5 ms·
This deal isn't about security, it's about data. Google already have one of the best security teams in the industry - Project Zero [0]. They don't need Wiz's "
by majestik 2y ago
This deal isn't about security, it's about data.
Google already have one of the best security teams in the industry - Project Zero [0]. They don't need Wiz's "enterprise" expertise for security.
This deal is about DATA. Wiz, as a cybersecurity vendor, have full remote access to their customers cloud compute storage (EC2 EBS volumes, etc) in the name of "security scanning" - this is actually part of their unique selling point - "agent-less scanning" which is unlike traditional security tools that require an agent installed in the OS. Instead, Wiz is able to just clone your full data volume and scan it locally in their cloud accounts/VPC.
With this deal Google has bought a ton of confidential data from Wiz's customers without their explicit knowledge or approval, and they will use it to improve Google's AI models like Gemini and probably several other products.
A year ago Google struck a $60M/yr deal with Reddit to exclusively license their content [1] for the same reason, and that data is probably much smaller and less valuable than the data Wiz has access to from their customers, which include companies like Morgan Stanley, DocuSign, Slack, Plaid, and others. [2]
Sources:
0: https://googleprojectzero.blogspot.com https://googleprojectzero.blogspot.com
1: https://www.reuters.com/technology/reddit-ai-content-licensing-deal-with-google-sources-say-2024-02-22/ https://www.reuters.com/technology/reddit-ai-content-licensi...
2: https://www.wiz.io/customers https://www.wiz.io/customers
- breppp 2y agoSo many sources yet no source of the actually outrageous claim that Google will use this to illegally siphon customer data maybe this deal is about a company with a lot of revenue in an area google is heavily investing in: cloud security?
- diggan 2y ago> actually outrageous claim that Google will use this to illegally siphon customer data Hypothetical question as much as anything: If Google purchases a company and the data the company stores about their customers, is it illegal for them to use this data for whatever they want? Lets say it would give them an understanding of what features from AWS people tend to use the most, and they use that to improve Google Cloud, would that be illegal?
- breppp 2y agoyes, due to privacy and contract obligations as well as this is the surest way for GCP to spectacularly commit suicide
- diggan 2y agoUnless you're talking about some specific Wiz<>customer contracts, how do you know? AFAIK, there are no explicit laws forbidding that. Maybe you could share what law you think this would be breaking?
- breppp 2y agoOP mentioned training AI on customer data GDPR, CCPA, HIPAA, etc, as Google has no way of knowing which data they will train on, add to that copyright and that's just off the top of my head cloud contract obligations are also pretty clear about customer data. furthermore it would be bad engineering and security if Wiz had actual direct access to customer data, versus having their code having access to said data. That would be a huge issue in due diligence for example
- diggan 2y agoDid you skim through Wiz's Privacy Policy? They're keeping a lot of stuff that isn't "direct access to customer data" and already permitted to be sent to 3rd parties, wouldn't surprise me if you could aggregate what features are most used on AWS by collating some other sources than having actual access to customers cloud. Obviously, existing agreements would need to continue to be run properly, no question about that. But there is always plenty of other data that probably could be used by Google to gain some insights.
- breppp 2y agowhat you talked about is different and is aggregated metrics that might be legal and interesting but i highly doubt it's 30+ billion dollar interesting i imagine you can buy that data from data brokers without any legal exposure but that's only a guess
- deleted 2y ago[deleted]
- billjings 2y agoFacebook did exactly this with a VPN acquisition. They didn't break into customer data; they just mined it for usage patterns. So as a pure speculation on Goog's motives, it doesn't sound farfetched enough to call ridiculous. Competitive data is valuable, particularly if you want to strangle the youth in their cradles (or acquire them).
- breppp 2y agogoogle is not facebook, and an ad-supported consumer software is not cloud. OP talked about AI training which is a bit more than metadata also, the vpn example ended in court
- kossTKR 2y agoThousands of lawsuits coming up? How are any of the mentioned companies okay with their highly confidential data being scanned by AI?
- kccqzy 2y agoProject Zero and Wiz and have very little in common. It's wrong to bring these two up together as if they are comparable. Project Zero focuses on discovering and analysis of new (including zero-day) vulnerabilities. I do not believe Wiz uncovers new vulnerabilities. The skillset of someone working on Project Zero looks very different from someone working on Wiz. The field of security is huge. It's unhelpful to lump unrelated things together.
- sofixa 2y ago> I do not believe Wiz uncovers new vulnerabilities Oh they do. https://www.wiz.io/blog/tag/research https://www.wiz.io/blog/tag/research A few fun ones are the multiple cross-tenant security exploits they found in Azure (which is why, among the tons of other reasons, Azure is just the worst possible choice for a cloud vendor from the big 3 - their security is a joke, and none of the vulnerabilities below should have passed even a cursory security review, but they did, which means the whole org doesn't take security seriously. Add in the fact that it's slow as hell, and has the UX worthy of an Enterprise vendor, the only reason to choose it is because you're getting a good deal on the golf course for it): https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration https://www.wiz.io/blog/azure-active-directory-bing-misconfi... https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-o... https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution https://www.wiz.io/blog/secret-agent-exposes-azure-customers... https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-azure-customers-databases https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-a...
- nolist_policy 2y agoGoogle has the best security. But it is hard to market real security (as oposed to snake-oil), so maybe this acquisition will help.
- johnisgood 2y ago> Google has the best security. Care to elaborate?
- nolist_policy 2y agoGoogle was owned pretty hard in 2009 (Operation Aurora). Following that they put security front and center in a way that few other vendors do. You can read my praise of ChromeOS here: https://news.ycombinator.com/item?id=41178525 https://news.ycombinator.com/item?id=41178525 To add a few, Chrome was the first browser to introduce process isolation: Every browser tab, every site (second-level domain) and every iframe runs in its own sandboxed process. With that it's the only end-user software (alongside the other browsers) that actually is secure against Spectre and Meltdown. Operating systems only protect against Specre/Meltdown leaks between processes. Google invented Certificate Transparency and Chrome enforces CT since years. Firefox added CT enforcement only a few days ago. CT solves the following: For example, if a rouge Chinese Certificate Authority decides to issue a cert for google.com to the Chinese government for Man-in-the-Middle attacks, CT blows their coverand makes it known to everyone that the CA issued a fraudlent cert.
- marcus0x62 2y agoGoogle isn’t buying Wiz for “security expertise”, they’re buying Wiz for a security product, in a growth area, that customers absolutely love. You’ve provided no evidence for the conspiracy theory that google is buying Wiz to siphon up a bunch of data, and if you’re going to link to Wiz, maybe link to their public list of security certifications, many of which prohibit the type of data harvesting you are suggesting. https://trust.wiz.io/ https://trust.wiz.io/
- tasuki 2y ago"Trust" screams insecurity. Security is in the direction of trustless rather than requiring trust. Do you trust companies which say front and center "you can trust us"? Wiz is a "security product"? Security isn't something you can buy and bolt on to your systems as an afterthought. It doesn't work like that!
- marcus0x62 2y agoI’m honestly not sure what your point, if any, is.
- zifpanachr23 2y agoThat the security software industry is kind of full of shit sometimes is I think what they were getting at.
- marcus0x62 2y agoBased on the exceptional level of ignorance and outright delusion in this thread, I'd rather not speculate. Easily 1/3 of the discussion is mired in conspiracy theories about Israel, and another 10 - 20% are people who's comments can be boiled down to "you know, I've never heard of this product/company/industry before, but, by God, the world needs to hear my hot take."
- tasuki 1y agoYes. You put it more eloquently.
- reliabilityguy 2y ago> They don't need Wiz's "enterprise" expertise for security. Yes, because exploit discovery is exactly what enterprise security is.
- laweijfmvo 2y agoI find it hard to believe (or maybe I don’t want to believe) that this could ever happen? Even if Wiz has T&C’s that allow full access to clients’ data, and even if the T&C allow some sort of “use” of that data that includes training an LLM, surely you can’t release an AI trained on private information to the public? You can’t have Gemini spitting out internal/private/confidential information? Am I just naive?
- bilater 2y agona you're right this would be a dumb move with a huge blow back
- nerdponx 2y agoIt's only dumb if they get caught doing it. If they do it once and keep it quiet and then someone finds out 2 years later, it's going to be a footnote in history.
- Izikiel43 2y agoI'm guessing you would be the same guy who wouldn't torrent millions of books and copyrighted works to train your LLM. Zuck can afford not to care about that pesky detail You are not naive, you are not considering that at certain scales, your concerns are the cost of doing business.
- Nimitz14 2y agoNot the same thing at all. Corporations care about their data a lot and would cancel deals over this. Noone cares if some authors get upset, they have no leverage. Disappointing how people will make confident statements while being so clearly clueless.
- dvrj101 2y ago> Corporations care about their data a lot and would cancel deals over this. Since you have mentioned "a lot" share few examples, pls.
- danielmarkbruce 2y agoThis is an incredibly stupid take on the deal.
- petargyurov 2y agoThis is an incredibly useless comment [0] At least say why you think so and contribute to the conversation a bit. [0] https://news.ycombinator.com/newsguidelines.html#comments https://news.ycombinator.com/newsguidelines.html#comments
- danielmarkbruce 2y agoThe comment effectively says "wake up to yourself, this nonsense isn't welcome". Some things are self evidently stupid, cynical and/or disingenuous to anyone with a modicum of intelligence and a cursory understanding of the field. Use your hall monitoring energy to add value. The type of post I call out here reduces the value of the forum.
- deleted 2y ago[deleted]
- HDThoreaun 2y agotheres no need to wrestle with pigs
- panarky 2y agoThe top three topics of batshit conspiracy theory supported by precisely zero actual evidence: 1) Hidden cabals colluding in secret to control world events. 2) Extraterrestrial beings live among us secretly controlling world events. 3) Google illegally steals private data to secretly control world events.
- thefourthchime 2y agoThis theory of yours is a conspiracy. Google would never start training off of confidential corporate information without authorization. The legal team would never allow it. And if they ever got caught, it would be a complete disaster for them.
- krembo 2y ago[flagged]
- czk 2y agoUsing private data to train a public LLM seems like a huge liability that Google's legal team would never approve. I could see them using the data for all sorts of kinds of analytics though. I heard Google deals in those a lot.
- qwertox 2y agoProject Zero is about finding security issues, not about developing products to increase security.
- TZubiri 2y agoThat doesn't sound very secure at all
- deleted 2y ago[deleted]
- eranation 2y agoI believe you are right in the direction, but wrong on the details. Yes they will now have tons of otherwise inaccessible data about how Wiz customer use GCP’s competitors (AWS/Azure), eg what workloads, how much they pay, how many EC2 / EKS / ECS / RDS / S3 / SageMaker are actually used and how much they pay. This is by itself highly valuable financial information, that any company would love to have about their direct competition. I highly doubt Google or Wiz have a legal avenue that allows them to use customer data beyond fulfilling their product needs. Products like Wiz (voluntarily) go through security audits and certifications, from SOC2 type 2 to FedRamp. Also enterprise customers actually do read T&C (their legal team does at least) and having terms and conditions that allow you to train models on customer data without their consent is not going to fly under the radar for long.