Bromure Secure Browser, Nessus Origins, Overbearer Proxy, Coding with AI, Fundraising in AI
Watch episode on YouTubeOkay, we are live. Renault, it's an honor to have you as the first guest on this interview series. You are by definition the OG, the GOAT for building defensive cybersecurity solutions. You started way back in 1998, creating Nessus, created Nessus, then you co-founded Tenable with Nessus as the key product.
And I had this unique privilege to watch you both you and Ron scale tenable from where it was in 2001, to what it is today. And the lessons I learned watching you guys scale the company is still ingrained in deeply in my consciousness. So I'm super grateful that you are part of this interview series. We are gonna make this super exciting. This is gonna be super fun. So let's get let's get started. So, Renault.
First question I have for you, the first question I have for you is what was your open claw moment in nineteen ninety-eight? Like why did you start Nessus? You know, like what happened in nineteen ninety-eight in you, I believe you were a teenager, either out of high school or just doing college, and you started this project and it became immensely popular within like first one year or two, and it just you know and it took out from there. So what what was happening in nineteen ninety-eight?
Mm-hmm.
Yeah, yeah.
You know, I think I think it's very similar to some extent to what we're seeing now with AI and innovation every day and new product every day. Like the late 90s, which is over a quarter century ago, you had the explosion of open source, right? Like Linux was being like di f from ninety-six to two thousand, Linux went from nothing to like, hey, this is a very viable platform.
And it was a very pro open source period. You have a bunch of people writing code. At the time, the reasoning was that anything open source was bound to be better than commercial software. So whatever you would write. And and yeah, and I saw that, I saw the explosion of internet. And I felt with the explosion of the internet, a, you know, it was a no-brainer, everybody would be connected one with the other. And two.
I was my reasoning as I was learning Linux and all that, I was like, well, there's no way everybody's connecting servers properly to the internet. And so the idea was, hey, let's do another many software which is going to kind of like tell you what you did wrong with your config. and then it kind of took a life on its own.
And y you know, in those days, I don't think security was like a primary decision maker in pushing software out. You just built something that had a functional use case and can get that out. You know, maybe it's a file transfer or something else. And you the goal was to get the functionality out, not necessarily getting thinking about the security aspects of it. And tools like Nest.
Yeah.
No, because no, because a lot of companies, you know, their websites, they were like you remember in construction, you know, you would go to whatever IBM.com and you had assigned thing in under construction. there was not a lot of sensitive data. You still had a big segregation between the internal processes of a company and their external things. So yeah, security was not top of the mind, but it was clear that more and more
of the process would move would move to the internet.
Yeah. And you know my my r my recollection, my recollection of early Nessus days is that you were very frugal in terms of how Nessus used the the the CPU or the memory on the system when Nessus was running because you are literally I I believe I have seen in some cases you did like assembly code.
instructions in Nessus to extract the most out of the hardware that is there. Like I'm curious, like what were you thinking in terms of design principles? Because you was very you were very involved in the entire development of Nessus. Like way till like I guess even like till 2010. You were literally writing code going in.
Yeah, yeah. Well I think well it was a different time, right? I mean the the computer I was using at fifty-six megabyte of RAM at the time. so that's not a lot. Which was huge. And it was not 64 because 64 was a little too expensive, so I had to kind of like cut down on one on the hardware. but the
That is huge. That is huge in those days.
No, I think I think it was a different time. I think the way you would scale at the time was really trying to make software as efficient as possible on a single host. You know, that's a big design pattern. And so the idea with Nesses is a more and more people you need to put, you know, you your typical network is like a slash twenty-four in the enterprise. So that's like two hundred and fifty six hosts. So you need you need to do that in parallel. and so if you scan a hundred hosts in parallel, fifty whatever the number is, you know.
Please.
And you you you compare to the amount of RAM the computer has, you y you have to be very frugal. and also at the time you didn't have a lot of like off the shelf software. I mean it was a very CPU conscious kind of era, a memory conscious era.
In a very on prem era, right? very on prem era the device.
Completely on-prem. Completely on-prem. I think having I mean downloading the updates, downloading the plugins from Nest, I I won't say, I I won't say it was like completely novel, but it was like the that new wave of software. You know, it was part of that new wave of yeah, yeah, you don't need to go to the vendor site and update manually, it comes by itself.
You know, one of the most underrated features that I that you know people don't appreciate as much, and this is like this was working in two thousand three, is the ability to push plugin updates multiple times a day. This was essentially CI C D working at scale back in two thousand three. Because you know, from our perspective, we would just, you know, write these plugins, ship it out. And this some of these plugins were completely new functionalities like compliance, malware detection.
you know, sometimes we did the DLP. I don't know if you remember, you know, these plugins we shipped, they were signing like the floppy drives and they were creating all kinds of chaos in the support team. Like my floppy tribe is crazy going crazy. And like the advantage of Nessus in those days was as a product person, you didn't have to like ship features.
Yeah.
You know what I mean? Like you could do a big release once a year. You could do a big release once a year, but like the core functionality, the customer should still get value with the plugins that I think.
Yeah.
That was that's the one thing I think I did right. which so you know a lot of a lot of things I would do differently today. But if if if you look at Nessus back in the day, it really was a script engine which would execute things against a number of hosts. And once the language became powerful enough,
Yeah.
Yeah.
yeah, like a lot of things could be done. And and and and actually, you know, there's a lot of internals in Messes which rightfully so are kind of completely unknown, but like so we had this language that we did ourselves. We had
a binary format, you know, remember the NBA so that some plugins we didn't want the IP to leak because that was after it was it was post open. and so we had this kind of compile system. And and the plugins themselves, a five format, was similar to what you have like on macOS with a fat format where technically you could support different bytecode. We never used it, but the idea was hey, you know, if if we change the way
NASL does a bytecode, we could so you can version it and you can have like multiple it's called a fight binary on the macOS when it supports both Intel and and ARM, we could we could technically do the same. So a lot of little things which were yes super precise, super finicky and and and fun.
Curious though, like you know, taking up this task of creating your own new language when others existed is kind of outlandish. I didn't I didn't say that. Outlandish. For you know, like you're young in the early 20s, I believe, to have the guts to say, hey, I'm gonna write my own language and I'm gonna control it. And then, you know, at least like for me, like a plugin developer at those in those times.
Yeah. That was a mistake. No, it i no, but it was not y it's it's actually
The language did enough to get our job done. It it did network connectivity, it could, you know, we could write exploits, confirm the vulnerability. So everything we needed existed in there. And if we didn't have something, you just added new features in the language and we could use it in the next version of Nessus.
Mm-hmm.
Yeah, well so initially plugins were written in C. Like it was really like a shared library we would load and unload. That was like version alpha one, I think. after writing a few, I realized that most of the plugins what they were doing is open a socket, send a buffer, receive a buffer, match a batter, right? And so going back to that memory scarcity, UI language is a
Yep. Yep.
At the time it was Pearl. Lua was like still very unknown. So really like in the late 90s, you had Pearl and Tical.
That was the one you could embed, and Perl was not meant to be executed in parallel, like to have like 50 kind of like threads in parallel processing. So it would have exploded. So that was one thing. Like, okay, we need a language which adds maybe half a megabyte of overhead when we execute it. The other design principle is that I was very scarred by Satan, which was the granddaddy of Vone Scanning.
Yeah yeah yeah.
And and the issue with Satan is that it relied a lot of like on external binaries and libraries to do its job, right? It would call ShowMount and all that. And I had a terrible time to install it. And else period, I had just like some weird version of Linux. and one of my design principles was that Nessus should be self-sufficient. And if we use something like Perl, the issue is that.
People will spend half a day just to install the modules and then we're going to lose track because that module got updated and it broke some plugin. We so I felt like controlling the environment was safer. Now that was a mistake to stick to it, right? Because the plugins became more and more complex. You know, it's one thing to send a buffer just to check like the version of a banner, but like you know, we implemented the full SMB stack and thing like that. So so it's time to become like a little bit more more more complex. number two.
when we became a company, I realized that
I mean my my take was, you know what, it's it's just just learn the language. You know, if you're good at computer, just learn a language. And and and I would even if if if you interviewed me in in two thousand three, two thousand four, I would probably tell you it's a great filter to to weed out the bad candidate. the issue is that A, we spend too much time kind of doing basic libraries, like, we need base sixty four or anything like that. and the second thing is it's not great for recruiting because
Sure.
When you recruit people, they well, yeah, because they come in rightfully so, and they're like, Hey, I'm going to improve my craft, and I then I want my improved skills to be transferable to my next company. And and a lot of people they're like, I'm learning a language I will never use anywhere else. What's the point? And so double-edged, so we on one hand we would control the runtime and all that, and and also like controlling the runtime was like you know, that you have a lot.
Yeah, really hard.
safety features in the Nessus language. Like you know, a plugin cannot open a connection to a third party host. If it's starting to use a little bit too much anymore, it's being killed. Like you have a lot of things like you it can't open local files, you have a system of privileges. So that was good too because it you know the idea was hey if if if if somebody if if there's a a a supply chain failure as we can see right now, you know very far thinking.
consequences won't be that bad. You know, we can contain them and and so so it it it helped a lot, but yeah, I I think in hindsight, if I had to do it today, first thing I would do would be to get rid of Nazal and move everything I can to a mix of JavaScript and and static JSON definition. A lot of local checks you can just do a JSON definition and have a built-in engine.
So so let's let's on that. Like so, you know, you know, you had this foresight of you know building the NASA, you know, with the mindset that you had then. But if you were to if you were to do it now, if you were to do re-implement Nessus today, how would you do it? Like which which which languages would you use, which which what would be your tech stack to implement Nessus?
It is
Yeah, I think so so the big difference today is that you've got enterprise quality building blocks. I mean the size of the building blocks has really changed if you think about it. Like late 90s, your building blocks versus some some C library which passes like style sheets, you know. and that was the most complex. OpenSSL was a big one, right? now you've got
Yeah.
in Kubernetes, Click House, and and and a bunch of of of technologies like that which expand what your software can do. So if you know if I were to build it today, you would have it would of course be multi multi-process, so it can scale horizontally in Kubernetes. It would use a message queue to distribute the load. So if something crashes you can still like recover the scan. In terms of
pure language, I don't know, probably a mix of Go and Node.js. you would use Cleek House for the backend so you could see the result over time. That's something I always wanted to do, just have a a way to point to a host and like have a a timeline, like what was this host like six months ago and what is it now? and so so yeah I think it would be it would be very different. It would also be harder to install. So is
Harder.
Well yeah, because now if if I use all this, then I need to supply you with like you need to have your Kubernetes cluster and all so that's where you have so much choice now. You have to kind of optimize at the from the get-go, is it like a desktop app or is it is it really like enterprise scale? And I think I think that Nessus was kind of like between the two for the longest time.
Like it would work well on the desktop and also would work well on a dedicated server. but yeah, if you want to take it to the next level, you have to pick you can you can do both. Or maybe you can have a hack with Docker Compose, but.
I have like two follow-up questions on this. One is one is, if this new architecture was implemented, what could it do that the current version or what would what ch or efficiency gains would we see in the new architecture compared to what we have in Nessus? And then I remember like Nessus went through a big architecture change when it went to a SaaS model from an on-prem model. Were some of these changes implemented then or are those still a work in progress?
No, so so the base Nessus engine when I left was still that kind of like monolithic on-prem server. And then you would have the SAS component kind of d d divide the work and basically say, Okay, well, here are five IPs, you scan that, and then it would connect to something else. But the problem is that
Nobody else.
It's not efficient on many ways. It's not efficient because every time your SAS thing would distribute some load, you have to compute okay what which plugins, which preferences. It it's it's a lot of like overhead. I think if it was done in a modern way, you would just have one big cluster of scanners. And and that would be it. And then if one of them crashes, you don't have to distribute the load, it's just host by host.
plugin by plugin within just distribute. so I think it would be it it would be just more efficient use of I think with the same hardware you could probably have like three, four times the output.
Do you do you think that this new architecture will in theory allow internet wide scans with Nesses at scale? Like, you the show runs of the world or the censuses of the world, like, you know, you power this with this completely new architecture. Because that's I believe like I don't think the Nessis level scan of the internet exists. You know what I mean?
No, I mean I guess I I guess you could I I don't think it would be the most efficient. I mean look I mean look you can re i i if if we're imagining rewriting everything, I guess you can imagine rewriting rewriting it for better scan. Nessus was not fully i if you look at the mass scan or thing like that, the efficient the the use of the bandwidth is really is really well done. Like you have a lot of things done extremely well.
The overhead of the you look at Nmap, the overhead of Lua is actually lower than NASL this point thing. So I I guess you could get closer to internet scale because yeah, if you have a large cluster with ten thousand nodes, I mean if you just throw money and brute force to the problem, you can make it work. but yeah, I think it would be there are better ways to do that.
What do you think is like, you know, what do you th think is the future of like defensive cybersecurity in the age of AI? Like, you know, what tools do you think are promising in terms of like, you know, like you know, attackers finding things on the internet? Like what what's your opinion on the future of defensive cybersecurity solutions?
Yeah.
I I i it it's it's it's a tough one. I mean well this week just for context, right? We we're witnessing in real time the complete collapse of the supply chain. every day you've got new Python and Node.js packages being like found out as so it's I you know i i it's t I think
I think AI helps a lot in everything which my view of where AI development should go is that you could imagine a world where generated code is safe enough. And you could imagine a world where Anthropic or whoever open AI, whatever they want, doesn't stop at producing the code, it puts it in production. Right. So you could imagine a world where you talk to your cloud and you say, Hey, I want
Yeah.
the best guessbook you know you can think of and then it's like okay here it is it's up and running here's a URL the certificate has been has been done and then if you approach it this way it would work really well because a as an end user you don't have to worry about the infrastructure right so
Forget about cybersecurity. Like it's not even defense, it's like it's better, it's things are valuable because you don't you don't see the infrastructure, you have professionals running it, and then they would probably use a cook cookie cutter approach of like, okay, for every time we need a database, we use this, every time we need a a key value memory store, we use mem c whatever it is. So you could abstract this and and think directionally, things are going to get way, way better.
So to me, that's kind of like my existential question. Like, I think AppStack is dead. I think that reconnaissance of your infrastructure is changing a lot. And maybe there's no infrastructure to think of. And you know, it's it's like it reminds me a little bit, you know, when the iPhone came out. There was a question of how who is going to be the security leader? Which security tool are we going to run on the iPhone? And the answer was.
Hmm.
the platform is safe enough. And and I I wonder if that's where it could things could go. I mean not not for everything of course, but I I I think that where AI can help a lot. So so help can help a lot when you create the code and of course AI can help a lot with like automation of maintaining your environment if you choose to run it yourself. I think the faith we have in the technology of the last six months has been multiplied by what five.
And okay.
You know, it's funny because we kind of like kind of went through phases as an industry, right? It came out for the cooler thing. no, it's really dumb. I agree, it's really good. I think right now it's we're we are in a it's a really good phase. Maybe there will be some more disillusion, but I if you look at the velocity, I think in two, three years, you can imagine a self healing kind of digital infrastructure.
Speaking speaking of velocity right now, you went from, let's switch gears a little, you went from running one project, one open source project converted to commercial for 25 years, and then you switched to two open source projects in two and a half weeks. So your velocity has increased thousandx. If you just take in the raw weeks that has taken.
Yes.
Yeah.
for you to shift new projects into the world, what changed? Like, you know, you you're like completely dedicated for 25 years for one project and then you went, and I I believe there are more projects coming too. So what changed?
well I think I mean I'm having a blast, honestly. I've been using coding tools for the last two or three years. you know, so I I've kind of witnessed and and I you know I published two projects. I have I think I have ninety-one private GitHub projects for a lot of like automation and things like that. So some of them are really dumb, some of them are super useful, but for me.
But do you use it internally for your projects or is it just your
Yeah, j j no no j just for me, just like you know, I like to experiment. I think lately I'm having a lot of blast because I'm having a blast because the I think with Cloud in 2026 you can really focus on your vision and it finds ways to implement it. Don't have to worry about i I I think as developers we kind of
We're a condition to what we know and it it it it does shape the vision. If you do something by yourself, it does shape the whole vision a little bit. Like if you don't know anything about virtualization and it's like an open source program, then maybe you won't start, you maybe you won't try, right? Because you don't know where to start and it's a thick documentation. I I think with cloud you can say, hey, I'm envisioning this, make it work. And it it kind of work-ish.
And once you start to find the right groove when you know what to ask, you know how to formulate it, you have the proper testing infrastructure so cloud can test its own code and all that, suddenly it's super fast. And it's not just the code. So I did two products, right? I did one which is it's called Bromure, right? It's a it's a secure web browser. It's the it's anti nesses in a way. It's basically the the idea is people are not going to.
No, is I don't patch up on enough. So why not have a browser which gives you peace of mind that even if it's compromised, it has very limited access to your system, right? So like webcam is disabled, files are not reachable unless you really ask and and then there are like gates and all that, right? so it's fully virtualized, it's a macOS thing. It feels like as much as possible, I try to make it feel like a native macOS app. even though it really
Chromium random Linux, but you know I I I I tried to do that. And yeah, although
But but Reno, before before getting into details of Romir, I'm curious, like somebody who's like a deeply technical person who's written like, you know, like high quality code, what does the development process look like for you now? Are you mostly thinking at an architect level where you are telling the systems this is how I want things to be done? And the systems go and then you verify if there it is correct correct or are actually are or are you actually writing code?
Я
No, I'm not running code. I'm reviewing some of it, not all of it. I s my process is nothing unique. I don't have a hundred agents and all that, or we get one instance of cloud code. I iterate a lot. So it's a lot of okay, build a shell, like build something which launches Chrome, right? And and actually it launches Linux. And you start with the VM and like, okay, now I want XLM, X window in it, and I want this option to be passed and
So so you kind of it's a lot of iterations. I found that when you give Cloud the master plan, it tends to be good with the architecture, like how it's going to architect the software and all that. But then every item quickly enough it doesn't go deep enough. So if you start, but if if if you follow what you would do as a human, kind of like, okay, start with the kernel and kind of like build it, it works pretty well. But yeah, I review some of the code.
I think I think the fun thing with Bromir is that it's it really is a compilation of my twenty-five years of history in tech. It's like it's it's some super arcane Linux configuration. that, you know, something I learned back in the day where it's a little faster to start X window if the phones are pre compiled. And nobody does that anymore. But you I found the common so it's a lot of things like that.
And it with a modern twist on it. So the concept is not new. but yeah, I think it's I think I think the concept of secure web browsing is still not solved. so so that's also the fun part.
And and have you experimented with like multiple agents like learning you know, you know, having like a PM agent and the UX agent and an engine yeah, and then like have you you know have you done that too? Like how does that how how has that process worked out for you?
Yeah.
So I I did some experimentation. So some people are more successful than I am with it. I did this system where I plugged together seven cloud agents, right? You've got the developer, you've got the security guy, the architect, UX, UI, marketing, and and a PM. And marketing and and actually it was and and just just for fun, I'm like, okay, like do here are some instructions. Let let's build like a
Open source with right. I didn't want to do that, I just wanted to see how a fight would go. And what was super interesting is that first of all they think a lot. So they so initially on on paper it works really well. You see them thinking. again, I didn't want to do anything with that project, so I called it magician with magician, dumb thing. So the first thing marketing did is it's it's a stupid.
and so they rename the project to Cantograph, which I think was fun. pretty good name actually. and and so and and and then they start to come up with a plan, the architect comes up with directives, developers start to implement it. Every time the developer st does something, CBD chimes in saying can walk me through it. So on paper,
It works really well. In practice, when you see the end results, I think you've got so many distractions. I think the develop the developer agent gets so distracted by security and marketing and UX and they all like they all chime in. Because they shine in they they ask the specs out. And security did.
spot like use use of bad crypto and all this. So so again when you just see the logs you're like this is going to be a great product. I I think the issue is that with the context window of the developer it kind of eats at it and then like it becomes like a s you know when you have a full context window the your agent kind of forgets why why is it here and what it's supposed to do. And so it finishes a job but it's it's a much lower quality
Is it inferior? Is it inferior is it inferior to inferior to maybe somebody who would be like you know, it's very important to have like a strong opinion on how things to be done, right? Like a CEO and who's just getting things, this is how I want it to be done.
I yeah in in my experience, which again was you know more like a Saturday night kind of fun experiment, I felt it was not as good as like supervision of every step. Like if I I find I I I built a bunch of StAS apps, you I I spared the world again for
But I found that when you give a strong vision one-on-one and you kind of iterate, I the end result quickly looks better and is more functional. I think with that kind of Wiz clone experiment, it was I don't know what it did, honestly. At the end of the day, it was like bad look. It looked like something you would do with cursor 18 months ago. Like the UI was not great, the it was missing a lot of functionality.
Is it is it like a classical classical design by committee kind of a thing where, you know, there are a lot
I I think so. I think I think it's a great analogy for development in the modern software company. You know, it's like you've got so many stakeholders who basically distract you from the core mission is to build a certain type of software, but then you know it's make make it look good, make it secure, make sure it uses the right word, making and and I think ultimately
We see it in in in a lot of more established software company. People kind of lose focus of what matters, what is the north top of the company. You know, they think their goal is to make software, not make software, which works well for customers. And I think it's the same with when you have too many agents. So I I'm not giving up on that approach. I think there is potential. Some people report great success. I I have multiple agents in different ways. Like for instance, I have one for if you look at Bromir.
the website is auto-generated. Every time I new release, the screenshots are taken automatically in every language. So it's a bunch of scripting orchestrated by AI. Then the AI looked at the screenshot, looked at the source code, read that redo the documentation, translate it in every language, and then publish it on the website. So it's a mix of you dumplify the agents a little bit by giving them a very strict mandate to look at the screenshot, you know, document it. But yeah.
I'm curious, like what does this mean for like I feel my my personal sense is the founders or builders in in the age of AI who are very technically adept have an unfair advantage in terms of building compared to people who are like professional leaders who haven't actually built things. Like what do you think, you know, like from an
organizational point of view, how does AI change things from your perspective in terms of like exit? Because you know, if you're if you're knee deep into the trenches, building things like you are doing, right? Like you're you're architecting, you're guiding, and you do need a lot of help at this point.
I you have your agents, you have a mindset, you have an opinion, you just go and you just iterate, iterate, and you ship things faster compared to like this design by committee, which is like very typical of most organizations. They're very slow to adapt, slow to release. And they and I also feel like some of I mean I could I could be wrong, but I also feel like there are a lot of people, especially in the C levels, who don't understand what the technology can do for them. They just know what is they just hear a lot of things. They ha they they don't have like a very
Deep sense of what is possible compared to somebody like you. it can do this for me now. You know, it can write seven, you know, it can write their code in seven languages, take screenshots. So what's you know, I guess my first question is like in this new age of AI, like how how does the process change? Why do big organizations feel? I don't know if you've like heard of IBM, like they had like this whole thing as a the building product was a process. Do you think that is still relevant in like to today's age?
I I think it's a great question. I think I think there is an unfair advantage. I think it's going to shrink. I think right now my secret weapon as a developer slash I don't know, sometime I pretend to be an architect, is I know where to push the AI. I I'll give you an example. Romere. So it's it's a virtual machine running a browser.
you have the option of plugging your webcam into it. And if you ask Cloud,
Yeah. that's the feature I'm disappointed with, by the way. I was like so hoping to have the face mash face mash I need to do a renouncer right now. That didn't work for me. For some reason my Mac doesn't support that feature. But yeah, please go ahead.
yeah, that I would use it. Yeah, yeah. I I don't want it.
But but yeah, there's the the so the the funny thing is that Apple has APIs for the speaker. So if you have music in your VM, you can get it on your computer, on the host computer, like for free, basically. It has API for the microphone, so same thing. If you if you want the VM to listen to, you can. It's just one call away. There's no API for the webcam, right? And so Claude initially was like, well, you can't share the webcam.
But as a developer, I'm like, well, there must be a way, you know, at worst. Because you there are there are sockets between the the the connections between the VM and the host. So you must be able to take the video stream and send it. And then like, yeah, I can do that. It's easy. and so I think my secret weapon right now is that I can push the I can push the eye when something doesn't work. Or or or the other way is true too, where
If there's a bug and the I really can't figure it out, I also, you know, sometimes it kind of goes in a loop. And I c I can stop it. You know, I'm like, okay, you know, I'm I'm seeing I understand what you're doing and you're doing the same thing you already try. So let's stop and let's take a step back. so right now that's the only advantage really. I think you also have disadvantages as as an experienced developer, which is that we've been our generation, you and I, you have been we've been trained
To think of computers working in a certain way. Like you have a form and you have to put data in a certain way, right? In the edit of AI, you can just like throw, throw random things in and tell the computer to do the work that we did as human beings, like I'm going to organize and over. So so you have to unlearn a lot of things. I I I think as the models get smarter, maybe it's going to be less of a disadvantage. I my my my biggest fear, I mean not fear, because I'm not
But like I really think the app and and and also by the way, I understand how the internet works kind of. Like I know how to create a website, I know how to create an account with DigitalOcean and or whatever, AWS. I think that yeah, your off-the-mill non-tech person doesn't know to do any of that. So that that's where we win, but I think this is going to become more and more hidden away. And I could see a world where yeah, people have great ideas because they had great ideas that didn't know.
Nobody just listened to them and they're not technical.
Do you think the cost of software development is essentially going to zero? Like the de the
I I think the the value of software is going to zero. Because a lot of it like you can reproduce. I mean not everything yet, but more and more. And a lot of companies I I I think you at a lot of SaaS applications out there. If you're like a fairly big company, 14500.
Exactly.
There are lot of things you can task two engineers, work on it for two weeks. Like let's say you want, or let's say you want to replace your Zen desk ticket to get any system, right? Well, you could vibecode it and have a solution which actually is very more much more in tune with your own internal processes because it's really built on top of your database, so it knows where you are, what you have access to, whatever you do, right?
and so that's going to put pressure on like a Zen task, right? And so I I I think yeah, I think the the so the software premium is shrinking.
And will continue to shrink.
I I I think so. I mean at some point you'll reach a size where I don't know, is a is a dentist going to want to have his own sales force? No, probably not. So you have like still and and you also pay people to take care of the software for you, you know, that's kind of the value. But I think people were right now I think it's a mix of hey, I'm buying you guys because I like your software and you're going to maintain it for me. That's a science attitude, and now like you're going to maintain it for me. I'm not buying it for the software, everybody has the same, basically.
And what you think? Like what modes will exist if that is the case, if the value of software is going to zero? Like what modes will exist in in the next two to three years? Like where do you think like the modes exist? Is it more in like the hardware space, where the modes will exist or something else?
I mean I think infrastructure is tough to replicate. Yeah. I mean you look at the Cloudflare and
Yeah. Like mining like mining would be like very good with plumbing and electricians.
Ye yeah, I mean no but not I mean anything physical, whether it's a physical device, whether it's physical, again, you're not going to vibe code Cloudfair tomorrow. y y y I mean it you need some software, but you have more than that. so so I I think that I think I mean model generation right now it's a it it's funny how it kind of went you know, if we had this discussion a year ago or eighteen months ago, I think the vibe was
Yeah.
models of no value, you know, it's all free. it's there's no future for these companies. Like you you open source equivalents which are good enough. And now it's one completely the other way where nothing nothing has value except the companies doing the models. but yeah, I think it's tough. I think it's the answer everybody wants to after.
The new term is cooked. Like you know, I don't know if you're it's like it's cooked or or it is hard to hard or hard. Are you either you're in the cooked category or are you in the hard category
Yeah, yeah, yeah.
Yeah, I think look the reality is also it's always a little in between. Like if you you you could try to vibe code a threat intel company tomorrow. And and and in some aspect, maybe some of the data collected would be actually super in tune with what your company is doing. And but it's also it's a lot of work, it's not your core business. Is it is it super important? You know, is it is it going to be the best product? No.
Yeah.
That's super accurate. That's super accurate because like, you know, like you know, previously for Threat Intel you would have to scan like the dark web websites and so on. But now that information is already available with the models because that in information is encoded. So you can just ask them, hey, what would would you know about this CVE or this vulnerability or this attacker? And it more knows much more in detail than typically, you know, you know, like the recorded futures of the world would figure out.
E
I i i it will I mean first I mean it's it's going to cost you like ten bucks in tuckens per C V E, so at some point the economics are not going to to work. But it also
Yes.
I I don't know. I I I I think it's it's not necessarily the first thing people w want to I I think to me the company which are cooked to use that term. It's companies which it's it's companies which take your internal data and present it back to you in a different way. You know, like hey, you know, we've we're sucking all your AWS configs, we're doing something and we show you some like you know
Ha ha.
Misconfiguration, cost, whatever. I think these companies, I think the buyer of entry at this point becomes very low because you can bytecode it. And and and whatever you'll do, it won't be as good as a company which has been doing that for five years, which has a billion features, but you'll implement the three features that you need. And
Yeah, it will deliver the outcome you're looking for, like specific outcomes that you're looking for without having to massage the data. You could literally say, Hey, this is the outcome I'm looking for, and then go from there. Awesome. So Renault, let's let's talk about Bromure. Like why did you why did you start what's the origin story? What's the origin story on Bromure?
Yeah.
Yeah.
So so the original story it's it's so dumb. So so I've been, you know, again, experimenting with a lot of things. I've been contacted by a lot of pseudo scammers lately, you know, I'm I'm not sure if if you receive that, but like a bunch of tags saying, you have a line of credit for you and all. And I always wondered okay, who are these people? And so as a joke, I set up like a honey
So these are not like from the bank, these are not the bank offers, right? You know, hey.
No, then other banks, it's it's shade I don't know what these people are. That's what I wanted to solve, right? So so I I started I did like a shady like a not a shady a honey website with like fake financial information and whenever some of these guys would ask me if I wanted a loan, basically I would say, yeah, absolutely. And here is my here is my banking info, right? And I I give them the link. And then and nobody clicked. And so I was joking with friends and I said, How do you think that scammers get like
training to not click on unknown links and all that. And then it that project gave gave me kept it it kept me thinking because A I did ask Claude do a website which when you go on it gathers as many fingerprints from the end user as possible. Like you know the IP address of course, the the the screen resolution, a bunch of things. And
It actually worked really well. It would use a it would do a a web RTC trick where it's kind of like the website pretends to start the conference. It can it sees your real IP address even if you don't have even if you have a VPN. it would do a lot of things like that. And so it was like, okay, well, A, it's actually not bad to have a browser to open a shady link with to see where it goes when you get the fake invoices and all that. And B,
Browsers are very leaky and and they say a lot of things. And so so that's kind of the original story. And I always loved Bromium, which was the granddaddy in that space, was the first company to try to virtualize everything. They started with a browser and then they added email and other things. Unfortunately, the the they didn't like exploded like they should have. but I was like, let's revisit. And so I started, it started with just macOS being emulated.
Linux. I wanted to run Safari in macOS. and Cloud actually using the macOS APIs implemented like a full thing in like 10 minutes. In 10 minutes it would it would create a like a shell of like running installing macOS. And then you know after that, well, I'm going to keep it running. It's fun. It's actually it is convenient to have a web browser where you know.
Y you have good control. Like, you know, there is like the context of this is the concept of I I don't know what they call it in Safari, but
Like window type, you know, you can create personal versus banking and all that. But like yeah, yeah, profile, yeah, yeah. And so I'm like, yeah, we should I should expand like Bromir to have the same concept, and then you can clearly separate. And you it's like there's nothing left on disk. like my banking website doesn't get access to my webcam, my
Profiles, profiles, yeah.
I have Twitter one where, you know, God knows which links show up there so it's like dedicated, like a bunch of things like that. And so yeah, I kept running and I was like, this is actually fun. So might as well release it.
What's the what was what was the primary use case? Like were you even thinking about like you know, like the use cases you talk about look like, you know, clicking on a link and so on, like ransomware would be like a
Yeah, that was so so so so the primary use case is sometime you do get some phishing, you want to see where it goes, how bad it is. And really the MO today, if you're a little paranoid, is well can we to open it in a virtual machine, right? Because you don't want to open it with your browser. You never know. It could be a zero day, it could be something very offensive.
but if you if you do it in a virtual machine, then you do need to have the discipline of creating the machine, opening the link, then destroying it. And at the end of the day, you don't do it. You're like, that seemed safe enough. It seems like innocuous. And so and soon enough you have this kind of sandbox VM, which actually is seeing a lot of activities and and and you end up using, you're more dependent on it than you think, and it has more of your data than you think, right? Maybe you log into whatever. And so
So that's the primary use case. It's okay, I got like a shady link, I'm not sure. And I don't want to have if I click on it, I don't want to I don't want to wonder if something bad happened or if some ex information got exfiltrated. It's a clean session. You you have the ninety-nine point nine nine nine percent guarantee that none of your personal data are leaked leaked based on, you know, unless you put it in. And so yeah, it's better peace of mind.
Mm.
And I I I you know, w one of the challenges in most of these command and control systems is you don't know what is going on, especially if you get breached by transfer, you don't know what is going on, what what what is getting exchanged, you have no visibility into this. And I believe Premiere tries to tackle this. Like if you look at that at an enterprise level, you could see what traffic is actually getting exchanged.
Yeah, you can do that.
Yeah, I think I think this the scorch of modern secure you know, it's funny.
When you know back in the day in the 90s, you know, SSL was the exception, not the norm, right? And and as we progressed, we basically said as an industry, you know, everything needs to be cipher. Makes sense. You don't want third party to see what you do and inject data. The problem is that we have been treating cipher data as some kind of like state secret, we should not look into. you know, it's mine in the middle is bad and all that.
And so it makes it super easy for an attacker to just exfiltrate whatever they want, just open an SSL tunnel and while it's invisible.
And you would know you would not know anything of what w yeah there is no way to know what got ex exfiltered.
Exactly. And and so now if you look at the browser level, you know, the developer tools in Google and all that, they give you some information about okay what resources were loaded and all this. I think the timeline is not always super clear. They try to make it side by side and say don't show what you sent. So if you upload your login and password, you won't find it into the developer console because they want to hide it. It's secret data.
optional disabled by default trace mode where you can recall everything going on. So you have the entire timeline. So you click on the shady link and yeah you could think so so that's kind of at the individual level and then at the end you can say okay what actually did go through what did I upload right? But now if you think about about this concept at the enterprise level and and some some kind some companies do that, you could imagine a version of Roomure used for your corporate environment
where we stream all the activity, we stream everything going on, we stream it back to the mothership, right? We have a recall. And then the one day that you go to IT, because here's the MO today, right? You click on a link, an employee clicks on the link, and then one day calls IT of security and say, I think I I clicked on the wrong link. And it's like, okay, what did you do? Nothing.
Did you put a password? Maybe, I don't remember. It it's always like that, right? And so everybody has to scramble and and I think if you can recall a reaction done again in a pure corporate environment, then you could have this kind of like trace saying, Okay, let's see if you uploaded any credential. No, you're good. Right? We don't need to investigate any further, nothing, but i you don't have that today. And it's it's it's kind of crazy.
And so so yeah, maybe Bromer will will tackle that next. Right now it's at the individual level, who knows?
What's the what's the license on it? What's the license?
it's MIT, it's I mean my point of view is that I spent at this point I spent a month on it, but it really three two or three weeks of work. I'm not going to copyright it like in a strict way. Well, what's the point? you know, I didn't do it, I had the idea, but Club did it. so so yeah, it it's it's it's MIT licensed. Again, you know, it's fun, like it's it's a funny little project.
What is what is the what is the future of Bromure? Like, you know, do you envision this being the everything browser where all your apps can run in it into it? Like what's what do you think is like, you know, I talked to you maybe two years from now and then we have like the Bromure Plus Plus, like what does that mean? What does that look like?
I I I I think
So so maybe there will be a Windows version. We'll see. I I I think the future, I just want to see how far I can take it. I ideally I would like to have a a a version for like small offices or mid-sized companies where you can create profiles like in a centralized way. You push them down with an MTLS certificate and all that, and you basically you have a guaranteed environment for your employees who use their own laptops.
So so just just like island.io does, except in a VM. So basically you would push to employees say, okay, you have our come our SaaS application sells false and workday and whatever, and it shows up. and then you have MTLS, so they can only use Bromere to connect to it. So it's great for contractors, they can't use like an unmanaged browser. You configure the browser.
That's it. And and optionally, you know, again, same thing, records a session and all that. Offer all that for free. Because it's the profiles cost nothing. So it's no, like it's you know a few bytes per person, so so I would not charge for that. and yeah, and see if if that takes off, you know, it's that that's the vision for it. the all discussion like do we do other apps than the web browser?
Slack is a great example with a web app. OpenCloud would be an example, but I think it's it's not Bromir itself. I would reuse the code, but I would probably create dedicated Mac apps for these.
Maybe I'm always curious why people name things the way they name it. Like why why why Bromure? Like what was like what was the thinking behind Bromure? Obviously you you said you were insinuated towards Bromium, you know, you were being being a big fan of Bromium and so on. And when I was looking up Bromure, I couldn't find a good reason for it. So I'm sure you have a good reason for Bromure. Like what what's the what's the w why did you name it Bromure?
Yeah.
I you know, I think I think names are tough. names are tough and even tougher in twenty twenty
I'll I'll give you an example. I was at I was at RSA earlier this year and there was a company and it had a funny name. And I asked, why did you name it? Whatever you named it. we just put it in Chat GPT and Chat GPT said this is a good name and it has a good ring to it. I was like, You are a founder, you should have thought more there should have more thought to this. Like you cannot be just going to Chat GPT.
Yeah, I I I tried that. I was not happy with the suggestions from the Chat GPTs and Clothes of the World. and also some of the names they suggested existed. So you need to do some background check. now I think bromure, as you said, it's it really is a pen on bromium. and bromure means bromide.
That's
It's a French word for provide, which kills germs and all that. So it's it felt very appropriate. Just like Nessus, it's the kind of name which makes sense in hindsight. You know, Nessus was speaked randomly. In a book, I just felt like it had a nice ring to it, and then people told me why I needed Nessus. it's an alien from the movie, but from the book Green World.
Which is very funny. I'm like, okay. so in in hindsight you always find a meaning. at the moment it's just yeah, Bromir, sounds good. The domain was available, so I did bromure.io, little website. yeah, it's again it's fine.
And then, you know, you were not satisfied with Bromeur. You wanted to do one more. So you did more better. So that project was also launched, I believe, like last week or the two weeks ago.
Yeah. Yes.
Yeah, I think I did it last week.
And so so I have to ask you this, like, did you literally start working on it like a week or or was it like incubating for a long time and then you pushed it last week?
Yeah.
No, it was an internal need. so we're seeing a lot of supply chains attack. I mean I'll if if you look at my lab, if you take a step back real quick, you know I have a lab, I have a bunch of services running internally, a bunch of random things, ranging from home automation to whatever, downloading CD permits. And the and and I have a process which rebuilds everything with the latest version every month.
Right, because that we don't have to patch anything, it's all automated. No need to scan anything. The problem with all the supply chain attacks is that now the latest package, it seems like a it it's a risk, right? The challenge in twenty twenty six is that it's it's really funny. We have this we want to factor authentication and all that for human beings, but at the same time
when it comes to automation, we want to make it as simple as possible. And people use bearer tokens, right? API keys. And a lot of my systems, they use API keys for like OpenAM, for being anthropic and all a bunch of things. And yes, the idea is well if it gets compromised, the first thing that the supply chain addicts does is it takes all your API keys that it can find.
and and and steal them so then they can have access to your environment in different ways. And so the idea with overbearer is just to have this proxy between money in the middle interception. So when you talk to an anthropic, when you talk to an AWS or whatever, it takes a token and replaces it by another one. And so that way the services that you have internally have a fake token. So if somebody steal them
Hmm.
so
Unless they maintain access in your environment and can talk to your proxy, they can't do anything with them. So peace of mind. and then you know you have like one central place which is like where all the Chrome jewels are, which does all the matching of the of the tokens. So that was the idea. It's fully Kubernetes, that's what I ran at home. and and yeah, I think it's I think it's a simple thing. I saw another company actually iron shell.
It's called they release something similar. I think it's a neat trick. And and and it gives you also auditing. Like a lot of these platforms, when you use a bare token, they're not very precise on when it was last used. So just some within the last week that's what Anthropic tells you. It's well, great, BFD. Like I want to know which IP address and when. And so so the
Mm.
Overbearer gives you these two things. It will tell you, okay, this is a fake token or this is a real one, you need to replace it. And two, it shows you exactly which API was called and by which service. So you can do some a little bit more auditing.
So I don't know, like s someone with like your pedigree could have gone and raised like a twenty million series A for Bromeur, but you didn't. Why?
well it's a lot of work. No, it it's it's I I don't know, I think
Who knows what the future holds? I am very happy with, you know, right now, you know, so I left Tanable five years ago. I've been advising a lot of startups. I've been working with a few fonts to kind of also advise them, pretend to advise them. I mean, I think it's good advice. I don't know if it's good. But basically, you know, so I've been exposed to a lot of companies.
it was satisf it it is satisfying intellectually it's always super cool to have to assess const constantly reassess your assumptions and all that. So that's fun. I was missing owning software. You know, the thing which I really loved the most back in my Nessus days was okay, we have this big release, we release it, we see how people like it, feedback, the good, the bad. you know, it's it's fun. You feel like a little responsible for your little corner of the internet.
I I was missing I was missing owning a product. Promir has like I don't know maybe ten users, maybe a little bit more. I don't know, but it's there are users which well I appreciate it. you know, I know I we th there are some users. I I don't do telemetry by the way, so it's hard to tell. But it's easy enough that if if something is broken I get like issues being filled in in
Hey, I'm I'm one of those users. I'm one of those users.
five in in github and all that so that that's fun and yeah and it filled my cup honestly it's it's it's fun i i i again i also think the value of self-restrain towards zero like maybe i could have raised a lot of money but also i did it in two weeks so anybody can do it in two weeks really i mean it's it's not I'm not special you know I just prompt it the right way and it's not super hard to reproduce it.
Mehul (01:00:20.334) Thank you.
Mehul (01:00:25.518) What do you think is like the future of fundraising then? Is it like do you raise a lot of money and then my sense is like once you raise a lot of money you're in a lot of pressure to make money at that point, right? And d d what what's your point of view on that?
Renaud (01:00:38.109) It it's right now it's a very tough market because it's a tough market to create a company. It's it's very noisy and one way for good or bad to rise above the noise is to raise a lot of money. The the the because you you're you're you're credible. I mean you're more credible if you say, Hey, we're the future of AI security. Same product, same team.
Mehul (01:00:55.854) Yeah.
Renaud (01:01:05.013) You'll be way more credible if you raise 200 mil at a scene round than if you raise half a mil. You know, that's that's that's the reality of the problem is the more you raise, the higher the bar for exit is. So you lose, as a founder, you lose the control of your destiny a little bit because you know you have investors and they want to see a return. They spend time on you and they dedicate it as they deployed capital, and rightfully so, they want to see something out of it. And so
Mehul (01:01:10.231) Yeah.
Mehul (01:01:32.182) And if you if you and if you raise two hundred mil, the exit is six hundred mil.
Renaud (01:01:36.861) E basically, I mean y you know, i y yeah, like like that's what investors tend to I maybe now they want ten X really, who knows, you know, in these crazy days. But like the the yeah, y you can't like if you raise that to two hundred mil valuation and then the I don't know, the company of your dreams, Apple, comes to you and says, Hey, we're buying you two hundred and five million. It's it's really
Mehul (01:01:38.158) That's what you're going to have.
Mehul (01:02:02.018) You can actually yes. Yeah.
Renaud (01:02:04.061) It's it's it's a really tough discussion with your investors, right? Because you lose that freedom. but if you didn't raise that much, maybe they wouldn't call you in the first place. So it's it's it's really tough. and and again, like from where I stand, it's I I enjoy staying on the sideline.
Mehul (01:02:28.168) No, it would be
Renaud (01:02:30.534) I have we we have to wrap up, I'm sorry.
Mehul (01:02:34.318) I have one one more topic to go through. like five minutes. We want to go to the Hall of Fame vulnerabilities from for Reno.
Renaud (01:02:36.083) Yes.
Renaud (01:02:44.86) Yes. sorry, to give me one second.
Mehul (01:02:49.422) Yeah, you can take a we can edit it out in the clip.
Renaud (01:02:51.848) Yes, s sorry, sorry, I have something right after.
Mehul (01:02:58.466) I hope not one of the agents reaching out for feedback.
Renaud (01:03:05.504) Okay, let's back. my whole of fame of yeah.
Mehul (01:03:06.958) We have we have Reno, we have to go through Reno, we have to go through your Hall of Fame vulnerabilities. You've seen probably hundreds of thousands of vulnerabilities. Which vulnerabilities stand out in your career in the 25 years as like the special ones, the special child's, the things that you're really excited, you know, and proud to work.
Renaud (01:03:26.662) I think I think there are a few I I think it's not so much a Vaughn, it's what we learn from them. Wannacry was back in the day, you know, Wanakrai was this kind of like Vaughn slash virus. and
Mehul (01:03:39.128) Yeah.
Renaud (01:03:42.408) Everybody wanted to scan with it. and and it was it was interesting because there was so much attention paid to that plug and I think we did twenty release in one day, like because we had so many variations of When I cry and all that.
Mehul (01:03:57.196) Authenticated, unauthenticated, all these different variations, local checks, all these different
Renaud (01:04:00.316) All of these ways but but people the feedback was hey I want to know it didn't fire on that host, I want to know why. I want s certitude that it's it's because we you know, if if it doesn't fire, is it because we could not reach the host or is it because the host is not affected? And so so we learned with
Mehul (01:04:10.158) Yes.
Renaud (01:04:22.305) Created something called Audit Trailiness after that flaw, which would record why why something would not fire, which was actually very interesting. I think the other fun bone was Howard Lead back in the day where you could actually see the memory content of the remote server. I think the plugin was fun because you actually see the results, so it's always fun. And at the time it kind of like our SaaS servers, we had a SaaS offering which was nascent, and the servers were probably red hot.
in the data center because of everybody's testing for it. So it was fun. And
Mehul (01:04:53.368) I don't and I don't know if you remember this, Sureno, but like the WannaCry WandaPrity was the first WandaPD where Tenable gave like a bounty to the researchers. Two thousand dollars for you know, there are like seven engineers or researchers who worked on that time. And ev because of the gr you know, because it was like it was like three days it was a two or three day crazy, you know, no pr pretty much no one slept in those two, three days. And you know, I remember I had like this fond memory, like every all the key researchers who were actually writing the plugins, they got like two thousand dollars.
Renaud (01:05:07.879) internally, yeah. Yeah, yeah, internally means
Renaud (01:05:16.586) Yeah.
Mehul (01:05:22.486) Pretty amazing. And N tenavel had never done that because it was one of the massive Vanu. At least I
Renaud (01:05:27.036) It it was massive. It was massive. It was panning. It it's it's funny because the world as VM is very quiet and then suddenly you've got like the big one of the year and then everybody wants to scan. Look
Mehul (01:05:35.266) Yeah. And same thing happened for shell. The same thing like you know, VM is dead, VM is dead and lock for shell happens, you first thing hey, tenable and call us. Like, you know, these are the people that people reach out to. Am I one over there?
Renaud (01:05:47.844) I I think that's a good thing that and the look for share was a very fun experience. The last one I did a tonable. I think these bones remind you of the usefulness of VM, which is not so much to monitor that the systems you know are taken care of. It's more like, okay, I which systems are not taken care of. That's it. Like whether I know them or not.
So it's more like that chaos mode of like, okay, I'm just just scan everything and maybe I missed something and everybody every time people realize that they missed some servers which different teams managing them or whatever. so yeah, it's it's it's a good kind of memory there. but yeah, the look for shell was like the most intense one I did. I had COVID when it happened. I just I had COVID and I got the vaccination the same day, you know, I got the vaccine and I got COVID the same day with
Mehul (01:06:41.718) And and I think and if I remember, I don't know if it was the WannaCry or Lock for Shell where Nessus went from like five hundred s requests per second to five million. Which one which one was that?
Renaud (01:06:42.174) Should have.
Renaud (01:06:55.868) Yeah, so we with so so log4 shells is a callback mechanism. So each plugin will call us twice per web app, I think. And so I set up the server and you know I see we push the plugin, we start to see the the calls and it would plateau at five hundred requests a second. I'm like, that's interesting, that's good. But then I was like, This is weird, five hundred, that's always five hundred, and I realized we were losing most of the requests, so we scaled it up and the right number
Mehul (01:07:15.961) Is it the stone?
Renaud (01:07:25.312) 5 million requests a second when people were doing peak scanning, which was insane. There's a lot of echo, it's not just like it's not 2 million hosts, it's not 2.5 million hosts per scan per second, but it's yeah, it was a massive scale. It was a fun experience.
Mehul (01:07:28.706) That is inside.
Mehul (01:07:43.49) And that shows you the breadth of Nesses. I mean it's still mo one of the most widely used products in the world. So kudos to that. Renault, this has been like an ama amazing episode. What's next for you? So you did you did from your you did bear a token. Are there more projects coming out? Like what's next for Renault? and when you when we do the let's once that comes out, let's do another episode. Renault, thank you for your time. You're way too generous. so good to talk to you.
Renaud (01:07:46.249) Yeah.
Renaud (01:08:00.432) We'll see what comes up. You know, we don't know. I don't have a master plan.
Mehul (01:08:13.275) looking for what to do next.
Renaud (01:08:13.825) Thank you. Thank you so much for having me. See ya. Bye.
Mehul (01:08:18.136) Thank you. Bye.