Cloud Security Podcast by Google
Cloud Security Podcast by Google

Cloud Security Podcast by Google

Anton Chuvakin

Overview
Episodes

Details

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.

Recent Episodes

EP274 AI, Zero Trust and Secure by Design Walk into a Bar...
APR 27, 2026
EP274 AI, Zero Trust and Secure by Design Walk into a Bar...
Guest: Grant Dasher, ex-CISA, ex-Google, Distinguished Engineer, Google (again) Topics: Why is the "Secure-by-Design" movement gaining so much momentum now, and is it a response to the failure of "bolted-on" security, or just a natural evolution of cloud maturity? In a future Secure-by-Design world, is identity the only perimeter that actually matters anymore? Or is this a cliche? As we move toward a world of autonomous agents, how does our approach to machine identity need to change? Are we just talking about more complex Service Accounts, or do we need a fundamental shift in how we authorize "intent" What is your advice to people who want to move fast and cannot wait for Secure by Design / Default AI to be decided by consensus or IETF, NIST or OASIS committee? We love the argument that modern AI agents are effectively repeating the mistakes of 1960s payphones - mixing the data plane and the control plane. What is your rebuttal? How do we build "Agentic Security" that doesn't fall for 60-year-old traps? Customers are torn between their Zero Trust implementations and their AI adoption. Is Zero Trust now "legacy," or is it the prerequisite for everything we're trying to do with AI agents? Is there Zero Trust for AI? Is this a fake buzzword or technical reality? Resources: Video version EP256 Rewiring Democracy & Hacking Trust: Bruce Schneier on the AI Offense-Defense Balance EP133 The Shared Problem of Alerting: More SRE Lessons for Security EP85 Deploy Security Capabilities at Scale: SRE Explains How Google SRE books "Atomic Accidents" book (yes, really)
play-circle icon
29 MIN
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security
APR 6, 2026
EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security
Guest: Dan Lorenc, Founder / CEO, Chainguard Topics: We just saw a security tool (Trivy) get used to pop an AI infrastructure tool (LiteLLM) to eventually pop end users. Have we reached the point where our security tooling is actually our largest unmanaged attack surface? Why now? Software supply chain security had the perennial vibe of "not top concern" for most organizations, right? TeamPCP pushed malicious code to existing GitHub tags. We've been screaming about pinning versions to SHAs for years, but clearly, nobody is listening. Is it time to admit that 'convenience' is the primary enemy of supply chain security? The Axios incident showed a victim compromised in under two minutes. In a world of auto-updating dependencies, is the concept of a human-in-the-loop for software updates officially dead, or do we need to look very hard at version pinning and such? With XZ Utils case, we saw a long-game social engineering attack. Beyond just 'watching npm closely,' what are the realistic architectural safeguards for an org that knows they can't audit every line of an update? We've spent the last three years talking about SBOMs (Software Bill of Materials) like they were a pill for supply chain health. But if the scanner producing the SBOM is the one that's compromised, isn't the SBOM just a signed receipt for your own house being on fire? What is the one practical thing they can do to ensure their CI/CD isn't a credential-exfiltration-as-a-service platform? Resources: Video version North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security EP116 SBOMs: A Step Towards a More Secure Software Supply Chain EP226 AI Supply Chain Security: Old Lessons, New Poisons, and Agentic Dreams EP24 Linking Up The Pieces: Software Supply Chain Security at Google and Beyond Matt Levine blog
play-circle icon
27 MIN