Empowering non-technical users to build production-grade applications requires a proactive, secure-by-design architecture. In this episode, Ashish sits down with Marcus Hallberg and Samuel Kelemen, security engineers at the AI software creation platform Lovable, to discuss how they actively secure AI-generated code and protect creators from supply chain risks. Focusing on solutions rather than alarmism, Marcus and Samuel detail their response to an incident where malicious contractors mimicked AI agent commits. They outline their multi-layered defense strategy: securing a predefined tech stack, utilizing integrated security scanners, and tuning coding agents with strict guardrails to ensure secure output by default. The conversation also covers the evolution of the shared responsibility model in the AI era, the critical importance of foundational hygiene like Git commit signing, and the necessary transition from local "YOLO mode" to secure, sandboxed agent environments. Discover how platforms can leverage AI not just to write code, but to actively assist users in finding and resolving security issues through concepts like "CISO agents."
Questions asked:
00:00 Introduction to Securing AI App Builders
02:00 Marcus & Samuel's Backgrounds and Roles at Lovable
04:30 Empowering Non-Technical Users to Build 40 Million Apps
08:30 Securing Predefined Tech Stacks and Tuning Coding Agents
11:00 Managing Trust When Customers Hire External Contractors
14:00 Addressing Supply Chain Risks with Synced GitHub Repositories
17:30 Educating Users and Developing "CISO Agents" for Support
24:00 Analyzing the Attack: How Threat Actors Mimicked Agent Commits
31:00 The Importance of Basic Hygiene: MFA and Commit Signing
38:30 Moving Agents from "YOLO Mode" to Sandboxed Environments
46:00 The Buy vs. Build Debate for Internal AI Capabilities
52:30 AI as an Educational Tool and Democratizing SQL Queries
01:05:00 Hobbies, Plants, and Pushing AI to Design 1940s Bridges
Ashish Rajan: [00:00:00] We need to delegate our work, but not our thinking
Ashish Rajan: they don't think about this prompt being in English or any other language. It's just malicious
Marcus Hallberg: It's only when you look at the actual source code and the commit itself that you see what they were actually trying to do
Samuel Kelemen: We're empowering a lot more people to write applications
Marcus Hallberg: When our agent writes code, the ultimate way for the agent to do that can be tweaked in certain ways to make sure that the ultimate code that gets written is more or less secure '
Samuel Kelemen: Cause I think most of us are running in YOLO mode.
Samuel Kelemen: We will have, like, asynchronous agents running all the time everywhere.
Ashish Rajan: Imagine being paged on an ungodly hour that someone is trying to access your network and misuse the trust that you have between your customers and the developers. That's the kind of story that I have for you for this particular episode.
Ashish Rajan: I had Marcus and Samuel from a company called Lovable. It's an AI unicorn out of Stockholm, Sweden, and this is a story of how they were able to detect and defend their organization from an abuse of trust between their customers and who the customers hire into their environment. The story is full of drama [00:01:00] and has a lot of learnings for people who are trying to be AI native and want to understand how do you even start defending when the bad people on the other end are happy to spend months trying to figure out how your organization works, how you produce your code, what do you do?
Ashish Rajan: All that in a chilling drama. By the way, there is a full talk that Marcus and Samuel did that I'll link in the show notes as well. But overall, I think it's a great conversation for anyone who is trying to understand how, as an AI company, you could prepare for defending an organization that you work with while being AI forward and AI native, as someone may call it.
Ashish Rajan: I hope you enjoy this episode with Marcus and Samuel, and as always, if you are here for a second or third time and have been enjoying episodes of the podcast, I'd really appreciate if you take a quick second to drop the follow or subscribe button, whichever podcast platform you are watching or listening this on.
Ashish Rajan: We are on Apple, Spotify, YouTube, and LinkedIn. And as always, I appreciate all the love and support you show us [00:02:00] and the programs that we produce here on TechRiot.io Enjoy the conversation with Marcus and Samuel. Talk soon. Peace. Hello, and welcome to another episode of Cloud Security Podcast. I've got Marcus and Samuel.
Ashish Rajan: Hey, man. Thanks for, thanks for coming in, guys. Just to set the scene, maybe Marcus, if you wanna start, give a introduction about yourself, and then we can move on to Samuel. So- Yeah, sure ... just start off.
Marcus Hallberg: So yeah, my name is Marcus. I work here at Lovable as a security engineer.
Marcus Hallberg: I have a bit of a detection and response background, but has focused more on cloud security in recent years. And yeah, just here trying to, uh, make sure that Lovable and our customers are secure
Samuel Kelemen: Hi, I'm Samuel. I'm a security engineer here as well at, at Lovable. Uh, my background spans all of security, so I was originally a cryptographer.
Samuel Kelemen: Um, but I've also been working on authentication, cloud security, all kinds of things. I joined here a few months ago, and I've mostly been working on authorization, authentication systems here, but supporting Marcus as a b- with his, uh, detection and response, uh, skills and workloads.
Ashish Rajan: Awesome. Uh, and I think we are in the Lovable office.
Ashish Rajan: Apparently, the sign that you're working for Lovable, or in the Lovable office, is that you're wearing... [00:03:00] You don't have shoes on. So for people who, who may see that frame ever come out, you'll probably see we're all in socks in the, in the Lovable office. I wanna start with the talk that you guys have had at fwd:cloudsec.
Ashish Rajan: If you wanna set the scene for what inspired the talk, and maybe flesh out some of the information that you can share with the audience about the talk.
Marcus Hallberg: Yeah, of course. So in the presentation that we gave at the conference, uh, we basically walked through one of the attacks we have seen towards our company and our customers.
Marcus Hallberg: So we explained, for example, uh, what we identified, what the malicious actor was trying to do, and then how we sort of went about detecting and responding to that. So there's a lot to be said about what the attempts was and, and the ultimate goal and what we found. But yeah, basically this is a, a good example of how we and others in this industry are being targeted for this, and what we can do to raise the bar for how we can protect not only Lovable, but our customers.
Ashish Rajan: Anything to add to the, to what the description has been, man?
Samuel Kelemen: I think that pretty much covers it. I [00:04:00] mean, we have, uh, an interesting new problem where a lot of our users are less technical than developers have been in the past. Yeah. So we're empowering a lot more people to write applications, uh, and that becomes like a kind of a fertile hunting ground for people to try things against them.
Samuel Kelemen: So it puts a lot of focus on us to try and be there to secure and provide, you know, education and responsiveness, uh, to those kind of threats that we see coming out.
Ashish Rajan: So for people who may not know the scale at which Lovable works, I guess, um, how would you describe Lovable to people who do not know about the company and the volume of, I guess to your point, the, the customers you guys have, so people have some idea for what, what Lovable is about and what you're protecting, I guess?
Marcus Hallberg: Yeah, absolutely. So, so basically our platform provides anyone with the abilities to build any application that they would like to have. So it's anything from founders building their first company to people, individuals who want to create, you know, their birthday webpage. And we really focus on the first thing where we want to, [00:05:00] and we have succeeded to become a platform where people can go and, and basically grown their first, uh, enterprise or idea for things they would like to, uh, turn into an active vision and an active company per se.
Marcus Hallberg: So I think that that's the journey we're on and that where we're continuing to be. And to date we have more than 40 million apps deployed. Uh, we have grown very fast, uh, in the, uh, time we've been around. Yeah. And we're seeing a large, uh, engagement from the community. Uh, and, uh, that we're adding more and more support for building more and more advanced features into our platform.
Ashish Rajan: I'm curious as to in the, uh, time you guys have spent in security, what are some of the kind of things you guys see? Or you, you don't have to be specific in details, but I'm just curious about the general pattern. 'Cause I imagine in the AI native company, as I would like to put place you guys in, uh, the kind of problems you see probably would be quite different to what a traditional company in the previous companies you may have worked for would have seen.
Ashish Rajan: Mm-hmm. What's some of the patterns you guys see and the kind of threats that are newer [00:06:00] compared to, I guess what... I feel, hey, wrong saying it traditional, but I guess- ... it's like traditional is three years ago traditional, but, uh, the logistic non-traditional, what would be some of the example patterns that...
Ashish Rajan: Maybe Samuel, if you wanna start first,
Samuel Kelemen: man. Yeah. Yeah, I think like the fundamentals haven't changed, so like we still need to be worried about where we're getting data, the confusion between data and code. This becomes a bit more challenging when we have prompting, so what is the... Like what is data? What is code?
Samuel Kelemen: That's becoming a even more blurred line. But the, the fundamentals haven't changed, so there's very few things that's, uh, completely new, but there's also like a whole new scale. So we have like scaling both in terms of users, but the number of apps. So as you said, we have more than 40 million apps. We have tons of users as well.
Samuel Kelemen: Uh, but also the, the number of ideas and the, the amount that people own is a bit different as well. So in the past, you probably have a few engineers working on a single app, and now you have single engineers with many apps. So I think just there's like a s- a whole new scale problem.
Marcus Hallberg: Yeah, no, I, I think that puts it really well. And I- Yeah ... I think also, um, the goal is [00:07:00] to enable people, right? Yeah. So a lot of our users are, are, as we mentioned, like non-technical. They have a lot of great ideas, and they're using our platform to build those ideas into reality.
Marcus Hallberg: And where security comes in is like how we create the proper security fundamentals- Yeah ... to secure those things that are being built. So there we work on different levels, so we work with our, uh, coding agent that is writing the software, with our security scanner that is checking the code that is actually being built.
Marcus Hallberg: And alongside that we have other, um, security fundamentals in place to make sure that we raise the bar for what a good application that is getting written is.
Samuel Kelemen: I was gonna say there's a challenge as well in that normally when you're doing security, you have an idea of what you're trying to secure.
Samuel Kelemen: For us, we're trying to empower everyone to make whatever apps they feel are necessary or what they wanna build. And so we're thinking about how do we secure things that we don't even know what it is they're, they're building.
Ashish Rajan: How do you approach that? 'Cause I guess to your, to your point... And the reason I ask is because a lot of people in a wider community of security as well are thinking about this problem, right?
Ashish Rajan: 'Cause a lot of people have never [00:08:00] been... Well, let's just say, I mean, many of us didn't even work in AI for a long- forever. Now suddenly all of us are using LLMs, we're using ChatGPT, Claude, insert another new model that comes out tomorrow or by the time this recording comes out. You f- you find that, uh, it's a really unknown territory for a lot of people.
Ashish Rajan: How do you even start planning for something that you don't even... A- and I mean from a security perspective. Obviously, as an organization, it's a very big question. But even as a security team, you're l- approaching this problem that, hey, now we are slowly starting to have more... one engineer with 10 different vibe coded apps that he or she thinks that is the right thing for them to use, and then the- maybe it's inside the organization, maybe it's outside the organization.
Ashish Rajan: How do you even start approaching that problem? And I don't know, Marcus, you wanna start first?
Marcus Hallberg: Yeah, so, so there, there's a lot of things, right? So first, first of all, the way we do it is that we have a predefined tech stack for how apps can get built- Right ... for example, right? So what we do is that we look at that tech stack, and we try to make sure that every level of that is, in [00:09:00] a way, secured, in a way, so that it makes sense in having checks and balances in place.
Marcus Hallberg: So for example, how does authentication work when you build an app? Uh, where's the data stored? How is that, uh, managed? So for each of those layers, we have different, uh, security mechanisms that we introduce.
Samuel Kelemen: Yeah.
Marcus Hallberg: But to your point, this is a, i- it's, it's hard to know what's secure when you don't know what is being built.
Marcus Hallberg: Yeah. So that's where we're also, for example, making sure that when our agent writes code, that we test that, and we have that feedback loop to say, "Okay, a customer who's trying to build this type of application, the ultimate way for the agent to do that can be tweaked in certain ways to make sure that the ultimate code that gets written is more or less secure."
Ashish Rajan: Yeah.
Marcus Hallberg: And then we have other checks like the security scanner and other features that happens once that is being put in place. So we try to address each and every level, but because we know the tech stack that the app gets built on, we have some knowns that we can work, uh, with basically.
Samuel Kelemen: I think also the industry is starting to realize that there's also a bit of a education thing here as well.
Samuel Kelemen: [00:10:00] So when we have non-technical users, uh, it doesn't mean we can just solve everything automatically. We will try to do our best to do so, but there's also some things where we wanna try and put education out there for people to learn. Yeah. And I think one example of how we're trying to do that with AI is, like, we're going to have a series of co-founders, uh, where you might have, like, a CISO agent or something that kind of, uh, is trained specifically to look for security issues and resolve those.
Samuel Kelemen: So I, I think that there's more of a complexity here where we're not just working in, like, the technical field, but also, uh, with, with people.
Ashish Rajan: Yeah, yeah. And to your point, there would still be gaps that are human-led, would always be human for lack of a... I mean, I still wanna prefer, prefer- preferably talk to Samuel rather than just talk to the agent of Samuel.
Ashish Rajan: Yeah. But do you, do you find when the, the talk that you guys had In what you discovered, how much of it can you share in terms of the investigation, forensic? What... I don't know how, how far or what you can share, but I'm curious as to hear what, what you can share about some of the things that you did [00:11:00] and to find it, to isolate it, to mitigate it, all of that.
Marcus Hallberg: Yeah. We can go into some detail, of course, and, and the majority, uh, of, of that is also in, in our presentation, right? Yeah. But, but to put it short, like, one of the... We, we have multiple tools that we use from, from the security team standpoint to both makes app secure, but also to analyze what those apps are doing, right?
Marcus Hallberg: So one of the major points in our talk for how this attack that we discovered happened was the misuse of trust. Mm. So for example, uh, if you're building a Lovable app and you want support, and you might, uh, get help from some other developer or from some other, um, person that you trust, uh, and you give them access to your, to your platform, to your project, and then that person is introducing those type of malicious artifacts that we found, that's something that is, like, it's not something we can prepare for, but it's something we can try to respond to and help our customers to avoid.
Marcus Hallberg: Yeah. But ultimately, it's not about the security of our platform, but it's [00:12:00] about that human element- Yeah ... that we talked about, where people trust others with the access to do the right thing. And this particular example was very interesting because we found, once we had done the complete analysis, that this specific threat actor had been, um, doing these techniques and refined it for a very, very long period of time, more than a year.
Marcus Hallberg: Right. And ultimately, the goal there was to get access to customer projects, getting the credentials, getting access to the actual applications being built. Yeah. And this is something that it d- doesn't only happen to us, it happens to others, and AI doesn't change that. But the way AI is being used to build and ship applications kind of makes that scale harder to address.
Marcus Hallberg: Mm-hmm. So I don't think this is the last thing that we as an industry will see- Yeah ... but it's definitely a new angle to those same problems we have had in the past.
Ashish Rajan: Sounil, do you want to add anything to what was called out?
Samuel Kelemen: Yeah. I think it becomes very challenging when you think about the breadth at which people are using AI.
Samuel Kelemen: So there's a lot of integrations, [00:13:00] right? So we have your Git, uh, repo, which holds all the code for your project in Lovable, but you can also sync that to GitLab or GitHub as well. So we have to think about not only the trust model of inviting a developer to work in your project in Lovable, but you might also in- invite developers to work on other platforms, like GitHub or GitLab.
Ashish Rajan: Yeah.
Samuel Kelemen: And so because the agent can pool code from GitHub that you've attached to your project, uh, any time you add an external person to your GitHub repo, they can also affect your project as well. So there's, like, a little bit of a, a challenge in seeing, like, we don't always have full visibility everywhere.
Ashish Rajan: Yeah.
Samuel Kelemen: And we still need to respond to support people to deal with those kind of trust issues.
Ashish Rajan: To, to your point, would this be the question of supply chain again then? Mm-hmm. Where... And, and I think we were talking about this earlier as well. Like- Obviously, uh, uh, actually, I'll let you expand on the supply chain thing first before I go into my question.
Ashish Rajan: So I guess, how would you expli- explain this supply chain in the context of the security for AI applica- AI-assisted or AI-built [00:14:00] applications?
Marcus Hallberg: Yeah, and, and this is interesting 'cause I think one, one of the things that we do, which Samuel mentioned, is, like, we, we give, uh, our creators access to their own source code, right?
Marcus Hallberg: Yeah. So the code that they own and that they build, we wanna make sure that they have access to that. And GitHub, uh, having re- repositories synced is one way to do that.
Samuel Kelemen: Yeah.
Marcus Hallberg: But that also opens up another threat vector for us, right? So by our customers having the repository synced and having, for example, uh, other developers helping them, that opens up that separate, uh, angle basically for us to address.
Marcus Hallberg: And we, um, like, it's not our GitHub organization, it's hard for us to, to say, "This is what you can or cannot do." Yeah. So this is where the, the trust and, and safety model becomes relevant to talk about, right? Yeah. What can we secure, and what can we do to go beyond that to help protect our customers? Yeah.
Marcus Hallberg: So I think this is something that both we and industry are right now sort of expanding on and trying to see, like, what is the best angle here? How can we make sure this is being done in a safe way? But I mean, this is taking, I would say, the [00:15:00] supply chain angle and adding that to, uh, AI-built applications, right?
Marcus Hallberg: Yeah. So it's, it's bridging multiple problems into one. Yeah. And that's where we are actively working to put as much guardrails as we can into place.
Samuel Kelemen: I, I think it's also, like, a convergence of the supply chain issue and then the internal, like, uh, disgruntled employee kind of threat vector as well, right?
Samuel Kelemen: So-
Ashish Rajan: Oh, yeah, 'cause in that context, technically now your customer's become a internal disgruntled employee in a way.
Samuel Kelemen: Yeah, exactly. So if you invite other people to work on a project or collaborate with you-
Ashish Rajan: Yeah ...
Samuel Kelemen: they're essentially like another employee, right? They have all the same access that an employee would in a bigger company.
Ashish Rajan: Yeah.
Samuel Kelemen: And then it becomes a little bit of a, a complication when you want to say, "Do you trust this person?" And I think we've discussed before, like, trust is never, like, a binary thing. Yeah. You have, like, you know, a sliding scale of where you trust someone to do some things but not other things.
Ashish Rajan: Yeah.
Samuel Kelemen: Uh, you know, I trust my doctor to do surgery, but I don't trust him to be my accountant- Yeah
Samuel Kelemen: or my lawyer, right?
Ashish Rajan: Yeah.
Samuel Kelemen: Uh, so I think this is becoming, uh, more of a problem that we have to think of in the industry as [00:16:00] well. How do we collaborate effectively? Like, what does trust mean? How do we explain these trust boundaries to, like, non-technical users? And I, like, I think it makes sense. Like, I think everyone wants their customers who are building products and, and companies- Yeah
Samuel Kelemen: with AI to eventually get to the point where they wanna hire people, right? Yeah, yeah. Like, that's a success story for us. That's right. Yeah. And how do we make that not so scary?
Ashish Rajan: Do... What do you recommend to the people who are building on Lovable who would have an external dev- Uh, 'cause I guess, and correct me if I'm wrong, at least Lovable closes the gap for me being a non-technical person to having an idea to having a prototype in my mind that I can potentially work on, make it production ready, and all that.
Ashish Rajan: Now, the production ready part is where I'm calling an external developer, putting GitHub, all of that. What do you guys recommend for- people who would be listening to this who are Lovable customers. Like, how can a Lovable customer keep themselves safe from, uh, potential hacks or whatever [00:17:00] else you know you...
Ashish Rajan: I mean, I guess hack's a pretty broad term these ti- uh, with AI 'cause I don't even know what that would be like in this particular context. But w- what's your general recommendation to pe- Lovable customers for how to stay secure with the unique ideas that they have built on your platform? What do you recommend to them?
Marcus Hallberg: I, I would say the, the, uh, the default there is, is what we tell pretty much everyone, is to use the security features we have built into the platform. Yeah For example, from a code security standpoint. Uh, when it comes to this specific problem that our presentation addresses, which is, like, the social engineering aspect or you inviting somebody who turns out to be malicious, I think that's something that is ultimately hard to, like, prevent.
Marcus Hallberg: Yeah. I think what we can do and what our customers can do is to sort of see, okay, so who is this person? Is this coming from, uh, for example, a, a company with a good reputation? Do I know who they are? Can I verify what they do? So for example, in this case, if we talk about inviting them to the, uh, project or into the GitHub repository where the customer's code exists, [00:18:00] to have a ways to see, okay, uh, what changes have they made?
Marcus Hallberg: Again, our, our users are mainly, say, non-technical. Yeah. But I think there are a lot of, um, measures that can be taken to sort of reduce that risk. The risk will still be there.
Ashish Rajan: Yeah.
Marcus Hallberg: Um, but again, we want to make sure we have enough, uh, guidelines, educations, and tools to basically empower all of our users and founders to build safely with Lovable.
Ashish Rajan: Yeah.
Marcus Hallberg: And I think it's also important to raise that this specific, uh, discussion that we're talking about is not really about the security of the platform itself, right? It's more about you giving your, your keys to your house to, you know, a, a, uh- Contractor ... a carpenter or a contractor, and then that person, uh, does a burglary, right?
Marcus Hallberg: Yeah, yeah. So it's, it's hard to prevent, but again, I think some of those things that we covered here is what our general recommendations would, of course, be. And if you are un- secure that something did... This looks weird, what is this, Lovable support is always there. You can always reach out to them, and they can involve us- Yeah
Marcus Hallberg: to help [00:19:00] you, uh, uncover what that was.
Samuel Kelemen: Yeah. Uh, I think also, like, this is not a platform nor an AI problem, right? This problem has always existed. Yes. And even outside of, like, technology, right? If you had a, a co-founder that, you know, you... that betrayed your trust, let's say-
Ashish Rajan: Yeah ...
Samuel Kelemen: uh, that was always an issue.
Ashish Rajan: Yeah.
Samuel Kelemen: Um, so there's nothing new here. It's just something we're trying to give you the tools to, to handle. Um, but I think that Lovable and AI will eventually be, like, the more secure place to build. Like, there's a fixed number of vulnerabilities, right? So, uh, we've been r- operating as security engineers in, like, a state of imperfect information.
Samuel Kelemen: The closer we can get to perfect information and know everything, uh, the faster we'll solve all those vulnerabilities and the more secure we can be.
Marcus Hallberg: Yeah.
Samuel Kelemen: Uh, so I think that, like, there's a lot we can do to make building with AI more secure- Yeah ... especially in the sense that we have, like, places where we can do automation.
Samuel Kelemen: We have places where we can do deterministic scans. We have places where we can do, uh, non-deterministic [00:20:00] scans with LLMs, and we can also, um- Find solutions that allow you to maybe know less, right? So I think there's a shared responsibility model and a bit of a trust model as well, where we have to deci- decide what, you know, Lovable does, what the AI does, what the end user owns.
Samuel Kelemen: Um, but in general, I, I think there's a lot of space here where we can actually become, uh, more secure than other solutions. Like, if they were building this without a platform or without AI, they would have all the same issues and no support. So I think it's a bit of like a... When you had the cloud- Yeah
Samuel Kelemen: transition, there was, like, a lot of, uh, people questioning the, the security model of the cloud- Yeah ... and the shared responsibility model.
Ashish Rajan: Yeah.
Samuel Kelemen: But I, I think most people realize now that if you're a small team, moving to the cloud comes with a lot of benefits. There's a lot of smart people and a lot of both, uh, attackers and defenders that have been working on maturing the cloud platform, and I think that will be true for all the AI platforms as well.
Marcus Hallberg: Yeah.
Ashish Rajan: Do you find that people are building cloud [00:21:00] infrastructure with Lovable apps as well? Like, does it extend from GitHub to infra, all of that as well? 'Cause I imagine an app being production-ready has to now extend not just to, hey, my code gets pushed out to GitHub, doesn't really matter, Node.js, TypeScript, whatever, but I also need the back end to host it on.
Ashish Rajan: Mm-hmm.
Marcus Hallberg: Mm-hmm.
Ashish Rajan: Are people even connecting that onto Lovable as well?
Marcus Hallberg: So there's multiple deployment models that we provide. Yeah. I think the default one, which is I think the really impressive thing, where our customers can have, you know, from a one prompt, they get a fully deployed public-facing application that with a back end, front end, everything combined.
Marcus Hallberg: Oh, wow,
Ashish Rajan: okay.
Marcus Hallberg: So I think that's, that's where the strengths comes in. Like, we have all those parts of the stack combined for our customers to- Yeah ... basically turn their ideas into reality. Um, and I think with that we're also adding other models to that as well, how we can, for example, connect your own infrastructure, and that's something I think we will see, um, develop over time.
Marcus Hallberg: Because we wanna make sure we have, uh, any type of, uh, foundation in [00:22:00] place to support where does our customer's journey lead, right? Yeah. Yeah. So we want to be with them on that journey.
Samuel Kelemen: Yeah.
Marcus Hallberg: Um, but I think with that in mind, it's also, uh, pretty interesting to, to see that- I mean, for me w- with my background, I, I always realized or, or thought like, "Okay, I need to learn, you know, database.
Marcus Hallberg: I need to learn front-end, back-end for me to build an application."
Samuel Kelemen: Yeah.
Marcus Hallberg: And what we can do now is instead allow the ideas to be in the first, uh, part of that journey, right? Yeah, yeah. So making sure that all those things sort of happen underneath. But yeah, o- our model will definitely develop going forward for how you can deploy your ideas and applications and infrastructure.
Ashish Rajan: Yeah. And I mean, uh, 'cause I think we haven't unpacked the, the scenario, 'cause we mentioned social engineering. So what was... I don't know, maybe Samuel, if you wanna kinda give it, give it a shot as well. Uh, what was the, uh, social engineering scenario? How much can you share about it? I think, what's in the talk, I guess, 'cause- Mm-hmm
Ashish Rajan: I mi- I have to imagine a lot of people may not get to the talk, and so this is one, uh, teaser into it so they can go and watch the talk online when it's available by [00:23:00] fwd:cloudsec. How would you, uh, what's being talked, spoken wi- uh, spoken in the talk for people to have some insight?
Marcus Hallberg: Yeah, I, I can, I can answer it. So, so what we saw was basically a v- variety of techniques. Yeah. So I think the most common one, um, that I think makes sense to a lot of people was that we had, um, customers that basically hired what they thought were, um, actual developers- Right ... who would help them build their application on Lovable.
Ashish Rajan: Yeah.
Marcus Hallberg: So usually, um, small companies or, or startups that were just turning their ideas, and they basically wanted to have someone that they thought had the experience to, to help them do that, to achieve their goal basically. Yeah,
Ashish Rajan: yeah.
Marcus Hallberg: Um, and then those, uh, people turned out to be part of the malicious, uh, actor group that we tracked.
Marcus Hallberg: And, uh, in, in the beginning what we saw was that they were acting as regular developers. You know, they would make code changes. They would make sure it looked like, "Oh, yeah, I'm building your app for you. This is fine." And then over time what we saw, because we were tracking both the group that were experimenting in their [00:24:00] own attacker-owned projects- Yeah
Marcus Hallberg: and then in the customer products themselves. So when we did the full investigation, we could see that as the attackers were developing, uh, new techniques and they were refining the malicious code they were introducing, they would first test that on their own projects, see that it worked, and then they would weaponize that and try to implement that into the customer projects.
Marcus Hallberg: Wow. And this is something that is common in the industry, but it's something that, uh, it's really hard to, you know, to, to discover unless you, you know what to look for.
Samuel Kelemen: Yeah, yeah.
Marcus Hallberg: And this is part of the problem as well. So, um, one of the things that we saw was, for example, that they had tried to understand how our agent work and when the agent made updates.
Marcus Hallberg: So, uh, as an example, we had a customer that was, uh, basically giving a regular instruction to our agent saying, "Oh, can you change this link with that?" Uh, in the chat message you get this little notification that says, "Oh, this, uh, commit happened."
Ashish Rajan: Yeah.
Marcus Hallberg: Uh, I think it was 1.5 seconds after, uh, an [00:25:00] exact ideal prompt appeared again.
Marcus Hallberg: Same message, same everything, but in this case it was the attacker who was listening to the Git commit happening.
Ashish Rajan: Yeah.
Marcus Hallberg: Then they fired an exactly similar looking one, but with the malicious code introduced. Oh. So from the user standpoint, it looked like, "Oh, this is the same change maybe."
Ashish Rajan: Yeah.
Marcus Hallberg: And it's only when you look at the actual source code and the commit itself that you see what they were actually trying to do.
Marcus Hallberg: So they were trying to mimic this way so that for the customer it wouldn't be obvious, you know, what, what was happening.
Ashish Rajan: Yeah.
Marcus Hallberg: And that is what we sort of uncovered and ultimately, uh, reached out and, and informed people about.
Ashish Rajan: Interesting. And, uh, along the j- 'cause it's almost like there's so many moving parts here as well, 'cause I'm glad we kind of started where, what you guys do and what you guys allow customers to do.
Ashish Rajan: So it kind of shows you the depth and the volume of this as well. Mm-hmm. 'Cause I also think for people who are building, uh, applications, perhaps may not be for 80 million people, 40 million people, but Internal stakeholders, there are over companies with 400 internal applications, multiple [00:26:00] of them. And we spoke about a lot of the people have would hire contractors, would bring external contractors, would, uh, come into the GitHub port system as well.
Ashish Rajan: Even internally, this is a big challenge to solve- Yes ... for a lot of people. It's not gonna leave it all, if someone external doing it. Like, even internally, if I was to introduce a contractor, um, and who was just malicious intent-
Samuel Kelemen: Mm ...
Ashish Rajan: how would I even go about doing this in an AI world? 'Cause to, a- and, uh, the, where, the nuance that I'm going for is a lot of people look at this as, "Hey, I'm looking for SQL injection, cross-site scripting.
Ashish Rajan: Am I doing static?" 'Cause it mostly people think of code as, I have put static credentials. I have a s- a static code problem. I have a my library is vulnerable problem. I have a, I don't know, runtime security problem. They don't think about this a prompt in, in English or any other language that's just malicious.
Ashish Rajan: How do you even approach this? 'Cause I imagine that's the question g- going in people's mind. How do I do that for myself in the GitHubs that I have to [00:27:00] even know that someone is doing this with our GitHub? Is there a, is there a framework for this?
Marcus Hallberg: Uh, I mean, I think it's, on one hand it's the same problem we've always had, right? So again, it's that sort of malicious insider type scenario.
Ashish Rajan: Yeah.
Marcus Hallberg: So, uh, some of those default, like, ways of going about it are the same. Like, so for example, you have, uh, and again, this is just more if you're a technical person, like, how, how, like, wh- where do you approach this, right?
Marcus Hallberg: Yeah. So ultimately you have, for example, all the Git history. Uh, there are ways to go about that. Also, there are ways that you can try to modify Git history, circumvent that. Yes. Again, it depends on what is the level of access does this malicious insider has.
Ashish Rajan: Yeah.
Marcus Hallberg: Do they have full accessibility to this GitHub repository?
Marcus Hallberg: Uh, are they only in, uh, the Lovable project and can make, uh, code changes in the UI? So again, it, it's all of those different levels. Yeah. But ultimately, with the type of, um, you know, logging that can be reviewed, uh, having measures to kind of look for those breadcrumbs, if you will, [00:28:00] there, th- those opportunities are there.
Marcus Hallberg: But to be fair, it's very hard, right? Yeah. And we, we can't expect our customers to be, you know, forensic analysts- Mm ... or to, you know, have the full security engineer mindset. But what we can do, and what we are doing, is to basically provide enough tooling and knowledge and, and basically intelligence for them to, um, know where to start looking.
Marcus Hallberg: And this is, again, an educational journey for both them and for us. Yeah. So I think it's about, again, raising that bar for if something malicious were to happen, what are the capabilities that we have, both here at Lovable, but also from our customer standpoint to look into it. But again, it's a problem that has been there for a long time, and this is gonna continue to be there, and it's just now gonna have the sort of, uh, AI angle to it as, as well.
Ashish Rajan: Yeah.
Marcus Hallberg: So I don't see this more as, like, this is a new problem because of how AI is, is being used to build applications. It's, like, how you use standard techniques to get, uh, [00:29:00] unauthorized access, trying to hide what you've been doing, et cetera. Uh, and that's, that's the, the race that we have, basically, and that we're on, and that we are trying to always be one step ahead and make sure that we have the right, um, capabilities in place to support, uh, our customers and ourselves.
Samuel Kelemen: I, I think security event monitoring has always been a, like, difficult thing. We all work in distributed systems now. We have many different, uh, providers and features and products that all contribute to, like, what is security. Uh, so security is like a cross-spanning thing. We've always had to consider everything.
Samuel Kelemen: Uh, so right now we have things like Lovable and GitHub, so we have events being driven from both sides, right? I think I'm very optimistic about how AI will allow us to have a better overview of all these systems together, because now we can ingest all those events somewhere and then use AI to really have an omnipresent, omniscient view on things and find these kind of vulnerabilities or indicators of compromise faster, and then raise that to someone who can do something about it.
Samuel Kelemen: And hopefully, AI can be one of those people who does something about it. So if I'm in a company right now, I don't know, I'm just trying to make a, name a company. Let's just say company XYZ- Mm-hmm ... who has 400 internal applications, they're all running on GitHub, and I've given access to, uh, hey, let's just...
Samuel Kelemen: Everyone has Claude Code, let's just say. Claude Code access, everyone's building agents, everyone's deploying code using Claude Code. Uh, 800 lines of code. I'm not gonna talk about the commit part, but let's just assume that one of them has, is a contractor who is the one with the malicious intent. So to your point, if I am keeping an eye on[00:30:00]
Ashish Rajan: the GitHub logs of the commit history for changes- And using an AI as an overlay on top of that to understand, hey, these, these streams of lo- information coming in, which one of these is just a, quote-unquote, kind of malicious that we should look into versus it's just me asking for a change of link? Mm. Is that, is that a good framework to kind of look at this problem as?
Ashish Rajan: I
Samuel Kelemen: [00:31:00] think there's, like, always been, like, a hygiene thing, right? Yeah. So, uh, we all get distracted by the flashy new thing. We have AI, we have, you know, all kinds of fancy t- new tools, but it comes back to, like, the security fundamentals. Mm. Like, do you have good hygiene? Are you using MFA places? Uh, one of my favorite tricks is I always add Marcus on all my commits-
Samuel Kelemen: as a, as a co-contributor. Yeah. And then I have Cursor open the PR. So then I merge, like, all my commits with, uh, you know, him as the author and with Claude as the PR author.
Ashish Rajan: Yeah, okay.
Samuel Kelemen: Um, so you know, there's ways to avoid this. If we were using commit signing- Mm-hmm ... you wouldn't be able to do this kind of impersonation thing.
Ashish Rajan: Yeah, yeah.
Samuel Kelemen: Um, so I think there's things that we've been, um, not very good at as an industry of adopting, like commit signing. Yeah. And I think all developers have some feelings about this.
Ashish Rajan: Yes.
Samuel Kelemen: Um, but the- I
Ashish Rajan: mean, there's, like, whole another problem of should I use my own GitHub account versus a company GitHub account?
Ashish Rajan: There's a whole another problem for that as well, but- Yeah ... I'll let you talk about the signing part for now, I guess.
Samuel Kelemen: But I mean, we all know that, like, there, there are these things we can do, and I think they haven't been [00:32:00] prioritized. Yeah,
Ashish Rajan: yeah. So,
Samuel Kelemen: uh, I think in general, like, there are, are things we can do here.
Samuel Kelemen: We just have to accept that we need to do them and- Mm ... you know.
Ashish Rajan: So GitHub hygiene would be something you guys would like. I mean, I guess two part because a lot of people look at that as a third party thing. Mm. They don't look at that, oh, we produce code. The, the, the problem of- be asking developers to use a company GitHub account versus a personal GitHub account because the number of commits, and developers are gonna hate me saying this, but it's like- Mm-hmm
Ashish Rajan: I think people are afraid that, oh, uh, the number of commits that I have for a year would reduce.
Marcus Hallberg: Mm.
Ashish Rajan: Yeah. And like, what difference does it make? But then like, oh, it's a, for them, it's a street cred- Yeah. Yeah ... that I have committed this much into a code. I
Samuel Kelemen: mean, that street cred is completely gone. Like, GitHub statistics mean nothing anymore.
Samuel Kelemen: We're all the top one developer with a million commits now.
Marcus Hallberg: Yeah. Yeah.
Samuel Kelemen: Um, but I think that there's also some sort of industry question about, like, delegation versus impersonation. Mm. Like, if you are using these AI tools, uh, should the tool itself have an identity, and [00:33:00] should that say that it's being, using delegated access, for example?
Samuel Kelemen: Yeah. Hm. Or should they act as me, right? If- Yeah ... like, in the, your logs, would you like to see that Samuel made this change even though it was my agent?
Ashish Rajan: Yeah.
Samuel Kelemen: Or would you like to see this agent made the change using Samuel's credentials? Hm. Yeah. Uh, I think that's, like, a bigger question. Like, how do we attribute, uh, these tools?
Samuel Kelemen: And I think they should be attributed.
Ashish Rajan: Yeah.
Samuel Kelemen: It shouldn't just be like, uh, you know, people are... Like, the AIs are taking more of my work, right? Yeah. Um, but they're not exactly me, right? They don't have the d- same decision-making capability I have.
Ashish Rajan: Yeah.
Samuel Kelemen: So I think there is a bit of a difference whether I made the change or an agent did my change.
Samuel Kelemen: And also, the threat model is slightly different, right? The agent can be, like, influenced in different ways than I can be influenced, so- Yeah ... if we're using model providers, the model provider could change and have some effect. We have the prompt injecting thing.
Ashish Rajan: Yeah.
Samuel Kelemen: Um, there, there's lots of questions, and I think that's still an open area of exploration in the industry.
Marcus Hallberg: Yeah, and, and I think, like, from a cloud provider perspective, you've had this problem before with, for example, [00:34:00] service accounts. Yeah. So before, when you had only, say, service account keys, you only knew, like, well, this service account did X, Y, and Z, but you didn't know, well, who was using that service account key.
Marcus Hallberg: Mm. Like, sure, you could correlate with IPs and see maybe some of the events in your audit logs, but then you had, for example, service count delegation and impersonation. So now you knew that, oh, this service account was used by Samuel or Marcus to do X, Y, and Z. And I think what we're seeing now with the introduction of, you know, uh, AI and agents and AI-driven development, we have the same sort of problem space, but this is now much more broader because it's not only my, you know, Google credentials, it's also any API keys or other credentials I have locally that I tell my agent to use or that the agent thinks it's, it's gonna use.
Marcus Hallberg: So I think that's where we... And I, I think we see some improvements of that in the community, but I think it's still, like, early days for how that same solution to that problem is gonna have to be, like, [00:35:00] recreated for, uh, all of those types of identities that the agent, uh, can ultimately use.
Ashish Rajan: Do you c- do you find- Have-- Maybe I'll, I'll ask this, 'cause a lot of people, um, in the advisory that we're on, we are talking a lot about Claude Code rollout, Codex rollouts as a strategy for the entire organization.
Ashish Rajan: 'Cause some people have already gone past speed boarded, like, kind of what you guys have done. Some people are starting today with, "Hey, we're gonna introduce Claude Code and Codex into the organization." What do you think ideally Now that you guys have done this for some time, what do you recommend to other people for how to approach this?
Ashish Rajan: 'Cause to your point, identity is a thing, GitHub signing is a thing. There's, like, so many moving parts to this. Mm. It's not just that, hey, I have installed Claude Code using security best practices that are Claude called, Claude co- Claude called out. Mm. So many Claude in my words, right? Yeah. Uh, let's just say Anthropic called out a security best practice.
Ashish Rajan: Mm-hmm. And am I good? I feel like the answer here is no. You- that's just their part. Mm. You have your part, kind of to what you said [00:36:00] about the shared responsibility we had in- Mm-hmm ... Cloud. How would you recommend people who are introducing this now in their organization? Mm-hmm. What can they learn from the experience you guys have had?
Ashish Rajan: Mm-hmm. And, uh, I mean, it could be an ideal scenario, so it doesn't have to be exact, but I'm just- ideally, what would you recommend people approach it as, and is there a good starting point?
Marcus Hallberg: Yeah, so I think there's a couple of things. So if we, if we look at first the problem, like, how should, you know, developers use, uh, Claude Code or AI to develop code safely?
Ashish Rajan: Yeah.
Marcus Hallberg: And I think there, there are, um, a lot of guard- guardrails that can be set. For example, if you're working in a repository, you can have, uh, predefined skills and MCPs and, and, uh, you know, other type of knowledge docs that you sort of point your agent to so it knows that, okay, if I'm gonna build this new feature in this project, these are sort of the guidelines that go with that as a sort of a default for how the agent sh- should operate.
Marcus Hallberg: But I think ultimately it depends on what problem are you trying to solve. So if, if it's like, oh, now you [00:37:00] have this fantastic tool and you're gonna use it for everything, you probably want to decide when to use it and when, when not to use it. Yeah. And also from, like, from an educational standpoint, teach, uh, the developers how to do it safely.
Marcus Hallberg: Mm. So for example, if you are telling a- an agent to do something and you ask it first, "Oh, can you create this plan and tell me how are you gonna solve this problem?" Then you quickly can see is that what you had in mind, or is the agent, uh, maybe doing something else that you initially intended? And similarly, when that plan gets executed by the same agent or another agent or another tool, what was the result of that plan?
Marcus Hallberg: Mm. And there are some, uh, I think, good practices for this already, where you can run, uh, you know, tests in a local sandbox, or you can sort of try to see as that execution happens, uh, if that is what you intended or not. Yeah. So I think it's both from an organization and, uh, a personal developer experience, how we s- put the right guardrails in place, and also how we educate users-
Ashish Rajan: Yeah
Marcus Hallberg: [00:38:00] um, on that journey.
Ashish Rajan: Yeah. So.
Samuel Kelemen: I think that right now we're talking about, like, AI guardrails. Yeah. But we also had guardrails before. Like, all developers make mistakes-
Ashish Rajan: Yeah ...
Samuel Kelemen: and we need to catch those mistakes as well. So we had things like CICD, uh, unit testing, integration testing, and I think all these things still matter even more than ever.
Marcus Hallberg: Yeah.
Samuel Kelemen: So I think when we're working with AI, we need to delegate our work, but not our thinking. And I think that the engineering becomes even more important. So like we need to figure out, okay, the AI will make mistakes. I make mistakes. I think Marcus also makes mistakes sometimes.
Marcus Hallberg: Yes.
Samuel Kelemen: Um, how do we reliably handle those mistakes in a safe way?
Samuel Kelemen: So do you have good CICD testing? Do you have, uh, yeah, I don't know, integration testing? Like, do you- I think you should think what can go wrong and how would you stop that from happening or from having a large impact, right? Yeah, yeah. So, like the AI never has to be perfect. Humans aren't perfect. It just has to be good enough or, or slightly better than humans [00:39:00] for it to be adopted, right?
Samuel Kelemen: And I think there's also a difference between like the output from an agentic workflow. So like we said, we're writing code, we have tests, uh, we can do that to a high quality. Uh, but also like how do you secure the workspace where the agent is doing its work, right? So we also are running on our machines, I think most of us are running in Yolo mode-
Ashish Rajan: Yeah.
Samuel Kelemen: uh, whether we can admit that to IT or not.
Ashish Rajan: Dangerously skip permission.
Marcus Hallberg: Yes.
Samuel Kelemen: Yeah, exactly, right? Dangerous everything.
Ashish Rajan: Yeah.
Samuel Kelemen: Um, but I think in the future we'll see more things running like in a VM or in a sandbox.
Ashish Rajan: Yeah.
Samuel Kelemen: And there's lots of reasons for this. One is like the tools that the AI needs are different from the tools that I need.
Samuel Kelemen: Yeah. I need to understand my daily working environment. Um, but I think there's also like valuable, uh, other things for us. Like, I would like to be able to start a session, uh, with an agent and then connect to that session when I'm on the boat, for example. So I- I'm lucky enough to live in Stockholm where I can take a boat to and from work, and I think that [00:40:00] AI is very good at this, um, kind of area where you have some ability to interact with it, but your focus isn't like fully in, in that moment, right?
Samuel Kelemen: Like I can't really program when I'm on the metro-
Ashish Rajan: Yeah ...
Samuel Kelemen: but I can like influence the agent when I'm on the metro.
Ashish Rajan: Yeah.
Samuel Kelemen: So if I can start, you know, some sort of agentic workflow or agentic engineering process, uh, on my computer and that's somewhere in the cloud or in a sandbox where I can connect to that from my phone and continue working from my phone, I think that solves a lot of issues both in like the usability of AI, um, but also in the security.
Samuel Kelemen: So we can lock down that sandbox. We have complete logs for that sandbox. Uh, we can have like policies and GRC around that sandbox. Yeah. But also each person and each engineer kind of gets a better user experience as well.
Ashish Rajan: Yeah. Yeah. And I guess to your point, it's a, I guess one, one thing to call out, and I don't know if you guys agree, but it's a staged progress as well.
Ashish Rajan: 'Cause initially many developers would start on their laptop with the dangerous skip permission. Mm-hmm. Mm-hmm. And then you almost need to graduate from there to your point of education. Mm-hmm. Use education as a way [00:41:00] to go, "Hey, I, I get it. You want to be able to be dangerous skip permission so you're not always saying yes for every action."
Ashish Rajan: But then the, the next stage after that is, okay, let's just introduce a virtual machine or some kind of remote access to this, to sandbox somewhere which hey, yeah, do dangerous skip permission doesn't really matter 'cause it's not a lot of sensitive files. It doesn't have a text file on the desktop with your username, password for the VPN- Yeah
Ashish Rajan: or whatever the thing may be, right? Mm-hmm. And I think, I guess a lot of people are in that journey where they think, "Oh, I have to go to a sandbox from get go." I don't know if you agree with it, but I feel like- You would probably... It's the same thing when people introduce SAST testing for a lo- first time.
Ashish Rajan: Mm. There's so much false positive. It's too much restrictive in the beginning. I feel like almost, uh, a lot of people struggle with the fact where if I start introducing a sandbox in day one, they're like, "Hey, I ca- I don't have access to production data."
Marcus Hallberg: Mm. "
Ashish Rajan: I don't have access to this." The, the, the, the number of reasons why it does not work just, it exponentially grows.
Marcus Hallberg: Yeah.
Ashish Rajan: Mm-hmm. But if they, oh, you know, like, the maybe the right way to do it, I need to [00:42:00] figure out to what you said, hey, what's the governance I can in- what's the skill that I can introduce in the Claude Code code being produced that, hey, every time you write, use a skill as a guideline for, hey, this is how we write.
Marcus Hallberg: Mm-hmm.
Ashish Rajan: This is the things we... Like, uh, is that a better staged approach? Because obviously sandbox may not be day one possibility for a lot of people. I don't know if you guys agree.
Marcus Hallberg: I, I think, yeah, I, I do agree, and I think it also depends again on, like, what problem are you trying to solve?
Ashish Rajan: Yeah.
Marcus Hallberg: So I think it's fine if you run, say, with, you know, uh, skip permissions or run dangerous permissions if you are, say, doing something locally, right?
Marcus Hallberg: Yeah. So you, let's say you wanna write up your meeting notes, or, "Oh, I have this to-do list I need to do. Can I get some help to create a plan out of that?" You should probably not do it with your, you know, Kubernetes credentials- Yeah ... uh, to go and say like, "Can you fix this- ... uh, application for me," right? No.
Marcus Hallberg: And I think it's the same, uh, journey both for people who use AI and also for, uh, those that build, uh, the LLM and the agents. Yeah. And I think one example there is in the beginning it was only, like, back and forth, right? [00:43:00] Yeah. So you asked, uh, your favorite LLM or your favorite agent of choice, "Can you do this for me?"
Marcus Hallberg: Yeah. And it would go and do that- Yeah ... uh, using its best judgment. Yeah. Today, we see that most of these tools are asking you questions back before starting. Mm. So it says, "Oh, do you want me to do this thing before that thing," or, "Would you like me to start by reading the documentation?" So I think this is something that gets developed both from how users, uh, use agents and AI, but also f- where we see that those that build those same tools realize, oh, we need to have that type of same education or ways to verify before, um, agents, uh, go and, and do whatever task you wanted them to.
Samuel Kelemen: I would just like to expand on, I think it's also becoming a product thing, right? Like, when we first started with agents, we got this text UI because it was simple, right? Yeah. Not because it was the best UI. So I think a, a lot of engineering has gone into making the U- the text UI in a terminal look very pretty, and that's all engineering work that [00:44:00] isn't going to making, like, the, the experience better in a different way, right?
Ashish Rajan: Yeah.
Samuel Kelemen: So I think the The time that we will have the text UI as, like, the main interface for interacting with agents is very limited. So maybe in five years we look back and this was just, like, a blip on the timeline of AI. But i- it is, like, a product question. Like, how do we make this secure, and what are we trying to do, uh, in these areas?
Samuel Kelemen: 'Cause a lot of times, uh, it probably d- won't make sense much longer for us to be using AI as just, like, a simple tool. Mm. Like, we're acting like it's kind of like a bash command or something, or we're acting like it's a chatbot.
Yeah.
Samuel Kelemen: And I think the, like, long-term vision is that we will have, like, asynchronous agents running all the time everywhere-
Ashish Rajan: Yeah
Samuel Kelemen: and it won't really make sense to interact with them on, like, one machine or with your tools that you're using locally. They will have their own tools, their own integrations, their own APIs even.
Ashish Rajan: Yeah.
Samuel Kelemen: Uh, so I think eventually this kind of problem will be, like, we will mature out of it as the product space grows.
Ashish Rajan: [00:45:00] Yeah.
Samuel Kelemen: I, I, I think that could be, like, a non-satisfactory answer for people who are just using the tools and they're not in, at an AI company. Um, so maybe we can find some happy middle ground where there are guardrails now, and I think there's plenty of, uh, tools in the industry that can help you have better guardrails around deploying this, but also the targets where you're using it for work.
Samuel Kelemen: So there's lots of Claude-enabled, um, GitHub actions or something that will- Yeah ... like, take a, uh, review of whatever you produced using AI. Yeah. And I think that can be a good middle ground as well.
Ashish Rajan: Yeah. And to, my, to your point, Claude even has, uh, pre-hooks, tool hook, pre-used tool hooks as well. Yeah. So, I mean, there's plenty of, to, to your point, there are options available to the problem that you're trying to solve.
Ashish Rajan: What is the bigger challenge for you? And maybe what I'm also hearing is a lot of the industry is also focused on the whole conversation of, "Hey, um, the- is this too complicated a problem for me to build for? Like, should I really build Claude skills for this, or should I just [00:46:00] buy a third party?"
Marcus Hallberg: Mm.
Ashish Rajan: And I, I understand the answer could be different for a engineering-heavy company versus a non-engineering company, but I would argue these days anyone can be an engineer- Mm
Ashish Rajan: because you have an AI. If you have a goal in mind for what you want to achieve and maybe have some support from someone who's experienced, you could go quite far.
Marcus Hallberg: Mm-hmm.
Ashish Rajan: Where do you guys sit on, a lot of people look, hearing this going, "Claude skill sounds good. Pre-tool hooks, hook GitHub actions. Yeah.
Ashish Rajan: Maybe I should just buy one of these tools and, uh, call it a day, I guess, for lack of a better word." Mm-hmm. Like, do you find, is there a balance where it's a build more first, and why build more, if that makes sense at, at scale? 'Cause I don't even know, um- Because a third party you may be going for is enough for the volume sometimes you may be dealing with as well.
Ashish Rajan: I don't know. I'm sure you have some thoughts on this as well.
Samuel Kelemen: I think that's like an industry question, right? Yeah. I think maybe a few months ago we were all having the conversation, is SaaS dead, right? Yeah. Um, and I think [00:47:00] to some extent, maybe it is, right? Some SaaSes are very expensive and not so complicated, and even if you're like a medium-sized company, maybe you can afford to spend a few developers to build that internally with something like Lovable or some other agentic engineering framework, uh, to solve kind of that immediate problem.
Samuel Kelemen: Um, but I think in general, like there is expertise that come from these SaaS companies where they have lots of engineers focused on a single problem-
Ashish Rajan: Yeah ...
Samuel Kelemen: and it's not always easy to actually solve that problem in the whole. Some- a lot of problems, they, they seem very easy until you get into the weeds and you realize, "Oh, I didn't think about that e- edge case or this other edge case," uh, and then it becomes quite complicated.
Samuel Kelemen: So I, I think there'll be room for both, but the calculus of when to buy versus build is definitely changing.
Marcus Hallberg: Mm. Yeah. I, I agree, and, and I think, uh, this is also relating to the conversation about, you know, the, the cost of writing software going to zero- Yeah ... but you still have questions like, well, if even if the software can be recreated, where does your data live?
Marcus Hallberg: How is that data being [00:48:00] accessed, and how can you sort of combine different types of data to, you know, to have more intelligence and give you better tools? Yeah. And I think e- to go back to your question, if, if, if should I use a third party? Should I, you know, build it myself? I think it... The dif- the answer will, will depend on, on both- Of course
Marcus Hallberg: the company person and the problem they're trying to solve. But I think what is really exciting is that now more than ever there are more options. Yeah. So you can basically have- Something, um, a tool, a platform, and you can go and you can create whatever it is you would like to do, right? Uh, but to go back to what Samuel said before, you don't want to leave the thinking to the AI.
Marcus Hallberg: So you still want to have, you know, you want to know what is my map, where, what is my charter, where am I going, and how does that road look like? So I think we will see different, um, companies, uh, people, end users taking different roads here. Some of them will rely on, you know, pre-built, um, software applications, [00:49:00] uh, tech stacks.
Marcus Hallberg: Others will say, "You know, for me, this makes more sense to build from scratch using some platform." And whoever wins, well, hopefully everyone does, but I think that's where we will see those different types, uh, and choices to kind of, uh, how they will, um, develop over time.
Ashish Rajan: Do you've, um, of... So people who are deploying this, I by the way love the answer 'cause I think I definitely feel it's like a it depends question as well 'cause what AI also has done is it's made people, or it's exposed the human part where we have this gut feeling, we go down a rabbit hole, and you realize, "Oh, actually I should have not done that," and I will like spend a whole day or two days on this particular problem that should've just been like in a lot more easier if I just left it alone So coming back to the, obviously the whole talk, I think it's a great idea.
Ashish Rajan: People should check it out. I also want to double down on what does the, to your point about the five-year plan, what do you think is like the security team looking like? [00:50:00] 'Cause I guess you guys are seeing a lot more volume of this. 'Cause a lot of people are still in that initial stage of, uh, "Hey, oh yeah, we have two or three apps."
Ashish Rajan: You know, they may not have 80 million people using it- Yeah ... but they definitely have starting to build that capability for now I have my AI, my traditional applications enabled by AI. I have my, uh, AI-enabled applications. I have my AI application itself. They're like all these complex multitudes of applications being produced in mul- What do you see as security people should have, or, and as security people in different teams, right?
Ashish Rajan: And you can talk about like if you take a step back- Mm ... you can talk from a reduction perspective, you can pro- talk from a cryptography, however you wanna take it.
Marcus Hallberg: Mm.
Ashish Rajan: I'm curious as to where do you see, considering you guys have been in the cybersecurity for a while, how much has of that needs to change for us to be ready for, I guess, what's coming for majority of people who are gonna start now?
Marcus Hallberg: Mm.
Ashish Rajan: Curious.
Marcus Hallberg: So, so I think I, I can maybe start, but I, I think from, from, from my perspective, what I'm seeing is like there, there's something really exciting with the fact that, [00:51:00] so platforms like ours and others where you have the scale, basically. Yeah. So you have all these millions and millions of apps.
Marcus Hallberg: Uh, you have the same problems as before with how do you, you know, patch vulnerabilities? How do you surface different types of findings to the end user and to us? And I think what is interesting with that now, and more so going forward is, how do we take that scale and that knowledge and intelligence that we can collect and feed that back to our end users?
Marcus Hallberg: Mm. So if you had, say, uh, before or even, even today, let's say you build your own, um, web server, right? Yeah. Or your own website. So you run it at home and it's working fine. Like you're, you're doing a great job and it's, it's okay. You might use Claude or, uh, some other tool to kind of help you along the way, but you're still sort of alone in the sphere of like, it's only you and, and your own infrastructure and code, right?
Marcus Hallberg: Yeah, yeah. So I think where the power comes is where we and others can bridge that gap and say, "Oh, we looked across the entire surface. This is what we're seeing. This is how we can help to, uh, harden, uh, and secure the code, detect when things go [00:52:00] wrong, and also patch vulnerabilities when they surface." And that's something that we are already now, but even more so going forward, gonna focus our efforts to basically improve that so that everybody wins in that sense.
Samuel Kelemen: Yeah, I think when I started in this industry, the goal of a CISO was to convince everybody that you needed a security team and that people need to think about security. And then we had, like, the whole shift left phase and the lift and shift to the cloud phase. Uh, so I think, like, the role in security is definitely changing, and a lot of that is, like, also improving user experience and user education around security.
Samuel Kelemen: So I think back when I first started, cryptography was very difficult, right? There were all these different parameters you need to know about, like what is a, you know, asymmetric key versus a symmetric key. Yeah. Uh, w- how do you generate the key? Where is your source of random? And then, like, when you're doing, like, hashing, like, how many iterations do you need?
Samuel Kelemen: Like, where do you put the, the IVs for things? Uh, and then Google came out with a library, uh, in ACL- Mm ... which kind of put, like, a nice facade API on top of it and made it easy for [00:53:00] people to consume. Hmm. So, like, then you had simple interfaces like encrypt this, right? And they would handle all the complexity internally.
Ashish Rajan: Yeah.
Samuel Kelemen: And I think the cloud has done a very good job about making APIs that make sense to developers. So we have things like Google Secret Manager or, uh, Google Key Manager that kind of move up another level. Yeah. So now you don't even worry about keys. You just delegate signing or whatever to, to the cloud.
Ashish Rajan: Yeah.
Samuel Kelemen: So I think now we're trying to do the same for our users who are even need a simpler API to achieve bigger things. So I think we will see also, like, a uh, an industry shift to providing, like, Legos that kind of go together to build the different things that you need. Uh, so like for example, authentication, authorization, like we'll probably have frameworks that allow you to easily implement like single sign-on or, uh, SAML for enterprise, or, you know, all these kind of things that most apps need, right?
Samuel Kelemen: And I think, um, one thing you mentioned was, like, there's a difference between, like, enterprise scale and user scale, and I don't think that's necessarily true. Like, if there's vulnerabilities there, it's still [00:54:00] a juicy char- target, right?
Ashish Rajan: Yeah, yeah.
Samuel Kelemen: Uh, so we need to, like, kind of solve on like a base level more things so that everything goes more secure.
Samuel Kelemen: And I think with AI and with app builders specifically, we have such a high leverage that we can easily make, like, high gains, uh, around the entire internet because when we make one change locally in our builder, it's amplified to, like, 40 million apps, for example.
Ashish Rajan: Yeah,
Samuel Kelemen: yeah. Uh, so I, I think as he mentioned, we've also been thinking a lot about, like, the full life cycle of security, and I think AI also gives us an advantage there, where, like, we can detect things in a way where we haven't been able to before.
Samuel Kelemen: Uh, and I- we can also generate, like, the fixes for it as well. Uh, so if we have like a good pipeline where we can test that your app still does what your app is supposed to do, then we're also kind of free to make changes within that, right? Because the AIs are non-deterministic, so when you accept a change from an LLM, you still have to verify that it works, right?
Samuel Kelemen: Yep. If you go and tell, you know, Lovable, like, "Make me a SaaS application," or whatever, it'll make you a [00:55:00] SaaS application, and then every time you change it, like, it's, like, a kind of a new thing, right? Uh, so there is this important thing to, to test that, but since we now have a framework where we can have, like, a non-100%, uh, correct or whatever, like we, we have some false positives, that's okay because now the structure of how you interact with it is also non-deterministic.
Samuel Kelemen: Mm. So we can find vulnerabilities, we can generate a fix for it, like Dependabot does now.
Ashish Rajan: Yeah.
Samuel Kelemen: Um, and then we can automatically merge that, and then in your agent loop when you're already talking to him, you're already doing the manual testing. So if we put in the security fixes while you're, you know, adding new features, then, like, part of the structure of how you interact with it will help solve some of those problems.
Samuel Kelemen: And I think we have, like, a very high chance of being able to solve more things in this kind of way because Dependabot does a, a good job of solving, like, CVEs that come up- Yep ... or, like, dependencies that are [00:56:00] outdated.
Ashish Rajan: Yep.
Samuel Kelemen: Uh, but it can't really do business logic changes.
Ashish Rajan: That's right.
Samuel Kelemen: So with AI, we can evaluate more business logic changes and try to get those into your, you know- code, your repo, your project Yeah,
Ashish Rajan: yeah
Samuel Kelemen: And I think that the testing now allows that because the user didn't care about the code, right?
Samuel Kelemen: Yeah. They cared about the product they're developing.
Ashish Rajan: That's
Samuel Kelemen: right. So if we change the code but still deliver the value they're expecting-
Ashish Rajan: Yeah ...
Samuel Kelemen: everybody's happy, and we have, like, kind of a place where we can play to build security in by default.
Ashish Rajan: To your point, then the ideal future, I think at least, I call it scaffolding.
Ashish Rajan: Other people may call it something else. But I think it's more like if whoever's watching this in different teams, even if they do one task that they do today with, "Hey, maybe this could be an AI task." And to your point, have, like, a, is there a good enough data source for me to get the information that I need?
Ashish Rajan: Mm. Do I need integration with a third party or an MCP or something or the other? And how do I make sure it, it understands it's me versus agent? Uh, if it... Uh, [00:57:00] and each one of them is, like, a complex thing to answer, but as you go down the path, you start discovering things that, oh, maybe- The one, the thoughts that I shared in the beginning may not be the best one, but, uh, there is this one little thing that I do always, which I feel is, like, a good one.
Ashish Rajan: And I'm just not talking about, uh, say, an individual detection team, but it could be across a GRC, uh, could be across your risk team, could be across detection, cloud security engineering. Every- if everyone starts doing each one of these, to your point, with the, uh, the same goal of making it universally equal for everyone, 'cause at the end of the day, we are all supporting the, the customer.
Samuel Kelemen: Mm-hmm.
Ashish Rajan: And e- each team is doing things to support the customer in being, quote-unquote, safe. Ultimately, all, uh, I guess that's the ripple effect that comes from each one of us doing it. And I don't know if, do you feel if that's a better future to go towards? 'Cause a lot of people are looking for answers that, hey, obviously this third party would play a role somewhere.
Ashish Rajan: Like, I can't build a threat intelligence feed- Hmm ... which is just constantly looking at everything that's happening in the world. Do you feel, um, [00:58:00] is that probably a better, uh, or maybe not a better, but I think is that a good way to think about the future for what security teams or what, say, an engineering leader could plan for or security engineering leader should plan for in their roadmap moving forward for the teams they have to enable them more?
Ashish Rajan: 'Cause the reason I say that is because a lot of people only have access to a Claude Enterprise.
Samuel Kelemen: Hmm.
Ashish Rajan: Mm-hmm. And you, I mean, we talk about agents, but for them it's like, "I don't even know how to build an agent."
Samuel Kelemen: Hmm.
Ashish Rajan: Like, do you, "What do you mean there's an agent?" Hmm. I always like, "Oh, Claude Code, you do /agents, you can make an agent.
Ashish Rajan: That's that easy. Just tell it what you need to do." And, like, things like that- Mm-hmm ... I would, at least I personally try and encourage people to do it, but I don't know if you guys agree there, that people should start small and start building up to- towards that bigger thing that we are talking about. Do you guys agree?
Marcus Hallberg: Yeah. I, I do agree. And I, and I think the journey will look differently for, uh, again, like, for d- who, who those people are that, that want to use AI in some sort of way. So I think fro- from my perspective, the, the key thing there is to say, so, so you or we all are experts in our different fields, right? Yeah, yeah.
Marcus Hallberg: So [00:59:00] if, if you're working with, you know, detection response, uh, compliance, uh, finance, whatever that might be, uh, I think a good first step is to look at, okay, so what are the things that can be, you know, done through, uh, AI, but also verified, right? Yeah, yeah. To make sure that when you build whatever solution that you have in mind to, to solve whatever problem, that you have a way to say, "Okay, now this solution is doing the thing that I would do instead- Yeah
Marcus Hallberg: but it's doing f- doing it for me. And I can verify that this is what good looks like."
Ashish Rajan: Yeah.
Marcus Hallberg: Uh, and I think that's a journey that has been, like, some of those automations has been happening as well. So for example, uh, if you've been working in a security operation center, uh, you usually have these different levels of triage, right?
Marcus Hallberg: Yeah, yeah. So you have the first person looking at the first alert- Yeah ... maybe adding some enrichment, doing a first assessment, and then sending that on. And a lot of those things are, are kind of being shifted away now or transferred and, and changed because of, uh, tools like AI. Mm-hmm. But it's still all about how [01:00:00] we verify what good looks like.
Marcus Hallberg: Mm. So I would start, uh, kind of small and make sure that, uh, if you're using Claude Code or something else, that you have a way to say, "Okay, now it's doing this, uh, work for me, and I have a way to confirm that, that, that is the actual, uh- Mm ... how it's s- how it's supposed to do that." Yeah. So you can verify it.
Marcus Hallberg: Then I think it's easier to go beyond that once you have a sort of a platform and a base to start with.
Ashish Rajan: Right. I guess you want detect and verify rather- Yes ... than just work on detection.
Marcus Hallberg: Yes. Yeah. Exactly. Uh, so those would be some of my thoughts, but I think we will see these different changes in all, all industries- Yeah
Marcus Hallberg: and for all teams- Yeah ... not just security.
Ashish Rajan: Yeah, yeah.
Samuel Kelemen: I think I agree with what Marcus said. There's, uh, I believe everyone will find the best way to use, like, Claude for their specific roles. So, like, we're very knowledgeable about our specific roles, and so we have a very strong notion of what correctness means for the things that we do.
Ashish Rajan: Yeah.
Samuel Kelemen: And so I, I believe that people will naturally find a good way to use Claude to do the things that they're already doing. But I would like to encourage them to, like, try to use Claude [01:01:00] for things that maybe is outside of their normal skills, where there is, like, kind of less of a notion of what correctness is, right?
Samuel Kelemen: Ooh. Okay. So I think one thing that's a good example is, like, everyone has to touch SQL, right? It doesn't matter what kind of engineer- ... or if you're not an engineer, like, we all have to find data eventually, right? Yeah. And I think this is a very good problem for AI because a lot of what we're doing is, like, exploratory research or kind of data sciencey kind of things.
Samuel Kelemen: Yeah,
Ashish Rajan: yeah.
Samuel Kelemen: We're not looking for, like, the exact answer or, like, a high-performance query.
Ashish Rajan: Yeah.
Samuel Kelemen: We're just trying to see, like, what is the data? Like, how does this... Like, how does this change how I work, right? If there's, like, 10 million records versus one million records, I might do something different.
Ashish Rajan: Yeah.
Samuel Kelemen: Um, and I think this is very good because AI will know, like, the schema. It can access the preview of the data. We have a tool internally that was built by our data science team, which, uh, connects to Slack to, like, our kind of analytics database.
Ashish Rajan: Nice.
Samuel Kelemen: And then we have, like, a lot of people asking this kind of Slack bot that we have how...
Samuel Kelemen: Like, w- w- find this data for me, or kind of summarize users that were [01:02:00] created today. Like, how big is the scale or, or whatever. What are people doing in the product?
Ashish Rajan: Yeah.
Samuel Kelemen: Mm. Uh, and I think there's a lot of room for those kind of things across the different areas in the company. Yeah. So, like, for security, like, we could have something similar, like how are things going in security events?
Samuel Kelemen: Or, uh, how are logins working across the, the thing- Yeah ... the company? And I think, uh, even getting access to kind of company information, like, I, I think we, we also have one that indexes the code base, right? Mm. So we can say, like, Level's code base. Like, tell me who owns this feature. Mm. Or tell me the last time someone looked at a login or whatever.
Samuel Kelemen: Yeah. Mm. Uh, and, and I think those are very good because- You drive a lot of value. These are like small tasks that would probably take you an hour or something. Uh, it'll probably be like under five minutes now. Uh, but also it kind of influences your work and kind of raises your knowledge about what's going on in the rest of the company.
Samuel Kelemen: Yeah, yeah. So you can, uh, direct your work, uh, find someone else who knows more about something. Uh, so I, I would encourage people to try that as [01:03:00] well.
Marcus Hallberg: Yeah, definitely. I think this is a great example, by the way, because I think to me, it sort of tells how you empower people to- Yeah ... use these tools for, to solve whatever problem they have.
Marcus Hallberg: Yeah. So as you said, none of those people that used our tool internally had to learn SQL, but everybody benefited from the tool to get the data that they needed for their own specific problem.
Ashish Rajan: Yeah.
Samuel Kelemen: I think a one... Another good example, sorry. Yeah. Uh, we have a organization called PX. They, uh, manage the support inbox for us.
Samuel Kelemen: Uh, and there's a lot of things they can do on their own now. So they're not engineers, but whenever a problem comes in from a customer, they can just ask these, you know, bots or Claude Code with some Slackbot on top, uh, like, "Where is this in the code? What's going on? Why is this not working the way we expect?"
Samuel Kelemen: Wow. And then they can either, you know, solve the issue themselves or, like, get some information to give to the customers, or they know which team to go to to solve the problem.
Ashish Rajan: Yeah.
Samuel Kelemen: And I think there's, like, also small changes are very, uh, easy to do with agents right now. Like, if you wanna turn a button from white to black or purple or [01:04:00] something, uh, this is something that you don't have to be an engineer to do now.
Samuel Kelemen: Like- Yeah ... a PX person can say, "This button is white, it should be purple. Please make it purple." And then we can spin up an agent to go and make that change, and, like, that's almost always safe even though, uh, they're not engineers, right? So-
Ashish Rajan: Yeah. I guess to your point, I think the one takeaway that I'm taking from this conversation is that obviously it's great to hear about the, um- The attempt that you guys, uh, picked up on, stopped, and remediated and everything else, but also on the fact that what does it look like to build, uh, and work towards a team that would help more security teams be AI-enabled, have their own scaffolding, what a good place to start is.
Ashish Rajan: And I love the example of going outside of security, 'cause to your point, all of us, we were talking about this, uh, when we were not recording, about climbing a mountain- Mm-hmm ... uh, that we have all climbed a mountain for our skill set- Mm ... which has, let's just say for lack of a better word, has enforced certain opinions in our mind for certain things.
Ashish Rajan: But you talk to someone who's not from your f- direct field- Mm ... uh, but adjacent in [01:05:00] the same company, and you find out this whole nother world opened up for you that you had no idea about. Mm-hmm. Whether it's customer support or finance or whatever.
Marcus Hallberg: Mm.
Ashish Rajan: And you realize, "Oh, this is, this is pretty cool." Mm.
Ashish Rajan: Like, maybe I can use- plug into some of that as well and learn information. But I'm super excited for, uh... I, I feel I can talk to you guys for hours, so, but I wanna, uh, wrap up there 'cause I think there's a lot more to unravel. But I am curious. I've got three fun questions- Mm-hmm ... that I ask everyone, so I'm gonna piggyback on each one of them.
Ashish Rajan: Uh, first one being, what do you spend most time on when you're not trying to solve all these AI security, uh, challenges of the world? Maybe I'll start with you, Marcus.
Marcus Hallberg: Uh, wow. There, there's a lot, uh, there. I, I think for me it's, uh, I have a lot of, like, you know, on my free time, hobbies that I do, you know, hiking, dancing, rock climbing when I find the time.
Marcus Hallberg: So I think for me it's that good balance. I think it's... One of the things I also realized, and, and I, I know this is sort, sort of like cheating on your question- ... because, uh, this, [01:06:00] this, uh, also ties back to AI, but, like, I, I, I find that I, uh, can use, uh, AI for learning new areas that I didn't know anything about before.
Marcus Hallberg: Yeah. So it gives me a really good tr- uh, interest in, for example, I wanna learn about history or, or something else that I'm interested in. H- what, what's the best way to do that? And then I can easily find good recommendations for documentaries or books to read, et cetera. Yeah. So I think, I think, uh, so both of those things happen.
Marcus Hallberg: Uh, but, uh, yeah, that, that, that would be, uh, outside of work what I'm, what I'm, uh, some of what, uh, what I'm doing.
Ashish Rajan: What about you, Samuel?
Samuel Kelemen: Uh, I'm a fan of the water, so I try to be rowing or sailing as much as I can. Oh. But I'm also kind of, you know, addicted to the AI right now. Mm. So I, I agree, like, learning new things, finding new information is always fun with AI.
Samuel Kelemen: Is, I think, also, uh, trying to construct challenges for AI. Like, one thing I like to do is ask AI to, like, design a city or, like, how would you engineer a bridge?
Ashish Rajan: Oh, wow.
Samuel Kelemen: And then I, like, try to give it, you know, kind of crazy input, like design a bridge like you're in 1940s- [01:07:00]
Ashish Rajan: Oh ...
Samuel Kelemen: uh, you know, Brazil or something.
Samuel Kelemen: Yeah, wow. And then see kind of the difference that it comes up with, and I think that's been quite fun as well.
Ashish Rajan: Wow. Okay. I'll ask the same question to you then. Yeah. What is something that you're proud of that is not on your social media?
Samuel Kelemen: I don't have social media, so- Oh,
Ashish Rajan: so you
Samuel Kelemen: have... I think-
Ashish Rajan: That guy, like that's a cheat code.
Ashish Rajan: But what, what from- Being
Samuel Kelemen: on this podcast is, I'm very proud to be-
Ashish Rajan: Oh ... here with you. I love that. Well, this is gonna go on social media, so I guess it'll be fine. Yeah. Uh, what about you, Matt? What's-
Marcus Hallberg: Uh, wow. One thing I'm proud of, which is not on social media, uh, I like plants a lot. So now in the summer and spring is, is coming here to Sweden, I, I love to see how my plants on the balcony are surviving, and they tell me I did a good job treating them over winter.
Marcus Hallberg: Uh, so, uh, I'll, I'll, I'll leave it with that as a, as a sort of a- Fair ... I don't take po- I don't, uh, take pictures and put 'em on social media, but, uh, they, they are there and they make, uh, b- make the home for me and my wife a lot, uh, more fun and, and good.
Ashish Rajan: Awesome. Uh, final question, what's, uh, what's your favorite cuisine or restaurant you can share with us?[01:08:00]
Marcus Hallberg: Oh, that's a difficult one. Uh, I mean, now we're here in, in Stockholm, and I think for me, I'm, uh, I'm really, uh, into Vietnamese food, so, uh, so- Like
Ashish Rajan: pho?
Marcus Hallberg: Uh, I, I think there, there's, uh... I'm not, I'm not an expert, so I'll- ... I'll be like- Or what's your
Ashish Rajan: favorite Vi-
Marcus Hallberg: Vietnamese, like to say what- Yeah. And, and I, I, I realize when I say this, it's, it's, I, there's probably a lot better, uh, Vietnamese restaurant, but there's, uh, there's one popular, uh, one that, uh, that I think people know about called Eatnam, which is, uh, also a favorite spot for me and my wife.
Marcus Hallberg: So, uh, I know it may, may not be the most authentic, but it's, it's a favorite spot for us.
Ashish Rajan: Interesting. Uh, what about you, Ben? What's your favorite cuisine or restaurant? I
Samuel Kelemen: think barbecuing with friends- Oh ... is kind of the most important part for me. I think as an American that's, uh, something core to my culture, and here in Stockholm there's only so many good sunny days, so we have to really make the best of them.
Ashish Rajan: Yeah, fair. Um, so I guess obviously we are at the Lovable office. Uh, how can people be in touch with you guys and, uh, I guess get to know a bit more about what you guys are working on? [01:09:00] Perhaps, I guess 'cause I guess you guys are recruiting as well, always?
Marcus Hallberg: We, we are. We have a lot of, uh, open roles actually on, on, on our team.
Marcus Hallberg: Uh, so, uh, if you're interested and, and, uh, you want to, uh, come work with us, uh, please have a look at those. Uh, I am on social media, like, like LinkedIn, so you can reach out to me there, but also to, uh, to see the, uh, the recording of the talk that we did and, uh- At
Ashish Rajan: forward CloudSec. Yeah. Yes. I'll put the link for that as well.
Ashish Rajan: But, uh, I appreciate you guys coming. I'll put the LinkedIn link as well. Um, but thank you so much for coming on the show and being so upfront about how much people can improve themselves by, uh, using AI. And I'm gonna challenge my AI to make a bridge for me in 1947 in Rio de Janeiro. That'll be pretty... I did not even think about it.
Ashish Rajan: I'm like, actually, yeah, why am I only thinking about future? Why not go, can we do something better in the past, is an interesting question to ask. So that's my, uh, takeaway from here. But thank you so much for coming on the show. Thank you. Thank
Samuel Kelemen: you for having us.
Ashish Rajan: Thanks. Thank you. Thanks, everyone.
Ashish Rajan: Thank you for listening or watching this episode of Cloud Security Podcast.
Ashish Rajan: This was brought to you by techriot.io.
Ashish Rajan: If you are enjoying episodes on cloud [01:10:00] security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple Spotify. In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security.
Ashish Rajan: Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast. You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.
Peace.

.png)
.png)
.png)

.png)


.png)











