Ubiquitous Data Collection And AI Startups – Security Boulevard Chats EP9
Mitchell and Alan talk about the ubiquitous collection of data including geolocation data by Apple, Google and other providers. The uses of this data can be relatively innocent for marketing purposes all the way to serious security issues of life and death. They also talk about the current state of Cyber AI startups. Has the bloom come off the rose? Will Cyber AI become a big company game with the giants of the field dominating? What about the Palo Alto/IBM partnership? Lots to discuss in that one.
Transcript
Hey everybody, this is Mitch Ashley. And, and I. And I'm Alan Shimel.
And you're listening to Security Boulevard Chat out on the The Boulevard. On the Boulevard. Yeah.
Baby Uhhuh, not cellulite. What's that? Not Hollywood Boulevard and Celluloid Heroes.
I think of that every time we say this. Me too. Me too.
You know, one of my great memories, Mitch, of, I went to St. John's undergrad, St. John's University, and the Kinks played at what today is Lou Car Sec Arena.
Back then it was, I think just Alumni Hall. Uh, and, um, I volunteered to be a usher for the show. Oh, okay.
Which was, they gave me a free T-shirt, Uhhuh. I made sure everyone was sitting in their seats. And then once the show started, I went down, like sat on the first row there right in between seats and had, you know, watching Ray Davies, like right on top of me.
And yeah, that was a great concert. That was awesome. Hollywood been so great.
Concert Hero hasn't been the concert desert in Nebraska, which not that many good. Yeah, we had concerts, but not like New York. Nothing like that.
No, we, well, at St. John's, the biggest ones we had was that King show. We had meatloaf and I think the Allman Brothers, the Allman Brothers were a great show there, this back in the day when they were alive.
Yeah. Um, little tween was gone already. But anyway, um, we were grass s Yes.
We're here to talk about security and cyber and all that good stuff. What do you got, you know, I wanna bring up a, a kind of a different topic than we've talked about before. Uh, Brian Krebs, who we, you all know, you know, if you've been to security Sure.
You know who Brian Krebs is, you know, with the, I guess he was with the Washington Post originally, right? Yep. Um, but he's been Krebs on security now for a long time.
That's right. He has Krebs on security. He had this interesting article about, uh, why your wifi router doubles as an apple air tag.
Long way of saying, essentially there was, I think it was University of Maryland, uh, was doing a study and found that our Apple devices, while they're roaming around networks, and we always have these features like, you know, turn on wifi so it to prove your, your, your cellular or your network performance. Well, some of it is about geolocation, also improving geolocation. But the point here was that all of our Apple devices, at least in that ecosystem, are collecting data about every access point that it sees as you're traversing through going over to Costco, or you're driving down the, down the highway, or you went to the mall or at the movie theater, whatever, wherever you go.
Or you're traveling on the airplane somewhere. All of us are providing data into, back into the back end of Apple systems about wifi access points. Now what exactly all data that they're capturing is not totally clear, but the University of Maryland did this study where they actually pulled publicly accessible data out of that information and could map sort of movement of people in Ukraine and in Gaza and places where there's a lot of, you know, disruption happening.
And you can just imagine like, oh, what else? Who else might want to use that information? Maybe people who are involved in those conflicts or maybe Sure.
Fiber threats. So it's a combination of, you know, we, we heard about geofencing when we went to the mall. It could tell you where you went to what stores.
Now that's happening on a, on a macro level. And it made me think, you know, Apple's big on our, our security, you know, take, securing our data. Uh, is that a little bit too much information that's leaking, even though it's not specifically about us?
I'm curious your thoughts on it. Well, you know, early on in the Ukrainian Russian, uh, war, call it a conflict or whatever, the Putin and those guys decide to call it special operation. Um, I know the Ukrainians were triangulating Russian soldiers using cell Mm-Hmm.
And that would give away their position and they could zero in their smart missiles and bombs to take 'em out. And as a result, you know, a lot of Russian soldiers died. And I think the Russian Army put sort of a stop on, you know, soldiers using their phones, their, their in, in these positions.
'cause it's a dead giveaway. I don't know if that's the same technology or that was cell phone towers, I think cell, yeah, but I'm not, I mean, cell phone towers will give you a decent location when you're using wifi. They really can triangulate in on you.
Mm-Hmm. You know, based on your laps and stuff like that. So obviously it's, it's an information leak there.
On the other hand, I'm not quite sure, and I I, you know, I'll go back to read the Krebs article, the Apple information, how is it being accessed by anyone? Right? I mean, the app, apple doesn't make that publicly available.
I'm thinking there, there ly is some publicly public information and they were talking about Apple and satellite based broadband services like starlink. Um, that they could do some correlation and tell from that. Um, some of these implications about shoe located devices where they're like, I'm wondering can they grab a Mac address from your device?
And then w follow where that Mac address is, is linking onto a WP or a STAR link or what have you. Yeah. And say, okay, assume that Mac address is Mitchell's phone and Mitchell's phone was went from this wireless access point to that wireless access point.
So we know where Mitchell's going here. Right. You're spot on and they're capturing the Mac address of all the access points that you're seeing.
Right. So that's how they correlated back to the same access. Sure.
And, and you know, so but are those Mac address points publicly? Obviously they must be, if this is what they're doing and Yeah, go ahead. You know, if they're doing it in the Ukraine and Gaza, I'm assuming they're probably doing it for FBI and, and criminal matters as well.
And you won't, um, it just, you know, this is why you can't have nice things on the internet that your Nokia flip phone. Yeah. You know, or just two tin kids send a, send a letter or a postcard stop.
You know? Um, I, I don't know a way around it unless, you know, because there are valid reasons to have that information out there. It, it is.
And I wonder, so apparently it's, some of the information is available through an API, both, both. Google does this too, by the way, not to pick on Apple. Oh, yeah.
Um, and, and, but at least the article intimated, there's not all the information's available through that API, so it, it's almost like my, I just suspecting here Apple made some of it available so that it's not all Oh, we're keeping all that private, not letting you know what we have. Right. So maybe way.
No, I think some of it probably has legitimate business uses. Like, think about this. I don't know, this is a first world problem, don't hate me for it, but one of the things that I really hate when I'm flying and I'm trying to stream video on a, you know, an air airline is that many of the airlines, when you log into the Zeta or whoever, however they're getting you online, you can't get like, local programming or if I wanna watch a football game or a baseball game, you know, and they're a blackout restrictions because it can't tell my exact location.
It prevents me from like watching a particular game or something like that. So the way to get around that used to be, I screw it, I log in via VPN while I'm online and make believe I'm in New York or Miami or LA or wherever I want to be, that's gonna allow me to watch the, the team, the game that I want. And what I've noticed is the plane's wifi systems, it's not that they've gotten smarter, but they're detecting that I'm not, you know, there's a VP N of Miami, it don't work.
And I suspect how they're doing that is they're probably looking at where the Mac address of how I'm connecting is coming from Mm-Hmm. Regardless of where my VPN says I'm logging in from. Right.
So that might be a legitimate reason why you'd wanna have that Mac address, though. It's not legitimate to me. 'cause I paid for the damn NFL subscription.
I should be able to watch it anywhere. I want creepy, but know, shout out to Pittsburgh getting the 2026 NFL draft, by the way. But we'll talk about that later Okay.
And end our quarterback, but, okay. Alright. Um, little Broncos uhhuh, if you connect a few more dots.
So step back one more degree, if you will. You're using your VPN to watch Netflix or whatever, you know, let's say you travel to London or something Mm-Hmm. You wanna watch a subscription from there?
Well, they might be able to detect that you're using A VPN either on the phone or, you know, while you're there, maybe looking at IP addresses or something, or the Mac address. But if you also step back and say, well, wait a minute. We've seen that Mac address in 25 places between Newark and landing and, and spending time in London.
We know you were in London five seconds ago Yeah. Before you connected on to the beachhead. Yeah.
And, and that's what I mean. Yeah. And, but so I guess the question then though becomes Mitchell, is that a legitimate use?
Right. Should they be entitled to do that? Or is that a little too big brothery for me?
I know. Is there no privacy? Can I not, you know, so I kept headlights on your car.
Turn on what? What's no, I, I, you know, from, uh, machine gun Joe, what's his name? Joe McCarthy.
Have you No Decency senator. But I mean, you know, I say hello to my little friend. Oh yeah, exactly.
But it's a different movie, not different movie, different movie, different guy. But I mean, I, I guess they have a right to know, because you're not entitled to watch the NFL game in London, but I am entitled to watch it while I'm flying from Florida to California. Mm-Hmm.
Right. And, and it thwarts me and it bums me out to no end. And I, I've, I've done some things.
I'm, I'm, you know, I'm not, you're not proud of, proud of because God, I'm not gonna miss that game while I'm flying. But you're climbing up the pole to connect, bypass the cables block. Look, I'll never tell.
You'll have to cut. You'll have to kill me first. Not that I would know anything about that.
No, no. But I'm watching that game. Screw you anyway.
Okay. Um, well, I think we've gotta beat this dead horse. Yeah.
No, buting you know what, honestly, it could wind up costing you your life in a war zone. It could, in the wrong hands. It could be used against people very easily.
Right. Absolutely. And it'd be interesting, I, I'm not sure if we've seen it yet in, uh, in court cases, but it'll be interesting to see.
Yeah. Now you a topic you wanted to bring up. I did.
Did I? You did. You told me You did.
You wanted to talk about, was it the, um, this No, it's not the CISO role that changed. We talked about it on, we talked about text gang, about the changing role of, of the ciso Yeah. Yeah.
Because of AI and all of that. Trying to remember. Yeah, no, that was in ai.
That was a text. And do check out Textron gang on, on Textron tv. But no, I thought I had another clever thing going on in security, Mitch.
Oh. And that, oh, now I remember what it was. Is the window closing on AI startups or is it just another cycle in the cyber world?
You know, what we've seen Mitch in the last year certainly is VCs are falling over themselves, throwing what dollars they have into AI and cybersecurity. ai cybersecurity companies are no exception. They've garnered a lion's share of the VC money available out there.
And especially because look, if you're a a new AI security company, you're probably right. Raising a, a round seed round kind of money. And that's where the money's going right now.
No one wants to invest in some company that had an inflated round, you know, in 2022 or 2021. And now, you know, if you're not doing a down round, are you really getting your money's worth? They'd rather invest in something clean and new at a, at a better valuation.
But, and, and so, and that fueled a ton of these cybersecurity AI or AI cybersecurity startups. But now the big boys are coming in, right? Cisco Palo Alto partnering with IBM using Watson and stuff for it, CrowdStrike, uh, thinking a big public cyber companies.
And they're all jumping AI. Now, this is not new. This is how cyber works, right.
These big companies will not let a once, once something starts going mainstream, they're not going to not feed at the trial. Mm-Hmm. Right.
And, and so they, they, you know, they, they make their bets. Their bets are usually, they don't develop their own solutions. They don't, they buy, they buy innovation.
Yep. And so, you know, a thing we learned, Mitch, when we were still secure, and, and I've learned working with Brad Feld, who was a, you know, money behind still secure is, if you're not in the top three in your space, get the hell out. Yeah.
Because when these big guys are gonna buy, they're looking at top three usually. Right. They wanna buy leaders in, in that space.
And so you got a lot of these AI cyber companies that look, their markets are immature. They got off a little later maybe than the first mover. Um, whatever the reason, they're not in the top three.
And now the big boys are coming in. And once the big boys come in, you need a lot of resources to compete. Exactly.
So what is a, what is an AI cyber company to do well, right? If they can't sell quick. Lemme throw this wrinkle at you.
'cause we, we went through this cycle, it's still secure, right? Um, with our products. One of 'em was an N product and, you know, suddenly Cisco grabs up somebody else, right?
So that we're not gonna sell us our stuff to, you know, sell out too. Uh, Cisco. Cisco.
Well, no, now you gotta compete with Cisco, right? Gotta compete with them and damn the torpedoes and pivot and say, who else in market is a potential buyer for the company, right? So, so accelerate today using that, that phrase accelerate today and how fast things change in the AI space.
You know, that was something that happened over, oh, they, you know, probably months six to 12 or 18 months that that's kind of an exact acquisition evolved. This could be like, Hey, there's three companies out there. Go buy one now.
Right? Right. And three months later, if you still, uh, if you're still standing after three, four months, see, but I don't think pivot in this case means pivot to another competitor.
Right. Because if you're not in the top three, that other competitor's not going to give you the valuation you want or your investors want. Exactly.
I think in this case, pivot means find something else, maybe move downstream in the problem. Right. You still use ai.
Yeah. Right. Use that technology, but use it for something else than your original business plan.
Uh, I I think that's gonna happen because there are a bunch of AI cyber startups that brought down some good money and now find themselves competing against Palo and IBM and, and Cisco and, and what have you. Um, but here's the good news. The smart ones will pivot into something new and novel and create yet another wave of innovation.
Those, and Mitch, that's the way it is in cybersecurity. It has been for as long as you and I are in it, right? These big companies, they buy innovation and the companies that get left over are kind of liquidated or pivot and reinnovate.
Mm-Hmm. Or languish stick into their old model or die. Right?
They languish until they're dead and someone shoots them. But, um, it's just again, how quick time is moving in this AI time crunch that, you know, it's not quite two years since gen AI kind of burst on the scene. November will be two years.
It's a year and a half, and we're already seeing this cycle play itself out. You know, the, so step back for a moment. The, the IBM Palo Alto acquisition, not, not about Palo Alto, no.
That partnership. Partnership, yeah, that's the right way to say it. You know, there was an AI component we're gonna partner on with IBM and used Watson, uh, for some of their technology, their LLMs.
But there was also the kind of security monitoring system that Palo took on in exchange essentially for buying the business of IBM using Palo's products and things. But they took, they kind of ingested an older, previously acquired SaaS application that IBM the longer use. Well, no, they, they bought qr qa, uh, QR radar qr Radar q that's the new QR radar.
It's a, it's a sim, but it was the sim at the heart of I IBM M'S security practice. Yeah. That was just curious to me that they, okay, the ole probably still gonna use it or maybe they're moving on to something else.
I don't know. It was time to jet. No, I think the IBM wants to sell security.
They don't wanna do security and Right. And, you know, QR Raiders are great for, for managed security providers. It's a cornerstone.
But you remember sim from our, you know, still secure days, Mitch, and been around for 20 years, 20 plus schools. You got to $5 million and a couple of years to get it up and running. Then I got a sim for you.
I'm a sim one. It hasn't gotten any better. I heard the phrase phrase, it's not single pane of glass, single glass of pane.
Right. But it, you know, look, in our day it was, it was QR radar. It was aite and there was the one that had the art.
They, they had like googly eyes was was there Yeah. Kind of out of Atlanta. They, they were a little lighter than the other two.
But anyway, that's always been the case with sim and, and over the years, look, we've seen Soar SOR come out and kind of leap, not leapfrog, but it's, it's an alternative if you're not doing pure sim. But you know, when you look at IBM's and IBM had a big security team, right? I remember you remember too.
Oh yeah. They bought the ISS business back in the day and that really helped them establish a security stock price. That was really their, yeah, no, well, export and exports is part in this deal too, right?
Yeah. Exports goes over to Palo. Um, but you know, that was that the card of that IBM, they, they did a bunch of acquisitions in the subsequent years, but that was the heart of the IBM security offering.
I wonder, are they just gonna sell Palo's security offering now? Or what, what's left of the IBM security offering? Well, it sounded like they're gonna be pushing a lot of Palo products, so Yeah, I don't know if it's in place of pure radar or if it, what, what it is.
So this is a bit of a tangent. I have a question for you about this because one of my thoughts around why, why sell this right now? And there's complex deals, so there's lots of factors for doing that.
But one potential reason is the Splunk acquisition of, or acquisition of Splunk by Cisco and the, you know, being positioned as a security company, right? You and I know Splunk from an IT operations log aggregation management to bulk, you know what, Splunk always sort of resisted being a security company, but it was the bulk of their business. It is.
And it is for others too. They're not, they're not only SIM that are that way. And what I was wondering is, ha how are we seeing a sunset on the days of sim and uh, and observability in the security world is the thing that's, I dunno if it's replacing it, but that's the thing that fills in the big gaps we've got.
I don't think stims ever die and they don't fade away. They just take on observability and said, but look, the fact of the matter is the people who started ArcSight and sold it for a couple billion bucks to hp Yeah. By the same people who started Sumo Logic, right?
And, and Sumo, much like Oxsight and the rest of the Sims never claimed to be a security only thing. They were very DevOpsy and, and all of that and observability and you know, next gen. But they were sim it was some people doing sumo.
And now, you know, you've seen Sumo went public and is a successful company, but they've had some ups and downs Mm-Hmm. And you know, they're gonna try to reposition themselves as an observability solution. Um, I think IBM made a conscious decision here that where do they play?
They play in ai. Mm. They've put a ton of frigging money into Watson.
And the funny thing is, IBM very well may have invented this whole AI thing with Watson. Mm-Hmm. Right?
But real quickly, OpenAI dos them. Right? What Microsoft did with das OpenAI is done with chat GPT to Watson it.
And, and so they've seen this script before. They know they're in a war to be an AI player. 'cause it, the stakes are that big.
So and so they, they gotta make their bets. I think, and this is a shifting, and I'm talking about Microsoft, but you look at the announcements that they've made in the last couple of weeks, I think we're, we're seeing Microsoft move from, we're a cloud company to now we're an AI company, right? I think that's the next generation of, and they put $10 billion of money in the OpenAI to prove it.
And, and look you again, we just discussed it today on the gang, right? Mm-Hmm. They have now come out with an AI pc and they're talking more about hardware micro Bill Gates.
Well, he is not quite in his grave to roll over, but he's not doing cartwheels. Microsoft's become, well, maybe they always did want to be hardware, but you know, an I PC the surface, uh, copilots in everything, Azure and DevOps. Yes.
Every company, today's an ai I'll do market re AI's eating the world, right? Yeah. Every company today's an AI company, including Microsoft and including Google.
'cause last week we were at Google, not Google next, next, whatever Google's show was last week where they announced everything AI into everything they're doing, IBM's gonna do the same thing. They're, they want to be a powerhouse there. They've got their cloud strategy there.
Finally, you can almost tell what, what IBM cloud is. They've got Red Hat Mm-Hmm. In there.
I don't, I think they just felt like they couldn't do justice to keeping security a a best in class solution without partnering with a, a Palo or someone of that scale to, to keep their security products top of light. Otherwise they could have given it to HDL. Well, if you don't, I think every company is, you know, every technology provider company, you don't have a solid, a AI story that you're either rolling out or developing or, you know, it's, it's got kinda long range legs, then you're just a fill in.
You're a observability company. You're just a monitoring. You're just a security company.
And I think the market, the value, how you're gonna be valued and viewed in the market, it's gonna drop rapidly if you don't have a credible story. I, I, I agree with you a hundred percent and I think they're all rushing to it. But let me ask you the definitive question here.
Mitchell is an observability solution, a security solution is an observability company, a security company. 'cause I will tell you, if that's the case, arose by any other name would still smell as sweet. Right?
And so tomorrow, yesterday SIM is tomorrow's observability, but it's the same old, same old, which is a whole nother topic. Um, I interviewed Austin Parker on his, uh, his new book about learning OpenTelemetry. And it was kind of interesting.
We talked about the book and learning and why he wrote the book and all that kind of stuff. But the latter after that conversation was all about if you really step back and what Open, OpenTelemetry and Observability is doing, it's clutching data to basically metrics, right? To correlate and, and make observations about.
And his point was, he thinks observability is gonna be a business tool, not just an IT tool. So think about measuring all this data we're getting from applications and customer experience and financial data, whatever it might be. You could create KPIs on any kind of information or, uh, monitoring if you will, um, around any kind of telemetry data.
And the more we're overrun or kind of create all this data, he thinks that's, that's where OpenTelemetry and Observability is going to. It's not an IT or a security tool. It's the next generation business tool.
I thought it was pretty fancy. Yeah, it is. I mean, it, you know, the whole OpenTelemetry thing is, is, you know, that's like a business school, uh, you know, case study.
Case study. Yeah. Yeah.
I mean it just, it rocks and rolls and, and it underpins almost that whole industry now, this whole observability industry that we used to call. It's funny. It's, it's, it encompasses them.
What we used to call eight pmm. 8:00 PM right? Is all, it's all observability now.
So it, it's interesting times. I mean, you know, it's funny, we, I look at the agenda that our editorial team comes up with every day for Textron Gang, and it just blows my mind, the, the sheer volume of AI news across every single silo we cover. But that's, that's the timeframe we're in right now.
And, and you might, you can embrace it or you can, you know, roll over and die. I mean, what do you want me to tell change tell you being changed, right? Yeah, exactly.
Choice that. Yeah, exactly. That's how it is.
Better to be, what is it Better to be p****d off? Well, I'm not even gonna go there. Anyway, Mitch, this was a great security boulevard.
Let's end it right there. Okay. I think we should draft things up and, you know, thank everybody for listening and watching and well, especially folks who have been with us for over the years.
We've been doing this for a while from back in the still secure us after all these years after over the years. Absolutely. And, uh, and you know what?
Do check out Security Boulevard because it probably publishes more security content than any other security site on the planet. Thanks to our security content creators network and all the great folks over at Techstrong. And so check that out.
If you are cruising the Boulevard for Cyber News, there's only one Boulevard to Cruise way to go. And that's Security Boulevard. That's where you want to be.
It's, you know, all the cool kids there. Yep. Alright, Andy, sell your Lloyd Heroes just to bring in full circle.
Alrighty. Before we get started on another tangent, we'll ask doesn't take much. So this is, uh, Mitch Ashley and Alan Schmo, and you've been listening to The Security Boulevard Chats.
Yeah, baby on the Boulevard.