alphalist.CTO Podcast - For CTOs and Technical Leaders

alphalist.CTO Podcast - For CTOs and Technical Leaders

By Tobias Schlottke - alphalist CTO PodcastBusinessEntrepreneurshipTechnologyManagement
Download on the App Store

alphalist.CTO Podcast - For CTOs and Technical Leaders episodes

  • #147 "Make It Secure" Isn't a Prompt: A L0pht Hacker on Securing AI-Written Code with Chris Wysopal // Chief Security Evangelist @ Veracode
    Nearly three decades after telling the US Senate the internet could be taken down in 30 minutes, the L0pht veteran explains why AI has made attack sophistication meaningless as a signal, and why the real fix is giving your models security intent before the code is written.
    Chris Wysopal was one of the first hackers to go public. As "Weld Pond" at the L0pht hacker collective in Boston, he testified before the US Senate in 1998, where the group delivered the soundbite that they could take down the internet in 30 minutes. He also wrote the Windows version of Netcat. In 2006 he co-founded Veracode, which by his account has now analysed trillions of lines of code. Today he's the company's Chief Security Evangelist.
    Tobi and Chris talk about what AI changes for attackers and defenders. Attacks are getting cheaper and faster, and a custom exploit no longer tells you a nation-state is behind it. Chris argues this follows a familiar cycle: attackers adopt a new class of tool first, defenders catch up, and parity returns. That only holds if defenders actually adopt the tools, especially underfunded organisations like hospitals, schools and utilities. They also cover the new attack surface created by agents, plugins and MCPs, why prompt injection may never be fully solvable, and how Chris would handle security debt when acquiring a small SaaS company.
    CTOs will leave with a concrete shortlist: avoid memory-unsafe languages, put a package firewall in front of open source, run AI-assisted static analysis with real architectural context, and give coding agents explicit security intent rather than hoping "make it secure" does the job.
    - From the L0pht and BBS culture to the professional security industry
    - The BGP flaw behind "30 minutes to take down the internet"
    - How AI changes the cost and speed of attacks
    - Prompt injection, agents, MCPs and least privilege
    - Security debt in B2B SaaS acquisitions
    - Secure on first write: security intent, context and pre-merge testing
    - How engineering and security roles change over the next two years
    1 hr 14 min
  • #146 AI Found What Nine Years of Security Research Missed with Charles Guillemet // CTO @ Ledger
    Ledger's CTO on vulnerability discovery, security-by-design, key management and AI-native engineering.

    Charles Guillemet started hacking at 12. He sold his piano to buy his first computer. Nine years ago, he built Ledger's offensive security team from scratch; today, he's CTO of a company protecting a fifth of the world's crypto, and he just watched AI find vulnerabilities his team spent almost a decade not finding.

    Topics covered:

    • The economics of security — and why AI is breaking them
    • Ledger's three layers of security, and what The Donjon actually does
    • Turning a security problem into a key management problem
    • Charles's recommendation for restructuring engineering teams around AI and "harness engineering"
    • Zero trust, bus factor, and protecting a company's "crown jewels"
    • Using AI to build a threat model and cut noise from production signals
    • Why Charles believes the CISO function should stay independent
    • Timestamps:

      [00:00:51] Intro & guest welcome
      [00:01:21] Charles's nerd origin story — hacking at 12
      [00:03:33] From software hacking into hardware security
      [00:04:45] Ledger's security org today: hardware vs. software
      [00:08:48] The three layers of security at Ledger — and The Donjon
      [00:13:28] The AI vulnerability that broke 9 years of research
      [00:14:47] Security as economic asymmetry — and why AI is collapsing it
      [00:18:31] Why blockchain attackers already spend big to break in
      [00:20:51] Is prompting AI to "find vulnerabilities" enough?
      [00:23:48] Security-by-design and turning security into key management
      [00:26:00] Does AI kill the CTO/developer job — or redefine it?
      [00:30:40] Rebuilding an SDLC: Charles's small-team, harness-engineering recommendation
      [00:36:22] Building a threat model with AI
      [00:38:58] Zero trust, bus factor, protecting the crown jewels
      [00:42:36] Using AI to cut through noisy production security signals
      [00:47:04] "Average is better than nothing" — the Wikipedia analogy
      [00:48:00] Why Charles thinks the CISO function should stay independent
      [00:49:09] The Easter egg question — advice to his 2017 self

      What you'll learn:

      • Why the old economics of security are breaking down — and what that means for your own threat model
      • A concrete way to turn any security problem into a (much easier) key-management problem
      • Charles's recommendation for restructuring engineering teams around small, AI-native pods and "harness engineering"
      • What zero trust looks like in practice when developers bring their own devices
      • How to use AI to build a threat model and cut through noisy production security signals
      • Quotes:

        ⭐ [00:14:22] "The cost of finding vulnerabilities is trending towards zero."
        ⭐ [00:26:21] "If they think they will continue writing code, yes, they will lose their job."
        ⭐ [00:23:39] "If you just prompt like crazy — implement this database, implement this feature — and at the end just prompt, 'please find vulnerabilities,' it's something, but it won't solve the security problem."
        [00:14:47] "Security is a matter of creating an imbalance, an asymmetry between attacks and defense."
        [00:41:21] "More and more attackers go through the developer door, trying to compromise the endpoint of one developer and then leverage his access to production."
        [00:47:14] "Some people say AI is only producing average results, but sometimes average is better than nothing."
        [00:39:19] "If a human has full access to a system he doesn't need, that also means the malware running on his computer has the same access."
        (All quotes lightly cleaned of stutters/filler — verify against final audio.)

        Links:

        • Ledger: https://www.ledger.com
        • Ledger Donjon (security research team): https://donjon.ledger.com
        • Meet Cerberus — Ledger Donjon's AI security harness: https://www.ledger.com/blog-cerberus-donjon-ai-harness
        • Charles Guillemet on LinkedIn: https://fr.linkedin.com/in/charles-guillemet
        • Want to keep talking about this with other CTOs? Join over 600 tech leaders in our Slack community — go to alphalist.com to apply.

          55 min
        • #145 "Harness Writing Is Not Hard": Build to Learn, Not to Run with David Soria Parra // Member of Technical Staff @ Anthropic
          David Soria Parra on why he'd build a custom agent harness only to understand it, not to run it,and why the industry's MCP-vs-CLI debate misses the point entirely.

          BROUGHT TO YOU BY: Blocks

          Sponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026

          David Soria Parra co-created MCP, used to help write Mercurial, and now works alongside the people building Claude at Anthropic — so when he says building your own AI agent harness isn't actually that hard (but probably isn't worth doing anyway), it's worth sitting with. This one's a grounded, unhyped look at what to actually build versus configure.

          Topics covered:

          • David's nerd origin story: a PHP guestbook at 13 and a very expensive ISDN phone bill
          • From Mercurial core contributor to Meta's internal source control team
          • What Meta and Anthropic both get right by running on almost no process
          • David's personal setup — a handful of skills, a few MCP connectors, staying "vanilla"
          • Why his workflow moved from Claude Code sessions into Slack threads with Claude
          • The real MCP-vs-CLI debate, and why it isn't actually a debate
          • Should every CTO or engineer build their own agent harness?
          • What's still defensible in software engineering as agents get stronger
          • Smart-home and hardware side quests: securing a UniFi network, hacking a coffee machine
          • Closing time machine question, via Mercurial's own abandoned time-travel Easter egg
          • Timestamps:

            [00:00:51] Intro and guest background
            [00:02:39] David's role in creating MCP — "one of the co-creators"
            [00:03:24] David's nerd origin story — a PHP guestbook at 13
            [00:08:32] From application development to obsessing over tools and infrastructure
            [00:09:38] Joining the Mercurial community
            [00:12:39] How Mercurial led to Meta
            [00:14:30] Biggest lessons from Meta — optimism, incentives, and minimal process
            [00:20:15] Senior vs. junior engineers in the AI era
            [00:22:26] Why high agency matters more than learning a narrow craft
            [00:23:13] How Anthropic organizes teams in a fast-moving field
            [00:25:46] Loose org process vs. strict model-safety process
            [00:29:15] David's personal setup: Claude Code, a handful of skills, MCP connectors
            [00:30:09] Personalized skills — writing voice and multi-agent code review
            [00:32:05] Combining CLIs, MCP servers, Slack, and Linear
            [00:33:00] Why his workflow moved from Claude Code sessions into Slack threads
            [00:34:56] Permissions and compartmentalization for company-wide agents
            [00:38:34] David's private setup — Herder, Pi, and running multiple agents
            [00:45:55] Context selection, RAG, Obsidian, Git, files and folders
            [00:47:42] General-purpose agents vs. custom automation — where each wins
            [00:49:38] Why he'd build a harness to understand it, but not run one
            [00:52:43] The new age of custom software — workout apps, home inventory, recipes
            [00:53:31] Reliability, and the ongoing case for buying software
            [00:55:14] How software engineering roles may shift, and what stays defensible
            [00:59:38] New software possibilities for smaller organizations
            [01:00:02] MCP today: the co-creator's view on his own invention
            [01:02:18] The real MCP-vs-CLI debate — and why it isn't actually a debate
            [01:04:27] Why building an internal MCP registry is "the better investment"
            [01:06:02] What to check for when evaluating an agent-connectivity vendor
            [01:06:57] Smart-home and hardware side quests — UniFi, coffee machines, and Bluetooth
            [01:10:09] David's closing recommendation: stop optimizing your setup
            [01:13:00] Talk to customers instead of building a software factory (unattributed exchange — see quote flag)
            [01:13:38] Outro: the "hq shelf" Mercurial Easter egg
            [01:14:51] What David would tell his younger self

            What you'll learn:

            • Why "harness writing is not hard" — and what actually separates a good agent harness from a mediocre one
            • When to reach for MCP vs. a CLI (and why the industry debate between them misses the point)
            • How Meta and Anthropic both run on almost no internal process — and what that requires of the people you hire
            • Why David moved his entire day-to-day workflow from local Claude Code sessions into Slack threads
            • What to check for in a vendor contract if agent connectivity matters to you
            • A grounded gut-check for anyone convinced they need to build a custom "software factory"
            • Quotes:

              "A lot of my workflows nowadays are: 'Hey Claude, can you look into this thing, review it, figure out what you feel about it — make an adversarial review — and come back to me.' Or, 'I need to change this over here, implement this new feature, go do it, and come back when you have a review.' A lot of my interaction moved away from Claude Code sessions to threads in Slack where I interact with Claude, and Claude does the thing for me." — [00:33:00] (cleaned of filler/false starts — verify against audio)

              "You don't need only MCP. You need also MCP, but you also need CLIs… Enterprises in particular love centralized things they can control via gateways in the middle. MCP is great if you need to govern the whole thing. But if you're running a local harness for your own development, running CLIs is perfectly fine. They both will be needed — they're just different for different use cases." — [01:02:42]

              "Harness writing is not hard. It gives it a bunch of tools, gives it a bunch of execution steps, be a little smarter about context selection, and go for it. It turns out the model does 90% of the work." — [00:50:00] (cleaned of stutters — verify against audio)

              "The main recommendation is not to over-focus on optimizing your setup. This is a very fast-moving technology — you don't need to fiddle with everything. Pick one or two things you find useful, be it Claude Code, be it Claude Tag, and just focus on using it quickly, optimizing for as little downtime as possible so you can get stuff going." — [01:10:53]

              Relevant links:

              David Soria Parra on LinkedIn: https://www.linkedin.com/in/david-soria-parra-4a78b3a
              Model Context Protocol: https://modelcontextprotocol.io
              Mercurial: https://www.mercurial-scm.org
              Pi coding agent (by Mario Zechner): https://pi.dev
              Anthropic: https://www.anthropic.com

              Join the conversation with 600+ CTOs sharing insights on technical leadership and tech trends in the alphalist Slack. Visit alphalist.com to apply.

              OUR SPONSORS

              Sponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026

              1 hr 18 min
            • #144 Writing Code Is No Longer the Job: Dana Lawson on Trusting AI Agents Like Self-Driving Cars // CTO @ Netlify
              Why CTOs should stop asking whether they trust AI agents and start asking when that trust becomes automatic, and where human judgment still has to hold the line.

              Sponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026

              Dana Lawson, CTO at Netlify, joins Tobi for a candid conversation about the changing role of software engineers in the age of AI agents.

              Dana's path into technology began in the US Army in the late 1990s. She started by managing backup tapes and automating manual workflows before moving on to engineering leadership roles at GitHub and Netlify.

              The conversation explores why Dana believes "writing code is no longer the job," how AI agents are changing software development, and why trust in agents may eventually become as automatic as trusting a car we cannot repair ourselves.

              Topics covered

              Dana's path from the US Army to GitHub and Netlify

              How automating password resets sparked her interest in software
              Why Dana argues that writing code is becoming a commodity
              The Hacker News reaction to her article, "Writing Code Is No Longer the Job"
              The self-driving car analogy for trusting AI agents
              Why "agent experience is human experience"
              How Netlify is adapting its platform for an agentic future
              The shift from writing code to defining architecture and guardrails
              The tension between speed, control, reliability, and safety
              Whether developers could become the bottleneck
              Why the key constraint may be moving from "can we build it?" to "does anyone actually want it?"
              The future of developer experience, CMS platforms, databases, and the web

              Timestamps

              [00:00:51] Introduction and Dana's background

              [00:01:44] Dana's path from art school to the US Army
              [00:03:51] Backup tapes, automation, and the origins of her DevOps mindset
              [00:06:03] Moving to GitHub and learning to operate at scale
              [00:08:33] How AI could change GitHub and the software development lifecycle
              [00:12:18] The self-driving car analogy for trusting AI
              [00:16:20] AI, productivity, and whether more software is always better
              [00:19:43] Dana's "30 apps in 30 days" challenge
              [00:20:00] "Writing Code Is No Longer the Job" and the Hacker News backlash
              [00:25:00] Craftsmanship, abstraction, and the changing role of developers
              [00:30:28] Control, governance, and building for the future
              [00:33:59] What the agentic shift means for Netlify
              [00:37:53] From developer experience to agent experience
              [00:39:02] The future role of DevOps, SRE, and release engineering
              [00:49:11] CMS platforms, databases, and the future of the web
              [00:53:19] Dana's side projects and what people actually want
              [00:55:38] The closing time-machine question

              What you'll learn

              • Why AI agents may change the entry point into software development
              • Where human expertise remains essential
              • How engineering teams can think about guardrails and safe deployment
              • Why product judgment and demand may matter more than implementation speed
              • How platform teams can create better experiences for both agents and humans
              • About Dana Lawson

                Dana Lawson is the CTO at Netlify. Before joining Netlify, she was VP of Product Engineering at GitHub. She began her technology career in the US Army, where she developed an early interest in automation and infrastructure.

                Relevant links

                • Netlify: https://www.netlify.com
                • Dana Lawson's article, ["Writing Code Is No Longer the Job"]
                • alphalist Slack community: https://alphalist.com/apply
                • alphalist events and community: https://alphalist.com
                • Join alphalist

                  Are you an experienced CTO or engineering leader? Join more than 600 CTOs sharing insights, challenges, and practical advice in the alphalist Slack community. Apply at https://alphalist.com/apply

                  Sponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026

                  1 hr
                • #143 The Company Brain: How Kombo Runs on a Git Repo and a Cursor Agent — with Aike Hillbrands, Co-Founder & CTO @ Kombo
                  A GitHub repo, a Cursor cloud agent, and a public Slack channel replaced Notion AI at a $25M-funded HR integration startup, and became the whole company's shared brain.

                  BROUGHT TO YOU BY: Blocks

                  Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026

                  Two failed startups, a Y Combinator batch, and a $25M Series A later, Aike Hillbrands and his co-founders built Kombo into a $10M+ ARR HR integration platform, and then, almost by accident, built a company-wide AI brain out of a GitHub repo and a Cursor agent. Aike joins Tobi to explain why files and grep beat MCP tools for agent reliability, what the "lethal trifecta" of AI security actually means in practice, and why he doesn't think AI will commoditize his own business anytime soon.

                  chapters:

                  00:00:00 — Intro

                  00:01:00 — Meeting his co-founders at CODE University
                  00:03:00 — Founding Kombo — the YC S22 pivot
                  00:04:00 — Nerd origin story: graphic design, Delphi, and Windows Forms games
                  00:06:00 — Selling an early company, and the open-source interception tool
                  00:08:00 — The Workday pain point that became Kombo
                  00:10:00 — Grayish markets: intercepting API traffic, and when it's not worth it
                  00:12:00 — Team size, the $25M raise, and staying a bootstrapper at heart
                  00:14:00 — From Notion AI to a company-wide brain
                  00:16:00 — Why the MCP experiment failed — and files + grep won instead
                  00:18:00 — Eliminating the "ask an engineer" bottleneck
                  00:20:00 — Two hours to build the repo, five minutes for Slack
                  00:22:00 — Linking files together so the agent connects the dots
                  00:24:00 — Public-by-default culture, and what data they'd feed the brain
                  00:26:00 — Exposing the company brain to customers
                  00:28:00 — The "lethal trifecta" framing, and why the market isn't investing enough
                  00:30:00 — The scariest failure mode: exfiltration, not just leaks
                  00:32:00 — The wife/prompt-injection story
                  00:34:00 — Why the risk can't be zero — and the "blue worker suit" analogy
                  00:36:00 — Public Slack as a social guardrail against prompt injection
                  00:38:00 — Shopify's "River" and Tobi Lütke's Lehrwerkstatt
                  00:40:00 — Buy vs. build: is anyone doing this well already?
                  00:42:00 — An internal app store made of markdown files and PRs
                  00:44:00 — Will AI commoditize Kombo's own business?
                  00:46:00 — Why enterprise integrations resist commoditization
                  00:48:00 — Integration teams of 10–15 people, and Kombo's end-to-end bet
                  00:50:00 — Is SaaS dying? System-of-record inertia
                  00:52:00 — What actually changes vs. what doesn't
                  00:54:00 — Time travel: advice to his younger self
                  00:56:00 — Outro

                  Quotes:

                  00:17:29 – "The agent will just run a grep command and find 200 files where something is discussed, and it will actually look at 50 or so of them. It's not stopping too early." (verbatim)

                  00:24:26 – "We also share with employees the money in our bank account monthly. This is the kind of public-by-default that we run."
                  00:35:52 – "By having it in the Slack channel, our people see what the customer is doing with the agent, but also the colleagues of the customer see what's going on. That's reducing the amount of exploiting you can do, by a lot, just because other people have visibility."
                  00:32:14 – "My wife accidentally prompt-injected it without any bad intention. Now imagine people with bad intentions." (Tobi)

                  58 min
                • #142 Why LLMs Need Their Own Programming Language: From Assembly to AI with Vaibhav Gupta // Co-founder @ BAML
                  From HoloLens assembly to AI: Vaibhav Gupta on why LLMs need their own language, and how BAML makes them type-safe and shippable at agent speed.

                  BROUGHT TO YOU BY: Blocks

                  A decade building computer vision and writing assembly at Microsoft (HoloLens), Google, and D.E. Shaw, then a from-scratch bet on a programming language built for LLMs. Vaibhav Gupta joins Tobi to explain why probabilistic compute needs its own tooling, what "shipping at agent speed" actually requires, and why the world's appetite for software is mathematically infinite.

                  Chapters:

                  00:00:00 — Intro
                  00:01:00 — From HoloLens to D.E. Shaw: a decade in computer vision and assembly
                  00:02:00 — Starting from scratch, and the YC pivot ("500K to not build a Slack competitor")
                  00:04:00 — Falling in love with coding — and bricking a few machines along the way
                  00:06:00 — His first AI moment: the GPT-3.5 wake-up call
                  00:09:00 — Code as a means to an end — why 90% of the job is plumbing
                  00:11:00 — Why he decided to build a language: first principles and BAML
                  00:13:00 — LLMs as a new compute primitive
                  00:15:00 — What BAML actually is — embedded, type-safe, callable from any language
                  00:17:00 — The business model and the "data trench"
                  00:19:00 — When AI ships code you didn't ask for — and why CI/CD breaks in an agent loop
                  00:22:00 — Live demo: function versioning and locking the codebase
                  00:24:00 — Why no one else competes here — Protobuf, Thrift, and Google's playbook
                  00:29:00 — Getting started: the BAML "hello world" (live coding)
                  00:32:00 — Everything is a function — type safety that runs in Rust
                  00:36:00 — Shipping at agent speed = trust plus granular control
                  00:38:00 — Visualizing code instead of reading it
                  00:44:00 — Where to start with BAML (docs.boundaryml.com → Agents MD)
                  00:45:00 — The mathematically infinite appetite for software
                  00:47:00 — Why we'll have 10x more builders — and why "English isn't a programming language"
                  00:51:00 — The future of SaaS: PaaS, harnesses, and customer-defined models
                  00:56:00 — Will design matter more in an agent world?
                  00:59:00 — The "time travel" decorator: advice to his 2017 self
                  01:04:00 — Outro

                  Quotes:

                  00:13:00 — "BAML's a new thing that exists because we have a new compute primitive in the form of LLMs." (verbatim)
                  00:10:00 — "90% of software engineering — well, in most jobs, 100% of software engineering is plumbing… And AI just takes that 90%, just makes it go away."
                  00:19:00 — "We can now generate code at machine speed… But we still cannot ship code at machine speed."
                  00:49:00 — "English can't go down to assembly… And the minute you add that to English, what have you done? You've built a new programming language."
                  00:45:00 — "I don't think we've yet found a company that hasn't found that I can make more money if I write more code."

                  --

                  OUR SPONSORS

                  Blocks

                  Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at blocks.cloud/alphalist.

                  1 hr 5 min
                • #141 AI Pat Works Here Now: Why Agents Must Follow Human Rules with Pat Casey // CTO @ ServiceNow
                  ServiceNow's CTO of 20 years explains why the safest way to deploy AI agents is to treat them like employees, same rules, same approvers, same spending limits, and why AI is reshuffling the deck on who your best engineers are.

                  Intro

                  How do you go from installing software off floppy disks to running engineering for a $13B revenue company — without ever losing the fish? Pat Casey, CTO of ServiceNow and its first engineer after founder Fred Luddy, joins Tobi to talk 20 years of scale, the architecture behind 90,000 databases, and why enterprise AI agents should be treated exactly like slightly untrustworthy employees.

                  Key topics

                  • Pat's nerd path: Atari 400, Wizardry, and building Adobe's first employee tracking system in Microsoft Access
                  • Flipping off Fred Luddy in traffic — and becoming ServiceNow employee-after-one
                  • The stuffed-fish code-ownership system and why productivity dips at ~100 engineers
                  • Inside the architecture: Java metadata engine, hacked Rhino, K8s services, single-tenant clusters
                  • RaptorDB: from MariaDB board seat to buying Swarm64 and forking Postgres
                  • Gen 3 of AI coding: Windsurf vs Claude Code, the 15% average vs the 5x outliers
                  • The five-chessboards theory of AI-native engineering, and Pat's daughter's vibe-coding conversion
                  • "AI Pat": agents in the user table, following human rules
                  • Hybrid pricing: seats for humans, consumption for AI
                  • Is the market wrong about SaaS incumbents? Pat's answer to the Anthropic scare
                  • What Pat would whisper to his younger self (spoiler: it's about Jelly XML — and family)
                  • Chapters

                    [00:00:51] Intro: who is Pat Casey
                    [00:01:43] Nerd origin story: Atari 400, tape storage, Wizardry
                    [00:04:12] First job at Aldus/Adobe — accidental ITIL
                    [00:06:12] Flipping off Fred Luddy → joining Glide in 2005
                    [00:08:28] From 2 job titles to 10,000 engineers — the introvert advantage
                    [00:10:21] The stuffed fish, and the productivity trough at 100 engineers
                    [00:13:44] Architecture: metadata engine, Java monolith, Kubernetes
                    [00:16:41] The single-tenant bet: 90,000 databases, 25B queries/hour
                    [00:21:32] MariaDB, Monty, and building RaptorDB from Swarm64
                    [00:27:21] Postgres fork, OpenJDK contributions, open-sourcing Raptor?
                    [00:29:35] AI coding gen 1–3: Copilot → 7,000 Windsurf licenses → Claude Code
                    [00:33:35] Five boards of chess: who clicks with AI coding (and who doesn't)
                    [00:36:47] Pat's daughter and the vibe-coding conversion
                    [00:38:21] Enterprise agents: from toolkits to outcomes
                    [00:40:41] "AI Pat": agents that follow human rules
                    [00:42:29] Pricing: seats for humans, consumption for AI
                    [00:46:15] The Anthropic scare, SaaS valuations, and the incumbent advantage
                    [00:53:06] The new bottleneck: not engineering, not product — customers
                    [00:59:00] Pat's advice to CTOs: lean in, don't turf it
                    [01:01:26] Time machine: what Pat would whisper to his 2005 self

                    Quotes

                    [00:41:30] "You should not trust an LLM more than you trust a human being. Modern business processes were designed on the assumption that human beings are a little bit untrustworthy." (fillers removed — verify against audio)

                    [00:34:00] "AI coding, if you get to that next level, is like playing five boards of chess, 'cause you got multiple prompts spinning at the same time." (one "um" removed)
                    [00:16:04] "If it was that easy, none of the world's big monolithic code bases would still exist." (condensed from "It's like, all right, if it was that easy, like, none of…" — verify)
                    [01:01:26] "This is not a time for excessive caution. It's not a time to completely go bonkers and do crazy stuff, but this is a time really to lean into the new technology." (one "uh" removed)

                    1 hr 7 min
                  • #140 From Stripe's Fifth Engineer to Serving Millions of Developers with Anurag Goel // Founder & CEO @ Render Goel
                    Anurag Goel was Stripe's fifth engineer before he built Render into a platform millions of developers deploy on. Here's his contrarian read on agents, security, and why "the AI cloud" is the wrong thing to be.

                    Show Notes

                    Anurag Goel joined Stripe as its fifth engineer in 2011 and later ran risk. He left to solve a big problem and landed on the one he'd watched eat Stripe's engineering time: making infrastructure disappear. This conversation is about what Render learned on the way to millions of developers and what changes now that a lot of what gets deployed isn't a website, it's an agent.

                    *
                    Key topics:*

                    From Stripe's fifth engineer to founding Render

                    The "application cloud" vs. "AI cloud" positioning
                    Agents as long-running, stateful applications for a new end user
                    Workflows, sandboxes, and the consolidated AI runtime
                    Executive hiring and reference calls as a growth hack
                    Security: minimizing blast radius, short-lived scoped keys
                    Distribution in the chatbot era (GEO) and why Google is underrated
                    Observability is the real bottleneck for production agents

                    Timestamps

                    [00:00:00] Intro and the pitch

                    [00:02:00] Origin story: ebook search engine, game rentals, and the first-ever Stripe payment
                    [00:04:00] Joining Stripe as engineer #5; talent density
                    [00:06:00] Raising the hiring bar, no warm bodies
                    [00:11:00] Executive hiring and reference calls as a growth hack
                    [00:13:00] Why he started Render: ~20% of Stripe's engineers stuck on AWS
                    [00:16:00] Agents as a new kind of application
                    [00:17:00] "We're the application cloud, not the AI cloud"
                    [00:18:00] Workflows, sandboxes, and the consolidated AI runtime
                    [00:24:00] Heroku's decline and the exploding sales pipeline
                    [00:25:00] The agentic moment: when adoption spiked
                    [00:33:00] Security and blast radius
                    [00:50:00] Why SaaS isn't dying specialization
                    [00:58:00] Distribution: from SEO to GEO
                    [01:02:00] Why Google is underrated
                    [01:03:00] Advice for CTOs going all in on agents
                    [01:06:00] Easter egg: a whisper to his 2011 self

                    1 hr 13 min
                  • #139 Your Future Job Is a Decision Inbox — Max Deichmann Built the Layer That Gets You There // Co-Founder @ Langfuse
                    Max Deichmann built Langfuse — the open-source LLM engineering platform acquired by ClickHouse — and explains why the engineer of the future isn't writing code, they're reviewing what agents did overnight.

                    Max Deichmann didn't set out to build the observability layer for the AI era. He started with mobile apps, taught himself to code via Harvard's CS50, and ended up in Y Combinator with a SaaS product he wasn't excited about. Then ChatGPT launched, and on a Sunday night at 10 pm, his co-founder asked: "If you just had time, what would you build?" The answer became Langfuse and eventually led to an acquisition by ClickHouse.

                    This episode is a rare, grounded conversation about what building and operating AI agents actually looks like in 2025, from the engineering loop to the 3 am incident, to what the engineer's job becomes when agents are doing most of the execution.

                    Key topics:

                    • Why LLM applications broke traditional observability tools, and what Langfuse does instead
                    • The pre-production → production → evaluation → iteration loop for agent development
                    • Open source as a trust and adoption strategy for dev tools
                    • The ClickHouse acquisition: why they sold, what the half-page doc said, and how it's going
                    • Agentic incident response: copy-pasting alerts into Codex at 3 am, and what comes next
                    • The "decision inbox" engineers are reviewers and decision-makers, not coders
                    • The real state of agents in production: what's working, what's not, and what LinkedIn gets wrong
                    • Timestamps:

                      [00:00:00] Intro & guest welcome

                      [00:02:00] Max's nerd origin story CS50 on a beach in Singapore
                      [00:04:00] Why they pivoted to Langfuse: firing customers mid-YC batch
                      [00:06:00] Building the first AI products and discovering the observability gap
                      [00:07:00] What Langfuse actually does: the LLM engineering platform explained
                      [00:09:00] Tracking business AND infrastructure metrics billing via Langfuse
                      [00:10:00] Open source from day one: trust, adoption, and hardening the product
                      [00:13:00] Go-to-market with 1.5 salespeople: how engineers sell to enterprises
                      [00:14:00] The acquisition story: 5 engineers, 40TB/day, and a Series A that became a sale
                      [00:17:00] What it felt like when half the AI ecosystem knocked on their door
                      [00:18:00] Life inside ClickHouse: cultural fit, Tokyo offsite, and what surprised them
                      [00:20:00] Agentic coding in practice: velocity per engineer, what still needs a human
                      [00:22:00] The planning loop: Claude summarising GitHub discussions, RFC → agent → review
                      [00:23:00] The "decision inbox" model: engineers as taste-makers and reviewers
                      [00:27:00] How to build an observability stack for the agentic era from scratch
                      [00:29:00] Agentic on-call: the 3 am Codex workflow and what's coming next
                      [00:32:00] Where Langfuse fits vs. traditional observability agent quality vs. infra health
                      [00:35:00] The real state of agents in production: the non-LinkedIn version

                      Best quotes:

                      "We didn't initially jump on the topic because we thought all the PhD AI people, they are much better at this. We have no idea what's going on, until we figured out nobody has a clue what's going on." — [00:05:00–00:06:00]

                      "We have two guys doing customer support, and we have basically an agent that is doing first-level customer support for us, and I think it's about doing about 10,000 conversations a week. We would never be able to do this type of support with two people." — [00:38:00]

                      "The alert comes in, I wake up at the night, I just take the alert from our Slack, copy paste it into Codex, and we have a skill there with all the context, and then it's just going." — [00:29:00–00:30:00]

                      "I currently think of an email/Linear inbox where an agent tells me, 'Hey Max, we needed to fix this here because this broke.' And then if I want to, I can just dive into it and see all the context within this notification and also take a corrective course, or I just let it go." — [00:41:00]

                      1 hr 4 min
                    • #138 From Hacker News to W3C: How One Amazon Engineer Accidentally Shaped the Future of AI Browsers // Alex Nahas, MCP-B
                      How a browser-based fix for an enterprise auth problem became a W3C web standard and what it means for how AI agents will interact with the web.

                      Alex Nahas, founder of MCP-B and initiator of the WebMCP web standard, joins Tobias to explore one of the most underappreciated shifts happening in AI: the browser as the primary runtime for agentic systems.

                      Key topics covered:

                      • What MCP actually is: an RPC framework for calling tools across processes, not the complex protocol it's made out to be
                      • The OAuth problem: why MCP's push towards OAuth locked out most enterprise infrastructure still running on SAML
                      • The WebMCP solution: running an MCP server in client-side JavaScript so agents can use the browser's existing auth context
                      • How a Hacker News post posted under anesthesia got 400 upvotes and caught the attention of Google and Microsoft
                      • Chrome 146 natively supports WebMCP, and what that means for adoption
                      • The chicken-and-egg problem: why website owners won't add WebMCP support until clients support it, and vice versa
                      • Agent identity: why agents don't need their own credentials and can operate as a subset of the user's identity
                      • Real-time bidding for agents: the emerging market where advertisers bid to inject results into agent contexts
                      • - The agentic web in two years: headless browsers, intent-based interfaces, and agents that only surface the UI you need.

                        [~04:30] "The browser itself is like the perfect sandbox we've been iterating on for so long now." — Alex Nahas

                        [~06:30] "MCP is just an RPC framework. It's super simple. Basically just a wrapper around API documentation." — Alex Nahas
                        [~13:00] "My first memory coming back was me arguing with people on Hacker News who didn't understand it." — Alex Nahas
                        [~16:30] "Agents don't need their own identity. They can have an identity that's like a subset of the user who spun them off." — Alex Nahas
                        [~32:30] "This reminds him of the dawn of programming — where everyone was just doing things and nobody really knew what they were doing, but people were just trying to figure things out." — Alex Nahas
                        [~43:00] "Believe in yourself." — Alex Nahas

                        42 min

                      About alphalist.CTO Podcast - For CTOs and Technical Leaders

                      From the publisher's feed

                      This podcast features interviews of CTOs and other technical leadership figures and topics range from technology (AI, blockchain, cyber, DevOps, Web Architecture, etc.) to management (e.g. scaling, structuring teams, mentoring, technical recruiting, product etc.).

                      More shows like alphalist.CTO Podcast - For CTOs and Technical Leaders

                      The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch by Harry Stebbings

                      The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch

                      541 Listeners

                      The a16z Show by Andreessen Horowitz

                      The a16z Show

                      1,087 Listeners

                      OMR Podcast by Philipp Westermeyer - OMR

                      OMR Podcast

                      34 Listeners

                      Lage der Nation - der Politik-Podcast aus Berlin by Philip Banse & Ulf Buermeyer

                      Lage der Nation - der Politik-Podcast aus Berlin

                      221 Listeners

                      OMR Media by Pia Frey

                      OMR Media

                      3 Listeners

                      The OMR Podcast International – Go inside the minds of the biggest names in digital and tech by Philipp Westermeyer, founder and CEO of OMR / Scott Peterson, digital marketing editor, OMR

                      The OMR Podcast International – Go inside the minds of the biggest names in digital and tech

                      3 Listeners

                      OMR Education by OMR Education / Rolf Hermann / Andre Alpar / Tarek Müller

                      OMR Education

                      1 Listeners

                      manager magazin INSIDE by manager magazin

                      manager magazin INSIDE

                      8 Listeners

                      Handelsblatt Disrupt - Der Podcast über die Zukunft der Wirtschaft by Larissa Holzki, Handelsblatt

                      Handelsblatt Disrupt - Der Podcast über die Zukunft der Wirtschaft

                      16 Listeners

                      OK, America? by DIE ZEIT

                      OK, America?

                      98 Listeners

                      OMR Silicon Valley Update by Christian Byza

                      OMR Silicon Valley Update

                      11 Listeners

                      Doppelgänger by Philipp Glöckler, Philipp Klöckner

                      Doppelgänger

                      15 Listeners

                      Macht und Millionen – Echte Wirtschaftskrimis by Business Insider

                      Macht und Millionen – Echte Wirtschaftskrimis

                      21 Listeners

                      5050 by OMR by Isabelle Gardt & Kira Schubert

                      5050 by OMR

                      0 Listeners

                      bto – der Ökonomie-Podcast von Dr. Daniel Stelter by Dr. Daniel Stelter

                      bto – der Ökonomie-Podcast von Dr. Daniel Stelter

                      21 Listeners

                      Machtwechsel by Dagmar Rosenfeld und Robin Alexander

                      Machtwechsel

                      114 Listeners

                      OMRap by Torben Lux, Falk Schacht, Niko Hüls

                      OMRap

                      0 Listeners

                      Lanz + Precht by ZDF, Markus Lanz & Richard David Precht

                      Lanz + Precht

                      316 Listeners

                      Was bisher geschah - Geschichtspodcast by Joachim Telgenbüscher, Nils Minkmar

                      Was bisher geschah - Geschichtspodcast

                      54 Listeners

                      RONZHEIMER. by Paul Ronzheimer

                      RONZHEIMER.

                      143 Listeners

                      Firewall: Jedes System hat eine Schwachstelle by DER SPIEGEL

                      Firewall: Jedes System hat eine Schwachstelle

                      7 Listeners

                      OMR Rabbit Hole: Die Höhle der Löwen by Florian Rinke, OMR, Podstars by OMR

                      OMR Rabbit Hole: Die Höhle der Löwen

                      0 Listeners