Noname Recon – Filip Verloy, Noname Security
Noname Security recently announced the launch of Noname Recon, the latest addition to the company’s API Security Platform. With Recon, customers are now able to simulate an attacker performing reconnaissance on an organization’s domains, allowing them to rapidly find and fix issues – without any integrations, installations, or implementations required.
Transcript
This is Textron TV. Hi, welcome back to Tech strong TV Our Guest today right now is Philip vilroy. I hope I pronounced that right we do the best we can Philip her life.
Hello, Philip. How are you? Yeah, thanks.
I'm glad to be here. To the record. Why don't you say your name correctly because God knows I mangled it.
Oh, no worries. So it's a Phillip Philly. Okay, and then Philip why don't I didn't even mention the company name or your title?
Why don't why don't you give us that? Sure, so, I'm the field CTO for the image in I'm here. That's a no-name security.
So I typically work with our larger customers and and partners and I sort of talk more broadly about the API security space as a as an industry, but other than directly talking about that Technologies. I love it where you based, by the way? So I live in Belgium, but I travel all over the world.
So today I'm talking to you from New York. But yeah, I'm typically either in an airport or on airplane summer. I know that life actually 2023 is shaping up to be.
To be like that again on the road. But yeah, you know it after three years of not go two and a half years of not traveling. I'm actually looking forward.
To traveling a little bit a little bit. I'm sure I'll be sick of it by June. But anyway.
You know, why don't those as long as we're talking about where you are and where you going where you been? What a little bit of your background Maybe. That's sure so yes, I've been in it for over two decades now.
I started on the on the customer side. So I was an IT administrator for a while then I jumped into consultancy. So I worked with a lot of Enterprise customers all around Europe doing mainly networking and security implementations kind of got interested into the fertilization space and Joint VMware was there for a number of years then joined my first startup which was a data security staff of both rubric when I was a field CTO for about six years and now since since about 10 months or so, I'm happily employed at no name looking at securing those those apis.
Fantastic You Know Field CTO. Our audience is technical. They they've heard the term before it's been around now for a while, but you know, it is relatively new there at one point.
There was just a CTO. right and in my you know, I I did a bunch of startups and security myself and Infrastructure, and you know this cto's back then came in two flavors. There was what we used to call the forward facing CTO.
He would talk to a lot of customer and it was always he back then unfortunately was very few women, but he would talk to a lot of customers he would talk to analyst press, you know a forward facing. Kind of CTO a lot of marketing. It's part of that role and then there was the technical CTO right who oftentimes results of the VP of engineering or ran product or you know was more involved.
Let's call it on the back of the house. And now we we have this notion of a field CTO and an organization's big and smaller using the field CTO. And this is the tip of the hour that that part this person is now the tip of the arrow in dealing usually with customers, right and and some of the Marquee Flagship customers of an organization really, you know, holding their hand understanding what their issues are what their feedback is what their wants are and and really, you know, then becoming that translation point.
back into the vendor to say hey, this this is what our customers are seeing what they want what they desire what we what we're doing. Well what we're not doing well and and so it's kind of a combination right? There's a back of the house function but very much so front and center Yeah, that's exactly right.
Yeah, so I'm definitely more of a customer facing person. Hence, the field part I guess of the title. Yeah, but yeah, I do talk indeed to a larger customers and got us there really important feedback, especially since this is a developing market, right?
So API security it's been around for a little while, but the types of solutions that we're developing and how we figure out best serving. Our customers is sort of a developing and dynamic Market still so their input is extremely important to take back to the engineering side of the house as you mentioned. Yeah for sure.
Absolutely. So you mentioned a few times API security. That's no names business.
Right? No name was I I think one of the first unicorns within API security probably the first um, they've been added some time and you know API security was a bit of a slow burn at first, but it's really come on gangbusters really strong in the last year or two as You know, I'm not as a replacement but is the new attack surface as the new Battleground in application security. My personal opinion is what's really ignited.
The API security space is the move to microservices based architecture. I I think we had a lot of apis from applications talking to external. applications and components, but when we went to microservices and containers in this whole Cloud native thing the API to eight, you know, the the internal the internal API, you know back and forth.
It exponentially increase the amount of apis we're using and and with of course with it the amount of attack surface. We got to be worried about. If what do you think?
Yeah. Yeah. No, I absolutely agree.
So so as you mentioned apis have been around for a long time, I think theoretically you could say since 68 or so, but there were mostly used for let's say configurational type of approaches where you could use an API to maybe change some things on your networking infrastructure and so on. And then more and more what we're seeing now, of course is applications talking to Applications across API sending data, sometimes sensitive data across those across those pipelines. And then as you rightfully mentioned with sort of the rise of microservices and distributed architectures, everything is now interconnected through apis, even if you look at a public cloud and the way that you consume services from up from a public Cloud you're essentially as a consumer of public cloud services talking to an API.
There might be a nice rep in the phase in front of it. But essentially you're talking to an API and consuming all of these Services fire and API. So apis are really everywhere even from a an Enterprise perspective based on our own research.
We're sort of saw that apis have grown over 200% here over here compared to last year people building their own api-based application. So yeah, it's it's definitely come to the foref. Much more lately.
Absolutely. You know and we and with that we've also seen a rather rapid evolution of API security. Solutions, you know my take on it and and I have a pretty unique seat here right fella because I get to talk to people like you all day, but my take on it was kind of the initial.
The initial focus of the API security crowd or Market was hey, you can't defend what you don't know you have so the first thing we got to do is identify what apis you have and and how they're configured. Right and that proves that that's not a trivial thing to do either, you know, we because it's kind of hunting in the dark there because you don't really know what you're gonna find. but I think Not just no name, but a lot of the API security vendors have kind of reached that level where they do a pretty decent job of discovering your apis.
But now I think we're ready for the next phase of API security and that brings us to what I wanted to talk to you about today, which is some recent product announcements new features functionality coming from No Name. Yeah, absolutely. So I think that definitely right.
So Step One is and I think will will be for a long time building a full inventory of all of your apis. And so even before we started talking about dedicated API security offenders or specific Solutions, you already had things like web application firewalls and API gateways to some extent they can Implement some security controls around apis, but of course if you is fairly limited as you mentioned before you can't protect what you can't see and they only see a limited amount of apis they don't see when we talk about micro services. For example, all of the east west traffic typically doesn't pass through your north south gateway to the outside.
So so there's a lot of innovation that needed to happen there to make sure that we can capture all that API trust but you're right. We're sort of move beyond that point and we're now looking into things like, how can we use AI? machine learning to really understand the business logic behind those apis and then tell you interesting things about people potentially trying to manipulate the business logic behind those apis and what we've done now is Not only have we focused on let's say internal API sort of initially.
What do you have in-house and how can those be consumed externally a potentially misused? We wanted to go a step further with our with our new solution called recomm and look from the outside in. So what we keep seeing is in the news, there's API breaches happening.
All of the time like Optus was a great example recently in Australia, but people figured out how to manipulate their apis and get the sensitive Pi related data. So it's really about trying to think like an attacker. So that's what a Recon tool is now focused on is if I'm an attacker and I'm sort of scoping out a potential victim from the outside in what are sort of the things that I'm looking for to take that next step in my attack.
So how as an organization am I exposing myself externally, so this is about you know, maybe you have documentation exposed externally that you don't want people to know about maybe that's credential flying around maybe in like get up repositories or Postman workspace or even your API externally leaking some of that information. That's what the attacker will use during the econason's face to then figure out. Okay, how can I take all of this now?
And perform the next level of my attack and gain entry into your into your organization. So that's really gives them the customer a good understanding of what is the external attack surface look like in terms of apis and what do I really need to focus on so I think security having been in security a long time as yourself, like there's a lot of noise and we have to sort of I figure out the signal to noise ratio a little bit better. So so what do you focus on first what's super important?
And I think if you look at that outside in view that is high priority, that's maybe even Priority One because that's how the attacker will gain entry to your into your environment potentially. So if we can fix those powerful abilities, that's that's a good first step. I think so, that's why we launched this this new tool just last month.
Excellent and thank you for that. So the tool was launched last month. What you know you're out here talking to customers.
What are you hearing from them on it? Yeah, dude really impressed. So we got a lot of extremely positive feedback.
So if you compare it with the solution that we already have in market for a little while. It's really good at as you see getting an inventory showing people what they have. Of course, it also tells them about what potential vulnerabilities they have in terms of misconfigurations and so on but this really brings the light another level of sort of let's say emergency sort of vulnerabilities that they need to respond to really really quickly and usually it's completely unknown to the customer.
So in terms of showing them, this is what the attacker would see from the outside in so this is how you're exposed plus you don't need to do any installation any implementation any integration you just give us your domain as an input and we'll give you this view from the from the attacker. So that's that's really really powerful because it's a all part to entry for the customer and we get a really big amounts of value really really quickly in terms of a report or an overview of their their exposure. excellent You know what not no name customers new people say hey, this sounds something I'm interested in.
Can we you know, I'm not gonna make you the sales guy but Philip Howard. You know, how is the price? How's it offered?
How do people get on the on-ramp for this? Yeah, so we for existing customers. It's an add-on to the to the existing platform because of course.
We we also want to then do something about it. Right? So showing them what the problem is is a nice is a nice First Step, but then you actually also have to do something about it.
So that's why it ties into our existing platform there. But yeah, we are open to having an old current customers of course work with this. So if you reach out to a No, Name sales rep we can definitely make that work.
The reason why we are doing it through sort of no name and the No Name past and network is this is something we can't just publicly give to anybody because that's potential for me to use that. Right? So you don't want to have your competitive scan your domains and see how honorable you are.
So that's why we sort of do it this way. But yeah, it's as I mentioned because there's no installation or integration or anything it requires. We can sadly quickly spend this up for a New Prospect.
And give them that feasibility into that external attack service. You'll say that I so back in 2003 or 4. 3 the company I had helped co-found and Boulder we came out with a vulnerability scanner.
and back then, you know you had things like messes and end map and qualis and found Stone stuff like that and that was like a pretty popular thing qualis was one of the first trading call it Cloud. We didn't have a cloud but cloud of Carlos was an external based scanner. And that was something a lot of companies did they would try to you know scan their competitors Networks.
for vulnerabilities and yeah We still it's still out there. Right? And this is what you got to do stuff like that.
Yeah, I know exactly like. Exactly it. Hey where we're better than you know what I didn't I don't even think did we mention the website?
com. You can find like the launch information of of the recount property on there. Of course.
Also, our existing platform is mentioned there and then I want to give a quick shout out to like we tried to do a lot of Education around API security as well. I think that's still really needed. So we do have something called No Name Security Academy, which is a free resource that you can use to learn about all of these issues when it comes to apis and how you can think about protecting yourself.
So that's completely no no name specific. It's more about educating. The broader marketing is is also super important.
Cool, man. That's great. Philip thank you so much for coming on textrung TV.
We're gonna let you get off here and hopefully make your way home to Belgium soon. Thanks. Love them.
All right, maybe we'll see you on the road. Take care now. Just all right.
We'll be back here in a minute on Tech strong with our next guest stay tuned.