Today: Demand for AI continues to reveal cracks in the enterprise tech pricing models that built the cloud, AWS sends more money to its Trainium business through Anthropic, and the latest funding rounds in enterprise tech.
Today on Product Saturday: Salesforce might have the answer to SaaS sustainability in an AI world, DuckDB addresses the "small changes" problem in lakehouses, and the quote of the week.
Today: New models from Anthropic and OpenAI claim impressive and scary cybersecurity capabilities, but only club members know for sure, NIST explains how it will deal with a huge surge in vulnerability reports, and the latest enterprise moves.
Snowflake CEO: Default multifactor authentication is coming soon
Snowflake will outline a plan to require all customers to use additional security protections "within the coming days" after a spate of high-profile security breaches involving customers that didn't take that step.
SAN FRANCISCO — After a week during which growing numbers of Snowflake customers reported data breaches after failing to use multifactor authentication to secure their accounts, CEO Sridhar Ramaswamy said Thursday that the company plans to require customers to use the additional protection in the near future.
"It's clear that we have to do something about this," Ramaswamy said in an interview with Runtime on the last day of the Snowflake Data Cloud Summit. Snowflake has been urging customers all week to turn on MFA security features for their accounts, "but I think making this programmatic is the next logical step we do need to take," he said.
Several high-profile Snowflake customers — including Ticketmaster parent company Live Nation and Santander, one of the largest banks in the world — have recently reported data breaches that security experts have linked to Snowflake accounts that lacked multifactor authentication. Techcrunch reported Wednesday that "hundreds" of login credentials stolen from Snowflake customers are available for sale in hacking forums, suggesting that this issue could become much more widespread in coming days.
Given that a lot of Snowflake customers use automated service accounts to run tasks, the problem is more complex than simply throwing a switch to require MFA in order to access data in Snowflake, Ramaswamy said. However, the company will outline a plan to address those accounts "in the coming days," he said.
Backed by statements from security companies Mandiant and Crowdstrike, Snowflake has insisted that the breach was not caused by any software vulnerability or security issue in its software. However, other cloud software companies require their customers to turn on the additional protections afforded by MFA; Microsoft will require Azure customers to use MFA starting in July, and GitHub mandated MFA use in January.
Tom Krazit has covered the technology industry for over 20 years, focused on enterprise technology during the rise of cloud computing over the last ten years at Gigaom, Structure and Protocol.
Today on Product Saturday: Manus gets in on the desktop agent craze three months after joining Meta, Snowflake introduces a new task-competition platform based around user data, and the quote of the week.
Today: Databricks co-founder Reynold Xin on the speed at which AI-driven coding is changing software, Snowflake launches a coding agent and previews its Postgres database, and the latest funding rounds in enterprise tech.
Today: Why Snowflake's acquisition of Observe underscores the importance of observability to enterprise AI, Microsoft attempts to fend off the AI coding upstarts, and the latest enterprise moves.
Today on Product Saturday: rivals Databricks and Snowflake roll out new tools that promise to help companies get their agents over the finish line and into production, and the quote of the week.