Episode 13

Andrew Hendela

With Andrew Hendela,
February 17, 2025

What we talked about

Welcome back to The PreVetted Podcast, where we spotlight extraordinary people and remarkable talent reshaping our world.

Show notes

Andrew Hendela joins the PreVetted Podcast for episode 13.

Full transcript

Federico Ramallo (00:01.049) So welcome to PreVetted Podcast, a blend of tech and leadership. Our goal is to explore the journeys and stories of our guests, revealing valuable insights about engineering and business, and sharing them with our community. Our guest today is Andrew Hendela. He’s the co-founder of Karambit AI. Hello, Andrew, how are you doing today?

Andrew Hendela (00:22.7) I’m doing great, you know, a little tired, but I mean, that’s the life of a startup founder. If you’re, if you’re ever feeling well rested, you’re probably not doing enough.

Federico Ramallo (00:35.26) There is no rest for the wicked, right?

Andrew Hendela (00:37.86) I mean, you have to rest. But if like, you have to rest, if you don’t, you’ll burn out. And that’s like, something else you have to keep track of as a founder.

Federico Ramallo (00:47.331) Right, right. There is a talk that I saw many months ago, but they were talking about for startup founders, there is no work-life balance. That’s a myth, right? It’s you’re 100 % committed to make your startup work, right?

Andrew Hendela (01:07.022) I think that’s definitely true. You have to obviously work a lot. But for me personally, I try to make sure that there is a balance because I need to know why I’m doing what I’m doing. I have a family, I have three kids, I have a wife. if… One of the recommendations I got early on, I got a lot of recommendations because I always like getting other people’s advice and…

figuring out how to work with them. But I was told very early on, like, your startup is not worth your family. And I agree with that 100%. Because, I mean, part of the reason why I’m doing what I’m doing is because I want to help take care of them. I want to do good for the world, but I also want to do good by my family.

Federico Ramallo (01:58.895) Yes, of course. the… We were talking about earlier, before recording, about the fires never… There’s always a hundred fires that you have to… So I’ve been through that same experience. I’ve been working 40, 50, 80 hours a week, right?

Andrew Hendela (02:00.43) you

Andrew Hendela (02:12.984) Right?

Federico Ramallo (02:28.441) There you go.

Andrew Hendela (02:28.898) Yeah, lot of work.

Federico Ramallo (02:32.707) Hello.

Andrew Hendela (02:33.166) Speaking of fun stuff, hey, Zed, can you come here? Or do you want to go?

Andrew Hendela (02:40.142) I don’t know why you’re asking me about that. You should ask mommy. See?

Federico Ramallo (02:45.795) Hello baby.

Andrew Hendela (02:47.406) Okay, you can have a little. But can you go please? Thank you. See? You always gotta balance things. I’m like, hey, can you… I mean, that’s the thing. It’s like, I work from home, so you never know when the kids are gonna come in. Sometimes I’m muting to say, hey, can you please leave? And then sometimes that doesn’t work. You gotta deal with the, as you were saying, the fire that pops up. And sometimes it’s a small child being adorable.

Federico Ramallo (03:15.555) Right, right. as parents, have to take, parse everything and give them the attention that they need, right?

Andrew Hendela (03:25.186) Yeah, but as I was saying, we had snow on Monday and now it’s Thursday and school is still not in session.

Federico Ramallo (03:36.079) I find that crazy for me, that snow stops everything. I understand the rationale, but it’s difficult because I come from a hot climate, for me, cold is 80.

Andrew Hendela (03:56.622) I’m from Connecticut originally, so we used to get snow all the time. So being down here in Northern Virginia, when they get snow, it’s much bigger deal. Like you get snow in Connecticut, it’s like, yeah, you might get a snow day if you’re a kid, but like they know how to deal with it. here it’s, yeah, it’s a big issue here when it happens. We get one snowstorm, essentially we get like one big snowstorm a year.

Federico Ramallo (04:15.535) It’s a non-issue and where you are now, it is.

Federico Ramallo (04:25.379) Right.

And the we were talking about the changes, you know, your schedule and your dynamic throughout the day, right? Because I just took my son to school today. You know, they started school today and, you know, I take him to school and then I came back and I’m like, wow, I’m at, you know, eight a.m., seven thirty a.m. in the morning and I’m, you know, I’m free now. I can be productive. I can do a lot of things. Right.

Andrew Hendela (04:29.239) You

Federico Ramallo (04:57.667) So it’s a whole different dynamic when my son doesn’t go to school, right? Because all that morning I have to spend paying him attention, right?

Andrew Hendela (05:10.21) Yep, it’s definitely that balance, right? And it’s another couple more things that are on the pile of responsibilities I have. And a lot of that work-life balance we were talking about a second ago is how do I make sure all of those responsibilities I have are being taken care of?

Federico Ramallo (05:22.468) Right.

Federico Ramallo (05:35.171) Right. Right. It’s, I remember the author of the book, he was talking about circles, right? So you have your family, your friends, your work, right? And you have different responsibilities on each and you have to balance them out, right? So it’s not like one has, it shouldn’t be that one has more priority than the other one because then, know, if you focus a lot on work, then, you know, your family never sees you, right? So that’s.

that’s not good, right? So finding that balance is difficult. And the book was talking about being able to make switching context.

actively, right? So, you know, when I work from home, you know, I have my office and then, you know, when I leave the office to the house, right, I make a conscious decision of, you know, if I’m going to play with my son and try to be 100 % focused on that, right? It could be not, you know, I can tell him, you know, I have 15 minutes until my next meeting, but I can play with you for 15 minutes and then I can go back, right?

Andrew Hendela (06:45.998) Yeah.

Federico Ramallo (06:55.151) And then he knows if I’m working, he shouldn’t interrupt, right? Which, know, sometimes they do, right? Yeah, yeah, yeah. But at least that helps you have these boundaries of, know… And then when you’re playing, you you’re also thinking about work and, you know, and then people pinging you. So it’s difficult to, know…

Andrew Hendela (07:03.022) Sometimes they do.

Andrew Hendela (07:21.976) be fully present in anything at any given time, which I think that’s the balance I’m always striving to make. It’s like, okay, if I’m here, okay, let me put my phone down. Let me like not have anything. Let me just focus on my kids or my wife or whatever the case may be.

Federico Ramallo (07:25.101) Yes. Yes.

Federico Ramallo (07:32.386) Right.

Federico Ramallo (07:40.591) Right. the coach K, Sean Climshin, he told me recently about this 96 hour, this emergency is going to change dramatically in 96 hours, 24 hours, does, sometimes they do, production is down, okay, we have to fix that, right?

Sometimes, you know, those 96 hours helps you have a better perspective rather than reacting to what’s going on right now with your emotions, right? It’s like, can this, is this, is my perspective going to change in 96 hours? Can this problem wait 96 hours, right? Before I do something, right? And I think the same applies for the family, right? So, you know.

Being able to say, yeah, because that way you can clear your mind so you can be focused, present with your family. One hour dinner is not going to, unless there is a real emergency, it’s not going to change the outcome of any business decision. So you can take those time slots to be fully present with your family.

Andrew Hendela (09:10.03) Right, and if you can take care of your family, then it becomes one less stressor for everything else. If you pile on business stress with family stress, it’s not something you really want to have.

Federico Ramallo (09:18.289) Right, right. It’s a

Federico Ramallo (09:27.919) right, right? And the family becomes your, I don’t know if the cheerleader is the right word, but you know, your support group, right? Your first support group, right? Those are unconditionally there, you know, cheering for you, right?

Andrew Hendela (09:45.806) Right, which is helpful in obviously all of the business stress, being able to go back and be like, okay, know, talking with my wife and my kids, like, hey, here’s the good things that are going on, like having them encourage me with the good things that are happening in their lives, you know, and help with that balance.

Federico Ramallo (10:03.823) Right, right. Because then that makes, you know, every other problem that the business is going to show up, it makes it not less important because, you know, but it has a smaller impact on you, right, on your mindset, right? It gives you the clarity to, it’s a problem, but I can figure it out, right?

Andrew Hendela (10:29.996) Right, it helps contextualize what is going on. like, okay, well, yeah, that’s… about spheres or circles, right? It’s like, okay, well, that’s… Yeah, maybe that circle is having problems, but this one’s solid. So just helpful… Hopeful mentally, because there’s a lot of times where it’s like, it seems like everything is going wrong. And then something switches and you’re like, okay. We have to get through those hard things to get to the better times.

Federico Ramallo (10:59.213) Yes, yes. The, you know, if we think about the definition of hell, right? What is hell, right? You’re miserable doing what you’re doing, you know, you’re not appreciated, you know, and everybody is, you know, is resentful to you or at you or with you, right? Then, you know, you’re miserable and then you keep dragging that, you know, that’s, that’s

an awful way to live, Regardless of the money, right? You can make a lot of money, but if you’re in that situation, you know, it’s a, what’s the point, right?

Andrew Hendela (11:44.504) Well, I mean, that’s it. It’s like if the goal is just money, I mean, you can get money a lot of ways.

Federico Ramallo (11:52.941) Right.

Andrew Hendela (11:54.382) And if that’s your only focus, then it’s going to cause all kinds of other issues anyway. You know, there’s all kinds of statistics about like, yeah, there’s a certain level of money you need to like, not worry. But it seems like that amount that you could be content with, if you’re, if you allow yourself to be content is actually a lot lower than most people think. And it feels like the numbers, the numbers increase as you get, I don’t know, older or like different

Different generations are like, how much do need? The boomer generation is not nearly as high. I think I heard some statistics where, in order to be happy, a millennial needs to make half a million dollars a year. Do you even know what that means?

Federico Ramallo (12:31.055) you

Federico Ramallo (12:41.199) That’s what less than 1 % of the population, right?

Andrew Hendela (12:45.422) less than one, one, like a percent of a percent or something like it’s, it’s pretty high, like to get that much as far as income goes. But I think people just maybe this is the perception of people, right? They see, they see people on like, I don’t know, all like Instagram or whatever, they’re like, Oh, this is the best. Oh, I see all those people with all this money. It’s like, yeah, but they’re showing you this polished thing. But that’s

That’s not true life, right? True life is messy. You go through things, you have hardships. And just because you’re always showing the best face on things doesn’t, doesn’t allow other people the, I guess the room to also have problems. And we can all say like, hey, we all, we all these issues, we have to work through them and we can all come together and, you know, get better on the other end. It just kind of comes back what we were talking about. Like, yeah, I can.

I can use my family to help me when I have business problems, can use my family to help me get through those too.

Federico Ramallo (13:51.572) Right, right, yeah. So there was a…

an American executive that went to a small town beach in Mexico, right? And, you know, he was watching the sea and their boats coming in, right? They’re fishermen, right? And when the boats arrive, there’s some locals that wants to buy the fish right fresh out of the boat, right? So, you know, after all that…

Frenzy, right? Because that’s very dynamic, right? That’s, you know, like, yeah, yeah, yeah, like, you know, I want this, I want that, you know, what, what you got, you know, and, you know, people bidding for the fish, right? So anyway, after all that, he’s pulling the boat, boat out of the water, right? And this is, you know, after, after lunch, you know, they, go up early in the morning, you know, like, let’s say noon, right? So,

Andrew Hendela (14:30.542) Yeah, yeah, I can see it in my mind. It’s a bit dynamic.

Federico Ramallo (14:57.113) you know, he’s pulling the boat out of the water, right? So then this man approached the fisherman, you know, like, why are you putting your boat away? You know, it’s like, well, I’m done for the day, you know, but you could do so much more. You could go back again and get more fish and then you can sell it. And then, you know, like because of the mindset of you can do more, you can put a, you know,

a fishing company business and hire so many employees and you know, so he was baffled by this idea of, know, I am done for the day, right? It’s like, why? Yeah, because you can make more money. But why? I don’t need more money, right? I have a lot of fish to feed my family. You know, I make some money selling fish, right? More than enough for what I need, right?

So now I can spend half day with my family. So why should I go and do more?

Andrew Hendela (15:59.628) Why should I put that effort in there where I can put the effort in somewhere?

Federico Ramallo (16:04.335) Right, right, right, right. So he was content with what he got and after asking more questions, he realized this guy is happy, this fisherman is happy, content with what he got. So going back to your point, the fisherman doesn’t need a $500,000 job to be happy. So yeah.

Andrew Hendela (16:17.996) Yeah.

Federico Ramallo (16:33.391) And there is a diminishing return of spending more hours fishing. is a time window for that. So there’s also that. But at the end of the day, he understood those priorities and he was able to balance his life in a productive way. So yeah, I agree with you on the balancing, finding that balance is…

It seems difficult, but at the end of the day, being able to have the freedom to be able to say, I’m going to spend a few seconds of attention to my son to talk to him rather than screaming at him, get out of here. Being able to have that freedom for me, that’s more important than whatever money in the world. And being able to be there, be present as you are.

Andrew Hendela (17:33.218) Yeah, it’s one of the benefits of being able to work from home. like when the kids are around, like, well, I’m here, I can take a break. Right. It’s like, okay. You know, when we’re done with our podcast talk, I can go upstairs and say, so what do you need? Rather than, hey, I have to drive 30 minutes to get home. Right.

Federico Ramallo (17:52.815) Right, right. My parents used to do that. They used to work on a corporate business. I wouldn’t see them until 7 p.m., 8 p.m., 9 p.m., depending. And then they switched to work from home. Many years ago before remote work was a thing, in the early 90s. So it was good. We had…

we have them present for everything. So yeah, I think that’s a very positive thing.

There’s another book that I keep mentioning books and I don’t remember, know, like who said what. know, I, right. It was a book. So, you know, this let’s call it this guy, you know, talks up, talks about the archetypes of happiness, right? So there are four archetypes, right? And he talks about them in hamburgers, right?

Andrew Hendela (18:40.622) Who said what? It was in a book at some point in the past.

Andrew Hendela (18:50.493) Right, this guy.

Federico Ramallo (19:03.747) So you have the hamburger made of pure fat, right? You don’t enjoy it, and it’s bad for you in the long term, right?

you have the, know, the, that’s kind of the rat racer ways, you know, like I’m working in a meaningless job, but eventually I’m going to get a promotion, right? To be more, more, more miserable in the future, right?

Andrew Hendela (19:33.836) Right. I’ll do a promotion so I can do more meaningless stuff.

Federico Ramallo (19:37.295) Right, right, right. And then you have the McDonald’s hamburger, right? Or fast food hamburger, right? It’s, you know, well, not anymore, but you used to, know, taste good, right? It actually tastes better. I don’t know if you know this, but it actually tastes better. McDonald’s tastes way better in Mexico than in the US.

Andrew Hendela (20:03.662) I mean, Mexican Coke tastes way better than normal Coke. So I’m sure that’s true.

Federico Ramallo (20:09.378) It’s…

It’s like an upper-class restaurant. competes with, you know, with, yeah, like middle-class, middle- and high-class families go there. And so, And they compete because of consistency and quality, right? So, you know, good environment, good quality, know, kind of a little bit cheaper than, know,

premium restaurant, kid friendly. yeah, for families with kids, it’s a great place to go. Anyway, the fast food hamburger is good. You have immediate gratification, but it’s bad for you long term. So that’s, if you only do that, that’s bad, right?

because then it’s the same, it’s the hedonistic way, right? You’re enjoying the now, but you’re sacrificing your future happiness.

It’s like, if you start taking drugs, right? It feels good right now, but then it destroy your body in the future, right? Or it destroy everything, right? yeah. Yeah, yeah, yeah. And then, you know, what happens if we could find, you know, this ideal hamburger, right? It tastes good. sorry, sorry. There’s a third hamburger. It’s like, it’s…

Andrew Hendela (21:35.534) Everything.

Federico Ramallo (21:54.251) is

Federico Ramallo (22:02.127) I’m trying to remember the third hamburger. So let me tell you about the ideal hamburger where I remember the other one. So the ideal hamburger is what happens if we could find, yeah, I remember the third one. So let me tell you about the third one. I’m trying to build momentum here, right? So So let’s say we find this super healthy hamburger, right?

Andrew Hendela (22:19.83) Okay. Right. Get your momentum.

Federico Ramallo (22:29.953) It’s good for your future self, right? It’s healthy, low carb, whatever, right? You taste, you bite, you eat it and it tastes like cardboard, right? It’s flavorless, right? So you’re sacrificing your current happiness for future happiness, right? So, you know, that’s not good either, right? I mean, if…

It kind of, but if you only do that, that’s not good. And then the fourth archetype of hamburger is ideal hamburger. You eat it now, it’s good for you. You enjoy it now, so you have immediate gratification. And also, it’s good for your bar in the future. So it’s not only immediate gratification, but it also helps build your future happiness.

rather than trying to find this, this ideal job or this idea project or the day that my company is going to be problem free, right? Which, you it never happens. Every day. Yeah. So what happens if we could have an activity that we’re doing today? And for what we’ve been talking, I…

Andrew Hendela (23:40.086) Right, right. Which is, it’s gonna be tomorrow. I’m sure it’s gonna be tomorrow. Every day, it’s tomorrow.

Federico Ramallo (23:57.741) I believe that what you’re doing today in your company is giving you gratification, day to day gratification. Of course, sometimes there’s some painful stuff, but overall,

Andrew Hendela (24:14.068) Yeah, gratification doesn’t always mean easy, right? And in a lot of ways, the things you do that are hardest can bring the most gratification. As long as they’re like two good ends, right? Kind of back to your happiness thing, right?

Federico Ramallo (24:17.465) Right, right.

Federico Ramallo (24:23.599) it

Federico Ramallo (24:27.427) Yeah, but so for every activity that you do daily, you have two things meaning gratification and meaning, right? And they both kind of, you know, it’s like a salt that enhances flavor, right? So if it gives you gratification and it has a meaning that it’s long term meaning to a personal goal that you have, right? Then, you know, that enhances the

Andrew Hendela (24:41.198) Mm-hmm.

Federico Ramallo (24:56.159) gratification because you know you’re doing something good right sometimes as you said you know some activities are a little bit painful right it’s like well i have to do this but if it’s related to my long-term goal then the pain is not that painful right it diminishes the pain right it’s or the comfort right

So from what we’ve been talking before, I believe that you are in that ideal hamburger, right? Because you’re getting a lot of happiness from what you’re doing every day, and also you have a long-term meaning,

Andrew Hendela (25:47.854) I that is the goal. mean, it fluctuates probably every day. A lot of times there’s just things you have to do to get done. But as you were saying, the meaning behind them is we get to help more people, which is ultimately my goal, which is honestly why going through like the hardships is worth it. Because you’re talking about like, oh, well, if you just get a bunch of money, it’s like, well, you… I’m in cybersecurity. I could go like…

Federico Ramallo (26:02.531) Right.

Andrew Hendela (26:14.924) I can go to basically any company at this point. Everybody needs cybersecurity. could just go, I can just go get a good job, right? But it’s, it’s not this, yeah, could get a cushy job. Maybe, maybe still stressful depending on how high you would, how high, how high you raise up there. But being able to like build this own company, like it gives us meaning because we get to, we get to decide how do we help people and

Federico Ramallo (26:21.667) Right, a cushy job.

Federico Ramallo (26:43.747) Right.

Andrew Hendela (26:43.766) It’s not the same thing as when you’re at a huge organization where it’s like, hey, here’s the work we have. Here, it’s like you get to direct it. You get to go and say, okay, what are the people we can help? How can we help them and use that as

Federico Ramallo (27:00.653) That’s the meaning. That’s meaning. That’s your meaning, right? Your meaningful meaning.

Andrew Hendela (27:04.814) That is the meaning. Yeah, I I’m here ultimately to help people and being able to do that. I mean, you know, I have an expertise in cybersecurity, you know, huge nerds. So what can I do with that? I can solve some problems. I can’t solve every problem, but, you know, I can help the people I can help. And that’s helpful because there’s, it seems like there’s unlimited problems in the world.

And a lot of times we focus on things we can’t actually do anything about. And then we worry and we sometimes go crazy. It’s like, well, what things can I help with? I can help with this. I’m going to do this, right?

Federico Ramallo (27:52.847) Actually, we talked before about what Karambit AI, what your company do, right? we kind of missed that for the audience. So let’s talk a little bit about that. What does your company do?

Andrew Hendela (28:02.571) You

We missed it early, it’s okay.

Andrew Hendela (28:19.02) Yeah, so our company, Karambit AI, and it’s honestly a lot of the reason why I’m thinking about, how can we help people that no one else can help is our company focuses on software behaviors. And the way you think about it is, okay, you download an app on your phone and you get a permissions list. like, okay, like it’s going to take location data. You don’t necessarily know exactly what it’s going to do with that, but at least you have something.

Problem is, if you’re not doing a mobile app, if you’re just downloading something on your Windows machine, your Mac machine, or like a Linux server, you don’t actually know what the behaviors are going to be until you run it and then you hope it doesn’t do anything bad. The problem there is that you’re basically trusting your suppliers. You’re trusting people who are building software. mean, if you’re building software, you’re trusting the libraries you’re pulling in. And there’s been a series of pretty high profile attempts.

where someone goes after a supplier to get to their customers. And that’s actually why we started our company, because there was a really big one at the end of 2020 called the SolarWinds attack, where SolarWinds cybersecurity company got hacked by Russians. Malware gets put into their software, and they had huge customers. Like Microsoft was one of their customers. If you looked at the list before it got scrubbed from the internet,

I think you can still use the Wayback Machine, but it had every government agency in the US, probably some state and local governments. I’ve talked to quite a few customers of theirs since we started, and they were trusted. So you let your update in, you run it maybe a little bit test. But then what the attackers did is it’s kind of brilliant if you have this attacker mindset. They knew what the defenses were going to do. They’re like,

Federico Ramallo (29:58.168) Wow.

Andrew Hendela (30:15.786) Okay, we’ll just get into SolarWinds. It’ll get signed. It’ll claim it’s right. So any antivirus is gonna say, it came from the right place. It’s fine. Just let it run. And then they waited two weeks and a random amount of time to start doing bad stuff. that… Yeah, they waited two weeks. And what’s kind of interesting is like talking to other people who are like doing IT upgrades. They’re like, yeah, like the longest we’ll wait like to do a test is like two weeks. So…

Federico Ramallo (30:32.12) Wow.

Andrew Hendela (30:44.234) Even the attackers knew that. They understood, OK, what are they going to possibly look for? And then the attackers waited those two weeks. It just started calling back to them. And they were able to compromise somewhere around 18,000 customers to the point where they could choose which, who do I actually want? The attackers would be like, OK, Microsoft, that sounds good. Federal government, yeah, I’ll take that.

Federico Ramallo (31:10.831) That’s kind of better, right? Better target.

Andrew Hendela (31:12.608) Yeah, we’ll take that. Better target, like we’ll get whatever we can or whatever we want. And we saw the aftermath of that. a lot of people, there were a lot of people regulating software supply chain security, but they focused on this thing called a software bill of materials, which is essentially your ingredients list. You you look at a cereal box, you’re like, yeah, I got a bunch of random chemicals in my food. I guess they’re fine. Right. And the software bill materials is like that.

But for software, like, hey, what’s, what is in this? But it doesn’t actually tell you anything, anything about that software. just says, here’s the list, but not if that, library is bad, what’s it going to do? So we created our company around the idea of, let’s stop attacks like that. Let’s actually inform people about, Hey, what does this software do? How is that changing? And is there something new and potentially malicious in here that no one’s ever seen before? So.

So we were essentially able to take the expertise we’ve been gaining for my co-founder. actually worked together for, it’s coming up on 10 years at three different companies. So like we work really well together and we’ve done really deep automated analysis of software. we, we took that expertise, pulled it into our company and, uh, I mean, again, the goal of being able to actually change how we understand software. Cause right now you just kind of like download it and use it.

And if we can make it so people can either understand or better yet, don’t even need to understand, like they can just have a very human readable. They don’t have to go down to the level of nerd like me and like get into it and say, Hey, very high level. What does this thing do? Do they want it? You know, what’s the recommendation? And that’s, that’s essentially the automated technology we’ve been able to build taking that expertise we have.

Federico Ramallo (33:08.653) Right, so you were able to put your expertise and your co-founder’s expertise into the product. Basically, you are taking this… So what happens with this… So there was a philosophical approach to cybersecurity, right? And then these hackers were able to basically… I don’t want to use the word disrupt because it sounds too marketing-y, right? But you know…

or flashy, right? But basically that’s what they did, right?

Andrew Hendela (33:40.696) Well, they were able to take advantage of how defense works. my co-founder and have done some offensive cybersecurity in the past. So finding bugs in software, exploiting them, thinking like an attacker. And that’s what you have to do. You have to figure out, OK, how does defense work? How does this anti-virus work so I can get around it? How does

Federico Ramallo (33:47.574) Right. Right.

Andrew Hendela (34:08.92) You know, how does this particular software I want to exploit work so I can, you know, go through all the path I can, you know, I can put my, my data here. So it goes all the way through and lets me do whatever I want. So you have to, you have to think those things through. And if you do that, like you can do attacks like that, where you just say, okay, well, all right, I will hit their weakest link because it’s, it’s just a matter.

In some ways for attackers, it’s not a matter of like, “if”. it’s “when”. It’s like, okay, how, how can I get in? What’s the easiest matter? And sometimes I think most attacks at this point, they just say, Hey, I want to send an email to a bunch of people. they click a link, all right, I’m in. But if you’re, if you have better security than that, if you have all the, you know, phishing defenses and all of that, then you have to try a little bit harder. And it’s like, okay, well.

What’s the weakest link? well, hey, they have these, you know, the standard enterprise probably. It’s like.

thousand, ten thousand suppliers of various different kinds, if you can get into one of them, now you can get access.

Federico Ramallo (35:22.551) right, right, because they trust the first level, but they don’t trust the second level of basically code and libraries that you have. Because right now all the software is interconnected through libraries, third party libraries, so you can trust the vendor that you have in front of you, but then you don’t know what’s… They don’t even know what’s behind.

Andrew Hendela (35:49.974) Right. And even if they know, okay, here’s all my libraries, but is there something bad in them? And is there something bad in this new update? You know, like, are we even updating? And if you don’t update, now you have like a vulnerability that might, somebody might know about that they can exploit. But if you do update, what if somebody like compromised like that open source library? Like it’s, it’s a mess.

Federico Ramallo (36:09.507) Right, right. I was going to ask you about that while you were talking about the libraries. What are your thoughts on closed source and closed source libraries, they give you a binary, right? So you cannot see what’s going on in there, And what your tool is doing is observing behavior, right? Versus using open source library where

you can see what’s going on. You can see the source and what’s going on, whether it’s compiled or not. You now have access to that, whether you or any other company actually go through the code.

Andrew Hendela (36:51.926) Right. And check, are you actually checking all the source code for the open source? You hope someone else is going to do that at least.

Federico Ramallo (37:01.507) Yeah, yeah, yeah, yeah. I mean, there was a library in NPM in JavaScript that basically, you know, the maintainer decided to just not use anymore. And then he broke like half of the internet, right? At one point, right? And it was a very simple library that was doing something very easy, very simple, but everybody was using it. Yeah, yeah, yeah, left path. Yeah.

Andrew Hendela (37:20.858) Was that left pad? Like somebody made a library for doing left pad and you’re like, anyone could implement this, but you don’t have to. So you have this one maintainer that has like…

Federico Ramallo (37:30.799) because you have that one library, right? And it was not malicious, but all he did was just close the library, right? And then everything broke, right? Or delete the library, something like that. So when you’re working with open source, you can see what’s going on, but now you have more risk on who’s actually maintaining the code. We’re talking about that, I think you were talking about that.

Andrew Hendela (37:33.454) Yep.

Federico Ramallo (37:59.897) that’s how they got into the systems, that they took the maintenance of one of these libraries, right?

Andrew Hendela (38:07.384) Well, so there’s a few different things you kind of touched on. One is like closed source libraries versus open source. Our technology actually focuses on the compiled software, specifically because you don’t always have the source code. But we want to make sure we’re checking, hey, that’s the thing that’s actually going to be run, because source code isn’t always telling you the truth. So there was a different attack in, I think it was the end of February.

last year, so almost almost a year ago now, against a library called XZutils. And this was open source and it was used by SSH. So secure shell. And this attack, this attack was, was kind of brilliant for a different reason. They, they basically, as far as I can tell, like they looked at SSH and said, okay, what’s in here? What libraries do we think we can like get access to?

And there was one library that had like one maintainer. So two, was like two years before this attack, someone like someone decided, okay, you know what we’re going to do? We’re going to start pushing really good code to this library. We’re going to, they put us enough code to become a maintainer. And now they’re in charge of that. They’re one of the two people who are in charge of that library. So into February last year, after like staging, like they had a binary for testing supposedly, and like a really obfuscated shell script.

They said, okay, I guess it’s go time. They pushed a commit that made it. when you compiled that software with, and then you linked it with SSH, it rewrote some of the functionality in SSH to have a backdoor in the SSH daemon. And that attack actually funneled all the way down to at least Ubuntu. So, know, huge, huge Linux distro.

Federico Ramallo (39:49.593) Ho ho ho ho ho ho ho.

Federico Ramallo (40:03.095) It got to major leagues.

Andrew Hendela (40:06.488) Yeah, it made its way where it was supposed to go.

The part about that attack that like the reason it got caught is because the attackers were sloppy because it was caught because someone at Microsoft who is a post-gress developer for Microsoft, because Microsoft pays for like a lot of open source development, noticed that his SSH connection took half a second longer than it had previously and and decided, okay, I’m going to go through

Federico Ramallo (40:22.511) You

Andrew Hendela (40:42.702) I’m going to do Valgrind, I’m going do analysis, I’m going to essentially reverse engineer this thing. Who knows how long that took, Days, at least, of time. He took out, was like, hey, half a second too long, I need to find out what’s going on here. Most people would have just waved it away when this guy did it. And he was able to say, there’s a back door in this library. Well, what? But if it had taken any less than that half a second, if it was like, you know.

millisecond which you probably should like if they had done more tests than they probably could have gotten they would have noticed they were like it’s like you know you know probably one millisecond is probably within within the tolerances for what they were doing but because because they were a little sloppy because they were trying to push it out quick they got caught

Federico Ramallo (41:34.361) Right, right. That’s amazing. And that’s kind of the risk when you’re doing open source, right? You don’t actually know where the code is coming from,

Andrew Hendela (41:49.826) Right, you know where the code’s coming from, you don’t really know who the maintainers are. Some of the reporting I saw on that particular attack, it was supposed to be one person, but it turned out I think it was like a group of like five Russians all pretending to be the same person. That was at least what the reporting said. But I mean, it kind of makes sense. If you’re going to do something like that, I mean, you might as well give our people under one name.

Federico Ramallo (42:03.588) Ha ha.

Andrew Hendela (42:18.88) submit a lot of good code, get trusted. Now you have control over some open source library.

Federico Ramallo (42:27.129) Right, right. I mean, as an engineer, I am amazed by their creativity, right? Even though it was used for doing unethical stuff, So, yeah, so thank you that the word is very sloppy, Sloppy enough, right?

Andrew Hendela (42:39.747) Right.

Andrew Hendela (42:47.672) Well, right. that’s, well, right. but that’s, if they were sloppy enough for a human to go through it, because you, you can’t, you can’t, you cannot have a human go through all of the Ubuntu libraries. You know, you can’t, you can’t have that because if you take eight hour per, per update, it would take years every month, right. For the, all the updates that come out. So.

Federico Ramallo (43:12.399) Right, right. And the number of libraries and updates that happen are very frequent, right? Ubuntu kind of started with the trend of major and minor versions, which was something novel for the Linux industry, right? Because before Ubuntu, was, go and compile your own kernel, right? Go and download all this.

Andrew Hendela (43:42.222) Right.

Federico Ramallo (43:42.303) source code, right? And they had like 50 questions that you you it wasn’t like a wizard, but you know, you have to think about 50 things, right? Like what is your, you know, GPU, right? What is your CPU? You know, there are so many things, right? Appropriate, yeah, yeah, yeah. So Ubuntu kind of simplifies that a lot, right?

Andrew Hendela (44:02.538) Right, make sure all of the flags are proper.

Federico Ramallo (44:11.031) and then they start doing these major and minor versions, right? So now you have a stable, quote unquote, know, server version, At least as a user, you know, because I started with Ubuntu, right? As a user, now you have a release, right? Now you have a number that you can, you know, say, I’m using this version of Ubuntu, right? So, you know, but…

Andrew Hendela (44:20.632) Right.

Federico Ramallo (44:40.025) But there’s so many libraries there that it’s, yeah.

Andrew Hendela (44:42.978) Yep, and each library is going to have its own version number, right?

Federico Ramallo (44:46.785) Right, right. everybody’s using different policies for release. you know.

Andrew Hendela (44:55.584) the version numbering itself is kind of, it’s its own thing, right? Honestly, that’s one of the reasons why like, so self-reviewed materials is like name and version number. Like that’s really what it comes down to. But those version numbers are effectively meaningless unless the developer gives them meaning. So there’s, you know, there’s like, the concept is supposed to be like, you know, major, minor point releases, right? But those only actually have,

relevance if a developer uses those to mean something. So you can have like a minor release that changes like every single function. But the actual underlying code, we’ve seen that in some of the analysis we’ve done on a bunch of libraries where we’ll do a comparative analysis to be able to say, hey, how has this thing changed? How are the behaviors changing? And we have some deeper analysis of like, hey,

How many functions changed in here? And sometimes it’ll be like, hey, was like 2.0 to 2.1. It’s like, how did 90 % of this binary change? That’s a bit much for what you would think is a minor release, right?

Federico Ramallo (46:06.019) Wow, that’s a lot. All right.

Federico Ramallo (46:12.045) Right, right. And that’s what I’m talking about, that they have different policies because there’s lack of consistency, right? Yeah. And it’s kind of order within the chaos, kind of, right? But on the security side, that’s a nightmare, right?

Andrew Hendela (46:16.312) Yep. Yep.

Andrew Hendela (46:28.078) It’s a huge nightmare. I mean, it’s even worse because a lot of times you use version numbers to find vulnerabilities. But you’re never required to ever change your version number, right? So you could do an update and then never actually change your version number. It’s like, OK, well, is this the vulnerable version? I mean, you should be if you’re trying to patch a vulnerability, but maybe you’re not. Maybe you don’t care enough.

let alone the fact that for open source, the bigger libraries are better about having version numbers be consistent. But if you’re using a small library, you’re probably going to have no public reported vulnerabilities in that library because no one checks it. If nobody is checking some small left pad, if there was like, move onto leftpad.dev, you download that, you run it, you’re like,

Federico Ramallo (47:11.693) Right.

Andrew Hendela (47:23.414) Okay, well, no one’s checking this for vulnerabilities. What if there is one? I don’t know what… I can only imagine what kind of vulnerability would get snuck into a left pad, right? But you don’t know, but no one’s gonna check that because they’re just like, it’s left pad, it’s boring. I’m not gonna bother like doing vulnerability analysis for that.

Federico Ramallo (47:33.711) Right.

Federico Ramallo (47:44.185) Right, right. And sometimes they reuse the same version number for, you know, it hasn’t been the norm, but I’ve seen at least two or three cases of that where they reuse the same version number and then they update the library. So if you don’t know that story, then you think it’s the same code, right? And it is not, right? So…

Andrew Hendela (48:03.118) Mm-hmm.

Andrew Hendela (48:09.214) Right, I mean that’s the other thing. It’s like, hey, there’s a… This has been the same version for the last five years. What? But it’s different every time. Yeah.

Federico Ramallo (48:10.255) You

Federico Ramallo (48:20.771) Right, right. So how can you trust a binary or a software in an untrustworthy environment, right?

Andrew Hendela (48:36.29) I mean, that’s really what it comes down to. mean, that’s why, that’s what we’re trying to solve, right? That’s what we’re doing. We’re doing it for a few major customers, even now, specifically because it always seems like the people who are the biggest targets are the ones that care the most about cutting edge cybersecurity. We’re progressively getting smaller and smaller. But if you’re a big target, you need to know what your software is doing. If you’ve been hit by these kinds of attacks, you’re like,

Oh, okay. This is, this is worth it. This is worth it to work with a smaller company. This is worth it to get that cutting edge analysis. A lot of like, I’m not going to another startup and say, Hey, well, I can try, but like there has to be other reasons for a startup to want this. Most startups back to the, back to the hundred, hundred little fires that are given at any point. Like for most startups, like cybersecurity isn’t like on their radar.

Federico Ramallo (49:24.11) You

Andrew Hendela (49:35.36) until it becomes like a compliance issue because they don’t have time.

Federico Ramallo (49:39.693) Right, right, yeah. I mean, if you don’t have customers, you have nothing to lose, right? So… Right.

Andrew Hendela (49:44.618) Exactly. Right. I mean, that’s really what it comes down to. It’s like, well, OK.

Federico Ramallo (49:50.959) And it becomes an issue when the risk becomes more and more, you know, the bigger, Higher. So what you do is you get all the code and all the dependencies and that gives you a non-moving target, right? And then from there you analyze that code on the behavior level, right?

Andrew Hendela (50:20.142) Yes. So one of the other interesting things is you’re saying code and it is technically code, but it’s like assembly code instead of source code. So we’ll take the actual binaries and we get behaviors, what’s known as through static analysis. So we don’t run the software to find behaviors. This comes back to our threat model is attackers are really good at avoiding

Federico Ramallo (50:27.925) Right. Right.

Andrew Hendela (50:49.428) detection when you’re running it. think, hey, if I run a piece of software, I don’t know if I’m going to get all the behaviors because maybe they’re going to wait 14 days like the solar winds detected. So we actually, so we use an open source tool as like the baseline called, called Ghidra. It’s the NSA’s reverse engineering framework. So we use that to get disassembly and then from the disassembly, have our analysis on top of it to be able to go and say, okay, hey, this, this function right here.

Federico Ramallo (51:00.463) Right.

Andrew Hendela (51:18.606) has these behavioral capabilities in it. Oh, this function over here is these capabilities. And then we are able to determine as we’re getting more and more versions, we build up models of, okay, what’s expected for this particular kind of software. And if that changes, we flag like a detection.

Federico Ramallo (51:38.985) Right, right, I see. you not only you get a non-movable target of the code, but also you freeze it. You don’t allow it to run. You chain it to the floor, basically,

Andrew Hendela (51:53.518) Essentially, we chained it to the floor. But one of the reasons we do this analysis of different versions is there’s nothing inherently malicious about any given behavior in a computer. the example I usually give is ransomware and Microsoft’s BitLocker, which is full of this encryption.

they’re both encrypting your hard drive. One is like recommended security practice. The other is, the other is obviously a hack, right? You don’t want ransomware, but you want to full disk encrypt your software, your hard drive. So we have that context to help us automatically determine, okay, what’s actually intended for this particular software?

Federico Ramallo (52:47.949) right right so basically what you’re doing is you’re generating signatures for every function right so that way you say okay i analyze this i know how this works so if this changes then i’m going to have to run the analysis again right to see if if it doesn’t the behavior there the functionality has changed or not

Andrew Hendela (53:13.934) Essentially, yeah, we do that at like different levels. So we do it at the function level, we do at the binary level, we do it at what we call a collection or like a scan level where it’s like, hey, here’s an entire package. How is, how is, how are behaviors changing at that level, which is potentially different. And then we, that way we can analyze, okay, well, this one library within this bigger package is actually the thing that looks suspicious rather than something else that’s doing something normal.

Federico Ramallo (53:45.263) I see. I see. So by package, you mean a lot of files and a lot of binaries that are somehow related, right?

Andrew Hendela (53:53.102) Yeah, think, you know, installer, a Docker container, a Debian package you get to move on to. So it’s like this, this whole like idea of, you know, individual pieces of software back packaged together is like normal across the ecosystem.

Andrew Hendela (54:14.222) Cause like, you know, each software is going to have a ton of libraries, like depending on how well it’s constructed. So you have to be able to handle that.

Federico Ramallo (54:26.017) I work a lot, I build applications in Ruby and JavaScript, you and I used to do .NET, I used to do, you know, Java many years ago, right? But anyway, it’s a, and those are more corporate tools, Where they have, you can build this,

these packages and that’s the application. So they have less dependencies to the outside world. But with Ruby, and particularly with JavaScript, every time you want to build your application, it has to download, I don’t know how many libraries, hundreds of libraries that you don’t know what they’re doing. So it has been this trend of more and more dependency.

Andrew Hendela (54:58.904) Mm-hmm.

Andrew Hendela (55:18.264) Yep. Yep.

Federico Ramallo (55:24.259) I would say codependency on libraries and packages, right? So it’s very interesting that you are able to get everything together and just analyze it before it runs.

Andrew Hendela (55:41.42) Yeah, I mean, the other reason we want to do it before it runs, because if it runs and it’s bad, now you have to deal with all of the repercussions of running something that’s Whether it’s a, know, Bitcoin miner that seems to seems to pop into libraries sometimes versus like something taking your data. Once something’s running, it’s running. And then you have to like, where did it go? Let me pull that out. know, Docker containers like, hey,

Where’s that running in the cloud right now? I, can I pull that down? Can I stop it?

Federico Ramallo (56:17.239) Right, right. At one point I was imagining your approach of, you you put it in a cage and you see how it behaves, right? But I can understand that, you know, how that could be, you know, dangerous, right?

Andrew Hendela (56:25.848) Mm-hmm.

Andrew Hendela (56:34.434) I mean, it can be dangerous. Anytime you’re dealing with something that could be malicious, it’s going to be a little dangerous.

Federico Ramallo (56:43.149) Right.

Andrew Hendela (56:44.43) It’s like you’re running it in a virtual machine, which is pretty common if you’re doing malware detonation. Well, there’s ways of getting out of virtual machines if you have a good exploit.

Federico Ramallo (56:58.072) there are ways to get out of virtual machines. Interesting. Yeah.

Andrew Hendela (57:00.418) I mean, kind of anything is possible if you get an exploit.

Federico Ramallo (57:04.495) Yes, yes. And we come back to this, like, eventually, you you’re at a point where you don’t trust anything, know, any libraries, anything, right? Because you can’t, right? You shouldn’t.

Andrew Hendela (57:21.09) You, one of the things I like to say is you need to be.

little paranoid. Not entirely paranoid, but you know, being a little paranoid about what’s going on in the internet is probably better than trusting everything.

Federico Ramallo (57:28.687) You

You

Andrew Hendela (57:41.634) Maybe healthy paranoia.

Federico Ramallo (57:45.095) I think paranoia is healthy if it’s a little bit. It’s like salt, know, we’re talking about salt before, right? A little bit is fine, you But it shouldn’t consume you, Yeah.

Andrew Hendela (57:50.848) Right.

Yep.

Yeah. It’s like, sometimes I get things, I get emails and I’m like, okay, I know this is actually legitimate, but it looks so wrong.

Federico Ramallo (58:07.791) I got a mail. I can forward you the mail because it’s funny. And basically they say, know, it says my phone number, my address, and I says, I know I could reach you to this phone number or I could go to your house at this address, right? And I know what you’ve been doing and I know you’ve been doing naughty things. You know, he kind of implies, you know, that.

he can access to my wifi or whatever. And then you have to send me whatever bitcoins, or I will publish everything you’ve been doing. I would expose you. The thing is, they don’t know that I don’t live in that address, but that’s the address registered to my data. So it’s very interesting. So I read it and I laugh. Yeah, yeah.

Andrew Hendela (58:55.7) Mm-hmm. Right.

Andrew Hendela (59:04.568) Right.

Federico Ramallo (59:06.543) And I’ve got like three different, because I have different addresses for different things, you know, and, you know, I’ve got the same email from, you know, for different situations, right.

Andrew Hendela (59:12.748) Right.

Andrew Hendela (59:17.262) Three different emails from the same person. I know you’re this person at this address. I also know you’re this different person at this different address.

Federico Ramallo (59:22.745) Right.

Federico Ramallo (59:26.991) Yeah, yeah, So yeah. We’re a little bit over time, so I apologize. We can wrap up with one last question, if you like. What are your goals or what do you dream to accomplish this 2025, which just started nine days? January 9, so nine days ago.

Andrew Hendela (59:32.052) Yeah, no worries.

Andrew Hendela (59:48.91) Just nine days ago. Yeah, I mean, for 2025, it’s been a…

think the things we were talking about early are like balance, right? Like, I have a family, I have a company, and making sure that I’m what I want to accomplish is be intentional and present wherever I am. So like, okay, I’m, I’m working right now with, I’m gonna work, work hard, okay, I’m gonna go with my kids, or would be with them. And that way, that way I can be be content, right? I can do the things that I can do.

Because there’s only so much anyone person can do. So if I can do that, if I can help grow my company so that I can be able to help more people, if I can show my kids and my wife that I love them and I want to take care of them, those are the two main things for me right now.

Federico Ramallo (01:00:44.975) That’s beautiful. That’s beautiful. Hopefully with, you know, by putting it out there, it’s, you know, it’s closer to become a reality, right? Yeah. And if I can, if I can help in any way, you know, just let me know, right?

Andrew Hendela (01:00:52.654) You

Andrew Hendela (01:00:57.294) Hopefully.

Andrew Hendela (01:01:02.71) Absolutely. All right. I appreciate it.

Federico Ramallo (01:01:07.735) It was great to have you, Andrew, and I’m looking forward to talk at another time and see how you’re accomplishing all these dreams, which are amazing.

Andrew Hendela (01:01:21.87) It was great to be here. Thank you so much.

Federico Ramallo (01:01:25.593) Thank you.

Presented by Density Labs. We help mid-market companies ship AI to production, not demos. New: Agentic AI, explained from production — what an AI agent actually is, and when a workflow ships instead.
Don't miss it

Listen on your favorite app