7 ms·
Carbon Black S-1
- rm_-rf_slash 8y agoFive years ago all the chatter was about private financing being the “new” normal for tech, as it offered closer control with fewer disclosure requirements. Companies like Uber were raising insane amounts of private money while thumbing their nose at public markets. Now all of a sudden it seems there’s a new IPO filing every week or so. Does this indicate a stronger economy and/or pressure from shareholders to allow their investments to become more liquid, or are people smelling a downturn around the corner and hoping to cash out before valuations drop?
- TAForObvReasons 8y agoIt's a confluence of all of those factors: - Dropbox demonstrated a reasonably strong market for IPOs, so it's definitely safer for other companies to get in before the first flop. - There's probably a lot of pressure to go public, seeing as how many of these companies have private for more than a decade [1] - There's also reason to believe we may see pressure in the equity markets in the near future, especially as the Fed adjusts interest rates. [1] https://www.crunchbase.com/organization/bit9/funding_rounds/funding_rounds_list#section-funding-rounds https://www.crunchbase.com/organization/bit9/funding_rounds/... Series A was in 2005
- toomuchtodo 8y agoIt seems like a terrible time to put your org's shares into the public market, so late in the business cycle with the eventual downturn looming. EDIT: Agree that if you must go public, go before the music stops. I'm wrong here.
- positr0n 8y agoSurely now is preferable to during the downturn when you'll get half the value for the same percentage of your company? (Assuming of course that you and I are correct that a downturn is looming).
- deleted 8y ago[deleted]
- sqldba 8y agoYou’ll get half the value and it remains stable - versus you get twice the value and then it suddenly nosedives and everyone questions your performance as CEO because “you must have made it happen”. Is that possible?
- icedchai 8y agoNow's the perfect time. We're near the peak, so valuations are very inflated.
- freehunter 8y agoPersonally I think it's both. We're seeing companies that normally would have gone public (enterprise software like Carbon Black) at the appropriate time, combined with some companies where it makes little sense to go public (Spotify, Snapchat) that I think are cashing in before the bottom drops out. Carbon Black has nowhere to go but up, they're destroying the AV industry and every security consultant I know is pushing this style of endpoint protection over traditional AV. And they're in the enterprise market, so they can charge big bucks. Spotify on the other hand is one player in a crowded and competitive market with some huge players who could destroy them in a heartbeat. And even with their exclusives and much bigger subscriber count, they're still struggling to beat much smaller competitors in actual engagement [1] (or at the very least struggling to properly count their streams which seems like a basic requirement). It makes little sense for them to go public when they could just as easily be out of business this time next year. [1] https://www.theverge.com/2018/4/3/17192342/apple-music-the-weeknd-my-dear-melancholy-spotify https://www.theverge.com/2018/4/3/17192342/apple-music-the-w...
- TAForObvReasons 8y agoSpotify was "forced" into IPO in a way: https://www.recode.net/2018/1/3/16847786/spotify-tpg-tencent-debt-dragoneer-ipo-music-streaming https://www.recode.net/2018/1/3/16847786/spotify-tpg-tencent... > In 2016, TPG, Dragoneer and Goldman Sachs lent Spotify $1 billion via convertible debt financing, which was supposed to give the lenders the ability to eventually turn their loans into equity. > The deal let Spotify bide its time before an IPO, but not too much time: The longer Spotify took to go public, the better the terms would get for the lenders. News emerged Wednesday that the company had confidentially filed IPO documents in late December.
- ocfx 8y agoCylance is doing a lot better.
- woolvalley 8y agoAs a carbon black victim who gets angry at CB consuming %50 of my CPU in the kernel as I do builds that touch many small files, it just feels like a combination of corporate spyware/rootkits, traditional antivirus and uploading that info to a backend. Am I wrong? Why hasn't traditional AV created a similar product then?
- guiomie 8y ago"Endpoints are the new front line in the cyber war, and organizations are shifting their defenses as a result" ... what do they mean by 'endpoint' ?
- bauer 8y agoComputer systems end users access web/email with. I deployed Bit9/Carbon Black a few years ago.
- chadbennett 8y agoEach node or computing device is an endpoint. Endpoint security is the new industry terminology for antivirus/antimalware/etc.
- tptacek 8y agoIt's a very old term; endpoint security is in contrast to network security, where you try to block bad things at network boards. Firewalls are the archetypical network defense, antivirus (very unfortunately) the archetypical endpoint defense; osquery would be an example of a modern open-source endpoint security tool.
- mischifous 8y agothoughts on CarbonBlack or Palo Alto’s Traps? Separate category, but what about OKTA?? (I hear they are crushing it) Do you think what ServiceNow is doing in ITSM is really special?
- deleted 8y ago[deleted]
- danpalmer 8y agoIt's often got quite a different focus to antivirus/anitmalware, a lot more about identifying and preventing data exfiltration for example.
- deleted 8y ago[deleted]
- CSDude 8y agoI deployed Carbon Black, and it seems a nice enough product. But it seems to generate too many programming related false alarms. Well, they could at least identify when I used ncdu on / and thought it was a crypto-locker, which is nice.
- wglb 8y agoI have heard that if you get Red Canary, they offer a service on top of Carbon Black to give a higher level of intelligence. This will likely help.
- eitally 8y agoAs long as Windows machines sit on employee desktops, there will be a compelling need for things like Bit9/Carbon Black. I helped with an enterprise deployment a few years ago and -- except the rule tweaking that required quite a lot of trial and error* -- it works as advertised. * There wasn't really any "error", per se. It was really just a trial in deciding how much the CIO/CISO was willing to deal with knowing about, versus remaining ignorant by choice since that was far less work. Given where they ended up, I'm not sure whether the millions spent on the software was a smart business decision. <banghead>
- P38 8y agoNext gen AWL/Endpoint solutions offer a simple and true default deny approach. Either an app (executable, script, dll) is trusted or it isn't. If it is not trusted it can't run - period. 100% successful at preventing zero day attacks and Shattered attacks and even malware that isn't written yet... Trusted apps are cyber fingerprinted using 6 hashes - in order to use a Shattered like attack all 6, including file length would need to be simultaneously crashed. No rules are required, no scanning is needed, instant protection on installation and can be managed/administered by non-technical staff. Can use an out of the box trust list with over 1000 apps already fingerprinted or build own trust list. Can be deployed using standard tools and is scalable to global enterprise.
- cobbzilla 8y agoAre you assuming no one ever finds zero-day vulnerabilities in "trusted" code? What happens when a piece of code that you trust is compromised in a way you didn't expect?
- FreakLegion 8y agoThey're talking about malware, not exploits. It's a habit of the non-technical side of the industry and means 'this hash hasn't been seen before'. Given the phrasing -- "Apps" are "cyber fingerprinted", hashes are "crashed" -- I'd guess the post was written by a marketer or SE.
- P38 8y agoWe are talking about file-based malware that needs to execute. It doesn't mean this hash hasn't been seen before, it means that application X which is trusted, is on the trust list (and yes, fingerprinted by 6 hashes) is allowed to run. Application Y which is not on the trust list is blocked from running. That malware can't get on the trust list (unless by a malicious admin) and therefore can't run. A zero day exploit that allows the injection of malware onto an endpoint for example, doesn't really matter as the malware can't run. How application Y got there, is irrelevant. It could have come from any attack vector.