Why Developers Won’t Be Replaced by AI with Snyk’s Danny Allan
Danny speaks with Alan about how AI empowers developers to focus on high-impact projects, helps companies retain top talent and strengthens secure development practices without compromise.
Transcript
This is Techron tv. Hi everyone. Welcome back here to Techron tv.
My next guest is Danny Allen, chief Technology Officer is ny, his friends call him Bobby r actually, Bobby Y's an old name you may not remember Bobby Orr, but anyway. Hey Danny. Welcome to Text Drug tv.
You've got some explaining to do. I do, Alan, I do remember Bobby Orr. He's a hockey player from Boston where I live now.
Um, and I love him because I've been playing hockey now for 45 years, but, uh, this past Friday I sometimes happened. It's not the first time I got a stick in the face. And so now I'm sporting a, a nice bright shiner.
A likely story, but a good story. Nevertheless, you know, there's been great hockey players over the years. I had, I grew up in Long Island during the Islanders heyday and I had a chance to meet most of the Islanders back then.
But, you know, for me, Bobby y always epitomized the, the grace of gracefulness of hockey. Right. He was like a ballet player out there, but he tough his nails too.
Right. And, uh, ah, those were great years. Anyway, I, I'm sorry you took the stick to the face.
It could have been worse as they always say. So. And I know it won't make you, it won't make you stop playing hockey, so more power to you, man.
Absolutely not. It's a great sport. Absolutely not.
Absolutely. Alright, Danny, when you're not playing ho Hockey, you're the Chief Technology Officer at ny. Give us a little bit of your background and then give us some of the sneak background.
Sure, yeah. I've been in security space for a very long time. In fact, application security.
I've been interacting and around the world for 25 years now. I started at a company called watchfire, which um sure started up in Ottawa. I was playing hockey up there as well 25 years ago.
Mm-hmm. But Watchfire acquired a company called Sanctum and they had a dynamic application security testing tool called OP Scan. And so for seven years, um, did a lot of application security.
That company ended up being purchased by IBM. So I, I did three years at IBM, but a lot of time over the last 25 years in and around security, starting with dynamic application security testing while I, I was working at Watchfire and, and we acquired this company sanctum. There's an individual there named Guy P Journey, who I became very good friends with 20 years ago.
And he is the founder of NY Guy po. Sure. Guyo.
So fast forward and 20 years later, I've had interactions with him continuously over the last 20 years, but eventually he convinced me to come over. And so, yes, now I'm Chief Technology Officer at sny and back to doing what I love, which is helping make software more secure. And that's that Sneaks mission in life.
Fantastic. That's great. It's what a great story.
You know, I'm also involved in the, in the, uh, remediation vulnerabilities space. So I started a company in Colorado in 2001 called Still Secure. Mm-hmm.
In 2003, we came out with our first vulnerability product called van Vulnerability Assessment of Management. It was, it was Nessus Scanner under the hoods, but we were writing our own Nale scripts back then. And then of course, you know, when Nessus stopped being open source, you could, you know, you could still write your own nozzles and, and stuff like that.
Um, and we did nac, which to me was always sort of a, I don't know, it was in our growth of vulnerability. 'cause what we were doing, we were testing devices before they got on the network for configuration of vulnerabilities. It's different, you know, same, same mission, different tool.
Uh, so I've also been in it that long and, and it certainly, I mean, NY brought a whole new, they brought AppSec to vulnerability management in my mind. Right. Because for a while there, we, you know, you had your vulnerability management and then you had your AppSec scanners and so forth.
Yeah. It's now you starting Different in my mind. Come together.
Go ahead. Yeah. What's different in my mind is BA Back, Nessus was an amazing tool, actually, Nessus and Melo and, and they were tools used by security practitioners.
And what snyk did differently is rather than building a tool for security practitioners, they said, no, no. They build Different develop developers, Let it build it for developers. Shift left.
Yeah. Build it into the pipeline and make it really easy for developers to use. And it's been an amazing journey because of that.
You know, it's funny. So for the last 10 years at RSA network, every Monday of RSA week, we always in partnership with them, and the Moscone Center put on our DevSecOps event 10 years ago, you could imagine what I had trying to bring the DevOps people and the security people together, they hated each other. Security people said the developers didn't care about security.
The developers had the security people, just the people who say no, and they're difficult. And it was true. And Snyk has sponsored this in the past.
They've been sponsors, they've spoken at our event, um, it was through Sneak really was one of the very first ones that said, wait a second, we could have chocolate in the peanut butter here. Right? We, we, we could make a security tool for developers that'll allow them to make higher quality code.
We'll stay away from the security word even higher quality code. And it was a game changer. A game changer.
Um, you know, we've learned a lot of lessons, as has sny, I've actually spoken to Guy this very, uh, subject, we've learned things along the way, right? Developers don't necessarily want to be security professionals. They do want to develop quality code, right?
Security people grudgingly acknowledge this, right? That developers wanna do it now, of course, two years, whatever it is, two and a half years ago, everything changes with, with, uh, chat GPT and AI and so forth. And, and now we're hearing, you know, woe is me.
We're gonna replace developers with ai. We don't hear that we're gonna replace security people with ai. So, which leads me to leave.
Maybe the security people are behind it, but, you know, what do you think about that? Daddy, you've been around this forever in the day now, are we at a point where we're gonna replace developers with ai? And what does that mean for security?
Yeah, I don't think there's a chance, Alan, that we're gonna replace developers with ai. And I say that, I always use the analogy of autopilots because, you know, the first flight was early 19 hundreds, early at 19 hundreds being 1905 or oh six. Autopilot was actually developed in 1912.
We've had autopilot for a hundred years and we still have pilots in the cockpit. I do think that the role of developers will change. So right now, developers primarily, I shouldn't say primarily, maybe 20% of their time is writing code.
And the other 80% is doing research and evaluation. I think they'll become more prompt engineers over time and, and their, their daily activities will change. But there's no way we're getting rid of developers and anyone who says that doesn't interact with, with development and developers on a daily basis, is my opinion.
No. So I think it's a little more nuanced than that. Right.
Okay. And I've seen this, so you look at like, recent announcements from Salesforce, you know, recently was Dreamforce and then, what did they call it? Agent Force or whatever, where they're putting out all these agents and you know, what would they believe?
And then, you know, Zuckerberg, mark Zuckerberg from Meta said that this year they think that a lot of mid-level developer jobs may be lost to ai. Uh, the Salesforce people said it was a lot of lower level developer jobs that'll be lost to ai. No one ever says, sort of master developers, your highest level developers are gonna be replaced by ai.
'cause those people will learn to harness ai Yeah. And be 10 x more effective. Yeah.
I tend to think of it kind of two different ways. One is the, the lower level technology, the front end. If we talk about the front end, it's more likely that AI is gonna be super helpful in generating the next web interface for me.
Like create the table, do the thing that it needs to do, but it's not going to be nearly as effective at back end of things. Like the way that we're writing software, Alan. And as you might imagine, we're doing static application security testing using AI itself.
That's super complex. Symbolic regression analysis, AI's not gonna pick up and, and do that. So it's gonna be helpful in the front end, but it's not gonna be nearly as effective in the back end.
And it's still not gonna do everything. It's still going to require someone to be there as the guardrails for the software as it's being built. Yeah.
So, you know, I'm reminded, I I remember doing an interview with, um, I'm, I'm drawing a blank on his name. It's one of the, Luke, Luke, Luke Keens, one of the founders of Puppet. Okay.
com 10, 11 years ago. And he said in 2035, software will write software. I'm not saying he's wrong, and he, it may even be before 2035, but I, and I don't think you are not disagreeing with that.
You are not disagreeing with that. That's kind of a double negative. I think we both agree with that, but I think the issue is it won't be exclusively software writing software.
There will be, yeah, I would agree with that. Humans behind it. And, but here's the thing.
You know, we've both been in technology and in security a long time. My advice, and I talk to young people all the time, my advice is you can't bury your head in the sand and make believe this is just a passing fad. 'cause it's not.
Number two, you can't fear it and say, well, I'm gonna go find something else to do. Right? I'm not gonna be a software developer anymore.
I'm gonna go be, I don't know, an air conditioning, because the AI will never install h HVAC systems, right? I mean, um, no, you've gotta embrace change. You've gotta embrace technology.
You need to leverage because the people who leverage, you know, I, I do YouTube shorts, I do a lot of videos like this, and we take some and we make short, we make sure it's out of a lot of them, you know, to get more views with it. I did want about a month ago, about Mark Cuban said the first trillionaire will be the person who figures out a novel way of leveraging ai, not something we're doing now, now. And that, so it won't be Elon Musk, it won't be Jeff Bezos, it won't be Mark Cuban.
It won't be Guy po. But it'll be someone who uses AI in a way that just, we haven't quite thought of yet. 2 million views because people are interested, I guess, in trillionaire stuff.
But to me that's, that's really the, the key here, right? That is the key is leveraging it. The key.
Yeah. That's where, that's where the industry is going. And I think the, the individuals that embrace AI and figure out how to use it, those are the ones, as you say, that will become the trillionaires.
I don't think the monies in the models or even in the GPUs, I think it's how do you take AI and use it in a novel way that completely and radically transforms an existing industry or creates a new industry. And we're doing that. We're proving this actually at Snyk.
We, we have a hundred million dollars product. We've announced that publicly. That is AI driven.
Like I think the value that we drive as an industry is going to come from AI within the software that we're building. I, I agree with you. You know, the, there's the old saying about the gold Rush, right?
It was the people who sold picks and shovels who really made the money and, um, not, not the people. You, because, you know, a few people made a lot of money finding gold, but there were many who bought picks and shovels that did find gold. And I think this is the same thing here with, with Snyk or, you know, tools that are incorporating AI to become better at their tools.
Now, as I said before, though, security's a bit of a different animal. How do you see AI being used, let's say, in snyk security tools for developers to, to make developers' lives easier, to make better quality software, et cetera? Well, we're using it right now in three very significant ways within the product.
But I'll talk about where it's going. One is, we acquired a company called, uh, deep Code back in 2020. Yes.
That did symbolic regression analysis of the code. And, and essentially what that means, sounds technical, takes the code, converts it into an abstract syntex tria, a symbolic representation of the code that shows the data flow from source through to sync. Um, and then it would say, is it going through sanitizers?
Is it doing all the right things? And it radically transformed the industry, not because it was using ai, but because rather than taking hours to do analysis, it took seconds. And because it took seconds, you could do it as part of a PR checker, like really, really quickly.
And it radically transform static application security testing. So that's one way that it changed the industry. The second is, we're using it now to generate fixes.
So not only are we doing the security analysis, but we are generating the fixes for the vulnerabilities that we find. And it's doing it in reverse order, actually. It's, it's taking that abstract syntex tree and it's generating a secure flow, converting that into code, and then inserting it back into the code.
And, and the reason that's interesting, Alan, is because it's not just like replace these four lines. It's change these two lines and these 10 lines and these five lines and insert this dependency. It's a very complex model.
The third way that we're doing it is around CVEs. As you know, from the security space, there are tens of thousands of CVEs reported every year. Last year was 40,000 CVEs.
And that was about a 40% increase. One of the things that we do within our product, it was hard for us to keep up with all the common vulnerability enumerated issues happening. So what we did is we took an LLM and we said, read the descriptions of what's being submitted to discover which function within that, within that open source component actually is vulnerable so that customers know whether they're coloring that vulnerable function.
And so, again, just making a developer's life easier, whether it's generating a fix, knowing whether the vulnerable function is called. All of these things we're already doing within our platform, but what gets me outta bed in the morning is not what we have done. It's all the opportunities to continue to use AI within the platform to make the developers more productive than they are right now.
So to me, that's now we're crossing into a Gentech ai, right? Yes. Where it's, it's not just the gen ai, you know, writing code or what have you, but having agents that actively go out and do these kinds of things that you're talking about autonomously, right?
Just, yeah. And I think that's where you start getting a blurry line. But go ahead.
It is, and in fact, the generative AI fixes that we're using, we can package those up and make them completely autonomous. So now you have agentic ai and what I expect to see over the next little bit is that by policy, because some organizations will say, you know, use the Agentic AI to fix this class of vulnerability for this type of application or not, or by policy, send it to the AppSec person to review. 'cause I'm not quite comfortable that it's, it's ready to solve that issue.
That's where I think we're gonna see all the innovation happen in the next few years. Absolutely. And you know, it's the same thing I saw in the vulnerability management in NextSpace back in 2003, in 2005.
I saw it in the IDS to ITS kind of thing that went down, you know, around the same time when we start automating remediations, people get a little freaky. I mean, they always want to have a human set of eyes. I, there must be something in human nature that we do that.
Um, but, but yet everyone's phone, I don't have my phone with me. You know, we're updating our phones multiple times a day. Right.
And no one pays attention to that anymore. Go figure. Yeah.
I I think the agentic is gonna come into its own over time as people get comfortable with it. I always say people, you know, I'll turn on self-driving mode in a Tesla, but am I ready to get in a Tesla and tell it to drive me across the country? And no, not quite yet.
Right. So I have to say, we have, so I have electric BMW, but it has like the self-parking and Yep. Scares the hell out of me.
I turn it on and I grab, I hold on it. My knuckles get white. I'm holding that wheel so tight.
Yeah. It, um, it's scary stuff, man. I, I, it's just, I think it's something in human nature about this is control this where I think policy comes into play because some organizations will be more comfortable with saying, for this type of thing, my policy is allow it to be completely autonomous for these types of things.
No, I want a second set of human eyes on it. Um, and so I think that the dev set governance impor, uh, mentality will be super important because by organization, by organization, they'll set the policy on what is allowed and not allowed or what type of agents will be used versus having a human in the loop to verify an action taking place. I love it.
io, I thought it was IO and I didn't want to mess it up. Um, I, I assume you guys will be at RSA this year. We will definitely be at RSA.
It's one of the big conferences of the year for us, because of course it's a security conference. Well, we'll be there all week at, uh, at broadcast Alley. You know, besides putting on the DevSecOps event Monday, we're all week doing live video at broadcast Alley.
Come on down. We should get some makeup in case the black guy's still there. We'll make it go away and, uh, we'll, we'll continue the conversation.
Well, I look forward to it, Alan. It should be a great time. All right, Meg.
Hey, keep playing hockey. Keep doing what you guys do at sncc. Say hello to Guy for me and thank you for coming on today.
Thank you for having me, Alan. I appreciate the conversation. Alrighty.
Danny Allen, chief Technology Officer Snyk and part-time hockey player, talking about AI and developers. We'll be back with more. You're watching Textron Gang.