Live data from Hacker News

Google to buy Wiz for $32B

reuters.com

801–810 of 951 posts

Re: Google to buy Wiz for $32B

#801
post #773

Earlier quoted context omitted.

8200 is an Israeli spy agency, whose alumni turn up in security companies almost as often as CIA alumni turns up in US newsrooms.

Thank you, didn't know about this rabbit hole. The wikipedia page has a handy list of companies to avoid at all costs: https://en.m.wikipedia.org/wiki/Unit_8200

https://darknetdiaries.com/transcript/28/

Re: Google to buy Wiz for $32B

#802
post #773

Earlier quoted context omitted.

8200 is an Israeli spy agency, whose alumni turn up in security companies almost as often as CIA alumni turns up in US newsrooms.

Thank you, didn't know about this rabbit hole. The wikipedia page has a handy list of companies to avoid at all costs: https://en.m.wikipedia.org/wiki/Unit_8200

Yea, good luck with that, especially when 8200 alumni are embedded deeply in the vast R&D sites all major US tech giants have in Israel (Apple alone employs thousands in Israel), whether by direct recruitment or by buying Israelis startups.

Re: Google to buy Wiz for $32B

#803

Earlier quoted context omitted.

I never heard of them until they were purchased for $32 billion.

Thats the kind of a company everyone wants to build in enterprise security. Incognito unicorns. There are many companies like these in security space. Another company I can think of is Rubrik. All these large security companies under the radar success.

Rubrik had pretty bad breaches in the past:

https://www.bleepingcomputer.com/news/security/rubrik-rotate...

https://www.bleepingcomputer.com/news/security/rubrik-confir...

This one is straight up embarrassing:

https://techcrunch.com/2019/01/29/rubrik-data-leak/

> The exposed server wasn’t protected with a password, allowing access to anyone who knew where to find the server.

So much about "zero trust", at this point it's nothing but a marketing term and has lost it's true meaning

Re: Google to buy Wiz for $32B

#804
post #789

Earlier quoted context omitted.

[flagged]

I think you might be missing the scale of the destruction and oppression of Palestine by Israel. Just look at what they did to Gaza https://www.bbc.com/news/world-middle-east-20415675

[flagged]

Re: Google to buy Wiz for $32B

#805

Earlier quoted context omitted.

It is a very legitimate tool. It identifies misconfigurations and vulnerabilities in cloud deployments. Anything from a container with a known-vulnerable package in the manifest to a workload with improper firewall rules.

Isn't this what tool like MEND or Black Duck (formerly Synopses)?

Wiz is closer to the CNAPP field instead of the software composition analysis tools you mention, Snyk would fit here for SCA.

Sysdig, Palo Alto's Prisma Cloud, or a few others compete with Wiz's CNAPP offering. Wiz also strays into some SCA and SCA-alike tooling for containers, code or XDR with their CDR/XDR products log ingest and agents available for response/quarantine.

Re: Google to buy Wiz for $32B

#806

Earlier quoted context omitted.

most people here are also in security and still haven't heard. It's more likely backroom kickbacks (and/or mossad) than invisible unicorn.

If you're in security and you haven't at least heard of Wiz, I have doubts about what you actually do. I'm not saying you have to be a CSPM expert, but not even hearing about Wiz, when they are the largest CSPM, is somewhat concerning.

Bullshit. Infosec is not just about highly inflated startups or whatever the fuck CSPM means. I know people who do exploit dev, reverse engineering, blue teaming and they have never heard of wiz. Stop overexaggerating

Re: Google to buy Wiz for $32B

#807

Earlier quoted context omitted.

When you use a cloud provider to setup a VM, what policies do you apply to it in order to ensure it’s secure? Wiz and other tools in the same space tell you and tracks compliance across your fleet. Idk if wiz does this, but their competitors have “compliance packs” which are preset compliance patterns, IE hipaa, finra, etc. That way you click a button and it tells you every change you need to make to be compliant Edi…

I don't know anything about cloud VMs, but I'm confused about how this is possible. Wouldn't determining whether you are HIPAA complaint depend on auditing all kinds of application details about how information flows through the system and how authentication and authorization are done? How could this be validated statically by looking at cloud VM config? Is Wiz doing some kind of AI magic over your whole codebase? I…

They don't only look at the configuration of the VM, they also look inside the data inside the VM.

Re: Google to buy Wiz for $32B

#809
post #627

Earlier quoted context omitted.

Don't conflate skepticism or criticism of Israel with skepticism or criticism of the Jewish people as a whole.

[flagged]

So is it totally okay that the Jews in the 1930s/1940s had the goal to eradicate the state of Germany?

Sick of this double standard.

Re: Google to buy Wiz for $32B

#810
post #413

Earlier quoted context omitted.

When you use a cloud provider to setup a VM, what policies do you apply to it in order to ensure it’s secure? Wiz and other tools in the same space tell you and tracks compliance across your fleet. Idk if wiz does this, but their competitors have “compliance packs” which are preset compliance patterns, IE hipaa, finra, etc. That way you click a button and it tells you every change you need to make to be compliant Edi…

But...don't these companies already have cloud security engineers on their payrolls? /s

I don't see the need for sarcasm. Most mid-size and up companies have security departments. And they use tools to make their jobs easier.

The problem with the cloud, from a security standpoint is that is it much more complex than a traditional on-premise infrastructure, especially if you go the "managed services" route and have minimal code.

Post reply on HN