Cloud Security Podcast by Google reposted this
What a bummer. Definitely among my top 3 security podcast. Thank you Timothy Peacock & Anton Chuvakin!
A farewell to Anton, and farewell to the show (for now) episode https://lnkd.in/gPZBxrtP
Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!
External link for Cloud Security Podcast by Google
Sunnyvale, CA 94089, US
Cloud Security Podcast by Google reposted this
What a bummer. Definitely among my top 3 security podcast. Thank you Timothy Peacock & Anton Chuvakin!
A farewell to Anton, and farewell to the show (for now) episode https://lnkd.in/gPZBxrtP
A farewell to Anton, and farewell to the show (for now) episode https://lnkd.in/gPZBxrtP
Cloud Security Podcast by Google reposted this
I definitely enjoyed the conversation, Timothy Peacock and Anton Chuvakin.
We (Mike Armistead and I) were excited to have been on the Timothy Peacock and Anton Chuvakin - Cloud Security Podcast by Google. It was great catching up with some old Google colleagues, have a few laughs, and talk about how agentic systems are changing the way security programs should be run. Thank you Tim and Anton... https://lnkd.in/gd-u9k8y
A new fun episode is here: EP292 Inside Chrome Security: AI Patching, Agents, Rust, and … Your Tabs https://lnkd.in/geShNxU5 Guests: * Jasika Bawa, Group Product Manager, Chrome Security * Doug Turner, Engineering Director, Chrome Security
We have a fun new episode this week: EP291 Ruthless Prioritization: How CISOs Can Execute a Minimum Viable Security Program https://lnkd.in/dgN55ANz
Cloud Security Podcast by Google reposted this
Anton Chuvakin and I had a real Google security titan on the Cloud Security Podcast this week—and no, that’s not just Gemini being dramatic, our guest literally has a four-digit employee ID. We sat down with Christoph Kern, Principal Security Engineer, to talk about a phrase that has been copied from Google document to Google document for over a decade: "Eliminate whole classes of vulnerabilities." If you're on the outside, you probably think our marketing department wrote that. But it's not PR—it's actual math. We got into the weeds on why the industry's traditional approach to AppSec is a game developers are set up to lose. When you ask a programmer to manually track pointer lifetimes in C++ or juggle 16 different cross-site scripting rules in their head, you aren't doing engineering. You're doing software "craft." And when AI is writing more code than humans have the bandwidth to review, "craft" simply doesn't scale. Here is what we unpacked: 🔒 Hiding the Danger: Why the path forward isn't telling developers to "be more careful" (spoiler: it doesn't work), but hiding risky constructs behind safe, compiler-enforced abstractions. ⚖️ Compilers with Empathy: How to build highly opinionated developer platforms (like Google's Boq or browser-native safe types) that stop bad code from compiling, without driving your "software artists" completely crazy. 📈 The Rust Proof-Point: Real data from Google's Android team showing that shifting to memory-safe languages doesn't just decimate vulnerabilities—it actually boosts developer velocity and drops rollback rates. Whether you’re a Fortune 500 CISO trying to prove to leadership that secure-by-design is a productivity cheat code, or a developer tired of fighting your tools, this episode is a masterclass in how modern software actually gets secured. Check out the latest Cloud Security Podcast by Google episode "Software Engineering vs. Software Craft: How Google Scalably Eliminates Classes of Vulnerabilities" on YouTube, Spotify, Apple Podcasts, or at our site. (And yes, listeners, we also debated whether people tune in for the security insights, for the reformed analyst Anton, or just to catch Waffles' ears peeking into the frame. Drop your votes in the comments.) 👇 Link to the full episode below!
Cloud Security Podcast by Google reposted this
Had an absolute blast in the studio today with two true Google Legends! Thanks for joining me today Jasika Bawa and Doug Turner! Stay tuned for an upcoming episode of the Cloud Security Podcast by Google
Cloud Security Podcast by Google reposted this
Anton Chuvakin and I had a real Google security titan on the Cloud Security Podcast this week—and no, that’s not just Gemini being dramatic, our guest literally has a four-digit employee ID. We sat down with Christoph Kern, Principal Security Engineer, to talk about a phrase that has been copied from Google document to Google document for over a decade: "Eliminate whole classes of vulnerabilities." If you're on the outside, you probably think our marketing department wrote that. But it's not PR—it's actual math. We got into the weeds on why the industry's traditional approach to AppSec is a game developers are set up to lose. When you ask a programmer to manually track pointer lifetimes in C++ or juggle 16 different cross-site scripting rules in their head, you aren't doing engineering. You're doing software "craft." And when AI is writing more code than humans have the bandwidth to review, "craft" simply doesn't scale. Here is what we unpacked: 🔒 Hiding the Danger: Why the path forward isn't telling developers to "be more careful" (spoiler: it doesn't work), but hiding risky constructs behind safe, compiler-enforced abstractions. ⚖️ Compilers with Empathy: How to build highly opinionated developer platforms (like Google's Boq or browser-native safe types) that stop bad code from compiling, without driving your "software artists" completely crazy. 📈 The Rust Proof-Point: Real data from Google's Android team showing that shifting to memory-safe languages doesn't just decimate vulnerabilities—it actually boosts developer velocity and drops rollback rates. Whether you’re a Fortune 500 CISO trying to prove to leadership that secure-by-design is a productivity cheat code, or a developer tired of fighting your tools, this episode is a masterclass in how modern software actually gets secured. Check out the latest Cloud Security Podcast by Google episode "Software Engineering vs. Software Craft: How Google Scalably Eliminates Classes of Vulnerabilities" on YouTube, Spotify, Apple Podcasts, or at our site. (And yes, listeners, we also debated whether people tune in for the security insights, for the reformed analyst Anton, or just to catch Waffles' ears peeking into the frame. Drop your votes in the comments.) 👇 Link to the full episode below!
Cloud Security Podcast by Google reposted this
Adding a quick reflection to Timothy Peacock's great summary below: what really stood out to me during our conversation was the stark contrast between a theoretical tabletop exercise and actual "keyboard-driven" recovery. ⌨️ Testing resilience by actually recovering your cloud estate is a massive undertaking, and Noah Korba shared some brilliant, pragmatic lessons on how General Mills gets it done. It was an honor and fun to join Tim and Noah as guest co-host for this episode. To clear up any audio confusion: no, Anton Chuvakin hasn't had a sudden high- pitch makeover—it’s just me guest-hosting on the mic 🎙️ Now I can have my Cheerios (gf) 🥣 #CloudSecurity #IncidentResponse #BusinessContinuity
Group Product Manager at Google | Mission driven storyteller | Creator of zero to one capabilities | Scaling $B+ products for the world’s most targeted enterprises
Tabletop exercises are great for talking. But what actually happens when your engineers have to sit down, click and clack on keyboards, and rebuild 90% of your cloud infrastructure from scratch? On the latest Cloud Security Podcast by Google, I sit down with Alicja Cade and Noah Korba, VP of Digital Core, Cybersecurity, and Enterprise Architecture at General Mills. We dive deep into "Mills Collaborative Recovery"—General Mills' annual, hands-on, two-week drill to test real-world cyber resilience in the cloud. Here’s what we cover: ⌨️ Real recovery over talking: Why they moved past hypothetical tabletops to actually rebuilding their Google Cloud estate in a temporary sandbox. 🥣 Defining the "Minimum Viable Business": How they mapped critical data flows to keep the supply chain running (and ensure Cinnamon Toast Crunch stays on the grocery shelves!). 🔑 The IT/OT disconnect: The reality of recovering physical manufacturing plants, where you can't just push a software update without physically turning a key on the factory floor. Check out the full episode to learn how General Mills approaches business-wide resilience! Link to YouTube in the comments! #CloudSecurity #CyberResilience #OTSecurity #GoogleCloud #BusinessResilience
Cloud Security Podcast by Google reposted this
Reken CEO Shuman Ghosemajumder was on Google's Cloud Security Podcast, in conversation with hosts Timothy Peacock and Nolan Karpinski. They discussed how cybercriminals have evolved over the years in using automation to simulate humans and create fraud, from click fraud, to credential stuffing, to AI-powered social engineering and deepfakes. They also talked about Reken's Private Core platform, how its on-device AI system enables a big leap forward for the industry in security, privacy, and performance, and the difference between strong and weak network effects. Shuman reflected on the early years of Google, Trust & Safety, and launching Gmail; as well as Tim and his days at Shape Security, including a story about how regular Google podcast host Anton Chuvakin once proved he was one of the smartest security analysts around. Apple: https://lnkd.in/e8MrfWfr Spotify: https://lnkd.in/eFZChJ-5 YouTube: https://lnkd.in/ez-8s7Z3