Techstrong TV September 24, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everybody, does AI stand for artificial investment? Let's find out. We'll be back in a minute.
Hey, folks, we're back and welcome to Textron Gang for Wednesday. We're here today with Chris Blas, who's a veteran, and Jeff Rich, who's from the, um, identity Defined Security alliance. There you go.
And Jeff has been on the show a couple of times, but for those of you who have not met him, he is kind of in charge of this alliance that focuses on identity, which is awesome 'cause we're gonna have a couple of security related conversations in a minute. But first, let's start with this whole investment from Nvidia into OpenAI, which is valued at a hundred billion dollars, but it comes in increments. Apparently it starts at $10 billion a throw for, uh, AI ordering Nvidia chips and return from building some data centers around those chips, which theoretically becomes this virtuous cycle between your customer and a supplier who's gonna actually keep building these things.
Chris, I know you've been dabbling in AI for a while, but this is the latest in a series of these investments that we've seen and video invested in Intel. And one of the dirty little secrets of AI apparently, is that we are subsidizing the crap out of the processing of those requests, and it's costing companies a lot more than they're charging end users. So the question becomes, is this sustainable?
And what do you make of this investment? So, I don't know. There's a couple ways to look at this.
Uh, look at this. You know, there's centralization and fragility. You know, are we integrating more vertical risk, you know, into the same stack, you know, for all sorts of reasons.
Economic control, uh, of technical, technical architecture, um, the same time, you know, this is the space. You know, I, I don't know that I can, I can double think the, the decision makers, you know, if I were them, would I be looking at certain things, maybe, right? And the, you know, as you say, the the phased approach of it, you know, may indicate some thoughtfulness on the, on the decision makers.
But, uh, we will see, you know, there's, there's again, it's, you know, we have these conversations all the time, and in this show, we literally have these conversations all the time. We try to think of something new to say, and sometimes just need to say the same things over again, I guess. But, uh, we understand.
I think everybody understands over the last several decades, a hundred years, however we wanna look at it. We've, while we've advanced things a lot, we've introduced a lot of brittle systems, you know, single, the supply chain where I spent so much of my time where it's hard to get people to think that, well, we need more than just one thin line of linked attestations to, to know where things coming from. So we're looking at chips and, and, and that whole thing, you know, this, this particular issue, you know, are we concentrating risk, you know, getting some benefits for some stakeholders, but at the same time, um, making them the system more fragile.
Uh, so interesting. A lot of concerns, Jeff. Yeah, I would offer that, although, uh, those are the right points, if from a bigger picture point of view, there's, if I were them and I were doing this investment, kinda like what you said, the phase approach makes sense for two main reasons.
One, is there ever gonna be a profit? And I think we need to ask ourselves that question. I, I don't have that answer yet, but I don't see a definite yes down the road, you know, we're gonna have to wait and see.
Um, and the second one is, and it plays on the profit motive to a degree. There is a lot of other hidden costs with ai, the energy use, the downstream environmental impact and everything else around that. Not to mention societal impact, which I'm not even gonna touch, just, just mention it, but not touch it.
You add all that together. I are the costs really as well defined as Nvidia thinks they are? Is it simply chips?
I, I think not, I can't help but wonder if this will just set the stage for some sort of investigation for, and I eventually, because you created this kind of tight ecosystem, and I can get to Chris's point, there's virtue in that cycle, but at some point, somebody's gonna complain and say, you know, basically Nvidia has locked out competition in this space already. And, um, Chris, you know, you've been around federal governments, it might take them a few years to wrap their heads around it, but eventually somebody's gonna come knocking, right? You would hope, right?
And it, it, again, if you go down this path, this is what governance is for, right? And, uh, but you know, Jeff, to your point, we have to, as we always have, again, this is not new, you know, if you worked in a global security free length of time, you realize that policies in, in, in various, you know, geographies and jurisdictions are where they are, and they're evolving along certain lines. Um, we have a certain arc for that sort of thing in the, in the current, uh, US administration.
So, which raises the question for me, will they, it depends, you know, is this an era of where one of these big players, you know, the US of market, um, will actually re reward and ignore, uh, uh, risky behavior? And if so, that I doesn't change my long term view of this, that, you know, you know, open systems and democracy and capitalism, all these things work because they're self-correcting. Any one actor can make Barbara, you know, bad choices, uh, or what may look like good choices, but turn out to be bad choices in the end.
And if they, um, that's not the right analogy for a show like this. If they fail spectacularly, um, someone else will pick it up. And as we discussed in this, in this show, in this forum, I have a lot of questions about, you know, how we're even allocating workload now, Jeff, power allocation, you know, the systems we're putting together have enormous benefits to be clear, we're going this direction, nothing's gonna stop it.
The question now is, how many keystone comps, uh, mistakes will we make along the way? And this one, again, I, you know, the people at the top people making the decisions to be clear are not idiots, right? And, and almost nobody is, right?
When you don't understand the dec decisions people are making, you know, and, and, and organizations being, uh, uh, you don't understand decisions organizations are making. The people inside are, are acting rationally. So, you know, I, I can ar you know, in a vacuum, I could argue the pros of this.
I can, I can argue some of the risks of it. The reality is how will it play out in the environment that we're actually in? And we'll see.
Mm-hmm. Our friends in Europe are gonna say, ultimately than the us the about you should say. Yeah.
So I have a question on that. Uh, extending a bit more. The UN general assemblies meeting this week.
I have trouble believing that the two letters, AI won't come up somewhere. Yes, right there, there is an actual session about AI safety that's being discussed at this thing, but I'm sure in the hallways, a lot of companies and countries are having conversations amongst themselves about what does all this mean? Because it does feel like, you know, us dominance of the sector.
So I'm sure there'll be some interesting things. But let's imagine you were sitting over at a MD, does this mean that you got a pony up $10 billion to get a customer for your AI chips? Is that how this is gonna play out as well?
I mean, you know, how crazy does this get, Chris? What do you say? Oh, it's too easy just just to say yes.
Right? And you get back to, you know, again, you know, we, we use these acronyms and company names. There are people there, you know, there's a bunch, you know, as you get to the decision making cycle, not that many.
And they'll make their choices. And, you know, and, uh, and I'm not gonna advise them, or at least not for free, but I'm, but, uh, you know, there's a lot of arguments to be said for yes. I mean, look, like at to my last statement, I can argue what might be the right or wrong thing to do for, you know, technical reasons or structural reasons, but there's also, we live in a reality, right?
And the reality, uh, like you say, Jeff, you know, we have, we have this going on. We have the UN general assembly next week, we have all sorts of global policy things going on. And when you're looking at the kind of timeframes and the financial investments, you know, you know, and the number of competitors, the number of entities globally doing these sort of things, you've gotta make your choices.
Um, and, and it, it, at the risk of to in fact, repeat myself, you know, this, this, you know, these things will play out. I have very strong opinions. The AI side of thing, lemme just take it there.
Narrative sovereignty is a term we tend to use a lot more in this is a civic AI and world we're talking about these days. And it's not, it's not, you know, quite a lot. You can talk about disinformation, misinformation, influence campaigns, and that's a, a real and present, uh, issue, but it's also in how we run our systems.
You know, of do I control the narrative sovereignty of my company? Do I actually know what I'm saying? What we're saying, what we say to each other, what we're saying to the outside world?
Turns out we haven't been doing that extremely well. And this whole ai, well, again, what we are calling AI this time around, uh, again, um, lends itself really well to that. So the attestation systems that that, that I and many others seem to think that we need on a global basis to deal with these sort of human issues, get back into corporate decision making, what is the right decision?
Are we making decisions transparently even amongst ourselves inside the company, um, or not? And, you know, so I look at these executives, they're trying to navigate worlds where literally, Mike, you and I, you know, this, I find this calendar year, particularly this threat of conversations every week to be fascinating, looking back at what I said and what we talked about in January or March or June. June was a, a huge month this year, right?
The world kind of changed in June. We're here now, if you are at the, in the corporate office, in the C-suite at a MD, how exactly do you navigate that? That's hell of a question, right?
But I'm happy to be an armchair critic and, and say what I would do. But it's, we need to recognize the reality of the, the decision of the, the, the, the situation, the deci decision makers in. And, and so anyways, he said at the long, long rant, but I think the kind of, so the narrative sovereignty, attestation systems, this is 99% of what I, and quiet wire and the open source civic ai we're all about.
We're applying this in different ways. And I look at this block, this topic, you know, this, this, what we're talking about here is yet another process that will be inflicted by the success or lack of success of that adoption of attestation systems, which is a little bit abstract and perhaps opaque for your, for your, uh, uh, for the viewing audience. But do we know what we're even doing?
And we, where we see these cartoonists sort of decisions we make, and it's, it seems ridiculous, but you get in on the inside and again, find out that the individual humans are be, are acting rationally. It's just that our systems are very rational. I suppose when I look at it, and Jeff, you've been around these kinds of decisions before, and we, you know, whether it's job or whatever else, but it seems like within Nvidia, it's not just the processors, it's the Cuda software framework that they're getting everybody right to, and those APIs, and that's where the lock-ins gonna be.
We have seen fixes to this in the past. So will there just become pressure to say, Hey, we need Cuda, or some clone of it to be open source and available and avoid this kind, and maybe that's how we resolve this issue. Uh, you know, I can't think of an answer that's very far from that, because it really boils down to Chris, when you talk about is this gonna be a success or not For, um, commercial organizations, the definition of success is ROI for every investment, bottom line.
That's it. In fact, that is the bottom line. So that's what they're for.
Yes, exactly. They're a company, they're money making organization. That's why we create them.
Yes. So Even though a concentrated M word could potentially exist on this, which could bring a bigger RI, we still don't even know that yet. So I, I think there will be, first of all, at some point e either there's gonna be a disruptor either from some regulator that says, no, you can't own everything.
Or there's going to be a disruption from another organization that says, we have an alternative way to do this. And by the way, it costs a lot less, and it, it may run faster. There's gonna be other benefits.
One of those two collisions is coming down the road. And like Chris, I don't know which one it is, Right? And, and the, and, and the, and the reality is that, you know, four corporations, you know, you know, we're sitting here armchair, but maybe, you know, and I've been in this position in major, you know, corporations, myself, I have a legal fiduciary responsibility made decisions that increase shareholder value.
It's not just greed. That's what the, you know, that's why we agreed to form this thing. It's called the company.
It makes money. That's why we spend time at, and we take roles and responsibilities, and, you know, this may work, you know, doing what I would see as morally and ethically and, and technologically and security, a bad idea may be the right choice because you will make more money. Now, I may not be personally happy with that.
I may think it makes our infrastructure fragile, and I think I'm right, but that doesn't mean that it's the wrong choice for those stakeholders to make. Mm-hmm. I also think there's a fork in the road, and it's nearer then we think, um, if you look at all of this stuff that they're talking about for these kind of large data centers, it's built around training.
They're really focused on, we're gonna go train super intelligence, or AI general intelligence, or whatever the term of the day is you wanna do. And that's all well and fine. But I think that the bulk of what we're looking at in the future is gonna be the running of the inference engines.
And that doesn't necessarily require Nvidia GPUs. We can run a lot of different processors in those instances. And I also think that we're gonna see a lot of these models are gonna be distilled into smaller models that run more efficiently on those things, and are better trained and better targeted.
So maybe, you know, as, as great as this all sounds, but maybe you know, this, uh, a GI and case involving Nvidia and open AI is, you know, high-end computer science, but not where the action's gonna be. Chris, am I crazy? Yeah.
Hold my coffee. Right? You know, 'cause yes, I mean, you, we've talked this about this on, on, in this, you know, you and I, and you know, on this show we've talked about this workload distribution.
What do you really need? A, you know, we're using Einstein to open the door, right? You know, so every time we're booting up an AI and having, you know, this huge power surge and to the, to the point of this segment, we need all these chips.
Um, that's not really justified. It's not the kind of thing that lasts long term, 3, 5, 7, 12 years from now. We're gonna do it that way.
No, we're not. We're gonna have massively distributed workloads where a lot of things will get done. You had a, uh, just in the last couple weeks, we had a great conversation on this, where old computers, so we're using old computers today to do modern things, and with AI and l with actual LMS running on 10-year-old machines, because the actual LLM part of it isn't much, and it doesn't need to be right away.
It's not talking to a human, it's, it's performing functions. So, you know, I would like to hope for all my, my, uh, uh, my, my nonpartisan, uh, uh, statements to date. I hope they're wrong.
I hope everybody bet betting on owning the castle and owning the keep turns out to be wrong. And I think there's a really good chance that they will be. This is all, you know, to my last point, a chance that they won't.
Maybe they're make the right calls, but I don't think so. So, so Chris, are they gonna convert those big data centers in in 10 years to big storage facilities that you can rent out? Basketball courts?
Yeah. Yeah. Community centers.
Yeah. Yeah, they Pickleball courts, man, pickleball. All right, folks, I think we're gonna leave it there.
But I, I, I would be careful when I was evaluating anybody's financial statements, you know, if I'm taking dollars from companies that I invested in, does that really count as a customer dollar or is that some other thing that we should keep track of in a different way? We'll be back in a minute. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back and under the heading once again of why we can't have nice things. There's a report up on Security Boulevard talking about how the bad guys are starting to do some stuff with ai. And it comes in two forms initially, and this may just be the beginning of a larger trend, but the first one is they're actually trying to poison the data we're using to train these AI models.
And then the second part of it is, well, they're actually starting to use these deep fakes a little more aggressively. Jeff, you live and breathe all this security stuff. Does any of this a surprise you?
And B, what else should we expect? Uh, no. So the only thing that surprises me is that it's now coming to light.
Um, I, I think this has been here, you know, every single tool that you have, whether it's a shovel, a pick, a handgun, or a rifle, can always be used in two different directions, at least. Alright, so here we are. Um, now that we have ai that's a great benefit in society and what we're doing for decisions and how we, you know, invest our money and, and how we make our company work and everything else, that, all the wonderful things that can come from AI when used properly.
The bad guys look at this and say, Hey, you know, that, that looks like a really good idea. I think I'm gonna use it too. So we, we certainly can't be surprised, one, at poisoning the data.
That's not a new, uh, that's not a new trick at all. And I, and Chris is violently, uh, agreeing with this one. Not a new trick.
They're you simply using a new tool. So I'm really not that surprised that we're seeing it. I'm surprised that it took so long for it to become visible.
I think it's been here for a while. This is kind of like a, you know, when you have a heart attack, you realize, okay, if I look back over the past 15 years, I can see all the warning signs and lifestyle and everything else that got me here. I think that's where we are with poison data right now.
I think there's more of it out there than we believe. Um, and the, the second thing with DeepFakes, and this is something that's really close to what we do at IDSA, you know, identity is, has now become the cornerstone for security in any system. Because no matter what, if you don't know who or what you're dealing with, you don't know who what's gonna happen in, in any way.
This goes back to, if you look back at military bases, back to, you know, probably back to Roman times when someone approaches, the phrase that's uttered is who goes there? They wanna know who you are, and in some cases find a way to validate it. We have better ways to do that now, um, than than Roman times.
So, identify who you are, validate who you are. And that's not happening well enough, often enough. Right now, we are still taking shortcuts.
Many organizations are still real happy with using SMS as a second factor in, uh, in authentication and in including financial institutions, which amazes me healthcare. Um, I, I actually had a, an encounter with a healthcare professional earlier this week who asked for my social security number. And the number I gave, I gave that individual was 2025.
That's the year we're living in. You shouldn't be asking me for my social security number anymore. What are you gonna do if I don't give it to you?
And, and completely befuddled and said, okay, I guess you don't need to give it to me, then. Well, thank you very much. I wish more people would take that position not to be, you know, uh, either arrogant or aggressive about it.
But when you add all that together with deep fake, the same principle applies with deep fake. Now, as good as those systems have become, and they're getting better by the hour, they are getting better by the hour. What we need to do as security professionals is find a way to, and use that and leverage the same systems to be able to ferret out the ones that have a high probability of being real and have a low probability and, and should be weeded out or find another way to authenticate who they are.
And there are good ways to do that. Now, whether it's with a token or a passkey or using geolocation, there's so many different factors you could use now available to us that don't involve SMS, that lets you determine it Now with, um, AI and DeepFakes and interactions from machine to machine, which is the one that people aren't talking about yet, but is certainly there, there are certificates as an example that really should be used, not a new concept, but if you have a trusted certificate with a, with a ca that you can, that you have faith in, you could have a much higher probability that whatever machine interaction your machine is having is valid rather than coming from a bad guy. So, uh, you know, I may not be making anyone feel any better about this, because yeah, the bad times are here with it right now.
A lot of good times are as well. We just need to keep up. We can't be lazy about it.
All right, so do we need like a new hashtag hashtag no ssn, what do you say? Uh, oh, you, you know, I wouldn't mind an OSMS, uh, you know, I, I, I could, in fact, I may, I may stare at that. Yeah, I think that's not a bad idea.
Um, it has its place, but not for authentication. Alright, Chris, well, we Have, go ahead. For the uninitiated who don't know what data poisonings all about, what is it that cyber criminals are trying to do here?
Exactly. Because it seems like, you know, I'm kind of hoping to poison an LLM that may have some impact. It seems like a long shot, or, or is there some other way of thinking about this thing?
Well, without getting too deep into the gory details, I just basically wanna agree with Jeff, you know, this is not new. There's almost nothing new about this whatsoever. Right?
I think what's, what's but of the things that are not new, the most useful thing to, to, uh, pay attention to is this is a speed thing, right? And Jeff, as you were talking, you know, we're, we're the same era, right? You know, war, not war dialing, but well, war islanding, right?
You know, the, the, you know, back in the day someone realized that, hey, if you just call phone numbers and a modem picks up, you know, what phone number has a modem, and now you can have fun trying to break into that modem and the network behind it and whatnot, then somebody else said, you know what, I can just take an entire block of phone numbers and write a script and have my computer sit here while I'm asleep and call one phone number after another. And, uh, that sped things up massively because all of a sudden, you know, you could hundreds and thousands in a night. And, uh, and for those of us on this side of things, you know, that was early in my career.
I was like, oh, wow, that, that's an interesting little twist. And then, then just to, just to make that story as fun as it was, you know, the response was, we will make it illegal. There's a law, I think probably still in the book, books in the States, if you call someone and hang up without saying anything that's actually against the law, or it was made against the law, so what the, what the heck what the hackers did was just change the code and add a little wave file that says, sorry, wrong number.
So if a human picks up, they say, sorry, we're a number. So anyways, without, uh, uh, going too far down the rabbit hole, this is the same sort of thing. You, the hackers, you know, the bad guys, um, now have AI tools that speed them up massively.
If the defenders don't, you know, address that, you know, and use AI tools to speed yourself up massively can be done mostly by not listening to people like Jeff and I, right? You know, just, just go out and do it. Get a chat GPT account asking about, tell her who you are, what you're trying to do, a situation you'll move forward.
Not as fast as the bad guys, but way faster than all the other people around you. You know, don't have to be faster than the bear. Um, and, uh, and Mike, I'm trying to re our call if I actually, you know, adjust your question at all.
They're trying to, you know, put information into your system so that your systems betray you, right? Again, right over and over and over again. This is another interesting way to do it.
And there are literally so many, and because of LLM model architecture, the word layer isn't just a metaphor. There are so many layers to do this in that we could have individual shows talking about individual, you know, a laura layer. You wanna stick, you know, poisoning in the laura layer, in the actual model execution as opposed to, you know, poisoning the data set.
You're training the models. You know, we could do this all day long. And, and, but Jeff, you, you touched on, I will try to end on this.
We have built this entire structure saying, I have an attestation, I've got a certificate. Wait, heaven, help us. We'll have two and we'll use text messages.
Um, that's not how anything works. Every decision we all make to pick the next words while talking to you right now to walk across the street, to do anything, to be a human being. We have 3, 4, 5, 6 things we, we can attestations that we can navigate on.
We have built our entire security architecture on one. I'm gonna get the ultimate cryptographic authentication for Jeff. And I'll know that one thing tells me that's Jeff.
No two is a start, not very good. Three is fantastic, four is ridiculous. It's not exponential, but we have to have more than one line of brittle authentication to give us access to whether or not you're poisoning my ai.
Hmm. So Jeff, is this data poisoning stuff just basically amounts to, um, damage for damage sake? I mean, is there any monetary purpose to this for the bad guys?
I mean, or are they just trying to, uh, you know, destroy things for the sake of havoc and they're just really, you know, anarchist? I don't know. Well, well, I think there's certainly an anarchist component somewhere in the earth.
There always is when there's bad guys involved because they can, they can jump on the wagon and, and have a certain level of anonymity in the beginning. But I think there's a lot of different vectors at play here. Let's, let's start out with a big one nation state, okay?
If na, if a nation state decides it wants to poison, um, data, for instance, that's being used by, um, an AI system, the advantage they have is from the time they start the poisoning until this time it's discovered, they can either redirect a strategy, they can redirect weapon deployment or, or anything in between. They can find a way to exfiltrate, uh, data using it potentially. Because if you put, if you poison data in a certain way, you can put markers in there that say, when I get this data, I know it's data that I poisoned.
And when I get something that doesn't have my marker, I know it's real data. So, you know, there's an exfiltration opportunity that really didn't exist before AI has allowed that to happen at scale. Uh, you know, and, and those at nation state, there's those too.
Plus there's also the whole, can I bring this nation down just by having all of its system collapse on themselves? That's another one too, that, that has been tried in the past with electric grids at, at different, um, uh, Eastern European countries, Estonia in particular, had it happen, um, quite a few years ago. Once again, not new.
So those are the nation state vectors. I think you also have, you know, um, competitive, uh, corporate competitive vectors, and I'm not accusing any given company, but let's face it, there are organizations out there, or at least individuals in organizations that have no compunction about saying, I'm gonna find a way to either get my competitor's information or destroy my competitor. Same methodologies I talked about from a nation state.
Um, and then you have the, um, the individuals or small entities that, that just want to say, I'm going to hold data ransom. 'cause you could do that as well. Once again, with those markers, you could say, I'm gonna hold data ransom and let an organization know your data is going.
You can't trust your data. You don't know what's accurate. I do, if you want your accurate data, you're gonna pay me and, you know, cryptocurrency.
So there's that. And then there are the anarchists that just anarchists rather than just wanted to say, let me see what I can screw up. Here I go, boom.
All of those are there. Plus there's probably some I didn't mention. So, um, gosh, it feels like I'm the harbinger of doom on, on today's show.
Well, the, the nice thing about, yeah, what I'm really enjoying about this period of my career is, is that, you know, well, you know, you're right. We get to bring a lot of the doom, but one of the things I've been saying all along is that, you know, regardless, the lights are still on, the internet still works, and, you know, does that mean you're safe? Oh, lord, no.
And there's a lot of things you should do, but will it all work out in the end, generally speaking? Yeah, just don't try not to be the end. Um, but I I love your exfil exfiltration example.
That's something people really get to Yeah. Visualize and, and it's, you're exactly right. And also each of these things, again, recurs me back to my point that, you know, it comes up over and over again.
We're having, you know, we're gonna let AI be agentic and actually do things. How do we trust it? It's like, what do we do now?
Well, there's Bob. I mean, Bob's been doing this for 30 years and we trust Bob. Why?
'cause he's Bob, well, what do you really, literally mean? And we find that, again, we have, you know, sort of fragile systems or not in ot, in operational technology, we find that you can trust Bob. And you know why?
Because there's a system or process around it. It's not really about Bob, right? It's about you have a system in place.
It doesn't break if Bob makes the wrong choice. Whereas we have these IT systems where if one system makes a bad choice, you're, you're, you're done. It shouldn't be, you know, we should have, again, two, at least two factor authentication.
Three again, literally in the anti station world, there are 3, 4, 5, and six. There's not seven, there's not 19. You know, it's not talking about gigabits of everything we're saying that if you were going to make a critical choice, and you have one thing to base it on, you are fragile.
That is a brittle choice no matter who you are. If you have two, that's, you can triangulate on that from your position to those two mean with three, you can make, uh, mature choices about risk and, and decision. Without those every single thing, Jeff, to your point, you know, is just fodder for you and I getting to get more airtime talking about today's latest, you know, silly risk.
Well, to your point, I to the point, I mean point I'll trust to the point where I discover he has a drinking problem and then him, all bits are off. But, um, when you think about this for a minute, and correct me if I don't understand this, but as I understand it, it's, these models aren't like software that I just go patch when I find there's a vulnerability. To your point, they're layered and all that data's in there.
And once the model's trashed, it's trashed. And I gotta pretty much go and rebuild the model and replace the entire thing. And this is not an expensive proposition or inexpensive proposition, I don't know, but it seems like it's a, it's a level of fix that's a lot more complicated than people might think.
Let me push back on both those points, right? Because, you know, you don't trust Bob up until you find out he has a drinking problem. What my response to you is that you made a bad trust decision in the first place.
How on earth did you build a critical infrastructure system and be the person responsible? And it comes down to whether or not, you know, whether or not Bob has a drinking problem. And whether or not, no, you build the system so that if one node in the system like Bob or Bob, um, you know, just, and again, you know, Bob doesn't have a drinking problem.
Bob just got contacted by nation state actors who told him that unless he does certain things with a totally straight face tomorrow, work, his family, you know, won't be there tonight. You didn't engineer a system to allow Bob to save his family's life. Forget your company.
Right? You know, there is a level of willful negligent incompetence. I will take this approach.
I just think about this. Yeah, if you've made those decisions out in the world and live, and it's got worked, okay, to be clear, you have had moral and ethical failures that you should personally be held liable for. And if things happen, if the dam breaks because you made the decision to build the entire infrastructure based on whether or not Bob has a drinking problem, you will suffer the consequences and you will personally inside your own head.
And people, you know, people in these levels of responsibility think of many of the, you know, the, the great disasters and the people, the captain in charge and so forth. Um, it doesn't work well for them because you can't justify that. So we've built a lot of fragile systems.
Listen, Jeff, that sounded like your classic insider threat problem. Is that what we're really looking at? Boy, when Chris was describing that, the two words Aldrich Ames popped into my head, and, and, and for those of you who don't know, either Google it or ask your parents, uh, uh, but Ridge Ames was, um, very deep in the intelligence community and was trusted, I won't use air quotes, but that that might be a justifiable use of them, was trusted for decades with top level nation secrets in the us and it was discovered that he was selling them.
Uh, and he had been selling them for a long time, and it's because there was a single threat of trust that existed. And he was Bob. And, and there was no way to validate Was Bob, was alder change compromised?
Why was he compromised? Was it something he did intentionally? Was he under duress?
There was nothing really, I mean, there were, there were certainly cursory controls put into that, but there was nothing to really figure out is that actually happening or not. And, uh, I'm not certain we're in much better shape now than we were then in the intelligence community. But I, Let me, let me riff off that and go back to Mike the second half of your question, right?
Which is similarly, you know, these are level of complexity challenges. It doesn't matter what the, what the frame is. You know, we, we think you, you would ask are the, if the layers of software and a ai, is it now so far?
No, it has been there for a long time. If you thought you really had a handle on your software and you knew what, no, you're wrong. I mean, since you know, 10 lines of code, no, that's not how it works.
You've gotten away with it because it has not come back to bite you yet. But you've needed systems all along that, again, assume that you don't know because, you know, emergent properties, levels of complexity. Um, it, it's, this is, this is where my inevitability curve thing comes to because it's an evolutionary thing.
Uh, you see genetically, you know, biologically all sorts of things happen for a long time. And then there's some evolutionary crux, and it, you can say that all of the other things were bad ideas, which is true literally in its own way, but in their environment, they were fine, but they had fundamental flaws that didn't. Saber-tooth, you know, saber-tooth animals have evolved eight or nine times in the history, completely unrelated.
They have no nothing to do with each other. What they had to do with is a high oxygen environment that supports, you know, strength being the, the, the main determining factor and coffee being delivered without asking for it. So as soon as that stops, they go extinct immediately.
There's no second generation, they stop immediately. So there's a lot of these inflection points, you know, punctuated evolution to come along and, and they point out that, yeah, believing that you knew what your software was doing in the first place was a, was not a long-term choice. All right, folks, we gotta, we gotta, we gotta move on to our next subject, but I will just throw out another hashtag we might consider hashtag zero trust ai.
Who knows, we'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Hey folks, we're back in. We've been talking about ransomware and I feel like we've suggested maybe we were making a, uh, some progress here and we were more cyber resilient than ever.
And then along comes this latest attack where, um, cyber criminals are basically taken out the luggage system that's managed by a company and probably none of us ever heard of until this week. Uh, and now, uh, we see travel delays and it's impacting everybody. And Jeff, I know you've been looking at this, but do we just have, or is the underbelly of it just too damn soft?
Well, I, I think this kind of goes back to a lot of what we were talking about in the previous segment, in that there's a level of trust that we have because it, nothing's gone wrong yet. And, and there's a phrase I use universe is meta is, is, and I'm gonna have to stop and say it metamorphic. The, the universe is metamorphic.
And whether it's a saber tooth tiger or an an IT system or an AI layer, no matter what it is, it will change. It can't remain static. It everything has to move and either grow or die, change or die.
So, um, yeah, there's a lot of fragility in there overall. We still have solid systems and sometimes it's issues like what, what's been happening with, um, a baggage handling and boarding passes in the EU that occurred this past week that make us think, do we have enough backup systems or different levels of trust to make this work? A lot of airlines in the EU thought, well, it's down.
That's fine, we'll just issue paper tickets until they realized that the paper tickets that they print came from the same system. So they, they, they still had a single point of failure. They, they, they didn't fix that problem.
So yeah, if you wanna issue paper tickets, that's a good, that's a, a good redundancy, but have it completely out of stream from the system that, um, yet you're currently relying on when that system, you know, turns over and doesn't work, right? So there's that. I, I'm gonna bring up a tangential and I think it's important to actually all three, uh, segments that we've discussed today about, and it's the airline industry.
Now, Qantas Airlines and I, I happen to, I was affected by this, although I only because my name's in it, not for any other reason. But, um, on on June 30th, um, Qantas was comp, the data was compromised, I believe it was ransomware. And they got personal data for 6 million customers.
That's a pretty good size number names, phone numbers for dates, things like that. No credit cards, no passwords, no passport information. So there was really no PII involved there.
That's good. But what happened, and I really think it's worth noting, is that the Board of Qantas cut the short term bonuses for all senior leaders by 15% because of that. And boy, if I, I'm ringing the bell for that one because not that I wanna see people, you know, e executives bonuses cut, but it's, we are finally, for the first time, it's 2025.
And, and boards of directors of companies are saying, Hey, you are the ones running the companies. You're responsible for making this happen. Something bad happened that probably could have been prevented.
You have to suffer because of it. And I am very happy that that accountability has started to show up. And I don't wanna get us too far from the whole ransomware and, and the systems we, we wanna count on, but that's a downstream effect that I think we're gonna start seeing more of.
And that's a healthy thing. All right, well see, there's another hashtag right there, you know, hashtag cyber bonus cuts. And we'll just keep going with that.
But Chris, I gotta ask you this question. 'cause I know you've talked about this multiple times over multiple shows now, but why in God's name do we keep having all these single points of failure? Are we unable as a, as a, as entities and engineers, especially just to look at these systems and kind of figure out where these things are gonna be?
'cause you know, in hindsight, at least it seems pretty obvious, but for whatever reason, we just can't seem to be able to figure it out. Well, we were talking biological evolution just recently, right? And, and saber, saber tooth creatures.
So you have to understand the reality of the situation we're all living through, right? So, you know, just sticking with biology for a minute, you know, you're following a certain path and you know, you reproduce. There's another generation, another generation, another generation that is the right path.
Now, will it extend indefinitely to the future, you know, past some punctuation event? Uh, maybe not. Uh, but they're separate issues.
And you know, in my very first, uh, cybersecurity show when we launched border where I think it was 92, it was in Atlanta, and I, I was brought up, someone came up to me with, with an oil refinery, and I said, oh my God, I forgot about oil refinery. You know, the whole oil ot world that I came from forgot about it. And I went back to my, you know, little five people and a dog, uh, company, and said, Hey, can we do anything for ot?
And the answer was, sure, and we can go outta business because we'll get one customer As, and Checkpoint is out there partnering with sun and yada yada. And at the turn of the century, I had exactly the same situation running the firewall business for Cisco. And we at the point that we had a, we were humming along doing 60, $70 million a month, massive, uh, uh, presence, and a whole team of, of Cisco, uh, uh, folks brought a whole set of oil industry to us.
And as the firewall team, we looked at it really hard and had to come back and say, no, we can't actually do it. You know, I mean, and to be clear, I I have a fiduciary responsible responsibility legally to, uh, Cisco shareholders who are, include not just the rich and powerful, but you know, retired people and their, their income to put money where it makes more money. And in 2000, um, as a vendor, I could not have fixed that.
And therefore, you know, at least from that source, which is a major source in the world, there was no solution. So what we keep coming back to is, is not that, you know, we're bad people or met bad companies are making bad decisions. It's just that there are intrinsic flaws with this when and if we hit various punctuation events, um, these are unlikely to survive the gap.
And I think, uh, the point of, of this particular topic and this ongoing conversation we have over the last, what is it, Mike, a year and a half or, or or more of, uh, of these, these calls, and we all have all these conversations all the time, is that I would, I would assert, I would, uh, pause it, that there's a number of, of chickens coming home to roost, uh, type of, of, of, of extinction events that are gonna be driving home. These sort of things that, yeah, long, thin, fragile, brittle, one by one, by one systems, uh, um, don't survive the break. I don't know, Jeff, maybe we should look at this entirely differently, right?
And just tell people that cyber attacks and these things are now a fact of life, and they are likely to delay your flight as much as a snowstorm, and we should just kind of suck it up. And that's just the world we live in. Well, I, I'm not sure I would use, we need to suck it up.
And snowstorms are more predictable, by the way. So, um, the, in fact, I am at, you know, two weeks ago when I was on this show, I was at an airport, um, when I did it. And today I'm actually, you can see I have my flying braces on.
Um, I'm on my way to the airport as soon as we, uh, complete this for yet another identity conference. It's it's conference season. But to, to your point about what's gonna get in our way, it's, we need to stop thinking about, we really do need to change our perspective, but I don't think we should just give in and say, well, you know, it's gonna happen.
Sorry, nope, I, sorry, I've been in this, I've been doing this 50 years, and I've never said, oh, well, I guess that's just the way it's gonna be. Never. Uh, and anyone I know that's had success doing this has never said that.
And it's always a matter of change your perspective, and it usually means expand your perspective. As an example, uh, when I would do, um, incident response or incident response planning and training, I would always focus on don't focus on what event caused your issue. Co focus on the effect of the issue, because there's gonna be multiple factor vectors that can give you that same effect.
What are you gonna do when that effect is felt? And then it doesn't matter if it's a snowstorm or if it's a ransomware attack, or if it's a union strike, it doesn't matter if your flight's interrupted. You need another way to get to where you're going or determine that you're not gonna go there.
So you need to expand your perspective to say, should my flight not happen or be delayed? How else could I accomplish what I want to do? You know, do I go try to rent a car or take a train or whatever it's gonna be That it literally, you know, that's, that's what, you know, well, season travel is, we li I, you know, you know, you're saying that as someone who does it, right?
Because, but I'm on a plane. I, on a, knowing that I have a connection, I don't trust the connection is gonna leave the ground. Sometimes they don't.
What am I gonna do? I'm standing in some country, um, and I, and I think, you know, we, you know, getting into the organization themselves and Mike note, you know, I, I don't think, because I love the, I love the, uh, the, the across the aisle sort of, you know, cynicism versus optimism, debates. We have, like, this mirrors a lot of my favorite conversations.
'cause maybe I'm wrong, but I think we are driving towards an era that isn't close. I wouldn't put it that way, but I think you can see it from here. And it's getting, it's getting into the, the frame where even people of my age are gonna, uh, uh, uh, in our working careers live in that world where cybersecurity gets at, where defense gets ahead of attack.
It's just that we've rushed ahead of ourselves, we build communication systems that communicate absolutely will communicate. However, are they secure? No.
Well, Jesus, no. And, and just, just not even, I mean, on every level. Um, and we're backing into the fact that we actually need to make them secure.
Now, an artifact of that is that everyone alive now is used to the idea that, well, cyber attacks and hybrids, blah, blah, blah, that doesn't mean that's intrinsically true forever. I think we are capable of building information systems that are a lot harder to attack than to defend. You just not, you just need to have things in place that, to date we have never implemented yet.
But they're, you know, the, and none of it really knew rocket science. I mean, I've got my own opinion on the things we can do right now, but you can look back over the decades and say, oh, that's right. People were saying that 40 years ago, 70 years ago, 120 years ago.
We we're just still in a very startup phase in our entire global communication system. Mm-hmm. All right, guys, well, we ran long on the first two blocks, so I'm gonna end this here, but I would give notice on this point, the airline industry many years ago noticed that there were just far too many plane crashes and they got together and all the engineers, and they decided to build more resilient planes.
This could be the same model that we can use, not just in the airline industry, but everywhere else we go to build more resilient IT systems from the ground up, because it's pretty clear at this point that we're just suffering because of our own lack of maybe foresight. Hey gentlemen, thanks for being on the show and sharing your thoughts today. That was great as always.
And thank you all for watching the latest episode of Techstrong Gang. Please stay tuned for the rest of the lineup for Techstrong tv. We got some awesome stuff as usual, and we'll see you all again tomorrow.
Hey everyone, welcome back here to Tech Drunk tv. You know, I don't know, there might be something in the water, but it seems it's, it's coming outta stealth season. Uh, we've covered a few companies this week, of course, that have come outta.
I've got another one here for you. And it's an exciting security startup. It's called Hush Security.
And to tell us about it, I want to introduce you to Mika Rave. Mika, welcome to Tech Drunk tv. Thank you for being here.
Thanks for having me, Alan. Nice. Hi everyone.
Yep. So look, first of all, congratulations, right? Mazel tough.
It's so, coming outta stealth is a big, uh, a big accomplishment in my career. I've done four or five venture-backed companies and, you know, launching them out of the stealth mode is telling the world the secret you've been working on. And, you know, no pun intended, 'cause you guys work secrets a lot, but, uh, congratulations.
But before we get into Hush meher, tell, give people a sense. How did you come, you know, what, what's your journey been like? Yeah, thanks, Alan.
So I've been, you know, working with computers since, uh, the third grade or so. Uh, been very enthusiastic about it. I liked it, you know, ever since the first, uh, um, trot CPC that I had, uh, like in 84, I've been using that, uh, been working through that, you know, through school, college, and through all, all my, uh, career basically, I started with, uh, you know, the, the electrical engineering worked my way managing teams of, um, of developers and engineers.
Uh, eventually ended up, uh, as a product manager, uh, responsible for a very big virtualization, uh, project, uh, with one of the companies I worked for. Uh, moving there from there to cyber. And then eventually kind of, uh, in late 2016, I was, uh, tapped on the shoulder by a friend of mine from way back when they were starting a company called Meta Networks, which was doing, uh, zero trust, network access very, very early on.
And so the technology was amazing. Uh, the people were great, and I, I kind of, uh, jumped on that, that wagon. The company was acquired, uh, three years after by Proofpoint, a very big, uh, you know, security enterprise.
Uh, and then, uh, we decided, you know, the entire core team and the rest of the, of the engineering team and, and the product team just came with us. We decided to move out and, and, you know, solve another big problem that was waiting to be addressed. And this is basically the exponential growth of, of non-human identities, secrets, uh, machine to machine access and so on.
Absolutely. Absolutely. And, you know, people think a company emerges outta stealth that all of a sudden it was born Today we just started.
But no, often I, look, I have friends who've had companies in stealth for two, three years sometimes. Yes. How long has the, let's call it the incubation of Hasin until, Uh, yes, that's very true.
We've been in sales for a year, right? Uh, we've been, uh, developing very rapidly the solution in various, uh, dimensions of it, right? And because we are, uh, a seasoned team that has been working, you know, together for past decade, but separately for, you know, more than two decades.
Uh, so we know, you know, we had a very good, uh, clear idea of what the, the solution would be like and what would be the infra for that, right? The, the, the ability to scale, the ability to design with security in mind, the ability to sell to the enterprises and the Fortune five hundredths of the world, all of those things, you know, you kind of acquire them as you go along and, uh, we've put all of our experience into this and pour it into this solution. We had one year to kind of, uh, hone it, and then now we are fitting that it's the right time to announce that to the world and start, uh, start getting some, uh, demand.
Yeah, Absolutely. And one last thing, Mika, what, what's your position? I'm the C-E-O-C-E-O and Co-founder.
And co-founder. That's true. Congratulations.
Thank you. Uh, Let's talk about Hush a little bit now. Hush.
Now that you're out of stealth, we, we, yeah, We, Um, so obviously you're deal tackling the Secrets problem, which is a, look, it's, it's a thorny issue. We've seen several companies, especially I'd say over the last year to two several companies really, uh, you know, going after this problem because it's, it, it's, it's a problem we've built up. I mean, the whole idea around doing secrets was, was in itself a good security.
And, and this is typical. I've been in security 30 years, you see this stuff. So we came up with the idea of having secrets and vault, and, and of course, HashiCorp, you know, kind led the way there a little bit.
And, and it sounded great. You know, another a, a good way of, of securing stuff. But it's a case where the solution became the problem a little bit, right?
Where we built up this whole infrastructure of secrets that then became a, a new attack surface, if you will. Yeah, right? That, that, And, and now, you know, it's like the old story.
We, we, we had elephants, so we got mice in to take care of the, The cat's got mice. Now we got a mice problem. Uh, now we gotta get cats, and then we get the cats.
We'll have to get the dogs to get rid of the cats and to get rid of the dog. You know, it goes round and round. But what, what about H'S solution is, is unique, is, you know, why, why is this the right solution to manage our secrets and secure secrets and vaults and so forth?
It's an excellent question, Alan. And I think the, the, it all started, you know, for us, right? The journey started like a, a year and a half ago when we looked at, at the, this problem, which was troubling us.
And we, this was part of, uh, what we wanted to solve. We looked at what was, uh, available at the market back then. And as you said, there were several companies, several very good teams backed by very good venture capital.
You know, we're, we're kind of doing, uh, uh, a thorough way of educating the market about this problem that is lurking within their data centers and, and clouds and so forth. And the exponential growth of secret. They did a phenomenal job in the education part.
But in my opinion, when we started to look at what we, they were developing, and we talked to a security practitioner, we found out that there wasn't really a solution. So it's one thing to talk about it and to scan, you know, and find, and try to find those and open geo tickets for them. But this is just a, you know, increasing your technical debt.
You are not actually solving the problem. You're still using, I would say, a broken, uh, architecture for, for the modern and complex environment that we, that we develop software in. And so we thought, you know, that's nice, but there's must be a better way to doing that.
And when we looked around, we actually saw kind, kind of parallel domains in which it was, uh, it was very well done. The, the first one is, is the human identity side of things, right? And, you know, think about what has been done in the past decade, like single sign on and MFA and, uh, IGA and Pam and so forth.
So the lab grade solution, you know, to help, uh, uh, mature the identity, uh, and, and solve the risk around that. The second place it has been solved, uh, quite nicely is cloud native environment, right? So when you go to AWS and you wanna access one machine, you don't necessarily take a key and store it in a vault to just write it policy, allowing that machine to access another machine.
And so we thought, we know how to do this. We need just to bring those principles and those methodologies into everywhere, cross cloud, on-prem, federated, uh, and done. Nice.
And a very, very important, uh, part of it is that we want to do it in a way that is kind of transparent or retrofitting to what customers are doing, because you don't want to go in and do like a multi-year project that costs hundreds of thousands of dollars and, and years of, uh, implementation. And so we actually found a way to do that, and we wrote a patent, uh, uh, on it. And, uh, we have built a platform around the, around that.
So, so first of all, comprehensive discovery, so you can actually see what you have and where the bodies are buried, so to speak. And then on top of that, we can actually transform you into policy-based access management rather than chasing secret. So in a way, we are going to obsolete the vaults and, and, and, and maybe the secrets as well.
Excellent, excellent. Um, so the, so I, I just wanna make sure we get this here for the audience, right? So that one of the real advantages of Hush is you don't have to be all in on the public cloud, on the hyperscaler, and you don't have to, whether you're a multi-cloud, hybrid cloud, what, whatever it is, right?
You, it's one solution across the infrastructure, Correct. For your, Yes. And by the way, we are using, you know, trusted framework and standards when we do that, right?
We don't wanna invent, uh, anything from the beginning. So for example, the base of our, uh, attestation is, is a spiffy, right? If you're familiar with that, it's a kind of an up and coming, uh, standard, which was have a very hard time kind of getting momentum behind it because it's quite hard to implement that on your own.
So we use that, we kind of bring that to the masses with a very, very easy onboarding team. And it's part, it's just one brick, you know, one component in our, uh, in our platform. And, uh, so we tend to build on, on, tried into, uh, standards and frameworks.
I got it. Let's talk, I wanna, Mika, I wanna turn a little bit to kind of the, the nuts and bolts of how people engage here. Um, sounds like, you know, if I'm a, an organization, I want to use hush security.
What, what, what, what's the process? What's it like to get started? Excellent.
So first of all, we need to connect, uh, to your infrastructure, agentlessly, right? So you give us a, you know, an API key or an, or an A RN or whatever the case is, we connect to your code repositories, to your infrastructure, to your SaaS. We scan whatever we can, and we build the, the initial, you know, inventory of, uh, of what you have.
And then on top of that, and this is where we kind of differ from anyone else, I think in this field, we map everything in runtime. So we have this set of runtime technologies, which we deploy very easily, and then we can see every machine to machine interaction and every authentication event that happens. And we've got so much telemetry, we, we upload some of it, uh, the metadata of that to the cloud, and we do some deep analysis with some ai, and we bring back very nice, um, uh, findings and result and, and basically posture for every machine to machine interaction that you have.
Excellent, excellent. Um, is there a free trial? Uh, how, you know, what, what, how, how's it packaged, I guess is the word?
Yeah, absolutely. So basically we allow a free assessment, right? So you come to us, there is a landing page in, uh, hashtag security.
Uh, you can go there and there is, uh, get a demo and get an assessment for free. So we can, you know, the onboarding is super easy. We can, uh, take, take our customers through that.
And, uh, and basically an hour or two, you've got all your environment, uh, mapped, uh, and, uh, and yeah, it's, it's, it's easy, as easy as that. Excellent. Yeah.
We, you're almost outta time, but you know, I, I feel like we didn't ask this question, or at least touch on this subject. Usually companies come outta stealth. It's, there's a, a raise involved with it, right?
'cause that of course helps us get out there, right? Um, talk to us about, uh, fundraising at Hush and some of the financial backers. Yeah, so our financial backers are, are amazing.
Uh, the, we've got Battery Ventures, which is a global, you know, uh, very well respected and known in the industry. And, uh, we also have as the cyber, uh, aspect of thing, which is Wild ventures, and then doing an amazing job. Uh, and so I couldn't ask for anything better, right?
It's, uh, it's a, well, uh, you know, known and backed one, which is better. And then we've got, you know, the, the cyber, which are experts, and they have their networks of advisors and, and CISOs. And so I think it's a great mix, and I, I, I, you know, recommend that for any cyber, uh, uh, innovators out there.
It's, uh, come talk to me about it. Excellent. Mika, again, good luck and congratulations.
You know, I, I think I told this once to a founder, this is the end of the beginning. True. And now you start on this next stage, and, and it'll, it's exhilarating.
It's, you know, but as long as you have the passion, if you have the passion for what you're doing and believe in it, it, it's, it's great. Um, keep us posted as you guys continue to expand here. Maybe we'll see you, I don't know, at some security conference in person.
Oh, Absolutely. I'm gonna be everywhere, so, uh, I'll, I'll look out for you. Alrighty, good luck.
Uh, thank you very much. Thank you. Hush Security, and it's hush security.
Go check it out. Managing Secrets, a real problem is a real solution. We're gonna be back on Tech Trunk TV in a minute.
We'll take a break. Hey guys, thanks. With Throw, we're here with Zach Lloyd, who's the CEO of Warp, and we're having a little chat about something called Warp Code, which is a whole new way of thinking about CLI for application development in the age of ai.
Zach, welcome to the show. Thanks for having me. Excited to be here.
All right. Well, I'm not sure everybody knows exactly what Warp is or what Warp Code does, but maybe walk us through the fundamentals here and why do we need a different way of thinking about the CLI? Yep.
So the, I'll start with just like the basics of Warp itself. So Warp, um, started, uh, three or four years ago with the idea of, uh, improving just like the fundamental terminal interface. The, um, you know, the kind of genesis to the idea was I've been an engineer for a really long time.
I've always worked in the, in the terminal, never been a terminal power user, but I've always worked with people who were, um, really good at using the command line and wanted to build something that made that power more accessible to other developers. So we spent the first couple years of Warp just trying to make the terminal more usable. Um, when ai, uh, started becoming more powerful, uh, even before sort of chat GPT, uh, we started building features into Warp that would allow developers to, uh, sort of translate natural language into terminal commands.
So if you're like, oh, I don't know how to, um, you know, find files across my directories or do certain advanced things in gi, you could, uh, sort of ask or in English how to do that, and it would give you the terminal command. Uh, as LLMs became more powerful, we realized like the terminal interface itself is actually a great interface for interacting with ai. And so instead of just using like terminal commands to drive your computer, uh, you can use, the biggest thing that's different in war versus another terminal is that you can just use natural language directly to ask your computer questions or ask your computer to do things.
So, for instance, you could be like, set up a new project for me with React and TypeScript and Warp will do it for you. The, um, as like, um, the models become more powerful, we realize like people want that sort of interaction, not just for doing things that are traditionally terminal tasks, but just doing coding. Um, which is probably like the number one developer activity.
And so the most recent thing that we've launched in Warp is a way where you can do a agentic coating. So you can, you know, simply tell your computer what you want it to build, what feature you want it to build, what bug you want it to fix, uh, in natural language. And it looks a lot like a terminal interface, but it actually can do things that are more typically in a code editor.
So like, it can produce diffs, it will show you a, uh, way of like reviewing your code. So it shows you the active Diff, um, it, uh, basically makes the coding experience where you, if you're starting a coding task with a prompt much better. How does that differ from all the other AI coding tools that are out there?
Are they kind of trying to wrap some sort of graphical environment around it and most developers don't seem to enjoy? Or what's the difference there? Yeah, so there's really, um, the way I think of it, there's two other kind of buckets of, of competitor products that have different approaches.
So one is like the kind of AI enabled IDE. And so this is something maybe like Cursor or uh, GitHub co-pilot where the fundamental interface, uh, is still like a code editor. So you're opening up files, you're looking at code, you're handwriting them.
And kind of the best feature in those apps, in my opinion, is like AI driven, auto complete. So you, you type and like you see the ghost text of like the computer, uh, of like, of the AI suggesting what, uh, should come next. Those tools also do have like agents in them, but they tend to be in a sort of chat panel.
And, um, you know, it's, it's a less natural way of working with agents than just having like the whole interface dedicated to the agent. The, um, the other thing that's really, I think, more usable in Warp compared to those types of tools is like, um, you know, you can do stuff, uh, across multiple projects at once, whereas the IDs tends to be very like one project at a time workflow, and you can do things across the whole software development life cycle. So Warp is really good for setting up new projects for coding on them, but then for also like deploying them, debugging them in production for interfacing with like your cloud services.
So the terminal is like, kind of like one level deeper in the stack. Uh, and so that's makes it, I think, a better option than the IDE based alternatives. The other set of tools that have caught on lately are things that are like, um, cloud Code or Gemini CLI that are like, they're not terminals, they're apps that run within the terminal, so they're like CLI apps.
And so those are, um, it's a very, it's a similar way of working to Warp, but with a much more limited, and I think hard to use interface because you're limited to, uh, just like a purely text-based app. And so, you know, like you, you don't get editable diffs, you don't get the ability to review, uh, an agent's code in a code review pane. You don't get a file picker.
So there's, there's all these like kinda limited things around working in a purely tech-based environment that I think, um, you know, warp makes much easier and, and gives you a better developer experience with. Is this also likely to appeal to software engineers that are running DevOps processes? 'cause they typically work within that terminal as well.
And I think a lot of the AI coding tools are a little more tuned towards traditional developers without thinking through maybe what software engineers need. Yeah, I, I totally agree with that. So that's one area where Warp is like really strong as for DevOps and production for people who are more comfortable in general in the terminal who are doing tasks that are more terminal oriented tasks.
Um, I think the other tools also are more widely adopted by like Vibe coders. So, you know, people who don't even really necessarily know how to code. And we have some people like that who use Warp, which is cool.
Um, but we're focusing more on pro developers who want to, you know, get to shippable a AI generated code, which means like, you know, as a developer, you really need to understand, uh, what code an agent is writing. You need to be able to review it, you need to comprehend it and like be able to stand behind it as though you wrote it yourself. And so we're, we're not really focused on the use case of like someone who doesn't know how to code making a whole app and Warp.
We're much more focused on the use case of a pro developer who wants to use, uh, AI to accelerate their daily workflow. Mm-hmm. And what is the impact of AI so far that you've seen in terms of what it means for professional developers?
Because to your point, I'll talk to them and they like the idea of it, but then they struggle when they have to debug an application 'cause they didn't write the code and they don't have a lot of understanding of what's happening in there. And so then they get a little frustrated. Yeah, this is, this is a hundred percent the biggest problem with it right now.
So if, like you said, if you look at the Stack Overflow, the latest Stack Overflow survey, um, the top two complaints, a, about AI generated code from pro developers are that the AI produces code that's hard to understand and has subtle bugs. And then the second thing is like, it's really hard to debug and work with code that you didn't write yourself. And so, um, these are, I I think there's a couple approaches to like fixing this, um, and being productive with, uh, with agents.
The first thing is like, I think it's like a, almost like a cultural thing or, or just like a how do you as a developer approach working with these tools if your approach is like you're just gonna like tell an agent to build a future and expect to get good chipp able code out of that. I think that's not really where we are today, frankly. Uh, it might work for like small, for small things where it can sort of like, just like do it in one shot it, but more typically, uh, if you take that approach, uh, you're gonna get code you don't understand, that might be buggy that probably won't work, or maybe it'll work, but you won't understand why and it won't be mergeable.
So what you have to do as a developer is change your approach when working with AI to first off, specify not just like what you want to build, but you have to specify how you want it built. And so I think that means like, um, you know, working with an agent on a, uh, first of all, just like understanding the code before you even ask you to build anything. And so these agents are actually like awesome code explainers and like code explorers, like they can, they can help you get familiar with new code really, really quickly.
Uh, and then the next step is like, once you understand the code, it's to be, you know, iterate on a plan, uh, or a spec, whatever you wanna call it, where you get really clear with how you want something to be built. Uh, then you, you know, then where the agent can really save you time right now is in like, implementing that plan. Uh, and it, it, uh, you know, you don't get as many surprises if you do it that way.
The third thing is that you should work in small chunks. And this is just like good engineering practice in general. Like, this doesn't really have anything to do with age agent development, but like, if you try and do one huge thing with an agent, you're gonna have the same problem as if like you wrote, you know, one huge PR on your own, you'd never want, like some, you'd never wanna review a giant PR from someone else on your team.
And so, like the way to do it with agents is, um, you know, specify a small piece of it, maybe you have it, like write a few functions or write the model layer or just write a, a part of the API verify that it's right, write tests for it and continue. And so like you have to like kind of think of it as like you're guiding like a junior engineer to write code. Uh, and if you do that, I do think you can get really great, uh, productivity gains out of it.
It's just like you have to have like a, a reasonable mindset around like, you know, how to work with it and not expect sort of magic. Mm-hmm. The, um, and so the, you know, I guess one of the big things that we're focused on feature-wise at Warp right now is like, how do you make that workflow really, really seamless where it's not just like fire and forget and let an agent just like go off and run and like do your thing, but like, how do you review its code as you go?
How do you work with it to get to a good plan? Um, and so those are the types of product features that, that you want. If you're a pro developer doing agentic development, How will this all evolve in your mind?
Is each developer gonna have one AI agent that does a bunch of things? Or will there be multiple AI agents that are trained to do various things? And if I'm on a team, well then we all have to coordinate our AI agents amongst ourselves, or maybe there'll be AI agents on the team that are trained to do specific things on behalf of the entire team.
Yeah, so it's a great question. So in the short term, I think it's totally fine to have like every engineer has their own agent set up because, um, it's like, it's very much the agent is in the inner loop, meaning like the agent is in like the part of software development before the engineer even shares their work. And so it's, in a similar way, it's fine for every engineer to have their own different IDE set up.
I think it's okay right now for every engineer, like use their own agent to, to help them get to a, a pr, they want someone on their team to review. I think as agents move to the cloud, which I think is starting to happen, um, it makes more sense to standardize. And so that, you know, like I think something that's gonna happen is like you're going to have agents writing code based off of system events, meaning like, oh, there's a crash that your crash reporting system has detected.
Okay, an agent is gonna be listening to that and write a draft pr and that's not even involving like a developer per se, in their personal setup. So for something like that, I think it makes much more sense for people to standardize, but we're very, I think we're very, very early in that workflow, uh, and where we are today. It's like, it's much more like, can you get developers accustomed and comfortable working with the genic workflow in a way that suits, um, how they like to work.
Mm-hmm. What do you think will happen with professional developers? 'cause every time we turn around somebody's saying, well, this is great, we won't need professional developers.
But as far as I can tell, somebody still has to at the very least, manage all the AI agents. So how, you know, from your perspective, you know, what's reasonable expectations here? Yeah, I think, um, I don't think professional developers are going anywhere anytime soon.
I think, um, if you're a professional developer, the smart thing to do is like invest in learning AI as another tool. Like, I think that's, that's where we're at with it right now. It's like, it's a tool and if you learn how to use it well, you can become a way better developer.
And so I don't think it's like a great strategy as developer to be like, I'm, I'm just gonna ignore this because it's like, yeah, I dunno, what's a good exam? It's like, oh, I only wanna work in Assembler. I'm not gonna work with compiled languages.
Like, that's like a self-defeating, self obsoleting approach. But I also don't think that there's, like, there's not like real risk, like at the moment, uh, every company I know is hiring more pro developers. Um, warp is hiring more pro developers.
I think if you are, um, a pretty inexperienced developer, there is risk. Like, 'cause like, it's the same kind of risk that exists from like WordPress or website building platforms, displacing people whose primary skill was like building websites. Like, like if your primary skill is like building something that an AI can totally build all of its own, I think you need to uplevel your skills.
But for by and large, for people who are working at, like, on either enterprise software or complicated consumer software for their job, I don't think there's like super big risk right this minute. Um, you know, the model's changed quickly, so I won't say like forever, but I don't like, we're hiring engineers right now. It's very competitive.
So I don't, it's like it hasn't really changed. Hasn Changed. So what will be the ultimate outcome?
And I ask this question because some folks say we're about to build more software in the next two years than we built in the last decade. But in my mind, it also just seems like, well, maybe we might build software a little bit faster, but maybe we'll just build better quality software with less stress. Yeah.
So I think it depends like what kind of software you're talking about. So there is this emergence of this new kind of software where never would've been economical to build software before. Um, but an agent can build it for you.
And so this is almost like personal software. Like I know people who are building like ad hoc things to manage like their wedding or whatever. And so it then, who are not developers, they'll go in, they'll use like a tool and they'll use something like they could to use Warp, but they might use something like Lovable or Bolt or whatever, and they'll, they'll build an a disposable personal app that will only be used one time.
And so that's like a whole new kind of software that never would've made sense to have been built before. So there's, there's gonna be more of that in the like, professional context. Um, I think it's more like what you said, like, I think it's like a productivity multiplier if it's deployed correctly.
Um, I, uh, you know, I don't, I don't, I have yet to see someone build from scratch. Something that's like a truly, you know, hard to build app like Warp or Figma or Google Docs or like what, like, it's just not a thing. It, like, it's, it's too hard and for the agents to do right now.
Uh, and so I think what you'll see is like AI gets deployed as a tool. It's, there's like a percent acceleration, which depending on the type of task you're doing might be, might be small or might be really big. Like it tends to be really big in circumstances where, um, you are doing something as a professional that's like, would it like zero to one, like in a language you don't know.
Like there are all these cases where it can really accelerate, but for day-to-day development, I think it's like some percentage acceleration and will, you know, help companies ship better software more quickly. All right, folks, you heard it here. The way we build software is definitely changing, but the key thing about all that as well, there's still humans doing it.
Zach, thanks for being the chef. Thank you for having me, Mike. This was great.
All right. And back to you guys in the studio. Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders who are shaping the future of digital defense.
I'm your host, Carolyn Wong, tech Strong TV podcast features your favorite video series, industry thought leader commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity both as a weapon for attackers and a shield for defenders. The AI security edge dives deep into the evolving cyber battlefield where AI driven threats challenge traditional defenses and cutting edge AI solutions offer new ways to fight back.
Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, we hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense. Today's guest, lemme see if I can say this right.
So there's an American version, which is Francesco Sip, but then I'm gonna try Chip sip. I, I tried. And then, and then, and then the proper version.
We're gonna try Francesco Chip. Yes. Boom.
We better now. Okay. I'm like extremely proud of myself for that, but you know, just, I think that might have been like a one-time thing.
So we're gonna call you Frank. Frank, thank you so much for joining us. Frank.
Frank is a cybersecurity leader, entrepreneur and thought provoker. He is at the forefront of application and cloud security. The most important thing that you need to know about Frank is that he was a practitioner and now he's a CEO.
He is the founder and CEO of AppSec Phoenix, also known as Security Phoenix, a company that is pioneering contextual, risk-based vulnerability management from code to cloud. Frank has done all sorts of cool stuff at h hsbc, at a Ws, at the UK and Ireland chapter for Cloud Security Alliance. He is a professor at Ions.
He is a multi award-winning podcast host. It's actually weird for Frank to not be the host right now. He's a regular keynote speaker, he's an author, he writes books, white papers, articles, and, uh, he's also a self-taught artist and a former professional skydiver.
So if this is the first time you're meeting Frank, I'm so excited for you because you know what, Chad, GPT, uh, there, which is actually like, that's an AI use case, right? Um, if this is the first time you're meeting Frank Bo are you in for some good stuff? Because there's so much good stuff.
Frank, welcome Caroline, as always, you shine. Thank you for having me. So Frank, what did you find?
All this stuff, everyone, uh, literally it's chat, GPT. So everyone on this podcast, I, I like to ask the same questions, but, but you're not like a, you're not like a typical podcast guest. Not really.
And so I'm gonna ask you a different question, which is tell me what you actually really think about all this AI stuff. Tell me the real brutal raw truth. It's a bubble.
Uh, uh, Uh, but it's a cool Bubble. Okay. Okay.
Tell us more about this bubble. com bubble. com or not as experienced.
Instead, right now, we have organizations still trying to figure out how to prioritize vulnerability, how to do cloud, how to do software, while attacker extremely enthusiast about, Hey, let's use this technology, or let's weaponize the model that are trying not to do it. And I think Tropic has published, uh, a recent playbook on how attacker are creating new method and way, and they, of course, they're trying to stop, they're trying to ban them, they go through, but we start seeing case where LLM are weaponizing vulnerability or are being used to attack ransomware. So AI has lowered the barrier of, of, of access for cybersecurity professional, but also for attacker.
And we were overwhelmed before, like I think right now the difference between the DO com bubble and right now is we're seeing this technology but exciting, but we're seeing it as faster growing as a weapon and as any new technology, we are seeing the rush to market. Of course, Trump insecurity read us as MCP because API security wasn't hard enough, so we needed to have GraphQL. And one of my good friends is saying, I love any GraphQL because I can hack the way through it very easily.
And because that wasn't sufficient, we had to create MCP. Actually, we release our MCP server and we shut it down for security concern. I'm proud to say it because we did a threat model on that and saying, that's not good enough.
But how many people out there are throwing the MCP out in the world and saying, yeah, it's secure enough, right? Frank, I I have to pause you for a moment because there are folks listening and watching who know what GraphQL and MCP are good for you, and there's people who don't. So for the folks who don't give us a little bit of background, talk to me as though I'm my 75-year-old mother-in-law, or my 10-year-old daughter.
I, I think you might be right. I, I get over excited about technology sometime and I think that everybody lives in the world of stuff that my brain leaves. Um, sometimes Only the really smart ones, All the crazy one.
Uh, but thank you for the compliment. I think when we look at the internet, we had the history of API that were soap XMLs of very ancient way to pass data through a system that expose a web interface, and then we kind of settle on rest API That is the standard method where we taught really, really well and long about how to secure those things, how to create that entity. So I think rest API has been around for very long time, but for rest API, you had to create basically endpoint for everything that you want to do.
And that is means development. So some of the dev team has said, why not throw caution out of the wind and open everything to everyone? Just query whatever I want and I expose anything that I want.
Because that has worked out well for us in the past. So that's was the history of GraphQL that you can secure, but it's really difficult to constraint or provide access control because fundamentally you can tell, gimme the information about this, this, and that. And GraphQL will say, gladly, here you go.
Uh, do you have the permission to see that stuff? Hopefully you have your pass through credential or pass through authentication configured. Most of the time you probably don't.
So you create just access to your data lake and if you're lucky, you just see what you wanna see. Um, but it's very difficult to control. Now, MCP have been built in a rush on a protocol that has two or three version and eight to a was the evolution of the MCP protocol, but authentication was nowhere to be seen.
And all to authentication token being passed through or authentication and authorization have been kind of left in the world. So we're seeing MCP being exploded up, down left and right because it's a new technology and because it just rely on not very strong foundation of authentication and access control. And that's one of the reason why we shut down ours because our API will build with Phoenix security with specific method in mind.
So we put, uh, an MCP server in front of it, and it gives, it gives you access in a different way that we want. And we expected, so we did a, like any security folk would do a threat monitoring exercise, we deem the things not secure enough and we say, you know what, let's leave the hype to the hive and I'd rather not get hacked than be late for a few weeks. Um, and that's what we did, but I think we won the few that actually take that in.
That's so interesting. Uh, humans want to use technology to share information and then they end up sharing it with people that they didn't wanna share it with. And if you're intentional about putting some calls, controls in place, then it takes more time, it takes intentionality.
Um, and now we have not only automation, but we have ai. So the problem is just worse, more data, more places for that data to be more places in our supply chain to poison and to steal information from. And so Frank, I think yeah, please.
When you Have, we have, I've been thinking about this very hard and very strong, like why LLM seems so attractive. It's like, why is so easy to get caught into the perception that we have an answer? And the answer was there is the fact that LLM always give you an answer despite that it's good or wrong or whatever, or whatever precision you have, you always could get an answer.
It might be wrong, but you always get an answer. So it feels that you making progress despite that you are actually making progress or not. And that's the intoxicating element of LLM.
You don't know anything about API security, I'll ask LLM to do, teach me about API security. You don't have context. You haven't asked us specific things, but it will return you with some stuff.
Um, hey, I have this code. What does this code do? I wanna do these particular things.
It will give you an answer. It's probably wrong. But that's why the excitement, because the barrier of acquisition have been lowered, the fact that it doesn't always speed the right information is a different story.
And hence why people that understand how AI was built. I was building bias and network and neural network back 10 years ago when AI wasn't cool. And me and my co-founder understand really well how AI was built.
And a m is just a variation of an ai. And if you understand how it works and how it was the right question, you become a superpower because it really 10 x you. And I think I'm, I'm surprised by the kind of things that if asking the right questions, it will give you the right answer or it will speed up your work, but also can slow you down tremendously.
Or it can create a generation, I think of no brain coder and as an industry, I mean you in threat mode or was we, we, we go long time, me and you, and we are seeing the industry kind of trying to make an effort. I think right now we are creating a generational people that don't think securely or they don't even understand what they vibe coding. So that's a little bit my fear of creating a generation that doesn't have the understanding or the baseline understanding, but just go with it and vibe with it.
And you can vibe secure coding. I mean, our good friend Jim has created a whole training about vibe coding securely. And I think you can, you just need to know what to do and what to ask and how to ask it.
And you still need the principle to be in there because AI will not magically secure your application. So Frank, uh, what I hear you talking about is a comparison. Uh, there is kind of like the no brain way to use ai.
And there is on the flip side, a very powerful way to use ai. And so my question for you is, what advice do you have for our listeners to be, not the former, but the latter? How can we all learn to be the best users of AI and not the no brain ones?
That is a great question. And for that, we've broken our manifesto. What, what, what, okay.
Uh, It's not yet public, okay? So we call, oh my gosh, AI Tell Us everything. Ai second human first, Ai second human first, the manifesto tell us everything.
So I've been thinking a lot about this, and I think with all this hype, we tend to, we tend to place AI first. You see a lot of company coming out and saying, we are AI first. AI is gonna solve all of the problem in the world, and it's so cool and it's whatever.
No, AI is just a tool. And like blockchain was just a tool. Let's try not to create solution before we have problem to solve Engineers.
And I know, right? But in general, if you, if you treat AI or LLM or vibe coding as a technology, as a tool, and you learn how to use it, you become really powerful. And I think in few years that's what's gonna distinguish the people that talk about by coding LLM, but they don't know how to use it to people that have experience and know when to use surgically technology for that experience.
And hence why we say human first, empower by technology like an lm like a chatbot, like an AI tool to 10 x their capability. But ultimately you'll never be able to fire an ai. So decision will never be able to be delegated to an agent.
But an agent can 10 x your engineers. So if you train your engineer well, junior and senior to use technology in the proper way, then you have a force of nature. And I think our attackers have understood that.
Well, first, some haven't. Some vibe codes write me the, um, what was it, what's a ransomware letter for the FBI for the director of FBI? Because we have all that data.
Uh, and somebody has came up with the same kind of things with Google without any proof and without proofreading or so on. But in general, you have people that understand this technology and they wanna use it and AI second, and you have people that put AI first and they will be left second. Yeah.
And hence the manifesto. You know, I'm so excited for this because it truly is the message the world needs to receive right now. You know, a year ago, and still today, every board on the planet wants everyone to use AI for everything.
You know, every engineering team is being told Use ai, use ai use ai. No one is talking about how to do it properly, how to do it. Well, boy, is there a difference between doing a thing Yeah.
And doing it Well, I, I can't wait. I can't wait. Who, who, who, uh, who's coming up with this manifesto?
Tell us about the creators. So I generate the first idea. I sent a few of the leader that you well know, Azar, a few others that have done their first pass on it.
Um, few other CSO and, uh, thought leader as well have contributed on it. We'll have the full, I think we have 25 right now, reviewers. We try to mix practitioner and CSO and non technologists to actually come up with a message that was sustained by both practitioner in security field, leader of CSO in the security field and non practitioner to actually write something.
And we wanted to keep it purposely short with 10 commandments that really say, think about these things securely and think about this as a technology. Like that's the underlying mean. We can go through the manifesto, but that's the underlying message of the manifesto.
Like, use the, use this technology as a technology, use it wisely Like by code. Absolutely by code. The head of things.
Um, as A-C-E-O-I push for AI adoption, not AI first, but AI adoption to all my engineering community. But also we have guard rails and we have methods of embedding things. And we are actively researching how to insert secure prompts in the vibe coding thing.
So they will always return a secure vibe coded message or prompt. Like that should be the core of what we do. And the core message of what we do.
It shouldn't be, if you don't use a vibe coding tool by Tuesday, you're fired like some CEO have put. Yeah, I think that's a wrong message because that's, that create that people will adopt, people will adopt and people will make mistake because it will delegate thinking to the technology. Well, this should be a thinking aid.
It shouldn't be an outsourcing and it might be unpopular in this opinion, but I rather us going forward with the eyes well open rather than creating, what was it, the movie Terminator? Sorry, I had to throw it in there. You know, Frank, what I like about this is what I'm not hearing from you is I'm not hearing any fear.
What I'm hearing actually is a sense of empowerment. You recognize the power that we have as humans. You know, do we store tremendous amounts of data in our heads?
Yeah, we do actually. You know, do we have decision making? Do we have discretion?
Do we have judgment? Yeah, we, we do actually, you know, and so I'm delighted to hear this sort of elevation appropriately of the human, uh, and who is in charge, right? The human or the machine and better.
You can Fire, you can fire a machine like ultimately comes down to that. Like you wouldn't be angry at the machine because it does machine job or it doesn't error or it has a bug. Ultimately, technology is technology.
And we need to recognize this as a technology. That's we, that's what we, in Phoenix, we created our AI agent as co pilots that aid decision making process, but empower people to make those decision. Ultimately, we present three remediation plan.
We don't know better than the engineer. We give you guidance, we give you insight, we give you direction. And we say, based on this, and we explain the reasoning as well based on this, this is why we're doing specific things.
But then if you think that fixing things by a specific asset or fixing things by a specific threats attack vector is better. Choose that remediation method. So we want to empower instead of replace human cool and security engineers.
I love it. And a lot of people are scared right now because they, yeah, this technology feels like is is AI is gonna replace or go or come for my jobs? If that's the fear, then you're in the wrong job.
You need to elevate yourself to use technology. I think that's where the fear come from. And you have I think two sides of people that fear a technology because they feel overwhelmed.
And by all mean this uh, scary technology because it seems to be able to do everything and nothing. So either you embrace it or you be left behind. And that's the hard truth.
So it's better to embrace it, use it securely, and be at the front edge of this. But if you were doing spreadsheet yesterday, I'm sorry, this will be replaced. Yep.
Hard pill to swallow. Uh, but I agree and uh, Frank, as we're kind of beginning to close up our conversation today, for folks, maybe today's the first time they've learned about Phoenix security, tell, tell folks about Phoenix security. So long story short, we were a bunch of practitioner that were leading AppSec and cloud set transformation in most of the banking world.
And we wanted to solve a problem that is how do we align executive expectation to engineering action? One of the frustration that we had was when we talk to engineers as security practitioner and as security leader, we tell them, you shall secure your system. And when they look at us and say, what does that mean?
We don't have an answer, or if we have an answer is, well, you need to fix your vulnerability by SLA or you should do threat modeling. Okay, teach me, I dunno, this is a template to use it goodbye. I don't have time, we don't have scalability.
So we wanted to empower, first of all, engineer to understand this is what security expect of you. And then we wanted to align that message with business expectation. Because if it's not important for your boss as an engineer, you're never gonna be giving attention to a particular problem.
So we wanted to solve the problem of security across application security and uh, cloud security. That is called vulnerability management. That is a problem that we had for 20 past years and we wanted to solve it from a business perspective because that's the only way it actually work.
And then in that journey we evolved that with asset inventory. That is also another big problem that we discover in the journey, saying, if we don't know who needs to fix what, how can we tell them to fix stuff? So we open source our CMDB, yamo based CMDB to empower every engineer to declare this is what I own and I don't have to log into an ancient 1999, uh, black screen with green line system.
I can just declare a yamo file in apo. And that's automatically configure Phoenix to say, this is the stuff that this team owns. So if they have vulnerability and you expect them to fix it, we're gonna notify exactly who needs to fix what, where, and ex tell them why this important.
And in a nutshell, that's Phoenix. That sounds really cool. Frank, if you could go back in time and do the job that you were doing at HSBC, what would it have been like for you if Phoenix Security technology had existed?
Well, it's funny that you asked because that's where Phoenix was born. Incredible. We created that for ourself in there because we had that frustration because we couldn't translate an executive saying we should do security.
An engineer saying, what does that mean? So we created a way for executive to report this is the percentage of security that we want to decrease. This is the risk level we wanna go.
This is the amount of money that we wanna reduce in terms of direct and indirect impact. And that very high level message that a non-technical, um, or risk base executive can express, could be translated to engineers saying, this is the vulnerability that you need to fix. This is where you need to fix.
And we as security were coming and saying, look, if you look at this library, these system, these things, you actually maximize your risk reduction. So you will look way better for your boss. So instead of demonizing engineers who were coming and aiding them to get to their target faster, and look, that was four years ago.
So it was a very, um, early stage Phoenix. But that's what the gamification from a business perspective and from an engineer perspective is what have enabled us to move from resolution time of 290 days to 20, 30 days. Nowadays, it's not sufficient anymore because I think with the latest data that we've seen, exploitation time fluctuate between three minutes and seven days, depending on what kind of data source you look.
So 30 days is not anymore for critical, but if you don't know who does what, probably you are over a year of remediation. Yep. Frank, last last thing that I'll invite you to consider doing with me.
I want you to teach me how to say your name properly. Can we, can we try this together? Let's, let's try.
Please say it and I'll see if I can repeat. So I usually, it's a funny joke and my partner always makes fun of me because I say I go by Frank for friends. And then if somebody doesn't call you Frank, it's like, does that mean that they're not your friend?
So I don't realize it's, it is, it is something that is ingrained right now with me. But if you wanna try in the Italian way and you did it beautifully actually, uh, it's Francesco chip. Francesco chip.
That's great. Yes. Okay.
I'm so happy. Um, gosh. Thank you.
Thank you So much. Honor Italian now Thank you for your time today. Thank you for your wisdom.
Thank you for the work that you're doing for our industry. I cannot wait to read this manifesto and tell the whole world about it. Thank you.
Brilliant. I think you worry man. Needed.
But thank you so much for ge having me on this side of the podcast. It's my pleasure. Folks.
Text Drunk TV podcast feature your favorite video series, industry thought leadership commentary, analyst research on so many topics including AI and cybersecurity, but also DevOps, cloud Native Digital transformation. Uh, come on over to Techstrong TV podcast to find all of your great content. This has been the AI Security Edge.
I'm your host, Caroline Wong. Thanks for being with us today. Hey everyone, it's Alan Shival and we're back here on Tech Drunk TV in beautiful Napa Valley at the Jfr Swamp Up event, continuing our Day two coverage.
There's a little bit of a break going on, you can't see, but out there people are eating ice cream and peanuts and potato chips. It's a little mid-afternoon break, but we're still here 'cause we've got a lot more to bring you. Let me introduce you to our next guest.
If you've been watching Tech Junk TV over the years and any of our coverage of Jfr, you already know him, but I'm gonna pronounce his name right for the first time. 'cause it seems my pronunciation is a little old fashioned. So let me introduce you to Yoav Laman.
Perfect. Diana, nice to Meet you Yoav. It's good to see you.
Yoav, of course, is a co-founder, one of the co-founders in CTO here at Jfr. You have a pleasure. How are you?
Likewise Busy. Lots of announcements. This warm up.
Probably The most, we're A few warm up that we have had, uh, lots of good, good feedback from customers and, uh, also some suggestions. So, uh, And that feedback's, that's, That's the goal actually. You know, what they say, the feedback from this year's Swamp Up will be in the products for the next, Next, hopefully even Well before with ai.
We have to. So you, we were talking, you know, before we got on, we have had a lot of people give us a piecemeal, a piece here, a piece there, a piece there. I'm gonna ask you, pull it all together for us, right?
Give us the a go overview of all of these great announcements, all this great innovation mm-hmm. That was announced here at Swamp Up. Okay.
So I'll try to give the full umbrella of announcements that we made. So we started with Jeff O Fly and Fly is, uh, uh, our own disruption of the platform for, uh, a new agent, uh, repository based on Artifactory. And that's, uh, that comes with, uh, a new user experience for managing software releases.
Uh, so that was our first announcement. Then we went over to, uh, UPT Trusts. And UPT Trusts is, uh, the way to control your software supply chain based on three, uh, major concepts.
First one is application that gives you ownership assignment for every release, every artifact, uh, in the JO platform. The second one is, uh, signed evidence and we announced, uh, partnership, uh, with many leading industry vendors, uh, such as GitHub, such as Sonar, such as ServiceNow, uh, to, uh, uh, integrate their evidence, uh, into, uh, into the JO platform to accompany the the releases. And, uh, finally, uh, it's, uh, policies that, uh, allow you to use the information, uh, within the JO platform, use evidence in order to assign rules for the progression of your artifacts, uh, of your releases, uh, all the way towards, uh, production.
Uh, so this is Apru. It's a, it's a unified package that includes all these, uh, three main features, uh, ownership evidence and uh, uh, policies. Um, so that was, uh, uh, another announcement.
We also had a deep dive to our integration around evidence with, um, with GitHub to take the salsa provenance of GitHub, uh, workflow build and put them alongside artifacts in the JFO platform, uh, as evidence, which is, when you come to think about it, it's the logical thing because, uh, you, it makes sure that, um, that the evidence itself is bound to the artifact and you can never get out of think. And it's also the fact that Artifactory is the entity that is exposed to your production. So that's, uh, one thing that where we did a deep dive of UPT trusts.
And the other thing is we announced on stage and integration with ServiceNow around Atrust as a, as a full, as a as a whole. And we show the synergy between applications that many of our customers are already managing in ServiceNow, and how change requests in ServiceNow are going to be, uh, reflected as evidence in, in, uh, in JO, uh, and vice versa, how, how you can move between the platforms. So that was, uh, also, uh, part of the big announcement of apta.
Yes. Then, so it's a mouthful. Then, uh, we move to, uh, uh, a new announcement, which is, uh, around machine learning and ai.
This is AI catalog. Yes. And AI catalogs, uh, allows you to have governance over, uh, models that are packages, but also models that are, uh, uh, sa like, uh, an and open AI and so on.
Uh, under a single platform, you have a catalog where you can find the latest versions of the models and the metadata about them, like, uh, the security status, the, the licensing, and, and, um, other metrics that have to do with the model health. And then, uh, similar to what we have, uh, uh, in curation, uh, we elevated the same features for machine learning. So you can allow different teams to use different type of models.
Um, for instance, you may allow a research team to use deep seek, but you never want to see that, uh, in a production facing, uh, uh, release. And part of that, when it comes to, uh, to SaaS models, is, uh, also being a gateway between you and the SaaS models. So if you, for instance, if you're using open ai, uh, you will use it through the JFO platform.
And that allows you to have governance also of this type of models. Uh, so, so this is, uh, this is the gist about the AI catalog. Mm-hmm.
And then we went into a bunch of security related, uh, announcement. I think I, I can mention two, uh, highlights there. The first one is the support for ID extensions.
Yes. Uh, and, uh, basically it's a combination of artifactory acting as a proxy for your, uh, vs code extensions. So we start with VS code, we will extend it to other ideas and, uh, curation allowing you, uh, to, uh, to, to control the, the, the, the, the extensions that your developers are able to install on their, uh, endpoints.
And this is one of the most dangerous and overlooked, uh, risk that developers are, uh, currently facing because you basically install a software on your, on from the internet that everyone knows that it's wrong. But, uh, for some reason with the ID plugins, it's assumed to be safe. It's not.
And we demonstrated, uh, uh, a social engineering hack that's, uh, tempted, uh, developers. We read about 'em, we hear about it every other week, whether it's a docker container or from a repo component, if it, Yeah. So, so now we can apply this protection by, uh, pointing at, uh, Jeff Fog your, uh, single source of record for, uh, for your ID plugins too.
And another security related announcements that we made is around the Genal mediation and, uh, what we've done there. So, uh, we do with modesty, we, we have one of the best, uh, research teams, uh, uh, in the world at Jeff o mm-hmm. The security research team and our security advisories are very accurate to a degree that you can, if you find a, um, a, a a zero day in when you scan the code, the advisory that Jeff o gives you is, is one that if you take this advisor as a junior developer, it really tells you what the problem is.
It gives you an example of how to fix it, and it goes into details of, uh, what exactly need to be changed in your code. And what we figured is that we can just give it to the LLM and we can prompt the LLM with the research data of JO and the LLM will remediate the, the vulnerability or, or the zero that, that, uh, the jfo scanners found. We started with the integration with the, uh, copilot, with the GitHub co-pilot, um, as part of the VS code integration.
But we will extend it. And the, the user experience is you write your code, Jeff Fog is, uh, scanning your code continuously, it finds issues, and it's taking the research data of the JO team to prompt the LLM and apply immediate, uh, uh, suggestions of how to fix that. And you just have to accept it and, uh, and merge the changes.
So, uh, that's the, the, uh, I think that's the last, uh, uh, big announcement. No, I don't think we did. J did we do fly?
We, yeah. Yeah. Started Fly, Fly With Fly.
Right. Okay. I got a little confused.
An ambitious, an ambitious lineup. Yeah. For one Swamp up.
Yeah. Very Ambitious. And, uh, it, uh, team that talks relentlessly on the, I mean, that breaking trust to, to our users.
The theme around all of it though, yo, Yoav, excuse me. You're okay. Yoav, the theme around all of this is really the, the transcendence of ai, and you know, how we're seeing this just totally upend the normal flow of, of, of progress, of, of it, of software development, of the software development, life cycle insecurity in DevOps, in platform engineering, in, in everything.
It's, if you're not adopting this to as, as OMI said on the stage, if you're not adopting this, get outta the room. Get outta the room. Another important kind of theme here though, was no one company can do this alone, right?
Even J Fraud's, great company, you got a great research team, you got great developers, but the, we're talking about just upending entire Yeah. Ecosystems in, in of blink of an eye almost. And so you need a partners like a ServiceNow and an Nvidia and Sonar and some of the other ones that we've spoken about.
Definitely. How is it working? 'cause now you're not just working as one team, you've gotta work at the pace and in coordination with other engineering teams.
Yeah. How does that affect the pace of what you, you are doing at Jfr? So, first of all, like you said, we are in an ecosystem, but, um, I think we are in an ecosystem of, of platforms today.
Yes, There may be a few platforms in, in each domain, but still it's an ecosystem of flaps of platforms that also makes the integration points. Once you figure out the integration points, uh, it, they, they are becoming very natural. So what we find out, first of all, we have great, great partners with us.
You mentioned ServiceNow and GitHub and Sono, but once you found out the logical integration points, it's very easy to get the teams together and, uh, create sort of a v team that works together and, uh, and creates the, the, the first level of the integration and then carries on to, uh, uh, to polish it. Uh, so it's actually surprisingly, maybe, but works exceptionally well once, uh, every once you have the clearance of, uh, how things are working together. Now, another thing that you mentioned is the, the impact of, uh, of ai.
So AI already made a huge change in how we code. Yeah. It's completely different now.
Nobody even is surprised by that. Maybe the next surprising thing, but this is also, uh, a reality today, is that you have coding agents leaving, uh, alongside the, the, the human developers. But I think that the main gap is around.
So, so coding is kind of solved. It'll change a a lot, I assume also, but, um, it's already, it's already happened. But I think where we still free, uh, see friction is around software delivery.
Because what's happening is that releases are being created in a much faster pace than ever. So it's a really a nonstop release train that is happening. And you cannot stop to, uh, think about irrelevant problems such as how do I version my release?
And what is the compatibility meaning compared to the, to the previous release? It's just an ongoing flow of, uh, of releases. With frameworks like UPT trusts, you will get the quality of the release so that you can trust.
Doesn't matter if, uh, it was an AI agent that created the release, or, or, or a human, or a combination of both. You have the gating, you, you have the governance to make sure that your release is, is ready for to be, to be deployed in, uh, in production, uh, and to be promoted, uh, across the different, um, um, policy gates. Uh, but at the end of the day, you need a new way to identify your releases.
Yeah. You need a new way to pinpoint them and, and, uh, and scale them up and roll them, roll back and identify issues with existing releases. And this is, uh, part of what, part of the change that we introduced with Fly with the Gen release as well.
I, I think between Fly and with, with AI catalog, that's one of the sort of unwritten or underlying thing things, is that versioning is going to change. Versioning. Yeah.
You will need a version, because at the end of the day, you need to for the same down. Yeah. But it doesn't need to be something that you, uh, take note of or remember.
Uh, and it cannot be, and I think the trust is still not there to walk in a full semantic way with the releases, but it'll gather. It'll, I'm sure it'll, because trust, trust is a trailing indicator, never a leading indicator. Do you know what I mean?
You gotta earn it. Trust, you gotta it. Yeah.
But I think it'll also play out like that because of, uh, of agent to agent communication. Yeah. So the negotiation of what kind of capabilities you have, it cannot be bound to a, to a specific version.
It doesn't make sense anymore. No. It'll be negotiated based on semantic, uh, between agents.
And speaking of that, we actually had, uh, uh, y Janin on, uh, but the PC server, he, he did a lot of great work on that. Yeah. Made sure to tell us.
So very proud of him. Yeah. Yan started the MCP server of Jeff Fog as a local MCP server.
As a, as a almost a, as a pet project. Yep. Uh, and then we, um, kind of upped the game and, and did a fully remote server.
Yes. Which is more, more difficult to do. But, uh, as a company, it allows you, uh, to have better control over security.
And also, um, you don't have to request clients to update the, uh, the MCP installation on the local machine. But it's a, it's a, uh, what's the word? A reference.
It's an indication. Uh, a reflection. That's the word I'm looking for.
It's a reflection of our times that before January, no one knew we didn't have MPC service. Here we are, September, MPC. Here we are in September.
And it is the standard. You must have it, you can't do without it. Yeah.
I think it's a kind of a common thing that we're seeing today. That, uh, thing is our changing on a, on a, um, You Know, Today, today it's adequately new. Tomorrow it's old hat.
Yeah. Well, MCP is a lot ahead of it. Like, there are a lot of proposal of, uh, improving the standout and adding, um, so, um, stronger authentication and, um, and the iden stronger identity and, and so on.
Well, I think there's also the A two A thing, and There's the A two A thing, which are we, we can argue whether the standards are Complementary. Well, that the thing about A two A is now that's part of Linux, I believe. Foundation.
Yeah. That's some big names. Yeah.
And, uh, we'll see, I mean, this is all gonna play out that the, the issue is for people like you and I who've seen this, you know, we've seen these games. We've seen these plays before, never at this velocity. That that's the key thing.
The velocity here, the, the time crunch. Yeah. It's, uh, incredible.
It's the wall. Yeah. Yeah, Yeah.
No doubt. What could we look? So next year in New York?
Yeah. God willing, I'll be there. It's my home.
September 1st, We will be there. What do we, what? You want to give us an early preview or too early?
I think it's too early, especially we just, uh, uh, wrapped up saying that, uh, which things are changing so quickly actually. Yeah. So betting on, even betting on next deal, uh, is hard.
I think you will see, uh, first of all, you will see there, there are some things that I can say that, uh, uh, you will definitely see like, uh, a lot of improvements on what we are bringing to market. Uh, today with APTAs, we have, uh, uh, a few more things, uh, at our sleeve. And also, uh, with fly, uh, I think we will see a more, um, a more intention based way to do DevOps.
Yeah. Almost, uh, um, vibe ops thing if you want. Yeah.
Vibe ops. Okay. Well, dev vibe ops.
'cause you gotta have the dev in the ops with something in the middle. No, But in, in, seriously, it's going to be much more intention Yeah. Faced, uh, with, uh, a higher degree of trust.
So I think that This is this, you, I remember when HTML came out, all of a sudden I was a coder. I was never a coder, but HT ml I could do then. Yeah.
HTML 2 0 3, 0 4 oh CSS JS script, you know, all these things came on. All of a sudden I wasn't a coder no more. I think we're gonna see a similar kind of thing.
You'll have, everyone could be a, a developer with vibe coding. Everyone will with AI will develop something if they need, but there will be the tools that the pros use, right? That vibe coating, refined vibe, coating squared, or whatever you want to call it, where it'll be for professional developers.
And, and that's, you know, developers aren't going away. They're not gonna be replaced. They're just gonna be empowered with This.
I, I, I agree with you. I think we will have humans mainly for, uh, just expressing intention and providing, uh, feedback loops. Uh, there's that.
I, I'll tell you what else, and I've written about this. Uhhuh For, You'll Need Humans for the Creative Spark. AI is very good at when you say, I wanna do this, I want you to do this for me, I want you to create that for me.
But it doesn't create the ideas. Of course, The human brain still creates the idea. It's that spark of humanity that I think will always be The human is the guide.
The human is the guide. Yeah. Uh, yeah.
But I'm, but the reason I asked you about next year is because I didn't think you would know what's gonna be next year, otherwise why you should retire if you already know what's gonna be next year, retire. But I would like to have you back on in July, maybe next year. We will talk about Swamp Up September 1st With pleasure.
Alright. Yoav, Yoav Laman, CTO Co-founder helping wrap up our day two coverage. But we're not done.
We still have a few more. So stay tuned. This is Alan Shimel for Tech Drunk tv.
We'll be right back. Thank. Hey everyone.
We're back here. Well, we're not live, unfortunately. We were live when we recorded this, but you're watching it on recording.
Let me introduce you to Dimitrius Brinkman. We are here at Swamp Up. If you couldn't tell 2025 Swamp Up.
And we are thrilled to have you tuning into our coverage of this year's Jfr Swamp Up Demetrius, first of all, welcome to Textron tv. It's great to have you on here, Demetrius. Looking at my notes here, it says, uh, founder of the ML Ops community.
Great title. Talk to our audience a little bit. What, what exactly is it and what do you do there?
Yeah, so we're a community of around a hundred thousand developers right now that's primarily focused on bringing AI and ML into production. That's the main thing, because there's a lot of research, there's a lot of demos that you see out there, but then actually getting use out of it and bringing it into production, that's what we focus on. And we do that in the various, in various ways.
One being we've got a Slack workspace. We'll do in-person events like meetups or workshops or conferences. We do virtual events and like meetups and workshops and conferences.
I also have a podcast myself. We have a newsletter. There's various ways to engage in the community.
We'll do like one-on-one matches, curated matches of people in the community. So in general, we just are trying to keep the education and the understanding of this field as high as possible, because it is moving so fast. It is.
Hey, just say you have a podcast isn't enough. Look into that camera. Tell them where they can get you.
Podcast. What's the name of it? Yeah, you can find it on anywhere that you find podcast.
It's called the ML Lops Community podcast. And right now we're on the 314th episode. Really?
Yeah. So we've been How often do you do 'em? Twice a week.
Really? That's fantastic. Good stuff, man.
So you're also keynoting or on stage tomorrow doing a session. You know, by the time people see this, you probably have already done it. Yeah.
So tell 'em what they missed. Well, by the time you see this, it could have gone horribly or it could have gone wonderfully. Let's hope for, I'm sure it would.
But really what I'm excited about talking about is the idea of how there's, there's almost two big ideas that I wanna present. One is how the chat interface isn't necessarily the best interface for us to interact with machines. It's very low bandwidth, and we're used to a much higher bandwidth when we interact with humans.
And then the other idea is what I am thinking about how all these companies that are putting agents into production, they all want to be an agent. They don't want to be a tool. And the way that it could shake out is you have a master agent that goes off and is using tools, but right now it's very fragmented.
And this ecosystem that we live in today is, I go and I navigate to one chat bot, and that has agentic capabilities, and it goes off and it does some stuff. Maybe it has access to some tools, but it's not like there's this ecosystem, this homogeneous ecosystem that I know this one chatbot can do anything. I have to then go, if I want something specific done, navigate to another website and use their agent capabilities to do something.
So a perfect example of this is when I wanted to file a claim for a delayed flight that I had, I was talking with my LLM of choice and saying, you know, can I get money back on this? Am I in the right to file a claim? And it said, yeah.
And instantly what you wanna do is say, okay, go file it. Go file It. That's the user experience that I want.
And, And, and you know what? That, let's call it the dream, if you will. And, and I thought we were getting at least when you talk about travel.
Yeah, right. I thought that was part of the, uh, and I'm not knocking them, don't get me wrong, but that was part of this chat GPT agent, like, Hey, chat, GPT, I gotta fly to Flagstaff, go out, find the best fare and book it for me. Yeah.
I haven't used it yet. I don't know if you have No, I I don't, I don't trust it. 'cause I'd have to go look at the flights myself and make sure that it, I'm not stopping over in Chattanooga or some someplace where, Well, you bring up something fascinating.
There's two pieces of that. One is the trust aspect, and the other is this UX cliff that I've been thinking about where a lot of interactions with machines, we don't necessarily need to type everything out. That's a much slower experience than if we just do two clicks and we get what we want.
Yeah. So there's almost this valley that we need to cross before an agent is even useful. The task has to be quite complex in order for us to do that.
And I think the reason that the flight bookings have captivated our attention is everybody has done that, and it's way more than two clicks. And it's cumbersome. And so when we think about that, we think, wow, it would be nice if I could just say, I want to do it this time, this day.
I want to go to this place. And then it goes and does it. And we don't have to go and click through and do all these multi clicks, which is, and then look back, ah, is this the price I want?
I don't know. And that's not fun. Yeah.
But to me, it, it sounds like a pay me now or pay me later kind of situation. Right. Because how do I set all those up?
It, it, I, look, I don't pretend to be a, an AI expert, but like I've gotten to the point now with my ais of choice where it knows me, right? Yeah. It knows my style and voice for when I'm writing it knows what I want out of the tasks, the usual tasks that I ask it to perform.
It would be great if somehow I could train my ai like, Hey, I like to fly out first thing in the morning. Yeah. I like to fly home first thing in the morning.
I will do a direct flight. I don't care if it's twice as much money. And no matter what I want direct, if I could help it, um, you know, all of these little kind of, this is me kind of thing.
Yeah. And I think that's where we struggle. Right.
Well also, if you think about that I'm not the same person today as I am tomorrow. Yeah. And maybe that's, there's certain things that I have hard rules on, and then there's other things that I'm a little bit more flexible on.
And so that as a problem is a very difficult one to crack. Yeah. I also think that, you mentioned something fascinating earlier about the trust, which is we have to be okay if we do have this master agent world that is some kind of a hybrid chat interface.
So it's not only us with words, but maybe there's other kind of UIs that we can take advantage of. So Let's explore that. What do you mean?
Well, I look at different ways that we interact with programs already. And if you take a little inspiration from video folks, you have histograms. Like these guys are used to dealing with histograms for the colors.
So is there a world where we can deal with a histogram like experience for what we want, as opposed to trying to really get into the minutiae in the words, because words aren't as easy to develop or as easy to tweak on that very small scale level. And then on the other hand, when we interact with humans, we're interacting at a very high bandwidth. And I'm sure you've been in a meeting where you end up diagramming things to get your point across.
When we are just restricted to text, we can't diagram anything. Yeah. And again, that brings us down in the bandwidth that we're able to convey to that LLM.
So potentially there's some kind of a whiteboard or it you can think of like your, your tablet that you're able to diagram with and it's recording your voice as you're talking to it. That could be a world. But at the end of the day, right now, what we're funneled into is the experience of just chat.
And then you're getting some inkling of when the chat bot will respond to you, it gives you these new UI elements. Right. So sometimes you'll get a scroll, sometimes you'll get a photo, or you'll get a code snippet, some data visualization.
You get that, which is great. And I think that's the first step. But for us as input, we need to up the input levels.
Well, so I'm a little older than you. Yeah. I'm gonna guess.
But, uh, look, I'm a child of Star Trek, right? Yeah. Man, my whole life I wanted to be Scotty and just say hello computer, you know, and, and, and tell it what I want.
But I I, I thought we were getting there. Right? And then I realized in like doing videos like this, right?
So I can't give the video to the AI and, and tell it do it. You gotta transcript it. And you would say, okay, transcribing is easy, and it's word for word.
And even if you, you know, fact, uh, uh, copy, edit the transcript to make sure it is you fact word for word, it's not enough. Because the way humans communicate, we communicate with our eyes, our eyebrows, our hands, nuances, tone in, in speech. Yeah.
Right. And ouris just aren't up to that yet. No.
So, I don't know. I mean, one of the, one of the things that really they say separated humans, let's say from Neanderthal or Dan Deso or whatever, that uhhuh close relative of the Neanderthal is, is our, our, the, the, the depth of our communication. Even if we didn't have a huge big difference in vocabulary, all the nuances in human to human communication.
And I think that is, that's a job that we need the AI to solve. Yeah. We don't have that No.
Anywhere near that, right? No, no. And it's, you don't realize how important it is until you just look at a transcript.
Yeah. But there also is the whole idea of, I know there's probably people out there that are gonna be thinking, oh, well, voice is trying to tackle that problem. Voice AI is the next frontier.
But I am not sure, have you played around with the voice tools? It's not that they're bad, it's that us in a work setting, what am I gonna do? Go put myself in a cubicle when I wanna work and speak to my Yeah.
Computer. You know, it's funny you brought that up. So I met a guy I interviewed last week, and I'll give a shout out to him.
This guy, Dr. Allen Becker, his PhD is in voice to text. Text to voice and ai.
He started a company, got sold to Snapchat. He ran Snapchat's text to voice for a while, but now he has a new company, I think it's called E Self. E Self ai.
Check it out. When we're done for me, you can sign up for a free five instance thing. They've developed avatars.
Yeah. That look at you, that watch you and talk to you hooked into LLM in the backend. And they do try to pick up nuance Yeah.
From your voice and from your gestures. Mm-hmm. It's early.
I played with it. It's, it's freaky. Right?
It really is. It freaked me out. But it, you know, it's not perfect yet.
Yeah. But, um, I am, I'm bullish on, on that happening. Yeah.
But you still have this, it's like we're in meetings, right. And then we have to have a moment where we get work done. Right.
And so if the way that we have to get work done is by talking to our, It's still cumbersome. It's like we're in a meeting again. Yeah.
And that's exactly it. And really, whether you're talking to the computer or typing to the computer, there are people who type really quick. Yeah.
And a lot of people are really not good communicators verbally. That's like me. Exactly.
That. There are, I mean, that, that's an issue. That's definitely a big issue, You know.
But let's, let's look at it from the other side of the coin. Demetri, you know, the windows mouse clicking kind of interface that is dominant today. Look, this was like 1960s, early seventies out of the, the park.
Yeah. You know, Xerox Park out here, we haven't really, I mean, it's been 50 years. Yeah.
And we haven't found a better mouse trap. It's time. It is time.
You could see that with like the touch screens. We have these gestures, you know, the pinch to zoom mm-hmm. The swipe.
And the other thing that I think is a big problem with us having to use chat and take what's in our mind and put it into a chat bot is how, right now we're very used to being fed things. It's almost like a passive experience A lot of the time when we're on the internet. And you can think about Netflix or when you're scrolling on Instagram or TikTok, these are passive experiences that we have become accustomed to.
And now chatting is very active. Right. We have to really define what we're looking for, what we want, and put it into the chat bot.
And so we don't have these passive gestures anymore when you're trying to work with chat either, which I find fascinating too. So is there a way to bring in these passive gestures into the chat experience? Or I guess at a certain point, once it evolves outside of chat so much, we probably won't call it the chat experience, we'll call it just the AI Communication experience.
Yeah. So you're not trying to tell me we gotta get passive aggressive with Ouris. Do you?
Are we? No, not that, not on that little, I mean, you might see it, you might see It Better. I don't know.
I haven't tried. I'll tell you, one of my biggest things that I've had to teach myself is you don't have to be polite. You're only making it harder on them every time you say thank you and please.
And all of these things You nice burning energy. Exactly. I wanna turn a little bit Demetrius and, and talk a little bit about security.
Right? So look, I, I think everyone agrees that we're all gonna have agents, digital workers, whatever you want to call 'em mm-hmm. Who are gonna go off and do these tasks for us, whether it's booking flights, writing code, or, or what have you.
And we're going to need either, we're gonna need a crap ton of agents, right? One, like almost an ephe ephemeral, disposable agent for every task we do. Mm-hmm.
Or some sort of master agent that's able to clone small parts of itself to do specific tasks. Yeah. No matter how, no matter which way we go, there's security issues.
Yeah. How do you view that? Yeah.
There's a few different issues that I'm looking at. And these are like the most basic of the most basic. If we get some of these DevSecOps people in here, I'm sure they think about it on much different levels, but in a broad strokes way, if we have this world where we have a master agent that helps us go out and it's our gateway into the world, and it can use these tools, and it's a big if, because like I said, everybody wants to be an agent.
They don't wanna be a tool because you're giving up your distribution, you're giving up your relationship with your customer. If now Chacha, BT, or Gemini is what chooses to use you or not as a tool, that's a big vulnerability for your company. So that's a big if right there.
But if we do get to that point where I go to my LLM of choice, and then I sink in with the tools that are out there on the internet. So Amazon is a tool. So buy something from Amazon can be many different types of tools.
Uh, look for something on Amazon, whatever, search Amazon. Now, are we okay with the context just flying around the internet? This data potentially sensitive data is now gonna be going to different tools and going to different LLMs.
And I'm not talking on the l are we okay with our data going to the LLM provider, but just data flying around the internet. That's one part that I think about. All right, well, we need to get the context and we need to have a way to securely do that.
It's not necessarily a new problem because we've been transporting data across the internet for a while now, but now it's a little bit different because there's agents that are interacting with each other and maybe one agent thinks this context isn't that personal. But then the other agent, when it summarizes it, it sees that, oh yeah, act it will say something that is personal and you don't want that. Right?
So you have wild cards in each agent, agent to tool call or subagent, whatever you wanna call it. And then next you have the authentication issues. So I want my agent to be able to understand everything about me.
That means it needs to look at my calendar, it needs to look at my Gmail, it needs to look in all of, everything that I'm privy to. It needs to be privy to in case it needs to act on my behalf. So you need to off into all these things, but it's not just OAuth because you then get to the next piece, which is the actions.
You don't wanna give it permission to take any kind of action. No. You wanna give it permission to take the action that you said was okay, not anything else.
Because if you give it a lot of scope, it can abuse its privileges. So I've been in, I didn't tell you this, I've been in security for 25, 30 years. You're only describing what I would say are innocent security issues on the agent.
That's true. What about when the bad guys say, oh, he's got an agent. Let me exploit that.
Well, did you hear what happened recently? There was I think, some output from an LLM that had a nefarious link. And when the user clicked on that link, it then was able to take control of the system.
It happens all the time. And so, yeah, you have, again, you have this wild card in there that the nefarious actors can hijack this agenda. They're not dumb.
They're as smart as we are. They're well funded, well organized, and they, and that, that's the truth. And If you do end up having everyone as a tool for your master agent, how do you verify that this tool is okay to use?
Agreed. It's it, look, here's the good news. First of all, no one's gonna waste.
Everyone's running as fast as they can anyway. And they're gonna keep running as fast as they can. But as these things, and I, I've seen cycles before, right?
We never lead with security. We just don't. Yeah.
We, The sad thing. But it's True. It's a sad, but as a security person, you either gotta come to terms with that or, or you know, you're gonna be depressed.
Um, we will catch up, we will put the guardrails in, we will come up with processes around it, but people are gonna run as fast as they can. And, and, you know, you can't put your, you can't lay down in front of the tracks and say, stop the train. Yeah.
You get run over. Yeah. And, and so I always say it's more of a yes we can mm-hmm.
Kind of thing, right? Yes, we can. You wanna run as fast as you want?
Yes, you can. We'll figure it out. Yeah.
And I, and I think that if I had to leave us with one thing, that's what I'd leave it. Yes. We can.
We'll figure it out. But man, thanks for the work you do, Demetrius with you community. It sounds great, man.
We appreciate you. Thank you for presenting at Swamp Up and for being here on Text Drunk tv. Thanks everybody.
Alrighty. We're gonna take a break. We've got more swamp up coverage coming your way.
So check it out. I'm sure that you have every one of your passwords memorized and you can recite them at infinitum whenever people ask. Or is it that you're using a password manager to remember them all for you?
Is there a better way to make sure that we're more secure and incorporating things like public private keys and multifactor authentication? In this episode of Tech Field podcast, keys are Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the enterprise IT industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our Tech.
Field Day is a part of the futurum group. And this podcast is also published on our sister company Site Techstrong tv. In this episode, as we're heading into security field day, we will be discussing pass keys and how they make security much easier.
Before we do that though, let's have our guest introduce themselves. Hey Tom, thanks. com, security Boulevard, cloud native, now, Techron tv, Techron ai, techron it digital, CXO, eh, I don't know.
And we're part of the Futurum group, which makes us a sister company with our friends, forensic tech Field day. Tom. Thanks.
My name is Kate Scar. I've been a part of cybersecurity for a very, very long time. I don't have all those exciting things that Alan does.
I'm actually coming back from a sabbatical that I took off and, uh, I'm happy to be back. And I'm part of, uh, the CD foundation, the chair of, um, cybersecurity sig, and I'm very much into everything secure. Awesome.
And of course, I'm Tom Hollingsworth, an event lead here at Tech Field Day. Let's jump into the premise for today's episode ahead of Security Field Day. No doubt that when you woke up this morning, you had to type a password into your device somewhere, whether it was a pin code into your phone or something alphanumeric into your device of choice.
And wouldn't it just be better if we could get rid of that? Because I know that I have way too many of those and I'd just like to have less than I need to worry about. That's the promise of something called a passkey, which is a type of security that will allow you to do, use things that you have and authenticate to that device, as opposed to having to remember the various passwords that I have for everything.
I happen to like them, and I know that at least one of our guests does. So the premise for this episode is that passkey are the future. So Alan, you, you were an outspoken proponent for passkey.
I was wondering if you could tell our audience very quickly, what is it about passkey technology that's better than a password in your mind? Well, you know, Tom, I'll tell you, I didn't type in a pin or a, uh, or a password this morning when I got on my phone, my iPad or my iMac, or even looked on my watch because I do use pass keys. And so a quick facial scan, a fingerprint on the keyboard or I, I am actually full disclosure, a customer of one password.
And I use that for PAs keys as well. And, and, uh, I log into, well, I don't want to give out too much security info because I've been in security game a long time too, but I do use one password PAs keys to log into various applications that I use. And, um, it makes life easier.
You know, there was a time, there was another password manager I used for a number of years that unfortunately was the victim through perhaps no fault of their own, of several data breaches. And as a result of that, I, it finally the, I said, I have to move through, you know, whether it's their fault or not, my, you know, there's, there's big hash balls of my passwords that are waiting for, uh, quantum computing for someone to crack and take everything I own. So I, I moved to one password a couple years ago, and, um, the whole, at that time, I remember looking how many passwords I had.
And granted, I'm a, I'm a freak. I'm a tech geek, you know, and I get all that. But if I told you I had over 350 passwords stored in one password, right?
350 passwords, I don't know if people out there, if you have more or less about the same, that's a lot of passwords to remember. And so if you don't have a password manager, you are reusing passwords. You're not using hard passwords, you're just, you're an accident waiting to happen.
You're the zebra waiting saying, I hope the lion doesn't get me today. Yeah. And, and Alan, I want you to change those passwords every 90 days.
Exactly. Every quarter it's, come on, dad. That's crazy that no one's doing.
We all know no one's doing this. We all know. Yeah.
But, and so passkey to me are a way around this, right? Whether it's biometrics or, or what have you that it's using, the fact that I don't have to remember 350 passwords that I change every 90 days is a godsend. Right?
This is, you know, I, I can't see why anybody would say no. And, and I agree with you that, that the com, that what passkey offer is a combination of a bunch of different things that we've been trying to get people to use over the years, right? You know, you, you have a password, but you also have some kind of a physical token, in which case a lot of times it's a, a, you know, maybe it's a, a trusted device like a phone or some other kind of token that you hold onto.
And that provides that second factor because we still have a lot of people out there who don't use two-factor authentication, or they use the bare minimum, right? Like, oh, I'll just have it text me whenever I, I need to log in. Or I, which authenticator app am I using again?
You know what, I'll just store all of my authentication tokens in the cloud because those will never get compromised. Right? Right.
Exactly. Yeah. I, Kate, I was wondering, maybe you could kind of tell us, you know, your perspective on past keys as far as, you know, what is the value to an enterprise that maybe is considering, uh, deploying them at, at scale?
Because I know for personal use, it's great, but personal use past about three or four people kind of starts to be problematic. Yeah. Um, well, from a cybersecurity point of view, you're gonna have stronger security, less phishing risk, right?
Um, no weak and reused, you know, passwords. So that's, you know, number two. Number three, just you want the experience to be seamless, and that's what one password would, you know, a password manager should do.
It should be seamless. And so there's just this better user experience, uh, which is very important. And at the end of the day, there is a cost savings here, you know, and operational improvements.
Um, so cost savings from the, you know, reduction in a support load, you know, oh, I forgot my password. I mean, you know, gosh, we've been dealing with that I think for 25 years, right? Um, so that, so having a, a password manager is, you know, would help in an overall cost saving savings.
And I think we're seeing that with a lot of companies where they're trying to create a frictionless environment. Like how many times have we gone to log into something recently and, you know, we put in a username or an email and it said, Hey, we just mailed you a magic link to verify that you are who you say you are. And, and that way we don't have to deal with this anymore and just click the box that says this is a trusted device unless it's on a public computer.
Uh, is it, what, what's the value that a company gets out of reducing friction with the user base by implementing things like pass keys or magic links? So from my, from my point of view, it is just, um, it's not, cybersecurity's always seen, especially with passwords, has always been a security bump, right? We, we are, we are making something difficult that should be easy.
And so what I, what I see is just people adapting more to something that will help in the, in the future that's a, a good for them. Like, like, this is good for you to do. And so the more seamless that we make this, the more frictionless, the more adoption that people will take.
I think there's two things I add to that. Number one, as, as we've highlighted, we're kidding ourselves. If people, if we think people who have lots of passwords are changing them every 90 days, are not reusing passwords are, are following good password hygiene.
And so we're creating. And so if they're not, we're creating risks to our organization. Secondly, I will tell you the amount of time that I used to spend, and some days unfortunately I still do hitting the forgot my password, reset my password, use a, a, a no auth from Facebook, LinkedIn, or Facebook, Google, or, or Apple.
The amount of time sunk into doing that is, is, is really disgusting to tell you the truth. Another thing though that I like about, you know, using the password manager and pass keys is from an organizational point of view, Tom, let's say I need you to log into an asset, a corporate asset. I'm gonna give you access, right?
But I wanna be able to control that access. Like, you can only come in for today or for the next week. You can't change the password.
Here's, here's the unique token if you will. Here's the unique username and password. I'm giving you the use on this asset for the next week.
'cause you're a contract maybe. And then after that it doesn't work anymore. That is such an inherently more powerful tool at my disposal to help secure my corporate assets, my ip, my, my crown jewels than just saying, oh, let me give you a pass, you know, a password and username or having you go off and create one on your own that I have no control over.
And, and again, another reason, that's not a passkey per se, but it, it's another reason why password managers are, are for me, a uh, indispensable, you know, if you're not using them, you're not serious about security. And I think you're right. And I think while you said that it's not a a pass key necessarily, it's a component of pass keys and, and there's more to the passkey phenomenon that makes it a valuable implementation of modern technology.
One of the things that I think that cannot be understated is the fact that most pass keys rely on things like secure enclaves. Yeah. Which we really haven't had up until just a few years ago.
You know, there's a secure enclave on a mobile device or on most, uh, devices now that have a TPM because most devices that we use do have that. And it's never been an option before because we've never really focused on focused advanced cryptography and things like that. But like you said, if I create those, those key pairs, and I know that something happens, like let's just say, Alan, that your, your identity gets leaked or someone is able to, to grab that information, I can invalidate that fairly quickly and ensure that nobody's able to use it to log in anywhere else and make you regenerate that and, and kind of start over.
Like that is kind of one of the things that security people have been asking about for years is how can in, in the event of a disaster, in the event of a breach, how can I walk things down so that I know that I'm not fighting my attackers while I'm trying to triage the problem? Yeah. Yep.
Or, or at least limit right in, in you we're gonna freeze it right there. Here's the funny thing. Everyone I know in security, and I've been in security 30 years, everyone knows the passwords is a failed technology for all of the reasons we stated.
And I've met so many entrepreneurs, really bright, smart entrepreneurs who have tackled big problems, who said, I'm tackling this problem, I'm gonna put an end to passwords. And yet it's still the default. It's still the default.
I, I don't know. I mean, we could talk here about passkey till the, the cows come home. I don't know what it takes to get people off the password.
I, I think what it's gonna take is people who are supporting them, just deprecating them. Like we've seen that with Microsoft, right? Where they're, we're moving support for passwords in their authenticator app, but they're gonna leave passkey support enabled.
And, and we've, we've brought people along in degrees because you know, now it's not just password, it's password and two factor. Like for example, when you join an organization and they want you to log into Slack. Now it could be that the default is that you have to create a two factor authentication, you know, the the infamous print this paper out and just in case you ever get something happens because we want to get people thinking in that method.
And the more we do that, you know, to me it's, it's no different than unsecured wifi or, you know, making your password Cisco 1, 2, 3. Like, we, we've gotta get people away from that idea that I can just do something quick about this. And I, I know it's gonna be hard for a lot of older folks.
I'm not throwing shade on anybody, but my father-in-law has his Windows 10 box set to automatically log itself in every time he starts it, because I don't want to have to type a password in whenever I get up in the morning. Whereas me, I get nervous if there's a computer that's just sitting there not at a login prompt when I'm not sitting in front of it. But I, that could also be my IBM training kind of leaking through where it's like, uh, you know, unsecured device is just an opportunity for chaos.
Um, you know, do we think that the, the upcoming generation, gen z gen alpha just kind of assume that pass keys and more advanced multifactor authentication are what is the standard? And as more people kind of move on with their technology, they just don't think about it because they, this is all they've ever known. So I, I do, you know, so I'm the dad of two boys, 26 and 24.
And I will tell you that my, my two sons, and I've raised them, you know, their dad was a cyber dude. So they've been raised, uh, in this enriched in this culture. They all use multifactor when they can and pass keys when they can.
They find it much more convenient to just text stuff back and do stuff like that. You know, speaking of my sons, I, I will tell you, when he was in eighth grade, we did a science project where we made up a phishing letter, sent it to his classmates and their parents and his teacher, uh, telling them, you know, that the, the, the class roster got, I dunno, something happened, but you had to go in and change your password. And we sent them to a lookalike page with a closely resembling URLI got 40% of the class parents to give me their passwords.
We sent them back and said, Hey, this was a science project, literally. And I was working with a company out of, uh, out of Carnegie Mellon password class, password training program. And they were nice enough to give me the training program for his class and their parents and their teachers.
And I went in and taught them a little password. But this is, you know, Tom, you know what the most popular password manager in the world is? Noted.
Mm-hmm. Your father-in-law probably keeps all his passwords in his notepad or notes app or, or something like that. Or on a sticky note underneath his computer.
I, I can neither confirm nor deny for, for, Um, no, not for the album here or doc some or anything, but yeah. Yeah. That, that's the most popular password manager in the world.
And until we get past that, we got issues. We do. And, but the the good news is, is that the technology has come a long way Yes.
Even in the past five years to allow that kind of thing. 'cause like you said, most of the time, unless your laptop or your, your tablet's been sitting for more than 24 hours, you can just use your face, use your thumbprint, use some kind of biometrics to, to be able to get into it. I don't, I, I imagine coming soon that a lot of this is just going to be passed.
You know, it's gonna be seamless pass through security. Oh, well we can identify who you are based on these things and you know, you're good. And, and we've even seen crazy like, you know, future tech stuff, like if anybody's seen, uh, mission Impossible, uh, was it Rogue Nation where it's like gate analysis.
Like we, we can verify that you're not trying to impersonate somebody that's a little bit further down the road, but I promise you that whatever that gate hash value is is gonna be stored in a secure enclave and the guards are probably gonna have to log into that workstation. No, I, I, I remember a, a company out of MIT biometrically that they would, you know, everyone types uniquely, like you write you type top TOM, you have a, a certain cadence that you use when you type that and, and they were able to, to see if it's really you by just the way you type your name and, and so, but, but here's the, here's the rub. We've had technology for this for a long time.
It's 2025. We're going to 2026. Our percentage of users are using PAs keys or biometrics.
Right? So Kate, I think Alan brings up some really good points. We've had all these technologies that exist for a long time.
I mean, if you really wanna get down to it, the, the, the heart of a pass key is really just a public private key pair. You know, Alice is sending Bob more email like we've always done. What is it about passkey that makes it more, I don't know, consumable for people?
What, why do you think that now is the time that we've finally gotten momentum to get people off of it? I think you're seeing the technology as, as Alan spoke about, it's actually, it's easier. We've come a long way.
I mean, it wasn't this easy, I don't know, maybe even two years. It's, it has changed a lot in two years. So that is, I, I think ease of use will always be the key.
Um, sort of say this. Um, I think that's the, the biggest deal I think, um, when, when we don't see cybersecurity as a roadblock, when we see that we're able to do something without it costing us a headache, a time, um, trying to figure things out and, and the old way being more time consuming, more of a, you know, more of this, you know, I have to, I forgot my password to I don't know, Instagram, and you get all the back and forth, that's a headache. You know, that becomes a pain.
So I think as, as we see the, this other new technology that is seamless, I, I love that word. Frictionless is another word I love. Um, I think it will be more adopted by us and, and by companies as well.
Kate, I think you're absolutely right. The real value in passwords for the longest time has been the fact that we have spent so much time getting them as frictionless as possible. Yeah.
You know, there's, the eight characters are more special character capital letter that has increased the friction that we've had, but it's just forced people to become more familiar with ways to make themselves more secure without realizing it. And pass keys, take it one step further by building in all of the good password hygiene and good security hygiene that we've been trying to teach people for years. You know, un passwords that you don't even know, or multifactor authentication.
And in doing so, we've moved people to the point where the friction is as reduced as possible for the things that they need to use. And that means that people are more willing to adopt these new ideas. If, if you remember how hard it is to get people to develop multifactor authentication, if you just tell them, you know, click on your phone and authenticate this.
Or if you've ever had them use some kind of a, an online payment system where they can use their, uh, you know, smartwatch or smartphone to authenticate a credit card transaction. They see the value in what it provides. And that is why passkey have a very bright future.
I wanna thank everyone for joining us for this episode of the Tech Field Day podcast. If you enjoyed this discussion, please make sure that you subscribe on our YouTube channel or in your favorite podcast application so you don't miss any of our episodes. We'd love it if you'd give us a rating and a review, because that really does help people find this content and lets them know what we're all about here.
This podcast is brought to you by Tech Field Day, which is the Home for IT experts from across the enterprise tech field a is a part of the Future Room group. com/podcast, or check us out on Techstrong TV and the Techstrong TV app. Thank you very much for listening in.
We'll see you next week. Hey, everybody, does AI stand for artificial investment? Let's find out.
We'll be back in a minute. Hey, folks, we're back and welcome to Textron Gang for Wednesday. We're here today with Chris Blas, who's a veteran, and Jeff Rich, who's from the, um, identity define security alliance.
There you go. And Jeff has been on the show a couple of times, but for those of you who have not met him, he's kind of in charge of this alliance that focuses on our identity, which is awesome 'cause we're gonna have a couple of security related conversations in a minute. But first, let's start with this whole investment from Nvidia into open ai, which is valued at a hundred billion dollars, but it comes in increments.
Apparently it starts at $10 billion a throw for, uh, open AI ordering Nvidia chips and return from building some data centers around those chips, which theoretically becomes this virtuous cycle between your customer and a supplier who's gonna actually keep building these things. Chris, I know you've been dabbling in AI for a while, but this is the latest in a series of these investments that we've seen and Nvidia invested in Intel. And one of the dirty little secrets of AI apparently is that we are subsidizing the crap out of the processing of those requests, and it's costing companies a lot more than they're charging end users.
So the question becomes, is this sustainable? And what do you make of this investment? So, I don't know, there's couple ways to look at this.
Uh, look at this. You know, there's centralization and fragility. You know, are we integrating more vertical risk, you know, into the same stack, you know, for all sorts of reasons.
Economic control, uh, of technical, technical architecture. Um, the same time, you know, this is the space. You know, I, I don't know that I can, I can double think the, the decision makers, you know, if I were them, would I be looking at certain things, maybe, right?
And, and the, you know, as you say, the the phased approach of it, you know, may indicate some thoughtfulness on the, on the decision makers. But, uh, we will see, you know, there's, there's again, it's, you know, we have these conversations all the time, and in this show, we literally have these conversations all the time. We try to think of something new to say, and sometimes just need to say the same things over again, I guess.
But, uh, um, we understand, I think everybody understands over the last several decades, a hundred years how we wanna look at it. We've, while we've advanced things a lot, we've introduced a lot of brittle systems, you know, single, the supply chain where I spend so much of my time where it's hard to get people to think that we, we need more than just one thin line of linked attestations to, to know where things coming from. So we're looking at chips and, and, and that whole thing, you know, this, this particular issue, you know, are we concentrating risk, you know, getting some benefits for some stakeholders, but at the same time, um, making them the system more fragile.
Uh, so interesting. A lot of concerns, Jeff. Yeah, I would offer that, although, uh, those are the right points, if from a bigger picture point of view, there's, if, if I were them and I were doing this investment, kinda like what you said, uh, the phase approach makes sense for two main reasons.
One, is there ever gonna be a profit? And I think we need to ask ourselves that question. I, I don't have that answer yet, but I don't see a definite yes down the road.
You know, we're gonna have to wait and see. Um, and the second one is, and it plays on the profit motive to a degree. There was a lot of other hidden costs with ai, the energy use, the downstream environmental impact and everything else around that.
Not to mention the societal impact, which I'm not even gonna touch, just, just mention it, but not touch it. You add all that together. Are the cost really as well defined as Nvidia thinks they are?
Is it simply chips? I, I think not, I can't help but wonder if this will just set the stage for some sort of investigation for antitrust eventually, because you created this kind of tight ecosystem. And I can get to Chris's point, there's virtue in that cycle, but at some point, somebody's gonna complain and say, you know, basically Nvidia has locked out competition in this space already.
And, um, Chris, you know, you've been around federal governments, it might take them a few years to wrap their heads around it, but eventually somebody's gonna come knocking, right? You would hope, right? And it, it, it, again, if you go down this path, this is what governance is for, right?
And, uh, but you know, Jeff, to your point, we have to, as we always have, again, this is not new, you know, if you worked in a global security free length of time, you realized that policies in, in, in various, you know, geographies and jurisdictions are where they are, and they're evolving along certain lines, um, we have a certain arc for that sort of thing in the, in the current, uh, US administration. So, which raises the question for me, will they, it depends, you know, is this an era of where one of these big players, you know, the US of market, um, will actually re reward and ignore, uh, uh, risky behavior? And if so, that I doesn't change my long-term view of this, that, you know, you know, open systems and democracy and capitalism, all these things work because they're self-correcting.
Any one actor can make Barbara, you know, bad choices, uh, or what may look like good choices, but turn out to be bad choices in the end. And if they, um, that's not the right analogy for a show like this. If they fail spectacularly, um, someone else will pick it up.
And as we discussed in this, in this show, in this forum, I have a lot of questions about, you know, how we're even allocating workload now, Jeff, power allocation, you know, the systems we're putting together have enormous benefits to be clear, we're going this direction, nothing's gonna stop it. The question now is, how many keystone cops, uh, mistakes will we make along the way? And this one, again, I, you know, the people at the top people making the decisions to be clear are not idiots, right?
And, and almost nobody is, right? When you don't understand the dec decisions people are making, you know, and, and, and organizations being, uh, uh, you don't understand what decisions organizations are making. The people inside are, are acting rationally.
So, you know, I, I can ar you know, in a vacuum, I could argue the pros of this. I can, I can argue some of the risks of it. The reality is how will it play out in the environment that we're actually in?
And we'll see. Mm-hmm. Our friends in Europe probably are gonna say, you should say.
Yeah. So I have a question on that. Uh, extending a bit more.
The UN general assemblies meeting this week. I have trouble believing that the two letters, AI won't come up somewhere. Yes, right there, there is an actual session about AI safety that's being discussed at this thing, but I'm sure in the hallways, a lot of companies and countries are having conversations amongst themselves about what does all this mean?
Because it does feel like, you know, us dominance of the sector. So I'm sure there'll be some interesting things. But let's imagine you are sitting over at a MD, does this mean that you got a pony up $10 billion to get a customer for your AI chips?
Is that how this is gonna play out as well? I mean, you know, how crazy does this get, Chris? What do you say?
Oh, it's too easy to just to say yes. Right? And you get back to, you know, again, you know, we, we use these acronyms and company names.
There are people there, you know, there's a bunch, you know, as, as you get to the decision making cycle, not that many. And they'll make their choices. And, you know, and, uh, and I'm not gonna advise them, or at least not for free, but I'm gonna, uh, you know, there's a lot of arguments to be said for yes.
I mean, look, like at to my last statement, I can argue what might be the right or wrong thing to do for, you know, technical reasons or structural reasons, but there's also, we live in a reality, right? And the reality, uh, like you say, Jeff, you know, we have, we have this going on. We have the UN general assembly next week, we have all sorts of global policy things going on.
And when you're looking at the kind of timeframes and the financial investments, you know, you know, and the number of competitors, the number of entities globally doing these sort of things, you've gotta make your choices. Um, and, and it, it at the risk of to in fact, repeat myself, you know, this, this, you know, these things will play out. I have very strong opinions.
The AI side of thing, lemme just take it there. Narrative sovereignty is the term we tend to use a lot more in this is a civic AI and world we're talking about these days. And it's not, it's not, you know, quite a lot.
You can talk about disinformation, misinformation, influence campaigns, and that's a, a real and present, uh, issue, but it's also in how we run our systems. You know, if, do I control the narrative sovereignty of my company? Do I actually know what I'm saying?
What we're saying, what we say to each other, what we're saying to the outside world? Turns out we haven't been doing that extremely well. And this whole AI what, again, what we are calling AI this time around, uh, again, um, lends itself really well to that.
So the attestation systems that that, that I and many others seem to think that we need on a global basis to deal with these, you know, sort of human issues, get back into corporate decision making, what is the right decision? Are we making decisions transparently even amongst ourselves inside the company, um, or not? And, you know, so I look at these executives, they're trying to navigate worlds where, hey, literally, Mike, you and I, you know, this, I find this calendar year, particularly this threat of conversations every week to be fascinating, looking back at what I said and what we talked about in January or March or June.
June was a, a huge month this year, right? The world kind of changed in June. We're here now.
If you are at the, in the corporate office, in the C-suite at a MD, how exactly do you navigate that? That's a hell of a question, right? And I'm happy to be an armchair critic and, and say what I would do, but it's, we need to recognize the reality of the, the decision of the, the, the, the situation, the deci decision makers in.
And, and so anyways, at the long, long rant, but I think the kind of, so the narrative sovereignty, attestation systems, this is 99% of what I, and quiet wire and the open source civic ai we're all about. We're applying this in different ways. And I look at this block, this topic, you know, this, this, what we're talking about here is yet another process that will be inflicted by success or lack of success of that adoption of attestation systems, which is a little bit abstract and perhaps opaque for your, for your, uh, uh, for the viewing audience.
But do we know what we're even doing? And we, we see these cartoonists sort of decisions we make, and it's, it seems ridiculous, but you get in on the inside and again, find out that the individual humans are be, are acting rationally. It's just that our systems aren't very rational.
I suppose when I look at it, and Jeff, you've been around these kinds of decisions before and we, you know, whether it's job or whatever else, but it seems like with Nvidia, it's not just the processors, it's the Cuda software framework that they're getting everybody right to, and those APIs, and that's where the lock-ins gonna be. We have seen fixes to this in the past. So will there just become pressure to say, Hey, we need Cuda or some clone of it to be open source and available and avoid this kinda lock in, and maybe that's how we resolve this issue.
Uh, you know, I can't think of an answer that's very far from that, because it really boils down to Chris, when you talk about is this gonna be a success or not for, um, commercial organizations, the definition of success is ROI for every investment bottom line. That's it. The fact that is the bottom line.
So that's what they're for. Yes, exactly. They're a company, they're money making organization.
That's why we create them. Yes. So even though a concentrated M word could potentially exist on this, which could bring a bigger RI, we still don't even know that yet.
So I, I think there will be, first of all, at some point e either, uh, there's gonna be a disruptor either from some regulator that says, no, you can't own everything. Or there's gonna be a disruption from another organization that says, we have an alternative way to do this. And by the way, it costs a lot less, and it, it may run faster.
There's gonna be other benefits. One of those two collisions is coming down the road. And like Chris, I don't know which one it is, Right?
And, and the, and, and the, and the reality is that, you know, four corporations, you know, you know, we're sitting here armchair, but maybe, you know, and I've been in this position in major, you know, corporations myself, I have a legal fiduciary responsibility to make decisions that increase shareholder value. It's not just greed. That's what the, you know, that's why we agreed to form this thing.
It's called the company. It makes money. That's why we spend time in it, and we take roles and responsibilities and, you know, this may work, you know, doing what I would see as morally and ethically and, and technologically and security a bad idea may be the right choice, because you will make more money.
Now, know, I may not be personally happy with that. I may think it makes our infrastructure fragile, and I think I'm right, but that doesn't mean that it's the wrong choice for those stakeholders to make. Hmm.
I also think there's a fork in the road, and it's nearer than we think. Um, if you look at all of this stuff that they're talking about for these kind of large data centers, it's built around training. They're really focused on, we're gonna go train super intelligence, or AI general intelligence, or whatever the term of the day is you wanna do.
And that's all well and fine, but I think that the bulk of what we're looking at in the future is gonna be the running of the inference engines. And that doesn't necessarily require Nvidia GPUs. We can run a lot of different processors in those instances.
And I also think that we're gonna see a lot of these models are gonna be distilled into smaller models that run more efficiently on those things, and are better trained and better targeted. So maybe, you know, as, as great as this all sounds, but maybe you know, this, uh, a GI and case involving Nvidia and open AI is, you know, high-end computer science, but not where the action's gonna be. Chris, am I crazy?
Yeah. Hold my coffee. Right?
You know, 'cause yes, I mean, you, we've talked this about this on, on, in this, you know, you and I, and you know, on this show we've talked about this workload distribution. What do you really need? A, you know, we're using Einstein to open the door, right?
You know, so every time we're booting up an AI and having, you know, this huge power surge and to the, to the point of the segment, we need all these chips. Um, that's not really justified. It's not the kind of thing that lasts long term, 3, 5, 7, 12 years from now, are we're gonna do it that way.
No, we're not. We're gonna have massively distributed workloads where a lot of things will get done. You had a, just in the last couple weeks, we've had a great conversation on this, where old computers, we're using old computers today to do modern things.
And with AI and LL with actual l LMS running on 10-year-old machines, because the actual LLM part of it isn't much, and it doesn't need to be right away. It's not talking to a human, it's, it's performing functions. So, you know, I would like to hope for all my, my, uh, uh, my, my non-partisan, uh, uh, statements to date.
I hope they're wrong. I hope everybody bet betting on owning the castle and owning the key turns out to be wrong. And I think there's a really good chance that they will be.
This is all, you know, to my last point, a chance that they won't. Maybe they're making the right calls, but I don't think so. So, so, Chris, are they gonna convert those big data centers in in 10 years to big storage facilities that you can rent Basketball courts?
Yeah. Community centers. Yeah.
Yeah. Pickle, they Pickleball courts, man, pickleball. All right, folks, I think we're gonna leave it there.
But I, I, I would be careful when I was evaluating anybody's financial statements, you know, if I'm taking dollars from companies that I invested in, does that really count as a customer dollar or is that some other thing that we should keep track of in a different way? We'll be back in a minute. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back and under the heading once again of why we can't have nice things. There's a report up on Security Boulevard talking about how the bad guys are starting to do some stuff with ai. And it comes in two forms initially, and this may just be the beginning of a larger trend, but the first one is they're actually trying to poison the data we're using to train these AI models.
And then the second part of it is, well, they're actually starting to use these deep fakes a little more aggressively. Jeff, you live and breathe all this security stuff. Does any of this a surprise you?
And B, what else should we expect? Uh, no. So the only thing that surprises me is that it's now coming to light.
Um, I, I think this has been here, you know, every single tool that you have, whether it's a shovel, a pick, a handgun, or a rifle, can always be used in two different directions at least. All right, so here we are. Um, now that we have ai, that's a great benefit in society and what we're doing for decisions and how we, you know, invest our money and, and how we make our company work and everything else, that, all the wonderful things that can come from AI when use properly.
The bad guys look at this and say, Hey, you know, that, that looks like a really good idea. I think I'm gonna use it too. So we, we certainly can't be surprised, one, at poisoning the data.
That's not a new, uh, that's not a new trick at all. And I, and Chris is violently, uh, agreeing with this one. Not a new trick there, you simply using a new tool.
So I'm really not that surprised that we're seeing it. I'm surprised that it took so long for it to become visible. I think it's been here for a while.
This is kind of like a, you know, when you have a heart attack, you realize, okay, if I look back over the past 15 years, I can see all the warning signs and lifestyle and everything else that got me here. I think that's where we are with poison data right now. I think there's more of it out there than we believe.
Um, and the, the second thing with DeepFakes, and this is something that's really close to what we do at IDSA, you know, identity is, has now become the cornerstone for security in any system. Because no matter what, if you don't know who or what you're dealing with, you don't know who what's gonna happen in, in any way. This goes back to, if you look back at military bases, back to, you know, probably back to Roman times when someone approaches, the phrase that's uttered is who goes there?
They wanna know who you are, and in some cases find a way to validate it. We have better ways to do that now, um, than, than in Roman times. So, identify who you are, validate who you are.
And that's not happening well enough, often enough. Right now, we are still taking shortcuts. Many organizations are still real happy with using SMS as a second factor in, uh, in authentication and, and including financial institutions, which amazes me healthcare.
Um, I, I actually had a, an encounter with a healthcare professional earlier this week who asked for my social security number. And the number I gave, I gave that individual was 2025. That's the year we're living in.
You shouldn't be asking me for my social security number anymore. What are you gonna do if I don't give it to you? And, and completely befuddled and said, okay, I guess you don't need to give it to me, then.
Well, thank you very much. I wish more people would take that position not to be, you know, uh, either arrogant or aggressive about it. But when you add all that together with deepfake, the same principle applies with deep fake.
Now, as good as those systems have become, and they're getting better by the hour, they are getting better by the hour. What we need to do as security professionals is find a way to use that and leverage the same systems to be able to ferret out the ones that have a high probability of being real and have a low probability and, and should be weeded out or find another way to authenticate who they are. And there are good ways to do that.
Now, whether it's with a token or a pass key, or using geolocation, there's so many different factors you could use now available to us that don't involve SMS, that lets you determine it Now with, um, AI and DeepFakes and interactions from machine to machine, which is the one that people aren't talking about yet, but is certainly there, there are certificates as an example that really should be used, not a new concept, but if you have a trusted certificate with a, with a ca that you can, that you have faith in, you could have a much higher probability that whatever machine interaction your machine is having is valid rather than coming from a bad guy. So, uh, you know, I may not be making anyone feel any better about this, because yeah, the bad times are here with it right now. A lot of good times are as well.
We just need to keep up. We can't be lazy about it. All right, so do we need like a new hashtag hashtag no SSN what do you say?
Uh, oh, you, you know, I wouldn't mind A-O-S-M-S, uh, you know, I, I, I could, in fact, I may, I may stare at that. Yeah, I think that's not a bad idea. Um, it has its place, but not for authentication.
Alright, Chris, well, we have, Go ahead. For the uninitiated who don't know what data poisoning is all about, what is it that cyber criminals are trying to do here? Exactly.
Because it seems like, you know, I'm kind of hoping to poison an LLM that may have some impact. It seems like a long shot, or, or is there some other way of thinking about this thing? Well, without getting too deep into the Cory details, I just basically wanna agree with Jeff, you know, this is not new.
There's almost nothing new about this whatsoever. Right? I think what's, what's but of the things that are not new, the most useful thing to, to, uh, pay attention to is this is a speed thing, right?
And Jeff, as you were talking, you know, we're worth the same era, right? You know, war, not war dialing, but well, war dialing, right? You know, the, the, you know, back in the day someone realized that, hey, if you just call phone numbers and a modem picks up, you know, what phone number has a modem, and now you can have fun trying to break in that modem and the network behind it and whatnot, then somebody else said, you know what, I can just take an entire block of phone numbers and write a script and have my computer sit here while I'm asleep and call one phone number after another.
And, uh, that sped things up massively because all of a sudden, you know, you could hundreds and thousands in a night. And, uh, and for those of us on this side of things, you know, that was early in my career. I was like, oh, wow, that, that's an interesting little twist.
And then, then just to, just to make that story as fun as it was, you know, the response was, we will make it illegal. There's a law, I think probably still in the book, in books in the States, if you call someone and hang up without saying anything that's actually against the law, or it was made against the law, so what the, what the heck what the hackers did was just change the code and add a little wave file that says, sorry, wrong number. So if a human picks up, they say, sorry, wrong number.
So anyways, without uh, uh, going too far down that rabbit hole, this is the same sort of thing. The, the hackers, the bad guys, um, now have AI tools that speed them up massively. If the defenders don't, you know, address that, you know, and use AI tools to speed yourself up massively can be done mostly by not listening to people like Jeff and I, right?
You know, just, just go out and do it. Get a chat GPT account asking about, tell her who you are, what you're trying to do, a situation you'll move forward. Not as fast as the bad guys, but way faster than all the other people around you.
You know, don't have to be faster than the bear. Um, and, uh, and Mike, I'm trying to rework our call if I actually, you know, adjust your question at all. They're trying to, you know, put information into your systems so that your systems betray you, right?
Again, right over and over and over again. This is another interesting way to do it. And there are literally so many, and because of LLM model architecture, the word layer isn't just a metaphor.
There are so many layers to do this in that we could have individual shows talking about individual, you know, a laura layer. You want stick, you know, poisoning in the laura layer in the actual model execution as opposed to, you know, poisoning the dataset. You're training the models.
You know, we could do this all day long. And, and, but Jeff, you, you touched on, I will try to end on this. We have built this entire structure saying, I have an attestation, I've got a certificate.
Wait, heaven, help us. We'll have two and we'll use text messages. Um, that's not how anything works.
Every decision we all make to pick the next words while talking to you right now to walk across the street to do anything, to be a human being. We have 3, 4, 5, 6 things we, we can attestations that we can navigate on. We have built our entire security architecture on one.
I'm gonna get the ultimate cryptographic authentication for Jeff. And I'll know that one thing tells me that's Jeff. No two is a start, not very good.
Three is fantastic, four is ridiculous. It's not exponential, but we have to have more than one line of brittle authentication to give us access to whether or not you're poisoning my ai. Hmm.
So Jeff, is this data poisoning stuff just basically amounts to, um, damage for damage sake? I mean, is there any monetary purpose to this for the bad guys? I, or are they just trying to, uh, you know, destroy things for the sake of havoc and they're just really, you know, anarchist?
I don't know. Well, well, I think there's certainly an anarchist component somewhere in there. There always is when there's bad guys involved because they can, they can jump on the wagon and, and have a certain level of anonymity in the beginning.
But I think there's a lot of different vectors at play here. Let's, let's start out with a big one nation state, okay? If na, if a nation state decides it wants to poison, um, data, for instance, that's being used by, um, an AI system, the advantage they have is from the time they start the poisoning until this time it's discovered, they can either redirect a strategy, they can redirect weapon deployment or, or anything in between.
They can find a way to exfiltrate, um, data using it potentially. Because if you put, if you poison data in a certain way, you can put markers in there that say, when I get this data, I know it's data that I poisoned. And when I get something that doesn't have my marker, I know it's real data.
So, you know, there's an exfiltration opportunity that really didn't exist before AI has allowed that to happen at scale. Uh, you know, and, and those at nation state, there's those too. Plus there's also the whole, can I bring this nation down just by having all of its system collapse on themselves?
That's another one too, that, that has been tried in the past with electric grids at, at different, um, uh, Eastern European countries, Estonia in particular, had it happen, um, quite a few years ago. Once again, not new. So those are the nation state vectors.
I think you also have, you know, um, competitive, uh, corporate competitive vectors, and I'm not accusing any given company, but let's face it, there are organizations out there, or at least individuals in organizations that have no compunction about saying, I'm gonna find a way to either get my competitor's information or destroy my competitor. Same methodologies I talked about from a nation state. Um, and then you have the, um, the individuals or small entities that, that just want to say, I'm going to hold data ransom.
'cause you could do that as well. Once again, with those markers, you could say, I'm gonna hold data ransom and let an organization know your data is, you can't trust your data. You don't know what's accurate.
I do, if you want your accurate data, you're gonna pay me and, you know, cryptocurrency. So there's that. And then there are the anarchists that just anarchists rather, that just want to say, let me see what I can screw up.
Here I go, boom. All of those are there. Plus there's probably some I didn't mention.
So, um, gosh, it feels like I'm the harbinger of doom on, on today's show. Well, the nice thing about, yeah, what I'm really enjoying about this period of my career is, is that, you know, well, you know, you're right. We get to bring a lot of the doom, but one of the things I've been saying all along is that, you know, regardless, the lights are still on, the internet still works, and, you know, does that mean you're safe?
Oh lord. No. And a lot of things you should do, but will it all work out in the end, generally speaking?
Yeah, just don't try not to be the end. Um, but I love your ex exfiltration example. That's something people really get to Yeah.
Visualize and, and it's, you're exactly right. And also each of these things, again, recurs me back to my point that, you know, comes up over and over again. We're having, you know, we're gonna let AI be agentic and actually do things.
How do we trust it? It's like, what do we do now? Well, there's Bob.
I mean, Bob has been doing this for 30 years and we trust Bob. Why? 'cause he's Bob, well, what do you really, literally mean?
And we find that, again, we have, you know, sort of fragile systems or not in OT and operational technology, we find that you can trust Bob. And you know why? Because there's a system and a process around it.
It's not really about Bob, right? It's about you have a system in place. It doesn't break if Bob makes the wrong choice.
Whereas we have these IT systems where if one system makes a bad choice, you're, you're, you're done. It shouldn't be, you know, we should have, again, two, at least two factor authentication. Three again, literally in the anti station world, there are 3, 4, 5, and six.
There's not seven, there's not 19. You know, it's not talking about gigabits of everything we're saying that if you were going to make a critical choice and you have one thing to base it on, you are fragile. That is a brittle choice no matter who you are.
If you have two, that's, you can triangulate on that from your position to those two. And with three, you can make, uh, mature choices about risk and, and decision. Without those every single thing, Jeff, to your point, you know, is, is just fodder for you and I getting to get more airtime talking about today's latest, you know, silly risk.
Well, to your point, I mean, to your point, I mean point I'll trust to the point, point where I discover he has a drinking problem and then him, all bits are off. But, um, when you think about this for a minute, and correct me if I don't understand this, but as I understand it, it's, these models aren't like software that I just go patch when I find there's a vulnerability. To your point, they're layered and all that data's in there.
And once the model's trashed, it's trashed. And I gotta pretty much go and rebuild the model and replace the entire thing. And this is not an expensive proposition or inexpensive proposition, I don't know, but it seems like it's a, it's a level of fix that's a lot more complicated than people might think.
Let me push back on both those points, right? Because, you know, you don't trust Bob up until you find out he has a drinking problem. What my response to you is that you made a bad trust decision in the first place.
How on earth did you build a critical infrastructure system and be the person responsible? And it comes down to whether or not, you know, whether or not Bob has a drinking problem. And whether or not, no, you build the system so that if one node in the system like Bob or Bob, um, you know, just, and again, you know, Bob doesn't have a drinking problem.
Bob just got contacted by nation state actors who told him that unless he does certain things with a totally straight face tomorrow at work, his family, you know, won't be there tonight. You didn't engineer a system to allow Bob to save his family's life. Forget your company.
Right? You know, there is a level of willful negligent incompetence. I will take this approach.
I just think about this. Yeah, if you've made those decisions out in the world and live and it's got worked, okay, to be clear, you have had moral and ethical failures that you should personally be held liable for. And if things happen, if the dam breaks because you made the decision to build the entire infrastructure are based on whether or not Bob, Dr has a drinking problem, you will suffer the consequences and you will personally inside your own head.
And people, you know, people in these levels of responsibility think of many of the, you know, the, the great disasters and the people, the captain in charge and so forth. Um, it doesn't work well for them because you can't justify that. So we've built a lot of fragile systems.
Listen, Jeff, that sounded like your classic insider threat problem. Is that what we're really looking at? Boy, when Chris was describing that, the two words Aldrich Ames popped into my head and, and, and for those of you who don't know, either Google it or ask your parents, um, uh, but Aldrich Ames was, um, very deep in the intelligence community and was trusted, I won't use air quotes, but that that might be a justifiable use of them.
Was trusted for decades with top level nation secrets in the US and it was discovered that he was selling them. Uh, and he had been selling them for a long time, and it's because there was a single thread of trust that existed. And he was Bob.
And, and there was no way to validate was Bob, was alder change compromised? Why was he compromised? Was it something he did intentionally?
Was he under duress? There was nothing really, I mean, there were, there were certainly cursory controls put into that, but there was nothing to really figure out is that actually happening or not. And, uh, I'm not certain we're in much better shape now than we were then in the intelligence community.
Well, I, Let me, let me riff off that and go back to Mike the second half of your question, right? Which is similarly, you know, these are level of complexity challenges, doesn't matter what the, what the frame is. You know, we, we think you, so you would ask, are the, the layers of software and ai, is it now so far?
No, it has been there for a long time. If you thought you really had a handle on your software and you knew what, no, you're wrong. I mean, since you know, 10 lines of code, no, that's not how it works.
You've gotten away with it because it has not come back to bite you yet. But you've needed systems all along that, again, assume that you don't know because you emergent properties, levels of complexity. Um, it, it's, this is, this is where my inevitability curve thing comes to because it's an evolutionary thing.
Uh, you see genetically, you know, biologically all sorts of things happen for a long time. And then there's some evolutionary crux. And you can say that all of the other things were bad ideas, which is true literally in its own way, but in their environment they were fine, but they had fundamental flaws that didn't.
Saber-tooth, you know, saber-tooth animals have evolved eight or nine times in the history, completely unrelated. They have no nothing to do with each other, but they had to do with they a high oxygen environment that supports, you know, strength being the, the, the main determining factor and coffee being delivered without asking for it. So as soon as that stops, they go extinct immediately.
There's no second generation, they stop immediately. So there's a lot of these inflection points, you know, punctuated evolution to come along and, and they point out that, yeah, believing that you knew what your software was doing in the first place was a, was not a long-term choice. Alright folks, we gotta, we gotta, we gotta move on to our next subject, but I will just throw out another hashtag we might consider hashtag zero trust ai.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hey folks, we're back in. We've been talking about ransomware and I feel like we've suggested maybe we were making a, uh, some progress here and we were more cyber resilient than ever. And then along comes this latest attack where, um, cyber criminals are basically taken out the luggage system that's managed by a company and probably none of us ever heard of until this week.
Uh, and now, uh, we see travel delays and it's impacting everybody. And Jeff, I know you've been looking at this, but do we just have, or is the underbelly of it just too damn soft? Well, I I think this kind of goes back to a lot of what we were talking about in the previous segment.
In, in that there's a level of trust that we have because it, nothing's gone wrong yet. And, and there's a phrase I use universe is meta is is, and I'm gonna have to stop and say it metamorphic. The, the universe is metamorphic.
And whether it's a saber tooth tiger or an IT system or an AI layer, no matter what it is, it will change. It can't remain static. It everything has to move and either grow or die, change or die.
So, um, yeah, there's a lot of fragility in there overall. We still have solid systems and sometimes it's issues like what, what's been happening with, um, a baggage handling and boarding passes in the EU that occurred this past week that make us think, do we have enough backup systems or different levels of trust to make this work? A lot of airlines in the EU thought, well, it's down, that's fine, we'll just issue paper tickets until they realized that the paper tickets that they print came from the same system.
So they, they, they still had a single point of failure, they, they didn't fix that problem. So yeah, if you wanna issue paper tickets, that's a good, that's a, a good redundancy, but have it completely out of stream from the system that, um, yet you're currently relying on when that system, you know, turns over and doesn't work, right? So there's that.
I, I'm gonna bring up a tangential and I think it's important to actually all three, uh, segments that we've discussed today about, and it's the airline industry. Now, Qantas Airlines and I, I happen to, uh, I was affected by this, although, um, only because my name's in it, not for any other reason. But, um, on on June 30th, um, Qantas was comp, the data was compromised, I believe it was ransomware.
And they got personal data for 6 million customers. That's a pretty good size number names, phone numbers, birth dates, things like that. No credit cards, no passwords, no passport information.
So there was really no PII involved there. That's good. But what happened, and I really think it's worth noting, is that the Board of Qantas cut the short term bonuses for all senior leaders by 15% because of that.
And boy, if I, I'm ringing the bell for that one because not that I wanna see people, you know, e executives bonuses cut, but it's, we are finally, for the first time, it's 2025. And, and boards of directors of companies are saying, Hey, you are the ones running the companies. You're responsible for making this happen.
Something bad happened that probably could have been prevented. You have to suffer because of it. And I am very happy that that accountability has started to show up.
And I don't wanna get us too far from the whole ransomware and, and the systems we, we wanna count on, but that's a downstream effect that I think we're gonna start seeing more of. And that's a healthy thing. All right, well see, there's another hashtag right there, you know, hashtag cyber bonus cuts and we'll just keep going with that.
But Chris, I gotta ask you this question, 'cause I know you've talked about this multiple times over multiple shows now, but why in God's name do we keep having all these single points of failure? Are we unable as a, as a, as entities and engineers, especially just to look at these systems and kind of figure out where these things are gonna be? 'cause you know, in hindsight, at least it seems pretty obvious, but for whatever reason, we just can't seem to be able to figure it out.
Well, we were talking biological evolution just recently, right? And, and saber, saber tooth creatures. So you have to understand the reality of the situation we're all living through, right?
So, you know, just sticking with biology for a minute, you know, you're following a certain path and you know, you reproduce. There's another generation, another generation, another generation that is the right path. Now, will it extend indefinitely to the future, you know, past some punctuation event?
Uh, maybe not. Uh, but there's separate issues. And you know, in my very first, uh, cybersecurity show, I mean, launched Border Wear, I think it was 92, was in Atlanta.
And I, I was brought up, someone came up to me with, with an oil refinery and I said, oh my God, I forgot about oil refinery. You know, the whole o OT world that I came from forgot about it. And I went back to my, you know, little five people in a dog, uh, company and said, Hey, can we do anything for ot?
And the answer was, sure, and we can go outta business because we'll get one customer As, and Checkpoint is out there partnering with sun and yada yada. And at the turn of the century, it had exactly the same situation running the firewall business for Cisco. And we at the point that we had a, we were humming along doing 60, $70 million a month, massive, uh, uh, presence, and a whole team of, of Cisco, uh, uh, folks brought a whole set of oil industry to us.
And as the firewall team, we looked at it really hard and had to come back and say, no, we can't actually do it. You know, I mean, and to be clear, I I have a fiduciary responsible responsibility legally to, uh, Cisco shareholders who are, include not just the rich and powerful, but you know, retired people and their, their income to put money where it makes more money. And in 2000, um, as a vendor, I could not have fixed that.
And therefore, you know, at least from that source, which is a major source in the world, there was no solution. So what we keep coming back to is, is not that, you know, we're bad people or bad companies are making bad decisions, it's just that there are intrinsic flaws with this when and if we hit various punctuation events, um, these are unlikely to survive the gap. And I think, uh, the point of, of this particular topic and this ongoing conversation we have over the last, what is it, Mike, a year and a half or, or or more of, uh, of these, these calls, and we all have all these conversations all the time, is that I would, I would assert, I would, uh, pause it, that there's a number of, of chickens coming home to roost, uh, type of, of, of, of extinction events that are gonna be driving home.
These sort of things that, yeah, long, thin, fragile, brittle, one by one, by one systems, uh, um, don't survive the break. I dunno, Jeff, maybe we should look at this entirely differently, right? And just tell people that cyber attacks and these things are now a fact of life and they are likely to delay your flight as much as a snowstorm, and we should just kinda suck it up.
And that's just the world we live in. Well, I, I'm not sure I would use, we need to suck it up. And snowstorms are more predictable, by the way.
So, um, the, in fact, I am at, uh, you know, two weeks ago when I was on this show, I was at an airport, um, when I did it. And today I'm actually, you can see I have my flying braces on. Um, I'm on my way to the airport as soon as we, uh, complete this for yet another identity conference.
It's it's conference season. But to, to your point about what's gonna get in our way, it's, we need to stop thinking about, we really do need to change our perspective, but I don't think we should just give in and say, well, you know, it's gonna happen. Sorry, nope, I, sorry, I've been in this, I've been doing this 50 years and I've never said, oh, well I guess that's just the way it's gonna be.
Never. Uh, and anyone I know that's had success doing this has never said that. And it's always a matter of change your perspective, and it usually means expand your perspective.
As an example, uh, when I would do, um, incident response or incident response planning and training, I would always focus on don't focus on what event caused your issue. Co focus on the effect of the issue, because there's gonna be multiple factor vectors that can give you that same effect. What are you gonna do when that effect is felt?
And then it doesn't matter if it's a snowstorm or if it's a ransomware attack, or if it's a union strike, it doesn't matter if your flight's interrupted. You need another way to get to where you're going or determine that you're not gonna go there. So you need to expand your perspective to say, should my flight not happen or be delayed?
How else could I accomplish what I want to do? You know, do I go try to rent a car or take a train or whatever it's gonna be That it literally, you know, that's, that's what, you know, well, season travel is we li I, you know, you know, you're saying that as someone who does it, right? Because, but I'm on a plane, on a, knowing that I have a connection, I don't trust the connection's gonna leave the ground.
Sometimes they don't. What am I gonna do? I'm standing in some country, um, and I, and I think, you know, we, you know, getting into the organization themselves and Mike know, you know, I, I don't think, because I love the, I love the, uh, the, the across the aisle sort of, you know, cynicism versus optimism, debates.
We have, this mirrors a lot of my favorite conversations that maybe I'm wrong, but I think we are driving towards an era that isn't close. I wouldn't put it that way, but I think you can see it from here. And it's getting, it's getting into the, the frame where even people of my age, we're gonna, uh, uh, uh, in our working careers, living that world where cybersecurity gets at, where defense gets ahead of attack, it's just that we've rushed ahead of ourselves, we build communication systems that communicate absolutely will communicate.
However, are they secure? No. Jesus, no.
And, and just, just not even, I mean, on every level. Um, and we're backing into the fact that we actually need to make them secure. Now, an artifact of that is that everyone alive now is used to the idea that, well, cyber attacks and hybrids, blah, blah, blah, that doesn't mean that's intrinsically true forever.
I think we are capable of building information systems that are a lot harder to attack than to defend. You just not, you just need to have things in place that, to date we have never implemented yet. But they're, you know, they, and none of it really knew rocket science.
I mean, I've got my own opinion on the things we can do right now, but you can look back over the decades and say, oh, that's right. People were saying that 40 years ago, 70 years ago, 120 years ago. We we're just still in a very startup phase in our entire global communication system.
Mm-hmm. All right, guys, well, we ran long on the first two blocks, so I'm gonna end this here, but I would give notice on this point, the airline industry many years ago noticed that there were just far too many plane crashes and they got together and all the engineers, and they decided to build more resilient planes. This could be the same model that we can use, not just in the airline industry, but everywhere else we go to build more resilient IT systems from the ground up, because it's pretty clear at this point that we're just suffering because of our own lack of maybe foresight.
Hey gentlemen, thanks for being on the show and sharing your thoughts today. That was great as always. And thank you all for watching the latest episode of Techstrong Gang.
Please stay tuned for the rest of the lineup for Techstrong tv. We got some awesome stuff as usual, and we'll see you all again Tomorrow. Hey everyone, welcome back here to Tech Drunk tv.
You know, I don't know, there might be something in the water, but it seems it's, it's coming outta stealth season. Uh, we've covered a few companies this week, of course, that have come outta stuff. I've got another one here for you.
And it's an exciting security startup. It's called Hush Security. And to tell us about it, I want to introduce you to Mika Rave.
Mika, welcome to Text Drunk tv. Thank you for being here. Thanks for having me, Alan.
Nice. Hi everyone. Yep.
So look, first of all, congratulations, right, mazel tough. It's coming outta stealth is a big, uh, a big accomplishment in my career. I've done four or five venture backed companies and, you know, launching them out of the stealth mode is telling the world the secret you've been working on.
And, you know, no pun intended, 'cause you guys work secrets a lot, but, uh, congratulations. But before we get into Hush meher, tell, give people a sense. How did you come, you know, what, what's your journey been like?
Yeah, thanks, Alan. So I've been, you know, working with computers since, uh, the third grade or so. Uh, been very enthusiastic about it.
I liked it, you know, ever since the first, uh, I'm imt CPC that I had, uh, like in 84 I've been using that, uh, been working through that, you know, through school, college, and through all, all my, uh, career basically. I started with the, you know, the, the electrical engineering worked my way, managing teams of, um, of developers and engineers. Uh, eventually ended up, uh, as a product manager, uh, responsible for a very big virtualization, uh, project, uh, with one of the companies I worked for.
Uh, moving there from there to cyber, and then eventually kind of, uh, in late 2016, I was, uh, tapped on the shoulder by a friend of mine from way back when they were starting a company called Meta Networks, which was doing, uh, zero trust, network access very, very early on. And so the technology was amazing. Uh, the people were great, and I, I kind of, uh, jumped on that wagon.
The company was acquired, uh, three years after by Proofpoint, a very big, uh, you know, security enterprise. Uh, and then, uh, we decided, you know, the entire core team and the rest of the, of the engineering team and, and the product team just came with us. We decided to move out and, and, you know, solve another big problem that was waiting to be addressed.
And this is basically the exponential growth of, of non-human identities, secrets, uh, machine to machine access and so on. Absolutely. Absolutely.
And, you know, people think a company emerges outta stealth that all of a sudden it was born Today we just started. But no, often I, look, I have friends who've had companies in stealth for two, three years sometimes. Yes.
How long has the, let's call it the incubation of Hush, been until like today? Uh, yes, that's very true. We've been in sales for a year, right?
Uh, we've been, uh, developing very rapidly the solution in various, uh, dimensions of it, right? And because we are, uh, a seasoned team that has been working, you know, together for past decade, but separately for, you know, more than two decades. Uh, so we know, you know, we had a very good, uh, clear idea of what the, the solution would be like, and what would be the infr for that, right?
The, the, the ability to scale, the ability to design with security in mind, the ability to sell to the enterprises and the Fortune five hundredths of the world. All of those things, you know, you kind of acquire them as you go along. And, uh, we've put all of our experience into this and pour it into this solution.
We had one year to kind of, uh, hone it, and then now we are feeling that it's the right time to announce that to the world and start, uh, start getting some, uh, demand. Yeah, Absolutely. And one last thing, Micko, what, what's your position?
I'm the C-E-O-C-E-O And Co-founder. And co-founder. That's true.
Congratulations. Thanks. Uh, Let's talk about Hush a little bit now.
Hush, now that you're out of stealth, we, we, yeah. Um, so obviously you're deal tackling the Secrets problem, which is a, look, it's, it's a thorny issue. We've seen several companies, especially I'd say over the last year to two several companies really, uh, you know, going after this problem because it's, it, it's, it's a problem we've built up.
I mean, the whole idea around doing Secrets was, was in itself a good security. And, and this is typical. I've been in security 30 years, you see this stuff.
So we came up with idea of having secrets and vault, and, and of course, HashiCorp, you know, kinda led the way there a little bit. And, and it sounded great. You know, another a, a good way of, of securing stuff.
But it's a case where the solution became the problem a little bit, right? Where we built up this whole infrastructure of secrets that then became a, a new attack surface, if you will. Yeah.
Right? That's, And, and now, you know, it's like the old story. We, we, we had elephants, so we got mice in to take care of the, Now we've got mice, Now we got a mice problem.
Uh, now we gotta get cats, and then we get the cats. We'll have to get the dogs to get rid of the cats and to get rid of the dog. You know, it goes round and round.
But what, what about H's solution is, is unique, is, you know, why, why is this the right solution to manage our secrets and secure secrets and vaults and so forth? It's an excellent question, Alan. And I think the, the, it all started, you know, for us, right?
The journey started like, uh, a year and a half ago when we looked at, at the, this problem, which was troubling us, and we, this was part of, uh, what we wanted to solve. We looked at what was, uh, available at the market back then. And as you said, there were several companies, several very good teams backed by very good venture capital.
You know, we're, we're kind of doing, uh, uh, a thorough way of educating the market about this problem that is locking within their data centers and, and clouds and so forth. And the exponential growth of secret. They did a phenomenal job in the education part.
But in my opinion, when we started to look at what we, they were developing, and we talked to security practitioner, we found out that there wasn't really a solution. So it's one thing to talk about it and to scan, you know, and find, and try to find those and open geo tickets for them. But this is just a, you know, increasing your technical debt.
You are not actually solving the problem. You're still using, I would say, a broken, uh, architecture for, for the modern and complex environment that we, that we develop software in. And so we thought, you know, that's nice, but there's must be a better way to doing that.
And when we looked around, we actually saw kind, kind of parallel domains in which it was, uh, it was very well done. The first one is, is the human identity side of thing, right? And, you know, think about what has been done in the past decade, like single sign on and MFA and, uh, IGA and Pam and so forth.
So the lab, great solution, you know, to help, uh, uh, maturity, the identity, uh, and, and solve the risk around that. The second place it has been solved, uh, quite nicely is cloud native environment, right? So when you go to AWS and you wanna access one machine, you don't necessarily take a key and store it in a vault.
You just write it policy, allowing that machine to access another machine. And so we thought, we know how to do this. We need just to bring those principles and those methodologies into everywhere, cross cloud, on-prem, federated, uh, and done.
Nice. And a very, very important, uh, part of it is that we wanna do it in a way that is kind of transparent or retrofitting to what customers are doing, because we don't want to go in and do like a multi-year project that cost hundreds of thousands of dollars and, and years of, uh, implementation. And so we actually found a way to do that, and we wrote a patent, uh, uh, on it.
And, uh, we have built a platform around, uh, around that. So, so first of all, comprehensive discovery, so you can actually see what you have and where the bodies are buried, so to speak. And then on top of that, we can actually transform you into policy-based access management rather than chasing secret.
So in a way, we are going to obsolete the vaults and, and, and, and maybe the secrets as well. Excellent, excellent. Um, so the, so I, I just wanna make sure we get this here for the audience, right?
So that one of the real advantages of Hush is you don't have to be all in on the public cloud, on the hyperscaler, and you don't have to, whether you are a multi-cloud, hybrid cloud, what, whatever it is, right? You, it's one solution across the infrastructure, Correct. For your sequence.
Yes. And by the way, we are using, you know, trusted framework and standards when we do that, right? We don't wanna invent, uh, anything from the beginning.
So for example, the base of our, uh, attestation is, is a spiffy, right? If you're familiar with that, it's a kind of an up and coming, uh, standard, which was have a very hard time kind of getting momentum behind it because it's quite hard to implement that on your own. So we use that, we kind of bring that to the masses with a very, very easy onboarding team.
And it's part, it's just one brick, you know, one component in our, uh, you know, platform. And, uh, so we tend to build on, on, tried into, uh, standards and frameworks. I got it.
Let's talk, I wanna, Mika, I wanna turn a little bit to kind of the, the nuts and bolts of how people engage here. Um, sounds like, you know, if I'm a, an organization, I want to use hush security. What, what, what, what's the process?
What's it like to get started? Excellent. So first of all, we need to connect, uh, to your infrastructure, agentlessly, right?
So you give us a, you know, an API key or an, or an A RN or whatever the case is, we connect to your code repositories, to your infrastructure, to your SaaS. We scan whatever we can, and we build the, the initial, you know, inventory of, uh, of what you have. And then on top of that, and this is where we kind of differ from anyone else, I think in this field, we map everything in runtime.
So we have this set of runtime technologies, which we deploy very easily, and then we can see every machine to machine interaction and every authentication event that happens. And we've got so much telemetry, we, we upload some of it, uh, the metadata of that to the cloud, and we do some deep analysis with some ai, and we bring back very nice, uh, um, the findings and result and, and basically posture for every machine to machine interaction that you have. Excellent, excellent.
Um, is there a free trial? Uh, how, you know, what, what, how, how's it packaged, I guess is the word? Yeah, absolutely.
So basically we allow a free assessment, right? So you come to us, there is a landing page in, uh, hashtag security. Uh, you can go there and there is a get a demo and get an assessment for free.
So we can, you know, the onboarding is super easy. We can, uh, take, take our customers through that. And, uh, and basically an hour or two, you've got all your environment, uh, mapped, uh, and, uh, and yeah, it's, it's, it's easy, as easy as that.
Excellent. Yeah, I mean, we're almost outta time, but you know, I, I feel like we didn't ask this question, or at least touch on this subject. Usually companies come outta stealth.
It's, there's a, a raise involved with it, right? Because that of course helps us get out there, right? Um, talk to us about, uh, fundraising at Hush and some of the financial backers.
Yeah. So while financial backers are, are amazing, uh, we've got Battery Ventures, which is a global, you know, uh, very well respected and known in the industry. And, uh, we also have, uh, the cyber, uh, aspect of thing, which is Wild ventures, and they're doing an amazing job.
Uh, and so I couldn't ask for anything better, right? It's, uh, it's a, well, uh, you know, known and backed one, which is better. And then we've got, you know, the, the cyber, which are experts, and they have their networks of advisors and, and CISOs.
And so I think it's a great mix, and I, I, I, you know, recommend that for any cyber, uh, uh, innovators out there. It's, uh, come talk to me about it. Excellent.
Mika, again, good luck and congratulations. You know, congratulations. I, I, I think I told this once to a founder.
This is the end of the beginning. Mm-hmm. S True.
And now you start on this next stage, and, and it, it's exhilarating. It's, you know, but as long as you have the passion, if you have the passion for what you're doing and believe in it, it, it's, it's great. Um, keep us posted as you guys continue to expand here.
Maybe we'll see you, I don't know, at some security conference in person. Oh, Absolutely. I'm gonna be everywhere, so, uh, I'll look up for you.
Alrighty, good luck. Uh, thank you very much. Thank you.
Hush Security, and it's hush security. Go check it out. Managing Secrets a real problem is a real solution.
We're gonna be back on text Drunk TV in a minute. We'll take a break. Hey guys, thanks.
With Throw, we're here with Zach Lloyd, who's the CEO of Warp, and we're having a little chat about something called Warp Code, which is a whole new way of thinking about CLI for application development in the age of ai. Zach, welcome the show. Thanks for having me.
Excited to be here. All right. Well, I'm not sure everybody knows exactly what Warp is or what Warp Code does, but maybe walk us through the fundamentals here and why do we need a different way of thinking about the CLI?
Yep. So the, I'll start with just like the basics of Warp itself. So Warp, um, started, uh, three or four years ago with the idea of, uh, improving just like the fundamental terminal interface.
The, um, you know, the kind of genesis of the idea was I've been an engineer for a really long time. I've always worked in the, in the terminal, never been a terminal power user, but I've always worked with people who were, um, really good at using the command line and wanted to build something that made that power more accessible to other developers. So we spent the first couple years of Warp just trying to make the terminal more usable.
Um, when ai, uh, started becoming more powerful, uh, even before sort of chat GPT, uh, we started building features into Warp that would allow developers to, uh, sort of translate natural language into terminal commands. So if you're like, oh, I don't know how to, um, you know, find files across my directories or do certain advanced things in gi, you could, uh, sort of ask or in English how to do that, and it would give you the terminal command. Uh, as LLMs became more powerful, we realized like the terminal interface itself is actually a great interface for interacting with ai.
And so instead of just using like terminal commands to drive your computer, uh, you can use, the biggest thing that's different in war versus another terminal is that you can just use natural language directly to ask your computer questions or ask your computer to do things. So, for instance, you could be like, set up a new project for me with React and TypeScript and Warp will do it for you. The, um, as like, um, the models become more powerful, we realize like people want that sort of interaction, not just for doing things that are traditionally terminal tasks, but just doing coding.
Um, which is probably like the number one developer activity. And so the most recent thing that we've launched in Warp is a way where you can do a agentic coating. So you can, you know, simply tell your computer what you want it to build, what feature you want it to build, what bug you want it to fix, uh, in natural language.
And it looks a lot like a terminal interface, but it actually can do things that are more typically in a code editor. So like, it can produce diffs, it will show you a, uh, way of like reviewing your code. So it shows you the active Diff, um, it, uh, basically makes the coding experience where you, if you're starting a coding task with a prompt much better.
How does that differ from all the other AI coding tools that are out there? Are they kind of trying to wrap some sort of graphical environment around it and most developers don't seem to enjoy? Or what's the difference there?
Yeah, so there's really, um, the way I think of it, there's two other kind of buckets of, of competitor products that have different approaches. So one is like the kind of AI enabled IDE. And so this is something maybe like Cursor or uh, GitHub copilot where the fundamental interface, uh, is still like a code editor.
So you're opening up files, you're looking at code, you're handwriting them. And kind of the best feature in those apps, in my opinion, is like AI driven, auto complete. So you, you type and like you see the ghost text of like the computer, uh, like of the AI suggesting what, uh, should come next.
Those tools also do have like agents in them, but they tend to be in a sort of chat panel. And, um, you know, it's, it's a less natural way of working with agents than just having like the whole interface dedicated to the agent. The, um, the other thing that's really, I think, more usable in Warp compared to those types of tools is like, um, you know, you can do stuff, uh, across multiple projects at once, whereas the IDs tends to be very like one project at a time workflow, and you can do things across the whole software development life cycle.
So Warp is really good for setting up new projects for coding on them, but then for also like deploying them, debugging them in production for interfacing with like your cloud services. So the terminal is like, kind of like one level deeper in the stack. Uh, and so that's makes it, I think, a better option than the IDE based alternatives.
The other set of tools that have caught on lately are things that are like, um, cloud Code or Gemini CLI that are like, they're not terminals, they're apps that run within the terminal, so they're like CLI apps. And so those are, um, it's a very, it's a similar way of working to Warp, but with a much more limited, and I think hard to use interface because you're limited to, uh, just like a purely text-based app. And so, you know, like you, you don't get editable diffs, you don't get the ability to review, uh, an agent's code in a code review pane.
You don't get a file picker. So there's, there's all these like kind of limited things around working in a purely text-based environment that I think, um, you know, warp makes much easier and, and gives you a better developer experience with. Is this also likely to appeal to software engineers that are running DevOps processes?
'cause they typically work within that terminal as well. And I think a lot of the AI coding tools are a little more tuned towards traditional developers without thinking through maybe what software engineers need. Yeah, I, I totally agree with that.
So that's one area where Warp is like really strong. It's for DevOps and production for people who are more comfortable in general in the terminal who are doing tasks that are more terminal oriented tasks. Um, I think the other tools also are more widely adopted by like Vibe coders.
So, you know, people who don't even really necessarily know how to code. And we have some people like that who use Warp, which is cool. Um, but we're focusing more on pro developers who want to, you know, get to shippable a AI generated code, which means like, you know, as a developer, you really need to understand, uh, what code an agent is writing.
You need to be able to review it, you need to comprehend it and like be able to stand behind it as though you wrote it yourself. And so we're, we're not really focused on the use case of like someone who doesn't know how to code making a whole app in Warp. We're much more focused on the use case of a pro developer who wants to use, uh, AI to accelerate their daily workflow.
Mm-hmm. And what is the impact of AI so far that you've seen in terms of what it means for professional developers? Because to your point, I'll talk to them and they like the idea of it, but then they struggle when they have to debug an application 'cause they didn't write the code and they don't have a lot of understanding of what's happening in there.
And so then they get a little frustrated. Yeah, this is, this is a hundred percent the biggest problem with it right now. So if, like you said, if you look at the Stack Overflow, the way Stack Overflow survey, um, the top two complaints, a, about AI generated code from pro developers are that the AI produces code that's hard to understand and has subtle bugs.
And then the second thing is like, it's really hard to debug and work with code that you didn't write yourself. And so, um, these are, I I think there's a couple approaches to like fixing this, um, and being productive with, uh, with agents. The first thing is like, I think it's like a, almost like a cultural thing or, or just like a how do you as a developer approach working with these tools if your approach is like you're just gonna like tell an agent to build a future and expect to get good chipp able code out of that.
I think that's not really where we are today, frankly. Uh, it might work for like small, for small things where it can sort of like, just like do it in one shot it, but more typically, uh, if you take that approach, uh, you're gonna get code you don't understand, that might be buggy that probably won't work, or maybe it'll work, but you won't understand why and it won't be mergeable. So what you have to do as a developer is change your approach when working with AI to first off, specify not just like what you want to build, but you have to specify how you want it built.
And so I think that means like, um, you know, working with an agent on a, uh, first of all, just like understanding the code before you even ask you to build anything. And so these agents are actually like awesome code explainers and like code explorers, like they can, they can help you get familiar with new code really, really quickly. Uh, and then the next step is like, once you understand the code, it's to be, you know, iterate on a plan, uh, or a spec, whatever you wanna call it, where you get really clear with how you want something to be built.
Uh, then you, you know, then where the agent can really save you time right now, as in like implementing that plan. Uh, and it, it, uh, you know, you don't get as many surprises if you do it that way. The third thing is that you should work in small chunks.
And this is just like good engineering practice in general. Like, this doesn't really have anything to do with age agentic development, but like, if you try and do one huge thing with an agent, you're gonna have the same problem as if like you wrote, you know, one huge PR on your own, you'd never want, like some, you'd never wanna review a giant PR from someone else in your team. And so, like the way to do it with agents is, um, you know, specify a small piece of it, maybe you have it, like write a few functions or write the model layer or just write a, a part of the API verify that it's right, write tests for it and continue.
And so like you have to like kind of think of it as like you're guiding like a junior engineer to write code. Uh, and if you do that, I do think you can get really great, uh, productivity gains out of it. It's just like you have to have like a, a reasonable mindset around like, you know, how to work with it and not expect sort of magic.
Mm-hmm. The, um, and so the, you know, I guess one of the big things that we're focused on feature-wise at Warp right now is like, how do you make that workflow really, really seamless where it's not just like, fire and forget and let an agent just like go off and run and like do your thing, but like, how do you review its code as you go? How do you work with it to get to a good plan?
Um, and so those are the types of product features that, that you want. If you're a pro developer doing agent development, How will this all evolve in your mind? Is each developer gonna have one AI agent that does a bunch of things?
Or will there be multiple AI agents that are trained to do various things? And if I'm on a team, well then we all have to coordinate our AI agents amongst ourselves, or maybe there'll be AI agents on the team that are trained to do specific things on behalf of the entire team. Yeah, so it's a great question.
So in the short term, I think it's totally fine to have, have, like every engineer has their own agent set up because, um, it's like, it's very much the agent is in the inner loop, meaning like the agent is in like the part of software development before the engineer even shares their work. And so it's, in a similar way, it's fine for every engineer to have their own different IDE set up. I think it's okay right now for every engineer to like use their own agent to, to help them get to a, a pr, they want someone on their team to review.
I think as agents move to the cloud, which I think is starting to happen, um, it makes more sense to standardize. And so that, you know, like I think something that's gonna happen is like, you're going to have agents writing code based off of system events, meaning like, oh, there's a crash that your crash reporting system has detected. Okay, an agent is gonna be listening to that and write a draft pr and that's not even involving like a developer per se, in their personal setup.
So for something like that, I think it makes much more sense for people to standardize, but we're very, I think we're very, very early in that workflow, uh, and where we are today. It's like, it's much more like, can you get developers accustomed and comfortable working with the genic workflow in a way that suits, um, how they like to work. Mm-hmm.
What do you think will happen with professional developers? 'cause every time we turn around somebody's saying, well, this is great, we won't need professional developers. But as far as I can tell, somebody still has to at the very least, manage all the AI agents.
So how, you know, from your perspective, you know, what's reasonable expectations here? Yeah, I think, um, I don't think professional developers are going anywhere anytime soon. I think, um, if you're a professional developer, the smart thing to do is like invest in learning AI as another tool.
Like, I think that's, that's where we're at with it right now. It's like, it's a tool and if you learn how to use it well, you can become a way better developer. And so I don't think it's like a great strategy as developer to be like, I'm, I'm just gonna ignore this because it's like, yeah, I don't know, what's a good exam?
It's like, oh, I only wanna work in Assembler. I'm not gonna work with compiled languages. Like, that's like a self-defeating, self obsoleting approach.
But I also don't think that there's, like, there's not like real risk, like at the moment, uh, every company I know is hiring more pro developers. Um, warp is hiring more pro developers. I think if you are, um, a pretty inexperienced developer, there is risk.
Like, 'cause like, it's the same kind of risk that exists from like WordPress or website building platforms, displacing people whose primary skill was like building websites. Like, like if your primary skill is like building something that an AI can totally build all of its own, I think you need to uplevel your skills. But for by and large, for people who are working at, like, on either enterprise software or complicated consumer software for their job, I don't think there's like super big risk right this minute.
Um, you know, the model's changed quickly, so I won't say like forever, but I don't like, we're hiring engineers right now. It's very competitive, so I don't, it's like it hasn't really changed. So what will be the ultimate outcome?
And I ask this question because some folks say we're about to build more software in the next two years than we build in the last decade. But in my mind, it also just seems like, well, maybe we might build software a little bit faster, but maybe we'll just build better quality software with less stress. Yeah.
So I think it depends like what kind of software you're talking about. So there is this emergence of this new kind of software where it never would've been economical to build software before. Um, but an agent can build it for you.
And so this is almost like personal software. Like I know people who are building like ad hoc things to manage like their wedding or whatever. And so it, and who are not developers, they'll go in, they'll use like a tool and they'll use something like, they could use Warp, but they might use something like Lovable or Bolt or whatever, and they'll, they'll build an a disposable personal app that will only be used one time.
And so that's like a whole new kind of software that never would've made sense to have been built before. So there's, there's gonna be more of that in the like, professional context. Um, I think it's more like what you said, like, I think it's like a productivity multiplier if it's deployed correctly.
Um, I, uh, you know, I don't, I don't, I have yet to see someone build from scratch. Something that's like a truly, you know, hard to build app like Warp or Figma or Google Docs or like what, like, it's just not a thing. It, like, it's, it's too hard and for the agents to do right now.
Uh, and so I think what you'll see is like AI gets deployed as a tool. It's, there's like a percent acceleration, which depending on the type of task you're doing might be, might be small or might be really big. Like it tends to be really big in circumstances where, um, you are doing something as a professional that's like, would it like zero to one, like in a language you don't know.
Like there are all these cases where it can really accelerate, but for day-to-day development, I think it's like some percentage acceleration and will, you know, help Companies ship better software more quickly. All right, folks, you heard it here. The way we build software is definitely changing, but the key thing about all that as well, there's still humans doing it.
Zach, thanks for being on the show. Thank you for having me, Mike. This was great.
All right. And back to you guys in the studio. Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders who are shaping the future of digital defense.
I'm your host, Carolyn Wong, tech Strong TV podcast features your favorite video series, industry thought leader commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity both as a weapon for attackers and a shield for defenders. The AI security edge dives deep into the evolving cyber battlefields where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back.
Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, we hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense. Today's guest, let me see if I can say this right.
So there's an American version, which is Francesco Sipe gu, but then I'm gonna sippel, I tried, and then, and then, and then the proper version. We're gonna try Francesco Chip. Yes.
Boom. Way better. Okay.
I'm like extremely proud of myself for that, but you know, just, I think that might have been like a one time thing. So we're gonna call you Frank. Frank, thank you so much for joining us.
That's Frank. Frank is a cybersecurity leader, entrepreneur and thought provoker. He is at the forefront of application and cloud security.
The most important thing that you need to know about Frank is that he was a practitioner, and now he's the CEO. He is the founder and CEO of AppSec Phoenix, also known as Security Phoenix, a company that is pioneering contextual, risk-based vulnerability management from code to cloud. Frank has done all sorts of cool stuff at HSVC, at AWS, at the UK and Ireland chapter for Cloud Security Alliance.
He's a professor at Ions. He is a multi award-winning podcast host. It's actually weird for Frank to not be the host right now.
He's a regular keynote speaker, he's an author, he writes books, white papers, articles, and, uh, he's also a self-taught artist and a former professional skydiver. So if this is the first time you're meeting Frank, I'm so excited for you because you know what, Chad Cheap pt, uh, which is actually like, that's an AI use case, right? Um, if this is the first time you're meeting Frank, or are you in for some good stuff because there's so much good stuff, Frank, welcome Caroline, as always, you shine.
Thank you for having me. So Frank, What did you find? All this stuff, Everyone, uh, literally it's chat, GPT.
So everyone on this podcast, I, I like to ask the same questions, but, but you're not like a, you're not like a typical podcast guest. Not really. And so I'm gonna ask you a different question, which is tell me what you actually really think about all this AI stuff.
Tell me the real brutal raw truth Is a bubble. Uh oh. Uh, but is a cool bubble.
Okay? Okay. Tell us more about this bubble.
com bubble. com or not as experience. Instead, right now, we have organizations still trying to figure out how to prioritize vulnerability, how to do cloud, how to do software, while attacker extremely enthusiast about, Hey, let's use this technology, or let's weaponize the model that are trying not to do it.
And I think Tropic has published, uh, a recent playbook on how attacker are creating new method and way, and they, of course, they're trying to stop, they're trying to ban them, they go through, but we start seeing case where LLM are weaponizing vulnerability or are being used to attack ransomware. So AI has lowered the barrier of, of, of access for cybersecurity professional, but also for attacker. And we were overwhelmed before, like I think right now the difference between the DO com bubble and right now is we're seeing this technology put exciting, but we're seeing it as faster growing as a weapon and as any new technology, we are seeing the rush to market.
Of course, Trump insecurity read us as MCP because API security wasn't hard enough, so we needed, needed to have GraphQL. And one of my good friends is saying, I love any GraphQL because I can hack the way through it very easily. And because that wasn't sufficient, we had to create MCP.
Actually, we release our MCP server and we shut it down for security concern. I'm proud to say it because we did a threat model on that and saying, that's not good enough. But how many people out there are throwing the MCP out in the world and saying, yeah, it's secure enough, right?
Frank, I I have to pause you for a moment because there are folks listening and watching who know what GraphQL and MCP are good for you, and there's people who don't. So for the folks who don't give us a little bit of background, talk to me as though I'm my 75-year-old mother-in-law, or my 10-year-old daughter. I, I think you might be right.
I, I get over excited about technology sometime and I think that everybody lives in the world of stuff that my brain lives. Um, sometimes Only the really smart ones, All the crazy one. Uh, but thank you for the compliment.
I think when we look at the internet, we had the history of API that were soap XMLs, a very ancient way to pass data through a system that expose a web interface, and then we kind of settle on rest API That is the standard method where we taught really, really well and long about how to secure those things, how to create that entity. So I think rest API has been around for a very long time, but for rest API, you had to create basically endpoint for everything that you want to do. And that is means development.
So some of the dev team has said, why not throw caution out of the wind and open everything to everyone? Just query whatever I want and I expose anything that I want. Because that has worked out well for us in the past.
So that's was the history of GraphQL that you can secure, but it's really difficult to constraint or provide access control because fundamentally you can tell, gimme the information about this, this, and that. And graph would say, gladly, here you go. Uh, do you have the permission to see that stuff?
Hopefully you have your pass through credential or pass through authentication configured. Most of the time you probably don't. So you create, just access your data lake and if you're lucky, you just see what you wanna see.
Um, but it's very difficult to control. Now, MCP have been built in a rush on a protocol that has two or three version and eight to a was the evolution of the MCP protocol, but authentication was nowhere to be seen. And all to authentication token being passed through or authentication and authorization have been kind of left the world.
So we're seeing MCP being exploded up, down left and right because it's a new technology and because it just rely on not very strong foundation of authentication and access control. And that's one of the reason why we shut down ours because our API will build with Phoenix security with specific method in mind. So we put, uh, an MCP server in front of it, and it gives, it gives you access in a different way that we want.
And we expected, so we did a, like any security folk would do a threat monitoring exercise. We deem the things not secure enough and we say, you know what? Let's leave the hype to the hype.
And I'd rather not get hacked than be late for a few weeks. Um, and that's what we did. But I think we won the few that actually take that hint.
That's so interesting. Uh, humans want to use technology to share information and then they end up sharing it with people that they didn't wanna share it with. And if you're intentional about putting some calls, controls in place, then it takes more time, it takes intentionality.
Um, and now we have not only automation, but we have ai. So the problem is just worse, more data, more places for that data to be more places in our supply chain to poison and to steal information from. And so Frank, I think yeah, please.
When you Have, we have, I've been thinking about this very hard and very strong, like why LLM seems so attractive. It's like, why is so easy to get caught into the perception that we have an answer? And the answer was there is the fact that LLM always give you an answer despite that it's good or wrong or whatever, or whatever precision you have, you always click get an answer.
It might be wrong, but you always get an answer. So it feels that you're making progress despite that you are actually making progress or not. And that's the intoxicating element of LLM.
You don't know anything about API security, I'll ask other lamb to do, teach me about API security. You don't have context. You haven't asked us specific things, but it will return you with some stuff.
Um, hey, I have this code. What does this code do? I wanna do these particular things.
It will give you an answer. It's probably wrong. But that's why the excitement, because the barrier of acquisition have been lowered, the fact that it doesn't always speed the right information is a different story.
And hence why people that understand how AI was built. I was building bias and network and neural network back 10 years ago when AI wasn't cool. And me and my co-founder understand really well how AI was built.
And LLM is just a variation of an ai. And if you understand how it works and how to ask the right question, you become a superpower because it really 10 x you. And I think I'm, I'm surprised by the kind of things that if asking the right questions, it will give you the right answer or it will speed up your work, but also can slow you down tremendously.
Or it can create a generation, I think of no brain coder and as an industry, I mean you in threat mode or was we, we, we go long time, me and you, and we've seen the industry kind of trying to make an effort. I think right now we are creating a generation of people that don't think securely or they don't even understand what they vibe coding. So that's a little bit my fear of creating a generation that doesn't have the understanding or the baseline understanding, but just go with it and vibe with it.
And you can vibe secure coding. I mean, our good friend Jim Monica has created a whole training about vibe coding securely. And I think you can, you just need to know what to do and what to ask and how to ask it.
And you still need the principle to be in there because AI will not magically secure your application. So Frank, uh, what I hear you talking about is a comparison. Uh, there is kind of like the no brain way to use ai.
And there is on the flip side, a very powerful way to use ai. And so my question for you is, what advice do you have for our listeners to be, not the former, but the latter? How can we all learn to be the best users of AI and not the no-brainer ones?
That is a great question. And for that, we've broken our manifesto. What, what, what, okay.
Uh, It's not yet public, okay? But we call, okay. Oh my gosh, AI second AI Tell Us everything.
Ai second human first, Ai second human first. The manifesto tell us everything. So I've been thinking a lot about this and I think with all this hype, we tend to, we tend to place AI first.
You see a lot of company coming out and saying, we are AI first. AI is gonna solve all of the problem in the world, and it's so cool and it's whatever. No, AI is just a tool.
And like blockchain was just a tool. Let's try not to create solution before we have problem to solve Engineers. And I know, right?
But in general, if you, if you treat AI or LLM or vibe coding as a technology, as a tool, and you learn how to use it, you become really powerful. And I think in few years that's what's gonna distinguish the people that talk about Vibe coding, LLM, but they don't know how to use it to people that have experience and know when to use surgically technology for that experience. And hence why we say human first, empower by technology like an lm like a chatbot, like an AI tool to 10 x their capability.
But ultimately you'll never be able to fire an ai. So decision will never be able to be delegated to an agent. But an agent can 10 x your engineers.
So if you train your engineer well, junior and senior to use technology in the proper way, then you have a force of nature. And I think our attackers have understood that. Well, first, some haven't.
Some vibe codes write me the, um, what was it, what's a ransomware letter for the FBI for the director of FBI? Because we have all that data. Uh, and somebody has came up with the same kind of things with Google without any improvement, without proofreading or so on.
But in general, you have people that understand this technology and they wanna use it and AI second, and you have people that put AI first and they will be left second. Yeah. And hence the manifesto.
You know, I'm so excited for this because it truly is the message the world needs to receive right now. You know, a year ago, and still today, every board on the planet wants everyone to use AI for everything. You know, every engineering team is being told Use ai, use ai, use ai.
No one is talking about how to do it properly, how to do it. Well, boy, is there a difference between doing a thing Yeah. And doing it Well, I, I can't wait.
I can't wait. Who, who, who, uh, who's coming up with this manifesto? Tell us about the creators.
So I generate the first idea. I sent a few of the leader that you well know, Azar, a few others that have done their first pass on it. Um, few other CISO and uh, thought leader as well have contributed on it.
We'll have the full, I think we have 25 right now in us. We try to make practitioner and CSO alike and non technologists to actually come up with a message that was sustained by both practitioner in security field leader, a CSO in the security field and non practitioner to actually write something. And we wanted to keep it purposely short with 10 commandments that really say, think about these things securely and think about this as a technology.
Like that's the underlying mean. We can go through the manifesto, but that's the underlying message of the manifestos. Like use tech, use this technology as a technology, use it wisely.
Like by code. Absolutely by code the hell of things. Um, as A-C-E-O-I push for AI adoption, not AI first, but AI adoption to all my engineering community.
But also we have guard rails and we have methods of embedding things. And we are actively researching how to insert secure prompts in the vibe coding thing. So they will always return a secure vibe coded message or prompt.
Like that should be the core of what we do. And the core message of what we do. It shouldn't be, if you don't use a vibe coding tool, by Tuesday you're fired.
Like some CEO have put Yeah, On tap. I think that's a wrong message because that's that create that people will adopt, people will adopt and people will make mistake because it will delegate thinking to the technology. Well, this should be a thinking aid.
It shouldn't be an outsourcing. It might be unpopular in this opinion, but I rather us going forward with the eyes well open rather than creating, or was it the movie Terminator? Sorry, I had to throw it in there.
You know, Frank, what I like about this is what I'm not hearing from you is I'm not hearing any fear. What I'm hearing actually is a sense of empowerment. You recognize the power that we have as humans.
You know, do we store tremendous amounts of data in our heads? Yeah, we do actually. You know, do we have decision making?
Do we have discretion? Do we have judgment? Yeah, we, we do actually, you know, and so I'm delighted to hear this sort of elevation appropriately of yeah, the human, uh, and who is in charge, right?
The human or the machine. It better you how Far you can fire a machine. Like ultimately comes down to that.
Like you wouldn't be angry at the machine because it does machine job or it doesn't error or it has a bug. Ultimately technology is technology and we need to recognize this as a technology. That's we, that's what we, in Phoenix, we created our AI agent as copilots that aid decision making process, but empower people to make those decisions.
Ultimately we present three remediation plan. We don't know better than the engineer. We give you guidance, we give you insight, we give you direction.
And we say, based on this, and we explain the reasoning as well based on this, this is why we doing specific things. But then if you think that fixing things by a specific asset or fixing things by a specific threats attack vector is better, choose that remediation method. So we want to empower instead of replace human cool and security engineers.
I love it. And a lot of people are scared right now because they, yeah, this technology feels like is is AI is gonna replace or go or come for my jobs? If that's the fear, then you're in the wrong job.
You need to elevate yourself to use technology. I think that's where the fear come from. And you have I think two sides of people that fear a technology because they feel overwhelmed and they all mean this, uh, scary technology because it seems to be able to do everything and nothing.
So either you embrace it or you be left behind. And that's the hard truth. So it's better to embrace it, use it securely, and be at the front edge of this.
But if you were doing spreadsheet yesterday, I'm sorry, this will be replaced. Yep. Hard pill to swallow.
Uh, but I agree and uh, Frank, as we're kind of beginning to close up our conversation today, for folks maybe today's the first time they've learned about Phoenix security, tell, tell folks about Phoenix security. So long story short, we were a bunch of practitioner that were leading AppSec and cloud set transformation in most of the banking world. And we wanted to solve a problem that is how do we align executive expectation to engineering action?
One of the frustration that we had was when we talk to engineers as security practitioner and as security leader, we tell them, you shall secure your system. And when they look at us and say, what does that mean? We don't have an answer, or if we have an answer is, well, you need to fix your vulnerability by SLA or you should do threat modeling.
Okay, teach me, I dunno, this is a template to use it goodbye. I don't have time, we don't have scalability. So we wanted to empower, first of all, engineer to understand this is what security expect of you.
And then we wanted to align that message with business expectation. Because if it's not important for your boss as an engineer, you are never gonna be giving attention to a particular problem. So we wanted to solve the problem of security across application security and uh, cloud security.
That is called vulnerability management. That is a problem that we had for 20 past years and we wanted to solve it from a business perspective because that's the only way it actually work. And then in that journey we evolved that with asset inventory.
That is also another big problem that we discover in the journey saying, if we don't know who needs to fix what, how can we tell them to fix stuff? So we open source our CMDB, yamo based CMDB to empower every engineer to declare this is what I own and I don't have to log into an ancient 1999 uh, black screen with green line system. I can just declare a yamo file in apo.
And that's automatically configure Phoenix to say, this is the stuff that this team owns. So if they have vulnerability and you expect them to fix it, we're gonna notify exactly who needs to fix what, where, and tell them why it is important. And in a nutshell, that's Phoenix.
That sounds really cool. Frank, if you could go back in time and do the job that you were doing at HSBC, what would it have been like for you if Phoenix Security technology had existed? Well, it's funny that you asked because that's where Phoenix was born.
Incredible. We created that for ourself in there because we had that frustration because we couldn't translate an executive saying we should do security. An engineer saying, what does that mean?
So we created a way for executive to report this is the percentage of security that we want to decrease. This is the risk level we wanna go. This is the amount of money that we wanna reduce in term of direct and indirect impact.
And that very high level message that a non-technical, um, or risk base executive can express, could be translated to engineers saying, this is the vulnerability that you need to fix. This is where you need to fix. And we as security were coming and saying, look, if you look at this library, this system, these things, you actually maximize your risk reduction.
So you will look way better for your boss. So instead of demonizing engineers who were coming and aiding them to get to their target faster, and look, that was four years ago. So it was a very, um, early stage Phoenix.
But that's what the gamification from a business perspective and from an engineer perspective is what have enabled us to move from resolution time of 290 days to 20, 30 days. Nowadays it's not sufficient anymore because I think with the latest data that we've seen, expedition time fluctuate between three minutes and seven days, depending on what kind of data source you look. So 30 days is not anymore for critical, but if you don't know who does what, probably you are over a year of remediation.
Yep, yep. Frank, last last thing that I'll invite you to consider doing with me. I want you to teach me how to say your name properly.
Can we, can we try this together? Let's, let's try. Please say it and I'll see if I can repeat.
So I usually, it's a funny joke and my partner always makes fun of me because I say I go by Frank for friends. And then if somebody doesn't call you Frank, it's like, does that mean that they're not your friend? So I don't realize it's, it is, it is something that is ingrained right now with me.
But if you wanna try in the Italian way, you did it beautifully actually. Uh, it's Francesco chip. Francesco chip.
That's great. Yes. Okay.
I'm so happy. Um, gosh. Thank you.
Thank You so much. Honor Italian now Thank you for your time today. Thank you for your wisdom.
Thank you for the work that you're doing for our industry. I cannot wait to read this manifesto and tell the whole world about it. Thank you.
Brilliant. I think you worry man needed. But thank you so much for GE having me on this side of the podcast.
It's my pleasure. Folks, text Strong TV podcast feature your favorite video series, industry thought leadership commentary, analyst research on so many topics including AI and cybersecurity, but also DevOps, cloud Native digital transformation. Uh, come on over to Techstrong TV podcast to find all of your great content.
This has been the AI Security Edge. I'm your host, Caroline Long. Thanks for being with us today.
Hey everyone, it's Alan Shilo and we're back here on Tech Drunk TV in beautiful Napa Valley at the Jfr Swamp Up event, continuing our Day two coverage. There's a little bit of a break going on, you can't see, but out there people are eating ice cream and peanuts and potato chips. It's a little mid afternoon break, but we're still here 'cause we've got a lot more to bring you.
Let me introduce you to our next guest. If you've been watching Text Drunk TV over the years and any of our coverage of Jfr, you already know him, but I'm gonna pronounce his name right for the first time. 'cause it seems my pronunciation is a little old fashioned.
So let me introduce you to Yoav Laman. Perfect. Hey, nice To meet you, Yoav.
It's good to see you. Yoav, of course, is a co-founder, one of the co-founders in CTO here at j Frog. Yoav, a pleasure.
How are you that Busy? Lots of announcements this warm up? Probably few.
The most few we're a few is this warm up that we have, right? Uh, lots of good good feedback from customers and, uh, also some suggestions. So, uh, And that feedback's, that's, That's the goal actually.
You know, what they say, the feedback from this year's Swamp Up will be in the products for the next, Hopefully even Well before with ai. We have to. So, y we were talking, you know, before we got on, we have had a lot of people give us a piecemeal, a piece here, a piece there, a piece there.
I'm gonna ask you, pull it all together for us, right? Give us the a go overview of all of these great announcements, all this great innovation mm-hmm. That was announced here at Swamp Up.
Okay. So I'll try to give the full umbrella of announcements that we made. So we started with Jeff Oak Fly and Fly is, uh, uh, our own disruption of the platform for, uh, a new agent, uh, repository based on olfactory.
And that's, uh, that comes with, uh, a new user experience for managing software releases. Uh, so that was our first announcement, then we went over to, uh, AmTrust. And AmTrust is, uh, the way to control your software supply chain based on three, uh, major concepts.
First one is application that gives you ownership assignment for every release, every artifact, uh, in the JO platform. The second one is, uh, signed evidence. And we announced, uh, partnership, uh, with many leading industry vendors, uh, such as GitHub, such as, so now, such as ServiceNow, uh, to, uh, uh, integrate their evidence, uh, into, uh, into the JO platform to accompany the, the releases.
And, uh, finally, uh, it's, uh, policies that, uh, allow you to use the information, uh, within the JO platform, use evidence in order to assign rules for the progression of your artifacts, uh, of your releases, uh, all the way towards, uh, production. Uh, so this is Apru. It's a, it's a unified package that includes all these, uh, three main features, uh, ownership evidence and uh, uh, policies.
Um, so that was, uh, another announcement. We also had a deep dive to our integration around evidence with the, with GitHub to take the salsa provenance of GitHub, uh, workflow bills and put them alongside artifacts in the JO platform, uh, as evidence, which is, when you come to think about it, it's the logical thing because, uh, you, it makes sure that, uh, that the evidence itself is bound to the artifact and you can never get out of thing. And it's also the fact that Artifactory is the entity that is exposed to your production.
So that's, uh, one thing that where we did a deep dive of Atrust and, uh, uh, other thing is we announced on stage and integration with ServiceNow, uh, around Atrust as a, as a full, as a, as a whole. Uh, and we show the, uh, synergy between applications that many of our customers are already managing in ServiceNow, and how change requests in ServiceNow are going to be, uh, reflected as evidence in, in, uh, in JO, uh, and vice versa, how you, how you can move between the platforms. So that was, uh, also a part of the big announcement of apta.
Yes. Then, so it's a mouthful. Then, uh, we moved to, uh, uh, a new announcement, which is, uh, around machine learning and ai.
This is AI catalog. Yes. And AI catalogs, uh, allows you to have governance over, uh, models that are packages, but also models that are, uh, uh, SaaS like, uh, anthropic and open AI and so on.
Uh, under a single platform, you have a catalog where you can find the latest versions of the models and the metadata about them, like the security status, the, the licensing, and, and, um, other metrics that have to do with the model health. And then, uh, similar to what we have, uh, uh, in curation, uh, we elevated the same features for machine learning. So you can allow different teams to use different type of models.
Um, for instance, you may allow a research team to use deep seek, but you never want to see that, uh, in a production facing, uh, uh, release. And part of that, when it comes to, uh, to SaaS models, is, uh, also being a gateway between you and the SaaS model. So if you, for instance, if you're using open ai, uh, you will use it through the GO platform, and that allows you to have governance also over these type of models.
Uh, so, so this is, uh, this is the gist about the AI catalog. Mm-hmm. And then we went into a bunch of security related, uh, announcement.
I think I, I can mention two, uh, highlights there. The first one is the support for ID extensions. Yes.
Uh, and, um, basically it's a combination of artifactory acting as a proxy for your, uh, vs code extensions. So we start with VS code, we will extend it to other ideas and, uh, curation allowing you, uh, to, uh, to, to control the, the, the, the, the extensions that your developers are able to install on the endpoints. And this is one of the most dangerous and overlooked the risk that developers are, uh, currently facing because you basically install a software on your, on from the internet that everyone knows that it's wrong.
But, uh, for some reason with the ID plugins, it's assumed to be safe. It's not. And we demonstrated, uh, uh, a social engineering hack that's, uh, tempted, uh, Developer.
We read about 'em, we hear about it every other week, whether it's a docker container or from a repo component. It, Yeah. So, so now you can apply this protection by, uh, pointing at, uh, Jeff Fog your, uh, single source of record for, uh, for your ID plugins too.
And another security related announcements that we made is around the gen remediation and, uh, what we've done there. So, uh, we do with modesty, we, we have one of the best, uh, research teams, uh, uh, in the world at Jeff o mm-hmm. The security research team and our security advisories are very accurate to a degree that you can, if you find a, um, a, a zero day in when you scan the code, the advisory that Jeff o gives you is, is one that if you take this advisor as a junior developer, it really tells you what the problem is.
It gives you an example of how to fix it, and it goes into details of, uh, what exactly need to be changed in your code. And what we figured is that we can just give it to the LLM and we can prompt the LLM with the research data of jfo, and the LLM will remediate the, the vulnerability or, or the zero that, that the jfo scanners found. We started with the integration with the co-pilot, with the GitHub co-pilot, um, as part of the VS code integration.
But we will extend it. And the, the user experience is you write your code, jfo is, uh, scanning your code continuously, it finds issues, and it's taking the research data of the JFO team to prompt the LLM and apply immediate, uh, uh, suggestions of how to fix that. And you just have to accept it and, uh, and merge the changes.
So, uh, that's the, the, uh, I think that's the last, uh, uh, big announce. I don't think we did, did we do fly? We, yeah.
Yeah. Started Fly, fly. Right.
Okay. I got a little confused. An ambitious, an ambitious lineup.
Yeah. For one Swamp up. Yeah.
Very ambitious. And the A team that works relentlessly on the, I mean, the breaking trust to, to our users. The theme around all of it though, Yoav, excuse me.
You're okay. Yoav. The theme around all of this is really the, the transcendence of ai, and you know, how we're seeing this just totally upend the normal flow of, of, of progress, of, of it, of software development, of the software development, lifecycle insecurity in DevOps, in platform engineering, in, in everything.
It's, if you're not adopting this to as, as Shami said on the stage, if you're not adopting this, get outta the room. Get outta the room. Another important kind of theme here though, was no one company can do this alone, right?
Even J F's, great company, you got a great research team, you got great developers, but the, we're talking about just upending entire Yeah. Ecosystems in, in of blink of an eye almost. And so you need a partners like a ServiceNow and an Nvidia and Sonar and some of the other ones that we've spoken about.
Definitely. How is it working? 'cause now you're not just working as one team, you've gotta work at the pace and in coordination with other engineering teams.
Yeah. How does that affect the pace of what you, you are doing at Jfr? So, first of all, like you said, we are in an ecosystem, but, um, I think we are in an ecosystem of, of platforms today.
Yes, there may be a few platforms in, in each domain, but still it's an ecosystem of lots of platforms that also makes the integration points. Once you figure out the integration points, uh, it, they, they are becoming very natural. So what we find out, first of all, we have great, great partners with us.
You mentioned ServiceNow and GitHub and Sono, but once you found out the logical integration points, it's very easy to get the teams together and, uh, create sort of a v team that works together and, uh, and creates the inter the, the first level of the integration and then carries on to, uh, uh, to polish it. Uh, so it's actually surprisingly, maybe, but works exceptionally well once, uh, ev once you have the clearance of, uh, how things are working together. Now, another thing that you mentioned is the, the impact of, uh, of ai.
So AI already made a huge change in how we code. Yeah. It's completely different now.
Nobody even is surprised by that. Maybe the next surprising thing, but this is also, uh, a reality today, is that you have coding agents living, uh, alongside the, the, the human developers. But I think that's the main gap is around.
So, so coding is kind of solved. It'll change a a lot, I assume also, but, um, it's already, it's already happened. But I think where we still free see friction is around software delivery, because what's happening is that releases are being created in a much faster pace than ever.
So it's a really a nonstop release train that is happening. And you cannot stop to, uh, think about irrelevant problems such as how do I version my release? And what is the compatibility meaning compared to the, to the previous release?
It's just an ongoing flow of, uh, of releases. With frameworks like Appt trusts, you will gate the quality of the release so that you can trust. It doesn't matter if it was an a agent that created the release or, or, or a human, or a combination of both.
You have the gating, you, you have the governance to make sure that your release is, is ready for to de to be deployed in, uh, in production, uh, and to be promoted, uh, across the different, um, um, policy gates. Uh, but at the end of the day, you need a new way to identify your releases. Yeah.
You need a new way to pinpoint them and, and, uh, and scale them up and roll them, roll back and identify issues with existing releases. And this is, uh, part of what's part of the change that we introduced with Fly, with the Gentech release as well. I, I think between Fly and with, with the AI catalog, that's one of the sort of unwritten or underlying thing things, is that versioning is going to change.
Versioning. Yeah. You will need a version because at the end of the day, you need to down.
Yeah. But it doesn't need to be something that you, uh, take note of or remember. Uh, and it cannot be anything.
The trust is still not there to walk in a full semantic way with the releases, but it'll gather it'll Time. I'm sure it take, because trust, trust is a trailing indicator, never a leading indicator. You know what I mean?
You gotta earn it. Trust, you Gotta it. Yeah.
But I think it'll also play out like that because of, uh, of agent to agent communication. Yeah. So the negotiation of what kind of capabilities you have, it cannot be bound to a, to a specific version.
It doesn't make sense anymore. No. It'll be negotiated based on semantic, uh, between agents.
And speaking of that, we actually had, uh, uh, Yanet, Janin on, uh, but the C server, he, he did a lot of great work on that. Yeah. Made sure to tell us.
So very proud of him. Yeah. Jonatan started the MCP server of Jeff Fog as a local MCP server, as a, as a, almost as a pet project.
Yep. Uh, and then we, uh, kind of, uh, upped the game and, and did a fully remote server. Yes.
Which is more, more difficult to do. But, uh, as a company, it allows you, uh, to have better control over security. And also, um, you don't have to request clients to update the, uh, the MC installation on the local machine.
But It's a, it's a, uh, what's the word? A reference. It's an indication.
Uh, a reflection. That's the word I'm looking for. It's a reflection of our times that before January, no one knew we didn't have MPC service.
Here we are, September, MPC, here we are in September. And it is the standard. You must have it, you can't do without it.
Yeah. I think it's, uh, kind of, uh, common thing that we're seeing today that, uh, things are changing on a, on a Right. You know, Today it's radically new Tomorrow it's old hat.
Yeah. Well, MCP has a lot ahead of it. Like, there a lot of proposal of, uh, improving the standard and adding, yeah.
So, uh, stronger authentication and, um, and the iden stronger identity and, and so on. Well, I think there's also the A two A thing, and There's the A two A thing, which are we, we can argue whether the standards are Complementary. Well, the thing about A two A now that's part of Linux, I believe.
Foundation. Yeah. That's some big names behind.
Yeah. And, uh, we'll see, I mean, this is all gonna play out that the, the issue is for people like you and I who've seen this, you know, we've seen these games. We've seen these plays before, never at this velocity.
That that's the key thing. The velocity here. That the time crunch.
Yeah. It's, uh, incredible. The warp.
Yeah. Yeah, yeah. No doubt.
What could we look? So next year in New York? Yeah.
God willing, I'll be there. It's my home. September 1st, We will be there.
What do we, what You want to give us an early preview or too early? I think it's too early. Especially we just, uh, uh, wrapped up saying that, uh, things are changing so quickly actually.
Yeah. So betting on, even betting on next year, uh, is hard. I think you will see, uh, first of all, you, you will see there, there are some things that I can say that, uh, uh, you will definitely see like, uh, a lot of improvements on what we are bringing to market.
Uh, today with APTAs, we have, uh, a few more things, uh, at our sleeve. And also, uh, with fly, uh, I think we will see a more, um, a more intention based way to do DevOps. Yeah.
Almost, uh, ops thing if you want. Yeah. Vibe ops.
Okay. Well, dev vibe ops. 'cause you gotta have the dev in the ops with something in the Middle.
No, but in, in, seriously, it's going to be much more intention Yeah. Faced, uh, with, uh, a higher degree of trust. So I think that, but This is, yeah, I remember when HTML came out, all of a sudden I was a coder.
I was never a coder, but H-T-M-L-I could do then. Yeah. HTML 2 0 3, 0 4 oh CSS JS script, you know, all these things came on.
All of a sudden I wasn't a coder. No war. I think we're gonna see a similar kind of thing.
You'll have, everyone could be a, a developer with vibe coding. Everyone will with AI will develop something if they need, but there will be the tools that the pros use, right? That vibe coating, refined vibe, coating squared, or whatever you want to call it, where it'll be for professional developers.
And, and that's, you know, developers aren't going away. They're not gonna be replaced. They're just gonna be empowered with This.
I, I, I agree with you. I think we will have humans mainly for, uh, just expressing intention and providing, uh, feedback loops. Uh, there's that.
I, I'll tell you what else, and I've written about this. Uhhuh For, You'll Need Humans for the Creative Spark. AI is very good at when you say, I wanna do this, I want you to do this for me, I want you to create that for me.
But it doesn't create the ideas. Of course, The human brain still creates the idea. It's that spark of humanity that I think will always be The human is the guide.
Yeah. The human is the guide. Yeah.
Uh, yeah. But I'm, but the reason I asked you about next year is because I didn't think you would know what's gonna be next year, otherwise why you should retire if you already know what's gonna be next year, retire. But I would like to have you back on in July, maybe next year.
We will talk about Swamp Up September 1st With pleasure. Alright. Yoof, Yoav Laman, CTO Co-founder helping wrap up our day two coverage.
But we're not done. We still have a few more. So stay tuned.
This is Alan Shimmel for Tech Drunk tv. We'll be right back. Thank.
Hey everyone. We're back here. Well, we're not live, unfortunately.
We were live when we recorded this, but you're watching it on recording. Let me introduce you to Demetrius Brinkman. We are here at Swamp Up.
If you couldn't tell 2025 Swamp Up. And we are thrilled to have you tuning into our coverage of this year's Jfr Swamp Up Demetrius, first of all, welcome to Text on tv. It's great to have you on here, Demetrius.
Looking at my notes here. It says, uh, founder of the ML Ops community. Great title.
Talk to our audience a little bit. What, what exactly is it and what do you do there? Yeah, So we're a community of around a hundred thousand developers right now that's primarily focused on bringing AI and ML into production.
That's the main thing, because there's a lot of research, there's a lot of demos that you see out there, but then actually getting use out of it and bringing it into production, that's what we focus on. And we do that in a various, in various ways. One being we've got a Slack workspace.
We'll do in-person events like meetups or workshops or conferences. We do virtual events and like meetups and workshops and conferences. I also have a podcast myself.
We have a newsletter. There's various ways to engage in the community. We'll do like one-on-one matches, curated matches of people in the community.
So in general, we just are trying to keep the education and the understanding of this field as high as possible, because it is moving so fast. It is. Hey, just say you have a podcast isn't enough.
Look into that camera. Tell them where they can get you podcasts. What's the name of It?
Yeah, you can find it on anywhere that you find podcasts. It's called the ML Lops Community podcast. And right now we're on the 314th episode.
Really? Yeah. So we've been How Often do you do 'em?
Twice a week. Really? That's fantastic.
Yeah. Good stuff, man. So you're also keynoting or on stage tomorrow doing a session.
You know, by the time people see this, you probably have already done it. Yeah. So tell 'em what they missed.
Well, by the time you see this, it could have gone horribly or it could have gone wonderfully. Let's hope for, I'm sure it, But really what I'm excited about talking about is the idea of how there's, there's almost two big ideas that I wanna present. One is how the chat interface isn't necessarily the best interface for us to interact with machines.
It's very low bandwidth, and we're used to a much higher bandwidth when we interact with humans. And then the other idea is what I am thinking about how all these companies that are putting agents into production, they all want to be an agent. They don't want to be a tool.
And the way that it could shake out is you have a master agent that goes off and is using tools, but right now it's very fragmented. And this ecosystem that we live in today is, I go and I navigate to one chat bot, and that has agentic capabilities, and it goes off and it does some stuff. Maybe it has access to some tools, but it's not like there's this ecosystem, this homogeneous ecosystem that I know this one chat bot can do anything.
I have to then go, if I want something specific done, navigate to another website and use their agenda capabilities to do something. So a perfect example of this is when I wanted to file a claim for a delayed flight that I had, I was talking with my LLM of choice and saying, you know, can I get money back on this and do, am I in the right to file a claim? And it said, yeah.
And instantly what you want to do is say, okay, go file it. Go file It. That's the user experience that I want.
And, And, and you know what? That, let's call it the dream, if you will. And, and I thought we were getting at least when you talk about travel.
Yeah, right. I thought that was part of the, uh, and I'm not knocking them, don't get me wrong, but that was part of this chat GPT agent, like, Hey, chat, GPT, I gotta fly to Flagstaff, go out, find the best fare and book it for me. Yeah.
I haven't used it yet. I don't know if you have No, I I don't, I don't trust it. 'cause I'd have to go look at the flights myself and make sure that it, I'm not stopping over in Chattanooga or some someplace where, Well, you bring up something fascinating.
There's two pieces of that. One is the trust aspect, and the other is this UX cliff that I've been thinking about where a lot of interactions with machines, we don't necessarily need to type everything out. That's a much slower experience than if we just do two clicks and we get what we want.
Yeah. So there's almost this valley that we need to cross before an agent is even useful. The task has to be quite complex in order for us to do that.
And I think the reason that the flight bookings have captivated our attention is everybody has done that, and it's way more than two clicks. And it's cumbersome. And so when we think about that, we think, wow, it would be nice if I could just say, I want to do it this time, this day, I want to go to this place.
And then it goes and does it. And we don't have to go and click through and do all these multi clicks, which is, and then look back, ah, is this the price I want? I don't know.
And that's not fun. Yeah. But to me, it, it sounds like a pay me now or pay me later kind of situation.
Right. Because how do I set all those up? It, it, I, look, I don't pretend to be a, an AI expert, but like I've gotten to the point now with my ais of choice where it knows me, right?
Yeah. It knows my style and voice. So when I'm writing, it knows what I want out of the tasks, the usual tasks that I ask it to perform.
It would be great if somehow I could train my ai like, Hey, I like to fly out first thing in the morning. Yeah. I like to fly home first thing in the morning.
I will do a direct flight. I don't care if it's twice as much money. And no matter what I want direct, if I could help it, um, you know, all of these little kind of, this is me kind of thing.
Yeah. And I think that's where we struggle. Right.
Well also, if you think about that I'm not the same person today as I am tomorrow. Yeah. And maybe that's, there's certain things that I have hard rules on, and then there's other things that I'm a little bit more flexible on.
And so that as a problem is a very difficult one to crack. Yeah. I also think that, you mentioned something fascinating earlier about the trust, which is we have to be okay if we do have this master agent world that is some kind of a hybrid chat interface.
So it's not only us with words, but maybe there's other kind of UIs that we can take advantage Of. So let's explore that. What do you mean?
Well, I look at different ways that we interact with programs already. And if you take a little inspiration from video folks, you have histograms. Like these guys are used to dealing with histograms for the colors.
So is there a world where we can deal with a histogram like experience for what we want as opposed to trying to really get into the minutiae in the words, because words aren't as easy to develop or as easy to tweak on that very small scale level. And then on the other hand, when we interact with humans, we're interacting at a very high bandwidth. And I'm sure you've been in a meeting where you end up diagramming things to get your point across.
When we are just restricted to text, we can't diagram anything. Yeah. And again, that brings us down in the bandwidth that we're able to convey to that LLM.
So potentially there's some kind of a whiteboard or it you can think of like your, your tablet that you're able to diagram with and it's recording your voice as you're talking to it. That could be a world. But at the end of the day, right now, what we're funneled into is the experience of just chat.
And then you're getting some inkling of when the chat bot will respond to you, it gives you these new UI elements. Right. So sometimes you'll get a scroll, sometimes you'll get a photo, or you'll get a code snippet, some data visualization.
You get that, which is great. And I think that's the first step. But for us as input, we need to up the input levels.
Well, so I'm a little older than you. Yeah. I'm gonna guess.
But, uh, look, I'm a child of Star Trek, right? Yeah. Man, my whole life I wanted to be Scotty and just say hello computer, you know, and, and, and tell it what I want.
But I I, I thought we were getting there. Right? And then I realized in like doing videos like this, right?
So I can't give the video to the AI and, and tell it do it. You gotta transcript it. And you would say, okay, transcripting is easy, and it's word for word.
And even if you, you know, fact, uh, uh, copy, edit the transcript to make sure it is you fact word for word, it's not enough. Because the way humans communicate, we communicate with our eyes, our eyebrows, our hands, nuances, tone in, in speech. Yeah.
Right. And our AI just aren't up to that yet. No.
So, I don't know. I mean, one of the, one of the things that really they say separated humans, let's say from Neanderthal or Danno. So the not, or whatever that uhhuh close relative of the Neanderthal is, is our, our, the, the, the depth of our communication.
Even if we didn't have a huge big difference in vocabulary, all the nuances in human to human communication. And I think that is, that's a job that we need the AI to solve. Yeah.
We don't have that No. Anywhere near that, right? No, no.
And it's, you don't realize how important it is until you just look at a transcript. Yeah. But there also is the whole idea of, I know there's probably people out there that are gonna be thinking, oh, well, voice is trying to tackle that problem.
Voice AI is the next frontier. But I am not sure, have you played around with the voice tools? It's not that they're bad, it's that us in a work setting, what am I gonna do?
Go put myself in a cubicle when I wanna work and speak to my Yeah. Computer. You know, it's funny you brought that up.
So I met a guy I interviewed last week, and I'll give a shout out to him. This guy, Dr. Allen Becker, his PhD is in voice to text.
Text to voice and ai. He started a company, got sold to Snapchat. ai.
Check it out. When we're done for me, you can sign up for a free five instance thing. They've developed avatars.
Yeah. That look at you, that watch you and talk to you hooked into LLM in the backend. And they do try to pick up nuance Yeah.
From your voice and from your gestures. Mm-hmm. It's early.
I played with it. It's, it's freaky. Right?
It really is. It freaked me out, but it, you know, it's not perfect yet. Yeah.
But, um, I am, I'm bullish on, on that happening. Yeah. But you still have this, it's like we're in meetings, right.
And then we have to have a moment where we get work done. Right. And so if the way that we have to get work done is by talking to our, It's still cumbersome.
It is. Like we're in a meeting again. Yeah.
And that's exactly it. And really, whether you're talking to the computer or typing to the computer, their people type really quick. Yeah.
And a lot of people are really not good communicators verbally. That's like me. Exactly.
That There are, I mean, that, that's an issue. That that's definitely, It's a big issue, you Know. But let's, let's look at it from the other side of the coin.
Demetri, you know, the windows mouse clicking kind of interface that is dominant today. Look, this was like 1960s, early seventies out of the, the park. Yeah.
You know, Xerox Park out here, we haven't really, I mean, it's been 50 years. Yeah. And we haven't found a better mouse chap.
It's tied. It is time. You could see that with like the touch screens.
We have these gestures, you know, the pinch to zoom the swipe. Mm-hmm. And the other thing that I think is a big problem with us having to use chat and take what's in our mind and put it into a chat bot is how, right now we're very used to being fed things.
It's almost like a passive experience A lot of the time when we're on the internet. And you can think about Netflix or when you're scrolling on Instagram or TikTok, these are passive experiences that we have become accustomed to. And now chatting is very active.
Right. We have to really define what we're looking for, what we want, and put it into the chat bot. And so we don't have these passive gestures anymore when you're trying to work with chat either, which I find fascinating too.
So is there a way to bring in these passive gestures into the chat experience? Or I guess at a certain point, once it evolves outside of chat so much, we probably won't call it the chat experience, we'll call it just the AI Communication experience. Yeah.
So you're not trying to tell me we gotta get passive aggressive with our ais. Do you? Are we?
No, not that, not on that little, I mean, you might see it, you might see it better. I don't know. I haven't tried.
I'll tell you, one of my biggest things that I've had to teach myself is you don't have to be polite. You're only making it harder on them. Every time you say thank you and please, and all of these things, It's burning energy.
Exactly. I wanna turn a little bit Demetrius and, and talk a little bit about security. Right?
So look, I, I think everyone agrees that we're all gonna have agents, digital workers, whatever you want to call 'em mm-hmm. Who are gonna go off and do these tasks for us, whether it's booking flights, writing code, or, or what have you. And we're going to need either, we're gonna need a crap ton of agents, right?
One, like almost an ephe ephemeral, disposable agent for every task we do. Or some sort of master agent that's able to clone small parts of itself to do specific tasks. Yeah.
No matter how, no matter which way we go, there's security issues. Yeah. How do you view that?
Yeah. There's a few different issues that I'm looking at. And these are like the most basic of the most basic.
If we get some of these DevSecOps people in here, I'm sure they think about it on much different levels, but in a broad strokes way, if we have this world where we have a master agent that helps us go out and it's our gateway into the world, and it can use these tools, and it's a big if, because like I said, everybody wants to be an agent. They don't wanna be a tool because you're giving up your distribution, you're giving up your relationship with your customer. If now Chachi, BT, or Gemini is what chooses to use you or not as a tool, that's a big vulnerability for your company.
So that's a big if right there. But if we do get to that point where I go to my LLM of choice, and then I sink in with the tools that are out there on the internet. So Amazon is a tool.
So buy something from Amazon can be many different types of tools. Uh, look for something on Amazon, whatever, search Amazon. Now, are we okay with the context just flying around the internet?
This data potentially sensitive data is now gonna be going to different tools and going to different LLMs. And I'm not talking on the l are we okay with our data going to the LLM provider, but just data flying around the internet. That's one part that I think about.
All right, well, we need to get the context and we need to have a way to securely do that. It's not necessarily a new problem because we've been transporting data across the internet for a while now, but now it's a little bit different because there's agents that are interacting with each other and maybe one agent thinks this con isn't that personal. But then the other agent, when it summarizes it, it sees that, oh yeah, actually it will say something that is personal and you don't want that.
Right? So you have wild cards in each agent, agent to tool call or subagent, whatever you wanna call it. And then next you have the authentication issues.
So I want my agent to be able to understand everything about me. That means it needs to look at my calendar, it needs to look at my Gmail, it needs to look in all of, everything that I'm privy to. It needs to be privy to in case it needs to act on my behalf.
So you need to off into all these things, but it's not just OAuth because you then get to the next piece, which is the actions. You don't wanna give it permission to take any kind of action. No.
You wanna give it permission to take the action that you said was okay, not anything else. Because if you give it a lot of scope, it can abuse its privileges. So I've been in, I didn't tell you this, I've been in security for 25, 30 years.
You're only describing what I would say are innocent security issues on the agent. That's true. What about when the bad guys say, oh, he's got an agent.
Let me exploit that. Well, did you hear what happened recently? There was I think some output from an LLM that had a nefarious link.
And when the user clicked on that link, it then was able to take control of the system. It happens all the time. And so, yeah, you have, again, you have this wild card in there that the nefarious actors can hijack this agenda.
They're not dumb. They're as smart as we are. They're well funded, well organized, and they, and that, that's the truth.
And if you do end up having everyone as a tool for your master agent, how do you verify that this tool is okay to use? Agreed. It's it, look, here's the good news.
First of all, no one's gonna waste. Everyone's running as fast as they can anyway. And they're gonna keep running as fast as they can.
But as these things, and I, I've seen cycles before, right? We never lead with security. We just don't.
Yeah. We, The Sad thing. But it's true.
It's a sad, but as a security person, you either gotta come to terms with that or, or you know, you're gonna be depressed. Um, we will catch up, we will put the guardrails in, we will come up with processes around it, but people are gonna run as fast as they can. And, and, you know, you can't put your, you can't lay down in front of the tracks and say, stop the train.
Yeah. You get run over. Yeah.
And, and so I always say it's more of a yes we can mm-hmm. Kind of thing, right? Yes, we can.
You wanna run as fast as you want? Yes, you can. We'll figure it out.
Yeah. And I, and I think that if I had to leave us with one thing, that's what I'd leave it. Yes.
We can. We'll figure it out. But man, thanks for the work you do, Demetrius with you community.
It sounds great, man. We appreciate you. Thank you for presenting at Swamp Up and for being here on Tech Drunk tv.
Thanks everybody. Alrighty. We're gonna take a break.
We've got more swamp up coverage coming your way. So check it out. I am sure that you have every one of your passwords memorized and you can recite them at infinitum whenever people ask.
Or is it that you're using a password manager to remember them all for you? Is there a better way to make sure that we're more secure in incorporating things like public private keys and multi-factor authentication? In this episode of the Tech Field Day podcast, pass keys are the future.
Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the enterprise IT industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events. Tech Field Day is a part of the futureum group, and this podcast is also published on our sister company Site Techstrong tv.
In this episode, as we're heading into Security Field day, we will be discussing pass keys and how they make security much easier. Before we do that though, let's have our guests introduce themselves. Hey Tom, thanks.
com, security Boulevard, cloud native, now Techstrong TV tech, strong ai, techron it digital, CXO. I don't know. We're part of the Futurum group, which makes us a sister company with our friends at Tech Field Day.
Tom, thanks. My name is Kate Scar. Uh, I've been a part of cybersecurity for a very, very long time.
I don't have all those exciting things that Alan does. I'm actually coming back from a sabbatical that I took off and, uh, I'm happy to be back. And I'm part of, uh, the CD foundation, the chair of, um, cybersecurity sig, and I'm very much into everything secure.
Awesome. And of course, I'm Tom Hollingsworth, an event lead here at Tech Field Day. Let's jump into the premise for today's episode ahead of Security Field Day.
No doubt that when you woke up this morning, you had to type a password into your device somewhere, whether it was a pin code into your phone or something alphanumeric into your device of choice. And wouldn't it just be better if we could get rid of that? Because I know that I have way too many of those and I'd just like to have less than I need to worry about.
That's the promise of something called a passkey, which is a type of security that will allow you to do, use things that you have and authenticate to that device, as opposed to having to remember the various passwords that I have for everything. I happen to like them, and I know that at least one of our guests does. So the premise for this episode is that passkey are the future.
So Alan, you, you were an outspoken proponent for Passkey. I was wondering if you could tell our audience very quickly, what is it about passkey technology that's better than a password in your mind? Well, you know, Tom, I'll tell you, I didn't type in a pin or a, uh, or a password this morning when I got on my phone, my iPad or my iMac, or even looked at my watch because I do use pass keys.
And so a quick facial scan, a fingerprint on the keyboard, or I am actually full disclosure, a customer of one password. And I use that for PAs keys as well. And, and, uh, I log into, well, I don't wanna give out too much security info because I've been in security game a long time too, but I do use one password PAs keys to log into various applications that I use.
And, um, it makes life easier. You know, there was a time, there was another password manager I used for a number of years that unfortunately was the victim through perhaps no fault of their own, of several data breaches. And as a result of that, I, it finally, I said, I have to move, you know, whether it's their fault or not, my, you know, there's, there's big hash balls of my passwords that are waiting for, uh, quantum computing for someone to crack and take everything I own.
So I, I moved to one password a couple years ago. And, um, the whole, at that time, I remember looking how many passwords I had. And granted, I'm a, I'm a freak.
I'm a tech geek, you know, and I get all that. But if I told you I had over 350 passwords stored in one password, right? 350 passwords, I don't know if people out there, if you have more or less about the same, that's a lot of passwords to remember.
And so if you don't have a password manager, you are reusing passwords. You're not using hard passwords, you're just a, you're an accident waiting to happen. You're the zebra waiting saying, I hope the lion doesn't get me today.
Yeah. And, and Alan, I want you to change those passwords every 90 days. Exactly.
Every quarter. It's, come on, dad. That's crazy that no one's doing.
We all know no one's doing this. We all know. Yeah.
But, and so pass keys to me are a way around this, right? Whether it's biometrics or, or what have you, that it's using. The fact that I don't have to remember 350 passwords that I change every 90 days is a godsend.
Right? This is, you know, I, I can't see why anybody would say no. And, and I agree with you that, that the com that what passkey offer is a combination of a bunch of different things that we've been trying to get people to use over the years, right?
You know, you, you have a password, but you also have some kind of a physical token, in which case a lot of times it's a, a, you know, maybe it's a, a trusted device like a phone or some other kind of token that you hold onto. And that provides that second factor because we still have a lot of people out there who don't use two-factor authentication, or they use the bare minimum, right? Like, oh, I'll just have it text me whenever I, I need to log in.
Or I, which authenticator app am I using again? You know what, I'll just store all of my authentication tokens in the cloud. 'cause those will never get compromised.
Right? Right. Exactly.
Yeah. So I, Kate, I was wondering, maybe you could kind of tell us, you know, your perspective on pass keys as far as, you know, what is the value to an enterprise that maybe is considering, uh, deploying them at, at scale? Because I know for personal use, it's great, but personal use past about three or four people kind of starts to be problematic.
Yeah. Um, well, from a cybersecurity point of view, you're gonna have stronger security, less phishing risk, right? Um, no weak and reused, you know, passwords.
So that's, you know, number two. Number three, just you want the experience to be seamless, and that's what one password would, you know, a password manager should do. It should be seamless.
And so there's just this better user experience, uh, which is very important. And at the end of the day, there is a cost savings here, you know, and operational improvements. Um, so cost savings from the, you know, reduction in a support load, you know, oh, I forgot my password.
I mean, you know, gosh, we've been dealing with that I think for 25 years, right? Um, so that, so having a, a password manager, you know, would help in an overall cost saving savings. And I think we're seeing that with a lot of companies where they're trying to create a frictionless environment.
Like how many times have we gone to log into something recently and, you know, we put in a username or an email and it said, Hey, we just mailed you a magic link to verify that you are who you say you are. And, and that way we don't have to deal with this anymore and just click the box that says this is a trusted device unless it's on a public computer. Uh, is it, what, what's the value that a company gets out of reducing friction with the user base by implementing things like pass keys or magic links?
So from, from my point of view, it is just, um, it's not, cybersecurity's always seen, especially with passwords, has always been a security bump, right? We, we are, we are making something difficult that should be easy. And so what I, what I see is just people adapting more to something that will help in the, in the future that's a, a good for them.
Like, like, this is good for you to do. And so the more seamless that we make this, the more frictionless, the more adoption that people will take. I think there's two things I add to that.
Number one, as, as we've highlighted, we're kidding ourselves. If people, if we think people who have lots of passwords are changing them every 90 days, are not reusing passwords are, are following good password hygiene. And so we're creating, and so if they're not, we're creating risk to our organization.
Secondly, I will tell you the amount of time that I used to spend, and some days unfortunately, I still do hitting the forgot my password, reset my password, use a, a auth from Facebook, LinkedIn, or Facebook, Google, or, or Apple. The amount of time sunk into doing that is, is, is really disgusting to tell you the truth. Another thing though that I like about, you know, using the password manager and pass keys is from an organizational point of view, Tom, let's say I need you to log into an asset, a corporate asset, I'm gonna give you access, right?
But I wanna be able to control that access. Like, you can only come in for today or for the next week. You can't change the password.
Here's, here's the unique token, if you will. Here's the unique username and password I'm giving you to use on this asset for the next week because you're a contractor maybe. And then after that, it doesn't work anymore.
That is such an inherently more powerful tool. It might disposal to help secure my corporate assets, my ip, my, my crown jewels than just saying, oh, let me give you a pass, you know, a password and username or having you go off and create one on your own that I have no control over. And, and again, another reason, that's not a passkey per se, but it, it's another reason why password managers are, are for me, a uh, indispensable, you know, if you're not using them, you're not serious about security.
And I think you're right. And I think while you said that it's not a a pass key necessarily, it's a component of pass keys and, and there's more to the pass key phenomenon that makes it a valuable implementation of modern technology. One of the things that I think that cannot be understated is the fact that most pass keys rely on things like secure enclaves.
Yeah. Which we really haven't had up until just a few years ago. You know, there's a secure enclave on a mobile device or on most, uh, devices now that have a TPM because most devices that we use do have that.
And it's never been an option before because we've never really focused on advanced cryptography and things like that. But like you said, if I create those, those key pairs, and I know that something happens, like, let's just say, Alan, that your, your identity gets leaked or someone is able to, to grab that information, I can invalidate that fairly quickly and ensure that nobody's able to use it to log in anywhere else and make you regenerate that and, and kind of start over. Like that is kind of one of the things that security people have been asking about for years is how can, in the event of a disaster, in the event of a breach, how can I walk things down so that I know that I'm not fighting my attackers while I'm trying to triage the problem?
Yeah. Yep. Or at least limit, right?
And, and you we're gonna freeze it right there. Here's the funny thing. Everyone I know in security, and I've been in security 30 years, everyone knows the passwords is a failed technology for all of the reasons we stated.
And I've met so many entrepreneurs, really bright, smart entrepreneurs who have tackled big problems, who said, I'm tackling this problem. I'm gonna put an end to passwords. And yet it's still the default.
It's still the default. I, I don't know. I mean, we could talk here about pass keys till the, the cows come home.
I don't know what it takes to get people off the password. I, I think what it's gonna take is people who are supporting them, just deprecating them. Like we've seen that with Microsoft, right?
Where they're removing support for passwords in their authenticator app, but they're gonna leave passkey support enabled. And, and we've, we've brought people along in degrees because you know, now it's not just password, it's password and two factor. Like for example, when you join an organization and they want you to log into Slack.
Now, it could be that the default is that you have to create a two-factor authentication, you know, the the infamous print this paper out and just in case you ever get something happens because we want to get people thinking in that method. And the more we do that, you know, to me it's, it's no different than unsecured wifi or, you know, making your password Cisco 1, 2, 3. Like, we, we've gotta get people away from that idea that I can just do something quick about this.
And I, I know it's gonna be hard for a lot of older folks. I'm not throwing shade on anybody, but my father-in-law has his Windows 10 box set to automatically log itself in every time he starts it, because I don't wanna have to type a password in whenever I get up in the morning. Whereas me, I get nervous if there's a computer that's just sitting there not at a login prompt when I'm not sitting in front of it.
But I, that could also be my IBM training kind of leaking through where it's like, you know, an unsecured device is just an opportunity for chaos. Um, do you know, do we think that the, the upcoming generation, gen z gen alpha just kind of assume that passkey and more advanced multifactor authentication are what is the standard? And as more people kind of move on with their technology, they just don't think about it because they, this is all they've ever known.
So I, I do, you know, so I'm the dad of two boys, 26 and 24. And I will tell you that my, my two sons, and I've raised them, you know, their dad was a cyber dude. So they've been raised, uh, in this enriched in this culture.
They all use multifactor when they can and pass keys when they can. They find it much more convenient to just text stuff back and do stuff like that. You know, speaking of my son's, I, I will tell you, when he was in eighth grade, we did a science project where we made up a phishing letter, sent it to his classmates and their parents and his teacher, uh, telling them, you know, that the, the, the class roster got, I don't know, something happened, but you had to go in and change your password.
And we sent them to a lookalike page with a closely resembling URLI got 40% of the class parents to gimme their passwords. We sent them back and said, Hey, this was a science project, literally. And I was working with a company out of, uh, out of Carnegie Mellon password class, password training program.
And they were nice enough to give me the training program for his class and their parents and their teachers. And I went in and taught them little password. But this is, you know, Tom, you know what the most popular password manager in the world is?
Notepad. Mm-hmm. Your father-in-law probably keeps all his passwords in his notepad or notes app or, or something like that.
Or on a sticky note underneath his computer. I, I can neither confirm nor deny for The album here or doc some or anything, but yeah. Yeah.
That, that's the most popular password manager in the world. And until we get past that, we got issues. We do.
And, but the, the good news is, is that the technology has come a long way. Yes. Even in the past five years to allow that kind of thing.
'cause like you said, most of the time, unless your laptop or your, your tablet's been sitting for more than 24 hours, you can just use your face, use your thumbprint, use some kind of biometrics to, to be able to get into it. I don't, I, I imagine coming soon that a lot of this is just going to be pass, you know, it's gonna be seamless pass through security. Oh, well, we can identify who you are based on these things and you know, you're good.
And, and we've even seen crazy like, you know, future tech stuff, like if anybody's seen, uh, mission Impossible, uh, was it Rogue Nation where it's like gate analysis. Like we, we can verify that you're not trying to impersonate somebody that's a little bit further down the road, but I promise you that whatever that gate hash value is is gonna be stored in a secure enclave and the guards are probably gonna have to log into that workstation with cost. You know, I, I, I remember a, a company out of MIT biometrically that they would, you know, everyone types uniquely, like you write, you type top TOM, you have a, a certain cadence that you use when you type that and, and they were able to, to see if it's really you by just the way you type your name and, and so, but, but here's the, here's the rub.
We've had technology for this for a long time. It's 2025. We're going to 2026.
Our percentage of users are using passkey or biometrics. Right? So Kate, I think Alan brings up some really good points.
We've had all these technologies that exist for a long time. I mean, if you really wanna get down to it, the, the, the heart of a passkey is really just a public, private key pair. You know, Alice is sending Bob more email like we've always done.
What is it about pass keys that makes it more, I don't know, consumable for people? What, why do you think that now is the time that we've finally gotten momentum to get people off of it? I think you're seeing the technology as, as Alan spoke about, it's actually, it's easier.
We've come a long way. I mean, it wasn't this easy, I don't know, maybe even two years. It's, it has changed a lot in two years.
So that is, I, I think ease of use will always be the key. Um, sort of say this, um, I think that's the, the biggest deal. I think, um, when, when we don't see cybersecurity as a roadblock, when we see that we're able to do something without it costing us a headache, a time, um, trying to figure things out and, and the old way and more time consuming more of a, you know, more of this, you know, I have to, I forgot my password to, I don't know, Instagram, and you get all the back and forth.
That's a headache. You know, that becomes a pain. So I think as, as we see the, this other new technology that is seamless, I, I love that word.
Frictionless is another word I love. Um, I think it will be more adopted by us and, and by companies as well. Kate, I think you're absolutely right.
The real value in passwords for the longest time has been the fact that we have spent so much time getting them as frictionless as possible. Yeah. You know, there's, the eight characters are more special character capital letter that has increased the friction that we've had, but it's just forced people to become more familiar with ways to make themselves more secure without realizing it.
And pass keys, take it one step further by building in all of the good password hygiene and good security hygiene that we've been trying to teach people for years. You know, un passwords that you don't even know or multifactor authentication. And in doing so, we've moved people to the point where the friction is as reduced as possible for the things that they need to use.
And that means that people are more willing to adopt these new ideas. If, if you remember how hard it is to get people to develop multifactor authentication, if you just tell them, you know, click on your phone and authenticate this, or if you've ever had them use some kind of a, an online payment system where they can use their, uh, you know, smartwatch or smartphone to authenticate a credit card transaction. They see the value in what it provides, and that is why passkey have a very bright future.
I wanna thank everyone for joining us for this episode of the Tech Field Day podcast. If you enjoyed this discussion, please make sure that you subscribe on our YouTube channel or in your favorite podcast application so you don't miss any of our episodes. We'd love it if you'd give us a rating and a review because that really does help people find this content and lets them know what we're all about here.
This podcast is brought to you by Tech Field Day, which is the home for IT experts from across the enterprise. Tech Field Day is a part of the Future Room group. com/podcast or check us out on Techstrong TV and the Techstrong TV app.
Thank you very much for listening in. We'll see you next week.