Is Jensen Huang Becoming AI’s New Wall Street Banker?
Today’s panel dug into an AI financing boom that is starting to reshape how the industry pays for its own growth. NVIDIA and Wall Street are now co-financing infrastructure at a scale that invites comparisons to traditional banking, and the panel weighed whether that puts Jensen Huang in a role closer to financier than chipmaker. The conversation aired live on Techstrong Gang, where the hosts and guests broke down three stories shaping AI, trust, and security this week.
Inside the AI Financing Boom: NVIDIA and Wall Street’s $500 Billion Buildout
The AI financing boom took center stage as NVIDIA and Wall Street firms partner on structures to support a $500 billion AI infrastructure buildout, according to reporting from Techstrong.ai. The panel discussed why chipmakers are increasingly acting like lenders to keep data center expansion moving. IBM and Together AI added to the theme with a $240 million deal to launch next-generation NVIDIA infrastructure on IBM Cloud. Guests debated whether this financing wave strengthens the AI buildout or simply defers risk to later.
Anthropic Tests Invisible Watermarks as AI Slop Detection Struggles
Anthropic is piloting invisible watermarks for Claude-generated text and files, per Techstrong.ai, as the wider industry searches for a reliable way to flag synthetic content. The panel connected this to Spotify’s move toward AI persona labels and to ongoing frustration with AI writing detectors that often misfire. The group agreed that watermarking only works if adoption spreads beyond a single vendor.
LiteLLM Attack and a New npm Malware Wave Expose Supply-Chain Gaps
A LiteLLM attack affected 2,500 companies and 434,000 CI/CD pipelines, according to CloudSEK research covered by DevOps.com. The panel also flagged a fresh wave of malicious npm packages nicknamed “Flooding Dropper,” along with a new survey tying rising production issues back to AI-generated code. The takeaway from the group: security debt is compounding as fast as AI adoption.
Between AI financing, watermarking, and supply-chain security, the panel made clear that trust is becoming the scarcest resource in the AI economy. Catch the full conversation and subscribe for daily breakdowns of the stories moving tech.
Transcript
Hey everyone, it's Thursday, and welcome to Techstrong Gang. We are really grateful you're joining us. Whether you're watching this live or you're watching it on demand, we're grateful to have you here as an audience.
I'm also grateful for some great Gang members we have today. We've got some newer Gang members, some older Gang members, and that's what makes Techstrong Gang great. Let me introduce who we've got for today.
First of all, I think it's his Techstrong Gang debut, but I know Paweł from the cloud native and DevOps world for a long time. It's my friend Paweł Piwowarski, and if I mispronounce it, I always mispronounce it, Paweł, forgive me. Hello.
And so Paweł, welcome to Techstrong Gang. It's great to have you here. Yeah.
Great to be here. Joining us. Thank you.
Yeah, it is. Next up is my friend Yvette Schmitter, a genuine New Yorker. Always good to have Yvette here.
So we went from Poland to New York, all the way to the Land of Oz. Our friend Alastair Cooke from Tech Field Day. Alistair, it's good to have you.
And then from New Zealand, it is around the world like a small world. New Zealand to the West Coast of the US and Silicon Valley, Jon Swartz. Good to see you, John.
And then a quick transnational flight from California to New York, back to New York, to Mike Vizard. Wow. A global panel, to say the least.
It makes it exciting. Welcome, gang. So Mike, it's Thursday, just another Thursday in the world.
So much craziness going on, a lot of it to do with AI, but what do we got in store today, Mike? Let's start us off. Well, NVIDIA's at the heart of this financing boom around AI, and the latest is a $500 billion deal that they worked out with a bunch of Wall Street investors.
Some would say this is just part of the ongoing circular financing, and some of that money apparently is also finding its way over to places like IBM Cloud and Together AI, and John covered some of that, and James, and a few others. P. Morgan.
P. Morgan of the Gilded Age fame, who was known back in the day as the Jupiter of Wall Street, and now is Jensen, the Jupiter of AI. And it brings us to this question, are all these wonderful AI folks the new captains of industry?
If you look back in the days, the folks of Rockefeller and Owens were celebrated as the ones who led the investment that drove the massive wave of innovation that benefited everybody, and so on and so forth. But there's another story. There's a story that says that those folks were just robber barons, and well, maybe this whole new thing is the latest flavor of robber barons from the Gilded Age.
Amit, what's your sense of what's going on here? So my take of this is that NVIDIA just turned its chips into collateral for a half a trillion dollars. So Jensen, as Alan eloquently just surmised, he signed like MOUs or memorandums of understanding with Apollo, BlackRock, Blackstone, all the Bs, right?
Brookfield, Goldman Sachs, KKR, to mobilize more than a half a billion, $500 billion, right? So customers can finance, air quotes, "finance" GPUs without touching their own balance sheets. We've been talking about this for a little bit, Mike, the funny money, like Monopoly money.
It's like, where is it? Which books are they really on? Are they really on their books or are they off books?
And who carries the risk at the end of the day? So Jensen is calling compute investable asset class. I love how these folks who make the thing, build the thing, sell the thing, create these new terms that make them valuable, right?
So now there's a new asset class and they hold the option to backstop up to $125 billion. Where are the zeros coming from? That's my question.
P. Morgan, the Jupiter of AI. But look at this, the backstop is this.
P. Morgan, back in the 1907 panic, right before any central bank existed, Morgan personally organized private money to catch the system. Now, watch the circle through.
NVIDIA sells the chips, then helps finance the buyers, guaranteeing part of the loans that do what? Pay for more chips. " So the demand number looks bigger than organic demand alone.
It's, again, like Monopoly on steroids. So Mike, you know what? You hit it, but there's an even worse potential here, and let me tell you why.
If you ever watched, well, all of us lived through the 2008/2009 mortgage crisis, right? That took us into the Great Recession. I think it was 2007 it started.
But if you ever watched the movie "The Big Short" or whatever, right? What happened was Wall Street created a new instrument by repackaging what, in essence, were junk mortgages. Yep.
They collateralized these mortgages and made them sellable. That's exactly what's happening here. They're packaging NVIDIA compute into a collateralized instrument that now Wall Street can buy and sell and trade on, just as we did in mortgages.
And we saw how that ended. Not good. Right.
This is the same thing. So that particular deal is just, to me, wow. If you don't learn your lessons from history, you're doomed to repeat them.
P. P. Morgan wasn't just the dean of Wall Street.
S. Steel. He bought out Edison and Westinghouse and created something called GE, right?
P. Morgan was the robber baron. He was the Jupiter of the whole Mount Olympus of robber barons, if you will.
And Jensen is, too. Because they are financing, and it's circular, a lot of it, but a lot of it's hard dollars out. But they're financing energy companies.
They're financing data centers. They're financing people buying their chips. They're financing people buying up the stack from the chips.
And it's not just what he's laying out money. Go look at their BD partner efforts. Everybody wants to partner with NVIDIA because that's the Good Housekeeping stamp of approval, right?
So he literally has set himself and the company up at the center, the epicenter, the nexus of this whole thing, now including Wall Street and these mortgage... Well, not mortgage, but these commercial paper based on the compute. We haven't seen it since- But here's the thing, like for anybody, like for your listening audience, follow the check, right?
For any infrastructure deal, ask who supplies the hardware, who finances the buyer, and then who eats the loss if there's a utilization miss. So one name answering more than one of those is a concentrated risk, not diversified demand. And I think everyone is focusing on the shiny objects.
And I say this all the time, if you want to catch squirrels, do shiny objects. You don't run your business that way. All right.
John, let me ask you this. You've been in the financial media. Honestly, I don't see them kind of asking the tough questions here.
In fact, I don't hear much about anybody shorting this because of this noise in this conversation. So, has everybody who kind of operates in that financial community just got blinders on, or is there something else at play? Yeah, I was going to say they're blinded by the brilliance of Jensen, who they all consider the white hat.
And right now they're just getting around to thinking about capital expenses, right? From their ROI obsession. So in a sense, Jensen, you all put it really well.
He's become more than just a tech vendor. He's a turn-of-the-century business baron or robber baron, whatever you want to call him. He wants to fund a national industrial expansion.
He basically wants to reclassify AI factories from what we should be looking at as volatile tech expenses into these investable long-term asset classes like, look, think about railroads, cell towers, power grids And you're right, Mike, that the investment community and the people who cover this stuff are blinded by $500 billion, the fact that they're the center of this wheel. And eventually they're going to get to this idea or this concept about circular financing. I barely see anything written about it.
And they're going to start looking at balance sheet exposure, and it's going to take a couple of quarters to get there. And you know what I think is going to happen also, and I'm hoping this happens, when companies start going public, like Anthropic and OpenAI, maybe it shines a light more so on the way this money, this funny money or monopoly money, is being thrown up in the air and landing all over the place. So I had this odd conversation with a CEO of an ISV today, and he was postulating the fact that maybe if this bubble bursts, it would be a great thing for enterprise IT organizations.
And the theory went something like this, it said, AI is just too expensive for a lot of these companies, and just like when there was so much fiber and so much alleged demand for fiber, it was expensive. And then when the market popped, fiber was cheap, and then we had all this innovation because enterprises could afford to get fiber. Well, will the same scenario play out here?
What do you think, Alistair? Is there reverse logic in there? I think there is a little bit of reverse logic in that right now, for enterprise organizations, they just can't afford to buy their own infrastructure, and they're paying ridiculous amounts of money for other people's infrastructure.
This is why we're seeing this. One of the things that, for me, comes back to is somebody in the end has to be getting some value and getting a bit of revenue as a result of all of this. And if we don't see that revenue turning up, then we're in the situation Alan talked about where the whole thing collapses because you've invested in things that are giving you no return.
And that essentially, as GFC was hiding the fact that there was no return, well, there may well be hidden lack of return here. We're still in the early stages of AI. We're still at the phases where there is an over-hyped expectation, and the reality of real, production, large-scale use is not here yet.
Right. So yeah, these kind of crazy numbers turn up, and the more I see the crazy numbers, the more cynical about them I get. Sure.
A valuation of $5 trillion for Nvidia for a- Five and a half trillion. Five and a half Let me- Oh, I'm sorry, Jensen. I apologize.
But for a graphics card company, right? Let me bring Palin into this conversation because we don't get enough of this perspective. But you're sitting in Europe.
Do Europeans look across the water at all this and go, "Boy, those Americans are nuts"? Well, so let's say it this way, we in Europe see this, that you Americans are doing your American stuff, right? With trying to monetize everything that is possible.
So probably we will monetize very soon that there is not enough power in AI, so someone will try to do these options, whatever kind of things that you will be able to benefit from that. But I want to look on this from a little bit different angle, because this is also the investment in infrastructure, right? So I did the check.
In last six years, we had every single year almost, even sometimes faster than one year, the new chip, which changed the perspective, right? How AI can be run. One year, and you pay crazy money for any single chip.
We thought that chips were expensive when this crypto boom was there, right? So you are collecting, let's say, hardware, which in two years will be old crap. Yeah.
For what kind of money, right? Crazy money. And there is a push to bring new hardware each year.
Well, that's the thing about these data centers. Every three years, you got to retool them. Yep.
Are you saying that that $200,000 car that I just drove off the lot isn't worth crap anymore? Correct. Yes.
Oh, depreciation. Yes. Yeah.
And it's still powerful, right? It's still able to do everything that you need. But someone else, your competitor, is buying more expensive, more powerful.
You have to do the same to be in this competition. Well, it's a Cold War arms race kind of thing. But the point is, this is exactly the indispensability trap, which was my book, right?
When it becomes this ubiquitous, when it becomes indispensable, the powers that bear on it, the market forces, the government, antitrust and those kinds of things, put so much pressure on it that it's not where the enduring wealth stays. The enduring wealth moves up the stack, away from this just grid, if you will. And we spoke about it earlier this week.
As these open weight AI models get more popular, and they become smaller and easier to run, do I need this big data center with all those gas turbines, right? Groq- Groq came out today with a new one. I'm sorry, go ahead, John.
Oh, no, I was going to say, that's really funny. Yesterday, we were talking about data centers, and we were talking about... Sorry, I'm not digressing, but we're talking about the hum and the noise pollution.
Of all things, I was listening today to a sports talk show, and they started talking about this. So it's- Oh, it's mainstream ... yeah, it's been all mainstream now.
And these numbers, it's like funny money. It's just all make-believe. It reminds me so much of 2008 era.
I'm sorry, Alan. No. Yvette, let's just take it full circle here.
What's the problem? The United States government, AKA the United States taxpayers, just standing by waiting to bail everybody out. Come on.
Well, why you always come to me with these, like this one, Mike? You set me up with it because you know I'm going to go. Okay, so all right, go.
So here's the thing, everyone's talking about old days of yore and the financial crisis of 2008. You have Dennis, who just said AI needs to be regulated like FINRA, right? So take that, like FINRA.
Then now you have movement happening up through the Supreme Court, so you don't have to do the type of financial reporting that you need to be doing to give that transparency to see all the funny money, right? So then you have most Americans stuck to their phones, scrolling TikTok and Instagram, and no one is understanding that your data is now more valuable than your vote. And when the time that you pick up your head from your screen after making your squirrel video flying a jet, it'll be over.
So I do think people really need to, I'm going to go back, read the terms of service when it tells you that it's going to keep all your stuff, even when you terminate. It's going to keep it. Your data is valuable, and if you start operating like your data is valuable, I think then we're going to have a turn.
But Mike, the way that the winds are turning here in the land of the home and not so free, we are going to have a situation- Wow ... where the titans of tech are going to lead everything. We have AI in banking, health.
It's everywhere. It's everywhere, everything. You can't even talk to a live person without getting a bot who messes your name up.
Even when you say the numbers, it gets it all wrong. If these people are driving, building it, creating it, selling it, the government is allowing them to do it with no guardrails. Unfortunately, Yvette, nobody reads the fine print.
It's all about convenience- Yes ... with all the here and now needs. Yes.
And the government is in on it. Yes. They're getting paid.
They're owning percentage. They are. Those 30 companies that they now own percentages of, and yet they yell and scream about socialist and communist.
Yep. But Mike, we got to hop. We got to hop.
All right. I'm sorry. I got to keep us moving.
All right. Well, let's move to our next topic because it's less controversial, shall we say. Okay.
So here we go. Anthropic is saying that it's going to put a watermark in content that is generated using Claude. The idea here, I guess, is we all want a little transparency into this content because, well, some of it is quality, and a lot of it is not.
So maybe people want some mechanism to know what that is. There are other ways of apparently finding whether or not this content is slop or not, so I don't know if a watermark is required, and I haven't seen anybody say they were going to build a AI content detector yet for the watermark, but who knows? Maybe that's coming.
But Alan wrote a column where he was kind of semi-outraged about the fact that somebody was attaching a scarlet letter to the generation of AI content. Alan, by all means, explain. Yeah.
" And it was one of the guys manning the ramparts at the fort that's falling apart, that AI's going to make our brain mush, it's going to turn us into non-humans. " Progress, no man stops progress. And progress is here.
So I wrote an article begging people to use AI, but not to just abdicate and say, "AI, write this. " But no, for those people who've worked with AI for writing, there is a process that you learn, that you develop with your AIs in terms of helping me frame the argument, helping me define the flow, going back and forth, doing the research, giving a draft, take an edit, go back and write. There's many shades of working with AI.
When you have only one scarlet letter, that scarlet letter may mean it covers everything. Maybe I had just AI do a copy edit. Well, nope, now you used AI because it's become a scarlet badge, a scarlet letter.
Right after I wrote it, a couple of days later, I saw an article from my friend Brad Feld. " He might as well have said just what these articles say, right? It rots your brain.
Socrates said writing made us stupid 2,400 years ago. And history has followed ever since proving how wrong that is. Mike, I have read a lot of stupid articles, though, so I got to say.
By Socrates? No. And then Reid Hoffman of LinkedIn, of course, one of the co-founders of LinkedIn and VC's.
Reid Hoffman wrote an article, I think a Substack on it. " Whether they used AI to write it or their mother-in-law or what have you, they put their name on it. They're standing behind it.
And if that's not good enough for you, don't read it. And again, I'll defer to Reid Hoffman and Brad on this because that's right. So I wrote a second article in regard to that, that, Mike, we do have AI detectors.
There's a whole cottage industry of programs that supposedly can detect AI. They're all full of crap. They can't detect diddly.
In the meantime, we had flying cars on "The Jetsons" 50 years ago. I still don't have a flying car, right? I'd rather put our money there than trying to do AI detectors.
So now I wrote this article today because Anthropic's doing this. Now Anthropic is saying, well, we want to comply with the European, the EU thing on labeling AI. Mike, you and I have talked about this.
What do we got to do? I've done research on it. I just wrote up a fresh new TCs and privacy policy that's on all Techstrong sites today.
According to the EU policy, as long as we have a human editor look at everything we're publishing, edit it, approve it, publish it, we are in compliance with the EU. The EU says we don't need a scarlet letter. This is Anthropic overstepping.
And as I said, in its socialist kind of way, it's cutting all the grass at the same height. Whether I used AI a little bit, a lot a bit, or all of it, it's still the same scarlet letter. It's a bad policy.
Get rid of it. So you put a lot of emphasis on putting your name on the article. John, when was the last time anybody ever read a byline or remembered, or heard, or thought about who wrote that?
They read the headline. Yeah, 100%. I'm going to say something that is probably pretty obvious.
When I was at Dow Jones, the only two things they cared about was their headline and the lead. They didn't care about any of the rest. I had people literally editing stories, but they only cared about those two things.
Even the editors didn't read it, and they could care less about the byline. And it's getting back to what Alan said. I think life is about nuance.
It's not, but unfortunately, we live in this world of black and white, especially around AI. The way Alan uses AI is kind of similar to what I do. It's about give and take.
It's about honing, refining. It's about researching. It's about getting opinions and having it edited or maybe throw things back at you.
It's not as clear and as sinister as many people think it is because they don't use it. That's the problem. Until they start using it, they don't understand.
Just to dismiss it as a creation of slop, it kind of completely misses the point for most people, I think. All right. So Pawel, what's good for the goose is good for the gander.
Am I putting watermarks on code now? What do you say? So yeah, it's again, the discussion about European Union and stupidity of it and regulating everything.
What is not true, as you said already. So, yes, EU provided even the icons you should put in the AI-generated pictures and things like that, but it's more like a courtesy than anything else. But I like to see myself as AI fan, not AI fanboy.
So I'm trying to find both sides here. So, for example, once I asked the owners of one of the biggest blog platform there, you may think what I have in mind. Why should I pay you $20 per month or something, whatever, for reading the articles which I can generate in the same form using free ChatGPT?
And another part of the story, if I am the carrot seller somewhere in the neighborhood market, and I'm using AI to understand how IT works and so on, that's fine. But if I'm trying to impersonate myself as an experienced leader who has thousands of issues in the team but fixed everything in one day, something is wrong. So I'm using AI a lot.
That's my commission here. But I'm trying to use this as, well, a tool. Which helps me to research, which helps me to put my thoughts into digital paper in better way, find out what I miss, and so on.
But also what I'm trying to do is to understand where AI can make mistakes because it does mistakes all the time, even more than me, what is a little bit crazy. So it's like a back and forth with AI. So I'm not against, for example, generated images, generated music, generated text, and so on.
But let it be done by someone who has at least some experience in the area and understand the broad topic, and this is the tool which we use, like this writing machine. Not the pen or the feather from goose to write the letters. That's it.
So these are lovely, noble sentiments that you're all expressing, and I applaud you, and I share them. Alister, the reality is that AI is going to be used to create massive amounts of content that will overwhelm all the quality content that we are creating, and we'll just get lost in a sea of crap. So is there some middle ground here to be found to kind of maybe delineate between AI slop and legitimate content that maybe doesn't require a watermark?
But is this something we need to address? So I'm still struggling with the idea that a watermark that says you used a tool is a problem. In the same way that, as Alan says, you move from writing with a quill to writing with a typewriter, it's very visible that you used a different tool.
So how is it a problem that we're making it visible that you're using a tool? No, because Alistair, you're missing the scarlet letter aspect to it. There's a stigmatization involved.
Right. And there's the challenge, right? Yep.
So how do we address whether using the tool is a good thing or a bad thing? The tool's going to be used no matter what. The tool can be used to do absolutely awful things.
Hallucinations, impersonation. We've seen a whole lot of deep fake kind of content. We'll see it again next time there's US elections.
Being able to readily identify that these things are not legitimate, that they were not representations of any reality is a useful tool. But the blanket approach that the moment you're using AI, what you're creating is rubbish, there's actually a problem, right? Yeah.
That's the perception now. Can I also mention I'm like- Hold that thought. I just want to follow up one thing with Alistair here and Alan, since you both brought it up, but where is the stigma?
Who cares that you used AI to use this? Is this stigma in your head? Because where's the stigma in the world?
There's absolutely stigma in the world. Go on your LinkedIn feed and read what people think and say. And also, this is applying also to music with Spotify, right?
They have this new AI persona badge that focuses specifically on artist public identity, so it flags profiles with photorealistic synthetic human personas. But guys, this is a phase. It is.
This is a phase we're going through as we normalize what AI can bring to us, right? It's a phase. We went through it when we went from quill to typewriter, typewriter to word processor.
When we went from the printing press to the computer screen, right? These are all different phases that at first people clutching their pearls saying, "We cannot let this pass. We cannot let this be.
We're going to be drowning in slop," as Mike says. Yeah. If you think about Hollywood, too, remember all the resistance to any type of technology when sound came along, editing- Sure ...
cameras. Well, look, real movie people will tell you if it's not black and white, it ain't crap. So when is- This color stuff doesn't work ...
so when is AI writing Pride Day coming? There's one thing that we are kind of not touching on. Nobody had a problem when they used the whole entire freaking internet to train, right?
So they treated the whole internet as free training, right? These labs did whatever, asked no one's permission, swallow credible writing with toxic material with equally indifference, right? And then you have documented cases from here in the US and German labs where they show over 1,000 verified links that had child abuse imagery next to racial slurs, no difference, right?
But provenance mattered to nobody while these models got built. Now, the same industry is trying to selling provenance as a feature. So the watermark just certifies that Claude produced a passage and says absolutely nothing about whether it's true, and I think it's smoke and mirrors.
It's like the biggest crime in my perspective is that they use the internet to build this stuff. My New Yorker's going to come out, build this stuff, right? Good, bad, and indifferent.
And so now if Claude just makes sure that your sentence is grammatically correct, it gets watermarked. Marked. Right?
And now that's the problem? Right. The problem should be is it true?
Is it real? Exactly. Alan, man.
I love you. I can't with you. It's that New York thing.
I miss my New York thing. Mike, but Mike, we've got to pop, man. We're 33 minutes.
We've got to move. I believe the New York word that Yvette was looking for was crap, but okay. No, that wasn't- I'm thinking of another word now.
No, Mike's from-- He's up in Westchester. He's lost his edge. Yeah, like Alan and I, we from Brooklyn.
Yeah, I know. That wasn't the word she was looking for. But Mike, let's go to three.
Let's go to three. Come on. I try to remember CP rules when I can.
All right. All right. Moving on to our next topic, which I'm going to call Pawel and really- Yeah, so next topic is kind of related to what we talked because it's also about LLMs or AI, but this is just the ground for what we want to discuss and- Let me set this up a little bit.
Let Mike set it up for you, Pawel. Where I ended up here. All right, so we are seeing a series of these software supply chain attacks.
The latest one has like 434,000 CICD pipelines have been compromised. There's another flood of NPM packages out there, and there's a survey talking where, I think it was Sauce Labs did this one with Wakefield. And they're talking about the fact that we're not testing enough of this AI code, and therefore we're seeing more issues in production, and that's probably not that much of a surprise, but it doesn't mean we're not going to use this stuff.
It just means we don't have a plan. So Pawel, I think that what I want to get at here, though, is we have these systems for building software that are incredibly complex, and are they too complex? And now they're overwhelmed by AI code, and we need to just kind of look at all this stuff again and maybe start over because we seem to be smashing a bunch of AI stuff on top of a very fragile ecosystem to begin with.
What do you think? Well, I agree with you to some extent, is that the fragility here is also created through using a lot of AI tooling around, but it's not the root case. Again, with these watermarks, right?
And we are thinking about watermarks, not about who is the real author of the content, on which LLM was pitched. The supply chain is complex, yes. It contains a lot of input information and input software, let's call it this way, because today, when we create any kind of software with any modern languages, we are collecting a lot of dependencies.
When we use NPM, it's like 1,000 of dependencies, right? And I'm sure that maybe not in most cases, but in most cases when we download those dependencies, at least once NPM will say this package is a little bit suspicious. And it's not the first time when we hear about this kind of situation when some NPM package or PI package or whatever was infected somewhere on the beginning, somewhere else, not in our supply chain, in somewhere else supply chain, let's say.
This is the biggest problem. We are depending on so many elements around that doesn't matter. Of course, it is very important how we secure our supply chain, but it doesn't matter how secure we are.
What matters really in this case is how aware we are, what we are downloading, what we are using, how we are able to check what is there. Is this time-consuming, compute-consuming, slowing down our delivery? Yes, it is.
That's why we just throw it away because we don't have time for it, right? And then we see like 500,000 infected pipelines. And this problem very often has only one source.
The one second of bots wandering from the main maintainer of this library. We saw this many time that really two minutes later the guy wrote, "Hey, I just clicked this link by stupid accident. Just don't take this package," and so on and so on and so on.
But it was downloaded already 10 million times Right? No. The problem is, well, us, we're human, and how we are able to switch a little bit our, well, it sounds bold, but security posture, private security posture, in the times of AI.
Because with AI, attacks are much faster than it were before. Scale. Oh my God.
So there was a survey done by Sauce Labs. They surveyed 400 executives, and 80% traced their AI, the issues, based off of AI-generated code this year. And those same freaking companies cut 42% of their QA testers.
" I'm like, yeah, these same folks moved the human, put an AI there, and bada boom. I almost can't- Yeah, but Yvette, let me play devil's advocate there for you. Okay.
What's Sauce Labs do for a living? Time out. There's this thing you do all the time where you just want to denigrate something you don't agree with.
Yeah, that's true. That is true. Denigrate.
Doesn't really work. Well, like what- Mike. When a testing company's telling me we don't do enough testing, that- You don't have to...
Come on, Alan. You need to tell me. That's just throwing the argument.
We're just saying it right now. A testing company doesn't need to tell me that we're not doing tests. Like a testing company doesn't need to tell us that.
We see it every day. Yeah, but- Pawel is absolutely right Nobody was doing testing before AI. Yeah.
There's just been less of it after, so again. Exactly. It is what it is.
Pawel did touch on it. The supply chain is it because think about it. You remember Change Healthcare?
The biggest healthcare breach? They got got, not because they didn't mess up. " So the thing is, you can be all good, but someone down the line that you use or you need their data, or they need access to your data, is going to get got.
It's a fact. We're seeing it. " I just got one from Tally.
I forgot that I even used them. I just want to be able to stack up all my free credit monitoring so they don't all expire at the same time. I just want to know, and maybe I'll ask Alistair, but what is to be done about this?
I get that there's an issue, and we have all the dependencies that Pawel described, and we are all dependent upon a couple of maintainers who may or may not do the right thing in a given moment. But by the way, nobody's paying those guys, so why the hell should they care what the problem is? Because it's not their job.
What are we supposed to do to fix this? " That's not how supply chain works. Your supply chain is all of those external dependencies.
If you're not checking those external dependencies, if you don't know the providence of those external dependencies, you have not managed your supply chain. Spot on. And I'm telling you, that's exactly what the problem is, because you're thinking, "I'm good," and you ain't checking who's downstream from you.
That's on you, boo. Absolutely. It is on you.
If you say that your ish is tight, then anybody who touches your API, gets your data, has access, you need to be all over them like gravy on grits, because that is how your tookus is going to get took. And every package that you are pulling from, an NPM repo or any other kind of source repo, whether it's a Docker container that you're pulling from Docker Hub, this is all your supply chain. This is all things that are running inside- Yep ...
your environment- Yep ... that you are trusting- Yep ... with the keys to the kingdom.
Often, the literal AWS access keys to the kingdom. Yep. And so if you ain't watching what's coming in- You're going to get got ...
you're going to get took. I got to love this. We've got Yvette having Alistair use the word ain't.
You don't see that very often down in the land of Oz, but good on you, Alistair. Does it create a slight exception with you here? I do not live in the land of Oz.
Let me go back to Pawel. That's a big island to the left. Oh, okay.
Let me go back. Oh, okay. I thought Oz was New Zealand.
Oh, no. " And they go, "Yeah, well, thanks for letting me know," and then what? Yeah, so this is the whole point about looking at your supply chain.
Supply chain risk is there is a single developer for this thing that I'm very dependent on. There is a dependency on the dependency, on the dependency, and at the end of that chain is a piece of software that hasn't been updated in the last 20 years because the maintainer actually retired. If you don't know that, you are not managing the risk in your supply chain.
It is a choice to use at least the top-level package, and then understand the series of dependencies, which gets really complicated because with those dependencies are chains partly through. Yeah. There is also a surprise because those packages, which are dependencies for us, they have their own dependencies.
Yeah. Yeah. And- So on and so on kind of thing ...
they have a platform and dependencies. So here's the thing. If I was 42 years old again, and I was looking to go start another company, because I have a hole in my head, and I needed a great idea for a company, and I can't understand why no one has made this already.
I want a repo firewall. I want a firewall that sits in front of my 12 biggest repos, that has an IDS system of signatures, that has the latest versions of what I'm dropping down, that keeps up on what I have dropped down, and then when there's a new one, it lets me know that I got to patch it. That doesn't let vulnerable packages from a repo into my fort, into my house.
Why can't we make a repo firewall? I've seen a couple of companies announce those things, but I don't think anybody's actually implemented them or... I think we should start the Techstrong gang.
Go raise some money. We'll call it an AI repo firewall, an AI-powered repo firewall. Agentic, of course.
And there's your solution. And we're going to sell out this company in six months after launch. What do you say?
As soon as we can. As soon as we can. Before they figure out it doesn't work.
But anyway, hey, we're at the end of our time, though, guys. I had to come in here and shut it down. What a great discussion today, though.
Good stuff. Great panel, great discussion, great topics. Pawel, thank you for joining us.
Yvette, as always, thank you. Alistair, I know it's the middle of the night there. Thank you.
John, and Mike, as always, thank you both, but it's our job, so I appreciate you coming on here. Thank you for watching. Hey, just as always, we're here live every Monday to Friday at noon, Eastern Time.
We're also available on demand on Techstrong TV, Techstrong TV YouTube channel, Techstrong TV OTT channel on just about any screen you want to watch this stuff on. And we've got Techstrong TV on most of those channels immediately following this. Looking forward to tomorrow's show.
Mike, you'll be riding the bus there. I don't think I'll make tomorrow. But until then, everyone, this is Alan Shimel on behalf of Techstrong and Techstrong gang.
Thanks for watching.