Exploring Security Challenges and Innovations with Gomboc AI’s Ian Amit
With over 25 years in security Ian Amit, CEO and Co-Founder Gomboc AI discusses frustrations with current cloud practices and the impact on DevOps teams. The focus shifts to improving engineering practices through platform engineering and the use of deterministic AI for automating code review. Ian also introduces Gobo.ai, a free tool for code fixing, inviting attendees to try it out.
Transcript
Hey, everyone. We're back here live at Platform Con Day in New York City, part of Platform Con virtual event. Well, this isn't virtual, the rest of the event's virtual, but you know the people you run into.
So I'm standing online for lunch and I say, you know, that looks like Ian, but I'm, and I'm trying to read his, his, uh, tag, but he's in front. So it's one of those parallel line lunch things. And he's a little in front of me, but I don't wanna skip the salad.
Of course not. But I had to skip the salad to, to get a, a, a good angle. But then he tore me.
He said, Alan, anyway, let me introduce you to my friend Ian Amit. I know, I know. If you knew Ian, like I knew Ian.
I first met Ian, I'll tell you when. Yep. I remember was the very first, besides Las Vegas.
Correct. I remember you giving me a ride Back. Yes.
I gave you a ride back. And, and you know, a butterfly flies on that side of the world. I know.
I, I was the, uh, what the heck. The next year as a result of that, I was the wrangler, the for sponsors. Right.
And me and this guy, Jean Kim mm-hmm. Was also on the board that year trying to help make besides, uh, Las Vegas successful. And then Jean says, Hey, you wanna grab dinner tonight?
And I, I went to dinner with Jean and we had about two bottles of wine. And he says, I'm working on this book. I'll show you an early, like, manuscript Right.
And tell you who I, who, who is mm-hmm. Who are the characters based on, well, that book was the Phoenix project, of course. com and everything else that's happened in my life in the last 12 years, 14 years, Is thanks to me, basically.
Yeah. Thank You. You're the butterfly.
Yeah. There you go. I the butterfly on the other side of the world.
That was fla, its wings. So, Ian, Ian, you're a well, well-known legend in the security business. Right.
What are you doing here? Platform. Great question.
So, you know, as you alluded to, you know, my background is in security. That's where I grew up. That's where I spent, you know, over 25 years.
Mm-hmm. Uh, everything from a practitioner hacking, pen testing, red teaming, you name it, I've probably done it in security twice and three times over my last couple of roles were as a ciso. Yes.
So, you know, you just stick around for long enough, you end up at those positions. Mm-hmm. And, and guess what the last, you know, four or five years of that kind of executive roles, I realized that one of the biggest problems that I've ran into, uh, kinda speaking about the butterflies and DevOps and how it came around was were filled with frustration.
Yeah. That, you know, security got to a point where we're really good at pointing out stuff and finding everything that's wrong and fixing some of it. But specifically in cloud environments, the frustration came to fruition when I realized, again, I, I have too much visibility, but I can't really do anything about it when I'm dealing, when I'm trying to fix things, I run into a brick wall that's called DevOps.
Yeah. These guys are overworked. Security is only one of their concerns.
Yep. And, you know, sliding into their schedule, you know, kind of dripping a little bit of, of alerts and tasks, just didn't, you know, it, it was, it's untenable. I can, I'm finding more stuff that they can ever fix.
And in back of my mind, I'm still, you know, hands on. I'm like, look, this is an engineering problem. It's not even a security problem.
These cloud environments are highly codified. Why can't you just automatically fix it? And I was looking around, I was looking around no solutions.
Everything around security was all about alerts and pro and, and automating the process of pushing tickets, I was like, it doesn't matter if you can, you know, push more tickets, that's not gonna solve the problem. You gotta solve the bottleneck. And that's what led me to basically start this.
So under that realization that, you know, we gotta shift truly left mm-hmm. And fix the problem where, where it lives. And on the engineering side, I started Goba.
And that's what we're trying to do. That's what we're actually doing. So that's what I'm doing here.
Got it. We're going to dive more into that. You know, I'm reminded when I still secure as one of the companies I co-founded.
Right. So this is when we thought IDS was ready to go to IPS. I remember that.
Yeah. And to me it was a no-brainer. Right.
Because the fact of the matter is, you know, the average attack, I think I have many bits, but by the time it hit the firewall or passed through, that router went to you. Mm-hmm. You had to make a decision.
Right. It was over already. They were in, they were out.
They were out, they were in, and it was done. Yep. If it was an obvious thing, and back then obvious things were like, code red.
Right. Or, you know, those kinds of worms, why wouldn't you just block it? Why, why not just block, You're walking into dangerous Territory?
So, no, this is, this is the problem. This is my second startup. My first startup back in 2004 Uhhuh.
That's when this was, was In that confluence of IDS versus IPS. Guess what we did? We realized that you had hundreds of rules Yes.
Enabled on the IDS, however, on the IPS. Exactly. Six.
I know. And you know Why I lived the same life. Exactly.
Because there's no confidence. High rate of false positives. Yeah.
And that startup back then was called B Defense. We literally sat on that precipice between IDS and IPS validated their alerts so that we can deal with them on the IPS side. Yeah.
Fast forward 20 years, we have the same situation now. Same. It's same.
The cloud uhhuh, I have hundreds of alerts from my CSPM and C app and all the fancy things that I can buy for a lot of money. A lot of them are false positives still. That's a big part of that Lack confidence and the whole deens desensitization.
Exactly. Exactly. The overworking, the sock worker, except as you mentioned, it's a little worse now in that it's not just confined to the security guy.
Correct. We're pushing it on the DevOp engineer. We're pushing it on the developer.
Correct. Who doesn't necessarily want that aggravation. They just wanna develop, they Want to Yeah.
Deploy stuff. Exactly. Exactly.
So Is platform engineering the answer? I don't know if it's the answer, but it's another milestone in Okay. You know, in the journey it started with DevOps, as you know, and then DevSecOps, right.
And platform engineering in, again, the way that I see it is just another step towards that Correct. Direction. So we started DevOps, DevSecOps, PE is really where it's at these days where everything is, is, you know, kind of embedded together security and operations and the door metrics.
And so yes. It's, it's, you know, this is The proof day. This is the proof, you know, I'm here, I'm meeting, you know, my, my customers where they're at, not just with the product.
Where again, we, we started as a security product. We ended up being a DevOps product Because Great. It's a great Story.
It is. Because I had that understanding that, again, this is not a security problem. Security doesn't have a problem in the cloud.
They can detect whatever they want. It's an engineering problem. It's a bandwidth problem.
It's a knowledge gap problem. Yeah. There's that.
And, and there's also a scalability problem. Exactly. Scalability.
com. Right. And because I, to me anyway, I saw it as, as you scale up that DevOps job mm-hmm.
Mission becomes much, much harder. Mm-hmm. And you can't just say, oh, well, we'll shift left, we'll shift.
Right. We'll, we'll shift more left. We'll keep shifting left.
Eventually you come to the precipice and you, I don't know, you know, this is it. Yeah. Like the movie Wall Street man looks in the precipice and that's when he knows he's a man bud.
You know? But, so you can't just shift left your way out of this. And to me, platform engineering is instead of just putting it on a developer, instead of the security guy banging his head on the wall until his head or the wall gets soft.
Right. Can we pre-game it? Can we pre engineer it A hundred percent So that it, it is finally built and not bolted on.
It is. It is. And that's exactly the approach that we're taking.
As I mentioned before, we're meeting our audience where they're at. Mm-hmm. Not just here physically in New York, in platform engineering with our, you know, with our audience, the engineers, but also with a product.
We don't open tickets. We're done with tickets. The world has enough tickets.
We're the world's got enough tickets. We're opening prs. Here's the fix.
I did the work for you, by the way. I'm not taking your job. I did that work for you so that you can free yourself up to deal with architecture, with functionality, the toil, the things you're supposed to do.
Exactly. The toil goes away. The knowledge gap gets closed in a PR and even further left in your ID as you develop, as you vibe code.
Right. And ta you know, and get, get, and you know, what you ask is, is platform engineering the answer, I'm, I'm not sure you know, what next up is going to be, you know, this whole IAC thing, this whole deployment thing is gonna move completely to the developer side because DevOps is gonna go away, right. Because it's fully democratized.
You know, you're gonna have copilots and, and, and cursors and duos and things like that, generating the environment that the developer wants to support the application that they're building. But again, the problem right now with those gen AI tools is that the environments they create aren't really grounded in reality. They're generative.
And that's, But they'll get better. They'll get better. They'll get better.
I Agree. They'll, they'll get better. But as long as they're not deterministic.
Right. And this is what kind of we set ourselves apart. We're using deterministic AI rather than generative the ai, We, I know this is live, but we literally RTFM for the developer, for the engineer based on the cloud documentation, based on the IAC, based on the security policies and the general DevOps policies, including finops included optimization.
We align those IAC platform that the, those IAC templates to what you actually need to accomplish or to the, the Constraints. And where does this live, Ian? So This lives either in your ID or in your git pipelines, in your DevOps pipelines, where it should live as a reviewer that produces those remediations.
And, and I mean, it's not like a person reviewing it, it's a process automated. No, It's a, it's a fully automated process. You know, you don't have to wait for someone to review it.
It gets done within seconds. I love this. All you have to do is again, you can either vibe code it, or you can, you can manually code it or use your existing code.
The second you introduce us, we come in, we review and we provide those remediations, those fixes. Nothing is done automatically. So you still have full control.
Mm-hmm. Just like a DevOps architect should have someone, you know, instead of of it being a junior DevOps engineer, it's us. Comes up with a pr, fully explained, fully reasoned, fully documented, here's what we're doing, why we're doing it, here's the gaps.
We're closing fully contextualized. Again, this is not template based. This is not paved roads as much as a lot of paved roads.
Mm-hmm. We're paving the roads. Right.
We're not forcing you to, oh, you have to go to get from here to here. You have to go from here to here to here, to here to here. That's paved roads.
I just wanna go from A to B. We'll pave the road for you. We'll provide the specific code that supports what you are trying to accomplish with the combination of meeting all the security requirements, all the policies that your management set.
Bam. There's the code. Review it.
If you like it, merge it. Great. If you don't make some modifications, that's it.
Like I said, we're meeting the engineers where they're at. No tickets. What About scalability here?
Easy. We're operating at the code level. So it's, that's it.
It's happening on, its it's, it's happening as So there is no backlog. Exactly. There's no backlog.
I'm not bound by the scalability of your, your cloud platforms. Even better, you know, at code you can describe an environment using five 10 resources that might show up. It's thousands of resources in your cloud environment.
That's exactly the scalability. We're operating at the code level. We're making sure that that is done precisely and correctly so that your actual deployments are going to be precise and correct.
Let me ask another question here. It lives in my, it could live in my GI pipeline. Correct.
Or as you say in the IDE, depending what IDEI use, I guess. Sure. But is it sort of an agent that you're doing here and it's talking to your mothership out here?
Is it To a degree, yes. So obviously we, we enforce the, or deploy the deterministic AI in a localized fashion on, on your end. And I, I can probably kind of preempt what you're asking.
No, we don't really need your code. I'm not learning from it. This is a big difference between generative AI and theistic ai.
I don't need to learn from other people's mistake to push them into your code. Right. That's how five kinda works.
Yeah. So yes, it does live in your localized environment. And yes, it does speak with the mothership.
The mothership typically, you know, provides the constraints. It provides the policies. So, you know, if you're working for an organiza or an organization that wants to meet NIST CSF or CIS benchmarks or AWS, well architected whatever policy it is that lives in the mothership, okay.
That Gets applied to your localized version of your code. That's where the fixes are being applied back to your Git environment. So yes, it is a SaaS product, right?
It's very lightweight. Uh, it is operating in, in sort of an agent AI fashion, whereas it's, you know, it mimics the behavior of an agent of Sure. A developer.
And hence the integration. We're almost outta time. But what, what's the website?
ai. ai. We've Just recently released a community edition, so Oh really?
Okay. Go check it out. Go Check it out.
If you go to docs dot Go box ai, you'll see the community edition, uh, sign up. It's completely free. We don't ask for anything, no strings attached.
Uh, the only limitation is that it only operates on Terraform Code in GitHub. It's a GitHub app. So again, you can just deploy it, fix your code, experience it, and if you like it, you know, we can keep talking.
I love it. Ian, it's a pleasure meeting you as always. It's too, Too long.
Absolutely. I love the karma. All right.
Goba ai. Correct. My friend Ian o meets company.
Check it out. We're live in New York. We'll be back in just a moment.