How AI Changes Security and the Tackling Security Debt – Security Boulevard Chats EP14
Mitch and Alan delve into AI’s profound impact on cybersecurity and the dual-edged nature it presents for attackers and security professionals. The conversation takes a deeper dive into the murky waters of deep fakes and AI-generated misinformation.
Transcript
Hey everybody, this is Mitch Ashley And Alan Shimel, And you're listening to Security Boulevard Chat. Yeah, baby. All right, Mitchell.
Now it seems like a well-oiled machine. We're getting this down, you know? Yeah, man.
Can learn new tricks. Yeah. Well, I think it's old dogs just relearning old tricks.
Oh, that's true. Remembering tricks, You know, but it's like the land of 51st dates every, you know, it's like every day's a new day is A new day. Groundhog Day.
Yep. We learned it again. Anyway.
So Mitch, uh, you know, as usual, a busy week in security, the, we've got our, our requisite reaches happening, uh, in the tech world. Our requisite security companies either doing layoffs, a lot of good friends at Cisco. Mm-Hmm.
A lot of talented folks at Cisco got laid off. Uh, in the last week. Um, some of the public companies have, have lowered their, uh, their guidance in terms of revenue.
Mm-Hmm. Um, uh, that's a tough time. But, you know, there's also excitement building with RSA this year, just a few months out, uh, for those who don't know, you know, at our annual DevSecOps event at RSA seminar, I think is the official word, it's an all day event within RSA at Moscone Center, and it's on the Monday of RSA week, which is year's Monday, May 6th.
We're gonna be focusing in on, you know, DevSecOps in the, in the world of generative ai. Mm-Hmm. And, and we've got some amazing speakers, right.
David Bran, uh, account acclaim, you know, multiple Yugo Nebula Award-winning Sci-Fi author, PHD nasa, JPL fellow there, uh, also one of the, you know, preeminent futurists for the last 30, 35 years in the world. Mm-Hmm. Um, then we have, you know, CSOs and security, senior security people from OpenAI DeepMind, Google Meta Anthropic more.
And, and of course you have a panel going on, but I think, you know, what we may lose sight of in the bright lights of all that is the very real question of inherently, what's the relationship between security and AI here? Mm-Hmm. I think we're right.
Is it, is it it a help? Yeah. Is it a help?
Is it a fo Is it both? Is it, is it everything to everyone all at once? I don't know.
What, what do you think, Mitch? I, It seems like there's sort of two or three different threads. One is attackers and what they're gonna do with ai, how does that aid them?
And as our, and then the response is, what in AI can help us before that or prevent that as well as other general security attacks. I think the second thread is, um, automation, right? How, what can we do to help improve the soc?
What can we do to help improve in incident response, whether it's information that can be surfaced through generative AI or machine learning and other things in AI that might help us with, we've got all this data, all this traffic, all these attacks. You know, what can we learn from all of that? And then I think the third, third one is sort of that biggest unknown is like, well, what aren't we thinking of that I, uh, might be able to help us with that we're sort of, you know, current paradigms.
Don't, don't set us up to think initially about that, that are really innovative and kind of move the ball forward. 'cause I mean, you, you've heard me say before, security is kind of a funny thing, that there's, we're still doing the stuff you and I did 23, 4, 5 years ago. Those things are still there and that the, the pace of innovation has, has happened, but we, I don't know, my sense is always like, we could be doing a lot more.
How do we help that get, get done faster? Yeah. Maybe AI is part of helping that accelerate.
I, I think it will be, and it should be. You know, I, I'm a binary kind of person. I dunno if that really, Are you a binary star?
Yeah. Or non-binary. I, I forget the whole, I always get confused.
But anyway, um, the way I look at it, Mitch, is I look at AI through two lens. One is, how can I use AI to help me get, you know, make better security? Mm-Hmm.
For lack of a better phrase. Yeah. To make the security better.
Right? AI is a tool I could use and there are some obvious applications of it that will allow me to do more, faster, better, cheaper, more efficiently. Mm-Hmm mm-Hmm.
The evil twin of that is, what do I need to do to secure against ai? So AI in the wrong hands, or AI pointed in the wrong direction. Mm-Hmm.
Right. And, and what, you know, that's part of my job. Now, if I'm a security person, that's part of my job.
How do I defend against AI generated attacks or AI aided attacks, enhanced attacks? And that's really scary because you know what? These bad guys have just as good if not better in imagination than the good guys do.
And many times they have just as big a infrastructure and, you know, resources. They're also more Directly financially motivated. Right.
Yeah. Than maybe day-to-day security engineer who's doing this for, you know, their passion or their belief in security. Yeah.
I, I agree. I mean, they're incentivized. The more they do, the more they make.
Um, so when I, when I look at ai, it's, you know, unfortunately, I think the answer is AI's gonna do a little or a lot of both of those things. Mm-Hmm. But I'd like it to do more to help than to hurt.
Mm-Hmm. Um, I, I think, I think eventually it certainly will, but there's gonna be, there's gonna be some AI and aided attacks. Excuse me.
I think we already see it with phishing. Absolutely. Right.
The level of phishing has gotten much better. I look forward to see what software and services I paid for every day when I get these emails for the receipt, you know, for Norton or for or, or any other of these kind of things. Uh, the, the, uh, the Best Buy Geek Squads and, you know, I get at least one or two of those a day.
And where they used to be just, they were so bad, they were funny. Now it takes me time. I go and I look at who the email is from really, you know, I look in the header to see the email, just to make sure it's really not from who it purport to be.
Mm-Hmm. Usually PayPal or something. Um, so I look, and I think unfortunately we're, we're at, we're a lot closer to the beginning of this.
Oh, yeah. Uh, dilemma or maybe not dilemma to the beginning of this era than we are to the end of it. Yeah.
I keep thinking there's low hanging fruit things that we can do. Like, you know, one of those, I have, I have the, this bugs me list, you know, it's not very long, but a few things that I see, like, so if on a webpage it can validate your email address, that it's a valid email address as you're typing it before you submit the form and all that kind of stuff, why can't you email client validate the links in the emails that you're seeing so that they're really going to the best Buy side? And they're not some wonky thing that seems like pretty low hanging fruit.
That'd be, should be a great, uh, application of ai. Maybe you don't even need AI to do that. But there are those kind of things.
I think to your point about being at the beginning of this, uh, I think we're, we're already seeing, but we're really heading into this big area of questioning everything. Right? Is that a deep fake, is that a, not just an email, but is that a deep fake video?
Is that a call? Mm-Hmm. Alan voice message is, you know, is a text.
All of this stuff. I, I think it's gonna teach us to question everything. The problem is, will it also teach us not to trust anything?
Are we gonna end up in this era, this era where we don't believe anything? 'cause we just have no way of validating it? And that, that I think is one of the, the kind of bigger dangers about security and ai thinking about security engineers.
How do I know why I'm reacting on the right information? Right. I could, Yeah.
No, I, I, I agree. Look, this is, I think, a society wide problem. And I think a lot of people, they look at the, the stuff that passes itself off as news today.
You know, I think there's some element of people who just believe it because it reinforces their worldview. Yep. Yep.
But I think there's a bigger group of people who don't believe anything because they think it's all nonsense. And that reinforces their worldview too, I guess. And then there's probably a small, small minority who say, you know, I'm gonna validate it before I believe it or not.
And, and they dig in a little bit, but most people aren't doing that. And, and it's, I think, a big problem in the world. Think it's tough to ask everybody to do that.
Not everybody is inclined to a take the time, more or less kinda really dig into it. Say, eh, maybe I don't want to do that. Agree.
Excuse me, Mitch. Um, agreed. I wanted to bring up another topic today, though.
You know, we're gonna be doing a, uh, video interview today on Security Boulevard Chat. And this is, I think it's the first time, well, since we relaunched this year, the, the podcast where we have a guest on. And, and, and look, I'm not fooling anyone.
It's not a live guest that we had joining Mitchell and I when we made this. It's actually, uh, an interview I did with Chris Ang from Veracode this, uh, past week for, uh, text Drunk tv. And Mitch, you know, Chris, we, we know Chris Ang Long time.
20 something years, man. Yeah. You know, Chris was, well, Chris is the VP of Threat research, but he's been at Veracode through all of its incarnations.
I think he might've been in that state guy even before Veracode. But, you know, at Stake, if you remember, was acquired by Symantec, and then they kinda spun out, or, or the, Chris has left there with some other folks. It was a long time ago for sure.
Chris Darby was the CEO there. And of course, Chris has gone on to amazing things. Um, anyway, I had a chance to catch up with Chris.
You know, every year Veracode does their state of software security, SOSS, and what they do is, it's not a survey, it's not interviewing, but they take all of the data that they see or pass through anonymized, obviously, to protect the innocent. And they, and they, they draw trends out of it, and they don't even do it. Here's an interesting thing I was reminded of.
In talking to Chris. They actually deploy, uh, a data scientist firm, I wanna say er or something like that. Chris mentions the name in the interview.
Um, this is a data science firm that specializes in cyber Mm-Hmm. And so they're the ones who are really kind of crunching the numbers and, and coming up with the trends that make their way onto the front pages of this report. Uh, this year's report, like the biggest thing that they saw was security debt.
Mm-Hmm mm-Hmm. And, you know, and I was, I spoke about this with Chris, it's, it's actually ironic that I was the one interviewing him with this, because, you know, so much of in the early DevOps days was about technical debt, Technical debts, all we, How much? Yeah.
Yeah. I mean, how much technical debt do most organizations who've been doing Waterfall or have been kicking the can down the road accumulated to the point where it was suffocating them, but it was so suffocating that they really almost didn't have an out Mm-Hmm. Without really biting the bullet with some catastrophic potential.
Um, and I guess I just never thought about it until Chris and the this report came out. But it's the same thing with regard to security. It is a monster of a thing.
And there's also maybe a connection, I'm, I'm curious to see in this interview, when we watch it of some of that security debt comes from software debt application debt, right? You're not updating this software. It's not, you know, not able to keep pace with change and updating open source, you know, vulnerabilities.
It might be in your own software applications and stuff that also contributes to that security debt as well as the workload and the backlog of security work that creates that debt. Yep. Agreed.
Agreed. Agreed. Anyway, you know, Veracode in, in the state of software security has taken, security debt is the star of this year's s uh, report.
And, and they've drawn out some really good data there that gives you some really good insight. So, if it's okay, let's, let's run this video of the interview with Chris, and we'll be right back. Hi everyone.
Welcome back here to Text Drunk tv. Um, I'm happy to have a good friend of mine back with us, uh, here to discuss the latest research from our friends at Veracode. He's Chris Ang.
Chris is the Chief Research Officer at Veracode, and has been for a long time. I, I know Chris probably longer than either of us want to admit. Uh, Chris, welcome, welcome back.
How are you, my friend? I'm doing great. Thanks for having me.
Good. It's good to have you here. Um, so Chris, I, look, I think most of our audience is very familiar with Veracode.
They're one of the pioneers in the AppSec market. And you know, and I, as I mentioned, you and I know each other back, I think from the at stake days through all the various iterations of Veracode and Yeah. Corporate overlords and all that good stuff.
But in, in, in case, I don't know, maybe someone out here is new or they don't know Veracode, why don't you, how would you describe Veracode to them? Yeah, we're, we're a software security company and we're trying to, I mean, we help our customers with software security at every stage of the lifecycle. So everything from like the educational aspect for the developer through fixing, uh, detecting and fixing issues as you're coding to doing static dynamic and software composition scanning as you're getting rage, deploy, uh, penetration testing after that.
So everything you can think of sort of in the, in the SDLC, you know, we've always talked about integrating security at every stage, right? And so we're all about doing that in an automated way at scale. Um, and it's, and it's taken a long time to get there, but it's, uh, I think the industry is realizing that you can't just, you know, you can't just think about this later.
You've gotta integrate it at, at every possible stage. I get it. Absolutely.
And, and, and of course you're being very modest, but you know, Veracode is not just a software security company. You guys have really, uh, help set the trail, if you will, or cleared the trail or made the trail, especially around application security, AppSec and, and stuff like that. Um, and is going back, I guess, is Veracode been around 20 years?
Is that fair, Chris, around that? Not Quite, but we're getting pretty close. It was, it was 2006.
Yeah, it's gotta be. Yeah. Yeah.
Okay. And yeah, I was Gonna say 2005, something like that. It was The whole, yeah, the whole motivation, you know, for me coming over was like, I was sitting there doing pen, uh, penetration tests for customers one off, you know, two weeks at a time.
And, you know, that just doesn't scale. Uh, and so when you start thinking about what does scale, how do you take, you know, the increasing amount of software that's being written by every company out there and, and scale that into a real program with process and tooling around it, where you can, you know, test your software and, and make security testing, you know, as ingrained as quality testing or, or, or all the other things that you have to do to produce software. The only way to do that was to bring automation to it.
And, uh, and, and the, the thing for us in 2006 was like, well, let's put it in the cloud. Um, we didn't have that word yet, but, um, yeah. You know, let's, let's put it in the cloud and, and get out of this, this mentality where you, you've gotta give people this, you know, the, the software to install and maintain and have computers for, and let's just, you know, let them upload stuff and we'll, we'll handle that part of it.
And, and that was what's really allowed a lot of big programs to scale over the years. And then we get a lot of great data out of that, which is kind of, you know, how we ended up writing this, this report. You're right.
The, by the byproduct of which is the state of software security report every year, right? Right. You see, but you can, a lot of that data, You see what's happening, right?
Across different industries, different languages. Um, are things getting better or worse? Where are the concentrations of, of, you know, bad news and good news?
And, um, you know, first 2010, we, we thought like, well, let's, let's put something out there for the industry. The report had a, a data set of 1500 applications, which was, we were like, wow, 1500 applications. Like, that's huge.
Uh, this year's report has a million. Yeah. So just a little bit different, a little bit bit more scale.
And you can learn so much by just like, number crunching that data and, you know, starting to, to, to ask some probing questions of like, what's happening out there. Of course, we do that hand in hand with, with, uh, our friends over at Entea who have the, you know, the data science, security data science background to be, to be able to really, um, to dig into some of the complicated things that we wanna do. So it's, it's been a really cool journey, um, getting, getting to do this every year and, and having, like I said, an increasing amount of like, really rich application security data every year.
No doubt about it. com, they could download That's right. A report, Right?
com/s oss, which stands for State of Software Security. I mean, you can get there from the front page also, but Yeah, they can read it. Um, yeah, we released it actually, um, just a few days ago.
Fantastic. Fresh off the prices. Alright, So Chris, let, let's start with, you know, what are the big, what are the big insights from this year's report?
So this year what we chose to focus on was security debt. Um, and you're hearing a lot about security debt lately, I think in, in, in conversations, just in terms of what's piling up, you know, and how difficult is it to kind of get on top of that, um, security debt as a concept? I think I, I always like to compare it to, to credit card debt or, or any sort of financial debt, right?
Where, um, if you accrue it and you don't pay it down, uh, it gets more expensive to fix later, right? You, you know, in, in finance world is interest in, in, in software world, it's, is sort of the complexity of software and the, you know, crusty old code and things like that. Um, and technically I think, you know, anything that you, any flaw, um, or vulnerability that you know about in your software that you choose not to fix, once you know about it, that becomes security debt, right?
You've decided to defer it. Um, for the purposes of this report, because we're doing calculations and whatnot, we're defining security debt as anything that you know about and haven't fixed for, um, at least a year. So that's a pretty, like, that's a ample amount of time, right?
So it's kind of fair to say, like, yeah, you've let it slide into, into debt at that time. And so what we find is security debt is all over the place. It's endemic.
It affects every application, uh, every industry, every language, um, size of application, size of company doesn't really matter. Um, and, and, and you, and you, you just kind of find, find it, um, everywhere. Um, and you find that 71% of organizations have security debt.
Um, about 45, close to half of that of organizations have what we call critical security debt, which is laws and vulnerabilities that are of a, you know, a high or critical severity that you've let slide past that time. So it's, it's pretty bad. Companies are letting this pile up and, um, you know, over time that that really, really accumulates.
Sure. Um, you know, to me, security debt is like dark matter, right? It may make up 80% of the universe, but we can't see it, smell it, touch it, but we see its presence based upon like its gravitational pull right?
On regular matter or whatever. So, you know, in my mind, security debt has a similar kind of thing because it's there. We may choose to ignore it, and many organizations kind of bury their head in the sand around it, but nevertheless, the gravitational pull of it prevents us or slows us down from doing things that we know we need to do.
Right. And, and I think in the case of security debt, it's almost sort of a ticking time bomb too, though. 'cause sooner or later those chickens come home to roost as, as the saying goes, right?
And, and someone's gotta pay the price. Um, That's yeah, that's exactly right. Um, you don't, I mean, nobody, like most people would rather go and write a cool new feature, right?
Than go and, and fix some security issues. And on a day-to-day basis, you don't, you don't feel the security debt there unless, you know, unless you've got, you know, a security team pounding at your door or something. But, you know, you really feel it when there ends up being a large industry impacting event like, um, you know, like a hard fleet or a, a log for J or something along those lines.
And that's where the security debt really comes back to bite you. Because if you've allowed yourself to kind of get that far out of whack, like with a, with a, with an open source library, for example, if I'm up to date, if I'm only, you know, a month out of date and some big vulnerability comes out, it's actually very quick for me to just go patch that with the, with a fixed code, nothing's gonna break. It's a really easy fix.
If I'm five years outta date, imagine I, I can't just jump to the latest version, right? Right. I have to kind of go step by step, um, you know, go from five years outta date to four years outta date, take the next major version, make sure that nothing broke as a result, because I'm making such big changes to the code.
When you can make small changes at a more frequent basis, um, you know, you, you, you, you lower the chance that you're gonna break anything. And that applies to pretty much any security fix that you're gonna make. I think the longer that you let it go, and also if it's current, if it's recent in your memory, if you're working, if you just fix it when you find out about it, you're already working on that code, right?
As a developer, you don't have to go unearth it from some branch from a year ago and figure out what, what was I doing at that time and what, what does this code actually do? And kind of get back into that mindset. You're already working on it, but it's a, it's a muscle, right?
Yeah. And it is muscle memory. com about 10 years ago, right?
And look, the whole technical debt thing was, was a big issue that DevOps was helping to address, right? Is a lot of organizations just kind of tick the can down the road. Yeah.
And, and, and like you said, eventually it becomes such a big hurdle to get up to speed, to get up to par, that you just can't do it in one fell swoop. Now it takes time and more effort, and it, it, it's not that any one little thing is fatal, it's the totality of it, right? Yeah.
That really weighs in, you know, as I said, it's like dark matter. It starts, you know, it starts morphing and pulling and pulling at the, the, the, the fabric of your, of your stuff. Um, so what what's the answer here though?
Yeah, there are, there are some things that, that can be done. Um, and one of the areas that we, I spent a little time investigating once we kinda looked at the, the nature of the debt and the volume of the debt is what are application teams actually, what kind of, what kind of effort are they actually putting against this? And so if you think about, for example, what's my average monthly fix rate?
Like if I have a hundred flaws in any, any given month, how many of those flaws am I actually fixing within that timeframe? Like, what is my capacity as a team? And so we've defined capacity in that way.
What's your, what percentage of the known vulnerabilities you have? Are you actually getting after month, over month? Obviously you want to be fixing faster than you're creating them, otherwise you, you get into more debt.
But what you find is that most teams are not dedicating a lot of capacity to this. Um, about two thirds of them are, are dedicating like 3% capacity. Um, I think, uh, if, uh, you know, there, there's, there's a, there's a, a chart in the, in the report that kind of shows what that looks like, but it's a small, it's like we're talking single digit percentages a lot of the times.
And so, okay, that's, I mean, not ideal from a security perspective, but you're balancing a lot of things, right? You're balancing new features. You're, you're balancing non-functional requirements, uh, other tech debt, right?
The, you, you're keep, you're keeping your stack up to date. All these other things that you have to do as a software developer. So let's just say that your capacity is what it is.
Let's say you don't, you can't change that even though that you, you can, but it's a business decision and it's a lot more complicated than that. So given the past capacity that you do have, are you as a team using that capacity in the best possible, most efficient way, right? Am I getting after the highest risk items, knocking those off at least?
And it turns out that largely, um, they are not, teams are not. So you would expect that you'd work on the most critical issues first, and once you kind of got through all those, you'd work on the, the medium severities and the lows. Um, but when you look at a plot of the, sort of the lifetime of those types of issues, you, you find that they're all being addressed at roughly the same rate.
You see, there's a chart that has these lines and they overlap because, um, there does not seem to be a prioritization there. And so that's one thing that's, that's actually really easy to get after is, is prioritize the security work a little bit better. Um, because if you have only got a certain amount of time to work with, uh, you really should be spending on the things that present the most risk to the business.
Not, you know, what, you know, what you just feel like working on. Uh, and we can't really tell why it is that, that developers are choosing to fix the lower severity items first. Sometimes.
Um, I think, I think a lot of it just has to do with convenience. Um, I'll fix what's in front of me right now, um, because it's there, which, you know, hard to fault that, or, or I'm gonna fix this because it's the most recent thing that popped up in a scan, so like, it's fresh and I'm just gonna go after that one. But in order to really get after this from a security perspective, you've gotta, you've gotta, you've gotta kinda level it up a little bit and be thinking about how does the overall bucket of flaws that I know about affect the risk posture and, and, and go at it in a more prioritized fashion.
The other thing you can do other than increasing capacity is, is just, um, um, getting better at, uh, at, at fixing the flaws themselves, right? If I can, for example, if I can learn how to fix a SQL injection problem in five minutes instead of 30 minutes, I'm just making those numbers up. It takes a little longer probably, but, um, then I've effectively increased my capacity, um, because now I can tackle six times more in the same amount of time.
And so getting better, whether that's through education, whether that's through sort of generative AI assisted type fixing, uh, any ways that we can make ourselves better at the task at hand, um, effectively increases our capacity, um, and allows us to chip away at more of the debt. So those, those are, so those are some things that teams can do. Absolutely.
Like any debt, whether it's credit card debt, technical debt, or, or security debt kicking the can down the road is just never a, a great solution. And, um, you know, easy for me to say, and, you know, but when people find themselves in this state, it's kind of usually too late for that. But you gotta start somewhere and, and, you know, there's no better day than today.
Chris, beyond technical debt, I, excuse me, beyond security debt, what other kind of big, you know, highlights from the report this year? That that is the, that is the bulk of it, because it's such a Okay, big. It's such a big problem.
And we, we slice the data a lot of different ways, um, and, and kind of look at what's happening, uh, and, and the factors that, that, that, that affect that. Um, we do have another section, uh, a section at the end of the report that kind of follows on some open source research that we, that we did last time. We started looking at what's, what, what was on GitHub and some of the characteristics that we thought might, you know, uh, lead to more risk.
For example, this, this was last time. So we looked at repositories and how often they were updated or, um, how many developers were on them. Um, those, those types of things.
And we, we pushed a little bit more into that direction this year, asking questions like, how, how much risk, uh, do you get out of using open source when you know there's only a single developer? Or like, if you look at the percentage of applications in a particular language that are using code from a single developer, right? There's a lot of libraries out there that are very popular that have one maintainer.
And so what does, what does that risk look like when you think about that in, in, in, in terms of the organization, if, if they introduce a bug, if their account is taken over, if they decide to disband the project. Like those, those types of things. Um, and then we looked at open SSF, which I'm sure you, you probably come across at at some point, but just sort of industry, um, work to kind of do many things, but they have a, this notion of a score that they put on, um, open source libraries that looks at a, a number of different factors to gauge sort of how secure that library is.
And it's more about practices than vulnerability counting, right? It's are they using, um, are there signs of dangerous coding patterns? Do they use branch protection?
Are there, do they use code reviews? Do they use SaaS against all these things that you, it's kind almost like a maturity model type thing, right? And so we looked at the scores of, uh, of open source libraries that they've assigned scores to, and then we've looked at open source libraries that we see actually in use in real, um, real world applications from our customer base.
And we actually saw that, um, the libraries that we saw in use tended to have on the higher side of open SSF scores. Now, I'm not saying that people are using the open SSF score to decide what they wanna use, um, but there does seem to be a correlation there that people are leaning towards the, the libraries that have better practices. Um, and so that was, that's sort of a good sign.
It was, we, this, there's a lot of data there, right? Um, but we wanted to, to kind of see what that was that was looking like. So there's a whole section there on open source, what that looks like in the ecosystem, how, you know, the, the, the, the influence that individual developers have and, uh, and stuff like that.
So, um, worth the read. But, um, yeah, our focus was really, let's get into this security debt discussion that nobody wants to have. And, um, and, and let's have it, and, and honestly, um, I saw, um, Ollie Whitehouse over at the, uh, at the, the uk, um, uh, uh, forgetting the acronym now, right?
But it's their, it's their cisa basically. Mm-Hmm. And he was saying like, one of the top priorities for the year, as he's concerned is like getting the security debt, um, conversation happening and figure out ways to get after that because it's just this looming, this looming problem that comes back to bite us every time, you know, every time, uh, uh, something big happens in the industry.
So it's a conversation needs to happen. Yep. I, and I think it's a topic that we are going to see throughout the year.
I hope to see some of it maybe at RSA where I usually see you, I usually see. Yeah. Yeah.
Hopefully we'll see you there. com. I'm sure there'll be links off the front Page.
Yeah. You'll, you'll find it. Yep.
Hey, Chris, as always, thanks for coming on and, and talking it up and, and informing us, enlightening us. Best of luck and, uh, come back. Well, if I, if I don't talk to you before, I'll see you in May, but maybe before That sounds great.
Thanks for the chat. Always a good conversation. All right.
Chris saying, chief research officer at Veracode here on Text Trunk tv. Tell you one thing, you know, Mitchell, I have less hair than I did 20 years ago. Yours is much more gray, but even Chris a has got gray on us.
Yes. You know, we just hang Around too much together for two. Yeah.
It just, you know, it makes you realize, Mitch, the, you know, here's to us and those like us damn few left. Yeah. Um, But we're Hanging on Chris.
Definitely. Yeah. But Chris has definitely wanted them.
And look, he does a great job there at, at, at Veracode, as does Chris Weiss fault. I mean, it's still a great company. They Did.
And a lot of people follow that. I mean, that report's important. Yeah.
I mean, look, they've been setting the mark in the AppSec, I think, as long as there's been an AppSec Mm-Hmm. Yeah, for sure. So, And that, and I'm lucky, I mean, whenever they have some kind of news like that, Chris, I guess tells the PR people or whatever to reach out to me.
Mm-Hmm. And him and I get together to discuss it. So I, I probably interview Chris three or four times a year, and I usually see him at RSA or Black Hat.
And, um, as a matter of fact, we made plans, we'll see him at RSA again this year. Mm-Hmm mm-Hmm. Good stuff.
And he, he's just, well, he's talking about real things, real data right. And analysis from it. So that's what, it's not just pontificating about what we think is happening.
No, I mean, the thing about Chris saying is this is a real deal security guy who's now been doing the research of Veracode for a very long time. And so it's not, it's not your average analyst, right. Who is riding that gravy chain.
Not, no, no disrespect Mitchell. Hey, I'm none taken. Alright.
I try not. Yes. He, he's a, he's a real security guy, so really, uh, really, really happy with that.
Anyway. Well, this is great. I appreciate you bringing that interview forward so folks could, uh, listen and watch.
Yeah. No, and, and if you wanna see it again, it, it, it's available on Textron tv as is Mitchell, these podcasts, you know, if you're listening to it on Apple or watching it or on Spotify or wherever, you can catch it there, you can also catch it on our Text Drunk tv, YouTube channel, as well as on Text Drunk TV as well. So there's no, there's no lack of outlets to, to watch your favorite podcast here on Text Drunk Every Part of our Global Takeover plan, Omni Universal.
Anyway, Mitchell, thanks for, uh, having me on Security Boulevard Chats and joining me this week. We'll be back next week with more. Yep.
And, uh, you've been listening to Security Boulevard Chats. Join us next time. Bye-Bye.