Explore your curiosity - Interesting people with fascinating stories.
Life consists of three things:
-The stories we tell others
-The stories others tell us
-The stories we tell ourselves.
Ori welcome aboard to the show, thank you so much for joining us today.
Speaker 2:Thank you for having me.
Speaker 1:So what was it, a couple years ago the life of everybody changed forever and I think and I'm talking about know ChatGPT making their huge announcement but since then I feel like life is changing on almost a weekly basis with every new release of you know Claude Decode, every new release of ChatGPT. Just this week we heard that Cursor came out with a multi, well they're beginning, shitty beginning I might say, of their multi agent strategy but the multi agent strategy is going to just change things again. So let's take this from the top and I want to talk first of all about how we used to work in the past or many companies still today are working in this way with kind of the traditional flow from, you know, executives and OKRs to product managers to engineering to support what did life look like before And then after that, we're going to talk about what life might look like in the future.
Speaker 2:So I think it's a great question. And the first thing that we need to answer is when, like, you know, and if you talk about, I don't know, like ten, fifteen years ago, back then, you know, we were very like software development and everyone's life were more sequential, meaning you did one thing and then you did the other. You first developed and then you test and then you rolled out and then you deployed. And then, you know, we had the famous software as a service and cloud adoption and transformation and the great years of digital transformation and COVID, you know, everyone wanted to be digital, which is great. So software moved into a continuous manner.
Speaker 2:You do everything and you push and you get feedback and you iterate faster and faster and faster. And then all of a sudden, you know, AI came to our lives, although the technology existed in some way, form or shape since then sixties, if you really want, you know, to be, to give the history lesson. So I think this is kind of what we need to understand that we are at real verge of disruption in every industry, every industry. And like, I can give an example. A couple of weeks ago, my CEO reached out to me and said, okay, I need you to do a meeting this and that company.
Speaker 2:I need you to run like an analysis. Now, in the past, what I would do is, you know, I would carve out couple of hours, even days, looked into the documentation, you know, review sites, look at Reddit and some others. What I did this time was quite amazing. I opened my GPT account that I have as part of the company, you know, gave it some prompt, directed it into the right resources, and a couple of minutes later, I had everything that I had, just as one very practical example. So I think this is like how I would answer your question, and also I think that the one thing, the one currency that keeps improving with technology is speed.
Speaker 2:We're just doing everything significantly faster, which is both scary and exciting if you think of it.
Speaker 1:So think it's a really beautiful point that you're making that we have been innovating the software process over the last twenty years, you know, ChatGPT, but something fundamentally changed wherein ChatGPT could code and you know, I don't want to you know understate here, we have Claude, we have other options, I'm just using them as the name. So it seems like we had a structure where we had front end developers, back end developers, we have some full stack developers, we have the UI, you have the UX, we have product people. That structure by and by has been the same for the last twenty years. I'm starting to ask myself, I myself am a you know CTO slash product manager. I'm starting to ask myself the structure of the future, is it going to be the same?
Speaker 1:Because I'm seeing product managers who have architectural knowledge just do all the work by themselves, working with, you know, six, seven agents at the same time, clawed open, and they're making progress, which is X than what you would do in the previous paradigm. So what is the hiring? What does the team structures of the future look like? And I'm not sure we really have an answer to that yet. What's our best guess?
Speaker 2:I think we don't have the answer yet. First, because the technology is still shaping and, you know, you can also say like, we like to say that, or with vibe coding platforms and, you know, from Base 44 to Lovable to all the rest, as, you know, example of great tools, software is now at the hands of the masses, meaning software creation can become, or can reach the mass very easily. Now, what does it mean? It means that, again, going back to speed, we can innovate faster. Okay.
Speaker 2:But like every other, it has a benefit and it has some risks and we need to be aware of that. Now, your question, I think that we still haven't figured it out. Meaning if, again, if you take a look at the previous kind of transformation or the big major shift in technology cloud, which is the last one that I think most of us in the industry right now went through, you had new capabilities that, you know, the supporting function, let's call them PM designer started to add, which was back then, you know, data analysis and funnel analysis and all of that. So I think as AI becomes native in our way of thinking right now, it's not native. We need to change how we think.
Speaker 2:We need to adapt to it. We need to add whether it's incremental, whether it's wrappers on top, or whether we adapt and change the processes that we currently have, but we're not yet AI native. We'll get there. Okay. But these are the type of skills that will also be added along the way.
Speaker 2:However, also I can, we can argue on the other side that do development teams need PMS anymore? Do they need designers? Because I've seen, you know, post on LinkedIn and other social networks that say that in one of the hackathon, they gave GPT, you know, to do the discovery. They handed it over to Cursor. They've done the development.
Speaker 2:They've done some, you know, fixing on top of the output. And, you know, all of a sudden you have a development team that can discover, ideate, write the requirements. I mean, not even write, but get the requirements from GPT, hand it over. So I think this is really, really exciting. And I believe that 2026
Speaker 1:Let's stay on that for a moment. Here's my prediction. The developers are going to argue the PMs are not necessary. The PMs are going to argue the developers are not necessary. And my opinion, they're both right.
Speaker 1:They are both correct. So how can that It's
Speaker 2:a great question and I think that 2026 will be kind of the year that we'll realize the new reality. Let's call it like that. You know, we're also talking about designers and marketing. Like I've seen great solutions that replace traditional marketing, which is like, you know, amazing. So what does it mean that, you know, like agent will talk to agent like the PM agent will talk to the development agent that will talk to the deployment agent.
Speaker 2:Management will just get an email saying we did that. Probably not. Right. We'll get there at some point. At some point.
Speaker 2:But I think for now we still need humans in the loop, which is a term that we hear all like every day, but it's definitely getting there. So at some point I think we will still need the human anchor, but maybe not. So, you know,
Speaker 1:I think we agree that long term, right, long run, you know, the humans are going to slowly disappear, you know, there's going to be different ideas around what the future looks like, but we don't really know. But there, I think we do have very concrete ideas about what we're going to do tomorrow. So we can see product managers are changing their processes instead of just creating a long spec that people need to read and honestly nobody does. They're now creating full fledged mock ups in Lovable. And sure, engineering take that app in Lovable and they're like, I get it.
Speaker 1:That acts as the spec. And then, you know, as you described, engineers are creating their own specs and saying, well, does this make sense? Should we do this? So I think it's really empowering each of our functions to take their work to a whole new level. So if you were talking to anyone in the audience who their engineering team is still in that old paradigm, what's a baby step that you would recommend them to start from?
Speaker 1:Is it DevOps? Is it product? Is it engineers? What's that next level that they can reach, which is not utopia, but it's giving them tangible gains?
Speaker 2:Yeah, so I think, and I had multiple discussions with that and with my team, with other people in the industry, AI, the main thing with AI is that it actually kind of increases the number one problem in product management, which is which or what are the problems that worth solving? And now solving the majority of those problems just became a lot easier. So instead of, you know, falling in love with AI, and we've all fallen in love with AI just due to the nature of it, and everyone's seeing, you know, the post that no more new developers or code is now being written by whatever percentage. But the point is we need to put additional emphasis on what problems are we trying to solve, and does it even make sense to solve it with AI? Okay.
Speaker 2:Now, the one thing to your question is my recommendation would be think about your number one problem right now. What's the biggest bottleneck in your entire process? Is it requirement gathering? Is it design? Is it technical design?
Speaker 2:Is it implementation? And look how you can accelerate, you know, using AI or any of the existing tools. Now, on what you just mentioned on, you know, moving from documentation to prototyping, I think this is the biggest change that is already happening. You know, you said nobody likes to write documentation, 100% with you. I think that, you know, a PRD is a document that development makes product right that nobody reads.
Speaker 2:These days are over because nobody needs to write documents anymore. And obviously we are exaggerating, but let's be, you know, futuristic for a second. I think this is already happening that instead of having the product write a 12 page document that, you know, maybe one engineer will write, to your point, they will experiment, they will generate their vibe coding. I'm already seeing great solutions that can take that, feed it into the existing design point, feed it into the existing code base, and then the development and the engineers will take that, fix it, make sure that it scales security performance, all of the non functional, you know, requirements, and everybody will be more happier because product will be able to better explain what they want, development will get it, and we will most likely shorten the handover between the different functions.
Speaker 1:One future that I think is possible today is a restructuring of the teams where you have a product UI UX team and then you have a engineering team which is just backend, right? So you're kind of taking away that role and responsibility of UI UX from the backend, from their, from the engineering team. And then you basically see the product UI UX front end developers working together, creating the full HTML, everything, and it actually works. It's no longer a mock up. And then the back end team just like makes it work, right?
Speaker 1:Adds all the web services and the microservices and everything. So that's a very tangible step that I think companies can do today and you know there's nothing stopping them from doing it. You still have the humans but the structure of the team, way they work is fundamentally different and you've moved from you know three, four teams and every time you have more teams there kind of more communication between teams to less teams, less communication, more efficient. So I think that's an amazing opportunity for all of companies out there. But you talked about risk.
Speaker 1:Let's dive deep dive into the risky part of this and the dangers of vibe coding because a lot of the engineers are like, no, vibe coding is evil. But my personal opinion is if you like it or not, it's going to become a thing ultimately, but we need to mitigate the risks. So let's talk about a few of them, starting with security. Vibe coding is creating security risks inside of the code, inside of dev, inside of the DevOps deployments across the board. First of all, let's understand what these problems are.
Speaker 1:And then let's talk about how we can potentially solve them with today's tools.
Speaker 2:So, you know, to me, Vibe coding is the evolution of low code, no code platforms, and those existed for many, many years. From Salesforce to ServiceNow, business apps, customer facing apps, have existed. It's the same problem only on steroids. What it means is the term citizen developer means that, you know, engineers or non professional developers are able to, you know, create apps and push them to production, which means that again, the good side, anyone can innovate. If you have an idea for an app, if it helps you solve a business problem internally, externally, anyone can expand it and write it and push it to production.
Speaker 2:So that's one thing which is great. But on the other side, also, you know, it's the perfect example of, with great power of gum, great responsibility. And security is not something that most people think about. Okay. And it's something that as the industry and, you know, coming from check marks as a security vendor, security professional, talking to many CISOs, many security people over the years, and something that starts with education, like understanding the risk of, you know, you now even have a travel app that you just push and I don't know, now your entire organization can open travel on their own.
Speaker 2:You know, I'm making this stuff up, but you get the point. Right? So first of all, it has to start with education. Just like, you know, a couple of years ago, and it still happens to this day, like everyone on the consumer side was launching campaigns against phishing. Why?
Speaker 2:Because, you know, if a phishing attack happens on a user, on a, let's call it a regular person that is not part of the enterprise, it possesses a risk to the, also to the company itself. So same should happen here, right? Now the risks here are very similar to everything that we've always done in software is first of all, like what's the impact that is going to happen? If you have a, I don't know, a read only application, then the worst case that happened is that, you know, the information will get leaked. However, what happens if it gets stolen, if it has the wrong permissions, so it might be able to access the backend.
Speaker 2:You know, you just mentioned the backend engineers, so it will be able to access the backend systems. And then if you have, like, I'm sure that the audience heard the term prompt injection. In the early, you know, web application, it was about SQL injection, and now it's prompt injection. So it's just the evolution. So just like on the tech side, on the creation side, on the defender side, the attackers are also evolving together with the technology.
Speaker 2:So we need to make sure that the right knowledge is there. And the big difference compared to everything else that we've done in the past is the pace and the scale, because vibe coding allows everyone, literally everyone in the organization to write applications, whether it's, you know, vibe coding, cursor, full vibe, like, you know, all of that. It doesn't really matter. A colleague of mine likes to say that the future programming language is English how, how do you, yeah, like how do you even, you know, secure English? Think about that for a second.
Speaker 2:So definitely exciting times, but I think it has to start with education.
Speaker 1:No, I love that point because if you don't understand your risk, you don't understand what can go wrong, you don't even understand how to defend, you know, just for a funny point, I think every single vibe coder at some stage is gonna understand the word sandbox that they probably never came across it before. It wasn't a thing that you know people in the street understood. But sandboxing is gonna have to be a thing right? Can your application access the internet? Yes or no?
Speaker 1:Can it extract information? What information is extracting? The stuff that you know email security professionals have been talking about like what data is being leaked, what is the types of data, like this is suddenly going to have to become to a certain degree common knowledge because everybody's going to be thinking about it. Now there's going to be two types of developers, I will argue. There's going to be the everybody developer and it's you know the marketing person and they're probably not going to be building SaaS applications from scratch but they will be building their own tools.
Speaker 1:And even these own tools, if you're using the leads and the customers of the company, that needs a level of security. And, you know, tenfold, if you're building a SaaS application at scale, obviously you need secure. What can we do practically today? I saw that Lovable has a small button to check the security of your code, but that's I wouldn't, I wouldn't put any confidence in that. But there's a lot of platforms that can do code set, for example.
Speaker 1:So scan your code. You get a whole bunch of security violations why not just take those violations back to the agent and be like hey can you fix these and then do the code set scan again and see well is this still an issue. So it seems like there's an opportunity to create feedback loops and to at least do something with these security violations that we have today.
Speaker 2:I fully agree and I will address that. But before addressing your question, one thing that unlike previous technologies that we have, and it's still the majority of them, okay? Like, you know, we like to think that everyone is AI, everyone is AI native. We are not there yet, but we're getting it faster than we believe. But the one thing that is different is the fact that agents and AI in general is learning all the time.
Speaker 2:So even if you give it a scope, the system itself can change its scope, which is really, really scary, which is I don't think we yet have a solution. I've seen a few early stage solutions that are going there, but this is really, you know, this is the main difference, you know, compared to a web application, you know, that, you know, you can enter username, password, you can download this, you can upload that. These are predefined actions that you knew how to assess the risk, put the right guardrails and manage the risk. In security, like many other areas of the, of our life, it's all about managing risk and, know, just like insurance, there is no 100%.
Speaker 1:Ori is going down on the deep edge now. Just want to kind of bring it back to the basic level. The reason why Ori is saying that it's better to have a smaller scope than a larger scope is because you know natively we think, oh, the AI doesn't work. Let's give it more information. It turns out that's the wrong solution.
Speaker 1:It turns out that the smaller the scope of the agent and the more focused it is on one task, the better job it will do, the less chances for it to hallucinate. So that point that Ori made you know very humbly is actually the future of a genetic program. It's the narrowing of the scopes, it's the guardrails of the agents, incredibly, incredibly important points. I just wanted to just to say thank you there for a moment and sorry for interrupting you, keep going.
Speaker 2:No, no, thanks for that. It's a good call out. So the one thing that I think we are about to witness is kind of a change of how we even test applications. Yes. And you know, coming from almost seven years of application security, and before that many years in DevOps and functional testing and everything, we're going to do a lot of combination of different types of testing specifically, and again, not to geek out on technology, but we're going to see kind of the evolution or revolution of dynamic testing, meaning to your point, there are solutions today that can test application like Lava application in real time.
Speaker 2:You can run that, like, you know, you mentioned the button that LavaBull has, it's a great starting point, but it's not enough. I think the opportunity is around to dynamically test, continuously dynamically testing your application. We're also going to see the fact that if you, very known and traditional processes, activities in security is going away, and is going to be replaced by agents. Pen testing is one great example that we see the majority of the analysts and the wide industry kind of pointing that out. So instead of having the human test it, whether it's weekly, monthly, doesn't really matter.
Speaker 2:You will have the agent continuously do that for you. And it also evolves over time. So I think this is kind of to your point, how
Speaker 1:To expand on that point, the old paradigm of pen testing is once a year you do pen testing, it costs you $50,000 $100,000 or if you get somebody cheap, 25,000. Huge amount of money. Completely stupid because all you did is you tested a point in time. So okay, so what that means is that the pentester probably one of the strategies they've used is they got the recent update that's come out of Microsoft or some other tool in your stack. They used more recently an LLM to reverse engineer that patch.
Speaker 1:You haven't patched it. Now they're penetrating your system using whatever patch you haven't patched. So is there value in that? My argument, no. But the paradigm that you're describing, this idea of continuous testing, whole different paradigm, incredibly valuable.
Speaker 1:In fact, even before we had these agents doing the work, I would argue against pen testing and against continuous white box audits once a month to make sure that you're not in risk in any way. But this is now the automation of that philosophy which is incredibly, incredibly important. Are we seeing this? Is this close or is this still a little bit into the future?
Speaker 2:It's already happening. A few things to take into consideration. First of all, testing will stay with us, I don't know, for the near future, mostly because of compliance reasons. You know, the fact that you have been testing to your point doesn't mean that you're really protected or again, there is never 100%. You can never be sure.
Speaker 2:Now, so while the compliance will still gather, and if your organization is waiting for the regulation or compliance, you're already late. Why? Because attackers will always use the weakest link in the chain, which is always, always humans. Now, what we are seeing is that instead of having the traditional attacks that are being covered by, you know, the pen testing of, to your point of snapshot in time of your application, attackers are already using your supply chain. And again, look at some of the recent attacks that happened.
Speaker 2:Hold on
Speaker 1:for those, for those of us who are not security experts, what does that mean? What's a supply chain attack? What does that even mean?
Speaker 2:Great question. Think of it as you have a bakery. Okay? The bakery in a very simplified way produces bread, Right? The bread is the application.
Speaker 2:This is kind of the analogy I want to give. However, along that way, you have the supplier that brings you the flour, you have your water, you have your oven, and you have your front of the shop and so on and so on. Now, think of that of the supply chain attack is by you eating the bread and getting a tummy ache. As simple as that. Now, it can happen because, you know, you got, God forbid, poisoned flour.
Speaker 2:Right? If you would only test, you know, how the bread looks at the end and the shape and the weight and everything, everything is perfect. Right? Because you're not looking inside. So to your question, this is what the supply chain attacks look like.
Speaker 2:It attacks the process and the components that you have as part of your software development. And this is now becoming more of a risk compared to everything else that you have. And this is where attackers are right now exploiting the weakest link, which is the supply chain of your software.
Speaker 1:So to get practical, right, you're writing your code, but your code is using hundreds, if not thousands of modules, which you're doing an NPM install, you're getting them off somewhere, you know, if you don't have the latest version, maybe there's a security patch that they haven't patched, but you know, maybe the latest one also has an issue because it's been attacked and changed. And in fact we saw a supply chain attack not so long ago which took down a whole bunch of computers all over the world. So this is a very real risk.
Speaker 2:It's not real, it's the only, it's not the only, but it's the major risk that you should care about. Okay? And it will only continue to grow with AI because right now with AI, and again, the pace of adoption is off the charts. We've never seen something like that, right? You know, GPT got to 100,000,000 users in two and something months, right?
Speaker 2:Never seen like And something like we are just getting started. So we are at the point that we don't know what we don't know, and hackers don't care. They will exploit that. And think about like, what's the goal of an attacker is to get something that you care about so that, you know, they can get the money so you can get it back, or they can take the data that is sensitive, confidential, and use it against you. This is what they want.
Speaker 2:So who said they have to do it on top of a run and live running and up and running like application? Who said that? If they can get into your developer or now citizen developer, you know, the vibe coding developers, they will do that. And they will do that much easier because of the education point that we mentioned before. I mean, the hackers only care about your application once they are in production, once they're running.
Speaker 2:It's been not that case for many years now because if they can, you know, if the application is the door, if they can get through the window, they will get from there. So this is kind of the
Speaker 1:It's your data. It's your customers. It's credit cards of your customers, it's the ability to send an email, authenticated email from your account so they can send real spam or SMSs or whatever. It's, you know, if I had to make one recommendation to my kids of, you know, what you should go and study in university, I think security is probably going to be a good bet for a long time to come.
Speaker 2:You know, it ties to the point is like, would the future generation university look like? Because even before AI, when, you know, a computer science student started in his freshman year, the majority of the technology that it would face in reality, in real world, in the industry were not even existing. Only when he will get there, he will learn the new type of technology. So this is, you know, a bigger topic to handle, but yeah, I mean, exciting times.
Speaker 1:It really is. So we'll finish with one final question. What is the one piece of advice that you would give the 18 year old thinking about going to study? Should they even go to university now or is that kind of stupid until universities figure out what to teach us? What should be the youngster's strategy for their future at this moment?
Speaker 2:So I'm still a believer in, you know, traditional, not traditional, but you know, in education, let's say it like that. And I would say, keep an eye for everything new that comes. Stay hungry, learn everything that comes. Like the pace of change is something that we've never seen before. And don't be afraid to pivot.
Speaker 2:Pivot your career. Pivot your life. Think about, I like to say to my PMs as I talk to them about their careers, like without a goal, it's hard to score. Right? So think about what do you want to achieve?
Speaker 2:Build a plan to achieve it, but also don't be afraid to pivot. Like if, you know, if we were to have this discussion like two hundred years ago and you would ask, like, would you like to be, I don't know, a horse rider? Those don't exist anymore. The point I'm making is humans always evolve. And I think we're already in the beginning of the evolution, you know, with self driving cars, with self writing code, everything that we've just talked about, vibe coding, I think it's, you know, about staying hungry and learning all the time, adapting to what's happening because reality and technology is changing everything that we do.
Speaker 2:So it's just stay hungry and don't be afraid to pivot. I love it.
Speaker 1:Ori, thank you so much for joining the show today. I appreciate you.
Speaker 2:Thank you. Thank you for having me. It was a great conversation. Thanks, everyone.