alphalist.CTO Podcast - For CTOs and Technical Leaders
Tobias Schlottke - alphalist CTO Podcast

Último episodio
147 episodios
#147 "Make It Secure" Isn't a Prompt: A L0pht Hacker on Securing AI-Written Code with Chris Wysopal // Chief Security Evangelist @ Veracode
01/10/2026 | 1 h 13 minChris Wysopal was one of the first hackers to go public. As "Weld Pond" at the L0pht hacker collective in Boston, he testified before the US Senate in 1998, where the group delivered the soundbite that they could take down the internet in 30 minutes. He also wrote the Windows version of Netcat. In 2006 he co-founded Veracode, which by his account has now analysed trillions of lines of code. Today he's the company's Chief Security Evangelist.
Tobi and Chris talk about what AI changes for attackers and defenders. Attacks are getting cheaper and faster, and a custom exploit no longer tells you a nation-state is behind it. Chris argues this follows a familiar cycle: attackers adopt a new class of tool first, defenders catch up, and parity returns. That only holds if defenders actually adopt the tools, especially underfunded organisations like hospitals, schools and utilities. They also cover the new attack surface created by agents, plugins and MCPs, why prompt injection may never be fully solvable, and how Chris would handle security debt when acquiring a small SaaS company.
CTOs will leave with a concrete shortlist: avoid memory-unsafe languages, put a package firewall in front of open source, run AI-assisted static analysis with real architectural context, and give coding agents explicit security intent rather than hoping "make it secure" does the job.
- From the L0pht and BBS culture to the professional security industry
- The BGP flaw behind "30 minutes to take down the internet"
- How AI changes the cost and speed of attacks
- Prompt injection, agents, MCPs and least privilege
- Security debt in B2B SaaS acquisitions
- Secure on first write: security intent, context and pre-merge testing
- How engineering and security roles change over the next two years#146 AI Found What Nine Years of Security Research Missed with Charles Guillemet // CTO @ Ledger
17/09/2026 | 54 minCharles Guillemet has spent nine years building Ledger's security organization from scratch — first as the founder of The Donjon, Ledger's in-house offensive security research team, then as CTO overseeing security for a company safeguarding roughly 20% of the world's crypto (per Tobi's intro framing).
The conversation centers on one uncomfortable observation: with the latest generation of frontier AI models, Ledger's researchers started finding product vulnerabilities that fifteen dedicated experts hadn't found in nine years of trying. Charles explains why this matters security has always relied on an economic asymmetry between what it costs to attack a system and what an attacker stands to gain, and AI is collapsing that asymmetry by driving the cost of finding a vulnerability toward zero.
From there, Tobi and Charles dig into what actually holds up: security-by-design, treating security as a key-management problem, zero trust, and for teams rebuilding their SDLC around AI — Charles's recommendation of small, AI-native pods spending most of their time on "harness engineering" rather than writing code. They also cover why he believes the CISO function should stay organizationally independent, even though it reports to him at Ledger today.#145 "Harness Writing Is Not Hard": Build to Learn, Not to Run with David Soria Parra // Member of Technical Staff @ Anthropic
03/09/2026 | 1 h 17 minSponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026
David Soria Parra co-created the Model Context Protocol (MCP), the standard that now underpins most AI agent integrations, and, before that, spent years as a core contributor to Mercurial and on Meta's internal source control team. He got into programming at 13, writing a PHP guestbook for a gaming website with friends, and hasn't really stopped building since.
This conversation goes straight to the thing every CTO is quietly building right now: their own agent harness. David makes a surprisingly blunt case that harness writing itself isn't the hard part: "give it a bunch of tools, a bunch of execution steps, be a little smarter about context selection, and go," and that most companies would be better off configuring a strong existing harness than building their own from scratch. He and Tobi also dig into why the "MCP vs. CLI" debate is largely manufactured, how Meta and Anthropic both run on almost no prescribed process, and how David's own workflow has quietly shifted from local Claude Code sessions to Slack threads over the past six months.
CTOs will walk away with a clear-eyed, unhyped view of harness-building from the person who literally created the interoperability standard. Everyone argues about when building your own is worth it, what to check for in a vendor contract, and where to actually put your attention instead of endlessly optimizing your setup.
What's covered:
- David's path from a PHP guestbook at 13 to Mercurial core contributor to Meta's source control team
- Biggest lessons from Meta, and how Anthropic runs on even less internal process
- His personal setup: a handful of skills, a few MCP connectors, and why he's a "vanilla" tool user
- Why his day-to-day workflow moved from Claude Code sessions into Slack threads with Claude
- The real MCP-vs-CLI debate — and why it was never actually a debate
- Should every CTO or engineer build their own agent harness?
- What's still defensible in software engineering as agents get stronger#144 Writing Code Is No Longer the Job: Dana Lawson on Trusting AI Agents Like Self-Driving Cars // CTO @ Netlify
13/08/2026 | 59 minSponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026
Dana Lawson's path into tech started with backup tapes, not a keyboard-in-the-womb origin story. She joined the US Army in the late '90s, automated her way out of manual password resets, and went on to become VP of Product Engineering at GitHub before taking the CTO seat at Netlify. She joins Tobi to make the case that "writing code is no longer the job", an argument from her own New Stack article that lit up Hacker News, and one she doesn't back away from here.
The conversation explores why trust in AI agents may eventually become automatic, the same way our trust in cars we can't repair ourselves already has. Dana explains why Netlify is designing for "agent experience" alongside developer experience, and why the engineer's role is shifting from writing every line of code to defining architecture, guardrails, reliability, and safe user experiences.
CTOs will walk away with a sharper way to think about where human judgment still matters versus where it's already been commoditized, including the tension between speed and control, whether developers risk becoming the bottleneck, and why the real constraint may be moving from "can we build it?" to "does anyone actually want it?"
What's covered:
- Dana's path from the US Army to VP of Engineering at GitHub to CTO of Netlify
- Why she argues "writing code is no longer the job" and the Hacker News backlash
- The self-driving car analogy for trusting AI agents
- What "agent experience" means and why Netlify designed for it
- Craftsmanship, control, and the shift from writing code to defining guardrails
- Whether developers risk becoming the bottleneck in the agentic era
- Why the constraint is moving from "can we build it" to "does anyone want it"#143 The Company Brain: How Kombo Runs on a Git Repo and a Cursor Agent — with Aike Hillbrands, Co-Founder & CTO @ Kombo
30/07/2026 | 57 minSponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026
Aike Hillbrands co-founded and killed two companies before Kombo, now a Y Combinator-backed HR integration platform with $10M+ ARR and a $25M Series A. Along the way, his team built something almost by accident: a company-wide AI brain made of a GitHub repo, a Cursor agent, and a Slack channel, built in two hours, that replaced how the whole company gets answers.
In this episode, Aike explains why files and grep beat MCP tools and vector search for agent reliability, walks through Simon Willison's "lethal trifecta" of AI security risks and how a public Slack channel acts as a guardrail against it, and makes the case for why AI won't commoditize enterprise HR integrations anytime soon, despite that being Kombo's own bet.
Topics covered:
- How Kombo went from Notion AI to a Git-based company brain
- Why files and grep beat MCP tools and vector search for agent reliability
- The architecture: per-customer summary files, cross-linked support tickets, BigQuery CLI, Slack integration
- Simon Willison's "lethal trifecta" and practical mitigations
- Why a public Slack channel works as a security guardrail
- The buy-vs-build question for internal AI tooling
- Why enterprise HR API integrations resist commoditization by AI
Más podcasts de Administración
Podcasts a la moda de Administración
Acerca de alphalist.CTO Podcast - For CTOs and Technical Leaders
This podcast features interviews of CTOs and other technical leadership figures and topics range from technology (AI, blockchain, cyber, DevOps, Web Architecture, etc.) to management (e.g. scaling, structuring teams, mentoring, technical recruiting, product etc.).
Guests from leading tech companies share their best practices and knowledge.
The goal is to support other CTOs on their journey through tech and engineering, inspire and allow a sneak-peek into other successful companies to understand how they think and act. Get awesome insights into the world‘s top tech companies, personalities with this podcast brought to you by Tobias Schlottke.
Sitio web del podcastEscucha alphalist.CTO Podcast - For CTOs and Technical Leaders, The McKinsey Podcast y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


alphalist.CTO Podcast - For CTOs and Technical Leaders
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.















