The Cyber Core Collapse: Surviving the AI Vulnerability Apocalypse | Still Cyber Ep 5
The cybersecurity industry is staring down the barrel of a “vulnerability apocalypse” as AI-driven code generation and machine-speed exploit discovery completely shatter traditional scan-and-patch methodologies. In this episode, Alan Shimel and Mitch Ashley sit down with cloud security luminary Rich Mogull to unpack Anthropic’s Mythos red team report and the industry’s response via Project Glasswing. Mogull warns of a looming “core collapse” in AppSec, urging defenders to abandon obsolete reactive tactics and urgently retreat to foundational principles like Zero Trust and strict segmentation before every single day becomes a zero-day.
Transcript
Hey everyone, this is Alan Shimel. And Mitch Ashley. And- Rich Mogull.
Rich Mogull. " No doubt. And I go, "You know what?
" But it's a bit of extraordinary times, so I think it's a good time to rekindle these conversations, and I hope this will lead to more conversations. But what are we talking about? We're obviously, like most people in security, talking about the Anthropic Mythos release.
Well, it's not really released, but the red team report that they released around it, and Project Glasswing and everything that's happened there. So Rich, if you don't mind, I'm going to ask you to kick this off, right? Because, A, you've been pretty prolific writing about it on LinkedIn and such, but also, B, you kind of wrote about something like this happening, what was it, seven or more months ago?
Six months ago? Something like that? I didn't write a ton six months ago.
The big thing I pushed out was actually only in February, but I think I did- Okay ... like LinkedIn post about it. Well, in AI time, it was six months.
Yeah, yeah. Yeah, it's- We're all living in bullet time now. Yeah.
And everything's the Matrix. Mm-hmm. " You know what?
He was completely right, and his timeline was there. And I wrote kind of back in February, it's very clear this is going to happen. We just weren't sure exactly when or to what degree.
And I think now what happened with Mythos is, that's just the slap in the face. It's like those shows, you just got to sucker punch somebody to wake them up. And I think that's what this is.
Yeah. And to be fair, it wasn't just Gadi did write about it, but it was based on research he did with Heather Atkins, right? From Google.
Yeah, over at Google. Yep. And it was this whole vulnerability apocalypse kind of thing.
And like you Rich, I said, you ever watch in the movies how the avalanche makes the snowballs in sort of slow motion? Well, at first it was in kind of slow motion, right? Because here's how I see it, is first we started just producing, and we have been producing a lot more code than we've ever produced before.
And I think that was one of the breaks built into the system. No matter how many engineers and software developers we had, there was a finite amount of code that we produced. Well, all of a sudden we saw that X amount of code become four X, five X.
Well, the next piece of that puzzle, and this is the one that I think where the dam really broke now, is that security research, AppSec, was basically a scanning job, right? Whether we used DAST or SAST or dynamic or software composition analysis, a lot of AppSec was about scanning to find potential vulnerabilities. Well, the AI stuff, just if we four X, five X the amount of code we produced, we've, I don't know, 10 X, 50 X the amount of scanning we could do up until this Mythos announcement.
So we've already seen the Gadi and Heather projections. It was kind of inevitable. " Well, Alan, we've been, for a while now, talking about a lot of these things, Rich has been writing about it too, of a certain number of things come together to happen to enable something that couldn't have happened before.
So we've been talking about scanning is dead. There's not enough people to review output of scanning. Human in the loop has to be redefined.
People can't be the central of this process. The value of code or producing code is dropped essentially to near zero. It can just be done.
And we're approaching that fast. We're hitting the bottom of that curve. I don't mean to overstate it, but I really do believe that to be true.
And so any kind of a system, when you start pulling out constraints and say, "Let this thing run without those governors in it," you talked about the natural breaks of how many people can actually sit around and write code. Something not only is going to happen, but something is going to be enabled that could never have happened before. And I think that's what we have.
We now have those conditions, and I call it perfect storm. I think it's much more than that. I think it's a resetting of all the parameters of a system that we've built security and software and businesses and everything around, that's changed.
That's how big this is. I really truly believe that. Oh, and this is, I think, the most impactful thing that will happen in our security groups.
Mm-hmm. And three of us, I'm the young one at only about 26, 27 years in the industry. Oh, you pup, you.
What do we got, Alan? Well, no, but yeah, we've got you maybe by three years or so, right, Rich? Yeah.
I started doing security with managed checkpoint firewalls in like 1997 or so. That's when I started too, '98. Yeah.
That was like 2000, 2001. Yeah. But collectively, that's 90 years or so worth of security.
I mean- But were they quality years? Quality. Some of those years were quality years.
So good quality, I don't remember them all. But here's the thing, and I'll ask the two of you for your opinion. I've heard people, and honestly, not who I would consider security people, but nevertheless smart people say, "Ah, it's not as bad.
It's not going to be as bad as we say. A, it's going to take years for it to kind of wind its way down. B, it's a lot of hype.
" But most of the security people who I know and respect say, "We're screwed, guys. This takes it down to the core. " It's like all of a sudden you change the fundamental laws of physics on us, and now we don't know how things are going to react.
I think the change at the core, as you know, because you'd already think, oh, core collapse. It was- Mm-hmm ... about this.
I think whatever we want to say or think, whether it's tomorrow, whether Mythos is it or not, there's no obstacle in front. So let's look at what Mythos is, and where it came from, and why- Sure ... it's doing what it's doing.
It's the next evolution of Anthropic's model. Anthropic's been very good with Claude coding, and they built the next version of the model. They trained it very heavily on writing secure code.
Guess what? They didn't set out to build a magical hacking machine. However, if you train something on all the secure ways we build code, of course, it's going to know the insecure ways, and it's going to find all the flaws, and it's going to be able to infer the different pathways and attack sequences that it takes to get through security.
It's just an emergent property. Anybody who's a great developer can easily become a great vulnerability researcher. There's no obstacle.
It's a mindset difference. It's absolutely not a fundamental skills difference. That's what we're facing, that's what we have here.
So if you read the red team report they issued, they found vulnerabilities in every major operating system. " We'll get into this. I don't even know if that's true.
I just saw a text message flying across my screen here. So fundamentally, where are we? Where we are is we have to assume that we now have AI capabilities that are capable.
They're not going to find new magical vulnerabilities of, oh, we found some new quantum layer in the quantum verse. It's going to be- That's three years out. Yeah.
Within the realm of known bug classes and everything else, but it can scan and search to a degree and chain things together to a way that's beyond most mere mortals, and even the very good people who could find that are usually off doing other things. It's going to then, that's in this isolated, controlled space, because you can't just steal the code for Mythos, for Claude, and make it run anywhere. Has to run on their purpose-built infrastructure, their purpose-built neural network.
However, we've seen these capabilities roll downstream very quickly. Open weight models, you can download it, run it on your own Mac today, can do today what the top-level GPT models and Claude models were doing a year ago. So we know it's coming one way or the other, that there's no gate anymore to slow down vulnerability discovery, exploit development, and chaining of exploits in red team operations.
It's all going to be fully automated with these agents. It's the irony of there is no first-mover advantage anymore, or there's no first mover innovator anywhere. The times is collapsing drastically.
So to your point, someone else would be able to do the same thing and better. Yeah. The AI space, you're seeing OpenAI was first mover.
Anthropic actually has more revenue right now- Yeah ... than OpenAI. So the old way of how we looked at those things are history, too.
But Rich, I want to go back to something you said here, that we're not going to discover maybe new classes of vulnerability, right? Buffer overflows are buffer overflows, and the kinds of things, we'll just discover them in code that we haven't discovered them before, because these AIs are really adept, really good at just looking at things maybe in a different way, from a different angle, and doing it. However, is there a finite amount of vulnerabilities in code, or is it infinite?
Because if it's infinite, we're really hosed. We're done. If it's finite, well, at least no matter how far out that is, it's something for us to shoot for.
You know what I mean? Yeah. It's finite.
But here's the problem, the math associated with the problem. To give you an example, a positive example. Mythos for Anthropic was able to find a 27-year-old vulnerability in FreeBSD, which is known as being a hard and secure operating system.
Yep. But they couldn't get remote code execution. They found privilege escalation.
Like all the internal security mechanisms work. It's not that it's infinite, it is bounded. It's just very bigAnd I think the problem we're facing is that for adversaries, attackers, bug hunters they have these powerful tools that they can point at a bounded problem.
So even the way, if you go more into the details about how they do the testing, they would take a big code base and they'd break it down into functional chunks. And then they would actually have different agents hit different chunks and then coordinate between them. What they're doing is they're taking this massive, two bigger, bigger than the context window space, narrow it down, but then you deploy a fleet of agents to go at all those different chunks.
And Mitch, we've talked, you and I are both doing code development with a lot of these. We're using different agents, different personas, different pieces all running in parallel. That's what they did, and then they synthesized it all together.
The problem we face is that for the adversaries, it is bound. Find a vulnerability in X, and until every vulnerability in X is found, it's going to find vulnerabilities in X. And we know that there's millions of X's out there, all the open source projects, all the commercial code, all the everything else.
So the attackers just need to kind of focus on the ones that they want to start with and find those vulnerabilities. And then once they find them, they then are back to what's the problem space they're dealing with, a bounded target, and then they can take that exploit and then go after a particular target with a bunch of exploits and chain exploits and go through a whole red team operation and burrow deep into the organization. Or they can take that exploit and just use the one thing across at a wide scale across the internet until they can find somebody who's vulnerable and then go in there.
That's the math of what they're dealing with. So basically, it's a search problem. It's a bounded search problem.
Find- Yeah ... X vulnerabilities in Y. So- We're screwed as defenders.
Yeah. Yeah. So- Go ahead On the defender side, we have to defend all potential code from all potential vulnerabilities from all potential attackers for all time.
And so it's a combinatorial complexity problem for us, and the math is just not in our favor. But was the math ever in our favor? No.
No, it wasn't. Mitch. Maybe it wasn't as stacked as it is, Nick.
No, go ahead. And I'm not saying this from a doomsayer standpoint, but I do think the problem is infinite, right? There is no singularity where we reach where code cannot become vulnerable.
Because something is always coming along that's better, right? There has. I don't think that's going to stop.
Now, that said, Rich, I know you've done some thinking around, well, what do we do about something like this? And maybe it's your first comment. Alan, I know you were saying previously some thoughts around the coming together of Glasswing and what these organizations are going to try to do or we think they're going to try to do.
How do you respond to this situation, I guess, is really where I'm going to. " No, they actually did something really good, I think, in terms of Anthropic's response. They said, "We can't sit on this.
We've got to do something. We can't play Chicken Little, but what could we do and who could we do it with? " And they won't be the only ones, the Ciscos and Palo Alto Networks and Apples and Nvidias, people like that.
Well, there's 40 in the- There's now 40. Yeah, exactly. In this initial, not class, but this initial cohort or whatever of people- Mm-hmm ...
who have been given access to this code. You know what was interesting? Were there any government entities in there?
Not in the initial. I don't know that there were any. Rich, did you see any?
Linux Foundation was the only kind of non-corporate. Yeah, I didn't see any that were announced. I think we can assume that some to some degree, particularly because it's an international issue.
And look, the odds are the government has had access to this and probably shot themselves in the foot by going after them. Going after Anthropic as a supply chain risk. Well, that's true, right?
" I'm not going to rehash that whole thing- Yeah ... " I don't want to use the word evil, but is going to use this offensively. Well, I don't think we can assume that our government doesn't have this somewhere, not even their own version.
I'm not even going to assume that they don't have access to Mythos right now. And look bluntly, like, all right, let's be honest, I'm not personally pleased with the direction our government's going for a while, but nation states are going to do what they're going to do. I've always long said this.
I've always supported. I'm like, I don't love that the NSA has to do what it does and some of our agencies, but that's the world that we live in. Yep.
And I accept that. So I'm not going to say that I don't want the government ever to have their hands on this or anything else. I think what they're doing with Glasswing, though, is let's get as much of the big core stuff as we can, knock down all the stuff Mythos could find, and Mythos does appear to be the best tool at this right now.
It was built to find vulnerabilities and fix them, just write secure code. Let's let it do its thing. Let's get everybody involved and fix as much as we can for as long as we can.
I do know that there are others applying. I believe that number is probably greater than 40 now. I don't have inside knowledge, but I know people have beenLike shared requirements that they have to be...
There's security requirements around their access to the system and how they have to handle their security. They have already said they're opening it up to open source projects and maintainers of major projects. Let's knock down as much of that threshold as possible, because, Mitch, to what you said, even if there's better magic later, the magic we have for now, we can constrain to some degree.
Exactly. I do think it's an absolute s**t show for enterprises because we're so f****d. Because it's one thing for Apple or-- And even Cisco's got all sorts of crap going back however many generations and the other hardware vendors out there.
Like for enterprises, especially the large ones, reams and reams and reams of code. I don't think patching is going to... Because it's all off-the-shelf stuff.
It's custom code. But that's the point. Our whole security business has been built on finding bugs and patching them.
Yeah. Finding bugs and fixing them. Or until I can fix them, let me kind of wall them off or make them inaccessible until I can fix them.
And whether it's a finite or infinite amount of vulnerabilities that you're going to find, there's going to be a s******d more than we have now, and we have the ability to patch in a given timeframe. And I'll make one other say, there's probably some mathematics to the amount of people you add to Project Glasswing, to the likelihood or propensity that that code finds its way out sooner than we'd like it. The code can't find its way out.
Like- Well- ... they get to use the model on hosted infrastructure. You could steal probably all the Mythos code, but you still wouldn't be able to run it anywhere you want to run it.
Like, there's so much there. However, stolen token and somebody's quietly pretending. But they have controls.
I've got the screen up. Hours ago, I started to fill out to apply to make sure that my account is cleared so I can do security research with it. They're gatekeeping.
They're doing more. That's only going to last for so long. It's only going to last for so long.
I think they're trying to flatten the curve, to use that COVID term again. But, Daryl- Well, it isn't just about stealing the code. It's someone can not steal the code to run it, but steal the code to develop their version of it.
Or steal the API keys to- Or steal the keys. Yeah, exactly. So there's lots of scenarios about how that could be used and misused, abused, leveraged.
And then the other thing is... There's a reason why we have government, right? And whether you like the government or not, when things get so big, going to the moon in '68, '69.
When things get so big, you want some entity capable of managing this who, and also who maybe doesn't necessarily have a horse in the race or an ulterior motive, though government has ulterior motives, too. But I guess what I'm asking is, is Anthropic the right leader to lead? Well, they obviously developed the tool, but are they the right party to lead this consortium to do this in a way that is, A, secure, B, the fastest, most efficient way possible, because every second is going to count, of doing this?
Right? Of rolling this out and in essence, building a community around it overnight at the same time. They're going to have to create some kind of governance structure, sort of like a Linux Foundation does or something.
There's got to be some coordination. I'm not saying- You think there is? I don't know.
I don't know. I don't think so. Well, it certainly could fall apart and that couldn't happen.
It can go either way. One thing we know for sure, it's not going to be the federal government stepping up and say, "We'll lead this effort," and blah, blah, blah, because that's just not the path- No, I don't think it is ... the ethos that they're pursuing.
You know what, Rich? I remember going to a meeting in RSA in 2006 or '07. Jim Reavis was there with Hop and a bunch of other folks.
The CSA came together pretty quickly. Yeah, I think the- Mindset ... the problem is these businesses are not going to be willing to give up that level of control.
I think that- Yeah ... they're honestly... And even then, look, I don't think Microsoft is always doing a great job at security these days, but their response team does a really good job of cross-industry coordination and takedowns, working with national law enforcement agencies.
Anthropic here has already brought in Microsoft and Google. They brought their competitors into the fold as part of this because they understand the implications of this on a- Well, they're also covering their a*s, Rich, to a certain extent. Well, yeah.
Yeah. Let's be honest about it. This isn't all noble.
It's, "Oh my God-" They didn't suddenly become altruistic, no. Right. It's not altruistic.
But what alternative is there? Any organization you'd want to stand up, like us, like CSA or others, they're not going to hand this responsibility over to someone like us with a Linux Foundation or OS. Well, yeah, a foundational model.
Yeah. I think they're going- It worked for open source, may not work for this. I think for now and the speed everything is moving, and these organizations and governance bodies, you know how long those things take to- Yeah Yeah.
Moving even CSA, if you look at our origins, I've only been there full time since October, but to get to what CSA today is, is very long. It's almost 20 years. Yeah.
There will be roles for governments in regulation of AI later because more for social collapse and workforce-related issues than anything else. But I think for this, doing an industry consortium on their own, pulling everybody in, and you know what? It's their house, it's their tool, and fortunately, appears they're doing the right thing.
Or trying to anyway. Right? Rich, let's talk about that paper you wrote, I guess- Yeah ...
it was back in February, right? Right. And it has neutron star kind of- ...
of a flavor to it, where that's really what we're talking about. In a supernova, the core of the star remains, but everything else gets blown away, right? Yeah.
And a lot of choice, heavy elements and good stuff makes its way into the galaxy. So it's like the baby goes out with the bathwater. There's a lot of destruction in supernova.
Yeah. So the core collapse metaphor, I was looking for a metaphor and looking for something obscure. I've done weird ones like quantum physics and tidal forces, and for this one, it kind of hit my head.
I felt like there was just something there about a collapse and a rebirth. That's kind of where I started from. And then I looked at the math of core collapse, and what's wild about it is you have fusion in the core and it goes from hydrogen to helium through the elements, gets to silicon, which is funny, because I didn't realize it was silicon, was the last element where you can still have fusion, where the force of fusion is able to fight the force of gravity pulling in.
Then when it converts to iron, iron absorbs energy. It doesn't give up energy during fusion. And so you hit a certain amount of iron in the core, and as the rest of the fusions move out into different layers, it collapses in less than a second.
And then there's a shockwave, and it blows all the outside of the star out, and that's where supernovas come from. What's left? It's a neutron star.
It's iron. It's effectively, or a core of iron that's there. I thought that's a great metaphor for what we're facing here, because as we've gone, it's not a doomsday in the end of time, but it is the end of how we practice security for a long period of time.
We've done a good job. We've done nothing wrong. Our scan, detect, patch cycles, our incident response, threat detection, our responsive aspects of security have been the right thing to do.
It allows an organization, the business to move fast and allows us to do our best to mitigate risk internally. But now we're getting to a point where we can't react faster. And as much as we'd want to use the automation ourselves, it doesn't matter how fast we can automatically create a patch, because we can't let prod go down.
And it can't just apply any patch without prod going down, as has been proven time and time and time again. So what I think is going to happen is going to blow away a lot of crap we have in security that's just... It has some level of value, but it's not really a core.
It's like of what really helps, which is getting back down to security boundaries and segmentation and isolation. Those are the things that I think are really going to help us. Even moving into Zero Trust, I think that stuff's going to make a huge difference.
It's fundamentals we know how to do. And really because what it does is it forces the attackers, it changes their math. All of a sudden, they have to get through multiple security barriers with, there's not one vulnerability or exploit that's going to slice through everything.
So the math for what they have to get through changes and becomes more complex, and that will balance the equations. I think the danger that we face is, let's go back to first principles, which is great. I think that's absolutely a fantastic thing to do.
The things we know to work and build back. But that's the point, is I think we have to build back from first principles. It isn't retreat and kind of do what we used to do.
A, we have to use AI to solve the problem that we created with AI, because it has to happen at machine speed faster than we can do it. On the other hand, I don't think we can put all our eggs in one basket. This is a combination of the moon shot, Apollo 13, and Armageddon all in the same time.
We've got to have multiple paths to figure out how do we avoid the ultimate scenario we want to avoid. And part of me thinks that if we truly believe the rate of code creation is plummeting down in terms of what it takes to do it, you don't need a mass amount of people. You and I don't need 20 developers to go write an application or system or whatever we want.
Do it ourselves. As that races to the bottom and the effort and the sophistication of what you can do, you can make an argument that there's also some things we should be building a parallel infrastructure on the new way of doing it. So that we're taking advantage of not only what we know as first principles, but we know of how to create secure code, things like that.
So my point being, I'm not saying that's the answer. What I'm saying is, the point is, all the things we assume aren't possible, someday they will be possible. And those days, as for some of that, they may be very soon.
So let's think out of the box in terms of-Take some of those constraints away we still think we have, now how do we respond? And let's leverage our best minds that way, too. But Mitch, are you trying to change the engine while the car is on the tracks still?
I think you've got to. I don't think you can ride a dead horse if a dead horse is dead. No.
And also to play devil's advocate to what you said, Rich, is the same mathematics that work against us in the amount of code being generated, the amount of scanning or finding vulnerabilities that AI enables, and both of those will be turned against... We'll put up more pickets along the defensive line, but there's going to be more AI that hits those pickets faster as well. So what we're really playing is almost a delay game, saying, "Look, I'm going to put up as many...
I know none of these are perfect. I know none of these are going to stop it permanently. " But what am I buying time for?
Is the cavalry coming, right? Do I hear a bugle in the background and here they come? Or is it just inevitable?
Or- Well, I mean, it's homeostasis. It's homeostasis. " Yeah.
Or what we need to do to continue. And that, to this day, has been one of my favorite phrases. And if we look at this particular situation, if the bad guys destroy the economy, they can't make money anymore.
And the nation-states can't fleece the citizens anymore. Yeah. Whatever it is that they do.
So there's going to be a homeostasis. I think, and even what OpenAI said, there's going to be a rough transition period, which I think is true. I think it's worse than they're talking about.
Because what they're referring to is, going to what you said, Mitch, where there will be, we're generating massive amounts of code, but we're going to be using these AI agents to do the security assessments on that code after we produce it. I would not want to be a code scanning tool right now because these things are going to just pump out- No, those are history. Right.
Yeah. If you look at with the security agents sitting there and checking and validating the code right along the lines as we produce it, and it's the same AIs that are doing the attacking, it's going to balance out. That's for new stuff.
And I think that's what we're seeing right now, and that's I think what the focus of Glasswing is, is let's get to a better baseline. And they can't fix everything and everything, but if we can knock out the major operating systems, open source projects, and security tools, that gives us, as defenders, now we've got some anchors that we can work with to put in our security barriers. But, as I said in going to your infinite...
And Mitch, you're still on mute. Your infinite canvas, that's the enterprise and the large enterprises. They've got so much floating around in there that- ...
it's not going to be new code. So that's where rethinking defensive strategies. Maybe we'll finally do zero trust for real, which I think could very much help.
I think it's a continuous equilibrium that you're reaching. In other words, you're constantly moving to the next equilibrium of what you're capable of doing and preventing and what they're capable of going after. And it isn't just because you're working hard at it, it's also because the technology is changing fast enough.
The agent that does the security assessment or the fixing of whatever we did five minutes ago, tomorrow will be that much better than it is today. So the tools are advancing rapidly, very rapidly. So are you racing to a point of, okay, there's a point where you can't get any better, or is it still there is an infinite amount of space between here and infinity?
And I think that's probably more the answer. But I think a good point that you're making is not everybody can do that, right? Yeah.
No. Mitch's ice cream shop- And then the security- ... that has my home issue ...
poverty line computer can't do that. So, but I want to talk about two separate things here because time is short. Number one, the effect on the security industry itself.
We said the rules are changed, the game is changing. All three of us were at RSA, what was it, two or three weeks ago now. That floor, I don't know, 600 something vendors or so on that floor.
Well, besides all of them saying they do agentic AI, what's the likelihood of half of those companies being around in two- I think 80% go away. I mean, for two reasons. Generous.
Yeah, I mean, for two reasons, I think. I think one, legitimately, we only have so many dollars to spend on security, and it's going to be forced to move towards the things that stop the actual attacks that we are experiencing. Yep.
So a lot of these complex things and subtle things, and I'm going to buy this for whatever, that stuff goes away. The other side of it is, I think the floor to build and maintain some of this tooling is... Guys, we've all been vendors.
How secure was your ship? I mean- Oh, infinitely. Yes.
All of those products frequently relied on-Being in the environment where you could wall them off- Well, no, we were selling an appliance. So what if we got them from Dell? They were appliances.
Yeah. And it's a certain... It's going to force...
Now look, can you do it? Sure. I'm building, in my monitor over here, coding something up with Claude, and I have a security agent running alongside with my cost agent, my engineer, my architect, my designer, all of those running simultaneously.
What's coming out of that is going to be pretty solid from a security standpoint. You know what? " And there's going to be a lot of people who don't want to do that, Rich.
Yeah. Yeah. Well, they're going to have a hard one.
Therein lies the issue. What you're talking about is could we buy enough time to, in essence, recycle our entire code base in the world and recycle it in a secure fashion so that this doesn't work on it, right? Yeah.
That we don't wind up in these things. Here's the neutron star scenario, though, where you were talking about earlier, Rich, is probably none of us believe that's possible. So at some point, there is a winnowing of what survives.
Not every corporation that builds software, whether it's this insurance company or it's Cisco, whatever it is, not every company can survive. And you could even see a sort of a Hunger Games-ish kind of environment of saying, "We are going to pick who the survivors are going to be. We're sorry, we have to decide.
We can only invest in so many to help us make it, to create this next generation of infrastructure," or- This is sci-fi scenario ... yes, it is. And maybe it's a three-body problem.
I'm not sure what it is, but it may turn out, and I suspect it will be, that this is not everybody crosses the finish line. There will be some casualties along the way, and some of them will be self-inflicted. There's- Because it's not possible for it all to happen that way.
Though I hate to be the dooms guy, but it just doesn't seem realistic to me we're going to get everybody there. It's fine, though. So I was at a dinner with a bunch of younger security professionals, all cloud-focused people last year, and we're sitting at the table and they're debating platform versus product.
Oh, God. And is it all going to be the platform, or are you going to get the specialty product? Well, I got a knack for you.
" Uh-uh. " ... the what?
" And I'm like- Yeah ... oh, my God. They had no idea.
Yeah. And this was just- No, and that's why people who don't learn history are doomed to repeat it. And you're right.
But this wipes all that crap away. It wipes all that crap away. But let me throw a real out-of-left-field curve ball at you guys.
What about if some organizations say, "You know what? I've had enough of digital- Mm-hmm ... insecurity.
I'm going to go old school. Break out- Survive ... " Right?
And it may not be as efficient, but until I have more trust in being able to run my business digitally, I'm going to go analog a little bit. If this goes the direction we're talking about, that will absolutely happen. There'll be communities- Yeah ...
" Or wherever, in Longmont or wherever- The anti- ... in the world ... the anti-computer folks.
The anti, yes. It's going to be Nederland, Mitch. It'll be Nederland.
Nederland. Thank you. Or worse.
You dialed it in much better. I remember going up to Nederland when I had to play something Colorado. Dead Guys celebration.
But I'm serious. There were some left over folks there. " Well, if enough people do that, they can start to form economies.
Whether it's just trade or economy or whatever kind of things. There are people who have survival kits in their house, ready to walk out if the water and the power go out, and all hell breaks loose on the streets of downtown, whatever city you live in. So, is this going to kick this off?
Don't know yet, but it sure could go that way, I think. Yeah. I don't think so.
I think, again, going back to the homeostasis, the equilibrium to... We'll get through this. Because I don't think people want the alternative.
We're seeing that in other geopolitical areas right now where people are starting to realize the consequences of some of these certain decisions. I hope so, Rich. I don't want to make this about geopolitics, but I hope so, man.
Well, I think it matters if, do you have a breakdown that's sufficient? This is kind of the- Yeah ... zone zero, zone Z kind of scenario of power go, there's no more power anymore for some long, it's the same time.
There's no water anymore. Something like that that would really be massively disruptive to society. Now you've got a upheaval kind of situation.
So you got to believe, Rich, those conversations, Alan, are all about what are we protecting first? Yes, we need to do multiple things, but there's a Maslow's hierarchy of digital survival-And that we need to go after first, whether it's nuclear power, water, financial systems, blah, blah, blah. And to your point, it may not be the bad guys that do it.
It could be the models themselves that do it, right? Not to be too- No, no. But that- ...
paranoid So that's protecting from a point out, right? Pick the most critical- Yeah ... things and build out.
Yep. Don't you think that we need to have a government involvement at that level, some public-private partnership to make some regulation, cooperation? Maybe tax dollars have to go into this.
I don't know. We see that in Europe. Yeah.
Europe, with the AI Act and with their attempts to manage things, the problem is I think anybody of all political sides would agree that we have a fully dysfunctional here. And the problem is this is, the US is where most- But sometimes- ... of this comes from ...
you need a crisis to... And I hate to, again, be the clutching my pearls. But sometimes you need a crisis to bring, especially in America- I don't think- ...
you need a crisis to bring us together. I don't think it happens unless there's already a major collapse. Look at what's going on with our inability to address climate change, which is a crisis.
And I'm historically very pro-government, and I would agree with you. I think we're not in a place socially for us. And the reason, I don't mean to sound so ethnocentric, US-centric, but this is where most of this technology is coming from.
It's here and it's China, largely. Yep. And they're going to be able to control what they have over there, but it's a very different society.
We're not in a position, I think, to have an effective government response within the near future. And I think all this is going to hit before that happens. Now, if we hit some of these big collapse, even then, we saw even with what we saw with COVID, there's only so long.
So I don't know. That's such speculation. I think what we do know is the bombpocalypse is here.
It's coming. We've got the first alarm bell. Somebody rang the bell.
The British are coming. It's here. What can we do now?
And I'm not going to wait for anybody else to come save me. I'm not going to count on anyone else coming in. I think that's what Anthropic is doing.
" So we've got the xenomorph, and now we've got to figure out how do we best prepare the world for the release of the xenomorph, because someone else is going to steal their own xenomorph. And then it's just we know how that ends. So that's where we are today, and full credit for what they're attempting to do, and I hope it works.
It's not a full solution. They're going to flatten the curve a little bit on some areas, and I think that's great and that's a start. For the rest of us, we need to freaking wake up as an industry.
We need to do the things we know we can do. We can take concrete actions today that will dramatically prepare us and minimize the impact. So when every day is zero day, that's what we're heading in.
Every day is zero day. Okay, that's our starting point. We're now going from assume breach to every day is zero day.
And that's a starting point that we can look at. We can do things. We can- That's the new zero trust, right?
Yeah And as an industry, we adopted zero trust pretty much through and through, right? Up and down stack. And- You know, I want to throw out an idea.
Go ahead And this is not something like the answer is this. In a really weird, perverse way, maybe it's too late in the day and I'm having too much of what Rich is drinking. In a really weird and perverse way, we have a government response to this, and that's the tech companies.
They are a government response. Because they have the relationships- Right ... at the federal level.
" Well, the relationship there is power and money, government, power and money of tech companies aligning on those two factors. It's survival for the tech companies, obviously. If there's money at the government level and power at the government level, those things align.
You've got your government. I'm not saying it's the right one or a good one, but in a way, we've got that oligarchy. What you're saying is, Mitchell, public good and good for tech interests are aligned, and therefore you have that alignment.
And you're right. Maybe. There may be something to that.
Who knows? Yeah. No, there is.
You're also saying we live in an oligarchy, which I cannot agree with. That's what I'm saying. Exactly.
Yes. I don't think it's public good that aligns. Rich, you don't think we are?
I mean, I know we are. I just- I don't think our public- Let's not go there. Yeah Let me come back to the security industry.
I don't care whether it's Palo, Ford, Cisco, Google, and the Wiz, and whatever there is there. None of them are going to do this alone. If we're going to be successful, or semi-successful, as successful as we can be, this is where you need, truly, a security community.
You really do need to put down your shields a little bit to say, "Hey, it's a common good here. " Whether you're working at one of those companies I mentioned, or you're a CISO for a company in Baton Rouge, Louisiana, or New York City, we all have to band together hereBecause it's going to take that kind of effort. It takes a village- I hear you ...
to burn a witch. But- But here, it's going to take a world. Or a duck.
Yeah. But I think you're right. And you know what?
We have done this before. And when Dan Kaminsky and the DNS vulnerability, and I still have trouble dealing with that because he was a good friend before he passed away, and I remember him. He called me.
" That was the phone call. I hadn't talked to him in months, and I'm like- Wow ... " That was during the bat signal.
He probably called you. But that coordinated disclosure, we've seen rival companies come together before around some of these safety and security issues. That was just one example.
There have been others out there. So I think we're seeing that. I hope it just grows.
The problem we'll get into is that it does get into politics. I don't mean US geopolitics, like the enterprise politics of who wants to work with who and who gets to be in the club, and people getting jealous because they're not in the club and they're not big enough to be in the club, or every little startup vendor thinks that they're the most important out there and they should be in the club. We're going to be dealing through all that, but I do think at the core, there is a recognition.
The smart people... This is it. That report that I had somebody today in one of my little channels say was just a bunch of marketing, and I'm like, I read the technical details of that Red Team 8 report.
And does it have marketing aspects to it as well? Yeah. But I can't refute what's in there.
They brought the receipts. Exactly. They've got hashes.
We've heard this too from people. That the leak of it coming out early with the leak of their code, it's all manipulation. Guys, we're about out of time.
I'm going to ask you one last question, if you don't mind, individually. What are the signposts? What are the signals we will see that, holy s**t, this is worse than we even thought, or, you know what?
It's not going to be so bad. I think we could get in front of it. What should we be looking for?
Rich, I'll let you go first. Mitch, I'll give you the last word with it. For the, oh God, we're screwed, it's when stuff goes down.
I think that's if- But stuff goes down every day, Rich. Well, okay. So here's what I'm looking at.
If this shows up in an open model in six months, and it might, and we haven't gotten our ducks in a row, and we see widespread outages of banks and power plants and schools and hospitals, we're f****d. Then we're f****d. And then it's going to be...
This is a Y2K moment. It is. Except we don't have years to build up to it.
We have months. At best. How do we know it's working?
Because that doesn't happen. Because- It's the old security way, right? Nothing happened.
We're doing our job. Yeah. Okay.
Mitch, what about you? " We are solidly in s**t zone territory if that happens. DEF CON Level 1.
That's... Yes. You're now at the top level, so hang on.
Strap on, buddy. Yeah. Fair enough.
Rich, Mitch, I'd love to continue this conversation. Let's give it an AI time. We'll give it a week or two.
The world will change. We'll come back and take another look, and we'll replay this. You're right, Alan, because I think every couple of weeks, every month...
The whole Anthropic thing, I heard rumors about that. I had some people tell me some stuff, like at RSA, of things that they'd seen and debates going on internally at Anthropic, and that wasn't that long ago. And if I think about three months ago, six months ago, so I don't know where we're going to be in three or six months.
There's a veil in front of us. I don't think we can fully predict. I think we can see the shape of things.
I don't think we're helpless. I think it's very easy to get caught up in the, this is like a disaster thing. People, they vapor lock their brains because it's just overwhelming, but there's concrete things we can do here.
Let's get started, let's do the work, and we'll get through this. We're going to end it on that note of good news from Rich Mogull. Hey, thanks for watching.
Mitch, Rich, thank you. We'll be back with more, as I said, maybe in a week or two on this, but until then, we're out. Thank you very much.

