RSSAmplifier

Blog

Ken Kantzer's Blog

logging my thoughts on technology, security & management

kenkantzer.comRSS feed ↗20 posts

Latest posts

Let’s be honest about AI Coding

Ken’s early 2026 thoughts on the state of AI coding, Claude, Kernigan’s Law, and what technology has worked thus far The post Let’s be honest about AI Coding appeared first on Ken Kantzer s Blog .

GPT is the Heroku of AI

I read a comment on HN that sparked this article: GPT is kind of like DevOps from the early 2000s. Here’s the hot take: I don t see the primary value of GPT being in its ability to help me develop novel use cases or features at least not right now. The primary value is [ ] The post GPT is the Heroku of AI appeared first on Ken Kantzer s Blog .

Lessons after a half-billion GPT tokens

My startup Truss (gettruss.io) released a few LLM-heavy features in the last six months, and the narrative around LLMs that I read on Hacker News is now starting to diverge from my reality, so I thought I d share some of the more surprising lessons after churning through just north of 500 million tokens, by my [ ] The post Lessons after a half-billion GPT tokens appeared first on Ken Kantzer s…

The Parable of the Wise Hiring Manager

One day, while The Manager was walking back from a morning coffee run, a group of frazzled engineers came near and spake unto him, saying: “Most Esteemed Boss, we are unable to hire Talent and many of our candidates refuse to take our coding challenges! The labor market is tight and our staff are [ ] The post The Parable of the Wise Hiring Manager appeared first on Ken Kantzer s Blog .

Learnings from 5 years of tech startup code audits

While I was at PKC, our team did upwards of twenty code audits, many of them for startups that were just around their Series A or B (that was usually when they had cash and realized that it’d be good to take a deeper look at their security, after the do-or-die focus on product market [ ] The post Learnings from 5 years of tech startup code audits appeared first on Ken Kantzer s Blog .

The Unreasonable Effectiveness of Secure-by-default

This is one in a series of deeper-dives into various Learnings from 5 years of tech startup code audits. In that article, I list several observations I had during the course of doing code audits fro 20-30 tech startups at or around the Series A / B mark. Security seems to be on the up-and-up, [ ] The post The Unreasonable Effectiveness of Secure-by-default appeared first on Ken Kantzer s Blog .

You Don’t Need Hundreds of Engineers to Build a Great Product

This is one in a series of deeper-dives into various Learnings from 5 years of tech startup code audits. In that article, I list several observations I had during the course of doing code audits fro 20-30 tech startups at or around the Series A / B mark. We did several code audits for companies [ ] The post You Don’t Need Hundreds of Engineers to Build a Great Product appeared first on Ken Kantzer…

Technology ROI Discussions are Broken

A note before we begin: I’m arguing that technology ROI discussions are broken, not that ROI as a decision-making tool is broken. A solid understanding of how to calculate and use ROI is an essential skill for any tech executive, and when done right, it’s a powerful decision-making tool. This post is about how technology [ ] The post Technology ROI Discussions are Broken appeared first on Ken…

5 Software Engineering Foot-guns

“In the brain of all brilliant minds resides in the corner a fool.” Aristotle Writing about Best Practices can get boring, so I thought I d take a break this week, and write about some bad engineering practices that I ve found the absolute hardest to undo once done. Real foot-guns, you could say. Each of these [ ] The post 5 Software Engineering Foot-guns appeared first on Ken Kantzer s Blog .

The Backlog Peter Principle

A few years ago, I was in one of my ruts. Everything I was working on seemed to be bogged down or low-leverage. What was so frustrating was that this had come on the heels of a few amazingly productive months, where I had gotten a lot done. Worse yet, this seemed to happen cyclically: [ ] The post The Backlog Peter Principle appeared first on Ken Kantzer s Blog .

How to find great senior engineers

Hiring experienced engineers is one of the most difficult and important things that engineering leaders have to pull off. But it’s hard to gauge experience in a series of short interviews. I’ve definitely worked with some amazing engineers who probably wouldn’t have been hired in some of my previous hiring pipelines. Here are some tips [ ] The post How to find great senior engineers appeared first…

The Googler’s Dilemma: Why Experience Will Always Have a Premium

I ve been thinking recently about how to discover and hire great engineers in the hottest job market in decades. One of the biggest hurdles to hiring good engineers, and especially experienced engineers, is that they re so. unbelievably. expensive. Just take a look at some of the total compensation packages on levels.fyi: Total comp grows exponentially [ ] The post The Googler s Dilemma: Why…

5 Red Flags Signaling Your Rebuild Will Fail

This is an updated re-post of an article I wrote on the PKC Blog in June 2018 There’s always a reason to rebuild. Perhaps you’re a CEO of a startup that has had some success and your engineers are clamoring to re-platform and do a rewrite from scratch. Perhaps you’re an executive or IT lead [ ] The post 5 Red Flags Signaling Your Rebuild Will Fail appeared first on Ken Kantzer s Blog .

Core Control #6: Log Everything

SANS Control 6— Maintenance, Monitoring and Analysis of Audit Logs The Core Principle The core principle is this: fish nets over fishing lines. In the case of security monitoring, fish nets are alerting on anomalies, where anomalies are defined as universal constants that have been broken. Fishing lines are manual search procedures. Phrase this principle like [ ] The post Core Control #6: Log…

Core Control #5: Secure by Default

SANS Control 5— Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers The Core Principle Let’s sum it up in three words: Secure by default. The more systems that are secure by default, the less twiddling your IT team has to do for each deployment. Less twiddling means fewer chances to make [ ] The post Core Control #5: Secure by Default appeared first…

Core Principle #4: Managing Privileged Access

SANS Control 4— Controlled Use of Administrative Privileges The Core Principle This core principle can be summed up by the famous Reagan Cold War quote: trust but verify. Transcendent CISOs trust their people with privileged access, but are simultaneously very stringent about authenticating them. This approach is akin to Postel s Law, which was the core principle [ ] The post Core Principle #4:…

Core Principle #3: Continuous Security

SANS Control 3— Continuous Vulnerability Management The Core Principle That first word—continuous—is the core of this control. “Continuous” has seen a bit of hype in tech circles in other contexts. In particular, I’m thinking of continuous integration and continuous delivery from the world of DevOps and continuous improvement from the world of Digital Transformation. Why not [ ] The post Core…

Core Principle #2: Know Your Software

SANS Control 2— Inventory and Control of Software Assets The Core Principle The same Golden Rule that applies to hardware applies to software: know what you have. No user on your systems should be able to install an executable onto a company device without the approval of security. This may seem like a draconian policy (and [ ] The post Core Principle #2: Know Your Software appeared first on Ken…

Core Principle #1: Know Your Hardware

SAN Control 1— Inventory and Control of Hardware Assets The Core Principle There are only six controls in the Top 20 list that are designated “Basic,” and an inventory of your hardware is number one. I actually would like to rephrase this control slightly, so it better fits the core principle I wanted to highlighted: if [ ] The post Core Principle #1: Know Your Hardware appeared first on Ken…

New Series: Core Principles for the Transcendent CISO

CISOs have an impossible job. They are faced with securing data across thousands of complex devices and services. They are often brought in after a bad breach and are asked to make sure “it never happens again.” Add to that the complexity of simultaneously meeting ISO 27001, PCI, SOC 2, and FedRAMP compliance standards, and [ ] The post New Series: Core Principles for the Transcendent CISO…