How Open Source Is Changing DevOps and Code Generation | TSG Ep. 874
Alan, Mike, Jon, Ira Winkler, Chhaya Gunawat, and Lisa Martin (CMO Advisor, The Futurum Group) explore how open source—with help from Microsoft—is bringing needed transparency to AI tools that generate code.
They also break down the risks of AI search results being poisoned, and what it means for trust in generative systems.
Transcript
Hey everyone, thanks to Microsoft. We actually compare into the black box. That's AI coding.
Maybe you're watching Textron Gain. Hey everyone. Happy Monday.
That's right. Monday for a lot of you, it was a long weekend on July 4th weekend. It's a pleasure when July 4th is on a Friday and you can get those great weekends though.
I prefer a Monday 'cause I like to get off Mondays. There's something about getting off Mondays that just gets me off. Anyway, um, happy Monday to you.
We've got a great text on gang for you. Let me introduce you to our fantastic panel. Most of them have been on the gang before, so you know them is the one and only Lisa Martin, the infamous famous man about town.
Ira Winkler, our man in Silicon Valley. John Swartz, the Dean, Mike Ard, and a new gang member to introduce you to today. And I hope I say her name right.
I practiced, but you never know. Chaa Gun. Am I close?
Chaa? Hi. Yes, that's right.
You got it. Alan Chaa. Tell people a little about yourself.
Sure. So hi everyone. Thanks for having me here.
Uh, I'm a DevOps interest over 18 years now. I graduated back in 2007 and luckily I entered the industry when DevOps was still evolving. We used to known as Build Engineers that we got converted into SREs, then it was DevOps and now it is ML Ops and secure Ops and whatnot.
Um, so I'm here at Amazon for five years now. I worked with various industry companies, for example, in NetApp. I worked through Chatter partners for Cisco and back home Bosch, uh, for a couple of years.
So that's kind of little bit about my background. Fantastic. Welcome to the gang.
You're gonna be a great member. We appreciate you. Mm-hmm.
Ira, Mike, you, I'm sorry you hear people graduated 2007. Yes. You know.
Good for you. Alrighty, let's move on. So Mike, uh, our first article to, or our first, uh, our first segment today has about an article up on Dev.
com stuff today, but this one is regarding a big news from Microsoft. Uh, they open sourced, uh, a piece of a piece of software that lets us peer into how AI actually does code, how AI produces code. You know, this has been a bit of a black box and a, a sticking point for a lot of people who don't under who wanted to understand how is, why is AI writing the code the way it is?
What, how is it writing the code the way that it's writing for good or bad? Mike, I'll throw it over to you. Yes folks, it's hard to believe I know.
But Microsoft is setting an example. Things that we should follow, things we should consider here. There is this AI editor that they are now making available as a under an MIT license for that matter.
And that's the AI editor that they use to create the AI coding tools. So now you can see exactly how this thing works and how it's actually constructing that code. And more importantly, I think, I think the tools that we have out there are gonna want to peer into that so that we can observe what's happening here.
And it's gonna be consumed more by, uh, observability tools that we use to kind of see what's going on all across our pipeline. Not sure how much each individual person wants to dive into that level of code, but the level of transparency is improving. Alan, is there hope for us?
Well, let me give you the good, the bad and the ugly. You know, the good is, as you said, code, kudos to Microsoft, right? They open source state and not only did they open source it, they put it out under an MIT license, which is one of the most open, if that's not too many, opens in one word sentence for you.
One of the most open licenses there is, it virtually allows you to do just about anything with it. Um, so kudos to Microsoft for doing that. And as I said before, I threw it over to you, Mike, you know, a lot of people have been wanting to get peer into the black box of how AI actually thinks of how it does what it does.
If, I don't know if thinking's the right word. I don't think reasoning is the right word either, but how does it work, right? How does it, you ask it to spit out code that does this?
How does it know what to write and how does it write? So now we actually can peek in and, and maybe see what, you know, what goes on behind the black curtain. There is the wizard pulls the, the levers.
The bed is like most open source code. No one's gonna look at it, right? It, it's almost, maybe it'll be comforting to know that we have it available, but who, you know, looking at it, uh, and then understanding it, that's even a smaller percent.
You probably count the people on like your fingers and toes. So, you know, it, it's a great thing for freedom. We just had July 4th, you know, so freedom, like Richie Haven said in Woodstock is a motherless child.
And, um, but how many people are actually going to, you know, use it, I think will be remain to be seen. I think, Mike, you're right, people who may be like collecting analytics and wanna see, you know, broad percentages of how code is derived via ai, they may use it for sort of research projects, if you will. I, I, Yeah.
Alan can I, oh sorry. Can I jump in quickly? Sure.
Do it. I think you're missing a complete group of people who are gonna look at it. And these are criminals.
You're gonna have a bunch of people who now, since it's open source, are gonna look at it to find vulnerabilities. That's number one. 'cause if you have open source, you know, it's easier to find the vulnerabilities.
Also, if it's open source, um, you got people fixing it, you got people enhancing it, but the security checks going in sometimes don't take top priority in fixing. More important though, I can promise you that there will be criminals who take this open source software, do the features that are supposed to help the community and then embed malicious software using those same features and then put it out and distribute it like it's a legitimate code base. And this has happened with library programs, it's happened with other open source compilers and everything like that.
And even if somebody takes it writes an enhanced version, somebody can compromise that legitimate good enhanced version and put malware into it because ugly, there's not Check. Well that's ugly. There you have it.
That I should have thought of that actually, IRA, but there you have it. That's pretty ugly, right? And it's why we can't have nice things.
John, let me ask you about this 'cause you're closer to this than all of us, but what's your take on what's going on here? Um, my take is, um, I think they should have done it earlier because this is not the first company who have done the open. So we have had deep seek, had their model out right from the day one.
So I personally feel they should have done it long ago. Uh, the model outsourcing. And the other thing is I feel they have taken the financial advantages of being upfront in the AI for a long term.
And now they're looking for more ideas to make it better in terms of the features that the developers are looking for. And the reason I've been, um, giving this feedback is because I've been talking to a bunch of college grads who are entering the workforce for the first time and they asked me, Chaya, we have not coded without ai, so how do we code with the air? You know, a world where we are not allowed to use this model because not many companies are going to allow the open source AI model within the workforce until it's scrutinized.
So there is a mixed conversation about it in terms of the open source versus the responsibility of it. I I, it's an interesting point. I Think one of the things that I've consistently heard from folks is that it's very hard for them as humans to debug code written by the AI because they don't know how it was constructed in the first place.
So let me come back to CHI on that. But can we maybe get better at at least understanding what the AI is doing and make it easier to debug? Because folks are, a lot of people are saying, I just assumed writing it myself.
At least that way I know how to fix it. Chi is that question to Chi Mike? Yeah, I thought so.
But cha thoughts? Yes. So the thing is now the space is getting slightly better.
People are starting to understand what the models is looking for examples to get the code trained, right? And that's why when we have multiple such co copilots, such co coding assistance, they can pick a model that will help in the right direction. So I feel there is a, there is a information out there on how to make the right judgment call in terms of the usage.
So I I wanna distinguish though this compared to let's say open Seeq, yes, the researchers behind Open Seek did open source open seek, but I don't believe they open source something here that gives you a picture into how it actually reasons in, in terms of developing code. I think with open seek, the, the, it was about how it was trained, right? And how it was, uh, you know, they did it with less ener, less energy, less hours, less time, right?
It was a, a more efficient model, but I don't know if they gave you, if the, if the code generator, if you will, was was in fact open sourced. To clarify, you're talking about deeps seek, right? Deep Seek.
I'm sorry, what did I say? Opens seek was that old opens seek, I was wondering. Yeah, no, it was open seat.
Wasn't that one of like the search engines before Google or something? I don't Yeah, no idea. Yeah, No.
Anyway, deep that's that, that was it. Yes. Deep sea.
But, so I don't know if, if they in fact open source this aspect of, of the model of the John, I have a question for you. Does this force all the other players, and especially open AI to kind of come around on this same issue as well and will everybody fall in line? I think because Microsoft's doing it, I think it's naturally we'll see open AI probably follow the same path in terms of as, as a competitor.
Um, yes, I think it will. And because what this is a, uh, me too race in a sense. We have people jumping from one track to another, whether it be be acquisition, whether it's philosophy.
And I mean, one thing I I just wanted to point out just ki kind of looking from it as at a higher kind of far away level, this passionate level is, it's interesting to see this evolution of Microsoft from this, you said earlier kind of like this me too company to DRI say almost a trend setter of sorts. Although the open source approach here leverages the same community dynamics that made BS code a success. But again, um, I think the change of tactics, and I think what we're seeing, and this is a microcosm, are these companies trying to find some sort of advantage, some sort of edge to, to get a step ahead of one another and then they're gonna follow one another and it's gonna be this kind of path race that goes on and on.
And we're gonna see this in other developments involving DevOps, security, whatnot. So this is gonna be part of a, a larger trend, I believe. And it's interesting to see Microsoft for ones trying to lead in a certain area when usually they're the followers.
I agree with John, I think that's what it is about. It's uh, the thing that I also wanted to add with this open AI and Microsoft partnering, uh, kind of going in a different direction. There are resources moving around.
There are a lot of OpenAI engineers going towards meta. And then because OpenAI is stepping away from uh, Microsoft, they need to come up with more ways to handle this, which they have built over the years. All right?
So as a guy who writes a lot of these articles, I'm kind of hoping everybody will just do this all at once. I mean, save me a lot of time and trouble next week and around noon would be good and everybody just, and name their announcement and call it even. Alright, that Gonna happen over like a par Mike, this is gonna happen over a period of six to nine months and you're gonna have to do a story that updates what happened before and, and there, it's not like gonna all happen in one fell swoop.
Is this gonna, and they're all gonna do it at different timing and try to present it as if it's something unique that only they thought of. Come on, if we all know the end of the moving, can I just fast forward? Let's go.
Yeah, I wish We could, makes life easier for us. Yeah, You want, it's the journey, not the end. Sometimes it's a repetitive journey or derivative it seems.
Yeah, but again, everyone could rush headlong into open sourcing this, but as Iris said, it, it may just benefit the, the ones who benefit the most may be the people we least want to have access to that. So Yeah. Ira, do you think the security people or the bad guys at least will contribute fixes to the project once they get to know how it works?
Let me tell you a true story. I once had a, a CSO from a Fortune 20 company give me a call and they're like, IRA, I think I have China all over my network, but I don't know what to do about it. I'm like, why do you think this?
It's like all of a sudden all my vulnerability reports are coming back clean. So, and it wasn't the network operations team, it was like, uh, you know, a malicious actor basically came in, updated all the systems so other hackers couldn't come in. But also they needed the systems updated for their, the latest version of the malware they were implanting.
And they thought that people would never notice this. And frankly, they didn't notice it until the security manager noticed this. And I think what's gonna happen is, unfortunately the bad guys are the people who have the most to financially gain.
Everybody's gonna pat themselves on the back. The open source people are gonna be rah rah rah, but the bad guys are gonna be seeing dollar signs or intelligence data in their shiny little eyes. And they're gonna go ahead and put out their own versions of this, if not figure out how to exploit the code.
And I'm telling you, that's gonna come a lot quicker than you think, Unfortunately. All right, let's take a break here on Textron Gang. We're gonna come back and talk about DevOps in the age of ai.
Got a lot of articles behind this one you're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You will access editorial websites, streaming videos, virtual events, custom content analyst research and more. Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in. We're gonna have a little conversation about DevOps and the age of AI because we've been debating this back and forth and fortunately we got to talk to some folks about what they're actually doing in real life. Sean Tyer, who is on a previous episode of the Techstrong TV channel, so go find this, but we're gonna run a little segment of this interview where he talks about how Mondelez his company, or at least the one he works for, is using a WSQ inside their software engineering workflows to think make things more efficient.
But it doesn't sound like maybe we're replacing DevOps engineers anytime soon, at least from his perspective. And by the way, if you don't know who Mondelez is, look in your kitchen cabinet, you'll find Oreos and Cliff bars and those are the guys who make those. Anyway, let's see what Sean says.
Everybody's talking about one of the implications for the future of application developers. And um, on the one hand some people will say it's just gonna make the developers more efficient and they'll still be with us, but they'll be in a different kind of role, more of an architect. And more, and much more of the code might be written by a machine and others are saying, you know, eventually the machine does everything.
But where are you on that spectrum? I think I'm probably leaning more towards the, we're always going to need people who are really good problem solvers and are able to define problems in a way that they can be solved effectively and securely and efficiently. Um, the actual work of a software developer or a cloud engineer on my team has already begun to change where we're relying on AI agents and assistants to do more of the work with us and for us.
And I think for me, in many ways, I'm seeing my team use these tools to help automate kind of the boring tedious work, right? Reapply the things that we've already learned. It's hard to predict.
I don't think anyone can where this is going to go in the future, but I'm leaning more towards the uh, uh, side of I'm always going to need engineers. I'm always gonna need people who know how to solve problems, how to define them well. And regardless of the tools that they're employing and I'm providing them with, I'm gonna still need those kinds of individuals in my organization.
All right, we're back in cha, you two are close to this. And the question that's been going around all this time is, does AI replace DevOps engineers and software engineers or is it just gonna change the way we think about building software? And if so, how?
That's a good question. And I do feel that there are, the changes are coming there, there are two aspects of, uh, agent ai, not just AI about the agent care. And in DevOp it's gonna help and it is helping a lot immensely with troubleshooting network debugging, security aspects of it, federated learning, but there's also other side of it, which we still have a lot of work to do, where we want this agents to handle the infrastructure dynamically.
And that's where I think, um, the experienced specialized DevOps engineers are still needed in terms of what automation we actually need so that we don't blow up the infrastructure, right? You can have an agent AI go and spin up hundreds of in instances when as a customer you may not even need it. So there is a need of supervised learning.
There is a need of, uh, structuring the process, but it is definitely, even, I am a extensive user of it, it is helping a lot in terms of debugging, in terms of collecting the information from different sources. For example, I'm a heavy MCP user, so what I did is I built various MCP servers and connected with Q and it is giving me a summarized information, which is helping me a lot to kind of debug in terms of any event that I want to take a look at it. So if we think that through for a minute, Nowlan, we've talked to DevOps engineers for years, and every one of them always says the same thing is basically, I'm overwhelmed and I can't keep up.
So at the end of the day, does AI kind of just make this a job that you can actually accomplish because there's gonna be more software than ever, but it seems like all the AI advances lately are for the developers and not much for the DevOps engineers. Uh, that's not true completely. If as a DevOps engineers you are very well aware of the capabilities of ai, it helps, it helps a lot, uh, in terms of summarization part especially.
So you can, uh, place automation in place to collect your logs, to have your network monitored, especially in the observability aspect, it is helping, it'll help a lot if having said that, it does require a little bit of ramping curve in terms of the knowledge base, especially DevOps deals with. Absolutely. And look, here's the thing, right?
And, and I'll mention, uh, not last week that we prefer as a platform con in New York. And you know, there's a lot of where they started off a little adversarial. There's a lot of overlap and cooperation now between the platform engineer and DevOps engineer and and so forth.
When it comes to ai, it's, it's a gen AI that's gonna help the DevOps engineer and the platform engineer. It's having these autonomous agents that are doing some of the work, but they're not replaced, at least not in the foreseeable future, which in our world is 18 months, right? In, in, in the next 18 months, let's say two years.
They're not replacing the DevOps engineer any more than they're replacing the platform engineer or the SRE or, or, or these people. They are helping, they are the co-pilot to the pilot, right? They're enhancing the DevOps engineer.
And Mike, to your point, maybe it allows these folks who are always kind of playing catch up, right? Too much work to do, too little time to get it done, to get out ahead of this and actually increase our, uh, deployments, speed up our deployments, better secure our deployments, right? And that might be the single biggest thing is can we use AgTech AI to help with compliance and, and not just compliance for compliance sake, but for security, right?
This is, I mean, you know, a, a great, again, I got into DevOps from security because I thought DevOps was a great opportunity for security. Agen AI for DevOps in my mind. Another great opportunity for security where we can build this in here.
These agents can do things that maybe a DevOps engineer is not a security person. It can enhance their security, uh, capabilities. And Ira, I know you, you would like to see better security.
I I would like to see better security and it, this is a catch 22 because so far when you look at ag agentic ai, ag agentic, and writing code and everything else, security has not been well embedded in anything. Like, you know, I'm dating myself, but the first version of the Mozilla and browser had no security in it whatsoever. 2 'cause nobody even thought about putting a password on the system and you know, so all of a sudden it took a few revisions to get there.
Now, when we're talking about agent ai, I promise you again, there's, let's make something functional first and maybe we'll think about it later. And even when you think about it, I mean, let's just consider the number of vulnerabilities that are being announced on a daily, weekly, monthly basis already of regular software where people are already well aware of security issues now, you know, it's like, what's the word, you know, um, to air as human to really screw things up, takes a computer, you know, and this is what's gonna happen, especially with security vulnerabilities. You're gonna have people doing essentially an agentic ai.
They are gonna try to secure the code that's written and maybe they're gonna go ahead and they're gonna also be able to do security reviews as well. That's another function perhaps built into DevOps. But I still think that this is, this is gonna be a, there is gonna be a nightmare resulting from security built in.
And much like we talked about on the previous se you know, segment. You know, I do think people are gonna start embedding malware into this and so proactively, like into APIs that are pulled, that's gonna be a future segment as well. And so anyway, I'll, I'll stop my monologue, but I'm just more, I, I just think we need to do this because productivity is not gonna stop.
But at the same time we really, really better have a fail safe mechanism as best we can built in. Lisa, again, let me call, let me pull Lisa into this chat since we haven't quite gotten there yet. But, um, we talked a little bit about this in the past, but there is so much noise being handed over to investors and Wall Street talking about how, you know, we're gonna reduce the size of companies and lay this one over and that, and yet I've also start to see is a message now where people are rehiring folks that they thought that they were gonna lay off.
And it turns out that they maybe have different jobs and roles, but, um, maybe the sum total here is I have the same number of people that I always had. It's just that they're more efficient, but it's not necessarily gonna be fewer people. And do we need to change our tenure and tone?
I think the tone needs to be transparent. It's like we talked about in, in the prior segment and Alan was talking about the good, the bad and the ugly. And IRA you commented on the ugly.
And that's just a fact where companies need to have the, the messaging really straight and, but it has to be transparent. I think that they have to understand how AI agent, it's augmenting the DevOps engineers, um, the developers, how it's augmenting other functions and roles in organizations. Um, but then we have conflicting messaging like Andy Jassy about 10 days ago that talked about AI replacing jobs at Amazon.
So I think we're seeing kind of a mixed bag here and what needs to be, what we need to have is that transparency, but it has to be consistent. Um, where we really identify what are the benefits of gen ai, agent ai, ai, where are the challenges and the concerns that everyone needs to be aware of? And the security front needs to be front and center and a constant reminder to organizations that this is something that needs to be, um, continuous in the ba in the foreground, really.
But I think that the messages are conflicting between different companies. Um, I'm hearing a lot of things here in Silicon Valley that a lot of, um, folks are saying, well, well if AI is gonna replace my job, how can I get AI skills? And we're seeing companies rehire, as you mentioned.
Um, and the message there is that folks that have AI skills or know how to use AI to some degree are more desirable. But I think, um, we're just gonna see an inconsistency of messaging as different companies are treating it differently. And, um, I think that's just a, a what we're seeing and what we're going to see for the foreseeable future that Probably, I'm sorry, go ahead Joe.
I'm sorry. Just I was gonna say, sorry, Alan. To Lisa's point, you know, Microsoft just announced 9,000 layoffs and Cisco's been letting people off, which they have not announced, but it's dribbling out 'cause I have several friends who just lost their jobs.
So it's, we're starting to see it, um, among the largest companies, the ones you think would be the best positioned. And again, what these companies do through technology waves is not, not just with ai. They, they move to the cloud, they move to it to mobile, whatever.
When they do, they shed a certain number of workers and hire new ones. So there may be a net of zero in the ends, but they're constantly shifting the employment. It's not, it's not great for the workers, but what the companies have to do if they're gonna maintain their, their edge and, and and their competitive stance.
So we're gonna see, we're gonna see a lot more of it. I wouldn't be surprised if, I mean, as you mentioned, Amazon, there'll be layoffs there. They'll, it will just go across the gamut.
In, in a year, half the people who got laid off by Microsoft, they're gonna be working for Cisco and the other half In Cisco be working For Microsoft. Yes. What happened before, right?
Yeah. This is happen. Another, another way, you know, there's a Loan out perfume ai, you just spray yourself with that and you become very desirable.
Um, wow. Oh, sorry, I just, I I hate to do this and put a damper. 'cause in many ways what you're saying is true, but I have a lot of friends who have been out of a job for an extended period of time.
So we really, I, I don't wanna downplay it because you know, it between the tariffs taking a hit on retailers as an example where I obviously have a lot of friends who have been laid off due to that, you know, to all, you know, different shifts. I think we've been doing, I mean this is a definitely a different topic for some other time, but I think, but It's a topic we've discussed. Yeah.
They're laying people off the guise of AI on what they're really doing is laying people off. 'cause they hired like drunken sailors during COVID. Yeah, during COVID.
They overhired. Yes. They, And now it's very hard, you know, like you are right?
I get friends every day riding me to help them with jobs. And these people are outta work eight, nine months and more. And they're not, they're highly skilled, highly skilled, very, I mean great people to put in an organization.
It's Just hard. Yeah. And I wish I could create a company of just laid off people.
'cause the fact of the matter is at this point, if you hire somebody who's been laid off, they are gonna be as loyal as hell. If you treat them decently, they're gonna do, they're gonna work their asses off. I hope I could say that on here, but I, I mean, you know, they are gonna, I I I just want to keep it real because it's easy to say like, you know, there's this whole Silicon Valley, it's, it's like fairytale land out there with like, people jumping around from one of the, you know, fang companies to another or something similar without courage, salaries and things like that compared to the rest of the profession that's out there.
And there's a lot of people who are not gonna be as, let's just say mobile as some of these other Silicon Valley companies that are like hiring and firing people on whims. So anyway, I just want to just have to keep it real for there. 'cause I just have a few people in my inbox today that, anyway, sorry about the damper.
No, you're You're absolutely right. It's, it's, it's like Logan's run here. I mean, I'll be honest, it's a lot of ages.
And, and, and, and, you know, the cycle is becoming to the point where, you know, you used to be considered old if you were in your forties at one of these companies. Now if you're in your thirties, you're considered on the cusp. So that's Something here.
So what I wanted to add is, yes, people are losing jobs, but there are also an opportunity here, there are a lot of jobs coming up in prompt engineering. I, the reason I say that, because I'm an immigrant for over 13 years now. I'm on, I'm on a visa here.
So losing a job, being an immigrant is the worst fear that anybody would have. So at, but that's the best side about me because I have this sword hanging on my neck. I'm constantly evaluating, am I on the edge of things?
Am I learning new things? Am I exploring it? And it, the the side of it also has it, the industry is changing.
When I started my career, there were a lot of jobs for manual testing. And now those are gone. There's automation, there's DevOps.
So now I feel the dev is getting automated. So in there is also an opportunity here in terms of skillset that people can have. And whenever I talk to people, there are still a lot of people who are not aware of many of the things in what they can use to improve their skillset.
So I think the responsibilities also on the workforce to keep up with the skillset that are coming up. And the AI is not that we are talking about it today. It's that it, the, I think chat came up in 2020, uh, I believe November.
So it's been like four years now. We need to kind of train ourselves to untrain the things the way we've been doing over the years. Yeah, Chad, that's a great point.
You know what to you Is trying to figure out what Logan's run is, John. Well, they, when they graduated in thousand, you're done. Yeah.
But, but no kidding aside, chia, congratulations and kudos to you, right? Because you just hit a really important piece, right? We, we see the headlines about immigrants, we see the headlines, people on visas.
We, we see the headlines about layoffs and about AI taking jobs and, you know, part of the American dream. And we just passed July 4th, right? Go west young man, we, anything is possible in America.
That's what brought immigrants here is that you, anything is possible in America, but no one gets handed a free lunch. Or at least they're not supposed to be. You, you, you, you, you work for it and you get it.
You make yourself better and you become more valuable. You, you can't sit there and think it's coming to me and I don't care. That frankly is whether you're an immigrant or you were born here and your people came over in the Mayflower, if you're sitting here thinking you're entitled to something, that's not America, that's not the us You, you have gotta be constantly honing your skills, sharpening yourself, making yourself more marketable, more valuable.
And I think that's the message to take out of this. I agree. I think it's a shared responsibility model.
And Reya, I'm glad that you brought that up because we, I, I talked about the Andy chassis statement from a couple weeks ago that we actually dissected on, on this program that ai and it's just feeding the fear that the, that the general population has of ai, it's gonna take over everything. I've got family in the entertainment industry who are terrified of it taking over jobs for them. But you bring up a great point chair in that it's, it's shared responsibility that you had this impetus within you.
And more people need to be aware that they need to take responsibility in educating themselves and upskilling themselves and learning how to use AI tools to make their jobs better, more productive, ultimately making their products and services better for those folks that are consuming them. But they've gotta, they've gotta have stake in the game. That's a, that's a mindset and a message that needs to be out there.
So I, I have to play devil's advocate here. Not to say that people shouldn't be motivated and keep on the cusp and everything like that. But you mentioned prompt engineers as an example.
Yeah. If you're in Silicon Valley and prompt engineering jobs are out there, you know, I look at the jobs around me and you know, not in the FANG type of group and prompt engineering isn't really that popular and then, or isn't that available? I also look to people who have been in the profession, you know, like for 20, 30 years, God bless you for 2007, but you know, I know people who started around 2000 earlier and even, you know, at your level, I mean I don't think a prompt engineer, unless you get some mythical job at open AI is gonna pay the same as somebody who's been work in the workforce for 25 years who has been doing a good decent job evolving for the needs of an organization and then all of a sudden the organization just says, Hey, we don't need you because well you're doing an important job, but we could not need that important job 'cause we have to have cuts.
And then saying for example, that you're gonna replace somebody at 2 25 a year with a prompt engineering job, which could be handled frankly by somebody offshore is not a realistic thing to say. Like, to become, hey, I wanna be trained in a salary for a job that pays half the salary I'm currently making. That's the problem people are having.
I mean, there is some, But let me, lemme turn it around and we're over time on this, but let me quickly turn it around on you. You know what, I think auto factory work has said the same thing in the seventies and eighties, right? The, those, those factory jobs were going away and all of a sudden they could go work at Walmart as a greeter or something, right?
For, it's about retraining people, whether it's prompt engineering or some other skillset. If, if your niche is being amalgamated, for lack of a better word, you've gotta do something about your skillset to make yourself marketable. Whether it No, I, Yeah.
You know, I don't know if it's prompt Engineering percent. No, I a hundred percent agree. Um, there's just like, you know, for example, factory workers factory closed down, they have to move.
You know, luckily we're in the knowledge industry, so perhaps there's a few more remote jobs that are available to us and I know people are taking advantage of that. But, um, yeah, I mean, I just wanna say it's not as simple as just saying, Hey, you haven't been staying up to date on what are now low paying jobs and therefore it's, i I just don don't like, but that, that's an Amer So is that people's problem? Is that a, is that an American problem where, you know, an economy problem where, look, we're, we're eliminating high paying jobs for people to take low paying jobs?
Well, I think that's a personal responsibility. I mean frankly at the end of the day you could say it's the economy, it's everything else. You know, as, I forgot who he sets the analogy, but you know, there's always a wind.
How you set your sail is how successful where you're gonna go. And that's what I think I'm saying, whether it's prompt engineering or whatever else the next thing is, Right? But I'm just saying it's, we're, we're sorry, we're changing.
The problem is the mindset that people have got complacent because complacency, I hate to say has been a beneficial thing for companies and the people themselves. I work for the government, I work for NSA where people are like, I've only, I asked, I had a friend who hated his job and then I'm like, why don't you leave and get paid 50% more? He is like, IRA, I only have 15 more years until full retirement.
I Like and he's, I got his countdown The hell outta there and then, Yeah. No, but you, you're right. I've seen that at the government.
Anyway. Hey guys, we've got last, last, Last, last comment on this. It is gonna be America's problem and we see it because there's a socialist who's gonna wind up running New York City.
This is an example thereof. Yeah. Alright, we got to, I hate to leave on that, but we're gonna take a break.
We're gonna come back. Let's change the subject Trust in AI search, not lls. This sounds like an IRA thing.
Lls uh, exploited by phishing. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts and more. com to learn more. com.
Home of security bloggers network. Hey folks, we're back and there's a report out from a company called netcraft and it's highlighting the fact that the bad guys are using LLMs to craft phishing attacks and they're doing it more efficiently and they're harder to detect. And it's kind of building what feels like maybe a tsunami of these phishing attacks that we're gonna see that are not only gonna come in higher volume but are gonna be more sophisticated.
Ira, is the cybersecurity game fundamentally changing here and maybe the bad guys are benefiting more from AI than the good guys? So I think there's a couple issues here. First off, I really don't like the concept of calling this a phishing attack.
It's not a phishing attack. What this is essentially in large part is a data poisoning attack against LLMs. And there is a distinct difference 'cause phishing implies you are pushing out information into people's inboxes.
So for ex in the, in the example cited in the referenced article, you know, a phishing attack would be, Hey, this is your bank. There's a problem with your credit card, please click on the link or call us up at this number and it's the wrong number. That's a phishing attack.
In this case, what we're talking is LLMs spitting out the wrong information where LLMs are giving people the wrong customer service type of thing. And I'll, I'll give you an exam. People know, you know, I run cruise con, people know I love cruising and I'm an active on the cruise, um, boards out there.
And what happens is somebody replied back saying, I wanted to like update my reservation and Royal Caribbean said there's a $400 port fee they didn't charge me for. And everybody's like, where'd you get that number? 'cause what the person did was they searched the internet, came up with a fake number for Royal Caribbean because that's what a criminal put out there on an LLM or whatever else, which is exactly what the attack is.
And they have the person calling a fake call center because the LLM or the website was malicious that they looked at and got a fake number. This is the essence of the attack in question that we're referring to. Now, the reality is how do we address this?
You know, the people who are running LLMs like chat GPT are not necessarily looking for poison data. They're not looking for criminals who know, hey, I could go ahead and say I am in the article, it's eyesights Wells Fargo. I'm Wells Fargo, here's my new numbers and feeding in fake customer service numbers.
And this is not unique to users. Users really have to just know, uh, and this is nothing new that you have to go to the actual company website or the number on the back of your credit card to actually get this. But anyway, to that extent it's this and it's just a matter of data poisoning that, you know, people have to be aware of.
Lisa, will people stop trusting AI search tools and go back to, you know, good old fashioned Google search engines? That's a great question. I I think we have this, we've got people that are pro ai, a lot of us in tech that, that know how to use it properly and responsibly.
And then we've got the, the consumer, the, the general population who's terrified of it. I think those are two very distinct populations. I rarely find people that are in the middle.
Um, I think that certain populations, like students for example, there's studies that, that I think I've talked about on, on iHeartRadio before that show that students between, I wanna say the ages of 18 and 25, who are leaning too heavily into like chat GPT and LLMs like that to do their homework assignments and are not even, uh, second guessing, questioning, verifying the information that's being spit out. I think that's gonna continue, but I think the message overall needs to be one I said earlier, transparent, there, there is, as you guys talked about earlier, the good, the bad and the ugly, let's just be upfront about that. Help people understand where AI is already being used for good.
Um, and when it's being used. Nefariously, uh, I talked about that on iHeart this morning about the transportation industry, the FBI and cybersecurity firms are saying now airlines are being targeted by potentially scattered spider. So let's make people aware so that they know how, what, what's happening, where the attacks might be coming from and what they can do about that.
But I think for the foreseeable future, we're gonna see those two groups, pro AI de maybe three groups, pro ai, those that are dependent on LLMs, like the students I talked about, and then the folks that will touch it with a 10 foot poll. Yeah. Could I also, oh, I, I, yeah, sorry.
I was just gonna quickly say, I do think that there is, the banks and other large organizations periodically put out phishing awareness and stuff like that. They need to start doing this with LLMs as well, saying, you know, much like that, please look at this information, not that information. So Ira, as you distinguished between phishing and LLM poisoning, I feel compelled to distinguish between poisoning and just the Seward that is the internet.
Okay? When you talk to me about poisoning, I'm thinking of a malicious actor deliberately going into a chat prompt, putting some information in that makes its way into the LLM that open AI or the body of knowledge that this LLM is using to answer the next person, right? And to me, that's poisoning.
I am intentionally going on there and, and putting in this data. One of the big changes I've seen in using AI, and I use it to help write and do stuff, is originally, you know, these LLMs were trained on a subset of the internet that was three years old, four years old, two years old, whatever. What I've seen take place over the last couple months, year, whatever, is it actually pulls data live from the internet now, right?
It, these are pulling data from the internet. And I think a lot of, especially like this article says 65% of the domains are wrong. You know why?
And it's Google search isn't gonna help you. The internet itself is so polluted with soundalike domains, fake domains, you know, malicious sites, and they get on a Google search too. If you ever get through all the sponsored ads in Google and go to the actual search, you'll click on things that are not real there too.
They don't do a great job of, of filtering it out. So when these LLMs are going out onto the internet, that's where they're getting poisoned. The environment is poisoned.
This is like water in Flint, Michigan, right? It's poison out there. And so they're just a reflection of, of the internet at large.
I don't even think it's, it's necessarily intentionally by people saying, Hey, I want to poison the, the LLM No, it's the internet itself that's poisoning em. Well, the the, yeah, the internet. See, the internet is the, these LLMs are poisoning themselves because here's what we, you know, l like you mentioned chat, JPT three years old data.
Now they have built in agentic AI that for example, says, I want to know who won the sports game. And it will pull an agent to query the internet to get the data back. And then at some point, are these LLM, you know, like chat GPT and all these other ones, are they gonna take or be held liable for feeding bad information and not filtering this out if people become reliant upon this?
'cause you're absolutely right. com and that's where I should get the data. Should LLMs, much like we were talking about the in the past segments, Well, is Google do this same, is Google Li is Google liable for putting bad data in search?
Um, are they legally liable? The answer is no. But if you are, Google's not saying give me Wells Fargo, you know, you could say, I'm searching for Wells Fargo and it says this is all the data.
But if I ask chat GPT, I have a problem with my credit card, who can I call at Wells Fargo and they feed Me a different, who doesn't say this is all the data. Like, you go on to Google and say, Wells Fargo, you're going to get sponsored ads by Chase City and you know, three other banks. Then you're going to get some, what we used to call Google search results that may have fake Wells Fargo domains in there.
Then you're going to get some more sponsored stuff, then some videos and some other thing. I, I would hold Google to the same bar that we would hold the LLM companies to. Well, I, I will play devil's advocate slightly and, and pass this on, but I do think that if I, there's a difference between me saying I am asking you a very specific question and one, a specific answer and doing a broad search the way it previously was.
I'll leave it there. Semantics. All right guys, we're we're, we're over time.
I gotta pull the plug, but what a great discussion, Lisa, it's so great having you on. Thank you Ira. Always bringing it.
I appreciate you Chaya. I hope we didn't scare you away. You're gonna come back 'cause you were valuable here.
Well, I had so much to learn from all of you. Thank you very much for Having me. Oh no, it's, it's our pleasure.
It's great to have you, John. Keep doing what you're doing. Keep an eye out there on the valley, make sure all's well hold up.
Two if by land, one if by sea. But you know, we'll go from there, Mike. Let's hope the Yankees, uh, you know, have a great after Allstar break.
I hope so. It's been an ugly mu it's been an ugly June. Yeah, it was an ugly June, but it's still July.
All right. Hey, we're outta here. Thank you for watching.
We've got Textron TV coming at you immediately following. As usual, we'll be back on tomorrow with even more Textron Gang and some more gang members. But for now, this is Alan Hummel.
We're outta here.