AI Anxiety, Infrastructure Demands, and New MFA Threats | TSG Ep. 981
Alan Shimel, Mike Vizard, Mitch Ashley, Camberley Bates, Jack Poller and Andi Mann discuss how attitudes surrounding artificial intelligence are changing as organizations confront both the benefits and the risks of increased automation. The gang reviews why AI adoption now requires radically different approaches to IT infrastructure, including how systems need to evolve to support more intensive AI workloads.
The episode then turns to multifactor authentication, where man-in-the-middle (MITM) attacks are becoming weaponized. The gang examines why traditional MFA models are no longer sufficient and why new approaches to identity and access security are needed.
Transcript
Hey, everyone, still feeling anxious about ai? I've got even more reasons for you too. You're watching Textron Gang.
Hey everyone, it's Alan Shimmel, and happy Monday to you. Uh, I am still, as I recorded this, you know, we record day before, so as of Friday, I am still in Las Vegas, nursing, uh, uh, AWS reinvent hangover. I guess, though I didn't drink anything.
I think several of us have that same, uh, uh, disease though, or symptoms. We'll, we'll talk about it maybe, but, um, welcome to our Monday Textron gang. Before we get shouted, I got a call out a big day for our Bard, Mike Ard and his lovely wife, Charlene.
It's their anniversary as we record this. So we're gonna wish Mike and Shar a very, very happy anniversary. See how red I can make his face on here?
Uh, happy anniversary to you, Mike. You're a lucky man. And as Mike said, when he was out here in Vegas with me this week, who would've thought he bet the under when, when they got married and, and, you know, he's lost his money, but he's gained a life partner.
Um, moving on though, we have Jack Poller with us, Kimberly Bates, Andy Mann, Mitch Ashley. This is like a majority Colorado board here. Um, oh my.
But welcome, welcome gang members. Mike, I appreciate you coming on on your anniversary. We've got some interesting stuff to talk about today.
We're gonna start off with yet more reasons to people who are worried or anxious about ai. Yeah, it's interesting how rapidly this, this whole thing is shifting because, um, early on it was all about, well, is AI gonna take my job and replace me? And that's a currently a concern.
But a survey suggests that people are also now diving in a little bit, getting, uh, the understanding of ai, maybe less odd by it, but certainly more concerned about losing control over it. And the fact that, uh, you know, they're trying to figure out, well, A, what am I allowed to do? But b um, they're starting to understand that some of this stuff can just kind of spiral without some sort of guardrails or controls in place.
And they're starting to ask some interesting questions about all this. So, Alan, we've been talking about this issue for a while now, but it's interesting, this, it seems to be taking on a different nuance. You know, it, it has been taking on a different nuance, Mike.
But here, here's an interesting thing. This is, I, I, who is it? Z's, uh, Maslow's hierarchy of needs and needs hierarchy, right?
So first, people are worried about their own wellbeing, right? Am I gonna lose my job? Am I gonna lose my livelihood?
Am I gonna lose my place in society as, as a result of this AI stuff, right? And I, I think we are still wrestling with that as a society, as as humans. But, but then the next thing starts, right?
And it's like, Hey, wait a second. Can we trust this thing? Um, you know, what, what's going to, what?
Is it trustworthy? Is it a security risk? Can I let it have, you know, intimate details?
It probably already knows intimate details about me. Unfortunately, um, you know, what are we gonna do? Who's regulating this this's gonna run amuck?
What happens if it decides to just get rid of us or something? So there, there are these trusted safety issues. And you know, I, I think even that falls into two categories.
There's what I call the irrational non-technical anxiety, which, and I've seen this with friends and relatives who are not in tech, who say, I'm not using that. I'm not using that. I don't trust it.
I'm shutting it down. I don't, I am not telling it anything about myself. I don't trust what it tells me.
Everything's a fake. And then there's the tech people who are maybe a little more enlightened only because they're exposed to it more. It's not that they're necessarily smarter, but they're exposed to it.
And they, and these, these are the kinds of people, Mike, who were like signing the letter to at, to AWS about, Hey, we've gotta put some guardrails in here. This thing, the security, you know, the security people are always on the megaphone blaring everything is No, no, no. But, um, you know, this, this is in my mind a little bit more rational, a little bit more developed nuance than just saying, oh, I'm gonna lose my job and we're gonna eliminate poverty money and everything else, and, and live, you know, on Vulcan somewhere or something.
But, um, thi this, this is real. This is real stuff. There is security issues.
There are, uh, privacy issues. There are trust issues that AI is gonna have to win over the minds and hearts of people. You know, Alan, I think it's even more fundamental.
I think when we talk about AI is replacing me. You're replacing my value. What's my intrinsic value?
If AI can do everything I can do, then how do I make a living? Then how do I feed my family, et cetera. And, and honestly, this is one of the things I don't like about our hype cycle, is we get the, uh, the tech giant industry pundits, you know, CEOs talking about how we're gonna replace all these jobs and, uh, yeah, we'll do something like universal income.
We can't even figure out how to give people a tax credit or feed our folks, you know, let's talk about a universal income so people know that's bs. So that over-hyping just, just makes the anxiety even higher. I think we're in a, who is the Mel Brooks anxiety with that Anxiety, high anxiety.
We think we're in the spiral right now. Yeah, we Spoke about it last week. But, but Mitch, I, I think, again, back to the hierarchy of needs that is very personal to me.
It, it threatens my very existence. Now we're seeing a secondary and a tertiary anxiety of, wait a second, I don't even trust this thing. Right?
I don't, I don't trust it. There's security issues. You know, the, in my mind, that's a little, not that replacing my job is irrational, but this is a little bit more nuanced.
It, it's not, I'm not just worried about my own personal wellbeing. I'm, I'm worried, you know about how's this, you know, what, what could, what bad could happen to everyone? Mm-hmm.
Well, I'll echo echo, uh, Mitch a little bit. That I think part of this is driven by the media in some extent. We have a, a media that lives off.
Sure. Blame the media guys. Why can't we blame the analyst?
Absolutely. You's gotta respond. So YY You, you know, I knew that was coming, right?
Mm-hmm. Okay. Yeah.
The old expression, if it bleeds, it leads still applies to ai, is let's talk about all of the bad things that can come about it. And then, as Mitch says, when we talk about the good things, we talk about the good things in ways that are essentially bad, it's how is this going to change our lives? We don't talk about it changing our lives for the better.
We talk about it changing our lives for the worse, right? And who are, I think you're right, Alan, that there is a divide between those who are technically literate enough to understand what the AI and LLM world really is all about, and those who aren't. And in some extent, this is like where we were with the introduction of the machine age and the industrial revolution, right?
Is it is a massive revolution in the way our society is working and will work in the future. What that happens, we don't know. And that, you know, that unknown leads to a lot of anxiety, But this is healthy.
This is healthy, this is like what should be happening. Because as we've experimented with ai, and we've seen each of us have gone in there and said, well, that's baloney the information I'm getting back, or that's inaccurate. You know?
And we were the early adopters of it, right? I, I don't think myself as an early adopter, but certainly I was, and as compared to my family members, um, that I was with this last week at Thanksgiving. So, um, that's important.
I mean, there, there was an article this week in Wall Street Journal about Waymo, and they've taken some of the guardrails off of Waymo, so it's now a little bit more aggressive. And what they were noting, driving more like a taxi driver, and they had one that they were swerving in and out, um, two Waymo's were swerving in and out, and they also had cited one where, yeah, the Waymo always comes in up to a, you know, a four-way stop, and they acknowledge everybody else before they'll take the turn or take, take the stop sign. And, um, and she said that, no, that's not what happened this time.
Um, now the goodness of that, another person in the article was quoted as saying, I will now take Waymo and sell the taxi driver because it's more aggressive. Okay? So, I mean, that's, that's a trust.
So she wasn't taking Waymo because she wasn't trusting it to be whatever. And yet now I'm saying, okay, so, you know, I haven't done Waymo, but you know, heck, so, you know, there's, I think there's, there's a good and bad in here, and that we should approach any kind of new technology with some skepticism. Um, and, and the report that you guys cited, the, I think it was Edelman, um, that's the primary purpose of their study, is to look at trust and look at, you know, trust.
Whether or not I'm looking at voting or the ai, AI is the obvious one, but a whole lot of other things that they're looking at. And oh, by the way, Mike, in that report, the media are the bottom of the barrel in terms of trust. So, sorry.
You know, even when we had newspapers, we were still at the bottom of the barrel. So we're used to being there. I don't even think analysts were on the list, but, but let me, let me follow up to what you said, cam, you know, it was, it's last week was Thanksgiving.
Well, actually, now you're watching this, the week before was Thanksgiving. And, um, it, it, and Thanksgiving is always a time to take the temperature of your friends and family, whether it's politics, technology or, or any other number of things. And, and Kimberly, I had a very similar thing to you, right?
I found myself doing ai. I call 'em AI parlor tricks with, with people showing them all the cool things. I, I showed them a saw I made of me as a Pittsburgh Steelers head coach.
It was a big hit, big hit. Um, but, but it, it, it, it, it kind of goes over a fact. Are we headed to a society, to a humanity point of thing where AI defines haves and haves nots.
If you are AI enabled and you embrace it, are you gonna have a better life, live longer, work less, make more money, be happier? I'm just throwing things out at you versus someone who says, I don't trust it, I don't use it and keep it away from me. And, and your life will be less rich, less, you know, diverse, less everything.
I don't know. I think it's gonna be released for the time being very similar to what we currently do, right? We all go to work, come home, have dinner, and you know, the conversation invariably turns to work and there's a bad day at work, and you basically start explaining to your family that, you know, you work with idiots and blah, blah, blah, blah, blah, blah.
Well, that's just gonna change. And say, you know, I had a bad day at work and I work with idiots except they're AI agents and they're idiots. But I had to go spend all my time fixing all this crap that they did.
And it's just gonna be the same conversation with a slightly different inanimate object as being this source of I, I disagree. Let, let's take, let's take a couple of recent things. Let's take the cell phone and the internet.
These, all, all of us are of nature. Some of us younger than others perhaps, but we're all around the of the same generation. Think about your life before the internet.
Think about your life before the cell phone, right? I was showing someone pictures of me last night that someone had sent me from 1983, and they were like, wow, look at these pictures. Uh, you know, these are great.
I said, keep in mind these weren't pictures taken on a phone that were digitized. These were photos that someone actually recently took a, a snapshot of, or, or, you know, a digital, a phone grab of, right? An instamatic that was technology at the time.
Absolutely. With the flash cue. You remember our flashbulb blind for a second, but, but think about our lives before.
There wasn't. Hey, you go home and you turn on the tv, Mike, it's not Uncle Walter on there no more, okay? It's not, it's, it's, there's a hundred channels, a hundred million channels and nothing on, right?
As the Bruce Springsteen song says. And so it has, technology has a profound impact on our day-to-day and, and how we do things. I think AI is gonna have that kind of impact.
Things that we just are gonna start taking for granted. Like, Hey, AI, go, you know, a digital butler, if you will. It's a new way of doing things and doing the science.
It's a new way of doing science. It's a new way of creating content. It's a new way of customer service type of customer service of, of automating those things.
And to my, I think whoever was making the comment, will we be happier, more content, whatever. And I, I would venture to say, not really. Technology has not necessarily made us happier or more content or working less.
It's just a change in how we do things. Look how it's brought us together, though, is one, one Nation, right? And all of that good stuff.
Of course, I I, I think it's gonna be, I think it's gonna be more of the same. And I'm gonna have a bunch of AI agents and they're gonna squabble with each other, and I'm gonna yell at them and say, don't make me pull this car over. Well, no, you just, you're gonna say, pull the car over 'cause you're not driving.
Am I gonna need to pull the keyboard over? Hold on. Oh my gosh.
Alright. Hey, but you know what? Let me just tie a bow on this one.
I hear you loud and clear. People who have anxiety around ai, whether it's at, whether it's at your inner core of like your imposter syndrome, run wild. Because AI's gonna expose you for not really being who, who you claim to be and, and make, you know, doing the job that you're doing and being replaced to fears around trust and safety and, and what could this thing ha what could happen if this thing runs amuck?
Um, we hear you. I, I don't think you're crazy. I think it's something we all have to come to terms with and, and figure out and, but it's gonna be a personal thing, right?
It, it's not gonna be a blanket thing. It's going to, it's going to go individual by individual coming to terms with how they're gonna have AI exist in their world. Sound good?
All right, let's take a break here on Textron Gang and come back. We'll talk about, uh, our next topic. You're watching Textron Gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and we're gonna talk about ai, but we're gonna geek out a little bit about it because, well, there's conversations that says that we need a new approach to the data center in terms of how we're gonna build and support these applications and environments.
And HP and a MD are calling for a more open rack scale AI infrastructure. And there are surveys out there that says that, um, it leaders, very few of them feel like their current infrastructure is up to the AI task. So, Kimberly, as you look at all this stuff, do we need to kinda re-architect the data center, rethink this whole thing from the ground up?
And is AI gonna just, you know, be in the 2026 year, the year of infrastructure? Well, I think it was Dell that coined the AI factory, um, terminology almost a year and a half ago. And when they came out of their conference, and, and I didn't understand it initially, and then I dug into what they were talking about, and this was what they were saying is that this is so big that we are going to create the data center people, the people in the enterprise are gonna create another factory to manufacture, and I would say manufacture these tokens.
They're gonna drive the AI initiatives within the systems. So you would have your regular enterprise environment that's doing the online transaction, and then to create this AI factory that is also able to do the work of the inference engine. And I believe this is what this, this is exactly what HV, this is not the first racks rack type scale offering that they've brought out.
They've brought out the GreenLake, and as primarily the difference of this one is based upon open compute, um, project and the open rack, um, spec, one of the open rack specifications. Um, and then the other big news on there is because they're, you're partnering with a MD and then they're also using their latest, um, acquisition Juniper in this rack scale kind of ability. Um, we've also saw that come out with a, um, AWS and like Mitch and Alan, you can probably talk about it, which is they announced their AI factory, it's already shipped, Dell has shipped theirs, but they'll probably do some revamp, and we'll see that as it goes through the year as they update and improve.
And we find out more information about what is needed on the platform. Um, and then, you know, what, a month ago I was sitting in a place called Oxide Compute, um, and they have rack scale devices. It's not specifically for ai, but I would expect for them to be delivering those kind of environments.
So yeah, this is where we're going. Um, and especially now that inference is starting to increase the amount that's being delivered. Um, and, and the enterprises are getting their, in their hands wrapped around the data and, and to be able to deliver on these use cases.
I'm, I'm gonna throw this out to the group 'cause, um, but I'm struggling with this in my mind. So if I use a service, whether it's Amazon or whatever, I wind up paying for tokens, and tokens are for input and output. So every time I do something, there's a cost on the inside and out and that, and then the output, is that gonna drive more people to want to build stuff that runs in their own data centers so they don't have to have those kind of token based costs.
And it'd just be something that I kinda run locally because it's gonna prove to be less expensive over time. I don't know, Jack, you want to throw a thought in on that? Um, it's less about tokens and more about the volume of data.
So the real issue is to get the benefit of L ai and LLMs in particular, you wanna throw as much data at it as possible, particularly if you were a corporate environment type of place, you wanted to have access to all of your corporate data, shipping that data into the cloud and putting it into a, an environment that AI can access it at the speed and scale it needs to, becomes very expensive. And then you have a latency of access issue. So there is the feeling that right now organizations are gonna, and also the security of that data, moving all that data around.
So organizations are really gonna want to keep all of that data in-house in their own environments and therefore need an infrastructure built to be able to access that data. And this is the startup, and I think I mentioned it, I don't think Kimberly was here, but Andy, you and I might have been on a a, a Textron gang a couple weeks ago where I talked about the fact that right now we don't have a well understood recipe for how does an organization, you know, if a, if a CIO says we're gonna do AI and we need to do an AI training and AI inference, how does an organization put that together? If we said we need to do virtualization or we need to do containers, you go to a, uh, a DevOps person, they understand that and they have a recipe and they can go build that relatively quickly.
We don't have that right now, which is why organizations like HP and Dell and, and AWS and all these different things are coming up with their own factory, which is a recipe that says you put all these components together on the hardware side and all these components together on the software side. And with that, you then have the infrastructure you need to do it. Since there's no standardized infrastructure right now, everybody's coming up with their own flavor of it.
Jack, I think that's an excellent point, but I think there's something more fundamental missing here. This is more like the moonshot NASA mission where we know that in order to, to, to do, you know, a hundred gigawatt or whatever, uh, data centers and racks that support 10 gig versus 10 meg, we need to invent technology. We need to come up with tank or you know, or you think about some of the things that NASA came up with, the flux capacitor.
We need a flux capacitor, right? We, we, right. No, seriously, we, we need to come up with better ways of producing enough energy that won't destroy the plant.
We need to come up with better ways of cooling down these racks so they don't, you know, without using 2 million gallons of water, we, we, we need, you know, it's one thing to say, you know what, I'm gonna come up with a recipe and I'm gonna go down to the supermarket and pick up these ingredients. It's another thing to say, I've gotta go invent these ingredients. I've gotta go make these ingredients so that we can have a recipe.
And so I think right now we're in a bit of a Cambrian era of people experimenting. Uh, and we'll figure out what innovations, what technologies, what inventions are gonna help us to, to build these factories. And then at some, so that, that's the phase one.
Phase two is, okay, now we have those things and I can write down my recipe versus Jack's recipe versus Andy's recipe and, and, and go with it, right? But we're, we're still in, you know, I, I'm from Long Island, right? If you ever read the story about the lunar mount module, the lamb, right?
They told Grumman, go build this. You got a year and a half, they didn't know where to start. No one had ever built a lunar module that was gonna land in no gra you know, microgravity.
And they didn't know if the damn thing would take back off after it landed like the, the, the capsule going back up. And they had to kind of make it up as they went. They had to invent, they literally invented things to do this.
That's where we are right now. We're inventing this, you know, we're not quite up to a recipe yet. We're still at the inventing it.
Well, and that's what the, I think one of the benefits or one of the high highlights of this announcement with HPE is, is that it is based upon open compute project and one of the open compute project for those who are not aware of what this is about. Um, and it's usually held in September if you wanna attend the conference that they do. But it is, brings a lot of the hyperscalers together.
I mean, who's involved with that is gonna be Google. It's gonna be Facebook and a bunch of other folks that are dealing with this. So they're, they're upfront and center, maybe not exactly what the enterprise needs, but they're upfront and center about what's going on in the, in, in the, their, their area.
And so that is how this is coming together. Um, and I have oddly, I have a lot of, um, confidence in what they're delivering in terms of spec coming outta there because they're moving so fast. I mean, it's not a slow process for them to bring something out.
Um, and more likely that it's going to be a solid kind of concept and offering that a vendor can take then and build their own rack for the benefit of the enterprise. I think the whole nother Go ahead, rich. There's a whole nother layer to this, Alan, which is, you know, if, if AI is the, is the nail gun to the traditional hammer of traditional code, we don't need a nail gun for everything, right?
And so, for example, there's a whole field of neuro symbolic fancy term, but basically a combination of generative ai, neuro kinds of processing along with traditional symbolic languages. So you see people, you see companies announcing things like security guardrails, compliance agents, those aren't all AI based technologies. A lot of that is procedural logic that's added on top of results from, from AI may have some AI components to it as well, but it isn't necessarily throwing more AI at the problem.
And, and when we seek higher levels of accuracy, a lot of that is symbolic language processing against ai. The other part of it is, I met with a startup during, uh, reinvent that is, is creating technology that will take AI content or generated content or data that's used by AI and create more symbolic, um, processing against that. So taking the results from AI and now saying, now future executions of this, we'll do, we'll do a symbolic processing result or process against that.
So we're not consuming tokens every time, which are extremely expensive, or we can collapse the amount of tokens that we need by optimizing the AI part of it. So it's, it's not a, everything is gonna consume massive amounts of tokens. Yeah, we're gonna consume a lot more of them, but there's an economy of mixing these technologies together.
So mi Mitch, that's an evolutionary step, right? First you, you kind of invent a thing and then you put your efficiencies in. Mm-hmm.
That's what you're talking about. We've got more Efficient. I I I, I would disagree, uh, walking around AWS reinvent last week, everybody, and you could see it was becoming a major conversation.
This whole notion of finops and applying it to ai because people are already at that point where this stuff is too expensive to run in production environments. And, you know, that comes back to, you know, Andy, there's this word called observability. Are we gonna apply that to AI and finops or what?
Absolutely. I mean, you know, there's a whole bunch of things you need to observe within the AI infrastructure, within the architecture itself to make sure you're doing the right thing. And it's not just token use, right?
That's a cost issue. Finops is obviously very important, but it's also about quality. Am I using the right LLM?
Am I, are my people using the right LLM? You know, um, are they asking the right questions? Are they passing through PII through to a public LLM, you know, are they submitting my IP to Claude and now Claude's learning how I'm coding and now my competitors are learning how I'm coding as well.
There's governance issues there, there's cost issues. Absolutely. And, you know, there's actually, um, well ESG value here, right?
I mean, Alan brought it up at the beginning of this block talking about the resources that we're using. We are literally pillaging the landscape for this stuff, right? Uh, and it is normal.
Uh, and, and Mitch, to your point, you know, talking about the idea of the, of these revolutions, this is something I wrote literally 20 years ago, is first comes the revolution, then comes the management. So management tooling is absolutely gonna be part of this gold rush. Actually, let me back up.
Management tooling is part of the general store that is servicing the Gold Rush. You know, you've got hardware vendors like HPE and a MD, obviously Dell, as you said, ly Nvidia, you've got the cloud players, AWS we saw that last week at reinvent everywhere AWS doing ai, um, SP you know, the service providers like Equinix, IBM, um, but management tooling is absolutely gonna be the thing you're gonna have to provision and deprovision dynamically these resources use an incredible amount of money, cost, power, water, this sort of thing. But, and you know what?
Mining was always a dirty business. Uh, we still see the impact on the landscape of failed mines certainly here in Colorado. We remember the Gold King mine, uh, leaking out into the mighty Colorado River.
All this toxic waste. Um, we do need new inventions, Alan. We need new energy inventions.
We need new efficient water and efficient cooling mechanisms. Um, otherwise we are absolutely gonna go back to, you know, to torture the metaphor, the disgusting, dirty, toxic environment that was gold mining. We're just gonna apply that, I guess down to data mining, and I would love to see us do that a little bit better.
Yeah, I mean, look, you know, you don't wanna invent LA last centuries Pittsburgh steel town, right? That you would, that's not what we're looking to do. However, here's, here's, lemme give you the good news.
The good news is we are at taking this on in an open approach, it seems. So rather than each con, each company, each player here, you know, in essence reinventing the wheel, starting from scratch on their own, saying, keeping it close to the vest, not sharing it. We we're in a collaborative way of doing this, taking a page from open source software even right?
Where you, you got like Linux Foundation or Cloud Native Computing Foundation, right? They're sponsoring these open things where it, that rising tide lifts all the boats and then people can innovate from on top of that, right? And so with this sort of open approach, it speeds innovation, it speeds standardization and, and, and standards and, and best practices, and then allows people to sort of solo on top of that, right?
And, and, and exhibit their creativity. I believe the phrase is necessity is the mother of invention, right? Yeah, Very True.
Well, if, if, if I may part of the open thing here, and one of the big things that is in the announcement is the, the, and Kimberly alluded to this with Juniper being part of this, and a MD being part of this is the current sort of AI infrastructure stack is Nvidia based, which means that it's, um, uh, NVIDIA's networking protocol, uh, which is based on InfiniBand, whereas this will be ethernet and most likely ultra ethernet, which is an initiative brought up by j Mets and AMD's part of the, one of the founding members, and running the, uh, ultra ethernet consortium to drive everybody towards the commodity of ethernet versus the, the proprietary fin band environment to be more open. So Jack, I noticed that they're using NVLink for me from Nvidia in there. Um, so, but I didn't catch what that was all about because I'm not a network specialist.
So, Uh, they're probably more that the existing Nvidia GPUs are NVLink based, but there's a drive from AMD's, GPUs and the other, uh, and uh, I'm assuming, and I haven't looked into the Google and some of the other GPUs that are now becoming on the market, will probably more be more ethernet based rather than envy link. You know, I think it's, it, we have a habit of thinking we're gonna solve the problems that we have with the ways, the current methods of that we use for solving those problems. So, for example, I think fintech's gonna get reinvented.
We've gone through this, this evolution before with just take, take sql for example. You know, and when I started in databases, you wrote your sql, you ran it, the CPU went wild, or the disc disc activity was insane, you pulled it back, you figured out how to make it more efficient. Then we had DBAs who would work on that.
Those SQL statements try to make 'em more efficient. Then we built query optimizers that the, that the DBAs use to, to optimize those. Today, the system optimizes the queries themselves.
We don't, I mean, yes, we can do things to make it more efficient ourselves, but that happens automatically. I think FinTech is moving up up the cycle and will be automated as part of this when it comes to token and token consumption and prompt optimization, things like that. So it's, I think that will all be reinvented in a, in a different way rather than waiting for the bill to come out from AWS Google and Microsoft to say, damn, that's expensive.
Who, who did what this month that caused that to spike? Oh, I think we're gonna reinvent a lot of things, Mitch, um, you know, asset management to understand where we're putting all these workloads or configuration management to make sure we're not overusing, uh, various resources, uh, and specific resources like GPU instead of CPU. We've been doing CPU monitoring for the longest time, now it's all about GPU.
So now we've gotta figure out new ways of monitoring even, uh, let alone provisioning access management identity. Think about all the agents running it as ai, and now we've gotta have agen AI as part of our access management. What role is, uh, an AI agent gonna take in our role-based access controls?
You know, there's all sorts. We're gonna reinvent all sorts of management tooling, uh, to deal with this. This is always the way we do it.
Agreed, agreed. Hey guys, we gotta, we gotta pull the plug on this se uh, segment though. 'cause we, we, we have time for our third segment.
So great conversation though. We're gonna take a break here on Textron Gang. We'll come back.
Mike has more Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in. If you watched the show last week, we were talking about how cumbersome multifactor authentication is, but Jack Poller has an article on Security Boulevard.
It's worth a deeper dive on it 'cause it suggests that maybe we are not as secure as we think we are with MFA, and maybe we're kind of leading everybody down a primroses path that might have a bad ending. But Jack explain. Well, let's start with, before we ever get to ai, we need to authenticate ourselves, right?
And we have to prove that we are who we say are, we are. So we started years ago with passwords, basically a shared secret that says, if you know the, say you have the same secret I do, you are who we say you are. And then we said, Hey, passwords are easy to steal.
We can convince people to give up their passwords very easily. And you store all those passwords in central database that can be stolen. So let's change that from something, you know, the shared secret to something, you know, and something you have or something you are.
And that would be multi-factor authentication, MFA or two-factor authentication. And we do that with trading. Uh, like you have a cell phone.
So we'll send you a message on your cell phone through a text message, SMS or we'll send you to a me, uh, a number to your email. Uh, the problem is, in the way that technology works there is very easy to do what we call a man in the middle attack, where we can put a proxy in there to fake that you're typing in on a real login page when you're typing on somebody else's login page, an attacker's page instead. And so you give up to the attacker your shared secret or your two-factor authentication code, and then they can take your information and log in as you and get your access tokens to whatever you're logging into.
And then once they have that, they have your access and can do whatever they want. All of that is technically complex, but doable. Unfortunately, now we have a group called Tycoon, which has built this entire infrastructure to do all of that as a service.
So now the criminals are running software as a service just like the good guys are and the bad guy. Software as a service says, Hey, you want to go set up a page, pay us some money. And we'll, we have all the infrastructure that makes it look like, you know, your login to Twitter, and it's not your login to Twitter, but somebody gets access to it, but, or your login to Bank of America.
We can duplicate that for you. Pay us some money, we'll do that. And then you get access to whoever you phish to get into that account.
Um, it's now so easy. It's basically your password based authentication or shared secret authentication is at this point relatively meaningless. Uh, so what are the alternatives?
The alternatives? They're sort of two good alternatives. One is something called pass keys that comes up with the Fido, uh, organization created something called pass keys, which doesn't use shared secrets, but uses, um, public key cryptography.
And it is a much more secure way to do that. And the good news is, last week, Microsoft integrated passkey into the Microsoft's, uh, login process. So now when a website offers you a passkey, you can store it with Microsoft or use your favorite password manager, like one password or any of the other password managers to store your passkey.
And it's a much more secure way to do it. The other way to do it is to use biometrics. Now, I wanna put a caveat out here that there are two types of biometrics.
There are biometrics that are stored only on the secure, uh, device in your computer or on your, like your iPhone or your Android phone where the capture of your thumbprint or your face never leaves the hardware chi, right? So there's no way for a bad guy to extract that and use that recording of your biometrics. There are some biometrics where your data is stored in the cloud.
If it's stored in the cloud, it can be stolen and you don't wanna use those. But anything where it stores it on your local computer is good. And then we have technology from a company called Badge and a couple of others, which never stores your biometrics at all.
They've developed technology that can recreate a private key and public key pair from your biometrics at any time. So you can do phyto keys and other things without ever storing your biometrics, but still use biometrics to prove you are who you say you are. So the good news, the bad news is it's now really easy to defeat password based authentication.
And to fa the good news is we have other alternatives. We just have to get people to use them. Can I ask a question about it?
Um, are the alternatives more expensive? Because it seems like, you know, that always winds up being a hurdle. Every time we have a chat about MFA, They should not be more expensive.
That doesn't mean they aren't, but they should not be on the technology side. It requires the website developer, application developers to integrate the new technology, which imposes a cost on them. Um, but all of these things have common libraries.
There are no JS libraries and other libraries to make it easy for people to do this. And the identity and access providers, as far as I know, are not charging extra to implement Fido because they want to encourage and they're actively encouraging security and secure features and functionality, and they want to help you build an environment where your users aren't compromised. So Jack a question on this, because I read through and the first thing that popped in my mind was whether or not what the barriers to adoption were.
Because, you know, change is difficult. We, we don't like to change. And, um, on one of them I'm thinking that you got a fob that you care, you use, um, for that.
And people didn't particularly like that even though it was very, very secure. Um, so that never really quite took off. Um, and the biometric elements, you know, there's innate fear about it, if you will, um, on that.
And that's, I believe, you know, I, I'm a little skeptical about it, but anyway, there's innate fear and it's changed. So what are you, what are you thinking about can be done to help adoption or, you know, am I right in terms of concern about this adoption and process of getting there? I think you're right in concerns of adoption, it took a very long time to convince people to use MFA.
And in fact, the last time I did a, a research study on this in the 20 23, 20 24 timeframe, uh, just two years ago, uh, more than half of organizations still didn't make MFA mandatory. Even though we understand the benefits at that time of NFA and implementing MFA today, while it's not, um, it is a much better situation than passwords only, it introduces friction into the login. It means there's another step to do.
The good thing about Fido Pass keys is it is actually, once you've set up the pass key, it becomes invisible to you. You enter your username on the website and it says, oh, you have a pass key. It goes retrieves the pass key.
It does all of that in the background. And you don't have to do anything other than say, yes, I want you to let you use this basket to get to this site, but it is a change in the way we behave in a login. And so that is part of the adoption friction.
And I think the good news here is that the consumer websites and Microsoft are driving this because they face significant financial risk from stolen accounts. And so they're really interested in driving this. I've got a few thoughts on this, right?
And, and I've been a proponent of MFA for a long time, right? I think we all know that the, our basic password, you know, trust system is broken and, and we need to get away from passwords. There is tr there still is tremendous pushback on MFA.
I know even here at our own organization we instituted MFAA couple months ago, and the, and the the IT guy on our team who works with Mitch and I gripes still that he can't get people to, to sign on and do it, right? Because people don't want MFA. However, even this MFA Jack, which you're saying is, you know, now becoming a little longer the tooth and not quite as secure instituting MFA, I've seen studies where it will reduce security incidents by 75 to 90%.
Imagine that if I told you I could reduce your security incident, 75 to 90%, why wouldn't you do that? Why would, well, I'll tell you why. You mentioned pass keys.
I consider myself a bit of a power user. I'll admit it, right? My name's Alan.
I go to a website these days and it said, would you like to use your pass key? Of course, I'd like to use my pass key. I'm a security dude, boom.
I want to use my pass key. Which pass key would you like? Would you like your one password pa pass key?
Would you like your Apple Pass key? Would you like your Microsoft? Would you like to scan this QR code?
And, and I, and it was vexing me. I don't know which one should I use, but I I I use 'em all and see which one works best. And you know what?
They all, they, you know what they all do. Really All those ones I just mentioned to you, they're all looking at my face or doing my fingerprint thing or you know, and, and, and letting me in there. Does it give us a better security?
Absolutely. Is it next generation MFA, I don't know, you know, passkey versus MFA, it, they seem pretty similar in some regards to what goes on behind the scenes is different. But clearly I I think our number one scourge is just the majority of people who still use plain old passwords don't even use password managers, right?
You can't tell me in today's day and age, if you're a user online that you shouldn't have 25 different passwords, 30 different passwords for various sites and eight and services you access. And if you're not using a password manager, let alone MFA for them, shame on you. You're, you just, you're the zebra in the herd waiting for the day where a lion picks on you.
So I'll, I'll take the other side of that conversation for a minute. So you, we have had ATM cards for decades. You go to the bank, you put in your card and you typically type in a, you know, four numbers and, and, and you get access.
I, you know, I'm not hearing about people getting hacked by their bank accounts because they have four Oh no bank, I gotta call bs. You know why you don't hear about it? Because we've taken the pain away from you.
It happens all the time. But the bank bears the cost. Yes, it happens all the time.
The bank bears the cost. There are people cloning ATM cards. There are people stealing your pen.
Go look up skimmers, credit card Skimmers, all of those Things. And, and, and, and yet I have not gotten an email from my bank in a decade saying I need to change my pin numbers. And yet I will get an email from, from some your website saying, I gotta change my password.
'cause you every other day, 'cause you, you keep your debit card underneath your socks inside your sneakers and you never use them. Oh, you kidding? Underneath the mattress.
Right next to a sock drawer. The rest of us, I've gotten, I get new debit cards all the time. They say, we suspect we saw suspicious activity.
Here's a new card. Mike hasn't even opened up his card, right? He never from the bank.
He never called the 800 number to activate it. Even I'll, I'll concede there are a couple of cards in my wallet that would classify as that Uhhuh. Mm-hmm.
But, but seriously because, and but there's a lesson there because it doesn't cost you anything. It's just a minor pain in the butt. Ah, someone got my passcode, someone got my debit card thing, I had to get a new debit card, I had to activate a different card.
But it doesn't cost you in your wallet when it costs you in your wallet. All of a sudden stuff gets real. It's when you call the bank.
Yeah. And there Is a lesson there, Alan, that's absolutely correct. And I think part of the lesson, I mean two things which we haven't really talked about.
One is that we need to place less of a burden on the end user for their own security, right? I mean, let's think about this logically. Most people can't handle risk.
They don't get it. They don't understand it. You know, people writing their passwords down on, on post-it notes and sticking them on under the keyboard.
We've all seen this, right? Humans are awful at managing risk. And part of what you're talking about there with the ATM card, the bank is making it easy for you to manage your risk.
They're doing the fraud detection, they're sending you a card proactively, you are not doing analytics on your spend. They are. And they're making it easy for you to deal with the risk.
And then the fact Is, Andy, you don't have any risk. 'cause if anything happens, they eat it anyway. Also.
True. Exactly. And the other part of this, by the way, is, um, and, and you know, Jack, this is amazing.
This is one of the reasons I come on tech, on tv 'cause I can learn stuff. I feel like Keanu in the Matrix now. I'm like, whoa, I understand identity.
Um, but m FFA is absolutely broken. But one thing you didn't say in your article was, how about we don't have a user ID and password for every damn transaction? Look, when I go to the hardware store, I I buy a new toilet.
I, that's it. I'm not gonna get another one tomorrow and then another one the next day. I don't need persistence in my identity.
You've never had for that transaction And you've never had me install your toilet. I was gonna say, I've never broken a toilet heard identity compared to a toilet. But thank you you for That analogy.
Not with standing the rash, and I use the word advisedly of connected toilets that are all of a sudden, uh, communicating with the cloud, doing analytics on my business as it were. Uh, maybe that's for another day. But the idea that we need a user id I pastor for every transaction, I think is a big problem as well.
I know it's about data collection, right? It's about personalization, it's about, you know, data mining. I get why people do it, but that's one of my bug bears.
Look, I don't mind using a token. I don't mind using your MFA, uh, using my windows hello or UB key or whatever it is, if it's gonna help me. But, uh, if there's just no reason why we need so many user IDs and logs in logins for every transaction, no wonder people repeat passwords and get hacked because they get exposed.
Well, I, you know, I don't, I I don't wanna, you know, I could take four hours talking about this stuff, right? And, and there's, you know, you go down one path and it opens a whole bunch of others. But let's just say to Mike, one of the goals of IPA, keys and badge and the other types of technologies is to eliminate that database of passwords, user IDs and passwords that then gets compromised that forces you to get a new password or a new card or whatever.
It's getting rid of the shared secrets is how do we do this technology in such a way and then make it usable for, as, as Andy was talking about, the user interface part of it and removing the friction is part of that. There is a learning curve here that it's something different than a password, which is why it's named, it was called something else else, but they called it now a pass key to put the pass in so that people would associate it with passwords. But it is a little bit different and you know, it's, there's, there's, so it is gonna take time.
It's learning curve. And you know, we still have, we still have organizations that say, you know, your mass, your max length of your password is a is eight characters, right? I mean, that's just insane.
There's, there's absolutely no reason that your password should be space limited at all. We have infinite amount of storage. Why are we limiting?
Like, but you know, I gotta Four hours Remember password somewhere. But, but let me look. I feel, I feel like we left something outta this conversation.
We didn't discuss ai. Well, I, how, how does ai, how does AI figure into this? And, and because let me, let me tell you why.
I think the, the identity problems that AI may cause, could cause are gonna make this stuff look like child's play. Well each of those AI agents has an identity, so it's gonna get crazy And well, and how do I know Mr. Smith from Zion, right?
Is it now looking like Mitchell right back to the red, blue, red pill, blue pills scenario. Mr. Anderson.
Well let me, let me just put one caveat out there. This is why we do not use voice authentication. Yeah.
Anybody who offers you voice authentication refuse it, Right? I mean, And there's a lot of technical reasons why I'm giving that advice, but let's not die there. Let's just say voice authentication is very easy to compromise And, and, and a world of AI cloning.
You bet. Um, so I gotta, I gotta, I gotta go stuff some more money under the mattress. But this was interesting.
You might find an old debit card there. Anyway, few tokens, guys. We're out time.
What a great discussion today though. Great panel. You know, it's good having those Colorado people and they're nice people.
Uh, Mike, happy anniversary. Thank you all for watching. It's, uh, Monday, we'll be back tomorrow with more Techron Gang.
A lot of our EWS reinvent coverage will be re streaming over the course of this week. So stay tuned for that. On, on, uh, Textron tv, we're also putting a lot more of these and a lot of the events we cover up on our OTT app.
'cause we realized it wasn't up there though. It was available on YouTube and our Text Drunk TV website. Um, so check out the OTT app on, on, uh, iOS, uh, Google or, or Amazon Fire, Roku, apple TV and check out my new podcast Agents of Dev.
Yeah, the really, with a really snazzy opening that the, the text drug TV video whizzes came up with. We killed it. Yep.
All right. Hey Mitch, thanks for the plug on that. Have a great day, everyone.
We'll be back tomorrow with more.