Live data from Hacker News

Google to buy Wiz for $32B

reuters.com

721–730 of 951 posts

Re: Google to buy Wiz for $32B

#721

Earlier quoted context omitted.

This is wild to me. As someone in security, Wiz is definitely one of the whales.

In your opinion, are they a whale because they make a great product... or just have a great marketing/PR/sales team? I am guessing "great product" because I cannot believe that Google cannot just rebuild it themselves (if not a great product).

Wiz is widely considered one of the strongest CNAPP/CSPM products on the market. I haven’t personally tested every single competitor’s solution, but I’ve found Wiz to outperform pan, crowdstrike, and prisma.

To answer your question. Google doesn't acquire Wis because Google can’t build a comparable product themselves. The real driver is that Wiz has already achieved market penetration and trust. Replicating that from scratch would be a massive undertaking, requiring not just a sophisticated product but also the brand credibility, customer relationships, and reputation for reliability. establishing that level of traction and trust is difficult, time-consuming, and expensive. I highly doubt Google would try to build a direct competitor from the ground up when acquiring Wiz allows them to leverage its existing success right away.

Re: Google to buy Wiz for $32B

#722

Earlier quoted context omitted.

kickbacks, may be. I have seen the product. It is not so mossad-y. It fairly straight forward cloud, VM, kubernetes scans. Does it protect stuff? Somewhat. Is it the best product out there - no. Are CISOs happy? CSPM is mostly a checklist item in their bucket to things to do. It depends on what kind of security you are working in. Most of the people in CSPM, CNAPP world have heard their name. It is product built for…

> It is not so mossad-y. Would we (i.e. anyone not in the intelligence space) know how intelligence service-y software would look like ? . Aren't all such organizations trained and designed to be inconspicuous and in places we are unlikely to expect.

Ghidra from the NSA at a glance looks and feels like normal software.

AquaSec is built by an Isreali company and looks and feels much like any other SaaS product.

Re: Google to buy Wiz for $32B

#723

Earlier quoted context omitted.

This is wild to me. As someone in security, Wiz is definitely one of the whales.

Same here, I guess it's the circles you run. I just went to their homepage and I have no idea what they do. I already have CI/CD, code, etc.. "securing" it seems like, use aws secret stores? In other words, their webpage is not telling me anything. Companies like these, always feel like instead of having a useful product, they hired useful networks of people to "spread the word" and sell sell sell to your network. Ap…

Companies have problems securing their workloads. Not just storing secrets. Off the top of my head, I've personally been able to centralize the following with a single tool (instead of gluing together a dozen different providers)

- scan cloud configurations for policy violations - detect and remediate infrastructure misconfigurations - real-time visibility into cloud resource inventories - early detection of issues - container vuln. scanning - runtime anomalous behavior - alerts and correlate security events - compliance mappings - id risky permissions in IAM policies - track changes and configuration drift over time - implement zero-trust policies across microservices - eforce network seg in containerized environments - run security checks during build and deploy stages - vulnerability assessments on running VMs and containers - policy-as-code for consistent security standards

Re: Google to buy Wiz for $32B

#724

Earlier quoted context omitted.

If you're in security and you haven't at least heard of Wiz, I have doubts about what you actually do. I'm not saying you have to be a CSPM expert, but not even hearing about Wiz, when they are the largest CSPM, is somewhat concerning.

I've heard of Wiz, but would have had a hard time listing out their feature/benefit statement, because I don't work with CSPM tools. I don't think this "I have doubts about what you actually do" line is doing the work you want it to; it may be backfiring on you a bit.

CNAPPs and CSPMs are extremely common tools in cybersecurity. This is my concern. If you're in cyber and don't have knowledge of these things you're either in something insanely niche, in research of some sort, or lack critical knowledge that you should have. There's a big responsibility as a security practitioner to stay up to date on new tools and techniques. CNAPP and CSPM is not some new thing that was invented last year. It's been around for a decade.

Re: Google to buy Wiz for $32B

#725

Earlier quoted context omitted.

Google's whole business for the last 20 years has been buying, growing, and profiting handsomely from acquisitions.

And Apple on an almost 20 years old product, and Microsoft through its enterprise users, like 2 decades ago...Think about it Nvidia in 20 years is still just doing just very fast matrix calculations and idk Toyota is still making hybrids. This assumption that a tech company is going to keep reinventing or inventing new wheels all the time has very little evidence in human history, while the opposite one, the many gre…

NVIdia reinvented the graphics card towards ML with their massive software investment into CUDA, infiniband (acquisition) among other tech needed.

Wiz isn’t a new industry for Google, but adjacent expansion. Not seeing the reinvention remark.

Re: Google to buy Wiz for $32B

#726
post #59
post #7

Imho, and as a xoogler who's been in Google Cloud's ecosystem the past few years, Google Cloud's three big focus areas have been AI (this is an evolution from their historical focus on data, then also analytics), Distributed Cloud (Anthos++) and security (post the Mandiant acquisition). They'll never be able to compete on base infra, given their late entry into the game, lack of presence in certain markets, and the l…

>and security (post the Mandiant acquisition) As a Googler who works in GCP security, security has been a key differentiator for GCP long before the Mandiant acquisition. Google invented BeyondCorp (a primary driver of Zero Trust). Google helped create security keys (U2F, FIDO, Webauthn), and was I think the first major company to adopt them, both for employees, and for consumers. Google was one of the first major co…

I think this is also a good argument for why it is beneficial for society that Chrome stays in Alphabet; Google is good at some things and bad at some things - that people have access to a reasonably safe browser for free should not be underestimated

Re: Google to buy Wiz for $32B

#728
post #59
post #7

Imho, and as a xoogler who's been in Google Cloud's ecosystem the past few years, Google Cloud's three big focus areas have been AI (this is an evolution from their historical focus on data, then also analytics), Distributed Cloud (Anthos++) and security (post the Mandiant acquisition). They'll never be able to compete on base infra, given their late entry into the game, lack of presence in certain markets, and the l…

>and security (post the Mandiant acquisition) As a Googler who works in GCP security, security has been a key differentiator for GCP long before the Mandiant acquisition. Google invented BeyondCorp (a primary driver of Zero Trust). Google helped create security keys (U2F, FIDO, Webauthn), and was I think the first major company to adopt them, both for employees, and for consumers. Google was one of the first major co…

Adding to it: deps.dev, osv.dev, SLSA (all are either free or fully open source) Google has been great contributor to the AppSec and Software Supply Chain community. I just pray daily that the “google graveyard” curse doesn’t touch these important projects.
Post reply on HN