Earlier quoted context omitted.
8200 is an Israeli spy agency, whose alumni turn up in security companies almost as often as CIA alumni turns up in US newsrooms.
Thank you, didn't know about this rabbit hole. The wikipedia page has a handy list of companies to avoid at all costs: https://en.m.wikipedia.org/wiki/Unit_8200
Google to buy Wiz for $32B
801–810 of 951 posts
Re: Google to buy Wiz for $32B
#802Earlier quoted context omitted.
8200 is an Israeli spy agency, whose alumni turn up in security companies almost as often as CIA alumni turns up in US newsrooms.
Thank you, didn't know about this rabbit hole. The wikipedia page has a handy list of companies to avoid at all costs: https://en.m.wikipedia.org/wiki/Unit_8200
Re: Google to buy Wiz for $32B
#803Earlier quoted context omitted.
I never heard of them until they were purchased for $32 billion.
Thats the kind of a company everyone wants to build in enterprise security. Incognito unicorns. There are many companies like these in security space. Another company I can think of is Rubrik. All these large security companies under the radar success.
https://www.bleepingcomputer.com/news/security/rubrik-rotate...
https://www.bleepingcomputer.com/news/security/rubrik-confir...
This one is straight up embarrassing:
https://techcrunch.com/2019/01/29/rubrik-data-leak/
> The exposed server wasn’t protected with a password, allowing access to anyone who knew where to find the server.
So much about "zero trust", at this point it's nothing but a marketing term and has lost it's true meaning
Re: Google to buy Wiz for $32B
#804Re: Google to buy Wiz for $32B
#805Earlier quoted context omitted.
It is a very legitimate tool. It identifies misconfigurations and vulnerabilities in cloud deployments. Anything from a container with a known-vulnerable package in the manifest to a workload with improper firewall rules.
Isn't this what tool like MEND or Black Duck (formerly Synopses)?
Sysdig, Palo Alto's Prisma Cloud, or a few others compete with Wiz's CNAPP offering. Wiz also strays into some SCA and SCA-alike tooling for containers, code or XDR with their CDR/XDR products log ingest and agents available for response/quarantine.
Re: Google to buy Wiz for $32B
#806Earlier quoted context omitted.
most people here are also in security and still haven't heard. It's more likely backroom kickbacks (and/or mossad) than invisible unicorn.
If you're in security and you haven't at least heard of Wiz, I have doubts about what you actually do. I'm not saying you have to be a CSPM expert, but not even hearing about Wiz, when they are the largest CSPM, is somewhat concerning.
Re: Google to buy Wiz for $32B
#807Earlier quoted context omitted.
When you use a cloud provider to setup a VM, what policies do you apply to it in order to ensure it’s secure? Wiz and other tools in the same space tell you and tracks compliance across your fleet. Idk if wiz does this, but their competitors have “compliance packs” which are preset compliance patterns, IE hipaa, finra, etc. That way you click a button and it tells you every change you need to make to be compliant Edi…
I don't know anything about cloud VMs, but I'm confused about how this is possible. Wouldn't determining whether you are HIPAA complaint depend on auditing all kinds of application details about how information flows through the system and how authentication and authorization are done? How could this be validated statically by looking at cloud VM config? Is Wiz doing some kind of AI magic over your whole codebase? I…
Re: Google to buy Wiz for $32B
#808Re: Google to buy Wiz for $32B
#809Earlier quoted context omitted.
Don't conflate skepticism or criticism of Israel with skepticism or criticism of the Jewish people as a whole.
[flagged]
Sick of this double standard.
Re: Google to buy Wiz for $32B
#810Earlier quoted context omitted.
When you use a cloud provider to setup a VM, what policies do you apply to it in order to ensure it’s secure? Wiz and other tools in the same space tell you and tracks compliance across your fleet. Idk if wiz does this, but their competitors have “compliance packs” which are preset compliance patterns, IE hipaa, finra, etc. That way you click a button and it tells you every change you need to make to be compliant Edi…
But...don't these companies already have cloud security engineers on their payrolls? /s
The problem with the cloud, from a security standpoint is that is it much more complex than a traditional on-premise infrastructure, especially if you go the "managed services" route and have minimal code.