Transforming Security: From Attacker to Defender with Mondoo’s Dominik Richter
Dominik Richter, Co-founder and Chief Product Officer of Mondoo, highlights the importance of reducing the attack surface and implementing proactive security measures, especially in the AI era. Mondoo uses policy as code and vulnerability assessments to address security challenges, introducing MQL for security relationships. The conversation also touches on OPA’s transition and Mondoo’s commitment to enhancing infrastructure security.
Transcript
Hey everyone. Welcome back here to Techstrong tv. I wanna introduce you to a first time guest.
I love doing first time guest on here. His name is Dominik Richter. And Dominic is the, uh, CPO Chief Product Officer and a co-founder at a company called Mondu.
Dominic, welcome to Text Drug tv. It's great to have you on here. It's nice to be here.
Good. So, co-founder, chief product officer. You, you didn't wake up in a cold sweat one night and say, I know just what I want to do.
I'm gonna go found a company and, and, uh, you know, put myself through this for a couple of years and hope, you know, we hope against hope. I'm one of the, we're one of the ones that make it. What, what, how did you wind up co-founding Mondu?
What have, what's your journey been like? You know, I've been in security pretty much all my life, uh, studying, you know, from hacking school networks to university and then finding my job in security. But the thing with security has been that I've been sitting on the attacking side for a very long time, and then one day decided, Hey, I've gotta switch sites.
I gotta see why is this so hard to secure? And in trying to defend it, um, I created a first startup in 2015 that did policy as code, actually mm-hmm. On the first frameworks to market, um, and brought security and the defensive side, IE the platform teams closer together.
And ultimately all of that led me to mondu today. Excellent. Excellent.
So you're co-founder. Who else founded the company with you? So we have a few others.
Um, we've got Christopher Hartman. Um, I, him and I have been working together since the Telco days. Um mm-hmm.
We've got Sue Choi, um, who has been in the, in the scene, especially with OpenStack and Chef software previously. And then we have Patrick Minch, um, another one of my, uh, co security, uh, hackers, um, who has been a co-founder of this as well. Very cool.
Um, so let's talk Mandu. What, what, what, you know, what's it about? What does it do?
What's the mission? So our mission is to reduce the attack surface of the world, essentially. Um, we decided that what we really want to do is not just add more findings to your list, but we actually want to help you to get better and help the world in having fewer security issues.
We know it's not an easy, uh, thing to do out there, but, um, we've wanted to make it easier for people to remediate and fix the issues that will ultimately get them hacked. Um, we've just recently looked at the list of companies again that get hacked like in an average month. And it is my personal data, by the way, it is your personal data.
My data got stolen last year, um, pretty badly. So Probably several times, several times, A few times. I gotta tell you, I started collecting, you know, you get those letters in the mail that says you might, you might, like, they don't know you really well, you might have been the subject or involved in a data breach here where you're personally identifiable information, including your social security number, date of birth, and everyth now.
And so we're giving you a year's free. Uh, at this point, I have a lifetime of free credit monitoring across all of the different ones from all of the times my data's been Breached at this Point, And that doesn't even have, you know, help anymore. Like I came back From, it's ruthless.
I, I use the letters. I just, I just like to see the stack grow because like you, I've been in security 25, 30 years. Right.
And, you know, I remember when they first came out when PCI first came out and the whole idea of providing credit monitoring first came out, but in the last year or two, it's out of control. I get, I get almost like once a week, My, my personal data has been stolen to the degree where people took over my, uh, the credit agencies, basically, they're there to monitor my stuff. Yeah.
So they had fake accounts on them because that's how far they got, especially at last year. I, I've been through that too. And so yeah.
And Addresses, tax returns sent and, and we're security people. Could you imagine civilians, right? How, how are they dealing?
It's nuts, man. If this happened to my grandma, I don't think what she would've done, I was able to react very quickly. But, um, I don't think they would've, so, no.
And that's what we're trying to change. Like, I'd rather, uh, people have fewer security issues, um, on their table that they can effectively solve. Especially now in the age of ai, you've got these attacks rolling out more autonomously, more automatically than ever before.
Like, we can't afford just sitting back and, and watching critical results fly through anymore. The attackers are just way faster. So, yeah.
Agreed. Agreed. So how, how are you doing it?
Let, let's hear. All right. So what we are doing is we are using a combination of policy as code and, um, vulnerability assessment in our environments to figure out what is the most pressing thing that is actually going to hurt you.
Not just the surface level symptoms, but what is wrong at the core. Um, back when I used to attack systems, I could usually see these very easy things that were being done wrong. Like, it's not even the hard stuff that people get wrong.
It is usually the easy stuff that gets you broken into and taken advantage of the most. And so for the vulnerability analysis as well as for the policy analysis, we are then usually looking at the entire context. So what is the system?
Is this really something that exposes you? How do you fix it? Um, what is the best way to approach it?
And that ultimately needs to be accessible to the people on the other side. That may be a entire team that you have. Those may be platform engineers.
They may use automation or they may not. We have a lot of customers who have like a bunch of Windows admins trying to fix their Linux machines. And so whenever that happens, you know, my fixes still need to be very actionable, um, for them so that they can go and fix the issues.
I love it. Um, I, I wanna talk OPA and stuff, but before we do, I want to just tie some bows around Mondu. Um, how does Mondo use Mondu use OPA?
How, what's the connection there? So, Or, or not, is it a replacement? You know, I, I don't mean to you go.
Yeah. So we've been looking at policy as code for a long time. Uh, like I mentioned, we did a previous startup where we started with policy as code.
Um, we actually came from the infrastructure automation side. So we built it around, uh, things like shaft software, which were used to automate operating systems. Sure.
And now we went into the cloud direction, but we realized with policy as code that we needed something that was accessible to a security professional, something that they could use and understand, and it needed to unify these different types of technologies that are happening and expose the context of them. OPA came up at tail end, um, after we had left there, um, I was with Google during that time. Um, OPA had risen to prominence and it had risen to prominence in the infrastructure, uh, security space to help write policies there.
Um, we had taken a look at it in the early days, right when we started mondu, but, um, similar to other frameworks we had then ultimately decided against it. We knew it was not going to be the right solution for us. Got it.
And, and so you, you guys basically developed sort of an alternative? We did. So we came up with something that we dubbed MQL.
Um, it is a query language that is, um, very much leaning towards GraphQL plus, uh, scripting for assertion. And the reason why we did this is because we realized, you know, a lot of these security problems that we're trying to analyze, they are actually dealing with relationships and context. So, um, we came up with a framework that a needed to be really, really good at expressing those relationship and that context.
So let's say for example, you've got an open process listening on one of your systems that can be attacked. Great. That process is usually reachable, um, because of some kind of cloud configuration, because of some kind of network configuration.
It may be rolled out through a package to all of your systems. So you need to understand where it's coming from, uh, what are the permissions it is running with, and so on and so on. These are all relationships.
And so we decided that we needed to have a stack that was going to be good at expressing relationships. So for example, is this a process that is running as root? Is this a process that is exposed through my gateways?
Can it be reads through that? And so on. All of this became one of the requirements why we initially looked at GraphQL, because as a stack, it is the graph alternative to talking to an API, essentially, the only thing that it didn't have was a strong way to express assertions or to mangle data and transform it.
And so we added those layers on top. We basically made it easy to, um, transform that data and to say, you know, much as to say, give me all of the users that this process has access to, but to say, none of the users should include your administrators, or none of the users should include to root. And so that ultimately became the framework that we used for policy as code.
Um, and we tested it with security professionals because our aspiration there was that it can be easily understood and can actually be used by the people that understand security the best and not just by developers. Got it. I, I want to pivot to this, uh, OPA and STYRO angle, but before we do, for people who want to go look up mondu now and grab information, what's the website?
com. Um, it has all the information about the company, but it is also connected to the open source projects that we have, CRO and C and spec. Um, if you wanna take a look at the open source there as well, CPEC is a great project that actually, um, exposes all these things that I mentioned about policy as code resources and how to do security this way.
Um, you'll find it through the website or through GitHub or Google Search. And mind you by the way, is M-O-N-D-O-O People probably see it in the bottom third with your name, but I'm just throwing it out there. All right, Dominic, let me, let me set the stage for this next part.
So look, I'm familiar with OPA, I'm familiar with the founders of, of the Styre company and the OPA, and they founded the OPA project. My friend Bill Mon used to be this, the, uh, CEO at Styre, though he left a while ago. And then, you know, apple did a very Apple-like thing.
They were big users. They still are big users of opa, of OPA, but instead of buying syra, they did it. They bought the people at Syra, including all the co-founders, all of the technical talent, and left the company as sort of a, a husk, an empty husk, an empty shell.
And basically Syra wrote to their customers and said, Hey, your, uh, enterprise level sup, your enterprise level product is end ending of life, end life. We're not supporting it. And for all intents and purposes, there is no styro.
And the good news is we've taken those enterprise level products that are built on top of OPA and given them to the OPA project, which is award of the CNCF. So they're not dying, but there's no one, you know, there's no throat to choke there, there's no company no longer a commercial company providing it. And, and the community will decide what to do going forward to continue it, not continue it, change it, not change it, what have you.
Good luck and good night. You know, um, this happens, this happens, right? It, it, it's, it does, yeah.
It's real life. So as you could imagine, a lot of enterprise customers of sty a as well as just ranka file OPA users are saying, Ooh, this, this sounds like it could, you know, what could go wrong? Right?
Um, and, and so they're looking, they're casting about for options. They're looking for help. Mm-hmm.
They're, you know, they want some reassurances. How was this affecting mondu and how, how are you guys responding? Yep.
So, um, lemme jump into the OPA angle first, because really if you look at it from the ground up, um, it was built for one thing really, really well, and that is authorization. Even when we started out, we started to look at a specific security problem that we were tackling. We're still building up a product underneath.
And I use languages and frameworks like anyone else. So, you know, we use Golang and things like React and other frameworks. And so, um, Rigo actually came up, um, for the authorization bit as well.
Um, we had evolved over the years out of it, but, you know, it is actually, um, purpose built for this and is doing a good job at that part. However, the problem is when you're starting to use it for tasks that it is not really originally designed to do well, and this is where the infrastructure, infrastructure security bits really come in, right? So I always compare it to like a spoon that I use.
It's great for eating your cereal in the morning, but once I start to dig a hole to build a house, uh, the spoon might not be the best tool to use. And so, um, as the star news has come in, a lot of users have, um, met that shocking day. First of all, the lack of clarity.
What is actually does that mean? But after a while, once it dawns that this product isn't really, um, having like its leadership anymore to lead us into the future, um, they feel that the problems that they had raised, especially around the infrastructure security use cases, are not getting addressed. And to be quite frank, they haven't been getting addressed well in the last couple of years either.
Um, a lot of us were looking at Sty a and OPA because we saw that it had this widespread use in the Kubernetes community and that it's going to be fixed eventually. Like all these problems that we're having, and we're waking up to the reality that that's not the case. And so for us, this meant actually, um, new users who are coming in, who are asking us how we tackle the problem for po um, infrastructure security, cloud security, and other use cases with policy as code and what we can do with it.
So as the first couple of users have been diving in, because you know, now it's worthwhile looking at the alternatives, they're actually starting to realize how many shortcomings the original approach with OPA has had in the use cases that they were trying to solve. Yeah. This is akin to sort of the, uh, the Broadcom VMware kinda thing where they, you know, they tripled the, the licensing fees and all of a sudden it became a, a reason for everyone to say, wait a second, there's alternatives, right?
Yeah. We could go to the cloud, we could use what the cloud provider has. There's, there's other alternatives that are cheaper that are maybe better.
Um, so that that's what's going on here. Now, there are some people who've made big investments in OPA. Yep.
And to rip that out, you know, no one likes to rip out if something's working right. Don't fix what's not broke. Yeah.
How's Mondo helping those people? So, um, what we are starting to realize is, first of all, um, in the infrastructure security use cases, you might have the investment, but really double check, is it working for me? The more we have talked to companies that have this use case that are using OPA there, the more we're finding that they're getting stuck with it.
It is very hard to spread. It is very hard to grow. I mentioned it before, right?
It isn't, it hasn't been built for this use case from the ground up. Um, so teams are often getting stuck. You will find, uh, teams of developers that are trying to, um, use this for security use cases and the security professionals on the other hand also not being able to use it as effectively as they should.
Um, and so our experience is really take a look at that investment and take a look at what it does today. A majority of the companies that we are finding, um, they just want their standardized policies to be used, um, for cloud or for operating systems and for the other systems that they're using for that. Actually mondu comes with most of these policies out of the box.
So you can just plug and play. It is not, um, really hard to replace for that use case. If you have written a lot of custom policies, well, we're finding ourselves in the age of gen ai and it is actually making things a lot easier to move things from one stack to the other or to use Gen AI for writing policies.
We have actually been growing our own policy teams this way over the course of the last year. Um, we've written the, uh, context that the AI needs to write good policies for you and to express them both with MQL as well as with our YAML based policies that we have. And so we have a lot of this tooling that makes it easy to convert the policies into something like MQL.
So you aren't stuck with OP and Regal. Um, it is not like you can't move off of it. It is actually something that is more feasible today than it would've been like two years ago.
Moreover, what we are finding, especially with our larger customers, is that the difficulty for them comes in managing this across their organization and being able to handle things like exceptions. Well, and this is really where OP and Rego have had the, the least capabilities. Um, the more we're engaging on these use cases, the more people are realizing that they can already do a lot more with MONDU and MQL today than they ever could have with OP and Rego.
And so it's suddenly doesn't just become a, you know, let me replace this, but actually let me do this better. I love it. Dominic, we're about outta time, but I think people got the gist of what you're saying here, right?
I want to just tell 'em one more time. Where do they go to get more information on Mondu? It's M-O-N-D-O-O.
Yep. Com. Com.
That's right. Com. Come drop us a message on the website or say hi.
Um, feel free to reach out. And then also on the open source, if you're interested in that, if you're coming from Opa rego from the open source side and you're interested in infrastructure security, cloud security, any of that with policy s co, feel free to reach out. We've got a great project there.
Excellent. Will you guys be a CubeCon? Um, we might.
Um, we are looking at that right now. Um, for now we are going to Hashi Con, um, if you wanna see us in a couple weeks. Yeah, same thing.
So we will be there, Textron. Uh, I won't because they're, they're too close to each other. And then I can't be in two places at once anymore.
I used till Quantum computing comes out, then I will be. Um, but for now, shredding Hers on. Right.
Um, anyway, thanks for coming here on Tech Drunk tv. Don't be a stranger. Come back and keep us posted.
Okay. Will Do. It's been great talking to you.
Alright, Dominik Richter, chief Product Officer, co-founder at Mondu here on Tech Drug tv. We'll be back in a moment.