Latest / Noise2Signal / EP 1. Bromure Secure Browser, Nessus Origins, Overbearer Proxy, Coding with AI, Fundraising in AI
Transcript
- Speaker 1: If you were to do reimsure analysis today, how would you do it? So your velocity has increased thousand decks. So what changed? What's the origin story on from your? Speaker 2: It really is a compilation of my twenty five years of history. Speaker 1: The founders or builders in in the age of AI who are very technically adept have an unfair advantage. Speaker 2: I think there is an unfair advantage. I think it's going to shrink. The value of software is going to zero. Speaker 1: Like s someone with like your pedigree could have embraced like a twenty million series A for Bromeur, but you didn't get why. Speaker 2: I was very scared by Satan. Speaker 1: Which one will really stand out in your career in the twenty five years as like the special one? Speaker 2: Ladies and gentlemen, please welcome Renaud Deraison, creator of Nessus and co-founder of Tenable. Speaker 1: Okay, we are live. Renault, it's an honor to have you as the first guest on this interview series. You are, by definition, the OG, the GOAT for building defensive cybersecurity solutions. You started way back in 1998, ⁓ creating Nessus, Jade Nesses, then you co founded ⁓ Tenable, ⁓ with Nessus as the product. And I had this unique privilege to watch you both you and Ron. Scale tenable ⁓ from where it was in 2001, 2003 to what it is today. And the lessons I learned watching you guys scale the company is still ingrained in deeply in my consciousness. So I'm super grateful that you are part of the C3 series. We are going to make this super exciting. This is going to be super fun. So let's get let's get started. So, Renault, first question I have for you. The first question I have for you is. What was your open claw moment in nineteen ninety eight? Like why did you start Nessus? You know? Like what happened in nineteen ninety-eight? And you I believe you were a teenager, either out of high school or just doing college, and you started this project and it became immensely popular within like first one year or two and it just Yeah. And then stuck out from there. So what what was happening in nineteen ninety eight? Speaker 2: You know, I think I think it's very similar to some extent to what we're seeing now with AI and innovation every day and new product every day. Like the late nineties, which is over a quarter century ago, you had the explosion of open source, right? Like Linux was being like di f from ninety six to two thousand, Linux went from nothing to like, hey, this is a very viable platform. And it was a very pro open source period. You have a bunch of people writing code. At the time the reasoning was that anything open source was bound to be better than commercial software. So whatever you would write. And ⁓ and yeah, I mean I saw that. I saw the explosion of the internet. And I felt with the explosion of the internet, a, you know, it was a no brainer, everybody would be connected one way or the other. And two, I was My reasoning as I was learning Linux and all that, I was like, Well, there's no way everybody's connecting servers properly to the internet. And so the idea was hey, let's do an automatic software which is going to kind of like tell you what you did wrong with your config. ⁓ and then it kind of took a life on its own. Speaker 1: And y you know, in those days I don't think security was like a primary decision maker and pushing software out. You just built some had a functional use case and can get that out. You know, maybe it's a file transfer or something else. Anyway, the goal was to get the functionality out, not necessarily getting thinking about the security aspects of it. And tools like Netflix. Speaker 2: No, because a lot of companies, you know, their website, they were like you remember in construction, you know, you would go to ⁓ whatever IBM.com and you had assigns in in under construction. there was not a lot of sensitive data. You still had a big segregation between the internal processes of a company and their external things. So yeah, security was not top of the mind, but it was clear that more and more ⁓ of the process would move would move ⁓ to his internet. Speaker 1: Yeah. And you know, my my r my recollection, my recollection of early Nessus is that you were very frugal in terms of how Nessus used the the the CPU or the memory on the system when Nessus was running. Because you are literally I I believe I have seen in some cases you did like assembly core instructions in Nessus to extract the most out of the hardware that is there. I I was I'm curious, like what were you thinking in terms of design principles? Because you was very you were very involved in the entire development of Nesses. Like way till like I guess even like till 2010. You were literally writing code. Speaker 2: Yeah. Well, I think well, it was a different time, right? I mean the the computer was using at fifty six megabyte of RAM at the time. ⁓ so that's not which was huge. And it was not sixty four because sixty four was little too expensive. So I had to kind of like cut down on one on the hardware. ⁓ but the Speaker 1: Huge. It is huge in those Speaker 2: No, I think I think it was a different time. I think the way you would scale at the time was really trying to make software as efficient as possible on a single host. You know, that's a big design pattern. And so the idea with Nessus is a more and more people are going to put, you know, your typical network is like a slash twenty four in the enterprise. So that's like two hundred and fifty six hosts. So you need you need to do that in parallel. ⁓ and so if you scan a hundred hosts in parallel, fifty, whatever the number is, you know. And you you you compare to the amount of RAM the computer has, you y you have to be very frugal. ⁓ and also at the time we didn't have a lot of like off the shelf software. I mean, it was a very CQ conscious kind of era, a memory conscious era. Speaker 1: In a very on prem era, right? ⁓ very on prem era. Speaker 2: On prem. Completely on-prem. I think I mean I mean, downloading the updates, downloading the plugins from from Ness, i I I won't say. I I won't say it was like completely novel, but it was like the that new wave of software. You know, it was part of that new wave of yeah, yeah, you don't need to go to the ⁓ vendor site and update manually, it comes by itself. Speaker 1: You know, one of the most underrated features that I that you know people don't appreciate as much, and this is like this was working in two thousand three, is the ability to push plug-in updates multiple times a day. This was essentially CI C D working at scale back in two thousand three. Because, you know, from our perspective, we would just, you know, write these plugins, ship it out. And this some of these plugins were completely new functionalities like compliance, malware detection. ⁓ you know, sometimes we did the DLP. ⁓ I don't know if you remember, you know, these plugins you shipped, you were signing like the floppy drives and they were creating all kinds of chaos in the support team. Like my floppy drive is crazy going crazy. And ⁓ like the advantage of Nessus in those days was as a product person, you didn't have to like ship features. You know what I mean? Like you could do a big release once a year. You could do a big release once a year, but like the core functionality, the customer should still get value. With the plugin. Speaker 2: That's the one thing I think I did right. which so so you know a lot of a lot of things I would do differently today. But the if if if you look at Nessis back in the day, it really was a script engine which would execute things against a number of hosts. And once the language became powerful enough. ⁓ yeah, like a lot of things could be done. And and and and actually, you know, there's a lot of internals in Nessus, which rightfully so are kind of completely unknown. But like so we had this language that we did ourselves. We had ⁓ a binary format, you know, remember the NBA so that some plugins we didn't want the IP to leak, because that was after it was it was post open. ⁓ and so we had this kind of compile system and and the plugins themselves, the file format. was similar to ⁓ what you have like on the macOS with the fat format where technically you could support different bytecode. We never used it, but the idea was hey, you know, if if we change the way NASL does a bytecode, we could so you can version it and you can have like multiple it's called a flight binary on the macOS when it supports both Intel and and ⁓ we could we could technically do the same. So a lot of little things ⁓ which were yeah super precise. She perfect Niki and and and Fa. Speaker 1: curious though, like you know, taking up this task of creating your your own new language when others existed. Speaker 2: Yeah. Is that mistake? Speaker 1: Outlandish. I didn't I didn't say that. Speaker 2: No, it it no, but it was not ⁓ Speaker 1: Like you were young, in the early twenties, I believe, to have the guts to say, hey, I'm gonna write my own language and I'm gonna control it. And then, you know, at least like for me, like a plugin developer, at those in those times, the language did enough to get our job done. It it did network connectivity, it could yeah, we could write exploits, confirm the vulnerability, ex- So everything we needed existed in there. And if we didn't have something, you just added new features in the language and we could use it in the next version of CSS. Speaker 2: Y yeah, well so initially plugins were written in a C. Like it was really like a shared library we would load and unload. That was like version alpha one, I think. ⁓ after writing a few, I realized that most of the plugins what they were doing is open a socket, send a buffer, receive a buffer, match up, right? And so going back to that memoir scarcity, you had languages out there like at the time it was Perl. Lua was like still very unknown. So there's really like in in the late nineties you had Pearl and Tickle, ⁓ which nobody uses anymore. That was the ⁓ the one you could embed. And Perl was not meant to be executed in parallel like to have like 50 kind of like thread threads in parallel processing. So it would have exploded. So that was one thing. Like okay, we need a language which adds maybe half a megabyte of rubberhead. when we execute it. The other design principle is that I was very scarred by Satan, which was the granddaddy of Vone Scanning. Yeah. And and the issue with Satan is that it relied a lot of like on external binaries and libraries to do its job, right? It would call ShowMouth and all that. And I had a terrible time to install it. And else very I had there was like some weird version of Linux. ⁓ And one of my design principle was that Nesses should be self sufficient. And if we use something like Perl, the issue is that people will spend half a day just to install the modules and then we're going to lose track because that module got updated and it works on plugin. So I felt like controlling the environment was safer. Now that was a mistake to stick to it, right? ⁓ because the plugins became more and more complex. You know, it's one thing to send a buffer. just to check like the version of a a banner, but like, you know, we implemented the full SMB stack and thing like that. So so it's time to become like a little bit more ⁓ more complex. ⁓ number two, when we became a company, I realized ⁓ Mean my my take was, you know what, it's it's just just learn the language. You know, if you're good at computer, just learn a language. And and and I would even if if if you interviewed me in in 2003, 2004, I would probably tell you it's a great filter to to weed out the bad kin edict. ⁓ the issue is that A, we spend too much time kind of doing basic libraries. ⁓ we need basic T4 or anything like that. ⁓ and the second thing is it's not great for recruiting because When you recruit people, they well, yeah, because they come in, rightfully so, and they're like, Hey, I'm going to improve my craft, and I then I want my improved skills to be transferable to my next company. And and a lot of people, they're like, I'm running a language I will never use anywhere else. What's the point? And so double edged, ⁓ so we on one hand we would control the runtime and all that and and also controlling the runtime was like, you know, that you have a lot of safety features in the Nessus language. Like you know, a plugin cannot open a connection to a third party host. ⁓ if it starts to use a little bit too much memoir being killed. Like you have a lot of things like they can local files, you have a system of privileges. So that was good too because it you know the idea was hey if if if if somebody if if there's a a a supply chain failure as we can see right now, ⁓ you know very far thinking. the consequences won't be that bad. You know, we can contain them and and so so it it it helped a lot, but yeah, I I think in hindsight, ⁓ if I had to do it today, first thing I would do would be to get rid of Nazal and move everything I can to a mix of JavaScript and and static JSON definition. A lot of local checks you can just do a JSON definition. So let's Speaker 1: Like so, you know, you know, you had this foresight of, you know, building the NASA, you know, with the mindset that you had then. But if you were to if you were to do it now, if you were to do re-implement Nessus today, how would you do it? Like which which which languages would you use, which which what would be your tech stack to implement Nessus? Speaker 2: Yeah, I think so so the big difference today is that you've got enterprise quality building blocks. I mean the size of the building blocks has really changed if you think about it. Like late nineties, your building blocks versus some some C library, which parses like style sheets, you know. ⁓ and that was the most complex. ⁓ OpenSSL was a big one, right? now you've got Kubernetes, Click House and and and a bunch of of of ⁓ technologies like that which expand what your software can do. So if you know if I were to build it today, you would have it will of course be multi multiprocess. So it can scale horizontally in Kubernetes. It would use a message queue to distribute the load. So if something crashes, you can still like recover the scan. ⁓ In terms of pure language, I don't know, probably the mix of Go and Nodejs. ⁓ You would use Click House for the back end so you could see the result of a time. That's something I would want you to do, just have a a way to point to a host and like have a a timeline. Like what was this host like six months ago and what is it now? ⁓ and so so yeah, I think it would be it would be very different. It would also be harder to install. Well yeah, because now if if I use all this, then I need to supply you with like you need to have a Kubernetes cluster and all so That's where you have so much choice now. You have to kind of optimize as the from the get go. Is it like a desktop app or is it ⁓ is it really like enterprise scale? And I think I think that Nessus was kind of like between the two for the longest time. Like it would work well on the desktop and also would work well on a dedicated server. ⁓ but yeah, if you want to take it to the next level, you have to pick. You can't you can't do it. ⁓ maybe you can have a hack with Docker Compose. Speaker 1: like two follow-up questions on this. One is one is if this new architecture was implemented, what could it do that the current version or what would what cheat or efficiency gains would we see in the new architecture compared to what we have in Nessus? And then I remember ⁓ like Nessus went through a big architecture change when it went to a SaaS model from an on-prem model. Were some of these changes implemented then or those still a work in progress? Speaker 2: No, so so the base Nessus engine when I left was still that kind of like monolithic on-prem server. And then you would have the SAS component kind of d d divide the work and basically say, Okay, well here you have five IPs, you scan that, and then you could connect to something else. But the problem is that it's not efficient. ⁓ on many ways. It's not efficient because every time your SAS thing will distribute some node, you have to compute okay, well which plugins, which preferences. It it's it's a lot of like overhead. ⁓ I think if it was done in a modern way, you would just have one big cluster of scanners. And and that would be it. And then if one of them crashes, you don't have to distribute the load it's just host by host, plug in by plugin within just distribute. ⁓ so I think it would be it it would be just more efficient use of I think with the same hardware you could probably have like three, four times a ⁓ Speaker 1: Do you do you think that this new architecture will in theory allow internet wide scans with nesses at scale, like you know, the show rants of the world or the censuses of the world? Like, you know, you power this with this completely new architecture. Because that's I believe like I don't think the netest level scan of the internet exists. Speaker 2: No, I mean I guess I I guess you could. I I don't think it would be the most efficient. I mean, look, I mean i if i if if we're imagining rewriting everything, I guess you can imagine rewriting ⁓ rewriting it for Bedoska. And that's just was not fully if if you look at the mascot or thing like that, the efficient the the use of the bandwidth is really it's really well done. Like you have a lot of things done extremely well. The overhead of the you look at end maps, the overhead of Lua is actually lower than NASL this point. So I I I guess you could get closer to internet scale because yeah, if you have a large cluster with ten thousand nodes, I mean if you just throw money in brute force to the problem, you can make it work. but yeah, I it I think it would be ⁓ there are better ways to do that. Speaker 1: What do you think is like, you know, what do you th think is the future of like defensive cybersecurity in the age of AI? Like, you know, what tools do you think are promising in terms of like, you know, ⁓ like, you know, attackers finding things on the internet? What what's your opinion on the future of defensive cybersecurity solutions? Speaker 2: I I i it's it's it's it's a tough one. I mean well this week you just for context, right? We we're witnessing in real time the complete collapse of the supply chain. ⁓ every day you've got new Python and ⁓ Node.js packages being like found out as so it's I you know it i it's t I think I think AI helps a lot in everything which my view of where AI development should go is that you could imagine a world where generated code is safe enough. And you could imagine a world where Anthropic or whoever of an AI, whatever they want, doesn't stop at producing the code. It puts it in production. Right. So you could imagine a world where you talk to your cloud and you say, Hey, I want the best guessbook. you know, you can think of. And then it's like, okay, here it is. It's up and running. Here's a URL, the certificate has been has been done. And then if you approach it this way, it would work really well because A, as an end user, you don't have to worry about the infrastructure. Right. So forget about cybersecurity. Like it's not even defense. It's like it's better. It's things are better built because you don't you don't see the infrastructure. You have professionals running it. And then they would probably use a cook cookie cutter approach of like, okay, for every time we need a database, we use this. Every time we need a a a key value memory store, we use mem c whatever it is. So you could abstract this and and think directionally things are going to get way, way better ⁓ over time. So so to me that's kind of like my existential question. Like I think AppSec is dead. I think that reconnaissance of your infrastructure is changing. a lot and maybe there's no infrastructure to to think of. And you know, it's it's like it reminds me a little bit, you know, when the iPhone came out. There was a question of how who's going to be the the security leader, which security tool are you going to run on the iPhone? And and the answer was none of them. The platform is safe enough. And and I I wonder if that's where it could things could go. I mean not not for everything of course, but I I I I think that's where AI can help a lot. So so help can help out when you create the code. And of course, AI can help a lot with like automation, automating your environment if you choose to run it yourself. ⁓ I think the faith we have in the technology of the last six months has been multiplied by what five. you know, it's funny because we kind of like kind of went through phases as an industry, right? It can also the cooler thing. ⁓ no, it's really dominant. ⁓ I mean it's really good. ⁓ I think right now it's we're we're either in a it's a really good phase. Maybe there will be some more disillusion, but I if you look at the velocity, I think in two, three years, you can imagine a self ⁓ healing kind of digital digital infrastructure. Speaker 1: Speaking ⁓ speaking of velocity right now, you went from let's switch gears a little. You went from running one project, one open source project kind of converted to commercial for twenty five years. And then you switched to two open source projects in two and a half weeks. So your velocity has increased thousand decks. If you've just taken raw weeks that has taken for you to shift new projects into the world, what changed? Like, you know, you you're like completely dedicated for 25 years for one project. And then you went, and I I believe there are more projects coming too. So what changed? Speaker 2: ⁓ well I think I mean I'm having a blast, honestly. ⁓ I've been using coding tools for last two, three years. ⁓ you know, so I I've kind of witnessed and and I you know, I published two projects. I have I think I have ninety one private GitHub projects for a lot of like automation and things like that. Some of them are really dumb, some of them are super useful. But you Speaker 1: Use it internally for your projects or is it just your Speaker 2: No, no, j just for me, just like, you know, I like to to experiment. ⁓ I think lately I'm having a lot of blast because I'm having a blast because the I think with Cloud in in in in twenty twenty six, you can really focus on your vision and it finds ways to implement it. Don't have to worry about i I I think as developers, we kind of We're a condition to what we know. And it it it it does shape the vision. If you do something by yourself, it does shape the whole vision a little bit. Like if you don't know anything about virtualization and it's like an open source problem, maybe you won't start you, maybe you won't try, right? Because you don't know where to start and it's a thick documentation. I I think with cloud you can say, Hey, I'm envisioning this, make it work and it it kind of work-ish. And once you start to find the right groove when you know what to ask, you know how to formulate it, you have the proper testing infrastructure so cloud can test its own code and all that, suddenly it's super fast. And it's not just the code. So I did two products, right? I did one which is ⁓ called Romeure, right? It's a it's a secure web browser. It's the it's anti necessarily in a way. It's basically the is the idea is people are not looking to patch. Yeah. They don't patch often enough. So why not have a browser which gives you peace of mind that even if it's compromised, it has very limited access to your system, right? So like webcam is disabled, ⁓ files are not reachable unless you really ask and and then there are like gates and all that, right? ⁓ so it's fully fertilized, it's a macOS thing. It feels like as much as possible, I try to make it feel like a native macOS app. even though it really Chromium and random Linux, but you know I I I I try to do that. And Speaker 1: But but Reno, before before getting into details of Romeur, I'm curious, like somebody who's like a deeply technical person who's written like, you know, like high quality code, what does the development process look like for you now? Are you mostly thinking at an architect level where you are telling the systems this is how I want things to be done and the systems one then you verify it that it is c correct or are actually are you or are you actually writing code? Speaker 2: No, I'm not writing code. I'm reviewing some of it, not all of it. I my process is nothing unique. I don't have a hundred agents and all that, or we get one instance of clothed code. I iterate a lot. So it's a lot of okay, build a shell, like build something which launches Chrome, right? And and actually launches Linux. And you start with the VM and like, okay, now I want XLM, ⁓ X Wheelow in it. ⁓ and I want this option to be passed. So you kind of it's a lot of iterations. I found that when you give Cloud the master plan, it tends to be good with the architecture, like how it's going to architect the software and all that. But then every item quickly enough, it doesn't go deep enough. So if you start, but if if if you follow what you would do as a human, kind of like, okay, start with the kernel and kind of like build it, ⁓ it works pretty well. But yeah, I review some of the code. I think I think the fun thing with Bromir is that it's it really is a compilation of my twenty-five years of history in tech. It's like it's it it's some super arcane Linux configuration. ⁓ that, you know, something I learned back in the day where ⁓ it's a little faster to start X window if the phones are pre compiled. And nobody does that anymore. But you I found the command. So it's a lot of things like that. ⁓ and it with a modern twist on it. So The concept is not new. but yeah, I think it's I think I think the concept of secure web browsing is still not solved. ⁓ so so that's also the fun part of it. Speaker 1: And have you experimented with like multiple agents with learning you know, you know, having like a PM agent and the UX agent and yeah, and then like have you you know have you done that too? Like how does that how how has that process worked out for you? Speaker 2: So I I did some experimentation. Some people are more successful than I am with it. ⁓ I did this system where I plugged together seven cloud agents, right? You've got a developer, you've got a security guy, the architect, UX, UI, marketing, ⁓ and a PM. And ⁓ marketing and and actually it was and and just just for fun, I'm like, okay, like do here are some instructions. Let's let's build like An an open source width, right? ⁓ I didn't want to do that. I just wanted to see how if I could go. And what was super interesting is that first of all they think a lot. So they so so initially on on paper it works really well. You see them thinking. ⁓ again, I didn't want to do anything with that project, so I called it ⁓ magician with magician, dumb thing. So the first thing marketing did is, ⁓ it's it's a stupid name. ⁓ and so they renamed the project. to cartograph, which I think was fun. ⁓ pretty good name actually. and and so on and and then they start to come up with a plan. The architect comes up with directives. Developers start to implement it. Every time the developer st does something, CPD shimes in saying to work me through it. So on paper, It works really well. In practice, when you see the end result, I think you've got so many distractions. I think the develop the developer agent gets so distracted by security and marketing and UX and the old the old chime in. Because they shine in they is it they ask the specs out. Then they review the implementation to make sure everything is kind of squared away. And security did. start like ⁓ yeah use of bad crypto and all this. So so ⁓ again when you just see the logs like this is going to be a great product. I I think the issue is that with the context window of the developer, it kind of eats at it and then they it becomes like a s you know when you have a full context window the your agent kind of forgets why why is it here and what it's to close to do. And so it finishes a job but it's it's a much lower quality Speaker 1: Is it inferior is it inferior to inferior to maybe somebody who would be like ⁓ you know, it's very important to have like a strong opinion on how things to be done. Right? Like a CEO and who is taking things this is how need to be done. Speaker 2: I in my experience, which again was you know, more like a Saturday night kind of fun experiment, ⁓ I felt it was not as good as like supervision of every stack. Like if I I find I I I built a bunch of SAS apps, you know, I I spared the world, but I didn't produce it. But I found that when you give a strong vision one on one and you kind of iterate, I the end result quickly looks better and it's more functional. I think with that kind of whiz clone experiment, it was I don't know what you did, honestly. At the end of the day, it was like bad look. It looked like something you would do with cursor. eighteen months ago. Like the UI was not great. The it was missing a lot of functionality. Speaker 1: You know, is it classical design by committee kind of a thing where you know there are Speaker 2: I think so. I think I think it's a great analogy for development in the modern software company. You know, it's like you've got so many stakeholders who basically distract you from the core mission is to build a certain type of software. But then, you know, it's make make it look good, make it secure, make sure it uses the right word, making and and I think ultimately we see it in in in a lot of more established software company, people kind of lose focus of what matters, what is a north top of the company. You know, they the things their goal is to make software, not make software which works well for customers. And I feel it's the same with ⁓ when you have too many agents. So I I I'm not giving up on that approach. I think there is potential. Some people report great success. I I have multiple agents in different ways. Like for instance, I have one for if you look at Bromeur The website is auto generated. Every time the iJune release the screenshots are taken automatically in every language. So it's a bunch of scripting orchestrated by AI. Then the AI looked at the screenshot, looked at the source code, read out redo the documentation, translate it in every language, and then publish it on the website. So it's a mix of you dumplify the agents a little bit by giving them a very strict mandate to get a screenshot, you know, document it. But yeah. Speaker 1: ⁓ I'm curious, like what does this mean for like I feel my my personal sense is the founders or builders in in the age of AI who are very technically adept have an unfair advantage in terms of building compared to people who are like professional leaders who haven't actually built things. Like what do you think, you know, like from an organizational point of view, how does AI change things from your perspective in terms of like exit because, you know. If you're if you're knee deep into the trenches, building things like you are doing, right? Like you're you're architecting, guiding, and you don't need a lot of help at this point. I mean, you have your agents, you have a mindset, you have an opinion, you just go and you just iterate, iterate, and you ship things faster compared to like this design by committee, which is like very typical of most organizations. They're very slow to adapt and slow to release. And they in this new age of AI, like how how does the process change? Why do big organizations fail? I don't know if you have like heard of IBM, like they had like this whole thing as a the building product was a process. Do you think that is still relevant in like to today's age? Speaker 2: I think it's a great question. I think I think that is an unfair advantage. I think it's going to shrink. I think right now my secret weapon as a developer slash I don't know, sometimes I pretend to be an architect is ⁓ I know where to push the AI. I I'll give you an example. So it's it's a virtual machine running a browser. You have the option of plugging your webcam into it. Yeah. And if you ask Speaker 1: I was like so hoping to have the fake I don't do a run over some. That didn't work for me. For some reason my Mac doesn't ⁓ support that feature. But yeah, please go ahead. Speaker 2: ⁓ yeah, but they would use it. Yeah. But but yeah, there's the the so the the funny thing is that Apple has APIs for the speaker. So if you have music in your VM, you can get it on your computer, on the host computer, like for free, basically. It has API for the microphone, so same thing. If you if you want the VM to listen to, you can't. It's just one call away. There's no API for the webcam, right? And so Cloud initially was like, well, you can't share the webcam. But as a developer, I'm like, well, there must be a way, you know, at at worst. Cause you there are there are sockets between the ⁓ the those connections between the VM and the host. So you must be able to take the video stream and send it. And then Claire's like, ⁓ yeah, I can do that. It's easy. and so I think my secret weapon right now is that I can push the I can push the EI when something doesn't work. Or or or the other way is true too, where If there's a bug in the I really can't figure it out, I also, you know, sometimes it kind of goes in a loop. And I c I can stop it. You know, I'm like, okay, you know, I'm I'm seeing I understand what you're doing and you're doing the same thing you already tried. So let's stop and let's take a step back. ⁓ so right now that's the only advantage really. I think you also have disadvantages as as an experienced developer, which is that we've been our generation, you and I, you have been we've been trained To think of computers working in a certain way. Like you have a form and you have to put data in a certain way, right? In the AFAI, you can just like throw, throw random things in and tell the computer to do the work that we did as human beings, like I'm new to organize and over. So so you have to unlearn a lot of things. I I I think as the models get smarter, maybe it's going to be less of a disadvantage. I my my my biggest fear, I mean. Because I'm not competing, but like I really think the and and and also by the way, I understand how the internet works kind of. Like I know how to create a website, I know I have to create an account with DigitalOcean and or whatever AWS. ⁓ I think that yeah, your off-the-mille non-tech person doesn't know to do any of that. So that's that's where we win, but I think this is going to become more and more hidden away. And that could see a world where yeah, people. of great ideas because they had great ideas that didn't know nobody just listened to them and they're not technical. Dude Speaker 1: the cost of software development is essentially going to zero. Like the de the Speaker 2: I think the the value of software was going to zero. No the the the cost no, but I I think that the terminal value of software is is is approaching zero because A lot of it like you can recruit use. I mean, not everything yet, but more and more. And a lot of companies, I I I think you look at a lot of SaaS applications out there. If you're like a fairly big company, Fortune 500. A lot of things you can task two engineers, work on it for two weeks. Like let's say you want or or let's say you want to replace Santa. your your Zen desk ticket ticketing system, right? Well, you could vibecode it and and have a solution which actually is very more much more ⁓ in tune with your own internal processes because it's really built on top of your database so it knows where you are, what you have access to, whatever you do, right? ⁓ and so that's going to put pressure on like a Zen desk, right? And so I I I think, yeah, I think the the so the software premium is shrinking. Speaker 1: And it will continue to shrink. Speaker 2: I I I think so. I mean at some point you'll reach a size where I don't know, is a is a dentist going to want to have his own sales force? No, probably not. So you have like still and and you also pay people to take care of the software for you, you know, that's kind of the value. But I think people were right now I think it's a mix of hey, I'm buying you guys because I like your software and you're going to maintain it for me. That's a SAS attitude, and now it's like you're going to maintain it for me. I'm not buying it for the software. Everybody has the same but it's Speaker 1: And what do you think? Like what modes will exist if that is the case, if the value of software is going to zero, like what modes will exist in in the next two to three years? Like where do you think like the modes exist? Is it more in like the hardware space ⁓ where the modes will exist or something else? Speaker 2: I mean I think infrastructure is tough to replicate. Yeah. I mean you look at the Cloudflare. Speaker 1: Mining like mining would be like very good, like plumbing, electricians. Speaker 2: Yeah, I mean no, but not the I mean anything physical, whether it's a physical device, whether it's physical, ⁓ again, you're not going to vibe code Cloudfair tomorrow. ⁓ y y I mean it you need some software, but they have more than that. ⁓ so so I I think that I think I mean model generation right now, it's like it it it's funny how it kind of went you if we had this discussion a year ago or eighteen months ago, I think the vibe was ⁓ models of no value. You know, it's all free. ⁓ it's there's no future for these companies. Like you you have open source equipment which are good enough, and now it's one completely the other way where nothing nothing has value except the companies doing the models. ⁓ but yeah, I think it's tough. I think it's the answer everybody wants to have to. Speaker 1: The new term is cooked. Like, you know, I don't know if it's it's cooked or or it is hard to har ⁓ or hard. Are you either you're in the cooked category or are you in the hard category? Speaker 2: Yeah, I think look the reality is also it's always a little in between. Like if y y you could try to vibe code a threat intel company tomorrow. And and and in some aspects, maybe some of the data collected would be actually super in tune with what your company is doing and but it's also it's a lot of work, it's not your core business. Is it is it super important? You know, is it is it going to use the best product? No. Speaker 1: It's super accurate because like you know, like you know, previously for threat intel you would have to scan like the dark web websites and so on. But now that information is already available with the models because that in information is encoded. So you can just ask them, hey, what what would you know about this C V E or this vulnerability or this attacker? And it w knows much more in detail than typically, you know, so you know, like the recorded futures of the world would figure out. Speaker 2: Well, I mean first I mean it's it's going to cost you like ten bucks in tokens per CDE. So at some point the economics will not be too to work. But also, I I I don't know. I I I I think it's it's not necessarily the first thing people w w want to ⁓ I I think to me the company which are cooked, to use that term. It's companies which it's ⁓ it's companies which take your internal data and present it back to you in a different way. You know, like, hey, you know, we've we're sucking all your AWS configs. We're doing something and we show you some like ⁓ you know, the misconfiguration, cost, whatever. I think these companies, I think the buyer of entry at this point becomes very low because you can wipe coding. And and and whatever you'll do, it won't be as good as a company which been doing that for five years, which has a billion features, but you'll implement the three features that you need. Speaker 1: Yeah. ⁓ You're looking for, like specific outcomes that you're looking for without having to massage the data, you could literally say, Hey, this is the outcome I'm looking for and then go from there. Awesome. So ⁓ Reno, let's ⁓ let's talk about ⁓ Bromure. Like why did you why did you start ⁓ what's the origin story? What's the origin story on Bromure? Speaker 2: So so the original story it's it's so dumb. So so I've been, you know, again, experimenting with a of things. ⁓ I've been contacted by a lot of pseudo scammers lately. You know, ⁓ I'm not sure if if you receive that, but like a bunch of text saying, ⁓ we haven't line of credit for you and all. And I always wondered, okay, who are all these people? And so as a joke, I set up like a Speaker 1: So these are not like from the bank these are not the bank offers, right? No. Speaker 2: But another banks, it's I it's sh I don't know who these people are. That's what I wanted to solve, right? So so I I started I did like a shady ⁓ like a not a shady a a honey ⁓ website with like fake financial information. And whenever some of these guys would ask me if I wanted a low, and basically I would say, ⁓ yeah, absolutely. And here is my here's my banking info, right? And I give them the link. And then and nobody clicked. And so I was joking with friends and I said, ⁓ do you think that scanners get like training? To not click on unknown links and all that. And then it that project gave gave me gave it kept me thinking because A, I did ask Claude, do a website, which when you go on it, gathers as many fingerprints from the end user as possible, like you know, the IP address, of course, the the screen resolution, a bunch of things. And it actually worked really well. It would use a it would do a a web RTC trick where it's kind of like the website pretends to start a conference. So it can it sees your real IP address even if you don't have even if you have a VN. ⁓ it would do a lot of things like that. And so it was like, okay, well, A It's actually not bad to have a browser to open a shady link with, ⁓ to see where it goes, you know, when you get the fake invoices and all that. And B, browsers are very geeky and and they say a lot of things. And so so that's kind of the original story. And I always loved Bromium, which was the ⁓ granddaddy in that space, was the first company to try to virtualize everything. They started with a browser and they added email and other things. And fortun unfortunately the the they didn't like ⁓ exploded like they should have. ⁓ but I was like, ⁓ let's revisit. And so I started, it started with just macOS being emulated, not Linux. I wanted to have Safari in Mac OS. and Cloud actually using the macOS APIs implemented like a full thing in like 10 minutes. In 10 minutes it would it would create a like a shell of like running installing macOS. And then you know after that, well Keep it running, it's fine. ⁓ it's actually it is convenient to have a web browser where you know you you have good control. Like, you know, there's like the context of ⁓ there's a concept of ⁓ I don't know what they call it in Safari, but ⁓ like window type, you know, you can create personal versus banking and all that. Profile? Profiles? Like Yeah, yeah, profile, yeah, yeah. And and and so I'm like, yeah, we should I should expand like Bromere to have the same concept. And then you can clearly separate. And you know it's like there's nothing left on disk. ⁓ like my banking website doesn't get access to my webcam. My I have a Twitter one where, you know, God knows which links show up there. So it's like dedicated, like a bunch of things like that. And so yeah, I kept running and I was like, ⁓ this is actually fun. What's the might as well renew it? Speaker 1: What was the primary use case? Like what are you even thinking about like you know, like the use cases you talk about, look like, you know, clicking on a link and so on, like ransomware would be Speaker 2: Yeah, that was so so so so the primary use case is sometimes you do get some phishing, you want to see where it goes, how bad it is. And really the MO today, if your little paranoid, is well, can we to open it in a virtual machine, right? Because you don't want to open it with your browser. You never know. It could be a zero day, it could be something very offensive. ⁓ but if you if you do it in a virtual machine, then you do need to have the discipline of creating the machine. Opening Zodica than destroying it. And at the end of the day, you don't do it. You're like, ⁓ that seems safe enough. It seems like innocuous. And so and soon enough, you have this kind of sandbox VM, which actually is seeing a lot of activities and you end up using, you're more dependent on it than you think, and it has more of your data than you think, right? Maybe you log into whatever. And so that's a primary use case. It's okay, I got like a ship, I'm not sure, and I don't want to have. If I click on it, I don't want to w I don't want to wonder if something bad happened or if some ex information got exfiltrated. It's a clean session. You you have the ninety nine point nine nine nine percent guarantee that none of your personal data are leaked they're leaked based on you know unless you put it in. And so yeah, it's better peace of mind. Speaker 1: And I I I you know, w one of the challenges most of these command and control ⁓ systems is you don't know what is going on, especially if you get bleached by ransomware, you know what is going on, what what what is getting exchanged. You have no visibility into this. And I believe Premier tries to tackle this. That at an enterprise we could see what traffic is actually getting exchanged. Speaker 2: Yeah you can do that. Y yeah, I think I think this this coach of ⁓ modern secure you know, it's funny. When you know back in the day in the 90s, you know, SSL was the exception, not the norm, right? And and as we progressed, we basically said as an industry, you know everything needs to be cipher. Makes sense. You don't want third party to see what you do and inject data. The problem is that we've been trading ciphered data as some kind of like state secret, we should not look at it. Yeah. ⁓ I know it's mine in the middle is bad and all that. And so it makes it super easy for an attacker to just exfiltrate whatever they want, just open an SSL tunnel and Speaker 1: And you would know you would not know anything of what w ⁓ yeah there is no way to know what got ex ex exfiltrated. Speaker 2: Exactly. And and so now if you look at the browser level, you know, the developer tools in Google and all that, they give you some information about okay what resources were loaded and all this. I think the timeline is not always super clear. They try to make it side by side and say don't show what you sent. So if you upload your login and password, you won't find it into the developer console because they want to hide it. It's secret data. ⁓ Bromure has a optional disabled by default. Trace mode where you can recall everything going on. So you have the entire timeline. So you click on the shady link. And yeah, you could think so. So that's kind of at the individual level. And then at the end you can say, okay, what actually did go through? What did I upload? Right. But now if you think about this concept at the enterprise level, and and some comp some companies do that, you could imagine a version of Bromure used for your corporate environment where we stream all the activity, we stream everything going on, we stream it back to the mothership, right? We have a recall. And then the one day that you go to IT, because here's the MO today, right? You click on a link, an employee clicks on the link, and then one day calls IT of security and say, I think I I clicked on the wrong link. And it's like, okay, what did you do? Nothing. Did you put a password? Maybe, I don't remember. It's always like that, right? And so everybody has to scramble and And I think if you can recall the reaction done, again in a pure corporate environment, then you could have this kind of like trace saying, Okay, let's see if you uploaded any credential. No, you're good. Right? We don't need to investigate any further, nothing, but ⁓ i you don't have that today. And it's it's it's kind of crazy. and so so yeah, maybe Bromer will will tackle that next. Right it's at the individual level, who knows? Speaker 1: What's the what's the license on it? Speaker 2: What's the MIT? It's I mean ⁓ my point of view is that I spent at this point I spent a month on it, but it really three two or three weeks of work. I'm not going to copyright it like in a strict way. Well, what's the point? ⁓ you know, I didn't do it. I had the idea, but Club did it. ⁓ so so yeah, i it's it's it's MIT licensed. Again, you know, it's fun, like it's it's a funny little project. Speaker 1: What is ⁓ what is the what is the future of Bromeur? Like, you know, do you envision this being the everything browser where all their apps can run in it into it? Like what's what do you think is like, you know, I talked to you maybe two years from now and then we have like the Bromure Plus Plus, like what does that mean? What does that look like? Speaker 2: ⁓ I I think So so maybe there will be a Windows version. We'll see. I I think the future I I just want to see how far I can take it. I ideally I would like to have a ⁓ a a version for like small offices or mid sized companies where you can create profiles like in a centralized way. You push them down with an NTLS certificate and all that. And you basically you have guaranteed environment for your employees who use their own laptop. Right. So so just just like INN.io does, except in a VM. So basically you would push to employees saying, okay, you have our come our SaaS application SalesFalse and Workday and whatever, and it shows up. and then you have NTLS, so they can only use Bromir to connect to it. So it's great for contractors. They can't use like an unmanaged browser. You configure the browser. That's it. And and optionally, you know, again, same thing, recalls a session and all that. Offer all that for free. Cause it's the profiles cost nothing. So it's no like it's, you know, a few bytes per person. So so I would not charge for that. ⁓ and yeah, and see if if that takes off. You know, it's that that's the vision for it. the the discussion like do we do other apps? ⁓ Then a web browser, you know, I mean Slack is a great example although it's a web app. ⁓ OpenCloud would be an example, but I think it's it's not broader itself. ⁓ yeah I would reuse the code, but I would probably create dedicated Mac apps for these. Speaker 1: You know, I'm always curious why people name things the way they name it. Like why why why Bromure? Like what was like what was the thinking behind Bromure? Obviously you you said you were insinuated towards Bromium, you know, you were being being a big fan of Bromeum and so on. And when I was looking up ⁓ Bromure, I couldn't find a good reason for it. So I'm sure you have a good reason for Bromure. Like what ⁓ what's the what's the w why did you name it Bromure? Speaker 2: I you know, I think I think names are tough. ⁓ names are tough and don't even tough. Speaker 1: I was at I was at RSid earlier this year and ⁓ there was a company and it had a funny name and I asked why did you name it, whatever you named it? ⁓ we just put it in Chat GPT and Chat GPT said this is a good name and it has a good ring to it. I was like, You are a founder, you should have thought mo there should have more thought to this. Like you cannot be Speaker 2: I I I tried that. I was not happy with the suggestions from the Chat GPTs and Clothes of the World. and also some of the names they suggested existed. So we need to do some background check. ⁓ no, I think bromure, as you said, it's it really is up and on bromium. and bromure means bromide. It's the French word for bromide, which kills germs and all that. So it's it felt very appropriate. J just like Nessus is a kind of name which makes sense in hindsight. You know, Nessus was sticked randomly. In a book, I just felt like it had a nice ring to it, and then people told me why I lit Nessus. Wow. They said, ⁓ you know, it's an alien from the movie well from the book Ring World, which is very permanent. I'm like, okay. ⁓ so in in hindsight, you always find a meaning. ⁓ at the moment it's just yeah, Bromier. Sounds good. The domain was available, so I did promise.io, little website. ⁓ yeah, it's Again, it's fun. Speaker 1: And then, you know, you were not satisfied with Bromeur. You wanted to do one more. So you did more or better. So that project was also launched, I believe, like last week or two weeks ago. Speaker 2: Yeah, I think I did it just week. ⁓ Speaker 1: And so so yeah, I have to ask you this. Like, did you literally start working on it like a week or or was it like incubating for a long time and then you pushed it last week? Speaker 2: No, it was an internal need. ⁓ so we're seeing a lot of supply chains attack. ⁓ I mean I I ⁓ I'll I'll ⁓ if if you look at my lab, if you take a step back real quick, I have a lab, I have a bunch of services running internally, you know, a bunch of random things. So ranging from home automation to whatever, downloading CD permits. And the and and I have a process which rebuilds everything with the latest version every month. Right, because that will not have to patch anything. It's all automated. No need to scan anything. The problem with all the supply chain attacks is that now the latest package, it seems like a it's a risk, right? The challenge in twenty twenty six is that it's it's really funny. We have this We want to factor authentication and all that for human beings, but at the same time, when it comes to automation, we want to make it as simple as possible. And people use bearer tokens, right? API keys. Yep. And a lot of my systems, they use API keys for like company, ⁓ for anthropic and all a bunch of things. And yes, the idea is, well, if it gets compromised, the first thing that the supply chain addicts does is it takes all your s all your API keys that it can find. ⁓ and and and steal them. So then they can have access to your environment in different ways. And so the idea with overbearer is just to have this proxy between money in the middle interception. So when you talk to an anthropic, when you talk to an AWS or whatever, it takes a token and replaces it by another one. And so that way the services that you have internally have a fake token. So if somebody steal them, ⁓ unless they maintain access in your environment and can talk to your proxy, they can't do anything with them. So peace of mind. and then you know, you have like one central base which is like where all the Chrome jewels are, which does all the matching of the of the tokens. So that was the idea. It's fully Kubernetes, that's what I ran at home. and and yeah, I think it's I think it's a simple thing. I saw another company actually ⁓ iron shell. They they release something similar. I think it's a neat trick. And and and it gives you also auditing. Like a lot of these platforms, when you use a bear tokens, they're not very precise on when it was last used. It's just how we did the last week. That's what Entropy tells you. Well, correct BFD. I want to know which IP address and when. And so so the ⁓ Overbearer gives you these two things. It will tell you, okay, this is a fake token or this is a real one. You need to replace it. And two, it shows you is exactly which API was called and by which service. So you can do some a little bit more holiday. Speaker 1: Yeah. So li ⁓ I don't know, like s someone with like your pedigree could have gone and raised like a twenty million series A for Bromeur, but you didn't at once. Speaker 2: ⁓ well it's a lot of work. No, i it's it's ⁓ I I don't know, I think Who knows what the future holds? I am very happy with, you know, right now, you know, I so I left Tanable five years ago. I've been advising a lot of startups. I've been working with a few fans to kind of also advise them, to attempt to advise them. ⁓ I mean, I think it's good advice. I don't know if it's good. ⁓ but basically, you know, so I've been exploring a lot of companies. Speaker 1: So Speaker 2: ⁓ it was satisf it it is satisfying. It's intellectually, it's always super cool. You have to constant constantly reassess your assumptions and all that. So that's fun. ⁓ I was missing owning software. You know, the thing which I really love the most back in my Nessus days was okay, we have this big release, we'll release it, we see how people like it, feedback, the good, the bad. ⁓ you know, it's it's fun. You feel like a little responsible for your little corner of the internet. ⁓ I was missing I was missing owning a product. Promiras like I don't know maybe ten users, maybe I'll tell you four. I don't know, but it's there are users which it Well I I appreciate it. ⁓ you know, I know I w we we is also some users. I I don't do telemetry, by the way, so it's hard to tell. But it's easy enough that if if something is broken, I get like issues being filled in ⁓ in ⁓ Speaker 1: I'm not those users. I'm another users. Speaker 2: a five dinner ⁓ in GitHub and all that. So that that's fun. And yeah, and ⁓ it fills my cup, honestly. It's it's it's fun. I I I again I also think the value of software is training towards zero. Like and maybe I could have raised a lot of money, but also I did it in two weeks. So anybody can do it in two weeks really. I mean it's not I'm not special. You know, I just prompt it the right way and it's not super hard to reproduce it. Speaker 1: What do you think is like f the future of fundraising then? Is it like do you raise a lot of money and then my sense is like once you raise a lot of money, you're in a lot of pressure to make money at that point. And d d what what's your point of view on that? Speaker 2: It it's right now it's a very tough market because it's a tough market to create a company. It's it's very noisy. And one way for good or bad to rise above the noise is to raise a lot of money. Yeah because y you're you're you're credible. I mean you're more credible if you say, Hey, where's the future of AI security? Same product, same team. You'll be way more credible if you raise 200 million a seal round than if you raise half a million. Yeah. You know, that that's that's the reality of of the problem is the more you raise, the higher the bar for exit is. So you lose as a founder, you lose the control of your destiny a little bit because you know you have investors and they want to see a return. They spend time on you and they dedicate it as a deployed capital, and rightfully so, they want to see something out of it. And if you Speaker 1: And if you raise two hundred mil, the exit is six hundred mil. Speaker 2: Basically, I mean that's what you know y yeah, like like that's what investors tend to I mean, maybe now they want ten X really if we know it's you in these crazy days. But like the the yeah, you can't like if you raise that to two hundred mil valuation and then the I don't know, the company of your treat, Apple comes to you and says, Hey, we're buying you for two hundred and five mil. It's it's it's a really tough discussion with your investors, right? Because you lose that freedom. but if you didn't raise that question, maybe they wouldn't call you the first place. So it's it's it's really tough. ⁓ and and again, like from where I stand, it's I I enjoy staying on the sideline. Yeah. Speaker 1: Yeah, Reno, we have to go through Reno, we have to go through your Hall of Fame vulnerabilities. You've seen probably hundreds of thousands of vulnerabilities. Which vulnerabilities stand out in your career in the twenty five years as like the special ones, the special child, the things that you are really excited, you know, and proud to work on. Speaker 2: ⁓ I think I think there are a few I I think it's not so much a Vaughn, it's what we learn from them. ⁓ When I cry was back in the day, you know, When I cry was this kind of like Vaughn slash virus. ⁓ and Everybody wanted to scan with it. ⁓ and and it was it was interesting because there was so much attention paid to the plug. And I think we did twenty release in one day, like because we had so many variations of Wannacry and all that. But we did But but people the feedback was hey, I want to know it didn't fire on that host, I want to know why. I want s certitude that it's it's because we you know, if if it doesn't fire, is it because we could not reach a host or is it because the host is not affected? And so so we learned with we created something called audit trailing SS after that flaw, which which would recall why why something would not fire, which was actually very interesting. I think the other fun bone was How bleed back in the day where ⁓ you could actually see the memory content of the remote server. I think the plugin was fun because you actually see the result. So it was fun. And at the time it kind of like our SaaS server. So we had a SAS sophone which was nascent and the servers were probably red hot in the data center because of everybody's testing for it. So it was fun. Speaker 1: I don't and I don't know if you remember this reno, but like the WannaCry Wanna Bridge was the first Wanna Bridge where Tenable gave like a bounty to the researchers. Two thousand dollars for you know, th there are like seven engineers and researchers who worked from that time. And ev because of the gr you because it was Speaker 2: Yeah. Yeah, yeah, it's another week. Speaker 1: It was a two or three day crazy you know, no pr pretty much no one slept in those two, three days. And yeah, I remember I had like this font memory, like every all the key researchers who were actually writing the plugins, they got like two thousand dollars. Pretty amazing. And Teneval had never done that because it was one of the massive vulnerabilities ever. Speaker 2: It was massive. It was massive. It was banana. It it's it's funny because the world does VM, it's very quiet and then suddenly you've got like the big one of the year. Speaker 1: Same thing happens for shell. Same thing like, you know, ⁓ VM is dead, VM is dead and locked for shell happens. And the first thing, hey, tenable and call us. Like, you know, these are the people that people reach out to. Am I vulnerable there? Speaker 2: I I think that's a good thing that and the Load for Share was a very fun experience. The last one I did at Tonable. ⁓ I think these Vones remind you of the usefulness of VM, which is not so much to monitor that the systems you know are taken care of. It's more like, okay, I which systems are not taken care of. That's it. Like whether I know them or not. So it's more like that chaos mode of like, okay, I'm just scan everything and maybe I missed something and everybody every time people realize I did miss some servers which different teams managing them or whatever. So yeah it's it's it's a good kind of memory there. But yeah the Leon Lot For Shell was like the most intense one I did. I had COVID when it happened. I just I had COVID and I got the vaccination the same day you know I got the vaccine and I got COVID the same day with Speaker 1: And ⁓ and I think ⁓ I know if I remember ⁓ I don't know if it was the WannaCry or Lockfor Shell where Nessus went from like five hundred s requests per second to five million which one which one was that? Speaker 2: Yeah, so we d ⁓ so Lock4 Shells is a callback mechanism. So each plugin will call us twice ⁓ per web app, I think. And so I set up the server and you know I see I we push the plugin, we start to see the the calls and it would plateau at five hundred requests a second. Like, ⁓ that's interesting. That's good. But then I like, This is weird, five hundred, that's always five hundred and I realized we were losing most of the requests. So we scaled it up and the right number was five million requests a second. ⁓ when people were doing peak scanning, which was insane. There's a lot of echo. It's not just like it's not two million hosts. It's not two point five million hosts per scan per second, but it's ⁓ yeah, it it was a massive scale. It was a fun experience. Speaker 1: And that shows you the breadth of Nesses. I mean it's still mo one of the most re used products in the world. So kudos to that. Renault, this has been like an ama amazing episode. What's next for you? So you did you did from your you did Bear Token. Are there more projects coming out? Like what's next for Renault? Speaker 2: We'll see what comes up. Speaker 1: ⁓ and when you when we do once that comes out, let's do another episode. Geno, thank you for your time. You're way too generous. ⁓ so good to talk to you. ⁓ looking forward to what to do next. Speaker 2: I don't have a master plan. Thank you so much for having me.