# Agentic Software Security: Platform Shifts and Verification

**Podcast:** HMZE
**Published:** 2026-08-13

## Transcript

You don't know each other?
We don't.
I mean, I know Andrey's name because he's, at least when I was at Scout, he was a living legend still and there was still people talking about Andrey.
Okay, now we have this on record.
Welcome to another episode of our new season of Beyond Vibe Coding, partnering with Impala Search.
The go-to tech and executive search agency in Germany.
In this podcast, we explore the transformational change in software engineering and knowledge work in general.
Ich bin Sebastian Heidemeyer zu Erpen, CTO at North IHO.
Und ich bin Andrei, CTPO at Trusted Shops.
Great to have you back.
Heute ist es Zeit für ein Tech Talk.
Wir sind wirklich forward to that.
Together mit unserem Gast, wir beginnen mit der Sicherheit zu beschäftigen.
Ja, Jan Brennenstuhl ist ein former Freund von mir und hat sich in Sicherheit für die meisten Teil der Arbeit.
Er hat seine Gedanken über die Sicherheit und die Agentik Software Development Lifecycle über seine eigene Setup.
Sehr interessant, aber auch als Sie will hören, ich muss den Episode halbwegs durchführen.
Aber ich hoffe, Sie noch genießen.
Willkommen Jan, zu unserem Episode.
Ich bin super froh, dass Sie.
Wir haben zusammengearbeitet, am Immobilien Scout.
Nicht super close, aber wir kennen uns.
I also learned that you knew Andre before.
And super interesting topic also for our new changing software development life cycles right in the agentic world.
Security will be the topic today.
Super interesting.
But before we jump into the topic, please introduce yourself to our listeners.
Thanks for having me and for the invitation.
It's my first podcast appearance, so I'm super keen to try this out with you together and learn from you also how this works.
My name is Jan.
I was born and raised in Berlin in the east part of the city and I'm still living there.
I'm born and still living in Freedassiner.
I have a wife and a two-year-old daughter.
I'm a software engineer by heart, I would say.
Und ich arbeite jetzt an der Intersection von Application Security, Platform Infrastructure, Identity, diese kinder, die trinite der Platform-Capabilität, ich würde sagen.
In den letzten Jahren, ich war mainly in verschiedene Parten von E-Commerce Funnel.
Aber es gab immer diese ...
So, yeah, let's get this started.
Let's figure out what changes in Ja, sure.
I would say basically 12 to 20 hours a day the agents are running and doing things.
Das ist mein realityer Moment, weil sie eigentlich arbeiten, oder sie arbeiten auch oft, oder auch immer an den weekendsen, und ich preparee Sachen für die nächsten Woche, das ich dann auf Mondays reviewiere.
Wenn du deine letzte Liste aus dem Code wrote?
Bei Hand, du meinst?
Ja, so wirklich classic, right?
So the way we did this back in the days.
I updated a configuration file earlier today by hand, and I even committed by hand.
So, you know, that was...
It's not that it's completely vanished, basically.
These things are still there, and for super narrow changes, I still tend to open some editor and just do it myself.
Die meisten der Parten sind größer.
Ich habe meine verschiedenen Flets der Local Agenten mit dem Rund.
Ich habe mit Cloud Code gegründet, Ende der letzten Jahr.
Das ist wie es all angefangen hat für mich.
Ich denke, dass Sonnet und Opus auf dem Reise war, das war die kickstart.
Ich habe immer diese Perspektive.
Das wird nicht mehr fly.
Für die Predicte später, ich sage nicht, dass ich meine Predicte nicht mehr so lange.
Ich habe es gelernt, aber dann wirklich schnell, dass es eigentlich nicht mehr so useful ist.
Und jetzt, ich würde sogar sagen, dass es nicht mehr so wichtig ist, sondern das ist das Wichtigste.
Das ist etwas ich über die letzten Zeit.
Ich benutze Pi und OhMyPi für die Entwicklung.
Ich bin einfach zurück und zurück, weil ich es gibt, dass ich es mit einem anderen Teilen bin und andere nicht so glücklich mit.
Curious about that because I also tried OhMyPie.
There was something in my setup that didn't work out of the box and then I scrapped it and went back to Pi.
But it read like OhMyPie is like an improved version of Pi with some additional batteries included.
But what are the pros and cons from your perspective?
I mean, I would say it's closer to Claude in the sense of that it's easier for beginners to onboard because it brings you all the nifty tuning that you want to have.
Aber die Problem mit Cloud ist, dass die Katalog der Features so groß ist, dass man gar nicht mehr hat.
Und das ist auch für OmaPy.
Es ist eigentlich eher opiniös.
Ich tente zu selecten, sehr viele Extensions für MyPy, die es nahezu, in der Sinne von den Features, die ich benutze.
OhMyPie.
Und dann, ich habe keine Ahnung, die resten.
Das ist die Unterschiede für mich.
Für Pi, ich habe eine Art von Sandbox setup, das nicht immer noch immer, aber auch immer noch.
Und für OhMyPie, ich benutze es als eine Art von Sandboxen, die ich mein infrastructure-Sandboxen.
Das ist interessant.
So, sind Sie da verschiedene Features?
Oder ist es nur eine Serie-Sandbox-Environz und die andere ist Play or Experimental environment?
Yes and no.
I don't know.
An example from today, basically making UI tests work, enabling my Pi to run my sandboxed seatbelted Pi to run UI tests using a Google Chrome browser is not something I could easily get working with my Pi setup.
So I basically didn't use the minus minus no Sandbox flag and restarted my Pi, but I basically switched over to my Pi and just did what I wanted to do over there because I know, okay, there's no, basically there's no serious Sandbox.
It just does this one thing and then I basically switch back.
That's the thing.
And as I said, they have almost feature parity, I would say, on my machine.
So that's what I do.
There's no real reason.
Ich glaube, es ist kein guter Grund für das, es ist historisch geworden.
Und ich glaube, noch nicht auf die Richtung ich möchte.
Ich habe, wie ich gesagt, Claude in der Zeit, ich habe OpenCode versucht, und ich bin jetzt mit Pi.
Ich bin jetzt am Moment, ich mag es die meisten, zu ehrlich sein.
Aber es kommt mit all dieser Überhandschicht.
Du musst deine eigene Sachen zu arbeiten, um zu effizient und effektivieren.
Und dann kommt alle die nifte Details von extensionen, die compatriotischen Sachen zu tun.
Das Ecosystem ist so großartig, dass es wirklich schwer zu figurenter was, was du sollst installieren und was extensions du soll.
Das ist das, was wir brauchen.
Wenn du ein Verlap hast, wenn du ein Verlap hast, wenn du ein Verlap hast, für ein Tool invocations oder so, dann hast du multiple Extensions gemacht.
Oder auch andere Sachen.
Und da gibt es auch incompatibilities.
Und das ist, wenn du jemanden musst, und da ist ein viel zu versuchen, ein bisschen cumbersome.
Aber dann OhMyPie schinesst, weil es hier eine fully-fledgede Sache gibt, das funktioniert.
Half of the features you don't need in your daily life.
One more question to that.
Are you using any skill framework or spec-driven framework to do your work?
So now we discussed the harness or partly the harness.
Another aspect of that would be also then skills.
Is there anything you use in that regard?
A large...
The project that I was involved with over the last half a year is heavily leveraging Speckit.
So there's a lot of, or I still try out a lot of things.
I have on my list to try out beats from Yegi for ticketing and these kind of things.
It's like there are so many tools that are published, you know this better than me, I guess, that it's really hard to fight the time to try out all the things.
Depending on the size of the project, I would suggest to use something like Specket or any Speck-driven framework.
At least for our setup, in our setup, it turned out to be rather useful in the long run.
It's super cumbersome to set it all up, you know, and, you know, constitution here and basically all these guiding principles defined over there.
Leave it to the agent to define all of this.
You don't get anything.
You have to put in some manual effort to do all of this and then it will help out in the long run.
But kick-starting, this is really hard.
Not hard, but take some effort.
And it's not the nice part.
Not this dopamine-driven agent interaction.
It's basically really writing text on how you expect things to happen.
Yeah, so I was wondering, and I asked, Specifically regarding that point, because as you just mentioned, these spec-driven frameworks tend to be a bit heavy in the use.
At least front-loaded, yeah.
Yeah, front-loaded.
I think that is a good example.
It nails it.
I think there are also a couple of more lightweight skill frameworks out there, which help you producing Better without this heaviness.
At least they promised us.
What are you referring to?
The Matt Pocock skills?
Yeah, the grill with dogs.
I think that is going in that direction.
It's at least also on my list.
I heard a lot positive from friends and network.
I was just curious now where we have the chance to...
To talk to a real engineer, Jan, you need to know, and usually we talk to leaders and managers, right?
So they also claim that they are coding, but they're not coding for money, right?
So they're doing this for fun and they're not shipping to production.
So now we have the chance to talk to a real engineer.
That's why the questions.
Yeah, at least from my perspective, I'm not involved in too many greenfield projects.
So, you know, this project I refer to, like, Was das eine rare, wenn wir etwas von scratch gebaut haben, wo wir etwas von scratch gebaut haben, und es hat, von unserer Perspektive, eine ganz einfaches Komplett-Sense gemacht, oder eine Art von Spacket-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense-Sense Code-wise, they tend to get out of hand.
Lines of code-wise, they tend to get out of hand nowadays.
And you add so many features in no time, basically.
And it's good to have these guardrails somehow set up through the specifications and also enable the agent to verify that future changes don't violate any stuff that you did in the past already, these kind of things.
But the larger point of...
Well, the larger share of the work I do is basically smaller extensions to existing software, I would say.
Smaller and larger extensions.
And often, you know, these are code bases that if you're lucky, they already carry some agents in the observators.
But often, you know, that's historically grown code bases.
And then I don't need the overhead of, you know, plan like...
Fully planing out or specifying a new capability when it changes basically.
And you know, five file changes for stuff like this.
So it's like, as much as I would love to try it out and play around, the opportunities are just not there to try all the available tools and 50 billion new projects every week basically.
That's the thing.
Unfortunately, also not for an engineer.
Yeah, unfortunately.
One final question.
You mentioned in this section, at least, you mentioned that you're running your Pi in a sandbox.
Can you describe the sandbox a little bit?
I use a Pi extension.
It's called Pi Landstrip.
Landstrip is basically...
Supporting multiple OSs, for Mac, it uses Seedbelt under the hood to wrap the process in the OS sandbox thing.
I also like there's other sandbox, of course, it's a huge topic.
We come to this potentially later also.
There are so many sandbox solutions that also popped up.
Ich denke, es gibt ein paar mehr popularen, die sind reasonably gut distributed.
So es gibt eine höhere Chance, dass sie das sie tun, was sie zu tun.
Aber ich denke, niemand hat eine wirklich gute Lösung.
Es sind basically die Enginheer, wie ich, die versuchen, aus verschiedenen Dingen zu tun.
Und ich glaube, ich benutze die Spirekstension.
Das ist, wenn Pi startet, das in Seedbelt ist.
Das ist bereits besser als die meisten Sachen, die ich in der Vergangenheit hatte mit anderen Toolen hatte.
Es ist so spannend, dass du das die Hard-Way lernen.
So die erste Zeit, wenn du das mal in der Agenten bist, wirst du etwas mehr machen.
Aber es ist eigentlich alles so ein Problem mit Spectrum Development.
Es ist so front-loaded, um es zu setzen.
As I said, it's also so hard.
You just want to run, you know, have the agent the ability to, you know, understand why certain tests are failing and you cannot do it because it's just not allowing the agent to spawn up a browser and run the UI test.
And it's so hard to configure, right?
And then you occasionally run into this, oh, I don't know, I cannot write into my...
M2 Maven files, wo I cannot read from something.
Every time you interact with this until you poke too many holes into it, then it's not useful anymore.
So it's still so early, I think, the tooling as well, like in early stages, that there's a lot of usability missing and there's still too much friction, I think.
für diese Dinge zu beherentwickeln.
Das ist mein eigenes Erfahrung mit dem, das bei mir, jemanden interessiert.
Und ich würde sagen, 80% der Fall ist nicht, dass sie nicht interessiert sind.
Und es ist eine Grunde warum die größere Harnesses nicht so, wie die Harnesses nicht so, wie die Harnesses nicht so, wie die Harnesses nicht so.
So it basically affects your experience hard and you want to have people use this stuff and not push them away by having too strict rules on what the agent can do and whatnot.
But of course in an enterprise environment, it's somehow important to find some guidance or rules or whatever tooling solutions for these things.
Because the next prompt injection and whatnot is just around the corner, I would say.
Absolutely.
Yeah.
I mean, in these cases, you hopefully have the guardrails in place already in terms of accesses.
So what systems can a person access, right?
So what accesses or how are these systems protected?
So you have some guardrails already, but still you want to ensure that also on the machine of the developer.
Ja, nichts horrendous kann passieren.
Und das ist eigentlich ein sehr guter Weg in die Mainz-Section, right, von diesem Podcast.
So, vielleicht zu starten, auf kurz.
So, ein paar Wochen später, du postet auf LinkedIn, wir putt in den Show Notes, über ein talk, ich glaube, du held an der HTW in Berlin, es ist die Universität der Applied Sciences, über die your perspective on the changing security environment in the agentic software development lifecycle, right?
So that's how I would phrase it as a headline.
Maybe you would phrase it differently.
But that caught my attention and I thought like, well, that's a great topic because security actually has not been a topic very much at this podcast actually.
And it's also something like you mentioned, right?
Most people just want to Ich habe es sehr gut, um es zu erreichen.
Ich dachte, das ist ein tolles Thema für uns.
Es wäre toll, wenn Sie kurz kurz vorstellen oder summarize Ihre Gedanken über die Sicherheit und dann können wir uns in die Diskussion.
Also, bei HTW, ich war als ein Privatperson.
Ich war basically beinahe.
Ich habe ein Universum an einem Staff-Member, der sich um die Cyber-Security-Course über den Weg zu haben.
Und das Trigger war ein Blogpost, die ich über die Zukunft der Applikation Security und die Leute in der Agenting-Erreinbe.
Ich würde sagen, dass die AI und all die Tools, die mit uns und all die Veränderungen, die wir in unserer Industrie sehen, sind komplett disruptiv.
Und sie sind natürlich auch nicht stoppings in front of die Information Security Department.
Ich habe eigentlich erwartet, dass da auch disruptions werden.
Und ich habe jetzt einen Gedanken gemacht.
Und dann haben sie mich, weil sie mich, Für die nächsten Generation ist es super interessant, wie ihre Leben werden verändert.
Imagine, dass jetzt ein Studierende, die mit AI ist, und die AI ist nicht mit der Arbeit.
Sie haben nicht mit der Universität, die mit der Arbeit mit der Arbeit mit der Arbeit.
Wie ist die Arbeit der Fokus?
Was ist die Sicherheit in der Zukunft?
Wenn large parts sind, die agents und larger Models sind?
So, ich habe das gehört.
Was ist dein Geist hier?
Was sind deine Zeithes?
Wenn es zu Sicherheit ist, die Sicherheit in der Jahre von ...
Agentic Engineering.
Engineering, I would say, becomes more and more important.
And I think what started already years ago, or what we did in the last years already in this field of our profession, is now even more important.
So I think the agents just up the pace of how quick we have to adapt.
So what happened already in the last years is that application security, Es ist nicht mehr so viel über die Technik oder die Technik oder die Policies, sondern es ist mehr über die Tools, die integriert werden, und mit den Engenern mit den Engenern.
Und ich denke, das ist einfach etwas, dass wir uns zu schnellen, weil die Agents einfach uns zu tun haben.
Mit Agents zu tun, dass es sich jetzt ein Ding zu tun hat, ich denke, was es sich eigentlich bei der Pace in der Implementation ist.
So es geht nicht wirklich, oder sie geht nicht über die Knowledge-Work, ich würde sagen.
Es ist eher die actualen Implementation.
At least, sie haben nicht das yet gemacht.
Es geht nur um die Implementation.
So what we see is a huge increase in lines of code and commits and GitHub suffers from all of this and there's so many resources, blah, blah, blah.
What this means is that the classic approach in application security is you have some gate somewhere, code is scanned eventually and then someone is reasoning about it and there's a ticket spawned and then there's someone informed and people are like...
There's a feedback loop in GitHub or stuff like this, but it's rather decoupled from the actual doing and runs on some CI, CD pipeline or stuff like this.
And then, yeah, if it's part of the deployment or it runs against deployed stuff, and then there's some tickets.
With agents, that's just not good enough anymore.
It wasn't good enough in the past, I would say, but there, basically, the pace was human-driven and it didn't matter so much.
Jetzt, wir sind jetzt unter Druck, weil die Code ist so schnell, dass man nicht weiterfixen, was schon schon ausdaten ist.
Und so haben wir eine Backlog-Findungen, die sich auf und auf und aufkommt.
Und so würde ich sagen, Detection ist nicht mehr ein Problem.
Es ist eigentlich die Mitigation, die es die eigentliche Sache ist.
Und wir müssen die Situation auf diesem Grund verbessern.
I absolutely agree on both sides.
I think there's a huge acceleration on the code generation side.
And I think this is just natural that it forces us to accelerate on the protection side, so to say.
I'm wondering, and you probably have some thoughts on this as well, is like, how do you tackle that?
Is that more tooling, more people, more processes?
Is that a harness?
So how to approach that challenge?
Ich habe es schon mal gehört, dass die Lösung ist, dass es sich auf die Sicherheit alles zu verändern.
Also, was das bedeutet?
Ja, das ist ja, viele Leute wissen, dass das auch was wir Menschen über die letzten Jahre, glaube ich.
Be es SRE, Operations oder auch Security, wir einfach alles auf die Seite, und dann wird alles gut aus, weil jetzt diese Themen sind alle responsabilität.
So, alle sind accountable für das.
What ShiftLeft told us is who owns security.
And I think what the next thing is to understand that we also need to shift in other directions.
What I mean here is especially down into platform and standardization to define or to set the environment for what security-related decisions teams should actually take.
So if we ShiftLeft, we should also ShiftDown so that they have left.
Less burden and less decisions to make to enable them or to avoid that the wrong decisions are being taken.
And wrong here is a bit overstated.
It's like it doesn't really matter, I think, what decisions are being taken as long as it's standardized across the whole fleet.
And the idea is basically agents will replicate the good but also the bad parts in our ecosystem and the code we write.
And the problem is...
The more bad parts you have, the more anti-patterns you have in your landscape, the more you will see these also being taken over or adopted by agents in their solution-finding process and their implementations.
And this is something that you want to avoid.
And this is not only true for security, but for a lot of platform topics.
But of course, security is part of this fundamental infrastructural setting.
I absolutely also here agree.
The point is that I think shift left at the end means accountability, not necessarily responsibility.
I think it can be solved below.
I think you said shift down.
And I think what we also have seen in other areas, and maybe this is then a good comparison, so to say.
ist, dass man es auf einen Schaden auf einem Schaden auf einem Schaden, welches die Unternehmen an den Plattformen nennt.
So, wie es in der Bedingung, es gibt es für alle, um ein bestimmtes Qualität zu erreichen.
Wenn ich mich noch über die Sicherheit habe, also mit der Comparation von der Cloud, ich denke, die Cloud-Topic ist einfacher, für mich zu grasp, als ich mit Sicherheit habe.
Ich denke, die Sicherheit ist ein...
Yes, cloud is also a topic for itself, but security is beyond.
So ensuring you take the right decisions or the platform takes the right decisions secures you.
I think it's a good approach because it takes the human.
So the human is not in the loop, but it's on the loop, right?
I think that's powerful.
I would agree.
Ich würde sagen.
Ich liebe die Wörterung von den Wörtern, die man in jeder newspaper verwendet hat.
Aber zu antworten, wie zu antworten, das ist eine Sache.
So, Plattform-Sanitization, für viele Dinge.
Ist es wirklich notwendig, dass Teams eine custom-deployment-Pipelite haben?
No.
Ist es wirklich notwendig, dass Teams eine bestimmte Beziehung über die Basel-Image haben?
Ist es wirklich notwendig?
Das geht in so vielen Themen.
Und für viele dieser Fragen, die Antwort ist nicht wirklich.
Und es gibt auch selbe Standards.
Und die Idee hier ist, wenn es die easiesten Lösung available ist, sollte es auch die most secureen Lösung sein.
Für Menschen und Menschen ist es die gleiche.
Die Parten ist es nicht so gut.
Wenn du etwas custom machst, musst du Zeit und Zeit.
Und etwas custom hier bedeutet, dass es nicht so gut ist, oder nicht so gut.
Und das ist die Idee.
Und auf der anderen Seite, ich also consider Agent Harnesses zu be Plattform, basically.
It's basically tooling, where we, I believe, need to inject security and other topics into.
It has to be part of the loops of the agent.
They need to be able to verify everything they do.
It shouldn't be now some asynchronous process running somewhere at some point in CI-CD or in production at one point.
It should be basically while doing, should it be...
Enabling the agents to run to the right direction.
And here we talked about having access to scanning tooling locally on the developer machines where the agents are running that can feed back into the loop.
Then the right skills, the right knowledge, especially in larger corporations.
I think there's a lot of...
Corporate enterprise knowledge, architectures, best practices, all these things need to be available to the agent to really run into the right direction.
Just to close this, for application security engineers, this then basically means to become real engineers because it's not about defining what I just said.
The harness needs to be more secure and it should take into consideration stuff from some random CII tool, but building this thing.
It's like building this integration and providing it to the whole population of engineers that are available.
That's the idea.
I'm wondering if such security harness is to some degree, at least for...
than the majority of the companies, so not enterprises, but mid-sized companies, available out of the box.
Do you know tools or harnesses doing that?
Injecting the right knowledge into harnesses is a problem that a lot of people try to solve at the moment.
There's all kinds of approaches and there's people who put MCPs in front of their company wikis and try to make this knowledge available, which is then hopefully not outdated.
These kind of things.
Security ist eine Partie, right?
In der Ende ist es um die Corporate Knowledge und Guidance zu den Agenten, um ihre eigene Loops zu tun.
Ich bin nicht aware, ich meine, es ist specialized Tooling, natürlich.
Es gibt Skill Framework, Skill Sets, das die Agenten in die ...
Red Teamers or Blue Teamers, and you know, that you can then use to, I don't know, analyze code bases or setups.
There is thread modeling skills, there is all kinds of things in this regard.
But if you really talk about software engineering, like building products, building code, you basically want to have this as not, you know, it's not a security harness, it's basically just an awareness kind of knowledge thing and backed by tooling that hopefully can find the right things.
Ja, es ist eher der Mindset und wie du das benutzt, eher als die bestimmte Tool-Innen.
Also, given die Faktor, die Bandwidth-Innen ist super broad, right?
Du musst, was wir sprechen über, was die Sicherheit ist, was wir sprechen.
Was ist eigentlich die Sicherheit, die wir wollen, eher als die Anwendung, in deinem Harness zu sprechen?
Ja, gott.
Und in der Endeffektion ist es um die Lube zu spätigen.
Wir wollen die Security Findings auf einen Moment in der SCLC haben.
Wir wollen sie schnell wie möglich.
Das ist die gleiche Lidt-Shift-Left-Idea.
Und die Liedt-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left-Left- Das ist, von meinem Perspektive, das ist die einzige, wie du kannst du das immer-reinfreigend backlog von Findenkontakt hast, weil du diese Flüte von Lines-Code aufhörstst.
Ja, given die Faktung, dass jetzt ein paar Sachen in der Loop, oder eigentlich alles in der Loop, ist owned by die Agents, hat infinite Kapazität.
really shifting left, left, left, left, left.
I think it needs to be overall more left than right.
So earlier is better than later.
But in a world where people are really, so human is really just on the loop and reviewing certain really critical stuff, I think you end up with a loop which is like, so the only limitation is your credit card, so to say.
Wenn du genug capacity hast, oder genug budget, so zu sagen, kann ich ein Flieter von Agents sein, die nicht mehr haben.
Es ist, wie bei der Definition, left.
Aber du bist recht, ich denke, es ist auch ein Waste von Kapazität.
So die früher, die besser.
Da, du bist recht.
Ja, ich meine, von einem Remediation-Porten-Vertigsten, natürlich.
Agents are the cause of a lot of problems at the moment, but these are not unique to agents.
It's just the agents up the pace.
The background was increasing already like two years ago or three years ago, but it was increasing at a human pace.
And now you have all this fluctuation and also new solutions being identified by agents and implemented by agents that the human never thought about.
And your infrastructure gets more and more heterogeneous.
Und das ist ein sehr guter Weg.
Und natürlich, die Lösung ist auch mit der Agents.
Natürlich ist es auch mit der Agents zu counter.
Aber es ist eine Reaktive-Masur dann.
So, du hast eine Finding, dann späst du deine Agents, du hast deine Lärbescale Mitigation Campaigns, die Auto-update, wenn die Agent Auto-updates all die...
Poor question, you have another agent that reviews all of this and then you have someone else taking over basically the operational part of deploying these things.
You know, that's the reality that some companies live already in.
But it's still better to even stop defining from being discoverable in production because it shouldn't exist in the first place.
Absolutely, absolutely.
There I think we don't disagree.
At the end, it's a bit like the cat and mouse game, right?
Ja, ja.
To some degree, it's always reactive.
It's just a question how fast you are in reacting.
And I think you have a pretty good point on mitigation needs to be left, left, left, left.
So actually the entire application security topic needs to be left, left, left to really ensure the...
Mitigation happens in a fast-paced manner.
Ja, exactly.
And this other dimension is down, right?
So basically, the agent should never come to a situation where they implement, I don't know, some custom authentication method somewhere.
Like it should not ever attempt to do it.
It should be provided with, you know, this is the way our authentication components work.
This is how you would interact with it.
Do it.
You know, these kind of things.
This, you know, crosses out a large...
Das ist ein Problem, von dem Beginn.
Es ist einfach ein Frage, wie es jetzt zu tun.
Wie können wir das jetzt nicht so gut bekommen, das ist so gut in viele Leute's heads?
Oder in Situationen, wo wir nicht die Standardization in der Platform haben, es ist wirklich schwer zu counteren.
Und ich denke, in der Endeffektions mit starken Engineering, und starken Engineering hier, meaning Sie sind die Möglichkeit, dass das die Agenten sicher ist, dass es sicher und sicher ist, und die richtigen Dinge.
Ja.
Makes sense.
And you actually also have a good point here.
Application security is not just about really technical aspects.
It's also about business aspects, business requirements, as you just pointed out, authentication, right?
So it's more a business requirement rather than a technical aspect.
So it translates into technical aspects.
But I think really building the harness end-to-end on all aspects, on all dimensions, so to say, is I think also a good takeaway here.
Ja, in den ersten Tagen, ich meine, die ersten Tage sind nicht zu weit weg, aber ich habe immer noch immer nach dem größeren Modell und der größeren Modell.
Und was ich habe über die letzten Monate gelernt, ist, dass die Faktor ist, dass die Harness Capablässigkeit ist.
So, du kannst du vieles auf die Dinge, die die Modell ...
der Modell wird in eine gewisse Schwierbarung und versuchen, Dinge zu schaffen, die man nie immer erwartet hat.
Und das heißt, dass das Wichtigste, die Wichtigste, die Wichtigste, die Wichtigste, die Agenten, die Wichtigste, die Wichtigste, die Wichtigste, und die Wichtigste.
Und so, ich denke, das ganze Hype über die Wichtigste, die Wichtigste, die Wichtigste, die Wichtigste, die Wichtigste, die Wichtigste, die Wichtigste, Es ist nicht notwendig, wenn du das ein properly configuriert und ein Capabell Harness konzentriert hast.
Ja, ich denke, es ist auch mein Meinung.
So Harness ist mehr wichtig als den Modell.
Es ist immer immer sehr, sehr impressionant zu sehen, die Entwicklung.
Aber ich denke, es geht nicht um...
Productivity that much as the earlier models, so the breakthrough, so NetOpus, I think it was really like a step up.
Nowadays, for sure it's improvement, especially in the benchmarks, but it doesn't translate so much into better results, higher productivity, and so on and so on.
Nevertheless, since I have you here now on the show, security experts, I need to ask that question.
Have you been scared?
der Fable 5, wenn es released ist, haben Sie sich nicht bemerkt?
Ich persönlich bin nicht bemerkt, nein.
Ich bin nicht bemerkt, weil die neue Toolung existiert.
Ich denke, es ist immer eine Rolle, wie man es benutzt.
Ich meine, es ist ein bestimmtes...
Asymmetry, you saw this in the recent Hugging Face incident where they couldn't analyze what actually happened using the model setup that they had because the model just said, no, I won't analyze this for you because this seems to be a threat activity and I was told not to help you.
Or I was trained not to help you.
And on the other side, we have attackers that don't have these restrictions on their models.
Es ist das Imbalanz, es ist das Asymmetrie, aber das ist auch etwas, was wir immer in Sicherheit hatten.
Es ist nichts new, es ist nur, dass die PACE ist.
Also, mit Huffington-Face, mit diesen super prominenten Incidenten, ich würde sagen, dass sie nicht inventen neue Security-Istungen haben, sie haben einfach so viele Dinge gemacht und die PACE war so hoch, dass sie so hochkonten, dass sie die Hunde also einen Menschen vielleicht beherrn können.
Aber vielleicht nicht in der Zeit-Renewer von Hours oder ein paar Tage.
Ich bin nicht scared.
Ich bin mehr scared der Imbalance, die eine Exekutive command von einem Präsidenten können.
Es ist die gleiche Idee, die in den Zeiten mit der Kryptographie hatten.
You know, where you were not allowed to export crypto knowledge from the US, these kind of things or crypto solutions.
And it just smells like a similar idea behind the scenes.
And it didn't turn out to be a good one in the first place.
But yeah, if of course a 12 year old script kiddie can now, you know, burn through their parents' credit card and use Fable to run an attack against some, I don't know, European company, of course, Es gibt mehr Anwärtsabkommen, aber ich bin nicht persönlich sicher.
Ich denke, all die Erfahrungen, all die Erfahrungen, all die Erfahrungen, die wir in der Vergangenheit hatten, sind noch immer noch immer noch immer noch immer noch immer noch immer noch.
Ich denke, das kann auch etwas scare jemanden.
Aber ich habe meine Meinung, dass es auch mehr so die Kapablieren ist, dass sie die Defense-Site mehr als die Application-Security-Site mehr als die App-Aktion-Security-Site mehr.
Es ist alles connected, ich weiß.
Aber ich habe auch gelernt von einem Security-Manager in einem meiner formeren ...
roles or companies.
They're two totally different fields, André.
So maybe also a bit of unfair question.
Good.
Looking at time, I think we wrap this up here for the meet section and for the listeners who listen more often to our episodes, they know there are two more segments to come.
One is the reality check and one is the prediction.
We already learned prediction like we should not listen to, but anyway, give it a try today.
But before that, reality check, some kinds of what the fuck moments or hot stuff.
WTF moments I have on a regular basis.
As I said, the agents are still running continuously, basically.
The WTF moments I usually have when I ask a simple question and then the agent runs and does things.
And I just wanted to have the simple answer.
Sorry.
Then you escape, escape, control C and try to interrupt.
Whatever is happening, especially if you're not in the sandbox environment and just the mayhem starts, that's usually my what the fuck moment.
And you actually also start then to question everything, right?
If you realize this is obviously wrong, this is at least my behavior or not my behavior, but it's how I feel in these moments where the result is obviously wrong.
I'm questioning the entire work of the last week.
Wenn das falsch geht, dann ist das richtig?
So, ich habe mich total zu Ihrer Meinung.
Es ist interessant, dass ich manchmal nicht verstehe, warum ich diese Dinge mache.
Es ist wirklich hart zu verstehen.
Ich frage mich eine Frage, ob mein Englisch so schlecht ist, dass es so easy zu misinterpretieren.
Oder wo ist diese Proactiveness gekommen?
Das ist nicht so explainable für mich.
Aber ich würde nicht fragen, dass es viel zu viel ist.
Und was ist die Hot Stuff, die du gerne überlebt?
Du hast auch eine lange Liste zu versuchen.
Aber was ist die Hot Stuff, die du gerne überlebt?
Ich meine, nicht so viel.
Tooling-wise, I'm still looking for better sandboxing solutions, as we spoke already.
But what I'm super interested in and where I'm super keen to do more with, if I would have the hardware, is local models.
And I'm also super keen in, you know, especially open-weighted local models.
I'm super keen to play around with these if I ever could.
Und ich bin auch interessiert, wie das sich das aufwachsen.
Denn ich meine, heute sind es immer noch auf der Konsumer Hardware, ich würde sagen.
So es wird sich um die Fläche.
Ich hoffe, dass das IPO-Präsure zwischen den großen Unternehmen und den Open-Provideren von China und anderen Bereichen, also da sind europäische Models, die jetzt alle jetzt, so ich hoffe, dass das Pressure Das bedeutet, dass wir alle unsere neuen Models auf einem neuen Token-per-second-schnitt-speed auf jeden Fall haben.
Das würde auch super machen und auch die Budgetungen auszulassen.
Ja, du musst definitiv hören, zu unseren heutigen Episode mit Stefan von ZipGate.
Sie haben einige Erfahrungen gemacht.
Es ist gut, dass es das Lokal ist, die Werkstationen Hardware zu nutzen, aber es gibt nicht gut results, oder nicht gut results, nur die limiteden Ressourcen.
Aber auch, auf mein Seite.
Sie also ran auf der B300 Nvidia, oder?
Ja.
Oder du hast eine Fallback-Solution.
Und es könnte sogar die cheaper option sein, in der langen run.
Das war die Grund, warum sie das ganze Leben starten.
Und es war sehr interessant, warum sie in der Ende des Ende für die Strecke, aber auch für die Lokal.
Deployed models rather than really WorkState solutions.
Nevertheless, I'm also looking forward to that moment when we can run that.
I think there are also a couple of open source projects to make larger models fit on smaller boxes, so to say, by just, for example, activating certain aspects.
Aber super, super interessant.
Ich denke, es wird einen impact auf die Frontiermodels.
Ich bin nicht sicher, wie.
Aber ich denke, Local AI, ich denke, wird es ein enormes Thema in 2027.
Das war bereits mein Prediktion.
Aber heute ist es nicht auf meine Prediktion, sondern es ist auf yours.
So, wenn du einen Prediktion mit uns?
I would say in the field of software engineering that verification becomes the premium engineering capability.
So if you like verification of intent, basically.
So if this is a skill that you develop as an engineer, like you look at things, you understand what is actually the things that you wanted to build and you can verify that what was built is also what you want to build.
And then you will strive, I believe.
You know, basically just know what you want to build and then verify that it was also built.
You know, I think what will vanish is people who...
That sounds bad.
What will vanish is like the need to have factory code workers, basically.
That's my...
Like, I mean, we see this already, so it's not so much of a prediction.
But I think that we will see a larger focus on...
Verification capabilities.
In the end, I think what larger orgs especially will do is that they will look into system thinkers rather than specialists, these kind of things.
And then so M-shaped engineers or whatever you want to call them.
Ich denke, es war ein guter Podcast auf das Thema, Lenni's Podcast.
Du may wissen, das.
Ich denke, es war mit jemandem von Netflix.
Das war genau das Thema.
Ich habe nicht gehört, sondern ich habe eine Summary.
Aber ich denke, es geht in die Richtung du gerade erwähnt.
Lenni's Podcast.
Ja.
I'm not so much into podcasts, I have to say, sorry.
No problem.
Occasionally I listen to this HMZE podcast.
Thanks for the advertisement.
So, before we stop here and I share Lenny's podcast with you, I think we should mention that you also write a blog.
Every now and then you post something on Engineering and Security or Application Security.
So if you want to learn more about that, you can, and this is now your turn, where can we find you?
Janbrennenstuhl.eu is my webpage.
Occasionally I post articles over there.
Have a look, share some feedback.
There's also Blue Sky and Mastodon and stuff like this linked there.
You can reach out to me if you want to discuss these topics.
If you want to discuss in person, I will be in Amsterdam in September at the AgentCon talking about agentic identity brokerage.
Yet another topic that we are looking into at the moment.
And yeah, so if you want to catch up there, then we can also catch up there.
Great.
Thanks, Jan, for having you.
It was really great to talk to an engineer again here on the show.
And yeah.
As we always say, see you soon.
Thanks for having me again and I enjoyed the talk with you guys.
Thanks.
Bye.
Bye bye.
The Beyond Vibe Coding Podcast is a project by Sebastian Heidemalze Erpen and Andre Neubauer partnering with Impala Search.
The content is created by us and our guests.
Join the discussion on LinkedIn or visit our website where we publish all episodes.
For questions and inquiries, feel free to reach out via LinkedIn.
Thank you for your time and see you in the next episode.
