Why AI-Generated Code Is Raising the Stakes for Secrets Management
Following a $50 million funding round, GitGuardian CEO Eric Fourrier discusses the mounting challenges DevSecOps teams face in protecting sensitive credentials as developers increasingly rely on AI tools to generate code. He explains how automated code generation can unintentionally expose secrets, why traditional detection approaches fall short and what organizations must do to secure the modern software supply chain.
Transcript
Hey guys. Thanks for the throw. We're here with Eric Fourrier, who is CEO of gi?
Uh, let me, it's GI guardian. Guardian GI Guardian. Yeah.
GI guardian. All right, try that one more time. Here we go.
Hey guys. Thanks for the throw. We're here with Eric Fourrier, the CEO of Get Guardian, and we're having a little chat about keeping secrets in application development in the age of ai in the wake of them picking up an additional 50 million in funding.
Eric, welcome to the show. Hey, thanks, Bob. Me, Mike.
How we buddy All? So, um, you guys have been at this for a while and I think it's, the landscape is fundamentally changing though with the rise of these AI agents. So what's your perspective on what's going on here?
Because a lot of people are not, well, they're not sure. Is this a new type of identity that we need to keep secrets for and from? Or is this just a non-human identity that will manage much like any other non-human identity?
Yeah, it's, it's, it's a tough question, Mike. I think, uh, when you think about it, it depends on the walk robot. It's, it's a bit of both.
So, uh, when you, when you think about it, like you take an AI agent right now, it's the, the reality is like every company right now is trying to deploy AI agents and an AI agent to be efficient. It needs to have access to data and need to have access to different data sources. Could be your, uh, CRM could be your product data and, and, and to get access to the data it needs credential.
So it needs API keys, it needs tokens. And because what's lacking right now, it's, it's very hard to identify, uh, an AI agent and get access to safely to different resources. So people are doing it the old way, which is giving them secrets, which, which is a huge problem when you think about it because it's, it's accelerating the, uh, the secrets post, the secrets end up like leaked everywhere.
And that's what we've been doing at Guardian for the last six or seven years, is trying to look for these secrets that are leaked in every system and to make sure attackers cannot choose them and to protect our customers. And yeah, AI agents have drastically increased, uh, the number of secrets used and the number of secrets leads, and there is currently no way to, um, to, to safely secure them. And, and, and that's really like the big problem we, we seeing right now.
Mm-hmm. Um, those AI agents, um, how good are they at keeping secrets? Because, you know, some of the people I talk to say, you know, the guardrails aren't so good and they're about as effective as keeping a secret as your average five-year-old.
Uh, that, that's a good question. So on on that part, it's really interesting because at the end of the day, especially with, if we look at a bit at coding agents, so it, it has evolved a lot over the past like two or three years. So when, when, you know, the first model of, uh, OpenAI started two or three years ago, there were actually, you could actually, um, with the right prompt, it was super easy to get like actual secret from the training set.
So because, you know, this model that've been trained on, on a lot of open source code and inside this open source code, you have a lot of secrets and credential you could actually get like credential from somewhere else on, uh, from, from a request to the model. But hopefully it has evolved a lot and now the coding agent are, you have more, a little bit more wild ways there are more powerful, but the real problems come from the person using the LLM. Its, and, and that's, I think, the world danger of white coding that a lot of people are underestimating right now.
It's, it's really of people that are non-developers, could be marketing could people could be self people, could be ops, like, could be people that have no training in software engineering that have no idea what, what it's credential and how they should be managed that now are able to vibe code application. And, and that's usually them, uh, making the worst mistake. Even if the, the agent or the LLM is now doing them, it's it the human that would introduce the vulnerability.
So you have this combination of both like an experienced human with like this coding agents that push you to be extremely fast and like you have this, you know, the hype of, uh, of the, of the trend that makes that force us to say, okay, we need to adopt fast, all these new tools, we need to release this AI agent to our employees, but we, we need to do it fast. So we, we just, you know, we don't do, we don't put any security guard. So the combination of these three things, which is untrain people, uh, push to, to, to, uh, the velocity on, on, on the code and, and the, the absence of an insecurity galleries, uh, make it a critical, critical issues, uh, for, for secrets and for, for, for companies right now.
Yeah. So I think 50 million is still a lot of money even in the age of ai, but, um, what is the plans or what do you think guys thinking about investing in it? Yeah, it's, it's a great question, Mike.
Um, I think for, for us it's on, on two side. Um, so first is, um, expand our current go-to market, uh, operations. So, uh, GaN was created in France, but you know, our, we have a very unique, uh, story for our French is like our first customer was US based.
Uh, we now do 70% of our business in the us. Uh, north America is our fastest growing region, but we, we really started like having reps in the US only two years ago. So, uh, we have 25 people right now.
We see a tremendous traction here. So, uh, we definitely want to double down, uh, in the us and at the same time, uh, over, over the next two or three years, uh, there is tremendous opportunity and we have already customers in Asia, so Australia, India, Japan. So, uh, we also want to open new region, uh, both in, in Asia Pacific and, and also on the Middle East.
Um, and, um, the other side is product like, as you've seen, like AI agent, uh, the pace is, is so fast. There is new, new innovation, new type of agent and new type of ities almost every three months. Uh, so we need to keep the pace and build more and more product, uh, so we can help, uh, our customers safely deploy AI agent, uh, while securing like the credential and really, really try to, to, to make them, uh, them more safe and, and, and really give them the ability, uh, to, um, to deploy them and enjoy the, the velocity and the a OI while, while being also safe at the same time.
Is this whole shift to AI gonna exacerbate an existing problem? 'cause I think a lot of developers aren't very good at keeping secrets themselves. They might be slightly better than the AI agent, but it seems like one's just gonna compound the other.
So what do we need to think about doing here to kind of protect our secrets? Yeah, it's, it's a great question. I think definitely every coding agent, uh, is making developers like more productive.
So, uh, give them the ability to write small lines of code. So if that already, which is the case, you're right, already leaking secret, it's just accelerating the problem. So it's why you need, uh, you know, shiftless have been, has been so important, uh, has been really important in the, in the past, the past five years, but it's even more important right now is like we should equip developers, uh, as soon as possible.
And we, uh, have tool that are, uh, really strongly suited for the agent, uh, workflow, for coding agent, uh, on the laptop of a developer. So it's, it's basically developing a series of, of, of tooling and product that are very close to the developers. So you can, uh, you can help write, uh, more, more secure code and avoid leaking credential, but also build like awareness, uh, and, and educate them on how really they can safely manage secrets.
Will we maybe have an AI agent that will go look for all our secrets at some point, and that will just be part of the DevOps workflow? Yeah, it's, it's a great question. So the, the, I think on the, on that, that's a question like we, we have asked ourself at the guy.
So we, we have our own detection engine to, to detect secrets and like, can, can we use an AI to do it? Uh, for now, the economics is, is still not there because, you know, especially for our customers, we need to scan like terabytes and sometimes petabytes of data when, meaning when we actually look, uh, for, for secrets in new data sources like SharePoint, Google Drive, you know, all the, uh, JIRA tickets, all the docker images, just so, so much data to scan that at the end of the day, you, you cannot send everything to an agent or otherwise you, you will pay like open eye or tropic like tens or 20 millions of dollars to scan your data. So it's, it's why where you need like products like GI Gallian and be smart about it.
We call it hybrid detection. So it's a combination of a first step that's a deterministic engine. And the second step that's really like, we use also AI in our product to do prioritization and to help our customers better remediate the secrets.
But at the end of the day, the first stage is, uh, needs to be, uh, deterministic, fast and able to process a lot of, of data that for now, uh, LLMs, uh, are unable to do. Do you think the bad guys are gonna get better at using AI to find our secrets? And this may be a big part of the problem going forward?
Yeah, it's, it's, it's a great question. I think like the, the big issue, um, and it's, it's, it's a, it's an issue that has already existed in cybersecurity for a long time. It's, which, which exists in life.
It's, it's always easier to, to destroy stuff than, than build stuff. And, you know, it's, it's exactly the same for, for cybersecurity. It's the job is, is is unfairly easy, uh, for an attacker to, to do damage compared to the defender.
And, and yet AI has accelerated that a lot is like, unfortunately now with ai, the attacker have the ability to, uh, they will scan the, the company data for it to enter into a system. They will scan the, uh, the system for secrets. And after they will probably use an AI to ask like, okay, what are the most important secrets?
What are the secrets I can use to move laterally and do more damage? And unfortunately, LLMs are very good at that. So, uh, that's why it's, it's so important.
Like it's, I always tell like, customers and prospect is like, now we need to move into a world on, on zero trust on your data. So you need to consider, if you have like secrets giving, you know, I always say giving the keys, keys to the kingdom and giving a lot of access, uh, you need to consider that they are gonna be compromised because you will get breached and attacker will get in. And with the AI can be what would take like, you know, 10 days of, you know, scanning secrets, uh, evaluating them, trying to find the right, uh, the right way to enter into a system can now take like, you know, minutes, tens of minutes.
So yeah, it's, attackers are now incredibly powerful with ai. What is the relationship between the application development teams these days and the security folks that are an nominally responsible for all these secrets? Is that getting better?
Because, you know, historically they've always kind of been two ships passing in the night a little bit, but, um, you know, are you seeing more collaboration and what's driving it? Yeah, again, very good question. I, I think it's, it's, um, the relationship you write has always been like, it's almost like you had a wall between, between teams.
But I think, and it's really, um, my vision for GYN in the next year, at the end of the day, like the problem of of secret security and non identity security has become so important that you need to, uh, first you need to, to have a product and a platform to address it. But at the end of the day, like for us, like we need to have like the application security folks, the identity players, the developers, the DevOps, like teaming together to solve the problem. It's not like, it's not the responsibility of one team or the other.
At the end of the day, it's like you need, and that's, that's why it's so difficult to build and that's why it's so valuable is like you need to build a tool for, for every, uh, persona and for every type of, of, of people. And, but at the same time, give them the ability to collaborate together. So I think they have no choice.
Uh, the problem is so important that, uh, it needs to be tackled from multiple angles. Uh, developers needs, uh, tools inside that development workflow to avoid leaking secrets, application security teams need, uh, holistic, uh, workflow and, and dashboard to be able to map all the, the issues and focus on what's the most important and the most critical, uh, piece. Um, and identity folks need to provide a way to, uh, app on the remediation, making sure we are like secrets manager in place, making sure we are short lived, uh, tokens and identity.
And, and it's a teamwork at the end of the day, uh, you, you need to work in teams and, and that's how we, we see the future with, and we were gonna orchestrate, uh, all this workflow from, you know, um, detection, prevention, remediation and, uh, governance and hygiene. And, and it's gonna be, um, it's gonna be hard. It's gonna be long, but yeah, that's, that's where we see the value and that's, that's our mission.
So what's that one thing you see teams doing that just makes you shake your head a little bit and go, folks, we gotta be a little bit smarter than that? Yeah, I think a, a great question. Um, I think like the, the, the big shift I'm, I'm seeing, and I I've seen it, um, you know, from the early days of GI g when, when I started GI Guardian, so we started with, with public monitoring Sogar style.
The first part of GI Gian was like we, and we were, well still very known for that, is like, we find like secret exposed on public data, like, which is today probably one of the most critical vulnerabilities you have, your AWS secret, you have a database secret sitting like on public aap, so everybody in the world can see it. So very dangerous. And, you know, in the early days of good gum, people were like, yeah, it's, I understand the vulnerability, and I was trying to educate people on like, yeah, but, and you also probably have secrets in your internal code base, and that's, that's also a big vulnerability because if an attacker can find it, it can make damage.
But yeah, people were arguing like five or six years ago, okay, it's, but it's in my internal code base, so it's safe, it's behind my, my internal firewalls and system. And, you know, the world has shifted because yeah, code has been designed to be shipped, uh, distributed in, into binaries, docker images. So, uh, people realize, okay, like definitely if I have secrets in code, it it, it's gonna be super easy for an attacker to find it.
So it becomes a strong vulnerability. And I think now we are at the stage where even like where places where we sold it was safe, like, uh, especially on the laptop of data droppers in our environment, viable, you have like, especially on all these, all the vibe colors and even devers, you have so many secrets sitting on, on the laptop and on, on places where you stay. It's, it's, um, I think I'm safe.
It's not that bad, but right now with like all the AI agent and all the, the open doors and the, all the stipulation attacks we have, even these places where we sold like, your, your identities, your secrets were safe, are not safe anymore. And I think for me, it's one of, uh, the biggest, uh, you know, attack vectors. I see right now it's, you know, the laptop of the developers, uh, because you know, you have so many secrets, you have so many privileges, you have so many AI agents getting access to, to data sources.
It's, it's, uh, it's a crazy, it's a treasure of our for attackers to, to just see them. And, and the issue right now, it's also what I was saying at the beginning is like now you have people that are untrained, that are non-developers, that are beginning to code, that are beginning to get secret. They're beginning to launch applications.
So it's just expanding like the threats for company at, at the pace, um, which is, which is very hard. And that, that they don't have the current security tools to secure right now because nobody has thought that, like, yeah, the, the, the person at the marketing was going to be, uh, now installing software, building software, having secrets, having a database, and, and yeah, it's, it's a tall new, um, new domain and new attack surface to, uh, to defend for our companies right now. All right.
Well folks, you heard it here. If you think your secrets are safe, well, thank again. Hey, Eric, thanks for being on the show.
Thanks, Mike. All right. And back to you guys in the studio.