Breaking Barriers: Open Source, Cybersecurity, and Mentorship – Tech.Strong.Women. EP 43
In this episode of Tech.Strong.Women., hosts Jodi Ashley and Tracy Ragan are joined by Sal Kimmich, who shares her unconventional journey from government-funded research to open source and cybersecurity, shedding light on the challenges and opportunities for women in tech.
She discusses the increasing reliance on open source within federal agencies, the security considerations that come with it, and how category theory is emerging as a powerful tool for identifying vulnerabilities. Sal also highlights the importance of mentorship, the barriers women face in tech and her ongoing work recognizing open source contributions in science, art and history. Join us for an insightful conversation on security, innovation, and the power of community.
Transcript
Hi everybody, and happy New Year. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jodi Ashley, executive producer here at Techstrong, and I'm here with my co-host Tracy Ragan, creator and CEO of Deploy hub, and very busy lady when working with the Linux Foundation.
I'm sure it'll come up today. Before I introduce today's guest, I wanna give you a quick update about what's happening here at Textron. com, so be sure to go and check that out.
We have a lot of virtual events happening. Uh, predict 2025 is coming up. If this airs after that, you can go out and watch it on demand, and I would recommend it.
It's gonna be an awesome virtual event, so you wanna be sure and check it out. com and be sure to tune in every day to Techstrong TV for great shows and interviews. Okay, Tracy, it's 2025.
What's on your mind today? So, over the Christmas holiday, I, I, you know, I, it didn't do a whole lot, but I would still watch kind of news coming across, particularly around cybersecurity and Space Force because it's something that I'm particularly interested in right now. And this, this article came across about the DOD and, um, you know, tackling Weapons Cybersecurity, and it talk, it talked about, you know, that there's work that's being done to address cyber threats all the way down to like code level.
But something in that really bothered me and it said, let me see if I can, I'm looking at the quote. Um, basically it said that they know that there are, uh, vulnerabilities out there, but they're willing to take the risk not to address them. Um, I'm not sure why that would be the case.
I don't understand it, uh, because it bothers me that we can do better. And even in weapons security, I, I, I feel like there is a lack of real understanding what these vulnerabilities are across the whole spectrum of cyber security. So to just say, you know, the, the risk is there, we understand it, but we're gonna move forward anyway, um, is kind of a bother.
It kind of reminds me of the recent fires in, uh, California, that area, Pacific Palisades that they've been, they've known for quite some time that it's a high risk area for, uh, flooding and fires. Uh, but we did, how much did they do to, to, to make sure it something as catastrophic as a firestorm didn't happen, or how, how prepared were they? So I feel like we've gotten into a, a place, maybe this happened in 2024 or maybe it's always happened that we're complacent when it comes to, um, predictions, right?
Predictions about what could happen in Weapon cybersecurity and saying, we can take the risk even though we don't know completely what we're talking about, we're okay with taking the risk, or is there something more we could do with protecting something like the Pacific Palisades from Firestorm? So it, it bothers me and as, as we go into 2025 with Gartner predicting a tripling of vulnerabilities, I feel like we've just been bombarded so much with these kinds of threats that we're just, we're numb to it. So that's my concern for 2025.
And I, I feel like it's a discussion that should be had within all organizations right now about how proactive we need to be. Yeah, I can imagine reading that drove you bonkers. It was kind of shocking, right?
It was like, Yeah, something like Space Force Sa something like Space Force, you know, that a general would say, you know, I accept the risk without any clue of what they're, what I'm actually accepting. I'm just gonna move forward. God knows what's gonna happen in 10 days.
Well, the people who are attacking us are not that complacent. They're on their toes, right? Yeah.
So we have a formidable, uh, uh, component, uh, component opponent out There That we need to be serious about. Yeah. But we have an incoming president who wants to change his mind again and move Space Force to the state of one of his cronies.
Like he, before, before the last election, he was moving it to Alabama and then Biden said, no, it's staying in Colorado. Which obviously I pay a lot of attention to living here. And now he's talking about moving it again.
So let's not focus on the secure side, let's focus on moving it and wasting a ton of tax dollars in the process. But that's a whole nother conversation. Yes, It is.
All right. Well we have a really cool guest today. I would like you to introduce you to Sal Kimmich.
Is K it ick or kimmich? They're both good. They're Both good.
You want say I like to say it right though, so well welcome and tell us a little bit about yourself. Yeah, actually, um, it's probably, I'd love to dive into a little bit the commentary on the DOD. Um, so I have a pretty unique background in and with open source in that throughout my career I have inhabited almost every profile of an end consumer that you can map.
So I have been an consumer in a federally funded program between both the US and the uk. I have been a machine learning engineer working within the DOD. So my first contracting role in DC was with the Missile Defense Agency.
And then I moved to go work with the US Air Force, their Kessel run software incubator. I then only left security clearance because I got married and moved to the uk and I did ask, can I work remotely for this skiff in a foreign country? And they said, no, obviously not.
We read the contract, you know how this works. Um, so I jumped into for the first time the corporate layer of open source, uh, which is generally what most people get exposure to if they're using advertising or marketing to understand it. That's the only layer that they'll ever experience.
But it's really, really important and we probably should dive into why they would accept vulnerabilities, um, in the DOD specifically, uh, because it's changed a lot in the last five years. And I think that's really positive the ways that it's changed. Um, so if you are an end consumer of open source as a federal developer, there's a couple of really interesting things.
So number one, you're never going to upstream. If you upstream once onto the thing that you were consuming in the last couple of years, you would not just immediately lose your job, you would lose your security clearance, you would never have a career again, right? And it's not one or 3% of open source consumption that is specifically in this case, federal.
We're not just talking about the larger and global government consumption. That's a different number. And that varies particularly by the European country that you're dealing with.
And they've got government style OPOs in order to be able to engage with it. But I had someone come up to me at a conference earlier this year, it was someone really early in the career, and they did ask me this question, what percentage of open source consumption do you think is federal? And I was sitting at a table with a color, couple of other open source leaders and I said, Ooh, it's literally impossible to know that answer given the design of the system.
But I would estimate somewhere between 30 and 35%. And then the only reason why I'm willing to say that publicly as something slightly more than a conjecture, even though that's all it is, there's no stats. I then turn to someone who works in a major corporation that I know has not just a general osbo, but a specific federal osbo.
And they did not speak a word, but they did give me odd and a shrug as if that is about correct. Right? So for every two of the developers that developers that you're thinking about consuming it and upstreaming to open source, generally there's one that is consuming that information and has to have alternative pathways of communication, mainly regulation, in order to make sure that those things are secure.
And I think this is really, really interesting when it comes to security vulnerabilities at the supply chain. So the first job that I ever took coming out of security clearance consumption and coming into the open and general corporate layer of production and open source was specifically sonotype. I did that because I think that they have a really, really interesting and pretty direct approach and engagement.
They are really focusing on making sure that they can secure that supply chain or that end consumer class. Now, I think in order to not be so afraid of vulnerabilities as they exist on the internet and on platforms like GitHub and GitLab, you have to understand that all of these things are built over kernels. And there are many different kernels.
I've mostly studied and investigated the Linux kernel. There are other kernels as well. And even the Linux kernel is not a single kernel.
There's about seven of them that are really, really important. There's three of them. There's like the main line, the main kernel, which most people generally use.
And then there's a long-term kernel of which they're very, very sincere in making sure that no vulnerabilities come into place. And then number three, when you're dealing with vulnerabilities and open source, you have to become extremely familiar with understanding the zero day marketplace. So when there is a critical vulnerability that has been observed and been highlighted in the days and sometimes weeks before, a zero day, a zero day just literally means you have zero days to patch zero days.
That's what it means. It is bad, it's immediate, and it's pervasive. Um, and so when you received a zero day vulnerability, you have to understand that all of the work has already been done to secure the critical infrastructures that you depend on.
Now this is not just the DOD, these zero days and the work done before the zero day hits. Public and corporate are protecting things like major cities, water filtration systems, those largely run on things like Kubernetes these days. So I think that's really interesting to dive into and to to consider.
It's a very different world of open source. Um, but it's increasingly important. And the nature and the style of leadership within the DOD has changed.
This is not so much due to the leadership in the executive branch. They are separate, but it has changed because of one very, very specific condition. Uh, this is the fact that generally, depending on the country that you're dealing with, it takes exactly four days of unlimited assault onto a foreign territory before you go into a condition of what is defined as protracted war.
When you're in protracted war, you begin to engage in a very, very different series of process, specifically in the chains of command within DOD, so that you can be highly responsive to it. So that's had an impact on the way that open source interplays with it. But also there's no difference in the actual nature of playing with the human gen like DTUs that is open source.
You have to use it because it is where the progress is made. You have to use the intelligence of the commons in order to get the right answer. And then you have to set up additional processes to make sure that is maintained as secure.
Um, so I, I really enjoy watching that space. And I also really now getting to watch it from afar. 'cause I'm absolutely just engaging in the corporate layer.
Um, which doesn't typically have this kind of insight once you're in security clearance, unless you leave the country, you're probably gonna be in security clearance the rest of your career. But in the, uh, Gartner, uh, report, I, uh, I only read snippets from it, it said that 58% of they said that code level vulnerabilities would probably triple with about 58% going after government and cyber infrastructure, right? Our, you know, our utilities, our, uh, healthcare, the, the, the infrastructure, the technical infrastructure that we depend upon, that's where those vulnerabilities will be targeting.
Um, and I, you know, I, it would be a curious thing to be able to get an SBO m from every single one of those cyber, uh, kind of infrastructure teams from the code they're delivering and look to see exactly what's what, what open source packages they're consuming, because those you would think would be the most then critical ones that we should be monitoring. You know, and at least minimum require for those teams to have an open SSF scorecard, right? At minimum to show that they have some commitment to adhering to security policies.
It's a, it's a, it's an interesting topic and I think that, um, there's part of us, and I'm reading this really interesting book, book called Sapiens and it talks about how we um, as our brain kind of developed, what drives us, A weird one is gossip and fiction and it has for thousands and thousands of years. Sounds About Right. I know.
And we will believe anything we choose to believe, right? So it's easy to say, that will never happen to me. It's easy to say, I can excuse those risks 'cause I don't believe it will ever happen because we wanna believe in fiction and if somebody tells us we're okay, even though we may know the data shows differently, we're gonna believe what we want to believe.
Really interesting right now. Now Sal, you have a PhD? Uh, yes.
Interesting story. I don't, but I can explain why. So, um, so I, most of my undergraduate training was funded by, uh, the National Institutes of Health.
And it included both a total consumption of my cost. So it included everything down to my rent and my healthcare. And then I was immediately positioned to do an accelerated PhD, PhD between the US and the United Kingdom, specifically working on real-time signal processing, um, for medical interventions for the human brain.
So I have this great and interesting background and one quick note there, if you can get one of these unlimited, uh, government funded undergraduate degrees. I went and I checked the contract that I was signing and it said, we will pay for all of the classes that you need to complete your degree. And I said, wait, is this limited or is this unlimited?
And I found out it was unlimited. So I in fact left my undergrad with two majors and two minors because I didn't have to pay for them. I could just pursue it as true education, much more European style.
So I got a degree in cognitive science with a focus on neuroscience where I was doing all of my statistical work. And I got another degree in political science with a focus on public law. I really enjoy.
And I find it very interesting to look at history from the perspective of codified law because it gives you much more information about who is in power, how is that power tit and how is it maintained or lost. You can do that by analyzing law much better than you can by sociology. Um, but then I jumped into this accelerated PhD, so it was a three year minimum.
I already had a first author paper route and if you wanna look at anything from my security clearance or my academic background, just don't search sal, search Sarah, SARA, I go by Sal because I asked mechanical Turk what three letter moniker was easiest to remember and signaled authority. And then I used that in order to enter open source quite literally. And when I, when I look at gender and pronoun dynamics, I really, myself, personally don't care.
Any pronoun said to me with respect will be treated with respect. However, generally if it's in writing, I'm going to prefer they them because I don't want to be indexed into a specific profile that could have a bias and an algorithm. And 100% of the time, if I'm pursuing a promotion, I will request that we use he him pronouns.
Not so much because I believe there's gonna be any bias from individuals that have previously worked with me. But because it's very likely that there's an internal system that is relying on an algorithm that probably does have bias. So let me just bias it in the right direction for myself.
But here's why I don't have a PhD. It's a great story and it comes from a very good mentor. So I had two different mentors.
I had one at the signal processing lab at the National Institutes of Mental Health in dc technically Maryland. Um, and then I had another mentor who is the head of the art and sciences, uh, section of the University College London, who was generally just there for life advice. And, uh, I had put together a online course that taught about a thousand people how to, uh, put together a machine learning pipeline specifically for brain imaging.
And if they completed that and they did a peer review style, uh, or prepared for peer review style paper, then I got AWS open source to fund the credits for them to be able to complete it. I got that done, I put that out online and I immediately started getting inbound requests for jobs. I turned most of them down 'cause I didn't find them interesting.
But there was one job that sounded very interesting because for about four months, the CEO just kept on calling me up and we would have discussions about potentially what I would do if I went into security clearance. 'cause I was not interested and I had to be convinced. Um, the CEO was also previously a, uh, a, uh, fighter jet pilot.
So very interesting because they were leading based on the profile that is impacted by the end consumption of open source, right? Very serious. They know that if they get this wrong, right, if we mess up this vulnerability chain that will result in a death, right?
So sincere and that kind of leadership style is much more available in systems outside of the corporate space. Um, and I always look for it, but the reason why I don't have a PhD is because my advisor on the UCL side, I said, okay, unfortunately I really do think there is a job here that I am inspired by and would really like to do. And he said, Hmm, how much money are they offering you?
And I said, this much money. And he said, oh, okay. If money matters to you, I need you to know that that's more money than I'm making right now.
I said, I, I think that matters to me. And then he said, okay, you know what? Go do this.
Go do this for a year, 365 days from when we stand down your PhD research. I want you to send me an email and let me know if you wanna come back and finish. And, uh, I remember the day, 'cause there were moments in and out of my first year of getting involved and stood up in federal software production where I didn't know if it was the right fit for me.
And uh, but it happened to be that on day 365, I was working remotely in Barcelona that week. So I wasn't producing code that week. I was just attending internal meetings.
You cannot produce code outside of a skiff. But I was doing a like semi vacation working on a beach in a foreign country. And I thought to myself, I can do this while making more money than I would make in literally the highest leadership position that I could ever possibly get into in open, in, uh, in academia.
Uh, so yeah, it's just because money mattered to me and because I had been able to raise the signal on all the things that are important to a corporate producer or to a security clearance producer. Can you demonstrate that you can do the work? Yes.
I already had a first author paper out, so I didn't really need to wait. I had already gotten it done. And then number three, can you excellently communicate and propagate not just your understanding of the topic, but the ability to actually do the topic to other people.
Now if you have those three things, it makes it very easy to get a very, very good and interesting job because there are so few people with that combination of skill. And um, yeah, sometimes I fantasize about going back to academia, but I just cannot pull myself to do it. 'cause it used to be that I had to be in academia 'cause I needed access to supercomputers.
And I really particularly love the supercomputer at NIH because if you work in this space, high performance computing of any type, you know, that our clusters are called, uh, bale wolf clusters, but not at NIH. We named them bio wolf clusters. And I'm very get overthinking that.
I I just love that. Um, but, uh, we've Had a very interesting journey then into employment as a woman in tech. You know, it has so many avenues and I don't think we've heard this avenue before.
You know, that you Yes, you basically did. And the, um, the idea of getting, basically getting your education covered. Mm-hmm.
That's amazing. So how did you find out about that? Did, did you just stumble across it or did somebody point you in the right direction?
Yeah, well I had very sincere financial need. Um, so I was looking for the best opportunity out there. And I got involved in research the second that I got to school, quite literally the first quarter of my first year as an undergraduate, I went to uc, San Diego.
And, uh, there was a professor there that was doing research on the cognitive design of cockpits for Boeing. And I myself am a pilot. That's why I'm always interested and have a portfolio that keeps leaning into aviation.
Um, but uh, they had shown us some transcripts that I just knew could not be correct 'cause you have to use alpha numerical when you're talking to a, uh, a control center. And I said, Hey, I think I can just correct these for you. Um, and that was how I got involved my first year, my first week of undergrad in research.
So it really, and and, and this is true. So when I, you have to be so sincere about research itself. All of the classes that you ever take at any university that you ever take, you will never be better than everyone else in the room.
And there's already gonna be 30 of you or 300 of you. But when you're pursuing research, you have the ability to see if there is knowledge that needs to be redu produced, go and pursue that knowledge and then share that knowledge as widely as possible. So the first study that I was ever published on was on, uh, cockpit design of Boeing seven 30 sevens.
And to this day, in my own consulting work, I use that all the time. I typically go and I'll speak to like mid-sized banks or something that has a critical service to it. And I simply explain to them this, you now exist in a world where you had site reliability engineering and you understood that that was real time.
But as we think about cybersecurity and the conditions that we have been growing into, cybersecurity is now a real time event. It has to be acknowledged in real time. It has to be patched and as near to real time as possible.
So I go in and I will teach them to use their dashboards like a cockpit combining both SRE and cybersecurity whenever possible. But here's the second layer of that, that's really important, especially if you're paying attention to say the Cyber Resilience Act right now. Um, there's something different about aviation than software and I think these are going to converge.
We're gonna create a thing like a com, like a compliance crap. It's all gonna look the same at the end of the day as this evolves. So if you are in a commercial aircraft, you're gonna have a black box.
If the thing fails, there is going to be a perfectly preserved audit log that should allow them to understand exactly what went wrong. That is essentially the ask of the CRA. They need you to have a verifiable and reproducible audit log of your cybersecurity methods and operations.
And you should make that as automated as possible and work it into your operational design. Um, and I'm super excited to see that. 'cause I think that's really important work.
And when I look at the way that compliance and regulation are evolving for software generally for open source to some degree specifically, but generally in the sector, I do think it's really appropriate to go look at the past 50 to 60 years of aviation compliance and understand how similar those things begin to look. I could not agree more. You just de just described what we've been doing at our and Deploy hub.
We used to call ourself the black box of software because the problem is is that the, the, the pipeline itself for every c when we were doing monolithic, we this argument, uh, didn't hold as much water because everything you did in the pipeline related to that one software solution that you were delivering to end users in one big monolithic ball, right? So you could have a black box, you could see, you knew where, at least where the logs were. But when we're fragmented with hundreds of microservices that make up a single application, that black box is a hundred black boxes.
It nothing is, nothing is centralized. And you don't know if they're all, um, living by the same security compliance. You don't, you have, it's very hard to see that.
So centralizing this kind of data in, in the way you just described should be applied to every piece of software that we, we push out the door so we have a full view of it. And it has to be versioned. It can, it's not just for the application at the time that it's executing, it's over.
It's the history that gives us the insights. It's the change, right? It's the change that shows what went wrong.
Mm-hmm. Um, so yeah, there's so much to be done in, in software for this discussion. We recently, this continuous delivery foundation, of course I'm pushing it recently started a new SIG called the CI/CD Cybersecurity sig that we're really gonna look at models because pro, part of the problem of building that black box is that DevOps engineers don't necessarily have time to go figure out what they need to add to every single workflow.
And this is going to be a manual effort to build that black box. We gotta make it easy. We gotta make a, a model that people could say, here's a an example plugin that I can use.
Here's an example command line interface that I could use to generate SBO for god's sakes. Something as simple as that. So I'm glad that you bring that up because it is incredibly important for software as we move forward.
Now I wanna talk about your background. You said you were in Barcelona, but now you are in Italy. Tell us what you're doing in Italy with uh, awarding open source.
Okay, well first off, I think I do a lot of personal travel now because when I was on government funding as an undergraduate, the one thing they would not let you do is study abroad. They'd let you go study at MIT in the summer, but not abroad. And I wanted to see the world.
Um, so, uh, for the last three months I have been here in Kunio, Italy, which is not a well-known place, it's not a very large town. It sits on a wedge in the Alps. Uh, and it's extremely protected traditionally from uh, like land attacks.
Um, so I came here 'cause I was really interested in this place, which is well known to people that study sovereignty as a physical location where this city itself has remained sovereign to both political influence and religious institutional influence, which is very unique to Italy. Um, and to kind of just observe that and understand that. So I'm here 'cause I'm doing my own midlife study abroad, but um, I'll point you right up to the ceiling real quick because you should be able to see it.
Beautiful masterpiece. Absolutely. I know, I thought she was sitting in the Sistine Chapel for a minute when she, when she logged in.
I'm like, no, that's actually a real room. Yeah. But, uh, that was commissioned by the family, the body family in the 17 hundreds.
That's their crest right behind me. Um, and uh, I came here specifically because, you know, I've, I've got insight into the government layer, government consumption layer. I've been working in the corporate consumption layer.
Um, but there's something that everybody forgets and it's that open source is also just incredibly fun. Um, when you look at vulnerability, sustainability, maintainability, you have to recognize that these are all building blocks and some of them are created specifically to be supporting critical infrastructures. Those are well protected.
Those are well maintained. They'll be sitting in something like an antitrust. But there's a lot of one-offs, really interesting things that are produced in open source that aren't meant to have a general audience.
And if they are, it's a very small audience. So we're doing a series of awards. I'm working with Art Farrow on this and I'm waiting for whatever his videos come out to be.
'cause I said the one thing I'm not is creative. You do that part. But, um, we're doing a series of awards based on every single Greek muse and we're gonna go find the open source, either project or committed commit, uh, community, um, that really aligns to those values.
Are you working in science? Are you working in art or music or in historical preservation? Um, if you're doing something like that in open source, I think it's really important to remember that that whole world still exists.
And then to also understand this, um, it's very, very true that there's an absolute alternative to burning out in anything. And you can call it something very simple, just call it burning in. Like stop paying attention to your retention statistics at a corporation.
Pay attention, right? If they're about loss, really pay attention to what is it that you're doing when you're doing it right. Um, and one of those things is allowing people to have and to develop their passions with technology.
So I'm using this opportunity as a time to help to highlight people that are genuinely showing something that is so passionate that I find it interesting and inspiring and worth sharing. I have one last question before, 'cause I know we're gonna run outta time, but I really have to get this question out because if there is somebody who's watching this who is an undergrad, which I hope they are, how did you find your research project and was that a government grant that the, uh, uc, San Diego was involved in? Yeah, so I, I mean honestly I started applying for funding in my first year.
Whatever I could find, like, is there an associate, so You yourself were looking when you were applying for funding, where were you applying to? So I started at the institution and then I started looking, uh, specifically into my uh, degree program. And I started going and getting the professional level education that you need and pursuing external organizations.
So two things that really helped there. I was working with the cognitive science department and they had a bursary that was available exclusively to graduate students to support their research with training. Okay.
It's not exclusive if you go and ask. So I went in and I got some funding to be able to pursue independent training. That's how I got connected originally with the Martino Center outside of, uh, or in Boston.
And the, uh, like brain, uh, and Cognition Institute from MIT. Um, so I went and I pursued education that was at one level higher than what was expected for me at my level because why would you wait to get it done? And then number two, I just break through whenever I see an arbitrary gate being kept closed and I will ask the questions, what are the conditions by which I can open this gate and I will ask it to the person who has the door locked.
Um, one of those conditions was very important to me. Uh, so I really wanted to join the association for the Scientific Study of Consciousness because I was studying real time interventions using FMRI brain imaging. Um, and I was told at the time that, that's great.
We'd love for you to participate in our student committee, but that's for graduate students. Now, one year later I show up to the same person who helped me in my PhD as well. I show up to the same person who had that door locked and I said, hello, I am still an undergraduate.
I have full funding, not just for myself but for my research. Does that satisfy the condition of being a serious researcher in this space? They said, yes, they let me join.
I was immediately working with the professionals in that field. Um, so go and look at gates, see if they're actually closed, see if you can get them open and if they are closed, make the conditions discreet, get them in writing and see if you can fulfill them. When you're fulfilling those conditions, great, you're done.
You're set. Now there is another thing that's really important. I pursued biomedical research.
So in order to do that with human subjects particularly, you have to be working under something that is called an IRB form. So the in Institutional Review board, um, I have occurred of many undergraduates old in one of those themselves under their name. But I was pursuing independent research.
I was creating my own research designs and then using the funding to get the data done and then to produce those methods. Um, and that worked. I just didn't tell myself that any of those were conditions just because they're arbitrary and they exist to satisfy a societal expectation of when you'll be ready to produce intellectual property.
And if you're pursuing open source, you're ready already. It's why you're here. Um, but one thing's really important because it's mentorship and I know the best mentor that I ever had in life was Dr.
Lisa ier. Uh, uh, Dr. Lisa Eiler, uh, from the VA hospital in San Diego.
And I remember going to her early on and I was shopping around and asking every single lab that I went to, do you think I can get a first author paper done as an undergraduate? And I had some people actually laugh in my face when I said, that doesn't matter to me. That's just a closed door.
I'll knock on the next one. But I went into her office and she said like five words to me that were so powerful 'cause I had never heard them before. I've been well supported, well coached my whole life, but no one had ever just said about something I wanted to do.
You can and I'll help you. So simple. But that's not something that women hear.
Women versus men are much more likely statistically to hear a no when making requests around funding, when making requests around promotions, all of these things. Um, and she just recognized something burning in me, the fact that I was really burning into consciousness studies and to modeling and interacting with consciousness as a computational design. Um, and she fully, fully supported me.
And I will always be grateful for that. And it's something that I make sure to say explicitly to anyone that I am mentoring, find out exactly what it is that they wanna do in life, see if I can support it. And then I do everything in my power to do that.
Sincerely, You can and I can help you. Those are very, very powerful words, right? Mm-hmm.
That's amazing. Absolutely amazing. It, you know, we hear, uh, the journey of women all the time and mentorship is always at the core of very successful.
Absolutely. Mm-hmm. That's what we hear.
And it's not just mentorship from other women, it's mentorship from men as well. Mm-hmm. Yes.
Mm-hmm. Yes, absolutely. Men are part of the solution.
They are so much part of the solution. Yeah, they're also part of the problem, but that's Yes. Yeah.
Yes they are. And I don't know how much time we have. Yeah, we're pretty much there.
You ladies. Um, Can we just ask a question? Yes.
You ask your question Recommendation. What is a book recommendation? Tracy?
Always that recommendation. Uh, so there's two books that are super important. Um, actually I have one of them sitting right over there.
It's, uh, cybersecurity for Generative Systems. It's very good. Um, another book that you should read if you're really interested in understanding the state of cybersecurity is, uh, the Cyber Deception book.
So there's a Cyber Deception 1 0 1 book. It comes out for um, FinTech services, uh, about every two years. And it basically explains how you create honeypots and artificial systems in order to observe adversarials attempting to get into your system without letting them do it.
Um, that still is incredibly important work and it's one of the most evolving areas of cybersecurity because now it's just agent on agent artificial intelligence. Um, but I do wanna jump back to one thing that I think is really important to consider and think about, especially at the corporate layer for vulnerability, uh, analysis and awareness generally. There's two approaches to it that we can take.
One of them is the one that most people are currently taking and it's basically doing a scan semantic analysis and identifying either the vulnerable project or the vulnerable code snip, uh, that's incredibly computationally extensive and it may also encourage people to be pursuing a vector of com of compound vulnerabilities. Always remind people that log four J in itself was not a vulnerability. It was a compound vulnerability when in place with JNDI that made it harder to catch for a while.
Um, but there's another approach to this that is entirely different and it is using category theory in order to find those conditions. So applied category theory is a way to begin analyzing vulnerability. Uh, and it would allow you to find categorical conditions and to avoid not just a single code snippet, but to actually be able to see, and when I say categorically, it means we have set condition A feeds to set condition B feeds to set condition C.
We now know exactly how many projects have that logical, substantial backend and we can remove that vulnerability. Whether or not it looks the same, we can remove that logical compound across languages, across semantic complexity. That's a direction that we absolutely have to go into.
And it's not something that is a far out there idea. There are some r and d spaces that are looking into this. And you must understand very importantly that this is an idea that particularly the US pays attention to NIST organizational design.
All of the things that it gives down for us to be compliant to are to be a CT compliant. So if you're interested in this space and you wanna understand and start thinking about it, then go to the top of the supply chain. Well, mental chain of understanding.
Can we categorically provide the best solution possible? We're gonna do that with applied category theory. It then comes down, it gets right now interpreted into a semantic language that we're communicating out and that's where there's a lot of lossiness in communication 'cause it's human to human communication.
But if in the next 10 years or so, and I always say apply category theory is the answer to everything, we just haven't found it yet. And that is so true. Um, but if we can close that gap, uh, we're gonna be able to avoid those conditions, not just in the current reality of production, but also moving into a quantum compute reality where they also will be able to have a much more efficient way of scanning if they're doing it as an adversarial.
So we want to make sure to categorically remove those logical conditions moving forward. And that I think is the most interesting area of cybersecurity right now. Wow.
Thank you so much. Um, that's a great place for us to wrap today and we really appreciate you being here. Tracy, you got anything else before we wrap this?
I'm just glad she mentioned Quantum. Yeah, I know you're into that too. All right, well thank you so much for being with us today, Sal.
And thanks to our audience for joining us for another, um, fun filled and very technical episode of Up Techstrong Women. Um, we're excited you were here and as I said, keep watching Techstrong tv. There's a lot of lot more shows to watch today, so stay with us.
Thanks again. Have a good day.

