AI’s Impact on Society & Cybersecurity | TSG Ep. 934
Alan, Mike, Mitch and Stephen Foskett, president of the Tech Field Day arm of the Futurum Group, discuss the viability of artificial general intelligence (AGI) and superintelligence initiatives before diving into how AI is being used to build software. Then the gang takes a look at the state of cybersecurity following a Field Day event that can be found on Techstrong.tv.
Transcript
Hey, everyone. Is the AI apocalypse upon us. Again, you're watching Textron Gang.
Hi everyone. It's Alan Shimel. Or maybe it's not.
Maybe I'm an AI fake, who knows. But, uh, welcome to our Tuesday edition of Textron Gang. Thank you for joining us.
We have, uh, a good stuff to talk about, as usual, a fair dose of ai, a little security thrown in, and we've got really some core gang folks here to talk to us about it. Let me introduce you to them. We've got Mitch Ashley, Stephen Foskett, Mike Vizard, and myself in our world these days.
But, uh, here we are on Tuesday looking at some fresh stuff to fresh fodder to go over on our gang. What do we got? Well, if you look across the spectrum of almost every publication these days they were talking about in some form or another, well, is this AI stuff gonna pan out the way we think it's gonna be?
Even such August Publications now as Foreign Affairs as Magazine has an article this week talking about how maybe the pursuit of all this, um, AI general intelligence, is gonna be a waste of time and effort and money. 'cause we're being conned out of our shoes written by two professors, one from Georgetown and one from the University of Pennsylvania. Then you have an article over on Textron AI talking about similar issues about what's real and what's not real, and everybody's not quite sure where we are on this adventure.
But Alan, let's start with you and your kind of sense of what's gonna happen here and can we get to super intelligence or should we just kind like, focus on what we know is good for now and go slow and steady? You know, I'm, I'm, I'm not usually a slow and steady kind of guy, but when it comes to ai, I, I, I think I'm, I'm becoming that. Let me just say the article you mentioned on Techstrong ai I put together, um, couple of things that kind of got my brain thinking on that was one, I, I saw a bunch of posts and reports that, uh, you know, AI is now passed the legendary Turing test, right?
Which was always said to show consciousness and sentient or what have you. And I think we, I hope the, the four of us can agree that whether or not it passed the Turing test, I, I don't think we've achieved superintelligent sentient consciousness or anything like that. So I think we have to downgrade the Turing test as the benchmark for these things.
Secondly, you know, it's, I some people call it the dead internet theory. I call it the AI lop quandary, which is we are literally drowning. But if we're not drowning now, it's up to our necks.
We may not realize it's getting up to our noses next, uh, in ai lop in AI generated code and ni AI generated content and AI to the point where it overwhelms our ability to filter, it overwhelms our ability to distinguish, it overwhelms our ability to just correlate and collaborate and make sense of it all. You know, and, and no less than Sam Altman. And I always get a kick outta Sam Altman talking about AI doomsday, you know, maybe he should write a big fat check towards that.
But, um, but no less than Sam Altman, you know, bringing this up. Um, the other thing is we we're hearing more and more about how this is affecting the human job market, right? Not in my article, but I did see it over the weekend.
Uh, a bunch of deans at schools are saying that, uh, computer science graduates are having an impossible time finding jobs, you know, and we, we sit out here and we talk about it kind of, you know, in a scholarly, aesthetically antiseptic way about junior developers not having, you know, roles and, and all of this. But this is where rubber meets the road. We're all parents.
We've all had, you know, tried to put our kids through schools and get them prepared for life and, and earning a living and finding a place to work. And if you've got computer graduates in computer science, I'm not talking sociology or some of the liberal arts that some folks don't consider so great, though, as a liberal arts major, I will argue. Yeah.
Point of Order. I have a sociology degree. So there's that.
There you go, Steven. Good for you. And, and you know, so I call b******t on that.
But anyway, back to the computer science people. If computer science can't find jobs because of this, what are we doing here? What are we doing?
Doing? Well, I'm gonna jump in and just saying kind of, you know, we talked a lot about the Turing test when I first got into AI in the eighties, and the Turing test, I don't know, is the right benchmark, because essentially is if you have a judge and you have a computer and you have a, an actual human responding to those behind, you know, in a blind sense, you don't see who it is if, whether it's a person or a machine. It basically, is there a discernible difference between the intelligence being exhibited by the computer versus the human, or whichever is which, and it does that constitute thinking?
And can you do it in a conversational way? I think in a lot of cases, you know, AI today does that already, is it really thinking? It's not a judgment, it's not a real anana analytical way of determining if, if, if something is thinking, thinking and reasoning and judging.
Um, so we throw around the Turing test as a, as a benchmark, and it is one. Um, but it's, I don't think it's telling us whether we've reached that general artificial intelligence level or not. Yeah, I I think that that's the important aspect right there, is that, you know, essentially we built a machine to solve the touring test.
And, you know, if, if you think about it, I mean, what the touring test says, can an average person, you know, can a person interacting with a, with a computer, uh, distinguish whether that's a computer or a person. We've spent billions of dollars and untold resources literally to build a machine that passes the Turing test because the whole point of chat GPT, is to build something that is indistinguishable from a human. But I don't think that Alan Turing's thought was that we would do that, that we would basically spend untold resources to pass the test, which, you know, basically we did.
I think that what he was trying to say was, you know, is it thinking like us? And I think that ultimately what he was trying to say is a really interesting philosophical point, which is essentially that it doesn't matter whether it's thinking or not, if it is able to convincingly convince us that it's thinking. 'cause I don't think that anything we've built is thinking, I don't think, and I, and I think there's good evidence that none of these AI models are actually reasoning in a psychological sense.
I think there's very good evidence that we've built models that are able to convince us that they're reasoning. And I think what Alan Turing was asking was, does it matter? And I think that that's maybe what some of the tech community is asking too.
And I would ask you that, does it matter if it's really thinking if it generates the results that it would, if it was thinking? I think it all comes down to there's an assumption that if it's thinking it's sentient, and therefore we'll lose control of it. And that's kind of where the assumption is behind that thing.
Now, I'm also dubious about, you know, God bless the touring, but we're talking about a test and an idea from 1950 something or other, and we're trying to apply that retroactively here in 2025. And I'm like, I agree with your point. It's kind of besides the point and not the goal in the first place.
But I do think we want machines that are able to help us do tasks and do things that we don't wanna do, and then we need to figure out, maybe, you know, the reality of it is we gotta figure out what we're gonna do now as, as a, as a subset of that. Because we gotta figure out how us plus the machine equals something greater than just the machine. Well, it seems that this is the, this is the kind of ultimate race of the next level of the race, right?
Which company can get to general artificial intelligence, whatever that is, and will that provide them a dominant position in the market over everybody else? Meanwhile, the rest of the market's taking what we have and, and innovations as they continue to come out in generative AI models and MCP and other things like that to help us implement what we've got today. So I think from, from that standpoint, predicting the apocalypse that's for deep thinkers like Alan Shimel to consider and, uh, help us understand better where, where we are on that continuum.
And, uh, over, over a nice, uh, uh, dirty martini. I Think, I think remember Colorado, but go ahead, Mike. I, I, I checked myself A AI will get smarter and then the reasoning engines will get better.
But I'm not a hundred percent convinced that we're gonna achieve a GI or super intelligence or anything that looks like that. I think it's gonna be, um, able this daisy chain in parallel or whatever, you wanna do a bunch of tasks and we'll make it seem like it's intelligent and we can program it so that it kinda has a quote unquote personality. But at the end of the day, it's still a machine.
And I want to take, I wanna take one of Alan's other point there, by the way, which is, and something that Mitch mentioned as well, which is this whole idea that programmers are being, uh, replaced by AI and that, you know, junior programmers can't fight a job because of ai. I think that's true, but not for the reason we think it is. I think it's true because companies are investing in ai and so they're not investing in junior software developers, but I don't think that's because AI is taking their jobs.
I think that's because AI is taking the money, and right now, every company globally is investing so much money in this technology just unsustainably large amounts of money that it has pulled the metaphorical air out of the room for everything. It's not just junior software developers or security and networking pros or whatever it is. It's marketing, it's, um, hr, it's events, it's literally everything customers worth.
We're seeing companies Yeah. Laying, laying off staff and closing buildings and stuff, not to save money or to be become profitable, but because that way they can put more money into GPUs and mm-hmm. I feel like that's just completely unsustainable.
Mm-hmm. So there's, there's an implication in this conversation though, that somehow or other developers and other folks are just fundamentally inefficient and that we are now going to get more out of the senior developers who have more time on their hands to go take on these tasks. They used to assign the junior developers.
And, um, I think that, you know, when you hear all these CEOs talking about it, you know, there's almost a sense of resentment that they had to hire these people in the first place. But I don't know, it's just kind of a weird vibe that's out there. Oh, I, I, I have spoken to CEOs who say, can't I just have 10 people and a bunch of ais and, and do everything we're doing now?
Mm-hmm. Right. And you know, I, I brought this up in a con, Steven, I think I had this conversation with you Friday afternoon.
Yeah. Which is, you know, I was raised, I was trained as a CEO as a founder of a company that your most valuable asset are your people, not your machines. Not even your ip, your technology, your code, your most valuable asset are your people.
'cause they'll generate more of that code and more of that ip. And, and is this really, to your point, Steven, are what we really seeing is a, a fundamental undoing of people being your most valuable asset. Have people become fungible because I, I measure their, their output versus the output I get from an ai.
And, you know, again, Steven, to your point, whether it's truly sentient or just smells, looks and tastes sentient, what difference does it make? It's sentient enough for me to do the job and Who needs on that point? I would, I would make, um, basically another rip from the headlines comparison.
So I, I heard this morning about the, uh, US administration trying to reinstate a program that would supply schools with, uh, locally sourced, uh, vegetables and meat and so on. And, um, and they were saying that when the program was canceled earlier this year, uh, schools increasingly turned to processed foods and the res because they, they basically had hungry students to fill it. It's, it's, to me, that's an apt metaphor for this idea that we're going to replace, uh, pro developers, professional developers with ai.
Um, where in the metaphor, the AI is the ultra processed factory produced foods. You know, is it food? And I'm not standing here saying it's not food.
I'm not standing here saying AI is not able to code. I'm standing here saying it's a different product, and we have to be aware of, we're putting in what we're putting in because that's what we are going to get out. I just think we're at, at a, a level yet, if you kind of get into the coding using, using the tools today, maybe it's replacing the entry level developer, maybe, but I, I actually don't think so.
I think that's shortsighted because people coming outta school now have a different perspective on AI and computers on social media, everything. Right? And somebody has to create the products for the next generation of people and solve the problems in a new way that, you know, the Gen Xers and, and everybody else hasn't, you know, hasn't come up with yet.
Um, but, but the other fact of it is, is it takes a ton of guidance to use AI tools to develop software. And I'm not talking about, you know, some numb school app of I'm gonna go replicate in my, the game that I used to play when I got my Apple two computer. Right?
I I'm talking about building real applications to go into production, and I'm not understating what these tools can do, but it takes a lot of guidance, um, and instruction and correction and redo and iteration to create software that's actually useful and production ready. That at least that's my experience. That's what I hear from senior developers that are using it on a regular basis too.
Yeah. And you know, there's another factor here. There's not all these people sitting on the other end of that pipeline waiting for yet another piece of software to be delivered to them.
I mean, I did not get up this morning and go, oh boy, let me download yet another app. I mean, unless something is killer, I'm kind of like feeling I'm fairly saturated with the software I currently have, and let me, I got too many tools to figure out how to work anyway. And so maybe if somebody gives me an AI agent to help me manage those tools so much, the better.
But I'm kind of not sitting here at the end of my chair going, oh boy, ship me more software. I'm always looking for more software. But, um, let me, let me, let me, let me, uh, let me put a cherry on or crown on this conversation.
I think what we're really seeing play out in real time before our eyes on a day-to-day basis is not the AI apocalypse, but the AI chacha, right? It's two steps forward, one step back. There's the jostling and the, and the fitting in of human, human ability, human ingenuity, human's ability to adapt with this new tool that I, again, Steven says, whether it's sentient or just does a really good job playing as sentient Is, is really challenging us.
And, and, but it's, it's empowering us in some ways too. And so what we're seeing is this chacha this two step forward, one step back as this continues to evolve and as humans react and evolve to it, but don't lose sight of the fact that it was human in ingenuity that invented this. That it's that spark of creation that has driven homo ais and homoerectus and Homo Neanderthal and, and homosapien to, to, you know, figure out how to master fire, invent the wheel and everything else that we've done over the last hundreds of thousands of years.
And it didn't happen in a day. It, it's an evolution. It's a, it's a give and take.
It's a chacha dance. And so to all those people out here who, who claim the, you know, the AI apocalypse is upon us. No, it's, it's not upon us humans, I, I humans will find a way, right?
And, and I think we need to give ourselves the time and have the confidence that, all right, maybe it's gonna be a little harder for the computer science major to get a job in the first month, but that computer science major's going to have some time on it, on his or her hands, and she's gonna go out and invent something using AI that could change the world yet again. So, or or Word, word of caution to those CE CEOs out there that think that they're gonna have, you know, two employees and 10 agents won't be long before those employees go out and start their own companies with two employees and 10 agents to kinda rock your world. So look out for those margins.
'cause they're gonna drop. Absolutely. All right, let's close this one up on Textron gag.
I like that. The AI chacha, I think there might be an article in my future on that. Um, we're gonna take a break here on Textron gag.
We're gonna come back, we'll be right back, uh, with more ai. I say you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group. Hey folks, we're back and we're gonna continue chatting a little bit about ai, but in this case, we're gonna talk about a Dora report that was issued by Google.
They do this every year. And this report finds that, well, not surprisingly, the majority of the people that they surveyed are using AI and they're using it to also write code, and they seem to believe that they are being more productive. I think the median average is people are using it two hours a day, which in my mind is probably about as much time as they actually spend coding versus all the other things it takes to build software these days.
But Mitch, I know I shared this report with you. It was somewhere in the neighborhood of 147 pages. Um, you know, what's your take on what's going on here?
Well, it, uh, we talk, we're talking about the developers using AI and adoption is soaring, right? 90% say that they're using ai. And to your point, you mentioned two hours a day.
I, that's kinda low, it seems like, to me. I'll bet it's more than that. Certainly people that are leaning into AI and using it that, that way.
I think what the report really highlighted, Mike, and, and it's understandable 'cause it's coming from the, the team, the Dora team at Google, is systemically, how much is AI helping us? Because there, there's a lot of stats that say people, it's helping me be more productive, I'm getting more work done, et cetera. But I suspect that's more on an individual basis.
Because when you d delve down into those wonderful hundreds of pages, um, which there's a lot of great stuff in it, uh, they're, they're talking about things like, so what are the archetypes of organizations that are successful being successful adopting this? It's much like the adoption of, of, uh, DevOps Alan that you, you and I have seen and Mike have seen going on over the, you know, past decade of, it's one thing for one developer to do DevOps much different from a different, from a team doing DevOps from a whole large enterprise doing DevOps. And that's very much kind of what the report showed is there are archetypes.
If you've got your systems, your process, your automations, kind of what you're doing well defined already, you're gonna have a better chance of making more progress with ai. If you're living at the other end of the spectrum of chaos and everybody does whatever the heck they want, it is probably gonna be less than, less than productive. Yeah.
I, I, I feel compelled to say something. Right? So this is what's, imagine that, Imagine, Right?
Uh, this is like the, I'm going to guess this is about the 10th, ninth or 10th year of the Dora report, right? And I feel compelled to give a shout out to my friends j Humble Jean Kim, Dr. Nicole Forsgren, who recently left Microsoft to go back to Google, by the way, but not to the Dora team.
Um, you know, I remember when they came up with this whole, you know, Dora stood for DevOps research and analysis. That was the company. They, the three of them started.
And, and it was Dr. Nicole who really put a lot of the academic, uh, backbone into the initial, uh, accelerate reports. And it, it really has become the, the bible for, for so much of what we consider measurable ROI or measurable, uh, you know, uh, KPIs for DevOps, right?
It introduced the, the DORO stats. And you know, you hear about these Dora metrics, you hear about 'em at conferences and on board rooms and in, in, in, in, in pitch decks and everything else. It's become what a, you know, one, an amazing thing they laid down and Google, I, I know what you said, Mitch.
It comes from Google, so it yeah, it does have a slant. Excuse me. But our friend Nathan Harvey mm-hmm.
Has done an amazing job leading the Dora project onward and upward, you know, uh, from the original founders, a lot of times something like that, it gets bought by a big company like Google, and it's just a couple of broken eggs in omelet becomes a marketing report rather than Yeah. You know, good analysis and science research. So ku, kudos to Nathan and the Google team on it as well.
Nathan presented last week at our DevOps experience, by the way, and that, that virtual event, you could still listen to Nathan's and hear it from him himself, his update on this Dora report. Um, here's what I found really interesting though. Everyone's using it.
No one trusts it Well, who's like percent or Don't trust it. The others are somewhere mixed up in the, in, in that spectrum. So, but, but what does that say?
What does that say? I use it, but I don't trust it. Mm-hmm.
It says the same thing I feel about a junior developer. I have 'em, but I don't Trust it, that our metric is okay. Right.
But that being said, I mean this, there's some real statistical rigor here. I mean, I, I, I understand being skeptical. In fact, I encourage being SSP skeptical, but at the same time, this is not just a Google marketing exercise, right?
As Alan said, this has some serious minds behind it. Uh, they have attempted to be true to that founding, uh, status. And also, you know, they, they show their work in many ways in the report.
Um, you know, it's not like they're just making stuff up here. Uh, I, and, and, and also, you know, to be honest, I think maybe, well, I'll speak for myself. I found the results pretty credible in terms of the level of skepticism, the level of use that the, the things they're using them for.
I mean, the funniest one is that the majority, uh, you know, one of the top uses is for calendar management. Yeah. Um, thank God, you know, I found it really incredible, um, you know, report.
And it jives pretty much as well with what we've seen at futurum with the futurum, you know, intelligence platform and the, you know, what we hear from our, our, uh, analysts here. So I wouldn't be, I, I mean, you gotta be skeptical about things, but I'm not too skeptical of it. I feel like it's a credible report.
I, I agree with you. I think it's very credible. And to Alan's point, it is the only metric standard when it comes to DevOps.
There's no even close second that is cited. I'm not saying that there shouldn't be, we're just, it hasn't come along, which says that what door has been doing has been helpful and valuable and giving people a benchmark to, to, to move against or to, to shoot for. And I think, I think, Stephen, to your point, the credibility around the research will help that continue, especially in the age of AI and looking at these stats around AI and what's really happening and what people are actually doing.
So I think it's gonna, it's got a long, I think it's got a long life. I Think the criticism of Dora has been that people over hype or analyze what it means, because you could do well on all the Dora metrics, but it doesn't necessarily mean you're shipping more software faster. It just means that you have the opportunity to do that.
Well, I, I agree. I mean, I could, I have my own criticisms of the door metrics. One of them is the, the biggest one or one of the big ones is are you getting more code into production faster?
Well, if it's sucky code, who cares? If it's great code invaluable to the business? Yeah.
You really care. So just being faster isn't, isn't that important based on what you're doing. But I think that was, I Mean, I can criticize it too.
So That was in the report this year though, that though we are pushing code out faster, is it safer or is it more stable? Mm-hmm. It's actually, we're pushing code out more, code out faster, but with more instabilities.
Mm-hmm. Which is the right way to look at it, right? Yeah.
But you know what I remember being, it was at a DevOps Enterprise summit in London, so it's probably around 20 16, 20 17, I sat down with John Willis and Damon Edwards, right? Who cam cams, right? Mm-hmm.
Another fundamental piece of the DevOps lingo cams. And, and Damon made the, the remark that, you know, two, it used to be two outta three camp bed, right? Like the song goes, you can't have bead stability, security, you can only have two of the three or whatever it was.
But he said, with DevOps, you can have all three. That was the promise of DevOps. We could go faster with higher quality and more security.
But this, the results we're seeing in the, in this DORA report say, not so fast, buckham, you know, we, we, you can go faster. Is it more better quality? And I don't know, is it more stable?
Probably not. And as long as that is the current state of it, I got a problem. Mm-hmm.
Yeah. It only gets better when I start to use some other form of AI to validate the code created by the ai because the humans can't understand the code generated by the ai. 'cause it's too verbose, and it's kind of complicated and it's hard to navigate.
And frankly, humans don't wanna sit there and just read code all day. So we gotta find a different way to check that code before it goes into production. I think there's another way to look at this too, is not just to your point about it, looking at a multiple dimensions.
It isn't that we just want more secure code and better quality code created by AI is it has to, it has to scale with the volume of code that we're creating, right? Because if we're creating, let's say in, in two years or three years, we're, we're creating 10 x code, but at the same stability, uh, uh, failure rate, um, you know, quality issues, well, then we're gonna need all those junior developers go out and help us fix all those problems, right? And then we're, then we're not in a good place.
If it steadily improves, which is the way it's gonna happen, it's not gonna happen. If all of a sudden one model will emerge to rule them all. 'cause it, it does everything perfectly.
It's gonna be an incremental improvement in that, but it's gotta be, it's gotta be improving along with, uh, our use and the amount of code that we're generating. Otherwise, we're just creating a mountain of technical debt to solve with who? More humans.
Well, You know what, Mitch, I, I, just, before getting on the gang this morning, I did an interview with, uh, Alan Snyder, who's the CEO over at, uh, now secure. Brian Reed Stewart, right? Mm-hmm.
Our old friend John Brody's there now, by the way. Okay. Oh, John Brody.
That's going back away. Yes. He Said, Alan, I, the first time I met you, I remember we were in the hall of black hat and you had some briefs.
Remember our briefs, our security brief, Mitch? I Do. Yes.
Um, So we had the chalk. But anyway, brought up something. If you're gonna have AI generate your code, and then you're gonna have AI test your code, and then you're gonna have AI move it along to deployment, automated agentic, all of that good stuff, where is the human in the loop?
And that, I didn't see that in the Dora report. Where is the human in the loop? Whether maybe it's not that junior developer, the computer science kid who can't get a job right now, but there has to be, or maybe there doesn't have to be a human in the loop.
Well, somebody has to take responsibility for the quality and the code. And, uh, you know, you're not gonna fire the AI I agent because, well, it's just a machine. Well, you can, but you gotta replace it with somebody else.
But ultimately, some human is the one who's gonna be called to account when the software goes wrong. So that's where that, What happens. Let's play that out.
What happens to the, when the human says, well, boss, it's that g*****n ai, the AI screwed it up. Let's get rid of the AI and put people back in. You can't say the dog ate my homework every day either, though.
So, you know, ultimately if the software, You say, the dog ate my homework, I shot him, what do he get? Or you get say, well, you're not that great at managing this AI thing. Let's get somebody that's better at AI than you human.
Maybe that's, that's the other thing that'll happen, right? Uhhuh? I think that is the Less dog shooting.
Please. No, nobody, I would never shoot a dog. I'd love my dog.
Yeah. Next thing you know, you'll be the head of home Homeland security. So I don't know.
I'm not gonna take that. Alan, don't take the bait. Don't take the bait.
Don't take down boy down boy. I want all the generals assembled in Quantico proto. No.
Um, let, but, but seriously, back to the humans in the loop. Guys, before we go off here, are we, do we agree that there always has to be a human in the loop? Or are we coming to a place where maybe there won't be a human in the loop?
Or what does that mean? I think, you know, there will be a human in the loop, but how many humans need to be in that loop is seems to be the, the debate of the moment. And it could be very few.
Well, It depends on which loop you're talking about. I mean, the whole point of DevOps, I think, is to take some humans out of this, some loops. Mm-hmm.
I think there may be an analog to factory automation and robotics. Right? You still have engineering in involved in creating and designing those processes.
Now, aided with a ai, maybe that increasingly can be done by ai, but you also have people come into the shop to do maintenance. You have people come in to say, you know, that robot's stuck in a loop and loop and smacked a person, right? Like it's not supposed to.
You, you have people that come in to address issues that come up with it. So maybe the autonomy isn't completely autonomous, right? It's automation just with some degree of autonomy.
But there's also human in the loop after the fact. Who knows? Yeah.
Could be. Hey, we gotta take a break. I'm just looking at the clock here.
We got, we got sucked into this one. We gotta come back. And good news, we're not gonna talk about ai.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Welcome back to Textron Gang. So we are, uh, uh, last week actually hosted our security field day event here on Textron TV with Tech Field Day. And I wanted to bring some of the takeaways from that event.
Uh, not so much the presentations and the companies, but the, the concepts from that event to this audience. Now actually, there's an important, um, aspect here that I wanna point out as well, is that, uh, today, when this episode airs is actually the first episode of the Security Boulevard podcast, which is going to feature, uh, Tom Hollingsworth, who runs the Security Field Day event. Um, somebody named Mitch Ashley, who, I'm not sure who that guy is, we'll see who that is, as well as, um, this Shimel guy and, uh, Fernando Montenegro, who is a good friend of ours from Futurum as well.
Essentially, we're gonna be talking security topics, uh, on the, you know, the weekly Security Boulevard podcast. Many of the things that came from Security Field Day were discussed, or at least, um, uh, mooted during the first episode of that, uh, podcast, Mitch. And, um, I wanna hit on a couple of things, uh, message basically from Tom about Security Field Day.
So what were the big takeaways? Number one, that, uh, traditional security is really changing. Uh, the idea that you can secure the perimeter is, is pretty much gone, uh, at this point.
Uh, now we're looking at making more, um, security closer to the edges of the network, closer to the applications, closer to the end users, which leads us to the importance of identity management. Um, one of the companies that came, uh, was a first time presenter, which is a one password, which, uh, you know, I, I'm not, uh, in their pocket or something, but I've been a customer for over a decade. I love the product and I love what they're doing to try to make it much more easy to manage things like pass keys and passwords and, and keep all of that secure as well as shareable.
And then the third thing that Tom pointed out is that the tax just keep getting more and more sophisticated. We actually touched on this as well on the Tech Field Day podcast, uh, which is coming out today as well, where we talked about the fact that, um, you know, ransomware gangs are now come, have now become basically illegal ransomware companies, and they have as a service providers that provide various, uh, elements to them. There's a DNS registration, there's a, a short link, uh, and so on.
Infoblox talked a lot about that, where essentially we, we are, are fighting sort of a black economy of, um, bad actors. And, and, and in many cases, those, uh, bad actors are incredibly well funded and well organized. So I, I'll throw it to you, Mitch, since you were on that first episode of Security Boulevard Podcast.
Uh, what were your takeaways from Security Field Day and that podcast recording? Well, I, it was, it was a great discussion. I hope folks will check it out.
com and of course, all the podcast channels over the, uh, OTT channels, et cetera that we have on texturing. You know, I think it was a good help healthy debate about really looking at the state of security of where we are today, right? We talked about, on one hand the ransomware issues and new techniques and, uh, that, that are being, that are used to, to forward that mission of the bad guys.
On the other hand, you know, I think there's a question to say, where's the innovation in the security industry with ai? You know, fight a fight. Fire with fire.
Let, let's fight AI with ai. Now, I'm pretty sure Alan said we're not gonna talk about ai. So, um, well, Alan, who, let's, let's look at it this way though.
So the bad guys are definitely using that technology. We're not talking about, and they're launching attacks at machine speed, right? And that's faster than any security person can keep up with.
And so now I've got more attacks than ever. I've got more code than ever. The attack surface is broader than ever.
It doesn't seem feasible to continue to manage security the way we have historically. Well, unless we're gonna start using more of that capability that we're not talking about. Yeah.
And that's, I think what Tom was trying to say, that, that it's not just about securing the edge anymore. You really have to secure everything and, um, and make sure that you have good identity management. And, and, and you know, that, that sounds truthy to me.
Alan, You know what? Security has been a Cold War game for as long as I've been in it, except there's no mad, there's no mutually assured destruction. 'cause we can't destruct, you know, we can't just kill those guys.
Um, but it, it, it's always been that the bad guys are, are, are no dummies. You know, they're black hats and they, they, they do their thing and we need to be on top of our game to, to play up with them. And so as you know, we go from, from missiles to ICBMs to sub launch, to, you know, star Wars kind of lasers and, and all of these things.
It's an arms race. It's an arms race. And, you know, in, in the real world arms race, eventually we, we, we outspent the Soviet Union and they couldn't keep up.
Right? And well, there were other reasons, but you know, it, but it nearly broke us. It nearly bankrupted us as well.
Don't forget. Right? And security's the same kind of game here.
And the, and the stakes are high. The stakes are really, really high financially, strategically, e everything else. So, um, but you know, having been intimately involved in the security world for 25 years now, AI is just the Johnny come lately to, to this battlefield.
Mm-hmm. But it's the same. It's the same.
The lines have been drawn for some time, right? And, and it's the same, it's the same combatants, Right? I think the, the pressure is on the incumbent providers of the security platforms and tools to add those AI capabilities that we need.
And if they can't, then they're likely to be replaced by any one of these, you know, I don't know, 50 startups that I seem to run into every day with AI security tools. But, um, I think most customers out there would prefer not to have to rip and replace everything. They'd rather see what they have, get augmented.
But, um, it's not clear to me how quickly the incumbents are moving. I think there, there's thinks Also think that was one of the things that surprised me. Uh, you know, Infoblox, uh, you know, I watched their presentation and this is a company that's been around forever.
Mm-hmm. And yet their messaging was very new. Their people were very new and, and the product focus was, was very new.
I was surprised to see some of these, uh, you know, old school companies. You know, you've got HPE you know, companies like that. And, and, and yet they're, uh, they're actually, you know, jumping ahead.
And, and that's, that's great. I love that because we need to, to, to, to use Alan's Cold War analogy, like I said here, as was pointed out as well, the, um, the black hat actors, this is not, you know, some script kitty. This is, this is a real, well-funded, well-organized organization that you're fighting against.
It's not, um, you know, it's not yesterday's black hats, you know, with the hoodie and the, and, and the monitor and all that kind of stuff. And, and I think that that has really changed the game. And so, you know, I think that the security industry is really stepping up in response to that.
Well, that's a big thing of it too, that, um, that we're in, we're in transformation about how we think about security, right? The AI is part of it, but it's also more fundamental things you think about that the impositions that we've put on end users has been better algorithms for your password, right? You know, you need special characters, has to be this long or whatever.
We've constantly played with that as, as a entry level standard. Now we've updated that to say it's two factor multifactor, it's passkey, it's something else. And I think we're starting to enter an era of, I know you don't like it, but there are a minimum set of things that you've gotta do, and maybe that will continue to increase.
And not to put the onus on the end user, but putting the onus on the end user for someone who's not a security person doesn't mean you're gonna get good security. And so you, you're gonna have to up the level of that entry point. The edge is the end user, right?
So I, I would say this though, this isn't a case of control versus chaos, right? It's not a bipolar, uh, battlefront. Today's friend is next hours enemy, right?
It's shifting. And, and to, to, when we talk about the black hats and we there, we still do have to worry about the kid in the hoodie, by the way, because they're still doing bad stupid things. That's True.
In the uk for example, they found that, uh, this ransomware attack literally was a kid in a hoodie. You know, I don't know if he was, He's in the, but He was literally a kid. But, you know, but you have, we geopolitically we exist in a multipolar world these days, right?
It's no longer the, the US versus the USSR. And we're all on that side of the divide. You, you have different spheres of influence in different players, whether it's Iran or North Korea or China or, or the us.
We're far from angels here, right? And even within the US there's different factions. So when we talk about, you know, the quote unquote black hats, they range from hacktivists religious extremists to puron, capitalist, financial, you know, people looking to make big money to anarchists too.
I mean, there's to Nation states trying to raise, you know, legit funding. Yeah. If you're gonna go good, all get smart on us there with the control versus chaos from the Six five why's gonna drop the cone of silence so we could have a discussion about it.
I don't have my shoe on here to dial up Max, but yeah, I mean, I might have scrolled right on that. Well, fortunately We're gonna have to drop the cone of silence on this episode in a minute. Mike, I think you had one more thing you wanted To jump in.
I understand. I would just point out one thing. It's like, look, if we're counting on end users to do the right thing so we can have, we're security, it's never gonna happen.
We're in deep trouble. I agree. Yeah.
That's why I think that we need more tools. Uh, you know, back to one password, you know, I'm a big fan of their tool because it's easy, as easy as it gets, which is unfortunately maybe not easy enough yet. But hopefully we'll see more, you know, better integrated security tools, uh, that can help end users do a little bit better of a job.
And to that point, they've had the best browser plugin, I think, which is what attracted me to using it and recommending it to people. Yep. Well, absolutely.
I'll just point out before we go, one more thing is that we're gonna be posting these, uh, recordings of these sessions to the tech field at YouTube channel. They'll also be accessible through Techstrong tv, including the over the top Techron app, which is maybe where you're watching this episode. So keep an eye out and you can learn more about what these particular companies are doing.
Excellent guys, Steven, you're right. We're way over time. Good discussion.
Good discussion today, gentlemen. Thank you. I hope you've enjoyed it.
As Steven mentioned, you could check a lot of this stuff out on the, on the YouTube channels, both Tech Field Day and Techstrong tv, on the Techstrong TV website, the Techstrong TV app. And, uh, we'll be back tomorrow with more. But until then, on behalf of Mitch, Steven, and Mike and myself, hey, the Yankees are playing baseball.
Uh, the Red Sox also, by the way, this is gonna be a challenging week for the three of us, I think. Yeah. Yeah.
This true. All righty. Even those, even those pesky Cleveland guardians are in there.
Yeah, Right. Absolutely. Well, Steven's a Red Sox fan.
He doesn't care about the in Indians. No, I, I, I, anybody who beats the Yankees is good By me, not the Indians. The guardians.
The Guardians. Um, all right. Hey, we're outta here.
Have a great day, everyone.