Cloud Security Podcast by Google

Anton Chuvakin

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.

  1. -22 ч

    EP289 Software Engineering vs. Software Craft: How Google Scalably Eliminates Classes of Vulnerabilities

    How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? In this episode, hosts Timothy Peacock and Anton Chuvakin sit down with Christoph Kern, Principal Security Engineer at Google, to look under the hood of "secure-by-design." They trace Google's 15-year engineering journey to fundamentally eliminate entire classes of vulnerabilities rather than just playing whack-a-mole with bugs after they are written. 🛠️ Software Engineering vs. Software Craft: Why Google ditched "be careful" programming checklists in favor of hard compiler and framework-level invariants that make security defects physically impossible to build. 📦 Hiding the Risky Abstractions: How replacing high-risk programming constructs (like raw pointers in C++ or raw injection sinks in browser code) with safe, compiler-enforced abstractions secures codebases at a scale humans can no longer manually audit. 📢 "Marketing Didn't Write It": Christoph and the hosts unpack why the concept of "eliminating a class of vulnerabilities" is a rigorous, mathematical reality at Google rather than just public relations hype. 🤝 Empathy vs. Opinionated Platforms: The secret feedback loop Google uses to build highly opinionated developer platforms (like Boq or browser-native safe types) that protect systems without turning developers into frustrated "software artists" fighting the compiler. 📈 The Android Productivity Proof: The real-world metrics from Google's Android team proving that shifting to memory-safe languages (like Rust) dramatically drops vulnerabilities while actually boosting developer velocity and lowering rollback rates

  2. 13 июл.

    EP286 Building an AI-pilled, solo vibe-coded, Clickhouse-based SIEM with Dan Lussier

    Can you build a fully functional, high-scale SIEM in just two weeks for under $7,000? In this episode of the Cloud Security Podcast, hosts Tim Peacock and Kyle Champlin sit down with long-time collaborator Dan Lucier, Founder of Nano, to unpack how he "vibe-coded" an entire SIEM from scratch during his end-of-year holiday break. Dan shares his journey of leveraging bleeding-edge AI code assistants to go from a Postgres prototype to a blazing-fast, production-ready SIEM built on Rust and ClickHouse. In this episode, we cover: 🛠️ The $7,000 Stack: How Dan utilized Claude Code and Kubernetes to build a lean platform running on 2 vCPUs and 4GB RAM while ingesting 10–20 GB of data daily. ⚡ Why ClickHouse? The database architectural decisions behind maintaining sub-second search speeds at massive scale. 🤖 AI-Pilled but Cautious: Why Dan takes a surprisingly conservative approach to AI case closure and triage (and how it compares to Google's Triage and Investigation Agent). 💻 Detection as Code: How MCP (Model Context Protocol) servers and AI are leveling the playing field for smaller security teams. Whether you're an AI enthusiast, a data nerd, or a security leader looking at the "fourth wave" of SIEM, this episode is a masterclass in modern, rapid-fire software engineering. 👉 Subscribe, leave a review, and join the debate on our LinkedIn page!

Об этом подкасте

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.

Вам может также понравиться