Raj Rajamani, CrowdStrike | RSA Conference 2023
Raj joins TechStrong TV to discuss CrowdStrike’s new XDR offering for ChromeOS and the latest trends in cloud security.
Transcript
This is texturung TV. Hi everyone. Welcome back.
Hey, this is our last interview for RSA 2023. Save some of the best for last. I want to introduce you to Ross Raj Raja Johnny.
God damn money rajamani. Raj rajamani no mistakes, right? That's what happens when you're on live TV Rogers would crowdstrike and he is going to be talking to us a little bit.
Hey Raj, welcome to Tech strong TV. Thanks Helen. Thanks for having me.
My pleasure to have you on here. So, you know what before we even get into crowdstrike or what's going on here. Let's hear a little bit about you.
I'm a dad. I have two kids and a dog me too. The house girls a boy a girl are you and the dog is a girl too.
I have a girl that I have two sons. Yeah, the girls always to remind us how much smarter women are. I always say God gives you what you can handle and what it would have eaten me alive because They're just inherently.
Smart. Yeah, I agree with you ended that a husband. What about a crowdstrike?
What do you do there? I've been a products. I look very closely with our customers and our engineering teams to build the best products that we can to keep them safe and secure our mission is to stop breaches, right?
Short and simple, right? Of course You know, the Road to Perdition is paved with the best of intentions and it's not it may sound simple, but it's not simple. I want to jump into.
Some of the things going on at crowdstrike, but just before we do I want to get out of the way. Our audience tends to be very technical. They're cyber security developers devops Cloud native folks and 99% of them are familiar with crowdstrike.
com. Absolutely. Okay, I want to talk about a few things.
First of all, look as I said, you're our last interview of RSA. It's been an amazing. Show 40 some odd thousand people a lot of a lot of excitement a lot of Buzz.
Crouch I was on the floor for a short time. Hmm. I haven't been around that many people in a long time and Christ.
I had a very big presence there. You guys also made kind of a big announcement here. Yes share with us if you can so be announced the beta as well as soon availability of our Insight xdr on Chrome OS and that's a pretty big expansion because many of our large accounts and customers are starting to use Chromebooks for certain types of functions.
These may be their contact centers Frontline workers certain roles that do not really need all the dynamic environment of a full windows or a Mac laptop. It also reduces their operational cost now, I don't know and if you know you you have tracked the history of Chrome OS but what Google did was actually create a very secure by Design operating system where it is inherently very difficult for attackers to kind of inject or insert a piece of malware into the operating system. And of course they did that by kind of really controlling.
It's almost like an iOS model where everything is tightly locked down. You have the Chrome browser and you have extensions and applications. But you know for the longest time, it was relegated to the educational market and now Are starting to see it become more mainstream with large Enterprises starting to use it and they all came to us and said hey, we want this secured and we want the same level of EDR and xdr capabilities that you have on Chrome OS as well.
So we work very closely with Google and we announced it. It'll become available in June. I guess it begs the obvious question if it was so locked down.
Why I need security great question. How frequently do you find yourself Alan going to hotel a restaurant and Airport Lobby and connecting to a Wi-Fi Gateway. Do you get emails today?
Do you get emails with fishing links that you may click on? Do you think if you're an Enterprise you may have You know the occasional user signing up for a new SAS based service because they find it convenient and you want to know all the different applications including SAS applications that you're in tech company maybe using do you want to protect them against fishing attacks and man in the middle then they connect to the wrong Wi-Fi Gateway. those are all things that the operating system does not protect against that's what we can actually get you visibility detection and protection against so I'm not an expert on Chrome OS or the security built-in, but my understanding was that you the software the whole OS including the browser was in some sort of sandbox that didn't have connectivity.
No, you can totally connect to the internet. I know you can connect to the internet but you didn't have acts like let's say for email. Let's say you using Gmail.
Yes. So I click on a link in Gmail opens. It spawns a new tab.
And that looks just like a bank account the bank website and ask you for the username and password. Okay. So from a fishing reactive.
Yeah, I could see that yeah, you know to me this is a kid, too. Phone security right and and I'm not gonna mention names but I have I have I'm in the security visit. I have security software on my phone, but a lot of non-security people who I mentioned that you say, what are you doing?
It's secure you don't need that stuff. Well, the fact is I I buy it and it goes across 12 devices. Anyway, which there would Jamaican but there there is that that is a perfect example right because You know 75% of fishing emails are so badly right and you can spot them pretty easily.
Yeah. But they get better every day, especially with Chad GPT. I'm sure they'll get even more remarkably better.
But the whole point again, I just want to time how long it took for us to get to the AI catchy part of this interview because I've been timing of all week, but you're right. Okay, it was average. Oh man.
I didn't come out of the gate with it. But anyway, but you're right that is gonna be a a help to these people who write write these emails because I mean I use it. I've been writing I wrote a job description for a social media manager position the other day and blew me away how good it was like only imagine how it would do for emails.
But yeah fishing is an obvious example. I guess this is in partnership with Google. Yes.
So will we see it like, you know when you buy a Dell laptop it comes with some AV on it. They don't call it AV anymore endpoint security. So the beauty Allen is that this does not require us to preload or install an agent on every device.
No, so what happens is Chrome OS Collects all the Telemetry the instrumentation sends it into the Google cloud in the Google. Admin Pages. There is a new place where you can enable the cloud strike integration.
It's literally two one checkbox and one hit the same that's all happening up there. Not even locally on the machine. That's right.
The events the Telemetry gets collected by Google sent into their cloud and their Cloud chested without cloud and we have the full disability as a result. I like that. I like that a lot.
If you don't mind me asking what's the cost of this? So B cell to the Enterprises and we have a price on our excellent Enterprise. Yes pricing thing.
Yes. This is not aimed at consumer. No, no.
Too bad. But yeah, I I mean I could understand that and and you mentioned it was in bed on the right beta right now. It's coming out in beta right now and we will make a generally available in June.
That's it. That's pretty firm date. Yes.
Okay. Well hold you do that. Yeah.
So get you must have done these studies what percentage of Chrome OS devices are in Enterprises. You think I think it's very low penetration, but there is increasing awareness and creasing motivation on the part of Enterprises to at least use this for certain types of roles. Now, I would be hard-pressed to find a large Enterprise that's using across the board everywhere.
I don't think that's going to happen. But you may find certain roles like for instance. If you have a retail store, maybe they use it for certain types of you know, quick internet browsing or contact centers is a classic example.
You just need to pull a few again details from a database on a web browser to kind of help a customer. Those are all things that you can completely and entirely absolutely meet with the Chrome OS it's maybe before your time but you know the old wise terminals remember the old of course remember device terminals. Yes.
That's all you really needed. Yeah, right for a lot of stuff like that. And I look we're not a big Enterprise really have you know, 40 people or so, but I find you know, I have all these people when we hire them.
Do you need a laptop? Yeah, I need a laptop. All right Mac windows.
Hey. And I'm like, okay, we'll get you you know, let's see what we have in in the office and they're like, oh no, I I need a Mac with that with an M2 Pro or M2 Max 16 gigs of RAM, and I'm like, wait a second 500 bucks. At best and for what for your email and some web browsing or slack, you know, I I don't see it, right that's not happening.
99 you're happy. And and by the way, the Mac Air is a hot as heck to machines. They don't you know, if I get your Chromebook for $300, that's a lot of money to save.
So I I get them want the motivation. Yes. Yeah.
I think some people may feel like, you know second class citizens. That they don't have a Mac or even a good Windows machine, but interesting nevertheless. So that'll be available in June.
Is there a specific place on crab strike or the website where people can find out just go to crowd straight? Just go to crowdstrike? Yes.
Okay. Let's let's kind of go bigger picture if we can. With regarding crowdstrike and zetsina.
Yes, Cena. Talk to me about this. So I lead a portfolio which includes Cloud security and we are extending our mission and we have been doing this for quite a while and it's one of the best gets Kept Secrets of the cloud security industry that we are protecting some of the most well-known brands that every one of us here is using every day and we are protecting them on their endpoints, which is their laptops.
They're protecting them on their chromos very soon. We're protecting them in the cloud right in the cloud. Some of the challenges are very different and Alan I'm sure you've heard of various companies that have done remarkably well over the last couple of years by solving some very important problems of cloud Security in a very elegant and neat fashion, but interestingly enough in the last three months.
Two of the most prominent ones have come out and said hey. While we've solve this problem, it's not the full set of problems that are other things that we also need to solve and we are going to partner and the most notable example, is that of this partnering with Sentinel one? So this does what is called cspm and they are partnering with Sentinel one for runtime protection and agent-based security and we are looking at it and saying wow that's interesting because this is exactly what we've been telling our customers very successfully for the last few years.
And if you look at many of the largest Brands, they're protecting their entire spectrum of cloud security needs with a single platform, which is a falcon platform. I love it. How do people engage with that?
They engage with that in many different ways, right? So depending and when I said full spectrum Alan what I meant for us from the time developers have finished their coding and want to deploy to the cloud. Okay, there are there is an increasing awareness of supply chain attacks, especially in the cloud software, which is largely powered by open source, people are very very worried these days after the sonicfall after three CX and various other Supply the White House put out a freaking bulletin.
Okay? Yeah. It's not for good reason.
But yeah, I mean just come from kubecon. Yeah, it was a bit of a topic there, right? Yeah.
So what's happened? What we do is we integrate with all the code repositories. In fact 16 of them.
So that before the court gets deployed into production. We can actually scan it for back doors for malware for vulnerabilities for hidden secrets and so on. So when you say you integrate with these repositories these are component repositories like amazing or something like that so your scanning the components that I finished yes or you're skinning the darker repository for container yes images.
Yeah the darker depositories the GitHub the Amazon you are you're you're doing it in Gitopsis. Yes, we call it. Right so you're doing it as like part of a git Ops type of thing.
Yes. Absolutely. And we are making sure that if we find the back doors the hidden secrets the vulnerabilities, we actually prevented from even getting deployed.
Are you scanning to see so like one of the most popular, you know, darker Repository? kind of tricks is you know, the Name a popular function that you would put into container. There may be 12 different versions of it in a DACA repo and then they'll upload one that maybe is off by one letter or nothing like that.
Are you testing for that as well? So again what we test for Island Road itself. Yeah, especially is the vulnerabilities if we can find any known backdoors, we don't necessarily check if one of the versions is off from a certain, you know, theoretically if it was You know a rogue version or a rogue name container and it was delivering some you know, payload your skin would pick that up.
Anyway, yes, absolutely. Right? So we start there from the you know from the time developers are ready to deploy.
We also protect we look for misconfigurations. So if you are configuring out if you're moving this into production. Making sure all the different services.
Are configured properly we make sure there are no vulnerabilities in your running environment. We protect you against runtime attacks. And we also protect you against identity theft and lateral movement type of attacks.
So that for us constitutes the entire spectrum of cloud security needs and we are the only vendor Alan that can provide all of this functionality from a single platform. I like it. excellent Roger's last question beyond all that impressions of The people here are they the right people for crowdstrike?
Are they? You know, sometimes you go to a showing there's more people giving you resumes then they're giving you questions about your product other times. They're like adult trick or treaters that are looking for swag and swag would have been your impressions about I say technology really happy to be back in person amazing, whether normally as you know, how to say little earlier in the year and yes here, it's been perfect even two weeks ago.
It was a little chilly here. So I'm just having rainy for months here. Yeah.
Well the good news is from this sign you you're on this side of it. You can't see it. But next year's May 6th to the night.
So should be even nicer. Yes, and overall the audience has been great engagement has been terrific we met with so many customers probably had at least 50 meetings in the last four days. That's great.
Of course many of them are existing customers coming and talking to us. It's I don't really yeah. So convenient to get it all done here actually.
Hey, I want to thank you. Thanks for having me. All right.
com our last interview here at RSA 2023. We hope you've enjoyed the last three or four days of interviews again, a quick reminder. Our devsecops event that took place on Monday here at Moscone.
We are replaying as a virtual event June 1st. Don't miss that. You can sign up for it on any of our websites.
Until next time and I think next time we'll be the open source Summit in Vancouver. Right from Linux foundation and I think it's May 8th or something this Alan Shimmel. We're out of here.





