Can AI Code Securely? The Future of Cybersecurity & Development | TSG Ep. 953
Alan Shimel, Mike Vizard, Mitch Ashley, and Jack Poller explore the future of cybersecurity and AI in software development, tackling the urgent need for stronger leadership, government action, and public-private partnerships to protect critical infrastructure.
The discussion dives into the vulnerabilities of AI-generated code vs. human-written code, emphasizing the importance of secure coding practices and built-in safeguards during code generation. The gang also examines how AI’s growing role in development is reshaping workflows, risk management, and the overall software supply chain.
Transcript
Hey everyone. Did Trump kill the Cease A Star? You're watching Textron Gang.
Hi everyone. Happy Monday, man. It's Monday.
That wet weekend went like that. Me, I was in Pittsburgh. I had a chance to see my Steelers, play the Packers and do some kinda north northeast thing.
See leaves changing color. We don't get that in Florida very much, but, uh, weekend's over. We're back here at work and we're all, I think, a little bit less safe.
We're gonna talk about that. We're gonna talk about some other good things here. But let me introduce you to our Monday panel of Experts to talk about it with.
We've got, uh, my friend Jack Poller. Morning, Mitch Ashley and Mike Fazar. Gentleman.
Gentlemen, welcome to Monday's Textron Gang. So, Mike, I, I, I'm glad we've got this topic on here 'cause it's been percolating with me now for months and, uh, you know, in spite of a lot of lip service about how important cybersecurity is going to be and how active they're going to be. The fact of the matter is what she called Ice Barbie, or whatever her nickname is.
Christy. No. Call her what you want.
Puppy Killer. She has gutted, gutted our Federal cybersecurity program. They have gotten rid of good people.
They have cut the budgets, they have introduced uncertainty into and doubt into the commitment of this country to, to take cybersecurity seriously. And we're all worse off for it. It's a ticking time bomb.
We're gonna pay the price. Jack, jump in here for a minute, because on the other side of the house, the Trump administration responding to some letters that the Democrats sent about the very thing that Alan just outlined are saying there's nothing to see here. They are gonna come up with a better CBE program that may or may not include Minor.
That's right. After they come up with the new Obamacare. Yes.
I'm just checking. I'm just checking. And they, they, they ditched the CIS people because they're gonna work with the states more closely and directly, and there's just too many people in the way.
And they're saying everything is just fine and dandy. What's Your take? Hold on, Jack.
And what's gonna happen if Jen Easterly runs a, a TV commercial that says Ronald Reagan says, cybersecurity's important. Are we going to then cut off all funding for cybersecurity? You can't believe this administration changes every time the wind blows.
Or, or someone sitting at 1600 Pennsylvania Avenue Demolishes another piece of the White House. All right. All right.
Hold on. I believe your son. Go Ahead, Jack.
Uh, you know, with, with, with, uh, uh, such an incendiary setup like that, I think this is the government we're talking about, there is absolutely nothing that can be done in the government that isn't affected by politics. And it is a shame that politics affects the safety of the country, but it does, and it does all the time, not only in the cybersecurity realm, um, there. So a lot of what's happening is clearly political.
A lot of it isn't. I think ceases mission is both not extremely well-defined and is changing and maybe needs to change a little bit. And the real question for me is, is CS a a agency responsible for protecting the government cybersecurity, or is it for protecting the nation's cybersecurity?
And it depends on your perspective of that mission, what you do, and how you fund it, and how You I I don't think it was ever set up to just protect the government cybersecurity, but I will put forth the proposition that the government cybersecurity is the nation's cybersecurity and the nation cybersecurity is the government cybersecurity, human rights are women's rights. Right? They don't, they don't, they don't.
There's no one in the, there's no line there, Jack. There's no line. I I I'm trying to make the distinction, I guess, between what private companies are responsible for in protecting their own environments, versus is the government somewhat responsible for protecting private industries cybersecurity?
And I think there is, uh, there is, I I think that screams, hello, 1995, right? Because here's the deal. In today's world, the government can't do it alone.
Private industry cannot do it alone. We need a partnership, a public private partnership of cybersecurity priorities, best practices, and working together to bring down some sort of umbrella, some sort of protection for our critical infrastructure. And that was always the mission of, of cisa.
You know what, we had Chris Krebs, Mitch, Mike, you know this, we had Chris Krebs speak at one of our RSA events that we did over probably three, four years ago. Now, Chris was a, a really good man appointed by Trump in the first administration, by the way. Right?
Because there was a clear mission for csa. Jack, what you are saying about what c a's mission, the mission at CSA was very clear under Trump won until, until Chris Krebs said that there was no hokey, hokey stuff with the election. Then they fired him.
Now they're prosecuting him. You know, Alan, I think what what this is a symptom of is the, uh, the Silicon Valley, uh, go in and break s**t and then figure out what you're gonna do. So by going in and, and, you know, knocking everything, everything over, getting ready people, et cetera, but kinda leaving the disaster in place and people trying to figure out, well, what are we doing now that we cut, cut.
But wasn't there a disaster before they went in and made a disaster? No. No.
I think, but that's the point is, you know, you can, you can, you can rec bring down the East Wing and say, now let's figure out what we ought to have for a ballroom. Or you can put a land together and, and say, this is what we want. That, that's the issue is there is no plan.
Let's, let's, so let me finish. Go ahead. I'm sorry.
Well, usually what you do is you say, you know what, we need a, we need a great leader. We need a Jack Poller to go in there and take the reins and figure out what we, Jack, I'm volunteering you. And, and Jack goes in and says, yeah, here's what we're gonna do, and we'll cut here and we'll add here.
And I need this budget from Congress as opposed to, you know, it's just a s show, you know, that's left. And you walk in, okay, now what do we do? What do we, what do we have?
What do we do? And what Was, it's worse than a nest show. Let's with, and Jack, I agree with you.
It's all politics, right? So you got rid of Chris Krebs, who was a very competent leader, well respected in the cyber industry, and really was making a lot of progress in that public private partnership. Chris left, we were blessed to have this woman, Jen Easterly in there.
Smart, understood. The mission was making things happen. They fired her too.
Then they've taken, and look, Jack, you live in DC area? I don't, but from what I understand, they've taken a lot of the, they, they ransacked the budget to CSA and took a lot of the people and put them on the front lines of immigration, because our and cybersecurity people make great ice officers. I don't, I don't know what the, the logic there is, but, you know, the Department of Homeland Security has become the ICE department.
Mm-hmm. And, and cybersecurity in spite of, you know, their lips moving and maybe some late night tweets when someone gets something a, a feather or something, um, they, they're not serious about cybersecurity. You know what I mean?
Cybersecurity is full of those DIA people. You got women and, and brown and black people in there. That's not the team Pete wants.
Mm-hmm. Jack, is there some way to maybe take a giant step back from this and have the private sector addressed, uh, security concerns in some sort of coalition or consortium or something that takes the politics out of this effort? Well, I think we do that every day with our own organizations, right?
And, you know, we have a very large cyber security industry with 4,500 vendors selling products to solve all the problems of both the government and the private sector. Right? And I think that the government isn't the only solution.
And a lot of times, a lot of people think that government should be the solution of a last resort rather than the solution of first resort. Right? So again, that's 1995 calling.
You can call it what you want. It's a Cybersecurity mission today. And protecting our critical infrastructure is absolutely a national priority.
And telling me you have a market of 4,500 vendors for profit who are taking the place of a, of a policy setting, public private partnership to protect the critical infrastructure. It's not the same. You need.
There are certain, you know what, we went to the moon 'cause it was hard, not because it was easy. We chose to go to the moon. 'cause there are certain things that you need the government to do.
Even Elon Musk realizes he can't go to Mars by himself. It has to be done through the government and maybe multiple governments. That's how big our cybersecurity mission is today.
Today we need the government as part of, I'm not saying the government necessarily needs to lead it Or Dictate It. And that, that, Steve, that's, that's where I was getting at. I'm trying to say that a partnership, it is definitely a partnership.
And it is, it is, it is misleading to say. I, I believe it's misleading to say that if CISA doesn't have its act together today, the world is going to end tomorrow. It is, No, not the world.
I'm, I'm, I'm, I'm, I'm just a little, I I think it's, it is, it is a serious situation. It is not hair on fire. The world is coming to an end situation.
And I think that it's something that can get resolved at the speed. Jack, have you had a glass of water today? Did you take any water from your faucet today?
Do you know if it's safe? Yes. And yes.
And the, But how do you know? Because it's, 'cause you haven guide yet, I mean, honestly, you know, that's like saying, look, until I see that mushroom cloud, I'm not quite sure if that missile has a nuclear bomb on it. Well, I'll, I'll give I'll give you the counter argument, Alan, which is, I flew, I was at, uh, cloud Field Day last week in Silicon Valley and flew outta San Francisco airport and sitting in the United Club next to me is a man working on his laptop.
He gets up to go to the bathroom and spends five, 10 minutes away from his laptop to cell phones, his wallet, the laptop is open, logged into clearly very sensitive information, of which I have a picture with a post-it note with this username and password on it. We are worried about very complex things. And at the same time, the very most absolutely most basic cybersecurity stuff in the world, we still don't deal with.
Right? And is it the government Responsibility? And so that's responsibility in not to have csa No, no, no, no, no, no, no.
But I'm saying that you can't, the government can't protect us from ourselves. That I don't want the government to protect us. I want a valid government partnership with private entities to, to enforce.
'cause sometimes you need government for enforcement at first to define and then to enforce certain things. No, we may not be able to stop that guy from going to the loo and leaving his, his computer open. I, I get it.
That's not CEC's fault. But Jack, there's a bigger mission here. There's a bigger mission here, right?
I i we live in, we don't, we live in a dangerous world. The fact that you just came on here and admitted you took pictures of his thing. We may have to cut that out.
I don't want see you get in any trouble, but wasn't password, Nuclear code. But as long As you don't, as long as you don't do anything with it, you're okay. Right?
But you know what, there are nation states at play here. I mean, I, I don't disagree with you in the league. We need, we need a little more muscle than that.
So Here's what I would propose though. So why can't now not relying on the vendors in the security space who have a profit margin or issue. But in my mind, there's six companies in E who lean each of the vertical industries out there, whether it's finance, retail, or manufacturing or whatever it is.
And can't they come together in some sort of mutual defense effort to fill some of the gaps here that the government is gonna clearly not fill Again, hello to 1995 to you too, boomer. Okay. Yeah.
We had something like that. It was called PCI, right? We had the payment card industry and what a great thing that was.
Right? We stopped. We stopped you.
You're missing the point. This isn't, first of all, yes, we need industry trade associations working in partnership with the government. You are mi look, this is a mission critical action here.
I'm not talking about stealing credit cards. Let, let me, let me support what you're saying in a different way, Alan, is, we, we can talk about cybersecurity, then we can talk about cybersecurity. That also includes nation state threats.
That's the difference here. No, no business entity is prepared to take on nation state. And it isn't just about stealing data or, you know, a financial motive.
It can be for disruption of society, disruption of our financial banking systems, whatever might be, you know, the power grid, all of that kind of thing. So, so by default you have to have some government and strategical level action, you know, people involved to, to do that. Now, whether you get into the detailed and we can run CVEs ourselves, or we need the government to do that, that, that's probably not as critical.
I think it's more of how do we protect ourselves from not just the bad guys, but the bad states. That, and that's it. And look, it gets worse.
Wait, there's more. It gets worse. The fact of the matter is, we already have a ticking time bomb in our infrastructure because for the last, going on a year, ho uh, uh, ice Barbie has, has ignored cybersecurity.
And we now already know that China sponsored nation state sponsored groups have infiltrated and have been inside some of our critical infrastructure. Just because it hasn't brought the lights down at your house, Jack or the water still good, evidently by you, doesn't mean that they don't have the ability to do that at any time they want. Right now, they're already inside because we've let the guard down because we've dropped the defenses, right?
We, I'm, and let me back up. I'm not saying we were perfect before this administration. I'm not saying CSA was perfect.
I'm not saying that CSA didn't have a big budget, and maybe you could cut the budget a little bit and make 'em a little more lean, a little more efficient. There's a difference between that and gutting it and making it part of the immigration, uh, deportation issue. We, we are in a cyber crisis in terms of our critical infrastructures profile to nation state actors.
And they're not messing around these nation states. They're playing for keeps. We can't afford the clown show that we have.
Now. I've just pointed out that the water in my house is good because, you know, a company called Poland Spring says, so I'm just pointing that, Well, you're importing your water, but seriously, the good there. So this, this is no longer, my God.
They, they might have my credit card or geez, they got my health record. I know what Michael Jackson had at the hospital. This isn't that kind of stuff anymore.
This is, this is, you know, for all intents and purposes, we've been in a cold war with China for probably 10 to 12 years. This competition is for who's gonna lead the world the rest of this century. And they, and the Chinese play on every battlefield they can, including cybersecurity, and they're damn good at it.
And if we don't get our act together, we're not winning that war. All the AI and, and, and, and quantum be damned, we're not winning that war. That's all I got to say.
Let's take a break here on Textron Gang. Let's talk about something a little less controversial. Uh, an outer space hack.
There you go. You are watching text George Gang. You've Earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions. Your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back and continuing our little chat about cybersecurity, but sometimes maybe we're our own worst enemies is we have a report, we're a bunch of academic institutions determine that. Well, much of the data traveling across our satellites is unencrypted and can be easily seen by anybody using basically, I don't know, maybe a hundred bucks worth of gear. Jack, you wrote an article about this, did a surprise you and B, how the heck did we get to this stadium affairs?
Yes, it did surprise me in a lot of ways. So let's first talk about, um, sort of the setup, which is the gun couple of academic researchers got together and they pulled about $600 worth of equipment that you can get to do software defined radio. So basically can listen to any radio waves they want.
They stuck a satellite dish out there. And their biggest challenge in intercepting the satellite data was simply getting the dish pointed at the right satellites. Once they figured out how to do that, they were able to get all the data that they ever want it.
And it turns out, when you transmit data over satellites, it's unencrypted. And we all look at that and we say, why the hell would it be unencrypted? And that's because satellites have limited bandwidth, limited processing power, and it costs time and money to do that.
And it's very expensive. So most organizations aren't willing to pay to encrypt their data over the satellites. So what data is going over those satellites?
Well, turns out T-Mobile was sending SMS text messages in clear text across the satellites. So anything you sent was easily interrupt, intercepted, uh, some of the airlines, uh, in flight wifi systems go south through the satellite. That's not only unencrypted but worse.
The airlines were leaking their private keys. They were sending the private key in a public private key pair. Why it was sent over the wire.
I have no idea or sent over the air, but it was sent unencrypted. So they were able to intercept and get to decrypt a private keys. And there's a lot of data like this.
So that's really pretty scary. And I think the biggest part of it is when we use the internet where these types of services, we don't know how that data is getting routed. And we think we have an encrypted can end-to-end encryption connection, but somewhere along the way it may not be encrypted.
And so that's the real sort of big concern is you have no idea that what you think is a secure channel in the middle somewhere is insecure. Yeah. Jack, I feel like we're back in the tone that days.
As you can see, you know, my past, we have clear going over the wire. It, it's like, oh, but didn't we decide to fix those kinds of things? Uh, maybe it's, is it securing the satellite, the encryption there?
Or just say, look, everything you send should be encrypted end to end. 'cause that way whatever it does with it is fine. It's not encrypted.
You've encrypted it before. Got, I think, I think it's both right, is that everybody has a responsibility to encrypt the data as often and as, as you know, and through all communication channels. So a organization that is going to use the satellite link maybe should encrypt the data before they get it to the satellite link.
Hmm. So that the satellite link is just transmitting, you know, a cipher text rather than clear text. You like ethernet.
True. You know, it's just like ethernet. It's not secure, just like ethernet either.
Right? It's not secure either. So I mean, Alan, what's your thoughts?
Look, this is small potatoes compared to what's going on in Portland. Jack, you made my point from the last session for me right here. This is when you need a government to step in and say, satellite transmissions of critical stuff or of of sensitive data needs to be encrypted.
You need enforcement. You can't rely on the goodwill of for profit companies who are gonna make a decision that it's too expensive to do that. And Bill does not tell their customers about it.
So Alan, is the government gonna pay for the encryption and the extra bandwidth required? No. Maybe, no.
Maybe you'll, if your, so here's the deal. Is your information important enough for you to remain confidential? That you are willing to pay a little bit more, to have a little bit more CPU on the satellite so that it stays encrypted?
Or you are you willing to say the heck with it? I don't care. But if you don't have, this is why you need a government, you know, this goes back to like, look, SAU, Locke, Montague, these people, right?
Why do we have a government, it's a social contract. There are things that a government has to do because we can't do them individually. Or even if you believe a corporation is a person That even a corporation can't do, you need regulation.
You need, you can't expect that the corporation is out for your individual wellbeing when the corporation's sole function is profit. Right? This is this, this, this basic, basic political theory.
You need an entity that enforces these kinds of things. Or at the very least in enforces a full disclosure so that, you know, going into it what you got, right? That guy who went to the bathroom, Jack and you took pictures of his laptop.
We'll, say it again. Jack took pictures of his laptop. That guy, he needs to know that he, he has sensitive data and he did that.
And if he then chose, chooses to still do that, you know, so be it. But at least he, he, he had the ability, the option to know that that's gonna happen. We need, this is why you need this stuff.
Wait, the United Lounge is a, is a secure environment, I mean, correct. Yeah. Well, he probably thought he was in the cone of silence and he was talking, was he talking on a shoe jack or Anything?
Well, I, I'll tell you, not him, but I'll tell you over the years, I could make millions of dollars ha from people who have used their, read their credit card numbers out changing flights or buying something. Yeah, absolutely. On a speakerphone in the United Club lounges, right?
Absolutely. So the United Club Lounge is a cesspool, a cesspool of poor security. You Always did very slow Five sticks.
Serious question project. So this is an academic research project, but a lot of folks in cybersecurity will say, you know, if you can imagine it, somebody's already tried it. So do you think nation states out there have already been using this technique and have been hoping?
Of Course they have. Look, look, these guys went out and bought essentially a dish tv, you know, one of the, the the dish TV satellite dishes that you have, and they repurposed that, right? That's, that's a little tiny thing like this.
I mean, look at, look at the, there's outside. How do you think the Israelis decide where someone is meeting in, in a building and they just happened to bomb that corner office where they are? Mm-hmm.
We've been doing this for years and years and years. There's uh, I think it's, uh, in Silicon Valley, right next to Mo Bayfield, there's like 20 satellite dishes and they're doing that. Yeah, absolutely.
I Some frigging riggly. I mean, anything you say on a cell phone, I think it can be easily intercepted. So I should go get some homing pigeons to send sensitive.
No, I mean, the, so the government, like, I'm sure Captain Pete, right? Well over cocktails has a satellite phone that is fully encrypted, right? Because I, I'm, I'm hoping they haven't cut that out yet in the, in the, in the march towards sending brown people out of the country, right?
Is that we haven't given up our encrypted satellite system that the military uses. I'm, I'm assuming, right? So, so let me, let me bring it back to a little bit more of a, a technology discussion.
It's something that you brought up about listening to cell phones. And we were, I was having this discussion with another group of people yesterday. Uh, we were on a group chat on Zoom, right?
And we were talking about, well, we said that on Zoom, everybody can hear. And they're like, well, it's not being recorded. Well, at the end of your zoom call, zoom pops a little window up and says, would you like a AI summary of the conversation?
Well, no. That's only if you had an AI agent running, you could make sure you shut your AI agencies off. Well, Well, now, now here's the question though.
Do you know for sure that the AI agent is not always running and you only get the summary after the fact or not? So I'm, I'm pretty sure. So Jack, I spent half my life on Zoom, unfortunately.
I'm pretty sure that Zoom pops a, a thing if any of the people in your conversation have their, uh, AI agent running. I believe so. I don't, I wouldn't swear on it.
But I think Now, now, now I'm gonna take this to the next step. Whose responsibility is that to ensure it? Is that the CISA and the government's responsibility?
Or is that you between you and Z? No, No, it's never the government's responsibility to ensure that it's the government's responsibility to break down the, the law, the best practice the regulation. It's up to you to, to abide by the regulation.
But, you know, it's Like two party consent or one party Or whatever. Well, they used to have that. But you know, I, I found this out in my, so I'm the president of the HOA where I live.
God help me. It used to be that if any of the, uh, residents were attending the HOA meeting and they were gonna record it, they had to make an announcement that they were recording the, the meeting. Now, they do not have to, at least in the state of Florida where freedom starts with a small f um, they, they could just record you without your, uh, without your consent or even, uh, notice.
Um, so I've started recording all the meetings and told people they could shut down their phones and I'll just make the recording available anyway, right. Which, which kind of takes the balloon, the air outta the balloon. But you know, there, there is no longer that consent, Mitch, you're talking about.
Now Zoom, to be fair to Zoom, if you remember, they, you know, during COVID and stuff, zoom used to send it out unencrypted. Yes, they did. And, and, and I don't, and I wanna be clear, I'm not taking pot shots at Zoom, and I apologize to Zoom for that.
It was much more just raising the case of there's a possibility to, for these things to happen that we don't think about, just like we don't think about your data being transmitted across the satellite unencrypted. I'll give you, I'll give you one. I found a, a thing yesterday, I was at a restaurant with Dan O'Brien.
I took a picture of our, of my dish, you know, food porn. I came home and Google said 10 people liked your picture. How the, how the Fri did Google make it public?
Well, they, they, they, they knew what restaurant I was at and they added it to the, the, the Google listing for that restaurant. Because evidently on my Google photos, I must have not clicked private or something. When I took that picture, I was very close to taking Google photos off my phone as a result.
That's wrong. But it it, it's a similar thing. You don't know once that date is out there, well, what, you know, who the hell used it and what's going on All when this episode is over and airs, I will get an invitation for a reservation from that restaurant that you went to, right?
Yeah. You can go look it up and it'll say, here, picture from Alan Shimmel, I'm gonna make sure this video's encrypted as I'm watching it. That's for sure.
It makes no difference if it's encrypted in transit. If Jack has his AI thing run it. Mm-hmm.
His AI assistant always Jacking his ai. Come on, Jack. So, um, well let, it's on a more serious note though.
Do people need to be more conscious of what they're sharing and when they're sharing? And is, is that too big a burden for people to figure out? So That, but to That point, to that point, Mike, is, you know, we talk about there's cameras everywhere.
Assume cameras, you know, there's cameras, same thing with audio, right there. We're never off mic. 'cause you know, who is listening in the background or somebody's recording a meeting that even though Zoom isn't recording it, they're recording it.
Right. You just don't know. So here's, and I'm not making fun of you, Mike, but that's a boomer question again, right?
Because people of our age, we, we, we had this concept, this notion of privacy, and it offends us to think that Google used my photo or that someone picked up my SMS by putting out a satellite dish. And, you know, may have said, saw me saying something I didn't want made public. But when you look at like our children or my young, I, I even see a difference.
My one son's 26, one's 24, they're like three school years apart. I see a difference in their notion of privacy. I I think, you know, what's the latest Gen Z is, is the, is before millennial.
Gen Z has no notion of privacy. They do assume everything is out there. So they don't care.
Well, I'd I'd also like to point out and to your statement about, you know, the government protecting us, that we now have another set of governments, particularly the British government that wants encryption back doors to be able to break encryption. They're Not the only One and they're not the only one, they're just the, the, the ready to the off the top of my tongue one. Right?
So there is, and this is why I'm, why I hesitate on the government doing all this because sometimes they get it wrong and breaking end-to-end encryption is definitely getting it wrong. Yeah. But you, you can correct that.
Right? And, and, and look, the US put a lot of pressure on Apple even going back to the nine 11 timeframe. Right.
To give them the keys to Apple encryption. Yes. Uh, For, for this very reason.
And so just to show you that I'm not just one of those flaming left wing bleeding hearts. I do believe that there, there are times of emergency where the government does need that. There, there might be cases of truly national emergency, but I would have some sort of, what was the court that you, Pfizer court?
The Pfizer. A court. Yep.
Yeah. I would have some sort of separate court system set up that you can't use that until you've had, you know, you made your your case for it and you could have an expediated expediated hearing. But, um, I, I do think sometimes Jackie, you do, I mean there might be national emergency issues where you do, So do I get up every morning and just kinda, you know, say hello to all the government officials that are listening in and, you know, just be friendly about it.
But I, but you all kidding aside, I think Gen Z, they assume that that's Yeah, they're fine with it. Alright, Well if it's not government officials, it's their friends, their enemies, you know, they just assume everything's out there. They're a founding fathers rolling in their graves as we see.
Yeah. I think they got a lot more to roll about these days. Mm-hmm.
All right, we'll take a break. Let's come back. What are we talking about next?
Coating slop. Oh boy. What, you know, what they say?
You roll with the pigs, you get 30. You're watching Textron Gang. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching it leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right folks, we're back. And yes, we're talking about AI code slop, and slop is being a word that's tossed around a lot lately, but it sounds like maybe we now have too much of a good thing. People have adopted these AI coding tools, but there shall we say uneven in the code quality that they generate.
And there's a report out from security that identifies 10 systematic behaviors in these coding tools and sometimes known as anti-patterns. And at the same time, ops, Sarah's got some capabilities that they've added to their DevOps platform that helps identify where this code slot is being generated and maybe wanna limit the usage of those tools because well costs money to use them somewhere, somewhere along the line. Mitch, I know you've been talking about responsibility and how much faith we have in AI tools and, and where are we on this journey for a while?
You, I think you have an article up on that, on the futurum sites, but mm-hmm. What's going on here? What's your assessment and do we need to kind of maybe take a step back and figure out what's going on here?
Well, you know, having lived through a couple generations of code generators and going back to even COBOL code generators, when I got outta school, one of the things I learned right away was what comes out of those suck. But they work looking at the code, the variable names, the structure is like, no one would program it like this. No one would code it like this.
Um, and I think that's what we're seeing here is how important is it for us to look at the quality of the code from a structure standpoint, non monolith architecture using good, good coding practices. We're assuming humans do that all too. Which not all humans do that either.
Then, then you talk about the realm of the, okay, what's efficient, what's secure, what's main, you know, what's easy to maintain. I, I think we will eventually get to a place where you don't look at the code, you don't really care what it generated. Um, you, you'll know if it's efficient, you'll know if it meets the need, but we're living in this world of you still need to look at it and I need, might need to maintain it.
Um, 'cause we don't trust, um, AI co generators or there to the place enough where everybody will kind of sign on to that. So telling, telling me, you know, reading this report that there's 10 sloppy practices, um, I could fill in the blank and say, yeah, there's this person that does eight of those two. Right?
It's, that's just the world of coding. And I think eventually we'll get past that. I think, I think this is a bit of a, a non-issue.
So, you know, I, Mike you mentioned ox. I I spoke to their CEO uh, last week. So they have this vibe sec thing they're doing, right, they call it.
Right? So, and it's specifically to help secure vibe coding. Um, I saw the Sera, I spoke to their agency and I got what they're doing.
But I also had a conversation last week with the CEO of check marks. My friend Sandeep Johari and their studies, their metrics are showing that AI generated code has two to four x the amount of vulnerabilities then human generated code on average, right? On average, two to four x the amount of generator, uh, vulnerabilities that human generated code.
And it, it's not just AI code AI assisted coding. Mm-hmm. Right?
'cause that's this new Gartner category now, right? They're having AI assisted security or AI assisted code security agents or whatever. But here's, here's where I think we're going, Mitch.
And, and you may or may not disagree. I think the question is what bar do we hold the AI to AI coding agents? Do we expect AI coding agents to deliver pristine code that is free of vulnerabilities far beyond what we get from humans?
'cause we know humans don't deliver perfect code either, right? And that might be a really, really high bar. Do we expect AI to deliver code on par with what a human does?
And look, we've lived with human coding. We could live with this and figure out how to secure that after the fact. Or do we want, or, or to Mitchell's point, are we willing to say the heck with it?
Let's just get all that code out there and we'll, we'll fix it in post as we say here on in text drunk tv, right? We'll fix it in post. So Alan, I I think you have to break it into two different things.
If it's coding practices, right? That's another thing. Um, half the developers, I don't know.
I'm just saying that half the developers start on a taking over a code base and they start rewriting it 'cause they like to do it differently, right? Mm. They'll mm-hmm.
Sort of put their mark on it. When you talk about code quality is different than secure code. Code quality is different than brittle or resilient code.
Uh, code quality is different than efficient. Uh, code that executes when it executes. That's I think where we point the standards to.
Whether it uses kind of good variable names or, you know, a little bit too heavy on that. AI likes to write a lot of code for you. And I think that's where some of these vulnerabilities come from.
Then two to four X that we're talking about. I, that's what I'm concerned about is I don't want to have to run scanners against everything every little bit that a AI agent or AI assistant does, because I think we're entering a place where it's very easy to change what code does. And so a lot of code is gonna be changed more so than what a human would change.
It's easy for AI to make, you know, 50% more changes than I might make just 'cause it takes me more time. So I think we're gonna see a lot more, we are already seeing a lot more code generated and a lot more code changed as you go through these, uh, assistant tools. And so it's, it has to be not a whole other step down the line in a, in a DevOps pipeline.
It has to be at the point of generation. That's where it's, you have agents that a specialized in security, specialized in resilience, specialized in whatever that are applied to the code before you take it and say, let me test it now. That's what needs to happen.
That's the real shift left is shift left means at the point of origin, it's made secure. I think that's, that's what we need to expect from ai. So we need to follow that up.
Essentially, AI agents that are gonna review the code and test the code that is created by the other AI agents, it just can't be the same LLM used to create the first code, because then that will just confirm the bias in the code in the, in the second instance. So we're gonna have, you know, this kinda DevOps framework of AI agents essentially. And then some human might review that because it'll be more reasonable.
But on the first pass, a lot of this code is just, uh, independent for the average human to kind of sort through. Well, well look, you know, we talked in the first segment about, you know, Alan was kept calling US boomers and talking about 1995. And let's just say I've had this conversation actually in 1992, and those code generators were called compilers.
And I've literally had the conversation with the chief architects of Novell NetWare when I was there, about converting from writing an operating system in assembly to writing it in C and how do you write portable C And I went through all this thing and I was on a project to do all this and convert the entire operating system into c And at the end of this weeks long conversation with the chief architect, they said, that's all great, Jack, but there is no way in hell a compiler will ever generate better code, assembly code than ica. And so we'll keep writing the, as the, the operating system in assembly and you'll have to port it to C to run it on other processors. That was the conversation in 1991.
Nobody today, ever, ever, ever in their lives questions the capability of a compiler. Now to your, to your point Jack, there's even, yes, it's the compiler. There's also an intermediate language of what code gets translated to, right?
Right. It does not translated to assembler, uh, p code for Python or byte code. Um, same thing for For Java.
For Java, right? It reduces it down to an we don't question that it runs and we don't look at that. Most of it's not human readable.
There's the tools that you can make it human readable, right? It's not, you know, execution code. It's not assembler code, but it's an intermediate step.
And that's I think where we're going to with the AI tools at some point. Exactly. We won't look at the code anymore.
Well, let's, let's take Jack's thing to the end degree though. So won't the AI at some point decide that well, all these abstractions that were created for humans are inefficient, so we're just gonna write everything and assemble all over again. Great.
Okay. They do that today. They're called tokens.
Yeah. Right? Yeah.
When, when, when you do rag uh, retrieval augmented generation, you take your database of stuff that you want the AI to look at, and you translate that text into a form that is easily processable by the ai and it's no longer human readable, right. To make it more efficient. We already do that today.
Let's take humans outta the equation. We'll get rid of all these carbon based life forms. Um, but Wait, wait, there's a Star Trek coming.
There is vi Ger Vier Vi. So quick plug predict 2026, I believe it'll be January 15th, we're gonna announce Techstrong's entity of the year. And there might be some of that involved in there.
Carbon based or none. Yeah, well, both. But um, but really, so look, I, I think, I think that is coming, right?
We're gonna have the AI agent of the year award. You're laughing. I Yeah.
You know, hey, DevOps dozen voting ended or nominations ended last Friday. We will see, I think we actually have a category mm-hmm. For that.
But, um, or it's something similar. But anyway, to me, guys, what you're talking about though, it be, it becomes a question of efficiency. Having the AI generate the code, but not getting too worried about the quality of that code.
'cause I'm gonna, in essence catch it in post right through my, my next iteration of a different AI agent. And then I may translate that into non-human readable form. And, and maybe we'll check it again there, and then we'll actually put it through and then we'll do one more check after it came through to make sure there's nothing in there that we missed the first time.
But you're gonna tell me it's cheap, it's faster, cheaper, more efficient to do those four things than it is to pay a person to do it and maybe do one quick look over. You know, it's a question of what's more efficient and what's going to, and, you know, and not, which is higher quality or even more secure. What am I willing to live with, Right?
And that's, that's going to, I think, the ultimate decision here. But, but don't you, you don't believe that that trade off's being made every day before AI assistance? Yes, it is.
I it is, but I I, we do that. I agree with you, Jack. I, I, yeah.
Mark this down. I agree with you, Jack. Okay.
Um, clip that we, we will give you the second mark so we can make a LinkedIn. I agree with you, but I, I think what one of the things that AI brings to the table is the ability to maybe do 3, 4, 5 layers deep, Faster, or more efficient than it would be to have humans in that loop. Right?
I think humans in the loop, assuming we, we can, you know, have gigawatt, uh, uh, cars that go back into the future and we have that kind of power to power all this ai, right? We have enough water to cool down all these processes for the ai. I think what we're we're trying to say is that the AI is gonna be cheaper to do these tasks, even if it, there's a couple extra, you know, rungs to the task to, than it is to have humans involved.
Not, not only agree, and we will create so much code. There's not enough human on, on the planet to review humans, even the scanners and output. At some point, the, you know, you exhaust what the human can actually do to, to add a detail.
I'm building a data center. Yeah. Center and a new, and a generating plant in my yard.
There you go. So we're moving from humans in the lude to humans or Luby. Well, I mean, at, at some point you'd then start asking yourself, what is the human's role here?
Mm-hmm. Could be human. That might be tomorrow's Textron gang.
We'll see, that Could, it's gotta be a Star Trek about that. That That might be an entire Textron gang episode. Well, I think they did a movie about that, Wally.
Uh, well, Yeah, Wally. Anyway, interesting times indeed. Mitch, I I should point that you're doing a lot of work on Ag Agent AI in the software development life cycle and the software world and, and, uh, the articles Mike spoke about on fu just a small, uh, glimpse into that.
And so if you're interested in this topic, you should follow Mitch and, uh, stay abreast of what's happening. com/mitch Ashley, you'll find me. Message was brought to you by cisa, um, by ai.
And we have nothing else. I think. We'll, we'll put this one to bed.
Jack, thank you as always for sharing your opinions and, and standing up for them. I appreciate your man. Thank you, Mitch, Mike, thank you.
Thank you for watching. I hope you've enjoyed this sparring today. On, on Textron Gang.
As usual, we have Textron TV immediately following this, so stay tuned for that. We will be back tomorrow with even more Textron Gang, so stay tuned for that as well. But for now, I'm Alan Shimel, and uh, have a great day everyone.