there was very simple is send us all your traffic coming in from your computer, from your browsers to our cloud data centers. We will scrub it, clean it, make sure that it is free of any form of security issues.
Now, that promise was amazing at a time, probably around a decade back when browsers were simple website renderers and were not as complex as they're today, which is full-blown application platforms with multitude of new protocols, et cetera. They're, they're the ux Exactly. The Browsers become the ux.
Yeah. And that's really where, what last mile reassembly attacks is unlike the time when these technologies were invented where browsers could do little apart from show a webpage. Today, browsers have the capability to run code, you know, web assembly, high quality, JavaScript, a bunch of other embedded languages.
So what attackers have started doing is traditionally what used to happen is, let's say if somebody were to send you ransomware as a malicious Excel file containing a malicious macro, which you would download, open it up and get infected, uh, in those days, your sass ESSE secure web gateways in the cloud would see a file is coming, pause that download in the cloud itself, scan and see that there is a malicious macro and block it. Mm-hmm. But now with browsers being able to run code, imagine that no file is ever sent, and the browser itself using JavaScript on the page assembles and creates that malicious excel right there in your browser rather than send it from the server site.
So now your secure web gateways and SS ESSE solutions never see a file because actually there is no file, the file is getting created live in the browser. And the example I can give you the analogy for viewers is imagine that, you know, you are looking for some kind of a painting, maybe a Mona Lisa that somebody's trying to smother in. 0 secure web gateways.
So last mile reassembly is rather than send the painting, you're sending the painter so that the painter can come and then kind of go ahead and sketch the whole painting in your browser. So if you purely scan for a file, you aren't going to see anything in the cloud because the file gets reassembled. Now, we can go about extrapolating this not just to files, but website, malicious scripts and whatnot.
So all your old attacks, which were capable of getting caught in the cloud, unfortunately, are all new again, because they get reassembled in the browser. So this is the big expose that Square X did last year at DEFCON main stage and where we showed that existing every vendor is actually vulnerable to this architectural attack. And it is true even today.
Absolutely. Absolutely. I, I, whenever I see acronyms though, I always like to explain it for people who, who don't understand.
When we say Sassy sass e like that, what do you, what does that stand for? Yeah, so Sass, ESSE is this industry acronym, and the whole idea really was could you decouple networking, uh, basically from, you know, security. And this was something which was invented like a while back.
So SASS e is basically secure access, service edge, uh, you know, fancy way of basically, you know, adding both networking as well as security and SSE security services Edge, uh, that is really just the security piece of it. Mm-hmm. So there are companies which do both networking and security, and they belong to the SSE category while SSE pure security companies who don't want to do the networking, but rather just security in the cloud.
Got it. And when we look at Square x new generation, a new way of approaching this problem, fair. Absolutely.
Yeah. Yeah. And the, the way we are approaching this, you know, Alan is, uh, for a very long time, the only way was clearly to ate the laws of routing physics.
And instead of allowing a packet to go to the destination, you know, with the fastest route force, everything to go through these data centers of these sass, ECC players, fundamentally becoming a choke point, slowing things down, massive latency, bad user experience and whatnot. So the key innovation that Square X has done is, rather than having a proxy, we have the ability to look at all data, all user interactions, and all workflows in the browser itself. And this adds no latency, gives us a full 360 degree view of everything that the user is doing and everything that the browser is doing, allowing us to detect and block attacks right there rather than SS ESC, where all you see is network traffic and you have to reconstruct what is happening at the application layer, which in today's complex browser based protocols, unfortunately, is no longer even possible.
And that is the big innovation that Square X has done. Got it. You know, look, Jay Charge was in, uh, someone I know a long time in the security world, right?
And when he first started Zscaler with the idea of running things in the sandbox before it got to your network, it was kinda revolutionary, right? Absolutely. Yeah.
Jay's made a lot of money from Zscaler doing that, right? Certainly. And I'm not begrudging him, right?
He's done a great job, but you're right, there was always that latency issue, but that was the kind of the price you paid for, for security. Um, as things have gotten more complex, of course everyone's come up with a little bit of a mouse trap on it, a better mouse trap on it. When, when you say square X secures it, test, it, scans it, whatever you want to call it in the browser.
So is is Square X then sort of a browser extension, a plugin, if you will? Yeah. Yeah.
So Alan, the, the key realization we had is, you know, security solutions unfortunately can never tamper with how people work and should never get in the way of productivity. And that's really where our thesis was, that if you start to give people a new browser and things like that, it'll never work. You have to work with every browser.
And the only way to work with every browser is similar to your ad blocker, which works on Chrome Edge, Firefox everywhere, which is, it's an extension. So our key innovation was to go ahead and push the extension technology to its limits where we were able to build a full security product as a browser extension. And the power of that is now we can deploy it in any browser, by the way, including the new AI browsers.
So we, I actually secure Atlas Comet, all of them right out of the box. So I, I'm thinking about downloading the Atlas one. I'll be looking for the Square X plugin for extension for it.
Vivek, I don't think we mentioned the website or anything, did we? No. com, there's four letters.
SQ rx Q rx Yeah. Dot com. Uh, it took me quite some negotiation, you know, with, uh, Broker, I would imagine it's hard getting a four letter domain, right?
Yeah. So that's the place everybody can visit to learn more. Excellent.
Um, going to RSA. Yes. So we did RA the last two years, and we plan to be there, you know, this year as well.
And every year, right before we, we, you know, do security exposes, vulnerability research and all of that. So we will be both at RSA as well as at Blackhead in the summer coming year. So We we're at both as well.
But check in with us maybe before RSA. Let's hear about your new research. Absolutely, Alan will do.
All right. Vivek, Rin, uh, here on Text Drunk tv. Vivek a pleasure.
Thank you for coming on. com. We're gonna take a break here on Text Drunk tv.
We'll be back in a bit.