# Bootstrapped Cybersecurity Growth: Zero Sales, Stable Pricing, Open-Source Strategy

**Podcast:** The Changelog: Software Development, Open Source
**Published:** 2026-07-21

## Transcript

What's up, friends?
Welcome back.
This is the Change Law.
This week on the Change Law, we have Haroon Mir back.
Haroon is the founder of Thinkst, the 50-person bootstrap company behind Canary and Canary Tokens.
They are honeypots and trip bars you sprinkle inside your network and forget about until an attacker touches one.
We talk about the AWS API key token attackers just can't resist trying the real credit card token they have that's backed by an actual bank partnership.
They have breadcrumbs, their brand new feature that leads intruders straight to your canaries.
A live demo where a hardware canary becomes a Synology NAS in one click.
And how a company with zero outbound sales and no price increase in 10 years quietly passed $22.5 million in annual recurring revenue.
Baller.
A massive thank you to our friends.
And our partners at fly.io.
That is the home of changelog.com.
Learn more at fly.io.
Okay, let's do this.
Well, friends, we're back.
Haroon is back.
It's been a few years, Haroon.
A big fan of your tiny little company.
And I don't want to say tiny in like a pejorative, but just how much impact.
And I mean that in a loving way.
A 40-person company.
Just having massive impact in the cybersecurity world.
We talked to you before about things and Canary and the Canary tokens.
Take us back into the world because we now have AI where the last time we talked, I mean, we probably had the burgeoning early beginnings and the early innings of it.
I mean, if you could even call that probably like the farm league to keep going with the baseball analogy, but we're now in a world where.
The attackers have the same tools we have, which has always been the case, but these tools we have give us versions of superpowers.
I can imagine this world you're in right now is just insane.
One, massive ARR, if you want to mention it, you can't think TechCrunch did it for you, but you can certainly as well.
I just want to paint the picture for who you are, where you work, what you do, and just a massive impact in monetary value because, hey, capitalists, we run businesses, right?
But at the same time, you're giving away a lot for free too.
You could be making more.
Yeah.
Is that enough of an intro for you?
What do you think?
I think that's great.
So company-wise, like you said, we are a pretty small company.
People-wise, we're just over 50 people now, which feels pretty big to us.
But product-wise… 50?
Okay, not 40.
I'm a mistake.
Yeah, no.
So we've just hit 50, and we feel that's huge.
But the company is almost entirely technical.
And like we've done a few things pretty unusually.
So for one thing, we still do zero outbound sales.
So last year we hit 10 years of selling things to Canary and we still never reach out to customers.
So everything's happened just with word of mouth.
Like we initially made something that a few customers like and they said nice things about us.
And we just try to not let them down.
And for the most part, like, I like to think that we almost the poster children for doing business this way, which is like, do good things and good things will happen to you and it makes you do good things.
And so I think like the model is a sustainable one.
Like we didn't raise money.
And fundamentally, we make.
two products.
So for people who are new, Canary initially were hardware devices, so they were hardware honeypots.
And our insight, we had two of them.
One was that honeypots almost always got a bad name because people used to use honeypots for research projects, like put one up on the internet and say that a thousand IPs from China attacked this honeypot.
And we said, what if instead you put honeypots inside your network?
where nobody should be touching them.
And then every time someone touched them, you basically got a high quality signal that bad stuff was happening.
And so we made these hardware honeypots and we made them really easy to deploy, like two minutes to deploy.
And again, our whole pitch was that if we made it simple enough and cheap enough, then why wouldn't you do it?
So even if you had lots of other security projects going on, just take a few of these, sprinkle them, forget about them.
And if they get touched, then you know you've got to change your plans.
And those ended up working really nicely.
So we started off doing hardware versions.
Today, we've got them running on GCP, Azure, VMware, Nutanix, just about every platform.
We've even got them for Docker and Tailscale.
So if you're running a Tailscale network, you can say, okay, I want...
a canary in tail scale.
It pops up into one of your tail nets.
And if someone's poking around, you get an alert saying someone just tried to access this machine that nobody should access.
So that's what we sell is these canaries that then have a management console.
And again, our pitch is they're dead simple to deploy.
They require no overhead.
People deploy them, forget about them.
And they tell people when there's attackers on their network.
And at the same time, we started doing something called canary tokens and where canaries act as entire operating systems.
So you can say, I want this to look like a Windows machine.
I want this to look like a IBM mainframe.
And so it's just one click for you, but the canary effectively acts like that entire machine.
Canary tokens are much simpler tripwires.
that you get to deploy in different places.
And we call them one thing when we call them canary tokens, but they're really about 30 different products under one umbrella.
Because what we do is throughout the year, we keep working on trying to find this intersection of really easy to deploy.
really high fidelity tripwires.
So we'll come up with some things that are good indicators of compromise, but they're complex to deploy and it doesn't make the cut.
And we get some that are easy to deploy, but not enough signal.
And the canonical example of a canary token is you come to us and we give you an AWS API key.
Like it's a legit AWS API key.
You store it on server 32.
Now, the logic is that an attacker who breaks into server 32 and finds this API key just has to use it.
They just have to check if this key is the key to your kingdom.
It's too tempting not to, right?
Exactly.
Every hacker would.
Exactly.
And there's some things with canaries and canary tokens that we really just lucked into, like it wasn't our original great thinking.
And one of them is...
that even attackers who are suspicious that maybe you run Canary, like what are they going to do?
Not try this AWS API key.
Like it might be the keys to the kingdom.
And so they've got to at least check if that key is valid.
And the moment they do, you get a message saying, listen, the key that you left on server 32 and forgot about just got used.
And so instead of finding out about your attack, Two years later on CNN, you find out about it in week one while the attackers are still orienting themselves.
And almost everything we do is aimed at exactly this.
It's stuff that's too attractive for an attacker to leave alone and a really high quality signal that tells you that there's badness.
And when we made Canary Tokens, in honesty, it was early for us as a company.
And we didn't know how we'd sell it because canaries are really dead simple.
And the story is easy.
Plug this into your network, forget about it.
When it goes off, you know you've got a problem.
But canary tokens, like this thing I just said about AWS API keys, it's slightly more complex.
And so instead we said, look, we'll just host them and give them away free and people can use them.
And from the time we've started hosting Canary Tokens on canarytokens.org, they've been used literally millions of times.
Like they were used just one December when CISA referred to them.
They ended up being used like 4 million times.
And as a company, we keep adding new Canary Tokens whenever we're able to come up with them.
People keep using them.
And people all around the world discover...
attacks on their networks just using the free canary token service.
For us, obviously, it ends up being reasonable marketing, like people know about us because they've used our tokens and tokens save them.
But it also just gives our engineers a chance to build stuff that matters.
So like literally today, I spoke to a kid who we're recruiting out of a local university.
He's into open source, he's submitted some patches.
And you get to say to him, like, listen, you can go build banking interfaces or you can work on this stuff that millions of people use and that public companies have said save them on their worst days in their history.
And it becomes a no-brainer just because it's real and useful and does some good.
So, yeah, that's Canary and that's Canary Token.
And for the most part, that's us.
Canarytokens.org.
I'm infatuated with this because the last time we talked, I was less smart.
I've gotten a little bit smarter since then.
Harun, thank you very much.
Nice.
I've since built a DNS resolver called DNS Hole written in Rust, largely to replace PyHole because...
Just because when I wanted to try and just to, I just was tired of the way I had to instantiate PuyHole, the fact that it's PHP, it's got some different things.
I just didn't really care for the architecture.
And as a technologist and a builder, I wanted to rethink it.
And so early days in my agentic world, because just so you know, I'm not a Rust developer.
I'm an agent driven Rust developer.
Okay.
But the point is, I've got a lot smarter with a lot of these different things.
I think this is really, really interesting.
Because these tripwires, essentially as they are, they're so wild to think about it.
I just was noticing this one here.
You have a DNS canary token where you can get alert when an attacker resolves a certain DNS name.
Now, I think this is kind of wild that you do this for free.
It's probably great marketing.
Does it cost you a ton of money to – what does it take you to build this platform and deliver it for free to folks?
What's the infrastructure cost to you?
I'm going to give you the most unsatisfactory answer ever.
Oh my gosh.
In that we absolutely don't check.
So it clearly costs us money.
I have no idea, Adam.
And I'll tell you why it's such a weird idea.
Like when we built the company, right?
Like when we built Canary, our first thought was like, can we build something useful?
And we're not hippies, right?
Like we like money.
Like it allows us to build better things and make an impact.
But we always looked at the company as a vehicle to make interesting, useful things.
And so I'll tell you something else that's on topic and weird.
Like we've been running Canary for 10 years and we've never increased our prices ever in 10 years.
So no Canary inflation.
And in part because we've never had to.
Like we sell to more people every year.
And that keeps paying the bills.
And again, we make good money.
We've been profitable from year one and it allows us to do cool things.
And so when it comes to Canary tokens, like we host it and we spend tons of engineering time building these things and it kind of nets out.
Like we keep making money without paying customers and it keeps allowing us to do cool things.
And it's one of the things that I think people obsess over slightly incorrectly.
Like we've got lots of, we get lots of VC attention and lots of PE attention and almost everyone starts with, do you know how much money you're leaving on the table?
And like, that's just not a terrible thing.
Like in fact, super recently, again, if you go to our X page, Twitter page for things canary about Three weeks ago, a student DM'd me on LinkedIn.
And first I thought it was crazy because like it's out of the blue.
And he DM'd me saying, I just attended a lecture with a CISO and you need to contact me because he should be paying you more.
And so I DM'd him and he says, no, this, we attended a lecture with some CISO of company that I won't name.
And he mentioned to us that they keep expecting you guys to charge more.
And you guys don't.
And you could charge him a lot more than what you charge him.
And again, like it's such a zero-sum way of thinking.
Like we make a product, we charge a fair price for it.
Customers like it and pay us for that product.
And we get to build a company that makes useful things.
So yeah, in general, we don't think you have to grab every dollar that's on the table.
because, just because it's there.
And Canary Tokens is a good example.
So we don't cripple anything in Canary Tokens on the free version.
Our paid customers get a private version of the same Canary Token server.
But fundamentally for us, like this is useful.
People should use it.
And so we put it out there and host it free.
And yeah, fortunately, we've not had to consider the cost.
We don't think about it.
Let's talk about that because I'm a big fan of self-hosting.
Okay.
Right.
You can probably know where I'm going with this.
And since you said Canary token server, that immediately sparks my interest.
And the moment you said it, I was like a dog seeing the rabbit.
I don't know, like the greyhound seeing the rabbit.
And I got to race now because, you know, you're giving me this shiny object.
And from the start, we've allowed you to build your own CanaryToken server too.
So what you see at CanaryToken.org, it's on our GitHub.
So if, in fact, it might be right at the start of our page.
Let me help you connect some of these dots because when I go to CanaryToken.org, it lands me, it actually redirects me to slash nest, which is fine, right?
And then it gives me this world of creating CanaryToken.
deploy it anywhere.
We'll have this up on the screen for our audience watching on YouTube, of course.
Listeners won't see this, of course, because there's no eyeballs here.
If you go top right and you see documentation, it should open you up in a very pretty documentation page, and then top right will be GitHub.
Okay.
This is what I want to zoom in on here real quick.
Okay, so audience, you're seeing me catch up in real time.
on this front.
I do a lot of research, but not always the depth that I should.
Okay, so what language is this then?
Let's see, we got, oh, Rust, no HTML, Python.
Of course, you guys are Python folks.
Yeah, exactly.
A little bit of TypeScript sprinkled in there.
Okay, so Python and TypeScript is your language.
Is this a framework?
Is this hand-rolled?
Is this vanilla Python?
What is this?
Yeah, so we've been loving Python forever.
Even our Canary product, like it'll use a little bit of C when we've got to do kernel packet stuff.
But for the most part, we happily a Python shop on our Canaries will then have it sandboxed for extra safety.
But this Canary token server, effectively, we've got what we call a switchboard.
And so as far as possible, we try to catch incoming requests.
using the switchboard, but it's almost all Python and pretty straightforward.
In fact, the Canary Token server, you can download a Docker image and run it on your own.
And we've had people in public running Canary Token servers and then selling services on top of that.
And again, like- You don't care about that?
No, like again, for the most part- Is there a license on this thing?
What's the license?
I think we used to have a BSD license.
I'm just checking now if it's BSD or GPL.
Code of conduct.
It's GPL.
Yeah.
So people using it.
So literally we've got...
Free Software Foundation version 3 GPL.
We've spoken to huge commercial companies.
I don't know if they're the biggest.
software company in the world, but they'd be up there.
And the first time we meet them, they happily tell us, look, we run your Kinetic Token server internally and this is what we do.
And part of our thing is like, hey, that's cool.
I think it's awesome that our stuff runs in your org and you guys use the stuff.
Coolest thing ever, right?
Exactly.
And again, we're not hippies.
We're doing pretty well with our product.
We're not hippies.
Yeah, there's almost a thing that says, well, if those people wanted to pay you, they'll find a way to pay you for something.
You don't have to extract every dollar from everyone.
And so far, that seems to work out pretty well for us.
So yeah, people can run Canary Tokens completely on their own.
They can use the free hosted one on canarytokens.org.
Or if they use our paid Canary.
canary, they get a token server built in.
And somewhere in that mix is a happy middle ground for customers.
We've got some canary customers who pay us like 20K.
So they've got a handful of canaries, but they deploy hundreds of thousands of these canary tokens.
And again, when people hear that, they go, well, you should be charging them more because clearly these people are getting value from the Canary tokens.
And for us, it's pretty reasonable to say these people are going to be customers almost forever.
They're not going to rip us out of their infrastructure.
Like we ending up on every VM and every workload of theirs.
So again, like they just, it doesn't have to be predatory with customers.
And so far that works out nicely for us.
And like I say, for us, we genuinely spend a lot of time trying to come up with new great tokens.
And if we come up with a cool enough token, then people use it.
And that ends up being a positive cycle also.
So, yeah, we think it's a good positive loop that more people should be going for.
I imagine since this is GPL open source as a server, does this, I didn't go into the code base yet.
So help me answer some questions that I would just ask my agent to help me with if you weren't here, because you're here.
So answer some questions.
Can I begin to develop my own tokens then, given that I get the server?
Is all that, like, is all your tokens that you've created in the token server?
Yep.
Like all the code base for what everything is.
Is there?
I don't know if the credit card token.
No, it should be.
Like everything that you see on there.
But you need the bank.
In the pre-call you mentioned.
Exactly.
That was in the pre-call.
Mention that real quick if you don't mind, please.
Yeah.
So one of our recent tokens is the credit card token.
So if you hit canadiotokens.org, like we'll give you a working valid credit card and store this credit card somewhere where you don't expect it to be found.
And if someone finds it.
and uses it, you'll get a message telling you this credit card that you only had saved on your mom's desktop just got used to try to buy an item in Bahrain.
And again, it's perfect for us because it's a high quality signal that badness has happened.
And I'll come back to that just because it's to answer a question you asked at the start.
To make that happen, we've literally partnered with a bank.
That's a valid credit card that you're getting.
That's legit.
And it's one of those experimental tokens for us because there's multiple things at play here, right?
There's an interesting psychology that happens because attackers over time are going to figure out, hold on, if we ever see this bank's bin number in a bunch of stolen credit cards.
Don't run that card because maybe it's a canary token.
And so part of our thinking when we built this was over time, we'll convince more banks to play with us because if they add their bins to these canary token cards, then attackers will start being wary of their bin numbers too.
So it's interesting.
The thing I wanted to come back to that I said, which is if you've If you've got, no, so we've discussed, if you've got canaries and canary tokens and deploy them, one of the problems for attackers is that attackers can't tell what's legit and what's not.
And it ends up with a really nice side effect that if you have a sticker on your network, on your corporate network, somehow saying we run canary and canary tokens.
then even a perfectly standard attack ends up dragging into molasses because now an attacker who finds a password somewhere is terrified that he's actually found a canary token.
And so now they find valid API keys, but they're scared to use them because maybe the stuff's actually got teeth.
So again, it's one of those things that we get lucky with.
Are you well known then by the hacker world, the black hat hackers, not the white hat hackers?
They know Thinx, they know Canary, they know your ways.
Yeah, so we are increasingly well known.
But again, it's one of those things that we get lucky with in terms of what the technology is.
So like I spoke about Canary tokens, but take Canaries.
You're an attacker and you're on this network and you see a Windows server with an open file share that says network diagrams.
Even if every spidey attacker, spidey sense is saying, this isn't legit, don't touch it.
Like, how can you not?
You have to.
You have, like, that's why you are there.
And it's such a nice connector.
to your opening question.
Like you asked what happens in this agentic world with attacks that are now AI driven.
Again, one of the things that canaries get lucky with, and I mean canaries as the overarching technology, is it doesn't matter how attackers get into your network.
Like super stupid attack, they bribed someone and have their username.
Super super high tech, they were actually hidden in the firmware on your monitor, and now they've broken out into your network.
When they're on your network, they have objectives, like they've got to go get something and touch something.
And that's when they touch your canaries and canary tokens and reveal their presence.
So it almost doesn't matter.
And in a world where attacks become more prevalent, it almost matters more.
Because it doesn't matter what the other noise is.
What matters is someone tried to use this API key that was on the server.
You've got a real problem.
And so it becomes a really high quality signal for really low implementation cost, which is why the technology ends up working so well.
Let's make a dividing line just so we got some clarity on this conversation.
So you mentioned Canary.
That's a hardware device, right?
That's something that you deploy.
How big is it?
How big is it?
Describe a canary.
So they started off as...
All right, Harun's going to grab one.
I'm going to rip out really old ones.
So when we started with version one, there were these...
Audio listeners, you got to go to YouTube for this, okay?
This is Harun showing off a canary.
So go to YouTube.
Yeah, so this is janky version one.
Okay.
Can you show me all the parts of it?
The interfaces?
Do a product demo while you're talking if you don't mind.
Show me all the parts.
So we make these.
So the hardware device that you're looking at is by design made to be dead simple.
So we used to say in our product demos that it should be like a kitchen appliance so that you can't do this wrong.
There's literally just this one button on it, which is also its LED.
And so the logic is you plug this in, it boots up, and it's going to show up as a Windows box on your network.
Now, this device also talks into a console.
So if I bring up...
On AWS, right?
If I recall correctly.
Yes, exactly.
So it sits in AWS.
So if I bring one up here and I'll share my desktop.
Yeah, do a little screen share.
We're getting a treat here, y'all.
Audio listeners, you're missing out today, okay?
I'm sorry.
If you're driving right now, pause the show so you can get to a screen.
Take us into the world around.
So what we're going to see here is just a standard console.
Now, this is a home console that I've been messing about with, so you'll see a whole bunch of what we call flux, where because they're canaries, you can logically group them into different.
Ah, very smart, yeah.
And yeah, we like our BIRD acronyms and we use them far more than we should.
And so what you're looking at here is on my home network, there's effectively two canaries.
One that believes it's a Windows server and one that believes it's a Linux box.
And so this Windows machine, if I click on it right now, you'll see it's running RDP.
Windows remoting, a Windows file share.
And so what that means, so what I'm going to do here really quickly is grab its IP address.
And that means that if an attacker on this network happened to try to browse to this machine, they'll see it on the network exactly like a normal Windows share.
And as soon as they browse to it, so when you create a canary, you can...
enroll it in Active Directory, you can RDP to it.
So in this case, they're going to see a bunch of files.
And if they try to access one of those files, you're going to get this message telling you, listen, somebody just tried to connect to this thing.
Here's what they did.
Here's what they tried to see on this machine.
And again, at its simplest.
that's what Canary is made to be.
So it should be...
So in a separate term, were you SSH into that?
You tried to hit it with something, maybe you curled it or something like that?
Exactly.
So, and in this case, I just opened the file share to it.
But the joy of Canary is, like, if you look at this guy who thought he was a Windows box, I can say, okay, I don't want you to be a Windows box.
I want to reconfigure you.
And so...
I can go in here and say, listen, I don't want you to be a Windows box.
I want you to be a changelog demo, if I could type, NAS.
And where we get its personality, instead of a Windows 8 machine, I go in and here's all the options for what we can make these machines, these canaries, just at the...
Ooh, make it a TrueNAS box.
Can you make it a TrueNAS box?
So I think we've got, in terms of NASs, if that's the plural of NASs.
Let's get TrueNAS on a list if it's not on a list.
Let's see who we've got down here that we can use.
Maybe even a ZFS file system, whatever works.
Yeah, exactly.
Spelunk is fine, sure.
We don't use Spelunk, but sure, we'll go there.
Yeah, so let's make it a synology.
Synology, yes.
Right?
And you'll notice when we do this, it changes a whole bunch of defaults.
So it says your MAC address is now going to be a synology.
It's going to change, like, is port scan detection enabled?
And I can just leave all of that.
So you'll see it says this is what the web server on it's going to look like.
So what I'm going to do initially is just leave all of the defaults.
Except I can go in and say, look, I want a file system on the Synology NAS and make my file system specific to my industry.
my cybersecurity industry.
And so it's going to say, okay, I'll create a file system for you.
And we can even go in there and say, look, I want to create a new folder called change, whatever, my spelling is bad, demo.
And in there, I want to create a file, a password protected doc file called secret.doc.
Okay, so You can leave the defaults or you can do this and then you say deploy.
And literally what's going to happen right now is that canary.
So I'm going to see if I can change what you're looking at on the camera just for a second.
If I change to this, you'll actually see you can turn off or you can't switch cameras.
Yeah, they may get upset.
They may get upset.
This is not that sophisticated.
Riverside, I hope they didn't mess up.
So I thought I'd show you the actual canaries, but that's cool.
What's going to happen now is that canary basically gets told to reboot.
And when it comes up again, it basically stops being a Windows box.
It comes up.
Initially, the hardware light goes red saying, I can talk to the console, but I'm not encrypted yet.
And then it goes green to say, okay, I'm now on the network.
And what you'll see as soon as this guy goes green again, which he now will, is you'll effectively have a disk station NAS on your network.
And so as a Windows box, you could RDP to it.
You could enroll it in Active Directory.
You'd have Windows RPC.
As a disk station NAS, it'll now have disk station NAS services.
If you made it an IBM mainframe, we do a lot of work.
So even down to the network level, like you TCP, you NMAP it, the stack fingerprint looks like it's supposed to.
You make it a Cisco router and that's what it's going to look like.
And so for a defender, really the amount of work should be minimal.
But if they want to do more complex stuff on it, they can.
So you'll see this now says that we've got a changelog demo NAS here.
And if I click on it and grab its IP address, if I open a new tab, is that still going to be shared?
I don't see the new tab, no.
It's okay, though.
We'll follow you.
So let's...
Stop sharing.
You can probably stop sharing and then reshare a new tab.
Yeah.
Got some post snafu or some post food on here.
Go to that.
And so if I surf to that guy, effectively, it's going to look exactly like a Synology NAS should.
And again, an attacker who's on your network and now sees this, like they at least have to try an admin admin.
Right.
Right.
Yeah.
What you're waiting for is for that one alert that tells you, listen, somebody just found this thing and somebody just clicked on it.
And here's the creds that they tried.
And this starts to get deeper, right?
Because if they tried valid creds, they tried Bob from Accounting's creds, you now know that Bob from Accounting is compromised.
And so again, it's at such a fundamental level.
How can attacker resist this?
Yes.
For you, it's so easy to deploy.
And so those were canaries that could be like that.
And if you say you want to add a canary, so I showed you the hardware version, but you could just as easily say, look, I want to add a canary, but I want it to be a VMware canary, or I want it to run in my GCP cloud.
I want it to run in my Oracle cloud.
And the exact same thing happens.
A VM pops up in your network.
And when an attacker touches it, you get this alert when it matters.
So that's Canary.
And then within Canary, each customer gets these Canary tokens, which are exactly what you've seen on the publiccanarytokens.org.
Except you can go here and say, I want to create an AWS API key.
And I say, I want to put this on Adam's laptop.
And I say create.
And what this gives me now is, okay, here's an AWS API key.
Put this on Adam's laptop.
We put it on.
We forget about it.
And again, you can forget about it forever.
And when an attacker who you care about, and that's the whole joy of these.
Like whether you've got these, Canaries on your network or canary tokens deployed somewhere, put them, forget about them.
And when an attacker that you care about finds them, you're going to know.
And look, some of the tokens are just cute.
So I spoke about the credit card token.
You saw the DNS token.
But for example, like if you use WireGuard, like we'll give you a WireGuard endpoint.
Store it on your boss's phone.
And when he goes...
traveling the next time, and you worried that he's in some foreign country and they've sucked down all his VPN information, you're going to get an alert saying, look, the VPN that was only on your boss's phone just got accessed.
Or we'll give you a QR code token and say, we're doing this for Adam's test.
And when it's over, redirect to Google.
And so here's a QR code.
And the funny thing about this, again, like I think last week we tweeted, somebody hit us up to say, listen, they did a user awareness training thing on their network.
They printed a few of these QR codes, left them lying around.
after everyone went home, the QR code got hit and it turns out that whoever was taking out the trash was going through the trash and effectively dumpster diving.
And so literally the tweet on the page is like, they didn't know they had this problem, but it turns out that the people going through their trash are doing stuff with it.
And so again, it's such a nice case.
a case study for canaries and canary tokens that say, even if you think you don't need them, drop a few because it's going to take you five minutes and cost you almost nothing.
And if it surprises you, it'll change your plans.
So you should consider it.
Yeah.
So that was back to your question of the difference between canaries and canary tokens.
Canaries are entire operating systems.
that either run on hardware or clouds or VMs.
And Canary Tokens are smaller tripwires that you get to put everywhere.
And canarytokens.org are completely free.
Anyone in the world can go hit it, enter your email address, not so that we can mail you, like we're not going to mail you or try to sell anything to you ever, but literally it's so that when someone trips that tripwire, that's where we'll alert you to say that badness has happened.
So you can start just by hitting canadytokens.org.
Create a canady token or 10.
Get alerted when it matters.
Super cool.
Super cool.
That's super cool, man.
Thanks.
Wow.
It's fun.
Well, friends, I'm here with the CTO of BuildKite and one of the most challenging problems.
of modern era software development is continuous integration and continuous delivery.
And so Lachlan Donald, Bill Kite CTO, what are you thinking about today's teams, the challenges they face, the speeds at which they're developing new features, new code?
It is just overwhelming.
How do you all think about that?
Such a good question.
It's the question everyone's asking right now.
All of our big customers are asking us at the minute, like, you know, if we 5 or 10x our throughput this year or 1,000x it, what breaks and when?
And, you know, my answer is kind of same as it's been for the past 20 years, which is that the bottleneck is still trying to integrate those code changes in and then...
deploy them and check they work and then keep them working as you keep throwing more and more code at it.
I think a lot of the fundamentals are the same, but we're just 1000xing the speed of it.
And, you know, that changes nearly every variable.
Yeah, for sure.
Okay, so where does Buildkite thrive?
What particular type of team or enterprise do you thrive in?
The area that Buildkite has always thrived in is like this like fastest moving tech companies of the world.
disproportionately successful in that small niche.
The kind of Shopify class, Uber class, you know, OpenAI class of folks that have this key problem around iterating really, really fast.
And, you know, the thing about all of those folks is they all have subtly different needs, subtly different problems.
And so we've tended historically towards building like really well engineered Lego blocks that scale like orders of magnitude more than.
what our nearest competitor does.
So, you know, I think that that puts our system in this tension where, you know, you've got to spend some time assembling those building blocks, those Lego blocks to get the thing that you want.
But the end result is far and away more performant and scalable and the experience is better than what you get from something that's off the shelf.
So I think we've started from a position.
of really well-engineered logo blocks and then are kind of working backwards towards kind of creating the thing that scales down to a startup that starts with one person and 10 agents next week.
Well, friends, go to buildkite.com.
That's buildkite, K-I-T-E dot com.
You deserve better CI.
Engineer for the frontier we are all facing, trusted by the teams setting the pace.
Again, buildkite.com.
Once again, Buildkite.com.
is small, simple, etc.
That was a V1.
I think you said we were looking at maybe there's a V2 that's been improved, but maybe it's got just one less button.
Who the heck knows?
Maybe, I don't know, how to improve something that's already so simple.
When you host canaries, do you need one?
Can you have one canary in a network?
Do you have to have one for every time you're creating a canary?
Or can one have multiple?
Like many canaries on, I suppose.
Great question.
So we, by design, make them so that they can only ever be one other system.
And like lots of us in the company have pentest offensive security backgrounds.
And we used to love, as attackers, finding anything multi-host with more than one network card on it.
Because inevitably, people use them to straddle VLANs and you can attack it on one network and pop out on another.
And so, in fact, it's a good segue for something else.
On our canady.tools website, we've got a whole page dedicated to security, but it's kind of unusual.
So if you go canady.tools forward slash security, we've got a bunch of how we think about the security of our devices.
And it's something that we think more security vendors should do.
Because anytime you run someone's device or someone's software, you exposed, like they could be the weakest link in your network now.
And so there's a bunch of stuff that we do to make sure that canaries won't be the thing that ruins your day.
And some of them, again, we've done kind of unusually.
A blog post we put out a few years back that is a little surprising.
Like we've got these Canary devices and they report in to your AWS console, but we don't multi-host that console.
So we don't have one fat web app that all our customers connect to, even though that's easier to manage and is pretty standard.
But from a security point of view, if we did that, at some point we'd make a mistake and some attacker would be able to log into their account and see your account.
And so we don't do that at all.
Like every customer gets their own hosted Canary token server.
And it gives us a sort of customer isolation that says no attacks going to bleed over from one to go to another.
And it's really old school security isolation.
But again, it's because we don't want to be the thing that gets our customers compromised.
So back to your question.
A single device acts like a single operating system at a time.
And what we do for that is make them effectively cheap enough.
So customers who buy canaries effectively pay $1,000 per canary per year.
And so when they start off, they pay $7,500.
They get five of those devices.
And then as they add canaries, they add them for an extra $1,000 per year.
That's just always how we've done it.
And typically what customers do is they start off with five.
So they pay us seven and a half K and inevitably we catch their pen testers or we catch an attacker.
And then they say, hold on, we should put these at all our sites.
And so again, something that we were super fortunate for.
I mentioned we don't do outbound sales.
Like we've got single customers now.
who pay us hundreds of thousands of dollars for seven years running.
And we've never met them.
Like we don't have a sales team to talk to them in the way that they normally do.
We've got single customers now who pay us like north of a million dollars.
And we don't have the people to do that sale at all.
But what they did is they started off with five canaries.
It didn't suck.
They moved on to 20 canaries and they liked it.
And now they have thousands of canaries because it works.
And so our pitch as a company is if we can keep making it good enough so that people renew and keep doing the right things, then we can keep focusing on that and not have to focus on shiny ads at airports or things like that.
And so far, It works.
Yeah.
You know, I have some thoughts, I suppose, on all that.
I think the shiny ads at airports, sometimes I was traveling recently, I think maybe in the last year, I remember seeing an ad for Notion and Notion is one of our sponsors.
We use Notion.
You probably use Notion.
And the ad was just like so not, it was like brand awareness.
Right.
I suppose.
And I'll just dovetail off that for a second.
But sometimes those shiny airport ads are not because they have to.
It's because it's a cool factor.
It's like, you know what I mean?
Like, it's like the Super Bowl ad.
We don't really need to advertise Pepsi or Coke one more time.
Everybody in the world knows Coke and Pepsi.
It's for the.
Top of mind, mind share, brand awareness.
Just because you can, you do.
I'm with you.
So now I'm going to ask you a culturally tough question.
Okay, do it.
Have you discovered paddle yet?
Paddle?
Yes.
I don't believe so.
It's like pickleball that Americans love, but better.
Okay.
Americans love pickleball, yes.
And here, in the great state of...
Texas slash Austin, Texas.
We actually have the pickleball capital of the world, or at least it was for a while there.
It was called Dreamland right down the street.
I'm sorry.
It's not going to last.
Paddle's going to take over.
Paddle's taking over.
Okay.
So Paddle's this thing that started in Mexico and then went big in Spain.
So currently Spain and Argentina are the world leaders in it.
But legit, it's like a worldwide phenomenon.
And USA is just starting.
Like soccer or football.
Yeah.
And USA, like Miami has just started with it.
But we discovered it as a company about three years ago.
And we are crazy fanatical about it.
Like there's a whole bunch of us who play a lot.
And so this year, the current world number one contender has a thinks canary on his sleeve.
And again, like you say, it's almost just because we can and because we think it's cool.
And it's, yeah, it's totally just like for us, one of those things that go, we can and we think it's cool.
And we love the sportsman like he, other than being great at what he does, like he's.
He's done some really cool things in terms of being a good ambassador for the sport.
And we're like, yeah, we like that dude.
Like we think that dude is very us.
And so we now sponsor the world number two paddle player.
But no, I'm totally with you.
Listen, I'll wear a Thinkst Canary t-shirt every episode, man.
I'll send you one.
Okay.
I'll send you one for sure.
In fact, a while back, we did a post on, I don't know if we discussed it the last time, on the stuff that we give out as canary gifts, in part because we are crazy particular about it.
So throughout the year, we spend a lot of time looking for like, hey, we think this is cool and we really like, like we wear all of our stuff.
But other than us.
We think that a customer or like someone who likes our stuff, who wears our t-shirt, like we're genuinely proud of it.
And so like we never do like cheap throwaway t-shirts that will go bad in a wash.
These are nice t-shirts.
Our hoodies are really good.
Like people really like them.
Or I'll tell you something else that's super crazy.
Like every year we do something else that's weird, which is we...
we try to, at the end of every year, send all our customers a customer gift.
And so this year we sent everyone these iFixit driver cash.
Nice.
Yes, I love that.
And again, people find it.
Where's mine at?
People, well, if you're a child of the 90s, like a year or two ago.
Swiss Army knife?
Like, yeah.
And again, it's a sort of thing you can, Like we do because we can.
And it's just the thing that says to customers, hey, like we think it's cool that you still support us.
Thoughtful advertising in a way.
Thoughtful placement.
It's the sort of stuff that, again, we're not hippies.
We like money, but we make enough money that we can.
And like the stuff just doesn't have to be junk.
Like we genuinely appreciate our customers.
And if we're going to give them something.
It should be something that we like.
And yeah, so far that seems to work nicely for us.
I like that.
I like all the way.
That's why I said we got to get Haroon back on the pod.
Even if we go back over some stuff again, that's what I told you in the pre-call.
I told Imadi and stuff like, hey, listen, you know, I don't care if we repeat ourselves from the last show or not because I enjoy the way you think, Haroon.
I really do.
I think the way you think is a breath of fresh air.
I really do.
And I like the demo too.
I think that's, so you answered the question, which was, you know, one, how does it work?
And then two, you gave us kind of a visual demo.
So audio audience, go to YouTube for this one here.
And then you gave us a visual, which is cool as well.
I like the fact that the individual hardware canary is only one thing.
That does make sense from a security perspective because you want to limit your exposure.
And, hey, you may have multiple.
Maybe you have a different problem, which is, hey, Haroon, we have literally 150 of these things in our hardware rack.
Maybe there's a 3D printing ThinkVersed thing out there.
I don't know.
I'm imagining.
I'm a racker, right?
I'm a mini rack guy or a full rack kind of guy.
Next thing I know, if I got more than five or even one, I'm going to want to make it nice in my rack.
No, so we've got both those.
So we've got rack mount versions that customers get.
And we've got customers who've just got a handful of them that have created their own STL files and shared them so that you could rack mount like four or five of them.
Yeah, it's pretty decent.
And yeah, you can get rack mount versions of them too.
You know, not that I, I'm thinking about, now I'm thinking about it from a, So I want to go back to self-hosting.
I want to go back to Canary Tokens, the fact that I can self-host this Canary Token server, and then juxtapose that against the fact that you have a hardware device, which is called a Canary.
So they're not the same, but they're similar in the worlds.
And from within a Canary console that runs in AWS, that's my own.
It's not the SaaS version with multiple changelogs or multiple customers on it.
It's my own hosted version of it on AWS.
Inside there, I can manage all the hardware canaries I have, but then I can also create canary tokens.
Exactly.
Who's hosting those canary tokens?
Where is that server living at?
It's on another IP on AWS for you.
Okay.
So it's hosted in the cloud.
Yeah, exactly.
So hosting the cloud for you.
Actually, I'm going to throw in one other confusion in there because there's something else that we build and give away, which is we also do something called OpenCanary, where OpenCanary is the free software only version of these guys.
And that's where I was going.
I'm glad you're answering this question.
Yeah, so it's super scaled down compared to...
Like with Canary tokens, it's absolutely as good as it gets.
Like even our paying customers get Canary tokens that are effectively the same.
Open Canary is a limited core of this Canary device.
So if you didn't want to pay anything, you can go to opencanary.org and you'll effectively get a tiny working honeypot.
that you can run, you can do a little bit of configuration.
And again, we've got great users.
So there's YouTube videos from people on how you can take OpenCanary and deploy it on simple hardware, deploy it on a droplet, deploy it on a Raspberry Pi.
In fact, we've bumped into some customer networks where we've competed with OpenCanary.
Like we get to a customer and the customer's like, look, we've got OpenCanary deployed all over.
Why should we pay for you?
And sometimes our thing to them is, look, if you're happy running that, like we build and maintain that exactly for people who don't want to pay for Canary.
So it might be that that's perfect for you.
And we're happy if you run that.
And that's cool.
So OpenCanary is...
the free little brother of Canary.
Canary is slick and drop it and forget about it.
And it's running in two minutes.
And Canary tokens are free for everyone on canarytokens.org.
And you've got your self-hosted option where you can pull the Docker image.
You can run it from GitHub.
And look, that has benefits on its own.
Because if you take our canarytokens.org canary tokens, some of them will tie back to canarytokens.org.
But if you self-hosted this and you run it on adamnetwork.com, now when someone finds that canary token, it links back to adamnetwork.com and it makes that token even more believable.
So, again, we make it easy for people to do that.
And if they want to, they totally can and should.
Yeah.
For me, I think self-hosting, especially in this era, like this is 2026, as we all know if you're listening to this.
Maybe you're listening to the future, like, gosh, these idiots were talking about that in 2026.
So this is March 2026.
And we're in the burgeoning era where the entire.
operating system of software development is literally being changed as we speak.
It's being rebuilt on top of agentic AI.
Agents are everywhere, and we're all learning right now how to use them.
So if you're listening to the future, that's where we're at right now.
Future, I don't know where you're at, but it's probably cool because I know where we're at now, and the horizon looks pretty cool.
And the reason why I'm so focused on self-hosting isn't the free nature of it, and I guess it is in the sense of freedom, but not necessarily the cost.
that I'm trying to focus on.
It's the sovereignty.
Is that I feel like my gut in this era is saying, even in the enterprise world, because the ability to create bespoke software that solves my need, SaaS is changing.
They're talking about SaaS killing in a way.
There's a lot of things, and I hate to use that word, killing, because it's just too negative.
But there's a lot of change happening right now, and I think for me specifically, I'm focused on what can I build just for the fun of it myself?
What can and should I self-host myself?
Not because I don't want to pay somebody because I'm cheap, but because I want sovereignty.
I want control and a boundary that I can reason about, that I can manage responsibility, not just the responsibility to make it, but then the… just knowing where it is.
And I think Canary Tokens is this example.
So we kind of got to the demo from that lens, which is, okay, wow, I can self-host Canary Tokens.
And that's super cool that you have OpenCanary.
Now let's talk about from a developer standpoint.
Take me into this world.
Okay, so you've got Canary, hardware device, running software.
You've got OpenCanary.
Are those two code bases divergent?
Is it open core?
Is there a build on?
Help me understand how the code bases all interact.
So those two are pretty different code bases completely.
So they're not even the same core.
They diverged so early on and yeah, they effectively two completely different products.
How do you manage that difference then?
I guess maybe not so much.
Answer the question, but more like from a developer standpoint, because if they're completely different, how can they open Canary?
It's kind of a misnomer in a way, almost, because it's not really Open Canary.
It's a fake Open Canary.
Because it's not the true Canary, is what I mean by that.
So mainly, I guess it's if you think about what Canary is, right?
So when we've got this thing that's going to act as a fake operating system.
it's got to have a bunch of components, right?
So it's going to have effectively a core that says run fake services.
And so what we've done is we've said, okay, this service would be good and useful for people.
Let's rip it out and put it into OpenCanary.
Like this is worth it for people.
And then the components of it, like let's fake out operating system TCP IP stacks.
that won't get ported across to open Canary.
Or what we've done a lot of work on with Canary proper, I mentioned in our original call, but when you drop a Canary device on your network, right, it's going to talk to the console running in AWS.
And we wanted, like our promise is this stuff is so easy and it just works.
And one of the things we do to make that happen is all communication between your Canary and the AWS console run over encrypted DNS.
And so on your network, you don't have to make holes or allow management traffic.
Point it to your DNS server internally.
As long as it can resolve DNS, it bundles all of its communication with the console via DNS.
It goes through.
Even when we push updates to the device, which we do multiple times a year, the only communication between AWS and your device is DNS traffic.
And that's not port 53 from your canary to the internet.
It's your canary talking DNS to your internal DNS servers.
And so that entire encrypted DNS channel.
only exists for Canary.
Like it won't be, it won't exist on OpenCanary.
OpenCanary is much simpler.
It says, hey, point me to a mail server so I can send your alerts out via email.
And if you take the Canary console, which we blitzed through earlier, we've put a lot of work into making sure that that console isn't the center of your universe.
So on day one, you go in and say, send all my alerts to Slack and then never log into your Canary console again.
Or, hey, I'm running Splunk, send all the alerts to Splunk and just never look at us again.
So Canary is really a super convenient version of OpenCanary.
But those two are...
sufficiently divergent.
And I don't see that changing just because at this point it would be incredible amounts of work.
So OpenCanary is, hey, if you like the honeypot idea, you want a bare bones honeypot without a lot of work, use OpenCanary.
Canary tokens is, as far as we're concerned, our cutting edge stuff.
on tokens and you get it free and self-hosted.
And Canary is the thing that pays our bills.
Nice.
Yeah, I think even last time I was alluding back to the fact earlier I said I've gotten smart since then.
I think I said I wanted like, hey, I self-host my pile.
I want to self-host.
I want a canary.
I think I even asked you on that podcast.
I think you said you'd send me one, but you never did.
I remember that.
I'm just messing with you.
I don't even have an AWS account.
So if I have to run my console in AWS, I would have to go and become an AWS user to get one.
for you.
So we make that stuff so slick.
I'll, I'll drop you an email after this.
It'll be interesting to see your, your comments playing with it.
I want to play with it.
I mean, it's less like I really don't, I don't really need it.
I just want to play with it.
Like I'm in this era where, especially as a podcaster, I mean, this is, this is the benefit of the job, right?
I get to play with everything.
Yeah.
It's a win.
And I would love to play with it.
We'll make it happen.
It's, it's totally.
I even do a demo.
I'll do a demo video of it.
Well, I'm trying to do more stuff.
on our YouTube channel, I'm starting to break into that a bit more.
And I think this is an area where it would be cool to show off this kind of device.
I mean, I think, again, back to the fact that you've got this, not a pejorative, but this tiny little company that does.
Was it 20 million annual recurring revenue?
Is that accurate, Arun?
Yeah.
So it was.
So we've now gone a little past that.
But yeah.
So last year we crossed that.
22 and a half ARR?
I'm just kidding.
30?
Yeah.
No, it's pretty cool.
And again, we've never raised our prices.
We're not doing outbound sales.
Like we don't ping people and say, hey, you should take more canaries.
We think if we can do it and not suck, then people will use us more.
And again, like one of the caveats that I want to add is we don't lack for ambition.
Like I want, I genuinely think canaries should be on every network.
Like if you're a big company, you should have a few.
And if you're a small company, you should have a few because like they save people from genuine badness.
But we just don't think we have to blast it to the world.
Like we think the way we're growing will get there.
And yeah, that's just how we plan to take over the world.
One happy customer at a time.
Let's go back to, if you don't mind, since this is GPL, let's go back to Canary Tokens.
So github.com slash thynxt slash Canary Tokens.
No, just canarytokens.org.
No, no, I'm actually pointing out the GitHub repo.
Oh, the GitHub?
Oh, yeah.
Yeah, sorry.
I was trying to direct the audience there.
So that's why I'm camped out right there because the reason why I ask this question is, one, open to contributions.
It's open source, but do you take any contributions?
Yeah, we do.
In fact, late last year, we bought a small UK company that was building Canadian tokens.
And we like what the engineer was building.
He had sent us some stuff, but he was actually building his own Kiniti tokens.
And we spoke to him and said, hey, we think this stuff is cool.
Like, why do you have to have the overhead of also building a company?
Like, come build stuff with us.
And so it was our first company acquisition.
But yeah, other people who want to build Canary tokens and people submit patches.
In the open source tradition, like it's not a ton of people who submit, like clearly more users than submitters, but we'll happily accept PRs.
And yeah, it's a good idea for people to check it out and play.
In fact, almost all of the tokens.
that are significant.
When we release them, we also release a blog post that often says, here's how we built it.
So like the AWS Canary token, we would have gone into great lengths saying, here's what it actually does.
Here's how we're getting these logs out from AWS.
Here's the trick behind it.
And in some cases, what that means is some corporate network somewhere.
might decide to not use our whole Canary token framework, but they can use that trick to set up traps on their network and more power to them.
Like one of the benefits for using Canary and Canary tokens is lots of times you're a big enterprise and you think, well, I can build this honeypot, I can build this strip wire.
And then priorities in the company change and someone rolls out of the company and who maintains it.
And who maintains the alerting?
Like, did the alerting go down and now you've missed your critical alert?
And so people pay us when they want that to not be their problem.
So if you are going to do it on your own, like, we'll tell you how we did it and we'll release code and you can go do it.
But if you want to do your business, then we take care of this business and it's a good deal for you.
And that trade-off seems to work.
I'm going to take this back to my lab, Haroon, because that's why I'm asking these questions.
Because one, when I start touching a code base, I can't help but just find, I'm an idea guy.
You can probably tell that.
Sure.
And I can't help but start to solve my own problems.
And that means potentially changing your code base.
Totally.
I'd love to be able to understand the pattern of what it takes to create new canary tokens.
Because the one thing I, and maybe.
Maybe there's a reason for this, but when I look at canarytokens.org slash nest, what I don't see here is an SSH key.
Yes.
And that seems like a pretty obvious one.
So it's interesting.
So if you did an SSH key, you'd need an SSHD to catch it, right?
And so we'd have to host an SSHD.
And we actually, it's so interesting.
Go into the nerdy stuff, man.
Take me there.
What's the angst?
No, so what's interesting is I skimmed past it when I had the console up, and you actually take me straight back into it.
So that's a great question.
Go ahead.
Console's coming back up.
Let's see it.
So we've just released what we call, and it's going to be slightly confusing for your audience because I'm now going to introduce a third concept.
And it almost doesn't have to be a third concept.
But this is what we have.
But literally, you're looking at something that we've just announced this week.
So if we go back into the console, you notice the canaries that I spoke about and the canary tokens that we've spoken about.
And down here, you notice something called breadcrumbs.
And what breadcrumbs are, breadcrumbs are like tripwires.
but they lead you to Canaries.
So like Hansel and Gretel's breadcrumbs.
And so if you take a look at these breadcrumbs, it's a concept that we're just starting to make a first class citizen.
And again, in the way we work, if you've got Canary as a customer, you just magically get the stuff free.
But you'll notice the first one is exactly what you said.
Yes, thank you very much.
I am running this canary on my network, which happens to be running a fake SSH server, then I can create a breadcrumb to that SSH server.
And so if I go SSH here, it says, well, which canary would you like to lead a path to?
And I can say, well...
I want to lead a path.
Oh, yeah, the demo we made earlier.
Yeah, so would that have been running SSH?
Yeah, sure.
And then I say this reminder is going to be on Harun's MacBook.
And so what it's going to do now is create a set of SSH keys and give me a SSH config file that does two things because it points.
to that canary.
Now I can take this and download this breadcrumb and store it on Harun's MacBook, the way I just said.
And an attacker who compromises me now sees these SSH keys that point them to a canary.
And so it's going to increase the chances that this attacker is going to hit the canary on my network.
And when they do, that canary is going to be able to say that key was created only for Harun's MacBook.
And so you're now getting a double time.
But if you are a large org and you just downloaded, you just bought five canaries, so you paid us seven and a half K, you can use this to create SSH keys for every server on your network.
Because if an attacker compromises that server, they're going to find that SSH key.
It's going to lead them to your actual canaries.
And it's going to tell us which server was compromised.
So again, it's just massively scales out the benefit to customers and it's free.
So yeah, this could have been called another canary token because the concept is exactly the same.
We see it here as a breadcrumb, but the concept is exactly the same as a canary token would be.
So yeah, it's a deployment artifact almost, but there you go.
Yeah, I am a little upset with one more concept.
Yeah, it's totally...
Yeah, we try hard not to introduce...
more concepts because again, the cognitive overload, like you end up with, oh, but do I do this or do I do that?
And so we've had literally what you're looking at, like we pushed it out and announced it this week after playing with it for a really long time.
And we've had customers trialing it and using it in anger for a while.
And it's something we're going to do more work on going forward.
Like we think it's worth it.
And again, something that...
Breadcrumbs, though, is that in the naming sphere of...
I mean, that's where you sort of dovetail it off.
I mean, I'm using a little pun there for a reason, but...
Yeah.
It doesn't fit the narrative of Canary tokens.
Yeah, it's true.
I suppose breadcrumbs, maybe canaries follow breadcrumbs, maybe.
A cum trail?
Yeah.
We went to Little Grimm Brothers.
A little too far.
Well, you might be in the park.
But, I mean, do you have canaries in the park?
No, you probably have – what are those in the park?
Like what kind of birds are those in the park?
Just doves?
I don't know.
Pigeons?
Pigeons.
Yeah, pigeons.
Those are the most popular in cities is pigeons.
Okay, I'll follow you there.
I'll let you have it.
Thanks.
So the reason why I asked you that question, and I'm really not angry, but I – As a developer, I angst over this and everyone listening to this will totally understand this.
When you start to build out a world of a solution and you start to name it, and then obviously you want to kind of keep that name.
I try my best to not fracture that world, but to kind of build incremental good layers on it.
Totally.
And I empathize with the struggle because, I mean, I pointed out SSH keys for a reason because that seemed like the obvious canary token.
And I saw it missing from the list, but it's more of a breadcrumb.
Why did you choose breadcrumb over token for that particular one?
So interestingly, and maybe we will bring a token out that is an SSH token also, because again, the company that we bought in the UK actually had an SSH token.
So we bought them and we bought their tokens.
And so we now have a working SSH token.
pre-built in there.
We've liked the thought for a while of leading people to canaries on corporate networks.
I like the idea too.
That idea of crumbs that says if the person has SSH, like create SSH config files.
You could put one of the docs, Harun.
Public docs could have little breadcrumbs.
You know what I mean?
Exactly.
Or if you've got, so if you just look at our initial list.
Or even like in an API, you could be doing like API sniffing and your API sends something unique that no one cares about because you're just trying to build on the application.
But a hacker with a nefarious means will look at the API call instead in the header and say, oh, hey, there's extra bits in there.
What is that?
And that's a breadcrumb.
Exactly right.
And in fact, when you just play with Canary tokens, you're going to see even the simplest of Canary tokens without having to build it or build stuff, you can build on.
So you mentioned the DNS token, right?
If you took a DNS token and put it in your host file and you called it supersecretserver.adam.home.
Then an attacker who finds it goes, what is this?
He resolves it or he surfs to it.
And the moment he does, his machine resolves that DNS token.
And you get told, listen, this thing that was only stored in Adam's host file just got resolved.
And if you take the simplest, like one of our simplest, simplest Canary tokens is we just give you a unique URL.
And if anyone surfs to this unique URL, you're going to find out, we're going to tell you someone surfed to this URL.
Now, years ago, a really smart reverse engineer gave a presentation on how you could embed canary tokens inside of binaries so that when people were reverse engineering your binary, you'd basically, so you could take one and make it a URL endpoint inside your code.
So now the guy reverses your code.
He sees this URL in your code.
He goes, well, what is that?
He hits that endpoint, and you know somebody just reversed your code.
And he actually spoke about different versions of it because if you wanted, you could wrap one up in a complex loop in your code.
And now only the type of reverse engineer who unfurled that loop could get that URL.
And now you know that you're being hunted by a slightly more advanced attacker.
So the Canary tokens really give you detection primitives that you can use in different places to do cool things.
And with them, really, the sky's the limit.
Like you can genuinely do cool things.
Yeah, just based on what you want to do.
Friends, I'm back with a good friend of mine, Michael Greenwich.
Michael, I know that I love WorkOS.
Our audience may not know about WorkOS, but what are the challenges developers face starting a new project?
Choosing the right tools, choosing the right database, choosing the right auth.
Take me there.
When a developer starts a new project, The decisions that they make at the very beginning end up having long lasting consequences.
What language you build in, what platform you build on top of, what database you choose.
These are things that are very hard to change later on.
So they have like major consequences.
And especially if they limit your ability to grow and scale, at some point as the product starts to take off, you're going to have to stop developing new product features and go re-architect or rebuild your system.
And that might.
be a killing blow right at the moment you need to accelerate.
So these decisions early on are really, really important.
And I think that's why developers gravitate towards solutions that are mature, things that they know that will scale, even things that are open source.
You're going to pick something like PlanetScale for your database provider, not because it's the cheapest or because it's the most fun to use, but because you know it's going to be a durable provider that you can scale on for years.
And WorkOS is like that for auth.
You know, at the earliest, earliest days, if you look across all these different services, they kind of look very similar.
But at day 1000 or day 2000 or day 10,000, you're going to want to have made sure that you picked a platform that could scale with you.
And today WorkOS is powering auth and identity and security and permissions for all of these AI companies, literally the fastest growing companies in the world, like OpenAI and Anthropic and Cursor and Perplexity.
WorkOS is under the hood there.
So I think when people pick WorkOS early on, really what they're doing is trying to pick the defaults.
to allow them to grow and rapidly scale.
And there's no platform other than us that's done that at that same level.
Well, friends, the next step is to go to WorkOS.com.
Sign up today.
Check it out.
Free for a million active users.
Try it today.
There's no excuse not to.
It is your default.
You should choose it.
So do so.
WorkOS.com.
Once again, WorkOS.com.
Let's go back to, if you don't mind, why Python?
I am not against Python by any means.
That's an interesting question.
But why Python?
And let me frame it from this perspective.
Let me give you my framing, and then you can answer however your heart's desire is because I like Python, but I also like maybe on a network device, maybe Rust might be more pertinent.
Like in today's age, Rust is all the rage these days.
or just mainly something that compiles to a single binary and it's easier to deploy and reason about rather than a complex Python code base and how do you deploy it?
Rust and Go will be the two things that kids will be calling for, right?
And we've got skills in the company.
Yeah, so we've got kids in the company who are hitting at us every day for being the old boomers using Python.
And look, Part of it genuinely does come from our background.
And when we started, we were going for what can we use nicely?
What can we reason about?
What can we do safely?
And we experiment a fair bit with new technology for new tokens.
But really, what you go for is stability across our development base.
If we were starting fresh.
we could be convinced to say, hey, let's do this thing in Rust.
In fact, we've got projects going right now that are distinct enough that are written in Rust.
But when we started, so 10 years ago, it was the best alternative for us then.
And it's not enough for us to move off it yet.
Like we don't think there's...
significant reason to.
In fact, we had to do a Python 2, Python 3 rewrite for some of our stuff.
And I personally, like earlier you spoke about capitalism, you start to get to the stage where you realize you're old.
And for the Python 2, Python 3 upgrade, I personally hated it because we take a bunch of engineers, who have to now work for months, we've got to make sure all our tests are correct.
We've got to make sure all our edge cases are correct.
And for that months of work, customers get zero benefit.
Like they're getting the same thing they used to, except now it's in a different language.
And so if the thought comes up of rewriting in Rust or rewriting in something trendy and hip, there's...
It would take a lot to convince me, mainly because you end up spending a lot of time on something that doesn't directly benefit the end user.
So, yeah, mainly that's where we are.
And for sure, like when you're hiring younger, hipper developers right now, like you'll attract younger developers coming in going, hey, we're a Rust shop or we're a Go shop.
Python still doesn't have heavy negative connotations.
Like it's not Java yet.
But yeah, that would be the answer.
It was good for us.
It allows rapid iteration.
And at this point, doesn't add significant drag.
But certainly, yeah, things like Rust and Go are...
are pushing in.
Like they're not just trends.
They're here to stay and they're going to bring goodness.
But that's the reason for the most part.
Yeah.
Well, I just think about, I mean, sure, Docker solves some of the problem, right?
A dev container solves some of the problem.
I think about a developer, and maybe these are the things you care about in terms of ergonomics, because you're not...
you know, the tried and true typical capitalist.
Like you're actually trying to make a dent in the world and making a dent in the world isn't just, you know, fat in your pockets with cash.
It's like, well, maybe I can actually make this project a bit more approachable, maybe potentially easier to develop against.
And if you have the desire to want canaries everywhere and the largest beacon to your funnel is canary tokens.
Yeah.
Well, heck, you know, why not?
Right.
Like just make it even more.
Not that, not that.
Not that Python is not.
So I'm not trying to hate on Python by any means, but it's when you can consider deploying Go to a system so much easier.
A single binary.
Systemd on any given Linux, a binary is pretty easy to reason about in a lot of cases.
It could be an API, it could be a CLI, it could be an MCP server, all in one single binary.
And heck, if you want to be nefarious or anti-nefarious, you can wrap a little canary token in that binary, as you talked about already, you know?
Yeah, no, it totally makes sense.
And it's stuff we've considered.
At this point, the honest answer is like 10 years in, like a legit software company, as we become adults, you end up with...
history and legacy that you carry with you.
Debt, but not tech debt.
Yeah.
It's just debt.
Yeah.
And you have the debt of choices, but one of the things we keep trying to do is trying to make sure that we're still making good choices.
And so it's stuff that will come up.
And yeah, I'm pretty sure we'll see a token released soon that's actually go on the back end.
And so it's a Go token now in the same framework because again, yeah.
That's interesting.
And actually an actual Go binary has a token itself to like instantiate it like a Go D kind of thing or some sort of like demon that runs in the back.
So that's what will be running in the background.
What is this?
Let me hit it.
Let me, whatever the binary's name is, dash dash help.
You know, let me sniff it a little bit.
It should be exactly that.
I'll give you a heads up when it's live so you can go.
That makes a ton of sense.
Yeah.
Wow.
Yes.
There's so much you could do with this room.
No wonder why you are so excited because, I mean, your world is endless.
Your world really is endless, man.
Yeah, it is pretty good.
And you're making enough money, which is phenomenal.
And honestly, you know, my only.
The reason why I ask you this is I'm just such a Go fan.
I'm just such a Go fan.
I'm not like I'll write Python all day long in the place where it makes the most sense.
And it's usually in the age of data or analytics or agents or it's TypeScript because I'm interfacing with an SDK or something like that.
And I'm harnessing, you know, an API call to an LM, you know, so I kind of hop into TypeScript and Python.
Usually in those times, I'm happily becoming a bun developer.
And, you know, my choice of stack when it comes to web these days is BUN plus SvelteKit.
Like you put those two things together, you can deliver a binary.
You can SvelteKit your way to a binary.
It's so amazing.
I haven't hit the edges yet where I'm getting bit by that choice yet, but thus far as paying grapefruits.
Otherwise, it's Go.
You know, it's Go, Rust, when it makes sense, when it's like network and I don't want any latency.
I want total performance.
In Go's case, it's got the garbage collector, so you have those issues.
It wouldn't make sense to build a DNS resolver in Go.
You could do it, but you would pay the penalty of latency on network calls and that hot path of a DNS lookup.
You don't want to slow that down with Go.
You want to do that in Rust.
So it's super interesting.
So we've got our network switchboard, which is our DNS server, runs in Python.
And like I say, we push binary updates through that with lots of the heavy lifting done by Twisted, thankfully.
But, and we've just, I think we've just got a Rust-based DNS cache proxy written fairly recently for some internal work.
But no, it's goodness.
And we're not super, religious about our tools.
Like, we'll use the best thing for the job.
So, yeah, for the most part, watch the space.
Is your desire for Canary Tokens to be self-hosted by a lot of people?
Like, if you had to zoom out and say, my Wave of Magic Wand wish list, not that I need it, but, like, if I could just have Canary Tokens go this direction, which direction would it be?
No, if I'm super honest, I like people using the hosted server.
And mainly there's a form of service level that we can give with that server.
So we've been running that server for 10 years and it's been down only a handful of times.
And if someone self-hosts you at the...
Like you don't know if they run it right or put it on hardware that gets filtered or something like that.
So generally, I like running it on the server and doing it nicely.
Our honest hope for it is that we can provide stuff that's so useful that people use it easily.
Like even with canaries, a counterintuitive...
thing that actually was a problem for us early on was people who overthought Canary.
So it's like everyone thought this has to be complex and people would buy it and they're like, hold on, we just want to strategize about where to deploy it.
And initially we didn't have the confidence to say it, but we saw it happening enough times to say, listen, don't think about it.
Or like, why are you thinking about it?
Just go plug these in.
And inevitably, it would catch stuff while they were still deciding where to deploy it.
Really?
Like mysterious activity?
Yeah.
We've caught so many attackers during our POCs.
So customers arrange a POC.
We send them a canary.
We set up a console for them.
And during the POC, they catch attackers.
Like we've got tons and tons of cases where this has happened because most customers just don't know how much bad stuff is bumping around their networks because they don't.
Like the state of network defense is often surprisingly bad.
And so one of our big things became saying to customers, listen, don't think about this too hard.
Like just deploy them.
Like the only way to do it wrong.
is for you to not deploy it.
So you might come up with the perfect deployment strategy after you can, but for now, just plug them in.
And again, I mentioned early about how Canary, like one of the things we got lucky with, I would have mentioned this on our first podcast, but for new listeners, when you think of like a honeypot or deception, your first thought is how you've got to make it really high fidelity copy of your network to fit in.
And you start to think how you've got to craft this thing to hide in your network, right?
And you'll end up with a really strange realization that we got really lucky with.
So for example, take that AWS key canary token I spoke about.
Like you'll get a customer who says, hmm, we're not an AWS shop, we're an OCI shop.
Like, can you give us an OCI token?
And we can totally do something for them, or if they're an Azure shop, we can give them an Azure certificate.
But here's the thing, an attacker who breaks in and is orienting themselves, who finds an AWS key on your network, doesn't have the luxury of saying, is this an AWS shop?
I'm not going to use this AWS API key on this network because I don't think this is an AWS shop.
They see that key and they're going to use it.
So if you take our canaries, right, they can act like, if you've got an OTA network, like they can act like a Simmons microcontroller, they can act and they can talk good Modbus.
But in honesty, if you've got an OTA network and you just placed a canary that looked like a Windows file server on that network, do you think an attacker who lands there and sees a Windows box with an open file share, they still have to hit it?
Yeah, it's too tantalizing.
They're like, what did I find?
What that means is that you can't deploy a canary wrong because your initial thought is, I've got to make it look like the other PLCs on this OTA network.
But the honest answer is you could have made it a Windows box and it would still work.
And so there's almost a thing where because security has had all this complexity for so long, you think it has to be complex to work.
And actually, just conceptually, these things work while they're simple.
Which we just got lucky with.
Like we didn't know when we started.
But yeah, that's how it is.
And it works.
So your desire for Canary Tokens is to be not generally self-hosted.
Although you can.
Yeah.
So my...
There's no limitations, but you just prefer it that way.
For lots of people to use it.
And in honesty, I think most people...
When we make all our stuff, internally, we fight very hard for, is this too much work for the customer?
And self-hosting, there's a portion of the population who can and should, so we enable it for them.
But most people, they want to go about their day and they want to get done with it.
And so our thing is to make it.
easy enough and simple enough for all of those people to get the benefit anyway.
And so you'll see almost everything we end up doing, we end up saying, it's so easy.
Visit us, click this, wait till it alerts you.
Because we think there's a sweet spot there of people who could do a lot of things, but never get around to it.
And instead, we make that happen reliably for them.
So if I'm honest, those are the people we most want to help because the people who want to self-host, they'll be able to do it.
Like we make it easy enough so that they can, but I think the other people are underserved and we're trying to make that happen for those people.
What about?
products that could bake what I guess you could bake a token in but what if you wanted to productize inside of your own product the usage of canary tokens I'm thinking like auth providers or like some particular applications out there would be really interesting just to bake in to like There's a license.
I can't recall GPL's license preventions.
Do you recall what limitations are there?
So GPL normally just says if they're going to take it and make changes, they must push those changes up.
To open source.
Yeah.
So it follows our hippie roots.
But guys who are self-hosting do their own thing.
And people who want to extend tokens.
Because we publicly write about how they built, like you can build clean room implementations of it just based on, like with many of the tokens, there's the initial, I say clever because I'm talking about our own stuff and everyone thinks their stuff is clever.
Like there's the initial trick that says, here's how you can get a signal out of this thing that something's happening.
And once you know that, you can build it a bunch of different ways.
And so when we write about it, we make that possible for people.
But yeah, we'd also be happy to play with people.
In fact, last week, the author of Center, which is application, open source application listing.
Yeah.
whitelisting and ignore listing.
They pinged on Twitter to say, hey, the same thing that we did for the CloudStrike token, can we do something with them so that their API keys are canary tokens also?
And yeah, we'll be happy to play with them and do that sort of thing.
So yeah, there's room for people to play and other vendors to play.
We'll happily work with people to make that stuff happen.
Yeah, because I mean, even on my, I mean, I'm just a little tinker here, but I am building some stuff and that stuff may get used by lots of people.
It may never get used.
Who the heck knows?
But I'm a builder like everybody else is.
And I like to know my limitations.
And one, I'm going to play with canary tokens.
I'm glad we had this conversation to remind me that this exists.
I'm glad we went down the road of the fact that there's a code base behind this and it's open for me to tinker and play with because I'd like to just, just for the fun of it, really.
consider tokens that matter to me that are not tokens that matter to you in the tokens world so far.
And I'm sure there's some.
Yeah, it makes perfect sense.
And look, if you're doing any of that stuff, drop us a mail, like the team.
We like our stuff getting used and we like cool use of our stuff.
So drop us a note and we'll be happy to hit you with thoughts and jump in.
Yeah.
If I sent a pull request that said rewrote this and go, would you be upset about that?
That's just a joke.
It's just a joke.
It's just a joke.
It's just a joke.
Like, hey, what is this PR?
Like everything's gone and it's replayed.
Okay, gosh.
Because, I mean, just because, just because.
I'm not much of a Python guy myself, but it's okay.
I will navigate your world just to play.
Your agent will be.
Don't worry.
Yeah.
Well, I just think even like, where's the playbook for what is a Canary token?
Like, is there a specification for a Canary token that I can easily read about in the docs?
I imagine it probably is.
Yes.
This is how my brain thinks now.
Totally.
Yeah.
So if you hit docs.canarytokens.org, you'll get a whole bunch of documentation.
on how to use them, what they're doing.
So docs.canarytokens.org would be a starting point.
And there'll be a whole bunch of stuff for you there.
Do you think that this is the biggest beacon to say things exist, canaries exist?
That's a good question.
And since you don't have this desire to market, what if you marketed through just the prowess of your awesome software in a way?
Like if you made just by sheer will of force being that cool, canary tokens, not that it's not cool, but cooler because everything can entropy, right?
Everything can always be cooler and better and faster and stronger, right?
So like if you put more weight behind the awareness of – and not even because you're marketing it, just because it's just got so much gravity coming to it that naturally – your kind of core business gets exposed and more people learn about and use canaries?
I think it's certainly possible.
Like I have a, and again, probably not a great answer there.
Mainly my, my answer there is that so far, like.
Yeah, I don't know.
When I say it, it sounds terrible.
My intuitive answer would have been that we're pretty happy with our growth.
Like, there's a line to be walked between customers who pay for the stuff, Canary tokens that we build.
And right now, we're pretty comfortable with it.
Client base keeps building.
Canadian tokens keep building.
I'm trying to think if we had a massive number of people building for it, whether that would make a difference.
Yeah, I guess it wouldn't hurt.
Mainly, I think there's an interesting thing where, like when we started, the thing on our mind was, like, can we build a thing that's useful?
Like, can this concept work?
And this was Canary.
And then like we had some people buy us and then we said, OK, like, can it work well enough that they'd renew?
And then our thing became, OK, but can like customer X like this?
And like at this point, like genuinely, like our customer list is crazy, right?
Like some of the best security teams in the world have blogged about how Canary saved their...
their networks or what they do with Canary.
And so for the most part, like what we want to do is keep that going.
And we've got a pretty firm belief that if we keep doing that, that stuff keeps radiating outwards.
And I'm not particularly worried about, the VCs talk about like, throwing jet fuel on the fire.
And like, I don't think we have to throw jet fuel on the fire.
Like, like I think, yeah.
That's not my suggestion either.
Even let me help you understand the lens of my question is, is less on the suggestion that, okay, because canary tokens are cool and it creates this natural visibility.
It's not the lens of growth.
It's the lens of.
more people using this tech because it's so useful in what it does.
The breadcrumbs idea you got is just fantastic.
Obviously, the idea of canaries are fantastic, as you mentioned how you've caught some in POCs.
It's more like the desire as a maker and a builder to see a useful thing be used.
That's where my lens is going from.
Yeah, I understand.
And no, like for that, getting it used by more people.
is a win.
Like, like it warms our heart.
Like it's why we're doing it.
So, so more people using it, uh, is a win.
And yeah, we could, like, I guess there's, there's more to be done with, uh, marketing it like, uh, and, and getting it out there.
Um, yeah, it's, it's worth.
Well, sales and marketing are two different things.
And that's why you always have the phrase sales.
And marketing.
Sure.
Marketing largely is story.
Yeah.
And usually people leverage that story for sales.
For sales.
Right.
But you can leverage that story for just the fact that you're cool.
You know, just because we're cool, we can.
Just the same reason why you put effort into the hoodies that you do, that you use quality hoodies versus something that's not high quality.
Sure.
But you put care and touch into everything.
That's kind of where I'm coming from.
Yeah.
It makes perfect sense.
I think there we probably stay too close to our early.
We'll build cool stuff and it will get out there.
And there's more work we could do to share that love.
And it would mean more people using it and getting saved.
So it's worth taking away.
I'll speak to our CEO.
Okay.
Good one.
Before we go, can you give me the juiciest canary story you got?
What is the juiciest story?
If we have CISOs listening to this or somebody who's adjacent to their CISO and they're like, my gosh, I listened to the coolest developer podcast.
I heard from this tech I'd never heard of.
They have the coolest views on their tech, the coolest views on revenue, how they run and shape their company, et cetera, et cetera.
Oh, my gosh.
They proved a concept inside a company that saved them from X.
Like, just give me the juiciest story you got.
The juiciest.
So the first thing I'll say is people should check out a site called canary.love.
So canary.love is just a collection of people tweeting nice things about Canary.
And mainly it's from defenders when Canary saves them.
But some of it is from pen testers and attackers saying, Canary caught me.
It's the only thing that caught me.
Here's why you should use it.
The best Canary...
So first I'll say, we seldom have a week go by without a post on our internal Slack from someone who caught something.
So some customer mails in to say, you caught our pen testers or you caught our attackers, you caught this.
Like empirically, they just work.
But some of the best stories we hear about Canary, we only hear like when we're at a conference or at a trade show and someone comes up to the booth and whispers to us because then it's like, hey, this happened and police were involved and we kicked down the door and the stuff went down.
But one of the things we didn't expect was how heavily...
canary tokens would end up being used by law enforcement.
And so law enforcement all around the world end up using it to track child sexual abuse cases.
And so we end up with a whole bunch of love from police departments saying, this is what the stuff is used for.
Here's how we catch people.
And for us, it's been like genuinely there's making an impact and there's making an impact.
And like we've gotten mails from police departments saying we've been after this dude for so many years and this is how tokens helped us track them down.
And thanks.
Yeah.
And these breadcrumbs would be cool too.
Yeah, so that stuff has been amazing.
And look, like I said, I don't know if we end up covering it, but like really big customers.
For us, there's still an element of it where you're still a kid.
And like if NVIDIA is the hottest company right now and they blog about embedding DNS tokens inside of models to detect when they're stolen.
Or Grafana, who we use internally for some dashboards, put a blog post saying, we told you we caught attackers, but how we caught them was Canary tokens.
That's the story I want to hear.
Give me those stories.
What more can you share about NVIDIA and their DNS token and models getting sold into Grafana is a friend of ours too.
Both of them are just public blogs.
Like, like NVIDIA let us know.
So, so I'll send you the links, but NVIDIA basically told us, Hey, we've put this blog post out and we talk about using canary tokens to protect models.
And, and Grafana had a super cool blog post because they basically wrote a blog post.
I think they called us the unsung heroes or something like that, which, which was super cool.
And, and they basically gave a how to, on Canary tokens because they ended up catching attackers on their networks through Canary tokens.
And so that sort of stuff, yeah, it absolutely makes it all worthwhile, right?
Like it's happy customers saying stuff we didn't even know they were going to say and giving real world stories about how they caught attackers.
So for us, it's perfect.
I guess last question for you.
I think, is are there any canary tokens in the canary token database?
Or, sorry, are there any canary tokens in the canary tokens code base?
They are not.
They are.
We have them all throughout our infrastructure, but not in the canary tokens code base.
So even canaries are canaried.
And so if someone were to...
hack into the devices or if people were to hack into our infrastructure, like we eat our own dog food.
But no, Canadian tokens is what you see is what you get.
And it's pretty straightforward.
That's a really interesting idea to figure out how to sprinkle.
And I guess you'd have to be, there's certain cases, maybe like a Palantir, you know, not an Atom Tinkerer code base where it matters, but like a Palantir kind of code base.
Or even Claude with, you know, the bombings in Iran around AWS data centers.
Like they're going after, like you can't write this headline, bro.
The data center is getting, I mean, the saddest stuff in the world, obviously, but data center is being bombed, not just because they're data centers, but because Claude exists in there.
It's crazy.
Like seriously, like did Predator not, or not Predator, Terminator not predict some version of this?
Like you can't write that headline where you were at a data center is not down because of a key role accidental.
It's down because of a bombing because Claude is hosted there.
It's insane.
You know what I'm trying to say?
Yeah.
Gosh.
No, it's, but, but look, literally like tokens and, and canaries, like we see deployments like that.
And, and.
So the cool thing about it for us as a technology that we've built, like I say, it's if you're a two-man law firm, like you buy it and plug it in and don't do anything.
But if you NVIDIA on your technical blog, you say how you're embedding them in a model.
And if you Grafana, who are super technical, and you're saying...
This is how we're deploying these things and how it catches attackers for us.
So it allows people to just use them and it works.
And it allows people with super smart security teams to extend them and get value.
And mainly the thing is you start and then you figure out how you can do more with it.
Yeah, I like this.
Every time, I mean, every time we've talked, this is twice now, but I think about our conversation a lot from a couple of years back and I've been a fan.
I'm smarter now and I can see how I can actually deploy these things realistically.
Like I've become a better networker, not like physically, like as a human being, but like, you know, software networks.
Yeah.
I've learned, I've learned a lot.
I've steeped, you know, my, my fascination is in the home lab.
I learn a lot.
Like the coolest thing about.
the world we live in is I'm not one of those home labbers where I'm like, I got to self-host all the things just because like, like really my home lab is where I experiment.
It is certainly a laboratory.
For me, it's an exploration.
It's a map of where I could go, where I want to go.
And that's what I love most about home labbing.
I learn about networking, learn about DNS, learn about storing and hosting data, learn about propping up VMs with Proxmox or.
I don't know if you've touched this yet, but Incas.
Have you played with Incas by any chance?
I have not.
Are you a fan of Linux containers?
Yeah, sure.
Containers, obviously, right?
Docker containers?
Well, I keep mentioning this because I'm going to have the person on the show.
At some point, Stefan, he runs this project.
It's a fork from Canonical.
You know Canonical?
Ubuntu?
Canonical had a project called LXD.
It had some licensing changes.
Some of the original creators and maintainers of it weren't, I don't know the exact story, if it was bad or good, but just for whatever reason, it's a fork.
And it's a derivative fork.
So I think LXD went, I think it was something around the, when you commit code to it, having to sign an agreement and not truly open source contributions anymore.
I think that might've been some of the details behind it.
We'll clear this up at some point in the near future.
And I'll stop.
paraphrasing this jacked up story I have, at least my version of it.
But Incas is a fork when it was open source of Canonical's LXD, which is Linux containers, it's system containers and system VMs.
So kind of like one layer below what Docker is.
It's not quite, it's similar.
You can run a VM like that.
Like a VM is like a Docker container in a way.
Yep.
If I understand correctly, maybe I could be wrong, but Linuxcontainers.org, Incas, it's the newest hotness out there.
It's so cool.
And I think in your world of what you do, it could certainly be part of your stack and what you are building over there.
Canonicals, another South African company, kind of.
Kind of, yeah.
Kind of.
Well, yeah.
So Shuttleworth was a South African technology guy, and then he went.
and took made Ubuntu happen.
But yes, we just claim him for our South African heritage.
I mean, my distro of choice for any given Linux server, hands down, is Ubuntu.
I mean, love the tech.
That's what he did, right?
Like he made a besquillion selling his tech company in the early 2000s.
Yeah, like it was the crazy early days.
I love that term.
He used it to go to the space station on the one hand.
And the other big thing that he did was he, I think he forked Debian and put money behind it to make Ubuntu.
And yeah, it's been great.
Like, I think it's been a genuine gift to the world.
Yeah.
Well, since you mentioned his name, Mark Shuttleworth, that's a fella I want to talk to.
His first name is Mark, right?
Yeah.
Is my member correct?
I thought so.
A lot of names in this tech world, but that is, if you're listening to this, Mark, much love, man.
Come on the show.
Or if you know somebody who knows somebody and you got away, I'd love to get him on the pod at some point.
I'll fly to you.
You can fly to me.
We'll figure it out.
I live in Austin, by the way.
It's a lot of good barbecue.
I'll attract you with barbecue and sit down with you on a good podcast.
But big fan of Canonical.
I mean, in every...
capitalistic nature, there's a moat to protect.
And I get that, right?
And there's business to be done.
I get that too.
Sometimes it feels like a rug pull in the open source world and sometimes just business.
And that's okay too.
That's why we have licenses.
That's what defines the line, but doesn't define what it is.
It defines the line of open source.
There are particular licenses that define the line of open source.
And there's some lines that get crossed and it's now that source available and there's some lines that don't get crossed and hey, that's truly what we call open source as we know it, which is fine.
But big fan.
I just mentioned Incas because it's cool.
I don't even know why I brought it up in the first place.
Totally cool.
It got us to the shuttle world plug, which is worth it.
Yeah, for sure, for sure, for sure.
Well, in closing here, Harun, what's left unsaid?
What did I not ask you that you're like, gosh, you know what, Adam?
How do we not name drop this or mention this?
We've got all the URLs.
We'll scoop them up and put them in the show notes, of course.
Anything here in closing that we can say and make sure we get covered?
No, I think that's it.
Have people check out canary.tools, canary.love, canarytokens.org.
And yeah, if they have questions, hit us up on Twitter X or on Mastodon and we'll happily hit them back.
But yeah, thanks for having me on again.
It's always cool.
What is your Twitter handle?
Oh, here he is.
Canary.
Yeah.
So at things T H I N K S T Canary.
That's the one.
I'll put that in the show notes y'all.
Don't you worry about that.
Thinks Canary on X Twix, call it what you want.
And then Harun mirror, his full name, put that in the show notes as well.
Follow Harun.
This is cool stuff.
And thank you so much for coming back on.
Thank you for just sharing the, sharing the depths, you know, being, being so focused on creating cool tooling.
And not just a fat pocket of cash, but, you know, employing cool people, doing cool stuff, putting it out there and being so willing to share.
Really appreciate that.
Thank you.
Thanks, man.
Well, friends, thank you for tuning into the pod.
It was awesome having Harumi back.
One of our favorite people around here at Changelog.
Fingst, a very cool company, 50 people, $22.5 million in annual recurring revenue.
No price increases, all inbound sales, and they're doing cool stuff.
That's got to be the coolest story ever.
Honestly, and seriously, I would love to just do nothing but play with their tech, the breadcrumbs, the canary tokens, and it's open source.
All right.
Big thank you to our friends over at Buildkite.
A big thank you to our friends over at WorkOS.
And of course, a big, big thank you to our friends and our partners at Fly.io and the Beat Freak in residence, Breakmaster Cylinder, bringing those beats that we love so much.
Thanks again for tuning in.
This show's done.
See you next time.
Winning.
Winning.
All right.
That is the show, Harun.
Thank you so much, man.
That was super elite.
Thank you, man.
I have an idea, actually.
Yes.
Do you have – could you spare two or three minutes more?
Yeah.
Yeah?
Okay.
Yeah.
I'm going to – this is for our Plus Plus audience.
I almost forgotten about asking you this in the main show.
Sure.
And maybe this won't go down well, but maybe it will.
How would you feel about a more capitalistic – let's just call him a reseller?
Yeah.
Distributor of things canaries.
So maybe you're not desiring to grow more.
But what if I knew the ability and I built my own company that only sold, deployed, serviced, loved your canaries?
