AI Agents Rule
In episode 855 of Techstrong Gang , Mike, Tracy Ragan, Jack Gold and Jack Poller discuss the degree to which IT platforms may need to be re-engineered for artificial intelligence (AI) agents before marvelling about how a company could fake writing code that was supposedly written using AI tools.
Then the gang takes a look at how flaws in Google browsers running on Android devices have been abused by Meta and others to invade privacy.
Transcript
Hey, everybody. Happy Monday. AI agents Rule.
You're watching text. Hey folks, welcome back and once again, happy Monday. We're talking about some of our favorite topics, DevOps and security.
I wanna introduce our gang members for the day. We'll start with Tracy Reagan, who is, um, the most senior member of the team these days. Tracy, how you doing?
I'm doing fabulous. How are you doing today? Actually, I'm doing really well 'cause we finally don't have rain in New Mexico, which is a weird thing to complain about.
So I might get outside today. All right, well, that's awesome. Um, it's a gorgeous 80 degrees here in New York.
Maybe, probably won't get much higher than that, and that's probably the best we'll ever expect Jack Gold. How are you doing? I'm doing well.
And Tracy, you can have some of our rain. We're getting lots today. We've had so much rain for New Mexico.
It's just weird. All right, Jack Gold Getting dge today with thunderstorms. It's not gonna be fun.
All right, Jack, go. I forget where you are. I'm in the Boston area.
All right, well, uh, I'm just down south of New York, so hopefully that all just went around this 'cause, you know, that seems to happen a lot. We duck and you get hit. All right, and then finally, Jack Poller.
Good to see you again. Jack. How are you?
Uh, doing pretty good. Good to see you again. I am actually currently at the Universe Conference in Las Vegas.
So, uh, I'm over here in the very hot weather. You know, it's, uh, gonna be 95 to hundred here, so I'm not going outside today. All right.
Don't, I don't think I've been in Las Vegas in months and I'm trying to keep it that way, but I know that record will come to an end sooner than later. Hey guys, let's just jump in here. io is talking about how they built an observability platform that is designed from the ground up for AI agents.
First. Doesn't mean humans won't use it, but it's an interesting premise. And there's also a startup called, uh, age annuity that is says that we need cloud infrastructure that is designed for AI agents and both have the same fundamental premise is that the scale at which AI agents are gonna be using infrastructure is much greater than anything humans have done so far.
And so therefore, just about everything we have is gonna break. Tracy, what's your thought on this? Are AI agents suddenly the primary users and we're kind of secondary, uh, supervisors?
Uh, I would hope so. To be honest. Uh, this is a perfect application in terms of in my world, in the DevOps world, uh, for ai.
Uh, you know, we've had these observability tools, which have been super, super useful. We need them. We need to understand transactions.
We, we have to have this data. But the problem is, is that there is so much of it now that it's hard for a human to do everything. It's hard for a human to address everything, and systems need to be more self-healing.
So if we have AI agents being the primary customer of this observability, then we can take it to the next step, which is, okay, we know we have a problem now what do we do Now? I think that there will be a, a bit of a pushback on this, to be honest, because I don't know if the trust in AI is there yet in order to really create these, uh, you know, make, make the observability data actionable. Uh, I see this in, um, you know, software de bloating.
I've been having conversations with people about software de bloating and auto remediation of, of DevOps scripts. And this kind of fits into that area where we're using AI in a way that de that developers who have been the, and operations people, DevOps engineers, platform engineers who have been the controllers and making the decisions, we're handing that off to an AI agent and letting the a agent make the decision. So we will have to change from a cultural standpoint to have trust in these types of systems, but I don't know if we have, uh, another option because these systems are gonna be so big.
Uh, we have so many things happening in so many places. We have AI infrastructure, we have Kubernetes. We will need better monitoring, better observability, but we will need actionable observability and we'll need something to do that action for us.
So it's an evolution of this space. Uh, it doesn't surprise me. com, it doesn't surprise me where this is going because humans can't do it all.
It's, it's essential. Mm, Jack gold. Are we just gonna have to reinvent all of it to accommodate these AI agents?
That's a great question, and, and it depends on who you talk to. Some people will say, yes, I happen to think not. I think it'll be more of a modification.
Uh, one of the problems, and, and Tracy this gets to your point, um, is do we trust AI and agentic AI to do the right thing for us all the time? I think there's still going to be a need for IT folks as overseers, maybe not having to delve down really deep into the, into fine tuning stuff, but I don't think we get to a point anytime in the near future where AI just takes over and we don't need IT folks anymore. So it's really, in my opinion, AI and I, I, I've used this term often in the past.
I look at AI as assisted intelligence rather than artificial intelligence. It's an an advantage for us to use to make us more efficient, but not necessarily to replace us in everything we do. Jack Paul, and what's your level of comfort with all this, especially from a security mindset?
Uh, I'm actually getting more and more comfortable because I think we're now operating in a scope and scale that humans can't possibly operate at. Um, and we've already done this. If you think about intent-based configuration, we've already gone from humans at the keyboard logging into each and every individual component in an IT infrastructure to simply say, this is how I want the ID infrastructure to operate, and then having automation go and do it for us.
And we've, you know, that's, that's really changed how we can do things. And that means, rather than a human managing, you know, 10 to hundreds of computers, we've gone to, you know, single humans managing thousands to millions of computers. Uh, you know, when you are a hyperscaler Google or you know, AWS or Microsoft, you can't possibly do these things manually, uh, nor can you do the observability manually.
So you need tools and automations to do this. And I think what we're doing is maybe conflating automation with artificial intelligence. And, you know, uh, you know, I think Jack Gold's sort of on the right frame of mind is not really artificial intelligence as much as augmented, uh, automation and automated intelligence.
And that's the only way that we can continue to operate and grow at scale. I guess I wonder how smart we think these things are gonna be. And right now, even some people will tell you that the reasoning capabilities is anywhere from that of a 5-year-old to maybe an intern.
So Tracy, how smart will smart get and how fast? Oh, that's a, that's a, that's a million dollar question or a billion dollar question these days, right? I think it has to do with how much data we have, what does the data look like that we're basing these models on?
How are we training these models? Uh, and I, you know, when it comes to DevOps, I question a lot of it because I don't see a lot of, uh, consolidated data that we can, uh, build these models on. But in this particular, for this particular use case, uh, I don't think you have to have, you know, a million examples.
Probably a hundred thousand is gonna do fine because when it, when it comes to configuring and fixing, um, infrastructure, there are less, there's less options. You have configuration data that you need to, to tweak. And, you know, like even like Kubernetes, it does its own amount of self-healing already.
So we're already used to that. I think the real, the real problem area is going to be in the agents themselves. I am not a fan of agents because I understand how hard they can be to manage.
And when I say manage, I mean all the way from the version that you're using the drift across the agents. Um, we are starting to see AI SBOs that include the version of the LLM that they're using. So we, we'll have to do some additional work to make this happen.
So we're not gonna be managing the data from the, you know, the observability will be able to take care of itself. I think we're gonna have to spend a more, more time making sure that the agents that we del that we're delivering out there, um, are repeatable, they're consistent, and we understand what, uh, what what they're based off of. So that's why I think a IS bombs are gonna become pretty important in these environments.
But even that data we have to do something with, so don't just generate it. We have to start consuming it and have ins, we have to have insights, not just, you know, there's two different things. There's observability and there's visibility.
I, I, I like to separate them. I observability is watching what's happening out there. Visibility is understanding what you put out there that's doing the work.
That is where I believe we're gonna have the most problems because we have the, we don't have a whole lot of tooling around it. Tracy, one other thing that you said is that, uh, you talked about, uh, the ability repeatability. And I think one of the things that's very important in, uh, AI agent work is understanding that LLMs are designed to be non-deterministic.
And in an environment where you're using them to make decisions about configuration and operations, you want repeatable answers. And therefore, the hard work of the agent is taking a non-deterministic answer from an LLM and making it a deterministic decision. So you always get the same types of decisions, and that's the part, you know, from a security or from a configuration point of view, that's the part that's worrying me, not the fact that it's there.
And there's another piece to it, I think as well that Tracy and, and Jack both brought up. And that is that once you have an agent, how do you know it's doing the right thing for you? And how do you know that it's talking to another agent in the right form?
That, that, that then is passing on perhaps bad information or insecure information, Jack, to your point, from a security perspective. So it's really, it, it becomes much more complex when you're dealing with IT staff. If I don't understand anything, I can go next door and talk to Tracy, or I can talk to Jack and say, you know, I, this is what I think is happening.
Can you back me up? Can you gimme some more additional information? How do we achieve that same kind of capability with AI agents?
Or do we depend on an AI agent is being exclusive and, and whatever that AI agent tells us to do, we do. Mm-hmm. Um, There's a lot to unpack there, folks, but the first thing is, theoretically, I think you're supposed to have AI agents that are monitoring the AI agents and therefore checking on what their work is and, um, governing them.
And who knows, that may or may not work. But the thing that that brings to mind, Tracy, is, um, AI is not cheap. And so at what point am I gonna be using so much compute and resources to automate something in a way that might be less expensive to do using a human Well, just like all technology, it's gonna get cheaper.
It always gets cheaper. Um, I, we're at the, the Arterius community, we're doing some work with the Gentech and building a model to, we're not building a model, let me re rephrase that. We're building an MCP server to, uh, do some work in updating, um, DevOps files for, uh, dependency pinning.
And, you know, we thought it was gonna be super expensive, and right now we're up to like $5 a month, something of, of that sort. Now that doesn't, doesn't mean we don't have a ton of data we're putting through it, but I do believe with some of the new technology that's coming out, the, um, you know, the AI PCs that we're gonna have, that it will get cheaper. It will, it will get cheaper and cheaper as we, as we move down this road.
Mm. Um, Jack, to your point, or not Jack poller, but Jack Gold to Jack Poll's point, um, so a lot of what we expect is deterministic outcomes. We think that we want it to be managed the same way every time because we need the outcome to be consistent.
And AI agents and gen AI seems to do things differently every time out. So how will we kind of marry up this probabilistic model with the, the deterministic workflows that it kind of lives and dies by? Sorry, which Jack?
Mike. Okay. Sorry.
Um, too many jacks here. Um, so it's going to be a very interesting challenge. I think in the early days, we're going to see a lot of oversight.
Once these AI agents get put in place, we're gonna see a lot of human oversight, uh, until we get much more comfortable with the fact that these agents are getting better, they're getting tweaked by humans to, to be more consistent, hopefully, and they're doing the right thing. I think until we get to that point, uh, we're going to look at agents as, you know, it's, it's, uh, you know, flip a, flip a card or, you know, roll some dice to see what the solution's going to be, because it could be very inconsistent. And I think for most organizations having inconsistency, you know, you talk about cost of ai, the cost of inconsistency, the cost of instability is much greater than we we would ever see for the cost of deploying AI systems.
It just messes up the entire organization. So I think what we really need to look at early, and especially early stages, is a human agent looking over what an agent is doing until we feel comfortable that those agents are actually doing the right thing. But we've already had examples this past week of, of ai, uh, basically blackmailing people trying to shut it down, right?
Um, how do we know something similar isn't going to happen? Or what if an AI agent gets taken over by bad actors and gets inserted into our organization and starts shutting down all our systems? So it's not, it's not a, a trivial issue switching over from humans to, uh, agents to, to run our environment.
Mm-hmm. Jack, Jack Poller, um, I kind of worry about the following scenario, right? Will there be too many agents popping up all the time that will ask me what to do?
It'll be like, you know, a bad version of clippy from Microsoft? Or am I going to like trust the, uh, at some point, do I develop enough trust in these AI agents to where I'm gonna let them run autonomously? Or how do I strike a balance between those two extremes?
Well, I think the big worry is when clippy starts to look like the Terminator, but, um, there Are processes I want to terminate, just Yeah, absolutely. I think, um, I worry, uh, less about the, the security of, uh, an agent, a bad agent, versus the fact that it's really just opening up another attack surface. It's yet another area where we can be attacked and exposes, you know, uh, it gives more foothold for the bad actors.
And there is just, there are just so many ways that we can manipulate AI agents, uh, in, to do things in weird ways. So with model poisoning or with bad inputs, and, uh, that it is a security issue. Um, but I think until we get it to do the actual working correctly, the determinism problem solved, um, it's less of a security issue than the fact that mo we have, you know, open S3 buckets by default.
And a lot of our infrastructure is so insecure that why bother attacking the AI agent when we can attack all the other vulnerabilities that exist that are easy to get to first. Um, so it's, it's gonna be a second order consideration for the attackers until we fix our cybersecurity hygiene problems to that exists today. Right?
So you're saying things can't get any worse than they already are, so what the, what the heck? And let's not, let's not pretend that humans are perfect, right? I mean, most of the pro, most of the problems that we find is something that we have caused ourselves, you know, so these are, some of these, uh, some of these configurations are so, you know, they're so obscure that you don't necessarily know what you should set them at.
So, you know, I, you know, there's something about having it, you know, and we, you know, I come from a, you know, a, a background of rule-based, uh, compile, uh, managers and in order, and one of the reasons why we wanted it to be rules based is because all the stupid compile flags that people were using that were breaking things in production. So it's kind of similar. It's similar.
So I think this is a really good application for it. I really do. For, for AI and for AI to be more agentic in DevOps, There's an entire Cybersecurity category of, uh, posture management and configuration management dedicated to checking that your configurations match your security policies.
And so I think, you know, if we start doing AI based, uh, observability and management, then we're gonna have another security category to validate that what the AI is doing is doing correctly. Hmm. Tracy, there's this emerging debate about whether or not we're gonna just add AI to our existing platforms, or will we need these kind of more AI agent native platforms that will replace the existing platforms?
I mean, do you think we're looking at a wholesale migration, or is this gonna be more of a, you know, an evolution of platforms? And over time we'll see what happens? I think companies will, most organizations will take it more of a, as an evolution.
I think that we've been burned in the past, uh, from, uh, you know, a technical debt perspective in trying to do this wholesale. So I think it will be an evolution, but I think there will be bumps in the road where we have to make big changes. I don't think it's going to be completely an evolution, um, but I think that one of the first steps is having those a I PCs brought into, you know, where all your developers are sitting.
All right, Jack, go. Last question. A lot seems to be riding on MCP to integrate all these AI agents and well, other folks are talking about the agent to agent protocol to integrate these things.
Um, how much of that is practical at this point? And how much of that is kind of wishful thinking for orchestration, but we get a long way to go? Well, this is an evolutionary process, right?
Anytime we talk about these kinds of standards, it takes a while for all of them, for them to all settle down and for everyone to adopt them and make sure that your MCP is the same as my MCP is the same as Tracy's or Jack Poll's. Uh, and so I think it's probably going to be a six to 12 month effort to get this all stabilized. But in the end, if we don't have some sort of real interface capability that we'd be able for agents to have agents talk to each other and interact with each other, all of this just goes down the tubes.
You, you can't make it happen. So MCP is, is very important, you know, whether ultimately turns into something else, it's possible. But as the industry starts to adopt this, it becomes a way for, you know, it's, it's the lingua f Frank of, of ai.
And if we don't have that, we're in real trouble. There you have it. Hey folks, I think we're on the AI agent journey, whether we like it or not.
So the only question now is to what degree we're gonna manage these things and, um, and how much do we trust them? We'll be back in a minute. Hey folks, we're back with our next block, and it's about a company that was based in India who said that they were an AI company and they had some neural network for building software.
And then it turned out to be, well, just tons and tons of Indian engineers working on projects that had been sent over. Um, they were back mi, Microsoft at some point. So it's kind of embarrassing some folks, but they have now filed for bankruptcy Jack goal.
Is this gonna be an issue going forward? Will a lot of companies kind of say they're ai, but not really ai? Uh, absolutely.
Mike. Look, there's a lot to impact here. Number one is from the VC perspective, the amount of money that's available out there to invest in ai.
If I put a shingle out on my front door tomorrow that said I'm an AI company, I'd probably be able to go out and get a couple of billion dollars. It's just that kind of money flowing into the marketplace. So anyone who can put together a, a, a, a viable, i, I wouldn't even say viable, but something that looks viable, uh, marketing plan or, or business plan is gonna go get money.
So that's what happened here. And, and, and e the, the company fooled a whole bunch of really big investors. As you said, Microsoft and others are in that space.
So that's number one. Number two is how do we know that an AI company is really generating stuff with ai? How do we know if we're not back there?
You know, if we were to design, let's like's, take another example. If we were to design a, a fewer were, you know, Mike Dard, uh, AI company, and you needed a new chip, you'd have your engineers at, you know, wherever the design company is, cadence and TSMC and everyone else, making sure that everything looked good and everything worked before you invested, you know, $2 billion in that space. Why weren't people looking at what this company was doing and where that code was actually coming from, uh, when they were investing and actually asking them to do things?
They were asking to build apps. You know, it was supposed to be all AI based apps when they were really having, as you said, hundreds and thousands of engineers working in the background, building this code. Uh, you know, it was done cheaply.
Indian labor is relatively inexpensive, but how do we know what someone is sending us, is what they claim it to be? And the third piece I think, which is really critical here, is that I think companies, uh, were so enamored with getting AI coding done, or coding via AI done, that they weren't really worried so much about how it was being done, as being able to stand up and say, see, my IT group, my DevOps folks just got all of this code for next to nothing 'cause AI did it, and I don't have to go out and hire 34 e 50 more engineers. So there's a whole series of things that go, that are, that are going on behind the scenes with this.
I think it's really concerning that we don't have a better understanding, a better handle. And, and this is a failure of both Wall Street and, uh, enterprise IT departments not understanding what's really going on behind the scenes before we invest all kinds of capabilities, uh, all kinds of energies in these kinds of companies. Tracy Ringin, is there a way to test this and discover this, or we just kinda have to take people's words for it?
Uh, well, I'm baffled by it. I'm so baffled by it considering, you know, um, some of the, the, the journey I've been on in terms of getting, uh, the attempt to get funding, um, I honestly, folks, they look at me and they go, some blonde chick from California, I don't think she can do this. Um, so it can be really frustrating to hear the story, to be quite honest.
Um, and it doesn't, it, it doesn't surprise me that it occurred. I don't think that there's a way you can test it. I would think that if there was a way to test if Microsoft would've figured that out or to at least looked at their code base, right?
Why, why did they not take the next step? It sort of reminds me of Elizabeth Holmes and her company that was gonna do the blood testing. Uh, Theramos.
Yeah, Theramos. He said, what on Earth, right? I mean, that's a cool dream.
And Walgreens bought, you know, into it, hook, line and sinker, and so did a lot of other investors. Uh, so y yeah, it would be great if we could have blood testing machines in at Walgreens, or if there was this really cool app that was building applications for us and really customized. Uh, but, you know, sometimes it's too, if it's too good to be true, maybe it's not.
You know, what about logic? Putting logic behind it first? So, um, yeah, it's a, this, these stories frustrate me, um, horribly to be honest.
And I, I think it, I felt sometimes it's like the ai ba, everybody got so excited about AI that there's probably more than one company that's that's out there doing stuff like this. There's no doubt, Right? Jack Poller, it may not just be in the land of DevOps that this is occurring, right?
It could be occurring in just about every vertical industry. There may be somebody out there who's doing fake ai. Not only is it probably occurring, it has occurred in the past.
I mean, there's a meme out there about the being named to the Forbes 30 under 30 list where, you know, something like, I don't know, a third half of the people there have been fraudulent actors, right? It's not just, uh, Theranos, there's a long list of companies including Sam Bankman Freed, who were, you know, uh, all named as 3,030 who were fraudulent people. Uh, and many VCs have been snowed under on this, because they're not technical people.
They're investment bankers, and a lot of them just don't understand the technology. What I find surprising about this one is we have lots of examples, uh, from Microsoft with GitHub, from chat, GPT, from all the popular, uh, chat AI interfaces of how quickly they can operate and generate code. And they can, you know, you can say, give me a, you know, give me a wire frame or create an app and, and they'll give you something back in two to three minutes, which has gotta be much quicker than an Indian engineer is doing it, typing it in by hand.
So how did it pass the sniff test? That's what I don't understand, is, yeah, one person at Microsoft said, well, give me a demo, or I want to type my own query into the chat bot. And it didn't come up with an answer in five seconds.
It took 25 minutes for an Indian engineer to go type it and get it back to me. And they said, yeah, this is cool. Let's go throw, you know, a hundred million dollars at, or whatever.
They invest in it. I just don't get that part of it. It just doesn't, I don't care either.
When I was reading it, I was like, how on earth did they do this? How, how, right now, You know, there's so much money out there right now seeking returns, right? That people are just investing in pipe dreams, and, and I think we're gonna see a lot more of it.
Uh, there's just too much money chasing, basically, too little technology. Well, that, and the other part of it is that I think, Jack, you hit on this at the beginning, which is that companies saw this, the, the, the consumer of the product or the service saw this as a way to get very inexpensive design help and, right. And so that creates an artificial demand for a non-existent product.
So, a again, Tracy, as you said with the Theranos, it's like, if we could get this, you know, this pipe dream of a, of a very cheap and expensive, very tiny blood test machine in, in Walgreens, why wouldn't we do it? Of course, we have to try. I mean, that we, we look at XI mean, you know, space X, they're trying and trying and trying their dream may never really completely come true.
We may never go to Mars. I mean, come on there. There's a lot of money being invested in these particular areas.
But to say that you already have the technology, instead of saying, I want investment to do research on the technology, that's the mistake. That's, that's where these companies are, are missing it. Because I, I, I believe that there is a big enough demand for these types of solutions, a blood test at Walgreens, that, that saying, you wanna in investigate and you wanna put research money towards it in order to b to potentially build that solution is a valid, uh, pitch.
So why are they not pitching that? Why are they saying they have a solution if they don't? And how come we can't see that?
Part of it is the consumer side, right? The, the enterprises, the IT departments, they are being pressured in a lot of organizations to go do something in ai just because it's a hot new cool technology. CEOs don't wanna get left behind.
People are trying to figure out what's the best way for me to implement ai, even though in many instances in organizations, you know, we, we found that 60, 70, 80% of AI projects aren't successful. But there's so much pressure within organizations now to try and find these kinds of companies that will give us a leg up against the competition that people are just not doing their homework. They're going out and investing and, and saying, boy, this is great.
I'm gonna, I'm just gonna go do this. Same with, you know, it's same idea with, with Theranos. It was, it's gonna gimme a leg up in the competition.
This thing has to succeed. I'm just gonna go invest in it. So there needs to be a lot more backend.
Does this really work? Is there really something behind it? Tracy?
I think the difference with between this and with X is SpaceX is that we know there's still experimenting, right? They're not promising to do this tomorrow. Uh, these guys are saying we can do this now.
And I think that's a real, a really problematic statement, right? We have all kinds of evidence of what SpaceX is up to in the bottom of the Gulf of America, right? So, um, I would ask Tracy one last question though.
Um, somebody I talked to says, you know, you can telco that's written by a machine versus a human in that there are certain things that machines will do that humans will not. Do you think that's a, a viable sniff test or no? Oh, a hundred percent.
A hundred percent. I mean, you could even see that. Just have it write a paragraph, right?
If you don't, even if you're not a programmer, just have it write a paragraph for you and then have, and then ask it different questions and have it write a different paragraph and you can see it has a cadence to it. So the co code looks the same way. There's a particular cadence to the code, so you can see that it's generated by ai, which to me is not a bad thing.
There is some consistency in how it's generating the code or the, or the, or the, um, the content. Um, but yeah, that should have been a good valid test. But as Jack Poller said, you know, or maybe it was Jack Gold, how come he didn't say, here, go write this, this application.
It didn't come back in 15, you know, in five minutes it had to go, you know, take maybe an hour to come back with an answer. There's that was the, that was the smell test on, on that test. I mean, that was easy.
That was just a really complex application with a huge context window that would take two hours to Right, Right, right. No, no. It was went through qc.
QC is what took the time. It wasn't writing the code. Yeah, right.
But there's definitely a format that it generates on everything. It does. There's definitely a format.
You can see the format it uses. There's a syntax. All right, well, hey folks, if you get something back from somebody and it feels like it's written by a human, chances are it was not a machine.
So double check the quality of the code and how it's created. 'cause the cadence is a dead giveaway. We'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, we're gonna have another little conversation about a different kind of security, but it's invasive spyware. I'm not quite clear that it's actually spyware, but that's what people are calling it.
Meta and y Yandex have been exploiting Android browser features to Coly track users. And now Meta says they've turned that off. Now, somebody pointed out that they're in violation of Google policies.
Um, Jack, we're all getting Jack Poller. We're all getting a little paranoid about, uh, what's happening on our devices and who's tracking us. And the devices feel like they're getting a little creepy every time I talk about something, suddenly there's an ad unit that goes with that somewhere.
This doesn't bode well for that. I mean, how concerned about all this should we be? Well, let, let, let's start with getting the internet memes outta the way first is that you're, you know, you're not paranoid if they really are out to get you.
And, um, well, you know, we, we can't possibly be shocked that either Russia, China, or Meta is spying on us, right? Uh, this is, you know, all three have a very long history of doing this. Um, apparently what they're doing is they're using, uh, the applications that the, the application that, that the native application that you install on your Android phone to have a backdoor communication channel to your web browser, and therefore being able to access and spy on what your web browser activity is doing.
So if you are trying to be anonymous and use the private mode of the web browser, or even if you're not, it doesn't matter because the, a native application or Yex or for Meta Facebook, so Facebook or Instagram or, um, WhatsApp, I, and I don't know if specifically which app is doing this, but they had the ability to go and look at your browser, talk a back channel to the browser and say, show me what, what websites you're looking at, how you were interacting with. So that was sort of the technology behind this, this ability to go talk to the browser and have this back channel communication was never meant for this. And it does violate, uh, Google claims that violates the Android and prone terms of service.
And so Meta says, well, we've stopped while we investigate whether we really did violate the terms of service, whether or not they violated the terms of service. This is really creepy behavior, and it is a big, um, both cybersecurity concern as well as a privacy and anonymity concern. And it just makes me immediately want to destroy all of my accounts with these, you know, you know, when I, I dropped out Facebook, I never found a lot of value in Facebook, but I have an Instagram account because so many of my relatives and friends are on Instagram.
But now I don't even want to have that because there's no reason Facebook should ever want that data, let alone have access to that data. And there's no reason that Yandex or anybody else should want or have access to that data unless it's for nefarious purposes. So, I mean, this, the, the, the, the creepy factor of this is just really huge and really bothersome.
Um, then there's also, it, it is really ugly. And then from a pure cybersecurity concern, this is something that Google should think about. Do we really need these types of features?
And not making it a terms of service issue, but a preventative issue in the first place? Does, does anybody really need to be able to get access to that type of data? And from a cybersecurity concern, my feeling is no.
And why should anybody be surprised about this? You know, uh, seriously, from, from both perspectives. One is that that's how Meta makes its money, right?
Knowing everything about you so they can sell you the, or send you the right ads so they, you can sell stuff. Uh, the other piece of this is, frankly, most people on phones when they install an app, never read the terms of service. They just click, yeah, okay, share whatever you want.
You know, the, it's an open book. I, I mean, look at, it's scary. My, my kids are older now, but look at what kids actually share on their devices.
So is Meta really getting anything that they couldn't get any other way? And finally, Jack, I fully agree with you. Why is this available in Android and Chrome browsers to begin with?
What, what's the purpose? Why did, why did Google put this in place? So it's a multifaceted problem.
No one should be surprised about this. Um, and I'm not sure that it's ever gonna get fixed. You know, if it's not this, it's gonna be some other exposure.
Well, didn't Google do it first? I thought I was running everything in Incognito and I'd be fine. And then we find out, well, incognito didn't rock anything.
But I think what we have to remember is data is the new gold. It's the new gold. And so these companies, mining for it is not, should not surprise us, but we should, you know, when it comes to, you know, I don't like the idea of somebody, you know, watching what I'm doing.
I used to didn't care. That's the weirder part. But in our new political climate, I do care.
I do want more privacy because now I'm worried about, you know, big brother watching. It's kind of, you know, it, we're getting to that point. Um, but I have to say that we, if if, if you're in the public sector, you, you think you'd be listening to this very carefully.
We're doing all this work in the public sector to have, you know, zero trust policies. And then we have some of our people in the highest parts of our government using their own, their phones and, and, and things like, you know, signal to, to, to do all their, their work. This is a huge problem because again, data is the new gold.
And, you know, why wouldn't you want to take this? If you can, you want this information because it's worth a lot of money. You could sell it to China, you could sell it to Russia, you could do something else with it.
Maybe nefarious, maybe may, maybe not, uh, could be creating a better end user experience. But I don't think that's the, the, the ultimate goal. It's to make money.
And it is, is it's something that we have to be forever vigilant. Data breaches, you know, this is kind of a data breach in my, in my world, a data breach that, that we, yeah, it's a data breach. Data breaches are costing $10 trillion a year, globally, $10 trillion a year globally.
And for companies that, you know, as we've pointed out, Google kind of, can we turn this stuff off? It, it, they don't address it because there is so much money in the data. There's another piece of this that's I think really critical for our enterprise listeners, and that is that about 80%, depending on which industry you look at, about 80% of enterprise users have phones as their secondary, or in some cases primary methodology of accessing corporate apps.
And many of those are done through a browser interface. So if you also have WhatsApp, Instagram, whatever, running on your phone, not only is meta knowing what you're doing personally, you know, which restaurant you ate at yesterday, but knowing what person you visited on your sales call yesterday, because they're, they're gathering that information as well. So it's not just, it's certainly a privacy issue, but it's not just, this is not just a consumer issue.
This is also an enterprise security issue, which is really concerning. Well, Jack, this is why I was just gonna say, this is why there's now the rise of the enterprise browsers with companies like Islands and some of the others that are making their own version of the browser. And I bet every single one of those companies right now is going into their code base and patching it and saying, we're gonna remove this capability from the browser and issue a new version of the browser.
If they don't, they should be doing that today, right? Well, we've Had, we've had private browsers, Jack for years, right? Yeah.
Like the Blackberry, they're not using it. Yeah. And no one uses them, Right?
Yeah, they don't, and keep in mind, I know, uh, I know young developers just out of, uh, university that they code on their phone with two thumbs, kind of blows me away. It's like, well, that's a whole new world, but, so they're actually doing work. Yeah, it's a PC to them.
They're actually doing work on the, on all kinds of different edge devices. So there's a, that's a lot of private enterprise data getting out. I'm kind of getting to the point where Jack Gold was talking about, I mean, there is no notion of real privacy out on the internet and all these places, you know, so meta is basically like going down to the local mall.
Everything you do in the mall is seen by everybody else. And it's the same thing that goes on at Meta, right? If I go in the mall and I go into some store, everybody knows it.
And so too, will they know what website I went to from Meta? And I think we just should stop having this illusion that somehow or other of these companies are gonna do anything about data privacy. And if you want privacy, you gotta take that on for yourself.
Is that just where we are, Jack Gold? Yeah. The, the only difference is that in other countries, certainly not in the US but in other countries, they're starting to realize this and regulate against it and, you know, can they completely stop it?
Europe is a great case in point, right? Can they completely stop this kind of thing? Probably not.
But if you're found out, meta is gonna get fined, you know, billions and billions of dollars. And so there's some disincentive for them to do it. Certainly Russia doesn't care.
North Korea, China doesn't care, right? They're, they're gonna use this stuff. But the only way this gets solved, in my opinion, is not through technology necessarily.
It's through government regulation, privacy records. I mean, remember the old days where people used to be able to, to share your medical data when you went to the doctor, uh, and then HIPAA came along and they couldn't do that anymore. It's not perfect, but it's better than nothing.
I think that's the only way this, uh, ultimately gets resolved. And frankly, I don't see it happening in the US anytime soon given the current administration. Yeah, we're not, we're going exact opposite direction.
I mean, even the, uh, the, the big beautiful Bill, um, has a, has a clause in there that says you can't regulate AI for the next 10 years, which would be disastrous. Mm-hmm. Well, To be very bad for us To, to be clear, it says states can't, but the federal government can't.
States can't, but the federal government just won't. So that's where Yeah, Exactly. Yeah.
It's because know how responsible states are. Yeah. There you go.
So, so Jack Poller, do you think Google will go fundamentally fix this issue? Or are they just gonna sweep it all under the rug and just rang their finger about you violated my policy? I think right now they're taking the, you violated my policy approach, um, because there are legit, there are some legitimate uses for the technology that they, you know, for the sort of backdoor way of doing things.
Uh, and so the question is, can they put some guardrails around it, whether it's terms of use or some technical guardrails around it to prevent, uh, the types of data leaks we're talking about while still making it useful for its intended purpose. And, uh, that's, I think what they're gonna struggle with. Companies like Meta and Gex and the, the, you know, they're gonna continue to, to find any way they can to get the data they need.
I mean, this is not the first time Meta has done this, you know, for years and years and years. They've used, uh, a tracking pixel, an image with one pixel in it to track you as any website that has it on it, it re you know, has to call to Facebook to load that image that you never see on your screen. 'cause it's one pixel wide.
And that was another way they've tracked you. So it's, it's a desirable technique that, uh, sorry, it's a desirable feature that go, that, uh, meta wants is to be able to track you, you know, that data, as Tracy said, that data is gold for 'em, that they live and die on that data. So if Google turns this off, then they're gonna just keep investigating and find other ways to do it.
There is another interesting aspect to this, and that is that this plays right into Apple's iOS message. You know, the more secure browser, everyone should have a a, an iPhone because Android is unsafe. Uh, whether it's true or not is, is a whole different discussion, but that's really what's going on.
What's gonna happen here, I think, and I think Google is gonna feel a lot of pressure. Maybe if they feel the pressure, they'll turn it off. Um, we'll see how long this is actually in the news cycle.
Uh, and it won't, it doesn't, to be honest, the, the average person who's not in tech won't even understand what this discussion's about. I don't wanna say that they're dumb 'cause they're not, that's just not their area. What they want us to be able to be on, uh, Facebook.
And they, it's cool to say, Hey, there's these restaurants that are near you, or here's where your friends are. And that's the kind of the reasons why we have that, uh, those features as Jack Poer, uh, just described. So I, will it be something that a private person might take in a lawsuit?
Probably not. And will there be regulation that says you're gonna get fined billions of dollars? Probably not.
There could be regulations. You're gonna get fined 40, $50 million, which is simply cost of doing business. So it's, yeah.
Yeah. So we don't see those kinds of massive, uh, you know, penalties for being a, uh, doing bad things in tech. We just don't.
So I don't, there's not an easy answer for this. This is a massive data breach that we cannot solve. And, and let's also be clear as it's not really an Apple versus Android issue, it's a who, who is actually getting your data.
Because if you're on a, an Apple phone, your data goes to Apple. And there is, right? It's a so, and there's a lot of, there's a whole lot of issues we wanna explore here of Apple getting the data versus meta getting the data.
No, I, I, I agree. And the only reason I use that example is because from a marketing perspective, this is gold for those guys, Right? Well, speaking, speaking from a marketing perspective, should I just go out and download like duck, duck go?
Is that gonna solve my problem? Uh, yeah, until I find a way into that one. All right, well, hey, we Can, I, I don't think Mike, honest, the honest answer is given.
We're all dependent on this technology. All of the technology we use at some point is gonna have a hole exposed to it. And the, and the, I was gonna say the bad guys, I, I wouldn't exactly call them bad guys, but the guys that can make money exposing those holes do so.
All right, well, folks, you heard it here. Any data that's not on your own machine, that you probably, and you probably should lock it down on your own machine as well, you might wanna consider the fact that it's probably been exposed to somebody with or without your permission. And maybe you wanna start thinking about modifying your behavior as a result.
I wanna thank all our guests for being on the show today, as always sharing their insights. That was awesome. I wanna thank you all for spending 45 minutes or so with us today.
Once again, please stay tuned for all the techstrong TV content coming up right behind us, and we'll see you next time.