why aren't all 7 resolved? a statement only gets an assessment when the public
record can support or contradict it. opinions and what-ifs never can, and 0 checkable
ones are still open, waiting for their date. predictions held up or didn't;
assertions are supported or contradicted. on every card:
▮▮▮▮▮ certainty ·
▮▮▮▮▮ debate potential. speakers are clickable
Insight
Podjarny: Developer-first security requires building a developer tooling company
“To achieve that, you need to build a developer tooling company, not a security company.”
Insight
Podjarny: Security products require broad stack coverage to deliver real value
“A security person needs breadth. They need, if you solve the security threat, but you only solve it for 50% of my apps, you're not very helpful security. I'm going to need to buy another tool or find another solution for the other 50% because I need to cover a…”
Insight
Podjarny: Containers are the evolution of the app, not the VM
“The industry has been seeing containers as the evolution of the VM. And they've been trying to retrofit VM patching practices onto containers while we saw containers as the evolution of the app.”
Insight
Guy Podjarny: Open source struggles with maintenance and vulnerability tracking
“Open source is not known for being very good at maintenance. So things like the vulnerability database and things like that. They don't really work that well in most cases”
Insight
Protect freemium growth from enterprise demands using structural resource isolation
“It became hard for someone leading both the product that growth aside and the enterprise motion to say, no, no, no, I will put aside this like very large customer's requirement. And I will prioritize this sort of freemium user. Need instead of that. So you hav…”
Insight
Podjarny: DevSecOps practitioners must be software builders, not passive auditors
“A DevSecOps person is very similar to an SRE. They should be a person able to build software build services and help developers successfully find issues and fix them as opposed to an auditor who should be good at finding those issues themselves and doing it.”
Insight
Podjarny: Security must be embedded in the development process to scale
“Security has to be built into the development process because nothing else scales.”