Live data from Hacker News

Google to buy Wiz for $32B

reuters.com

691–700 of 951 posts

Re: Google to buy Wiz for $32B

#691

Earlier quoted context omitted.

Mossad aren't the guys doing cyber ops in Israel. They're suave arsim (how else can you blend in Beirut or Tehran). Also, if you've worked with Israeli government cybersecurity teams, they aren't much different in caliber from the kind you'd find at the NSA, GCHQ, or Netherlands.

I think you just watched Asi Cohen skit https://youtu.be/bN-en_7KGT8?si=xqhHaa9lBXpjntEq

I actually didn't see this before, but that is absolute gold - Asi Cohen is a national treasure (and absolutely a suave arsim XD)

Re: Google to buy Wiz for $32B

#692

Earlier quoted context omitted.

These companies are the closest you can get to a legal mafia, they are effectively charging companies around the world to keep them "safe". In other words, a job that is traditionally considered to be a basic service of the government is now being privatized by people that nobody knows if we can really trust.

Big difference The mafia charges protection from itself, here the bad actors are out there and wiz help you protect from them. Wiz selling doors with appropriate locks for your bussines.

[deleted]

Re: Google to buy Wiz for $32B

#693
post #541
post #59

Earlier quoted context omitted.

>and security (post the Mandiant acquisition) As a Googler who works in GCP security, security has been a key differentiator for GCP long before the Mandiant acquisition. Google invented BeyondCorp (a primary driver of Zero Trust). Google helped create security keys (U2F, FIDO, Webauthn), and was I think the first major company to adopt them, both for employees, and for consumers. Google was one of the first major co…

Having previously used AWS, I would also say that GCP IAM is much better. Yes, it's a lot less flexible than AWS IAM, but complicated IAM policies with conditions and stuff can be really hard to reason about. Disclosure: my thoughts are my own.

The best way to use AWS IAM policies is to not use them at all.

AWS allows to use multiple accounts easily, and accounts are (by default) completely isolated from each other. That's actually how services work internally at AWS, it's not uncommon for a service to have hundreds of AWS accounts (one for each region multipled by the number of environments).

It's not so easy with GCP.

Re: Google to buy Wiz for $32B

#694
post #39

Earlier quoted context omitted.

I can't help feel like this will be rolled into GCP and quickly lose support for Azure and AWS and then just die. That's a lot of money to spend to kill off a business.

that would immediately shed half the value of the company and Google would need to book a huge loss e.g. half of Fortune 100 use Wiz and I assure you most of them do not use GCP (or do not use only GCP)

I would think the majority of f100 is multi cloud and absolutely uses GCP for at least some workloads.

Re: Google to buy Wiz for $32B

#695

Earlier quoted context omitted.

How dare the founders be born in a country!

You are saying this as if the founder is a normal civilian. The guy served in unit 8200 and 81 around the beginning of the 2000s(Second Intifada, first g a z a war, if not more), and overstayed his mandatory service. This isn't a normal company, just like every Israeli security "startup" with founders coming from idf intelligence units. Even ignoring this, 32b for such a company just doesn't make sense.

Correction, all co-founders and a lot of staff come from unit 8200 Typical Israeli security "startup".

Re: Google to buy Wiz for $32B

#696
post #33

Earlier quoted context omitted.

I can't help feel like this will be rolled into GCP and quickly lose support for Azure and AWS and then just die. That's a lot of money to spend to kill off a business.

GCP has been doing more multi cloud stuff lately though: Anthos for K8s in other clouds, BigQuery Omni for bigquery in other clouds

I rolled out their "workloads for AWS" stuff recently, it was pretty slick to be able to have AWS IAM roles just translate to GCP roles. You don't have to run your own CA like you do for AWS Anywhere.

Re: Google to buy Wiz for $32B

#697

Earlier quoted context omitted.

most people here are also in security and still haven't heard. It's more likely backroom kickbacks (and/or mossad) than invisible unicorn.

If a security firm could blackmail Google, what would that look like?

What could possibly be worth 36 billion? That we don't already know?

Re: Google to buy Wiz for $32B

#698

Earlier quoted context omitted.

I vaguely remember this hot second you refer to. What is the HN equivalent where those conversations are happening today?

Lobste.rs for technical stuff. But most security related conversations by security SMEs aren't happening online anymore. We have specific user conferences and regional user groups now.

Cool, any in central Louisiana? Poland? That'll teach the AI!

Re: Google to buy Wiz for $32B

#699
post #392
post #375

Earlier quoted context omitted.

Unless you're talking about some specific Wiz customer contracts, how do you know? AFAIK, there are no explicit laws forbidding that. Maybe you could share what law you think this would be breaking?

OP mentioned training AI on customer data GDPR, CCPA, HIPAA, etc, as Google has no way of knowing which data they will train on, add to that copyright and that's just off the top of my head cloud contract obligations are also pretty clear about customer data. furthermore it would be bad engineering and security if Wiz had actual direct access to customer data, versus having their code having access to said data. That…

Read through the Wiz MSA [0] at section 6 which discusses “Customer Data” and among other things specifically asks Customer not to send HIPAA data (perhaps to sidestep the issue you just raised) and concludes with this:

Customer hereby grants to Wiz a non-exclusive, worldwide, royalty-free right to use Customer Data to provide the Services and perform its obligations under this Agreement.

Or if reading terse legal documents isn’t your thing, go ahead and just read through Wiz’s own blog post about how their scanner works, which confirms they have full, direct access to customer EBS volume snapshots in the default “full SaaS” deployment model. [1]

Your point that due diligence would have taken issue with this might not be grounded in Google’s reality.

0: https://wiz.pactsafe.io/legal#wiz-subscription-agreement

1: https://www.wiz.io/blog/the-wiz-approach-to-agentless-scanni...

Re: Google to buy Wiz for $32B

#700
post #108
post #102

I'm surprised this acquisition didn't happen sooner. The first time I used Wiz I knew a big cloud provider would be snatching them up at some point. Why? Because every enterprise that decides to use cloud providers then needs to find someone to keep that cloud environment safe. But also, and may more important, you get to see everyones cloud usage, across all providers, with a high level of permissions. Said differen…

If you'd be so kind for those of us that haven't touched cloud in 5/10 years, what is Wiz? from reading the google announcement: solving the supply chain hybrid cloud security issues? I could google I know but you seem to know what you are talking about, so if you'd be so kind. :)

If you don't mind a short blog post I run though the capabilities of something like Wiz: https://rakkhi.substack.com/p/choosing-the-best-cloud-native...
Post reply on HN