5 augusti 2026
51 min
Software factories are technically possible today, yet almost nobody can is operating one. The security model is what's missing. In one incident a coding agent deleted PocketOS' production database as a side effect of an unrelated fix. In another, a distinguished engineer at GEICO asked an agent to land a pull request and watched it push to production instead. The reality is coding agents cannot yet be trusted with the autonomy a factory requires.
Recorded at The Marquee in Las Vegas on the backdrop of Black Hat, Allie Howe moderates a panel with Eli Aleyner, VP of Product Strategy and Alliances at Docker, Ian Livingstone, CEO and Co-Founder of Keycard, and Ezra Tanzer, AI Forward Deployment CTO at Snyk, on the security problems standing between teams and the autonomy curve a software factory requires.
The three companies co-authored Agent Baseline, a vendor-neutral reference architecture published days before the panel that defines agent security by six outcomes (Discover, Constrain, Authorize, Observe, Validate, Respond) and 35 capabilities rather than by product category. We get into why most teams believe they can only pick two of security, capability, and autonomy, Eli's (Docker) response to the Hugging Face/OpenAI sandbox escape, why credentials belong injected at the moment of use instead of sitting in the agent's workspace, and why customers are seeing risk come from negligence and over-provisioned agents rather than from malicious engineers.
Lyssna på fler avsnitt från
Insecure Agents
Visar 1–10 av 54 avsnitt
27 augusti 2026
32 min
25 augusti 2026
41 min
20 augusti 2026
49 min
18 augusti 2026
35 min
14 augusti 2026
34 min
12 augusti 2026
29 min
28 juli 2026
27 min
23 juli 2026
28 min
21 juli 2026
27 min
17 juli 2026
28 min