DOGE Security Breach, RSAC AI and Security, IT Unemployment – SB Chats EP11
Mitch and Alan discuss plans for the free RSAC AI and AppSec event (4/28) with leaders from OpenAI, Anthropic, AWS, Google, and Meta, the increase in IT unemployment, and if Musk’s DOGE is the largest security breach of our government.
Transcript
Hi everybody, this is Mitch Ashley. And I'm Alan Shimel. And you're listening to Security Boulevard Out on the Boulevard.
Yeah. Baby Chat's on the Boulevard. Yep.
Welcome, welcome. Good to be talking security with you, Alan. Absolutely, Mitch.
It's been too long. You know, whenever I say out on the Boulevard, I always get mixed up between a Bruce Springs thing song and The Kinks. And the Kinks, and then, uh, spell your heroes.
What about broke out on the blah blah? You know, maybe that's what it is. Sheryl Crow, you know, I saw her on, was it the Grammy's or another show?
She looks great. She's still man. Yeah.
She's still making great music and performing. Yeah. I gotta be honest, I'll make a confession.
I always had sort of a crush on Sheryl Crow. Well, we didn't, you know. Oh, okay.
Why everyone did. I thought it was just me. No, I, I checked online.
Everybody does March. All just saying. Alright.
I can see we, we made the right at the fork. I guess we should have taken the left fork. Yeah.
Boy, that's a different podcast. That's not just, yeah. But it's good to be back on Security Boulevard and, and you know, hopefully we'll get back into things here on a more regular cadence.
Yeah. Because there's so much, so much as usual going on in the world of cyber. Um, you know, we're coming back into, uh, conference season and we've already announced our RSA lineup, an RSA event for this year where we'll be doing AI and cybersecurity on a, and its influence on, or its effect on app dev.
That's Monday of RSA week. So very excited with that. Well, hey, I wanna, I wanna put a plug in for that too.
'cause the speakers at this thing, I mean, I thought last year was great, but I mean, you're talking about, you know, the, uh, CSO from Anthropic and from, um, open ai, open ai, you know, um, and Llama or Meta Lama Meta AWS would be there. Yes. Well, we have, we have a, it's a leader from AWS, she lives down here in Miami, actually, who's written all kinds of books and spoken to Ted's and mm-hmm.
I mean, she's a rockstar, rockstar, rockstar. com, you can get all of the speakers. You know, Mitch, I think you're gonna do the panel there this year, right?
Yeah. I'm doing the panel and I'm excited because we're working on what the topic will be working with the panelists on that. But, you know, I think it, I always like to take kind of a, so what does this mean approach and how do we, what is it, what do we have to do to prepare organizations or how do we adopt this?
Or where are we and what are the challenges we're running into? Um, so trying to bring some, okay, I wanna take something away in that respect as well as listening to, you know, these, these other thought leaders on this. So it, it, it's gonna be a fantastic event and it's free if you're registered for RSAC, you're invited, you know, come join the party.
Right. Even if you just have an expo. Only as a matter of fact, even if you don't, we will be publishing a code for a free expo only pass that'll get you into our show Monday, as well as the expo during the week.
And, you know, if you've never been to RSA, it, I, there's usually you're only one or 40 or 45,000 people that'll be there if you're, if you, if you're even mildly interested in cybersecurity, I, I highly, highly recommend it'll put a link, put a link in the descriptions folks can go and pre-register to get Absolutely. Very cool. Um, but Mitch, let, let's turn out, you know, gaze to cybersecurity.
We were talking earlier in DevOps Unbound that overall IT job growth, or at least unemployment has gone up as of the end of the review again at the end of 2024. First time in a long time that we've seen unemployment tick up for it in, in, you know, recent memory. Oh, forever.
I don't remember. I mean, other than maybe 2008 kind of time, you know, where it might have, I don't even know if that it necessarily took to head. I don't remember.
I'd have to go check the memory. Yeah. 7%.
Uh, but at the same time, the projection of security people that we need, the resources in the town that we need for security is like still climbing through the roof. You know, it's not going down. I mean, employment needs are still there.
And you could say, well, why is that? I mean, yes, we have more attacks and more security, more things to secure. Lots of good reasons.
Some people point to AI and how we're gonna secure AI and all the new skills that we're gonna need for that as well. So we've kind of piled onto what already was a, we can't hire enough good folks in security to now we need that skill on top of it. You know, I thought about that a little bit, Mitch and I, I mean, look, when we look at AI and security, there's kind of two aspects to two sides of the coin.
One, I call AI as friend one, I call AI as fo, right? Mm-hmm. From the friend point of, and I don't mean the Vietnamese noodle soup, um, from the friend, let's fry.
So easy for us to get distracted, right? Guys. It is squirrel.
So from the friend point of view, harnessing AI to make our security more effective is giving a shot of innovation into the whole AI ecosystem. How do we use AI to better spot intrusions, to better respond to security incidents, to, you know, to do things faster with greater efficiency. Right?
And that in itself is game changing. Mm-hmm. Mm-hmm.
Of course, the other side, you know, Dr. Jekyll, Mr. Hyde, the other side of it is the bad guys use it too, and they're doing some new amazing things, right?
You know, the thinkings and the text. This, this, the, what do they call text message spam? Uh, yeah, I don't know what it's called.
I get this phishing, uh, smishing smishing. SMSI, you know, I got, I was getting some last week from, you know, purporting to be like, uh, easy pass and sun, like the, the tall companies. Yeah.
I just got one of those that I, you know, that, uh, I was gonna get penalties if I didn't click here and pay. You gotta look at the URLs real close to see that they're, you know, both big URLs. Um, you know, so I think it just what we need make make security harder, but that's the, that's the reality of it and bigger.
Yeah. It, yeah. Um, it's interesting, you know, I I I've said before, sorry, don't, you know, don't mean to defend anybody, but security is languished in terms of real innovation.
I think. I mean, it's, there's so much of what we do now is a variation of an evolution of what you and I did, you know, 20, 25 years ago. And, uh, you know, blockchain, as innovative as it was, and as much of it was gonna change everything Yeah.
Changed some things for crypto and a few other applications, but it didn't change. You know, that wasn't the magic silver bullet to, uh, solving our security problems by any stretch. And so the, the real innovation, I think happens on the attacker side.
They're the first early adopters. They're adopting AI first to attack us with it. And, you know, we're, I think we're slow to respond and how we use AI to our advantage in not only defense, but in response.
And I'm not saying we aren't working on it, but dang it, folks, let's, let's get on the front end of this curve and get aggressive about solving some of these challenges. And let's, let's really innovate. Let's out innovate the, the attackers instead of just responding to attackers.
That's my position. You know, Mitchell, we've spent so much money on prevention and in, you know, keep, if you're a stranger, what you can get in and out of our systems. To me, the, the, the Achilles heel still, uh, and the root of all evil or 80% of our security issues are, are stolen credentials.
Mm-hmm. Most people don't brute force their way in. They get in because they already have the credentials, the username and passwords.
Right. I think whether, you know, is that how ransomware is delivered? Someone clicks on a bad link or it somehow gives up their credentials.
So whether it's ransomware or, or, uh, feels low and slow sort of attacks or, or what have you, it's still that weakest link in the chain. And even though two factor authentication and, and biometrics and, you know, all of these things we've tried to put in place that strengthen that user credential sign, a single sign on zero off, it's still the, the weakest link in the chain it seems. Well, it's, you know, it's attackers are like water damage.
It'll find whatever the easiest way to get in and, you know, fill your basement or the, the one place that in your car window where the, where, where the lining isn't quite matching the window and it'll find its way in. Um, and it's not that it's finding the rare exceptions. It's finding the easiest place to get in.
Well, what's the easiest place his people and credentials and things like that. And, you know, it's been true. It's still true.
And, you know, we used passwords for how long? Well, at least did they, at least they aren't, you know, telling that unencrypted, you know, text going across the wire, but oh, we, right, we went through that stage. We did.
Yeah. Do you still allow, you know, I tell that on your network. Yeah.
Um, but it, it certainly is. And I think, you know, if you think about, okay, well if that's still the, the people, the human element is still, I don't wanna say the weakest point, but the easiest entry point. Um, at the same time, what we have access to as individuals is infinitely expanded, right?
Think of everything that available on our cell phone or on our laptop. We use A VPN now to get in, right? We use VPN technology embedded within applications and networking, but still the things that are located on our laptops and cell phones.
And now you don't have to get to the directory to have, you know, the golden credentials for everything. It might be sitting here in a Excel file on your laptop. So it, it's, the things you can get to are so much greater as an attacker, uh, rather than, I need just, I've got to get to that one server that's gonna let me escalate upwards instead of, you know, horizontally co laterally.
Agreed. Um, I, Mitch, I, I, you know, I, I get so, so you're, you're that, you got that Midwestern calm thing. I get so frustrated by the whole thing, because to me, this is something we, we should, we should have licked already.
Oh, I, we have the means to lick it, but we just don't seem to be able to do it. Um, I'm sorry. The, the other thing, Mitch, I wanted to talk about in the same vein, right, for many of us, the whole software supply chain security issue mm-hmm.
Sort of started with the SolarWinds attack. Mm-hmm. Yeah.
That was it. At least visibly to the broader market. That was true.
And it had happened before that. But, you know, so much has paid attention of, of bad software getting pushed out to customers. Well, the Yes, that happened, that was the end result.
The, the real attack was into the software build process and attackers getting in that through developer credentials and then hiding themselves sufficiently so that when a build kicked off, they would kick off their, their code to insert, uh, you know, air code into the build. Um, unless, you know, something was snooping around, might get their attention, then they would go back and acquiesce for a while. Oh.
Pretty sophisticated stuff. But that's what got into this. Like, that's what got into the water supply that eventually poisoned, you know, the downstream and, and nothing's been the same.
Right. But here's an interesting story. 4 billion.
And, uh, taking it private with the idea of, I don't know, loading debt on as, as PE like to do, right? Because they finance these deals on debt, right? I mean they, right.
And then shedding costs and then, I don't know, maybe some m and a activity and then maybe, maybe taking it back public again. Um, and here's an interesting fact to it. The price of SolarWinds today, the day we recorded this is about the same price it was when it first went public, I think in 2018.
So before the, before the, uh, incident, the security issue. Mm-hmm. So it went public in 2018.
It went up, it went down, it went below that, 2018 came back up and it's right where it was then. And now some PE companies gonna buy it. But you know the story with PE companies, Mitch, right?
They break some eggs to make those omelets. You don't know if SolarWinds is going to survive. Will it ever be public again?
Maybe, you know, what are the odds of it being public versus the odds of it being dismembered or sold off piecemeal to some other company? I don't know. Um, or combined with other companies, I hesitate to make this comparison 'cause it's not, you know, truly faithful, but you think about what Musk's approaches of buying a company and getting there and ripping it apart and finding out what's in it and getting rid of a bunch of stuff.
Maybe that's to an extreme of how he does it, but maybe not. That's a lot of what PE firms do of here's what it looks from the outside and from as much as you can learn from due diligence, now you get inside and you can say, well, here's economy so we can make, here's wasteful spending, quote unquote, and what we don't think we need to be spending on and personnel changes and, you know, synergies, you know, all that kind of thing. It, what comes out doesn't, isn't what started when it came in.
It isn't just to make it bigger and better. It's to make it profitable and sometimes profitable selling off parts of it. Sometimes it's emerging as, you know, whatever the next generation of the company's gonna be, but it usually looks pretty different than where it started.
There's a reason why they got bought by a pe PE firm right now because they're doing fantastically and don't eat other people's money. It's, uh, stock price, things like that. Sure.
I, I mean, you know, what's something worth? Well, whatever, someone will pay for it. So they, this PE firm obviously thinks at that price.
4 billion is gonna be financed mm-hmm. And debt added to the balance sheet. Mm-hmm.
Right. It may be that, you know, very little real money, you know, not that it's not real money, very little, you know, new money's being put into it, you don't know. Or it might be a little dead, I don't know.
Yeah. But it'll be interesting to see. And you know, you mentioned Musk is, is this gonna be a model we see with security companies, um, where, uh, people go into these so-called zombie companies that really, you know, are living off of VC or PE money and, and you gotta, you know, do an Elon Musk on, I mean, you cut 75, 80% of the people run, run the systems on a shoes string and try to get cash flow positive as quickly and, and as positively as you can.
Mm-hmm. Um, you know, Mitch, another friend of ours, Sam mm-hmm. Wrote me this week and the company he was working at had a 10% layoff.
And, um, it was interesting that he po he pointed me to a looking glass. Is that the page where you go write about employees, employees get to write about next door? Probably you're talking about Yeah, Glassdoor, I knew it was something with glass in it.
Um, oh, Glassdoor. I don't remember what it's, I don't look at it, but yeah. But, um, you know, some interesting things on there about it.
You know, again, same kind of story. And I, I wonder if this is gonna be something we see again and again and again, uh, in, in the, in the marketplace. I mean, there's a lot of security companies out there, and I don't know how many of them are still innovating, still viable.
And I'm not saying that, uh, SolarWinds is not, or any of these companies, it falls into that category. Yeah. I'm just saying that this is, this could be a t trend we see happening in security, right.
Uh, because the right, wrong, indifferent or not, I think we're in a very turbulent time of change and there'll be winners and losers. Like there always is, I read, read an article and I don't remember where it was from, but talking about the deal market changing substantially, um, and how fewer deals that we're seeing m and a, you know, whether it's PE or IPO, that kind of thing, acquisitions, um, primarily because, you know, sort of the dust is starting to settle and people are saying, well, what's this gonna mean whether it's tariffs or these cuts or whatever it is that's happening in, in a new administration and, you know, in, in, in uncertain times. Right.
That's when money gets tight just because of uncertainty, right? Well, absolutely. And that's always been true.
Uncertainty is the worst because you don't know whether to spend or cut and so you tend to get paralysis by analysis. Exactly. And the stock go down and, you know, all kinds and, you know, not so fun things.
So it, it, it, it will be some turbulent times. There'll be a growth phase too, you know, we will come out of at some point as well. So, agreed.
Mitch, one more thing before we wrap up. I did wanna mention, you know, you are of course rum, VP analyst, DevOps and DevSecOps. Urs recently announced the, uh, hiring, uh, joining of the firm by Fernando Montenegro.
Montenegro. Mm-hmm. Who I actually have known a long time.
As it turns out I didn't put all the pieces together and um, Fernando might be joining us on the Boulevard. Yeah. There were some discussions about, um, where we might take the Boulevard next.
And uh, Krista case is also working in security Yeah. At Futur. And between the three of us, you know, we cover, let's say the broad spectrum of, of security, data security and protection, privacy, and of course software supply chain DevSecOps.
And the nice thing is, um, you know, you and I have noted it, you know, which year was it at RSA two or three years ago when suddenly we're talking about software security, you know, when we've been, been expecting to do that and now that is much more commonplace. So when you think about security, you've got now add AI to that as well. So we'll see.
Absolutely. Uh, I you, we'll, we'll, and make some announcements as we further those conversations about what we might do here on this podcast, but um, I'm excited about working with both. Oh, absolutely.
So Mike, both the other folks at the future and good stuff. Alright, Mitch, that's all I've got. Me too.
Well hang in there and we'll talk, talk about deep seek next time or we save that for another one. Yeah. Now there might be some other Chinese, you know, nuclear fusion plants they're building.
I heard fusion plants. Exactly. We'll see what, until that, Mitch, let's wrap up.
Alright, you wrap it up. Go ahead. Well, you know, signing off, this is Mitch Ashley and, and Alan Shovel, and you've been listening to Security on the Boulevard Security shots, baby Security Boulevard shots.
There you go. Bye-bye. Take care everybody.