Navigating Cyber Warfare and Ethical Technology Development | TSG Ep. 903
Transcript
The Russians are coming. The Russians are coming. You're watching Textron Gang.
Hey everyone, it's Alan Shimel. Welcome to another Friday edition of the Textron Gang. My God, where does the weeks go?
You know, it was last Friday, I was coming home from Vegas in black hat after averaging about 17,000 steps a day. And, uh, this week I didn't even, honestly, I didn't get a chance to exercise as much other than maybe a walk on the beach or two. But, um, it's Friday.
I am looking forward to the weekend. I'm sure you are, too. We've got a great tech on gang today.
We've got some security related things, and we have our security heavy heavyweights on our panel today. Where, let me introduce you to our panel. First of all, I, I assume he's back home in Seattle area.
Fred Wilmont. Fred, you home? Yep.
Good to, yes, sir. Back home in Nice, cool weather. Ira, you look like you're once again on the road in a hotel room Today.
I am in the lovely city of Chicago after keynoting the Isaka Chicago Convergence Conference yesterday. All right. Well, are you headed home today?
I'm actually headed home tomorrow. 'cause obviously I made myself available to you today I am giving a presentation to the RSA CSO Mentorship forum immediately after. Very cool.
And then a couple business meetings. Good. Good for you.
Good for you. That RSA CSO forums. I, I forgot the lady who runs it, but I've interviewed her a number of times.
Nice woman. And, uh, they do good stuff. Good stuff.
And then of course we've got John Schwartz and Mike Vard from our Crocker Jack editorial team. Second to none, gentlemen, welcome. Um, so Mike Russian Hacking is back.
Did it ever leave? I, I don't know what, what do we got here? I don't know, but I gotta go with that.
The Russians are coming. The Russians are coming thing. Well, You have to be a age for That.
A 1970s, something around, I Mean, I might be sixties even. I'm not quite sure. 96 Alan Orkin.
Yeah. Yeah. Alright, so let's get started here though.
But the, um, as the president is meeting with, uh, his counterpart from Russia v Vladimir Putin, um, to talk about what's going on in Ukraine and maybe come up with some sort of settlement, coincidentally, there was a report out of New York State talking about how they think that the electronic filing system known as pacer, um, was hacked by the Russians and specifically involving cases involving Russian nationals. Now, I guess, you know, I'm gonna start this off with Ira a little bit, but for the Ukrainian war, I think we expect it much worse from a cyber attack, cyber, uh, conflict. And it maybe hasn't been as heavy a conflict.
It feels like it's been a little more contained. Is that fair? Or is it just we don't know about what's going on to the full extent here?
So I think there's a lot of lack of appreciation for what's being done behind the scenes. So, for example, it's been acknowledged that NSA went ahead and proactively took down a network that was going to attack the Ukraine before the Russia started invading. And so NSA was highly involved in taking down Russian infrastructure, which was poised to attack, you know, again, the Ukraine at the same time, taking down that infrastructure took down a lot of other infrastructure that Russia had in order to go ahead and take down the US harm the US and things like this.
You know, what we are seeing now with, regarding Russian cyber warfare, if you wanna call it that, I don't like to call it cyber warfare in this case. This is really intelligence operations because you might call this, um, you know, there's, everybody likes to call, you know, like information warfare, but it's broken down into, it's really called these days cyber network operations, which has cyber network defense, which is defending us. It has cyber network, um, exploitation, which is spying and cyber network attack, which is actually taking down infrastructure.
Russia was ready for cyber network attack for the Ukraine war, and periodically they rear their heads in trying to take things down and attack things. What's going on here is cyber network exploitation where they've been able to infiltrate critical systems, much like, for example, the SolarWinds case when the SVR Russian intelligence was able to go ahead and infiltrate a lot of organizations, take them down, prepare the battlefield for cyber network attack, or just do cyber network exploitation, which is intelligence gathering in this case. And Russia has done this before.
I remember the face of Obama staring down Putin when they met. You know, there's a very pop, you know, very prominent picture of that where, you know, Obama was having nothing of Russia hacking. And Russia does respond to power like that.
They respond to the ability of, for example, when General Naka was in place, general Nakasone before the election was able to proactively send warning messages to Russian actors that said, if you do this, clearly we know where you are. And that intimidated a lot of the Russians and kind of toned down what they were doing before the most recent elections. And we need to go ahead and consider this with regard to the pacer system, which is what's attacked here, which is the thing in the news, because this system has, you know, people don't think of a court system as being critical to national intelligence, but when you look at it, there's a lot of unfiled documents, or sorry, um, not public documents, documents that are filed that are calling each other names.
For example, like when you get involved in a lawsuit, you're responsible for everything from the Hindenburg accident to eve giving Adam the apple in lawsuits, and you get all this dirt that's never released to the public. But what this provides is how Russia would call it compromat on a lot of people. They also know what the FBI and other in intelligence sources know that are filed in court actions.
Because some of these things, again, might be sensitive not to be released to the public, but the judge needs to know about these things. So there's a lot of intelligence value in here. There's a lot of, again, if I want to compromise people, the coma is like compromising information.
And they will go ahead, collect this and use this to their benefit. They are gonna go ahead and see the extent of informers that are being able to, if we are prosecuting Russians anymore, they will go ahead and, for example, start to see what we know about them, what operations we have. It might not give classified information as to, for example, what are our exact operations.
But knowing that I know something could potentially indicate my intelligence sources as well, even if it's not directly mentioned there. So this system is kind of critical. And to the extent something's gonna be done, you're not gonna see Russia stare them down.
I think there was like some news stories how we stood down, you know, things inside CISA and other organizations that were targeting Russia for a period of time. I don't know if they were stood back up. And these are concerns that we need to have because we can't just play defense all the time.
We have to go ahead and ensure that they know we're playing offense as well. Well said Ira. I, well, well said.
Look, a couple of comments, thoughts on this. Number one, yes, I think the NSA maybe preemptively short circuited some of Russia's cyber warfare plans when, when the Russia, Ukraine war first flared up, conflict war, whatever you wanna call it. Um, however, we're not on the front lines here in the us.
We don't know everything that's going on behind the scenes on the cyber level between Russia and the Ukraine. The good news is the Ukraine has proven themselves not to be the republic, the former Republic of Georgia, right? That was basically crippled be before, uh, you know, when Russia took, took out, took down their, their cyber or took down their computer assets.
I think Ukraine might even be giving as good as it gets behind the scenes. And I, and I think there's absolutely a, a, a facet of this conflict that is being fought in the cyber realm. We probably won't hear a lot more about it until years from now when this thing's over and people begin to talk a little bit more.
But I think that, you know, tussle goes on every day. Of course, it may not be as bad as the thousands of people who are dying, you know, in with real bullets and, and so forth and bombs and missiles and drones and everything else going on there. Um, I wish I could tell you I had high hopes for Donald Trump meeting with, uh, Putin in some military base in Alaska, but I don't, I I, well, Alan, just to be clear, it's sort of like there were quotes from Trump in one of the articles referenced where it's like, well, Russia does that, and as opposed to confronting him, it's like, well, maybe I'll talk to them about it.
Maybe I won't. Right? It's not, It's not, it's not, it is his priorities.
Well, here's the part of it that actually matters. See, the thing is we likely spy on them. I'm hoping we still spy on them.
They spy on us. China spies on us. We spy on China.
Everybody spies on everybody else. But what you don't do, like I have, you know, from my intelligence background, I have good friends who are in the CIA and we would joke around and my CIA operative friends would say, you know, there are things we're not supposed to do. But really at the end of the day, the one thing we're really not supposed to do is get caught.
Yeah. Now, in this case, Russia has been caught. And what happens is you pay a price for being caught.
And why do you pay a price for being caught? For one, you don't wanna look weak because that's issue number one. You don't want to go ahead and say, well, if you hack us, oh, well you just do that.
I'll take it. You know, that's number one. You go ahead and you start and there is a form of punishment that goes, not necessarily for doing it, but for being caught doing it.
And that's kind of where we are. I mean, to a certain extent, because if you act like it's okay, there are not gonna be punishments for it. It means that they're gonna become more egregious, which, and China is highly egregious.
Like I have friends. And just to give you an idea of what goes on behind the scenes there, like somebody from cell phone companies, you know, my friends called me up and they were saying how China took a handset and basically re took the exact handset and put it in one of their factories to build themselves for a Chinese company. And they went to China and said, oh, look at what these guys, you know, you're doing this, don't do that.
They're like, no, it's a completely different phone. And the US company was like going, oh no, look, we could take the back off of your handset and put it on our handset fits perfectly. No it doesn't.
Look, it's completely different. China continues to do this because it is in their best interest. I, let's admit it is in their best interest, but they do it because there are no repercussions.
There should be repercussions for doing this. So you think twice and don't escal and Russia doesn't escalate their attacks in many ways. Like China has continued to do to US companies.
Well, China ira, today with China, it's the phone, but yesterday it was the F 35 stealth fighter plants, okay? Or the F 22, I don't remember which one it is. But China clearly steals ip.
And you've gotta, you've gotta have, you've gotta be firm. But what we need to be firm with everyone who, who infringes on our sovereignty, whether it be our court systems, computer system, whether it be the IP of our companies. And it's one thing to talk a big game, but you know, as Teddy Roosevelt said, you gotta carry the big stick too.
And, and that's what's missing. I'm A, I'm, I'm a little concerned about the meeting today because it could go anywhere from, you know, this is a, a piece in our time moment to a nothing burger. But given the people who are involved, they could also spiral outta control the other way.
And suddenly this is a much more intense issue for the United States because tempers are flaring. And is anybody besides me concerned that this is gonna lead to a wave of you? You're talking about taco here, man, president taco.
So I would just offer a couple the, The fact, oh, sorry, go ahead Fred. No, that's okay, John. So I would just offer a couple things.
Uh, the speak softly carry a big stick. I don't think, uh, could be any more true today, right? We have a unified vision and purpose, uh, from the DOD down through Cybercom across all of the elements of our military organization and our relationships therein don't expect, just because we're not talking about it, there aren't plans to think do operate.
We don't need to give those away. We're not gonna empower somebody with the knowledge and understanding of what it is that really bothers us, whether or not we really know about it, and whether or not we're gonna act on that. That's giving them power away here.
And the other thing is, is that, um, when we talk about what happens from a a, an offensive cyber campaign perspective from the United States, it's a military method that's, it's not a civilian problem. It's not a, somebody stole our phone, right? We need to have a financial repercussions as, as a result of this.
This, it's an act of war. And so in those cases, right, only the DOD decrees that right nakasone's famous for doing the right thing at the right time because he took those gloves off and did those things. And, uh, the folks that are, are sitting in those seats today will all do those same things with more unity of purpose than previously.
So I think I would not necessarily worry about whether or not we have the wherewithal, the timing, the skill, the, the unity and purpose, and also the ability to execute. I, I think that's probably more true today than it's been. Um, but it's also that there's a whole lot of political shenanigans going on right now.
Of course, there's a reason to talk about this today. Of course, there's a reason to publish this, you know, as a function yesterday. And of course there's a reason to, you know, try to undermine one of the fundamental institutions of the rule of law.
So it all makes perfect sense, right? It's all timing based. And you know, I a hundred percent agree with ira.
It's, uh, this is an intelligence operation here. And, uh, there, there's a whole bunch of other things that we already know that whether or not we're acting on is a different story. And maybe the outcomes of today tell us whether or not we're going to do something more, uh, more intentional.
Fair enough. Guys, we're, we're outta time on this one. So I'm gonna, I'm gonna pull it, the plug on it.
But stay tuned next week, we'll see what happens. And the continuing saga of the Russians are coming. The Russians are coming.
You're watching Textron Gang. Let's come back and we're gonna talk a little bit about AI code concerns and security. Imagine that we'll be right back.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're talking about a new report from Sonar, which shows that while AI coding tools are creating functional code, there seems to be two issues. One is, um, there's vulnerabilities that seem to get more severe, the more complex the application becomes, and the coding tools themselves seem to be, shall we say, verbose in creating large amounts of code.
And that creates technical debt and some of that technical debt creates more security issues. But Fred, as you look at this report, um, what's your reaction to this? 'cause is this the beginning of some sort of building crisis or will this all get resolved by some sort of other AI agent that will show up to solve all these issues?
Mike, you let the count outta the bag already. Uh, the, the, the challenge here is now we've allowed, uh, the models that have the capability to write code, to write a lot of code, uh, prolific use, whether it's, you know, using quad code or it's cursor agno. Pick your choice of what's helping you write, uh, agents or writing code or co-piloting you through, you know, to the end goal of accomplishing whatever it's, you're trying to write.
The thing that's interesting about this, and none of this should be a shock, right? But, oh my gosh, models have personalities. Some models write better code than others, okay?
Some developers write better code than others. And when we think about the construct, um, we would also say, what is quality code? So when we pass stuff through static or dynamic analysis, source code, composition analysis, we have a whole bunch of metrics that today we measure code by.
We might have to think about another way to measure some of the elements, but in today's universe, we talk a lot about code smell. Code smell is like, is this, you know, was this written by a 12-year-old, right? Or was this written by somebody that writes efficient productizable and production code and something that is maintainable sustainable over time?
It doesn't introduce technical debt every time we write code. Well, those are right, the obvious choices for the pinnacle of this. And you get a rating, you know, A, B, C, D, E, F right on, on code smelling.
But fundamentally what we think about is the same trade-offs we have for writing code. As an engineer, I need to write code fast. We call that velocity, right?
I've gotta write a lot of code, I gotta write it fast. I velocity is, you know, I'm gonna over index here 'cause I gotta get something out. Or we have quality, right?
Which attacks both the vulnerability surface here and also the coat smelling surface here. And turns out there's a trade off. There's always been a trade off.
But what we understand is, at least to characterize it, is that we could see that the number and percentage of vulnerabilities that are associated with various models are an early indicator as to which types of models might be better for writing code. And you know, from the comparison here, you know, we would say that, you know, GBT five oh has just released out, uh, a little bit Wawa for some folks that have, that have been trying to use to do the same things as four O. But we would also say that the number of vulnerabilities associated with that is probably, you know, lower than say llama, which is a little bit behind the, the power curve here with 3 2 90 B.
A lot of folks are using the COD models and, and frankly they're probably sitting in the best, you know, position A 3 7 4 oh, uh, sonet, four oh opus, um, for quality of code. But then what we also know about engineering is when I say, Hey, look, I need higher quality code or I need it faster, you're gonna make some trades. And what we've seen is you can make some efficiency trades, but guess what?
You're probably gonna introduce bugs and vulnerabilities and some of those illustrations, you know, with three seven sonnet bumps those up to, you know, a higher percentage. So what's the overall takeaway? It turns out you need to test your code out.
And so none of that's changed, right? And we already have a lot of the instrumentation to do it. So, you know, my perspective is, yeah, hey look, you know, meet the new boss, same as the old boss.
And the quality output is something we still have to govern. You still need to do static and dynamic testing. You still need to make sure you run multiple environments to test and validate what you're doing with your code when you deploy it.
And you probably need to understand your code the same as you did if you wrote it with your own fingers or you let somebody auto complete it for you. And, uh, and make sure that you're doing the same sort of checklist as you go through it. But, you know, we haven't eliminated vulnerabilities from writing code since the inception of time.
I'm not sure why we would expect right now in this case to be that we're gonna do that. So we're at the early part of that bubble. But I think, right, Mike, back to your point, yeah, absolutely, we're gonna have a whole fleet of agents that are going to go through and meticulously scrub code, but we're just not there yet.
Bravo, Fred. I I, I agree with everything you said there, man. Thank you.
Well, could I make a comment because Sure. Fundamentally what bothers me, and this is a pet peeve that I've had throughout the, in, not just in coding, but in every aspect of business, good security process should be part of good code. That, and the problem is, a lot of these people, they just want the code cheap.
They don't care. And people, the customers of these systems are not considering security as a, as a requirement of the software. And this is where problems happen because you look at this and say, AI is doing this, and it's sort of like, I hate the use ai.
If you don't, if you, I haven't said that enough, but the problem with AI using Dr. Evil quotes, which makes me feel better, is that it does exactly what you tell it to do. It's not super like brilliant or anything like that.
AI is not gonna say, well, you've given me a software requirement, so therefore I however think that it should be also secure. So I'm gonna add my own layers of programming to it. Basically what these systems are doing is giving you the code you asked for without regard to cybersecurity.
'cause that's not part of their format. And frankly, while maybe the more higher used systems are going to embed security concerns into it, producing higher quality code. 'cause one of the issues is that fundamentally a, all software has bugs that's a given.
Some bugs create elevated privileges, information leakage, et cetera. Those are what we call security vulnerabilities. So all software has bugs and all software will have security vulnerabilities.
The problem is that the security vulnerabilities are an output. And the more security vulnerabilities you have, in my opinion, the more bugs are gonna be produced by the software as well. And so when you're not even inputting in security requirements, you're also gonna get poorer quality software, which to, you know, Fred's point is gonna be the bigger problem.
'cause people want, you know, the old, you know, triangle, good, fast, cheap, you know, people want it good and you know, they want it fast and cheap, but they're gonna sacrifice quality. And to me, cybersecurity is just a part of the quality aspect to the software. And I think people need to step back and say, I want AI to write my software, but they need to also step back and say, I want good AI to write my software and I might have to pay for that.
Or I might have to go to vendors who are using tools that embed these concerns there. 'cause I promise you somebody using a cheap code generation tool is not all of a sudden gonna say, well, I have this other set of tools here that help me with my security concerns. You know, they're, they're gonna say, Hey, that adds cost.
I just want cheap and fast. Did that. So it sounds to me like you don't agree with meatloaf two outta three ain't bad, is is not good enough for you?
Well, it didn't leave a meatloaf, a very happy camper. You know, it almost looked like he was on suicide watch after that song. So that's a lot of companies I put them on suicide watch for, you Know, so, so I, I would add two things to this thing.
I think that we've been telling ourselves for years now that developers don't test because they don't have the time to test, and they're always under pressure. And I say nonsense, I don't think people wanna test and they just, RA's point, they just wanna go fast and cut and paste. And I guess even if there is AI agents out there, it doesn't mean that they're gonna go invoke the AI agents to run those tests.
So, um, we are gonna wind up with a massive amount of more insecure code just because people don't wanna be bothered. Tyra's point, this is not a good situation. So, you know, I, I look, IRA, Fred, me, we've all been in the security world for mm-hmm.
Than we wanna admit. This isn't an AI problem, guys. This is, this is, this is a coding problem.
It's been a coding problem, but I I have a little bit of a different solution. Yes, ai, vibe, coding, all this stuff is generating a lot of code. But I think AI could be a bigger friend, a bigger helper in testing an automated continuous testing.
And if we train it well to, to smell code as Fred says, right? And, and test it and correct it, I think it, it, it provides a better bang for the buck for humanity and, and for technology than just having AI do the code. And, you know, and I I, I'd like to see us put more chips on that front having AI and more automated testing because we could all benefit from more testing of our code.
Well, Alan, I, I completely agree with what you're saying, but I will give you the big, but you know, the, but is the most important because we have countless software companies. Palo Alto spent 600 million or whatever on dig, you know, all the, there's lots of money, lots of companies that are doing testing software quality. The problem is, people who are using these tools to write the code and write it cheap and fast are not the companies that want to go ahead and apply and also use a set of software tools.
The companies who are doing things right are gonna be the companies who are using exactly what you said, Alan, the tools that, you know, help secure things on the fly automatically. The problem is we have many, many more companies. It's like, I hate to phrase, you know, small businesses, the backbone of America, you know, at this point, the reality is, is that large businesses are gonna secure their code in ways you set.
A few small businesses might care, but the vast majority of code is not gonna make use of these security tools unless they're embedded in these other programs that are actually writing the code, because the people don't wanna spend the extra money on it. I also, yeah, one challenge, and I also, I also do not see open AI or anthropic or any of those people standing up saying, oh, and you should go use this other LLM and AI agent to go validate our crappy code that we generated using our tool, because it's basically saying, don't use our tool. So they're just gonna ignore this Until someone begins, Fred, go ahead.
One. Yeah. One, one sort of, I I wanna say guys, that's maybe the problem of now, but here's the future, right?
So for the last couple of years, there's been a thing called the AI cyber challenge at Defcon, okay? And this last, uh, exercise here, Georgia Tech walked away with an $8 million prize from the Pentagon to do what? Basically vulnerability patching.
Okay? So, and these, uh, models, right? For these systems have been open source.
That was the decree. So in these cases, the winner actually went and found, uh, O days, then patched those, and then did that in the most cost effective manner. Those have to be made available in open source.
So while we're saying these things, the simple fact of the matter is that's the future, and it is here. Is it promulgated throughout the entirety of the industry? Absolutely not.
Is there gonna be years of pain here? Probably. Sure.
But the folks that write the most code have the most urgency in adopting some of these things, and the frameworks are available, and they're continuing to go down this process of figuring out ways to not have to do this right at the, at the, at the keyboard for the person writing the code, but in the production space where those vulnerabilities will actually bite you in ways that you don't see today. So I would say there's hope, um, and that's something we should, we should, you know, add a little bit more of our, our feedback around our support for, and certainly directionally drive towards Keep the hope alive. I mean, I, I appreciate what you're saying for, but it's just like the average company using, because I, I, I actually have issues with freeware.
Not that it's not, not that it's not good, you know, open source I guess is the word, but a lot of people who need open source, like the cheap stuff don't have the people who have the skills to use it. That's why companies like, what was it? Tenable use Snort, I think to start, there was, um, no, Sourcefire was stored, Tenable was N sorry, source fire.
Um, so Sourcefire commercialized it to actually make it accessible to people. Because the problem with open source is yes, open source is great, but until it's properly maintained by somebody with a clue and commercialized, it doesn't have the impact in my opinion. Like Unix, Unix, you could get for free how many people use free BSD compared to the number of people who are using, well, this is a bad example, but you know, Mac, for example, Well, you, you don't write a firewall on a Mac, right?
You do use free SB or net BSD to do that. 'cause that's what it's built for. But, you know, I, I get your point.
I think the, the counterpoint would be that, you know, so I write code, my company writes code, but we're small, right? I, I absolutely want every possible automatable methodology to improve the quality of whatever we do. And I look at opportunities like this as a terrific, you know, stretch for folks that we work with, uh, for folks that we sort of look at detection ecosystems for and for organizations that do struggle with that, Iris.
So you're right. What, what I see will happen here isn't that the mom and pop organizations writing code or are going to grow up and adopt these things, but I do see a great opportunity for consultative, you know, support and help across the board here for, uh, adoption's sake. And I think there's truisms on what open source does.
But look, uh, if you look at Snort, if you look at bro, now, Zeke, if you look at some of the, you know, Pam, right? All of these things grew up out of, out of open source. And the reason why they're so used and so prolific and also battle tested is because they have so many users.
Yeah. So the benefit here is like, you know, to your point, it's the, it's the embarrassment of riches that, you know, an anthropic calves or somebody else has that we don't have that, that most, uh, common folks don't have. And so the only way that we can get an opportunity to get to some of those things is through some of these projects, because there, you know, we can get some of the benefit of the battle testing of that, and also the feedback loop.
So it, the question like everything, and you're a hundred percent right to question, you know, the open source versus free is what is the commitment to maintenance, to sustainability? These are the things, but, and To ease of use, because that ease, ease of, that's the biggest thing with raw open source. A lot of times it didn't have a youi, a gooey didn't have a ux, it didn't have, you know, uh, to make it user friendly, if you will.
I think that's what I was talking about. But I, I think that's changed though too. You know, I, I think with the, the Linux foundations and the CCFs and eclipses and stuff, they are making open source have a, a, a friendly face on open source.
But, you know, we're outta time. I I, I'd love to talk about this more on a future one. I think the real problem is a lot of the people who are gonna start generating code now using ai, vibe coding, all this, don't have the, the background to know about testing, to know about how CICD works to know about these kinds of things.
They're just, they're just throwing stuff on the wall. Anyway, let's take a break though 'cause we, we don't have more time to talk about that. We're gonna come back and talk about brain hacking.
I don't ask me. We're watching. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey folks, we're back.
And they say truth is stranger than fiction, but apparently the folks at OpenAI and Sam Altman are backing a startup that wants to create a human to machine interface called a brain chip. I guess, John, this is your story. Is this for real?
It is for real. Although we've been hearing about this for quite some time, and Sam Altman has been making promises and giving us timelines that he's been missing consi consistently. So we'll have to wonder, wonder about the timing, when this is actually gonna become a reality.
But as you said, he and, um, the, uh, Alex Nia of world, an eyeball scanning digital ID company that's backed by OpenAI, something we written about, they are going to start this company, which would be funded by open AI's venture team among others called Merge Labs. And you're right, they're looking at using AI for brain, a brain computer interface, something that would compete with Neuralink. That's another layer to this story.
It's a continuation of the antagonisms between Altman and Musk, Elon Musk who runs Neuralink. So the idea, and this is something that dates back to 2017, goes back to something when Altman referred to as the merge, which describes the moment when human brains and computers work together or come together. He wrote about this in a recent blog about this high bandwidth brain computer interface, which could soon be developed.
There's been talk about this concept for decades, but, um, the idea is that advances in AI and implant technology are now letting some researchers collect and process higher signal levels from the brain. And there have been two examples tied to Neuralink that have been somewhat successful. Uh, it's it's, it's a longer term thing.
Uh, it's, it just to, to be, to put in perspective, uh, Altman is not gonna be involved in day-to-day role in the operation. It sounds like he's in a sense, kind of, uh, paralleling with Musk does. He's gonna have this constellation of companies where he will jump in and out of, uh, it's a, it's an interesting concept, but I I wouldn't expect in any type of product or services in the next couple years, All you're gonna volunteer for this.
I mean, what could go wrong? No, I just see so many nightmares. 'cause let me, let me just say, I wish they would.
Well, I guess somebody has to think forward, but if they could, and, and here's the thing, I think this could be immediately useful, but I don't think it's gonna be practical, because let me tell you where it's useful. People who can't see, people, who can't hear people missing a limb to control a, a, you know, an or, you know, the bionic man, you know, that type of stuff is so much in its infancy. And I see them going for like this brain connector.
Like, 'cause I wish they could get basic motor functions right before I start to conceive of something. Like, I don't know if anybody else saw Murderbot, for example, but you No, I I missed that one. Darn.
No, it's actually, its, so I saw that one. Good. It, it's so stupid.
But honestly, it was among it, it was the cream of the crap for me to watch. I don't know a better way to describe it, you know, because there's so little that's actually worth watching. But, you know, they had a guy that you plugged in and all of a sudden you could download data to his head, frankly, to get that where you have to go ahead, tie into memories and everything, which is kind of what everybody gets the implication of.
That's hard. People don't understand memories to begin with, you know, that's number one. But I wish these people, as opposed to saying, you know, they're gonna supercharge the brain.
I wish they could first beta test this, where it's critical, where helping people see, helping people here, helping people walk who've lost, you know, limb Well, or communicate. I mean, look, uh, a yeah, you know, a thing near and and dear me is a s it's You, you're right. Um, IRA, that that's, that's the point that it always comes back to.
And it's not just this company or this startup, it's just this, this kind of, these blinders, it Silicon Valley always has where they jump ahead of themselves, they get ahead of themselves, they think about what this could possibly do in five to 10 years, rather than kind of just go to basic blocking and tackling and figuring out more practical things. Just being pragmatic. And I think this is kind of this, that that feeling is kind of fallen into this company, I think, and among others.
But I, you're, you're right. It's, this is like a kind of an ongoing issue that, because What Iris was talking about isn't sexy, what IRA's talking about is practical, right? It's not right.
Well, I, I would go an extra layer because frankly, it's not sexy. It is practical, but it's not mass producible, you know, thankfully on this planet, we do have some people who, who need this. There's not the mass produced number of people who need this.
They want to have augmented brains, which again, theoretically, I, I, I mean, I, I, I'm, I'm, I'm hesitant to say I agree with having an augmented brain, but I first wanna see a few good proof of concepts that they could augment. Things that need to be augmented, you know, that just prove that you can attach an eye nerve to the brain as an example, which should be there. Or, or attach a herring, herring nerves to the brain, as an example.
And if you can't attach the herring thing, you're gonna start messing with my memory, my consciousness. What makes me, me, I have serious hesitation and I want Sam Altman to be patient z, patient zero. What gives me, yeah, what gives me pause is the, um, involvement of Altman or somebody like a Musk and, and something like this, this whole concept.
I don't those be blunt. I don't trust these guys. I, I don't, I don't, I don't trust elements.
What open ai, it, I sure as hell don't want them tapping into my brain. I wrote about this with the big, all these trillions of dollars for AI data centers and stuff. When you're these guys and, and you know, they're human.
They didn't get to where they are without having oversized beyond oversized egos. And for them, you know, you, it's not really a question of how much more money, because they're gonna make money. They're making millions of dollars every second.
These people, it's immortality that drives them. It's immortality that drives them. And this is another way.
At the end of the day, they all want to be Robert Downey Jr. I'm Iron Man, and they all want to, they wanna play God too brutality and that God-like ability. I'm super, They wanna human, And I live forever.
I'm, I'm, I'm, I'm typing in the chat, GPT now asking it to create a screenplay for a sci-fi horror show that involves a publisher of technology publications based in Florida who's now hooked up to a computer brain. And it's gonna be called Shimmy Bot, right? Shimmy.
Shimmy. That's the sequel. That's the sequel.
IH mean, I will watch it. Yeah. But let me ask you this question, and, and in many ways, I 100% agree with you, John, at the end of the day, do I care if somebody wants to play God short of like, the plot of, uh, what was it, the Thunderbolts or something like that, where somebody can actually transform into a God or whatever, you know, the reality is, at some level, we need people like this to help.
Yes, yes. Lead the charge. You know, we wouldn't have like visionaries, you know, Steve Jobs, I'm sitting here on my Mac looking at my iPhone for, I don't have an Apple watch, but you know, there's some, the, the share arrogance and the vision has a benefit that has benefited lots of people.
Yeah, I, I totally agree. I totally agree. Agree.
I just don't, I just don't agree that, that some of the people who are, who, who, who aspire to this, like Jeff Bezo, oh no, Zuckerberg, these guys scare me. I mean, I think about previous generations of leaders, even I'll, I'll throw out gates or, or jobs, or even Allison back in his heyday. I, I have a little bit more faith in those folks or, uh, people that we, we we're not familiar with, who aren't as famous, who did incredible work.
I'm just afraid of these as, as a, as Alan has written this, this group of individuals who have so much power and are wielding it in ways that truly terrify me at times. I, I think there are two problems here. Uh, we probably should disambiguate them.
The first one is an oligarchy of power. That's a thing, okay? But we also need to be really aware of advancing neuroscience, right?
And to IRA's point where he was just headed is this, people have been brain hacking for a while, quadriplegics that, I mean, there's trials of this already where quadriplegic have been able to move, uh, with thought alone based on some of the advancements in restoring mobility that exists today. Is it prolific? No.
Could this possibly democratize that? Maybe things like facilitating commun communication for people that have a OS or had a stroke or, you know, something like this. It can't be verbal anymore.
Now maybe verbal and have the ability there. It's not just whether or not you're sort of like cognitive enhancement driven here, uh, or the ability to put your soul into a chip. It's like there is so, uh, massive a number, uh, and cost for what it looks like to do all of these treating neurological disorders and so on and so forth, that we really could do a lot of good in society as a result of it.
Now, just like, uh, you, you know, you, you, you gotta put some regulations around this, like hacking an infusion pump. Uh, Billy Rios proved that, Hey, look, software is software, right? Regardless on a medical device or otherwise, you have to do the homework and make sure people can't be hacking other people's chips in this particular case.
But the possibilities here are amazing to think about the, the benefits and things like That. No doubt, no doubt, pub and, And sometimes look the, to your point, John and Ira and Fred, so all three of you are right, but sometimes you've gotta, you gotta really, you know, when I was in junior high school, I had an assistant principal, Mrs. Smith, I'll never forget this woman.
She had a profound impact on me. She used to say, aim for the stars. Aim for the stars.
If you just get to the planets, you did what no one has ever done before. And so, th that's what this is. Sometimes you gotta have that amazing vision that may be unachievable, but a failure means you only got halfway there and you only, as I said, didn't get to the stars.
You got to the planets, you did what no one's done, and you've moved the ball and you did something truly remarkable. Well, A yeah, sorry, Alan, with all due respect to assistant principal Casey Caseon there, um, It was Mrs. Smith like that.
Yeah. But, but anyway, the point here is there's a difference between I am going to shoot a rocket to Alpha cent Tori, and if I only land on Jupiter, I did really well compared to messing with people's brains. And I appreciate I Yeah, but no, I look, no one's gonna roll out s**t that I would hope.
Well, with this administration, you don't know. I don't, no one's gonna roll out stuff that hasn't been fully tested and is safe and, and all of that stuff, I would hope, right? Let, Let's, the other thing is people are doing In this administration, uh, people RK Junior, I got, I got one bet on this whole thing.
Somebody somewhere right now is building a B, CI firewall. So there you go. Yeah, yeah.
People are doing this today. Like, let's not get it twisted. This is not like a new concept.
It's been going on, whether neur leak or otherwise, people have been hacking to improve some of these components. I mean, take a tour through the bio hacking village of Defcon. This has been going on for a decade at least.
And trying to understand the implications and the signals is just as much a part of why does it make sense to do something like this? But people are struggling and they don't have answers. And I think, you know, so, uh, it's odd for me to take the, the, you know, the, the light of hope part of this perspective, but, uh, normally it's more stoic.
But I, I think in this particular case, you know, this is a huge advancement opportunity. You fed by, fed by hubris, fine, who cares? Everybody's got it.
Like Shimmy said, if you don't, uh, reach for the stars, you're not gonna hit the moon. It's fine. Well, Yeah.
You know the point, I'm sorry, Fred. You know, the, it's interesting. So one of the many criticisms, valid criticisms of Silicon Valley is that it doesn't reach for the stars.
It doesn't have a Hoover Dam project doesn't go for a moonshot. That's been the criticism for the last 10 or 15 years. So for that, at least for that reason, I will give these guys credit for trying to do something above and beyond for the moonshot.
A latest dap that helps you park and get your car washed while you're at the theater. Yeah. Just earlier this week though, at one point out, somebody said to me, you know, it's 2025 and if, and the moon is something like more than 3000 kilometers wide.
So if you can't hit it, you kind of suck. Sure enough, we're gonna leave it on that. Guys, we gotta pull it.
We're outta time. IRA's got meetings to do. Fred's got where he is.
Got a company to run, and we've got stuff to do with Techron. Have a great weekend. Watch the rest of Techron TV today.
We'll see you all. Monday is Alan Hummel. We're out.