Smart Devices, Grok’s Missteps, and C-Level Security Wake-Up Calls | TSG Ep. 878
Alan, Mike, Jon, Camberley Bates, and Ira Winkler explore how smartphones are evolving into AI-powered digital companions—reshaping how we interact with tech daily.
They also dive into the growing concern over trust in AI outputs, especially following missteps like the Grok AI model under Elon Musk’s leadership.
Finally, the team discusses how software supply chain security is no longer just a technical issue—it’s now a full-on C-suite priority.
Transcript
Hey, is that a phone in your pocket or is your AI glad to see me? You're watching Textron Gang. Hey everyone, it's Alan Shimel.
Happy Friday. It's Friday. Can you believe it's Friday this week?
I blinked. It was Monday. Um, we've got a lot to talk about, including that little phone in your, or maybe it's a big phone in your pocket.
Maybe it's a folding phone in your pocket, but there's a phone in your pocket and it could be your gateway to AI going forward. We're gonna talk about that. We've got more, we've got a great gang to talk about it with.
Um, some of our best characters on the gang joining us is Kimberly Bates. Kimberly, it's great to see you. Great to see you too.
How are the Yankees doing? Um, well I, they won, I think they won their last two games against Seattle, but it's almost Allstar break. We'll, we'll take, we could, we're limping into the break.
Um, IRA Weaker is here, of course, our security person extraordinaire, who's never short of an opinion. Nah, glad to be here. Yep.
Always happy to give that opinion. And, uh, also joining us out in Silicon Valley, I'm man in, in the, in the valley, John Schwartz, as well as the Dean Mike Ard. Guys, lady, welcome.
Let's jump into it. Mike Samsung announced the next version of their foldable foldable. I guess, is it still a Galaxy or is it something else now?
Yeah, was it a razor called House these days? Um, that's a full seven Fold. Seven of course rolls right off the tongue.
But more importantly about than the folding is the ai. What, what, what, what do we got here? Yeah, so Samsung was in Brooklyn this week where all the cool kids are hanging out in New York and had a big event.
And, uh, you know, I appreciate what everybody's doing there, but it was basically a two hour plus commercial. And so that was kind of like, you know, a lot like an Apple event. And I'm hoping somebody might actually change that format one of these days soon, because I swear there was more video showing than people actually talking.
But one of the things that was interesting was they were positioning this new phone and all the other phones going forward as your AI companion. And for example, they were talking about how you might be walking down on a subway somewhere and there's an ad for a concert and you'll take a picture of set concert and then it will automatically drop that into your calendar. And then not their agent, but some other agent might therefore then go out and buy those tickets for you.
And that whole process just becomes something that starts with a click of a photo on your phone. I think, I think we're a ways away from making that kinda everybody's everyday experience. 'cause you gotta upgrade your phones in the first place.
But Alan, it does seem to mean that our relationship with our phones is about to change. Yeah, no, I don't think we're as a ways away as you think we are. I, I think it's really right around the corner.
Um, couple things here. First of all, I, I don't want to discount the idea of this foldable phone, right? Because I, I think it's attractive.
Let me just say, uh, from the outset, I'm a, I'm an iPhone user and Apple guy, so I'm not going to use this phone. But I like the idea of the foldable phone. And if you look at the screen specs, it really is a beautiful screen.
I mean, it's a nice screen with great technology behind it, and maybe we're gonna need a bigger screen to, to communicate or interact with our AI agents and alter egos who are out there doing things for us. Beyond the foldable aspect of it though, look, I think Samsung, again, is leading with innovation in, in a hot new area, right? Because quite frankly, what's the difference between iPhone sixteen, fifteen, fourteen, thirteen, twelve?
It's incremental. There's not really nothing. And, and you know, a lot of innovation does seem to happen on the Android side of the, of the house and with Samsung.
And I think their use of AI here again, positions them as more of a leading edge. You look at the ho-hum apple intelligence about, you know, it was all about what, what's on the comm? Samsung's showing you some real functionality here.
You know, it may not all be available, but it's real functionality. The bigger issue though, is look, eventually the iPhone catches up and they, you know, they're within a release of each other and they have very similar, uh, features. What this means is that all of our phones are gonna be our AI gateways, right?
Think of them as our digital agents, our digital workers, and Salesforce calls them, right? Our digital workers out there doing these kinds of tasks for us. And not just tasks, but really kind of thinking for us as well.
And I mean more, you know, just taking it to the next level. Now, I think the issue though is where, you know, where we could see a potential roadblock is how much computing power, how much AI computing power can we put on these phones? If you look at the specs on this fold seven, right?
It it's on, i I believe it's on a Qualcomm Snapdragon eight or something Chip, isn't it? Or it's chip set, but there's GPU, there's CPUs, there's, what was it, 12? Was it 12 gigabits of Yeah.
You know, was an NPU in there too. And an NPU. I mean, this is all great.
Is that gonna be enough to run the AI in our pocket, or is it still gonna have to No pun phone home to, to get AI done, Kimberly? So I'm not sure. Yeah, I was gonna say yours, I'm not sure, saw the announcement this week.
I think it might've been even yesterday. Open AI is buying Joni Ibes hardware startup. Joni is the designer of the i the architect.
Nobody knows what they're actually doing. Um, it's well kept under wraps. There's a lot of speculation about whether or not this is eyeglasses or something along those lines.
But, and then, then Wall Street's saying, okay, so this could drive o open AI to a trillion dollar valuation, you know, blah, blah, blah. I think the, the statement here, a you're, you're right. The, the, the consideration is this gonna talk to the cloud?
It has to, in my opinion. We'll see if they can do it differently. But the other piece of that is where is this going?
You know, strategically, how is, how are these folks envisioning us using the devices? I mean, when Tesla says, or, or, or, um, Musk comes out and says, grok is now going to be in Tesla here within the next week. Okay, that changes.
So I think all of this, these pieces of that we look as devices and look at how we interact with things. Um, this AI is not just the phone, it's the car. It's a lot of other things that we're gonna be having, seeing where this AI plays out in.
Yeah. Could I just say, oh yeah, I was just gonna say this all frankly, I'm sitting here like, everybody's saying this is revolutionary. This isn't revolutionary.
This is just evolutionary. When you look at it, I mean, a foldable phone, oh my God, does anybody remember the Motorola razors? I mean, I'm like, you know, that's innovation.
We're going back, you know, it's Like, yeah, no, no, but to be fair, But I'm, I'm like, That was a flip phone Ira. These are not flip phones. This is A, I know these Are, this is One big screen.
These are like screen technology. Yeah. And I appreciate that.
I hated moving to like a God, I'm a Blackberry and then onto an apple because they didn't fold and put in my pocket. Well, but with the AI though, it's really just an evolution because you stop and think like, you know, all of a sudden everything's just evolved as the technology is. And, and when you start to think how seamless can things be, it will be, in my opinion, and it has become more and more, like, for example, QR codes on, you know, on advertisements, allow my phone to pick something up, pull up directions, do whatever else.
Now we're talking about taking a picture, interpreting that, have an agentic AI kind of go out there. You know, I'm more concerned, frankly, a little bit about the security and privacy. Again, because you look at this and yes, it no matter what, whether or not it goes out to the cloud to process, because when you put something in your phone, it has to do a query.
Now with regard to how fast the chip is, the chip doesn't have all the data set. The chip will just have to process and do basic things, but then still have to go out and pull things. And frankly, if I have your cell phone today, I can pretty much put your life together.
I don't know when, how many people remember, for example, Google Friends, where it's like, okay, broadcast your location to all your friends. I'm like, what part of this seems like a good idea from a privacy perspective. Now we're talking about, like you're saying here's, you know, let me take a picture and, you know, everything seems wonderful, honestly, that I'm gonna have an AI assistant, like for example, I want to know if it's gonna rain.
And I just say, sir Siri, is it gonna rain? And all of a sudden I get like a weather report saying, okay, where am I? What's the weather for today?
Now if I go ahead and say, Siri, I'm hungry, put out my basic, I don't know, Chick-fil-A order, it has to go ahead, process this, understand it, and then interact with Chick-fil-A and make an order for me. And it knows what are my preferences, what everything is out there about. When you put a query out, it's telling you what you think.
There's a difference between a tracking mechanism and people knowing what your Google searches are. People knowing where your maps are going, people knowing what you're ordering from stores all brought in together. And I'll just leave it there.
'cause I think it speaks For itself. You, I wanna part that there's two separate parts of this. One is the horsepower needed to do these, whether they're revolutionary or evolutionary to, to perform this AI pars, you know, and, and they're not just pars to perform this ai, there's a certain amount of horsepower needed and phoning it out to the cloud or wherever is going to introduce latency as well as security issues, right?
It's probably more secure if I kept it on my phone versus sending it out for now. And when you think about it, these little pocket rockets that are in our pockets, right? There's more computing power on the one you have in your pocket today than there was on the Apollo 11.
I think it was 11 that landed on the moon, right? We have more computing power in our pocket than Neil Armstrong had landing on the moon. But that's not enough for this next generation.
And, you know, technology, we used to have Moore's law. You always said, ah, don't worry, you know, we're gonna double computing capacity in 18 months. Well, we haven't been hitting those numbers in Moore's Law, but certainly here on mobile devices, we're seeing a revolutionary change, or not a revolutionary change, but an exponential increase in computing power on board.
I read to your point though, yeah, I read an article just this morning on this, that the fact of the matter is the large hyperscalers, the large collectors of information, the Googles, the Apples, the Metas X, Twitter, whatever you want to call it, they continually are adding to their treasure trove of information they have about each one of us, our habits, our likes, our dislikes, our travels and everything else. And until, I don't know if it's a countrywide thing, a personal thing, but until people say, I'm fed up, God damnit, and I don't, I won't take it anymore. It's not gonna change.
You Know, there, there's interesting premise in Mike's story, which is in our, in ai, the tech strong ai, and it's these, these two major providers, smartphones and tablets are basically locked in this AI arms race. And that's gonna affect millions and millions of people, if not more. And it's interesting to me, we talk about evolution.
I think we sh also mentioned transitional because Apple in a sense, I think, and what I've been hearing through the company and people who've left the company is that it, they're in a sense, kind of in a transition from the iPhone era to the AI device era. I'm not saying the iPhone's gonna go away, but there might be a new device that, but, But that's the whole to Kimberly's point, right? John, that's the whole thing behind the Johnny I smart.
Uh, That's where I'm going to next because that deal just closed. And the, from all indications are, they are open, AI is gonna have some sort of device within a year, maybe six months, which also will have an influence on Apple because Apple is looking at what, at a ways to build out their AI presence. And they're looking at companies like perplexity and in a sense, even teaming with a company or buying it outright to develop an a AI search engine that would twin with Siri.
There's like a series of things that are gonna happen and, and Meta's gonna do the same thing. So we've got all these, this kind of transition as, as we go back to 2007, right? Steve Jobs, we have the iPhone, which is now our computer in our pocket.
And now they're, we're probably in this era where we moved to an AI device, which is the next iteration of the, of a phone. Well, I just wanna, sorry, if I could just reiterate a critical point. When people talk about ai, and I hate the term 'cause it's too broad, it's too nebulous, but AI requires two things, and this is where I have to keep harping on it.
AI requires processing capability. It requires, well, actually three things. Algorithms processing capability and data algorithms have been around, we could tweak the algorithms or whatever, but they've been around for decades.
Processing power allows the algorithms to function more efficiently. However, the key thing is still the data, the data you need is not gonna be on your phone. The data you need is gonna be out in the ether, the internet, whatever networks develop.
And so while it's critical that we are talking, how much processing can be done on the cell phone itself, which means maybe it could be more efficient, you're still gonna have all the concerns about going out and seeking data. Because until you're at the point where you can put all the data of the internet and all the functionality on the phone as well, which will never happen, you're still gonna have to go out to the rest of the world. And we're talking, I mean, frankly, this is an engineering issue that was released that we have an AI phone.
No, you have chips that can process AI algorithms more effectively, but you are still gonna have to go out and get the data. And whether the queries are done on the phone itself or the queries are done, it still has to do the queries itself. It has to still search, bring all the data back it needs, and then do more things.
Anyway, I'll leave it there for that. I'll tell you what I am concerned about that goes beyond the IT and the security and all those other things is, you know, are we gonna live in a world soon where my AI agents are gonna call your AI agents and I may never actually interact with you or have a conversation with you and it's just gonna be kinda AI agents doing this back. We talking about, it's, it's Wally, the movie Wally, you'll be, I, you Know, Actually that is what's so important, I think of what's happening with the open AI acquisition is that, and IRI agree with you, there's three elements there.
The fourth element is our interface. And that what potentially is happening here is, um, we're having a rethinking of what those interfaces are going to be Like. Yeah, yeah.
The human, human computer inter interface. So, so what is that major interface? And that's going to be a race to what that is, and most likely is going to be some level of a, you know, small device that we can hold in our hands because we wanna carry it around and look at it.
But I think that's what, where these guys are going is gonna, well, There, there was that one company that had the pin, if you remember that didn't go over so good. No. Anyway, hey, we're over time.
We gotta stop on this. It's, look, we're not stopping, we're not, we're gonna be talking about this. I have a feeling for weeks, months, years.
But let's take a break here on tech strung gang. We're gonna come back and, you know, AI can't make up legal citations and courts can't rely on them or can they? You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
Group. Hey folks, we're back. And it's not just AI and law, it's AI in just about anything we've seen this week where the, uh, rock AI was spooning out all kinds of Mecca Hitler nonsense and lawyers are citing AI case or cases that never existed in the first place.
And it feels like maybe we're getting a little too dependent on AI already. But John, you've been covering this whole space, it seems like now every other day there's a new it. Yeah.
And so it's, I mean, in a sense it's like AI gone wild, right? It's, it's, it's uh, it's unpredictable. Um, and it's, it's embarrassing companies, as you mentioned, there was an incident at X, which the timing couldn't have been worse.
The CEO just quit. The CEO quit basically the day after an update to Rock was spreading anti-Semitic and pro Hitler messages. Uh, her timing couldn't have been worse.
Uh, so she left, uh, Musk threw his hands up and said, you know, this is the world we live in. That's just a nev never a dull moment. So ironically, Musk, the guy who warned us about what could happen with AI was a victim of it.
Um, we mentioned it, the Georgia Court of Appeals decision to toss out a, a ruling that relied on fake cases generated by ai. Uh, that's not the first time this has happened, but this is the first incident that I think has been where a court case, uh, ruling has been reversed. There have been incidents over the last couple of years where AI has been used to site cases that didn't exist or to mislead, um, a judge.
And the judges have been rebuking some of the attorneys and finding them. There was a case in New York, there are multiple cases. And then there was a federal judge in Colorado who rebuked, uh, the attorneys representing the MyPillow guy in a defamation suit when they discovered that, that, that his attorneys had used a generative AI program to submit a court filing filled with errors.
And I think, I wanna kind of kick it to Alan because, uh, I talked to a friend of mine who is a lawyer and, uh, she practices family law. And one of the things she mentioned was that law school 1 0 1 teaches us, is it Shepherd eyes? Shepherd she shepherd.
Well, shepherds is the book you shepherd eyes it as the verb of a shepherd verb, okay? But, you know, that went over to computers when I was in law school in 19 82, 81, we were already using the Lexus Nexus to shepherd die case law. Um, but look, you know, there's this, there's this term in law fruit of the poisonous tree, right?
All fruit of the poisonous tree are bad. And so if you have cases that are decided on poisonous, you know, on poison, everything coming out of it is, is no good. So of course the court had to overturn it.
I think the case in Colorado, John, they actually sanctioned the attorney and find them $2,500 or something for, for spouting off nonsense. But a couple things. Elon Musk isn't the victim here.
Elon Musk is the cause. Elon Musk decided that there were too much, there was too much woke and liberal input into his rock gr AI and removed all of that. So it went too far the other way and started spouting antisemitic Hitler stuff.
And he throws his hands up in the air and says, oh, another day in the internet. No, when you put your finger on the scale, bad s**t hap bad stuff happens. I'm sorry.
So let's not feel sorry for Elon. He's the cause Oh, no, No, no. I, I'm not at all.
I'm just saying, I find it ironic, this guy who's been pointing his finger and warning us about what could go wrong is in a sense per perpetuating this problem. Well, he, he brought it on himself. But that being said, here's the bigger issue guys.
You know, our friend Chris Blaque is railing on here every week about his partner, Lumina and Civic ai and putting ethical kind of guardrails around our ais. And I do believe it's going to happen, not because of government is mandating it or anything like that. I think just good functionality is we, we are our patients for AI hallucinations, for making up case law for, you know, spouting unacceptable type of, uh, stuff.
What we saw here with Gar, you know, the public and, and the market is gonna force people to put these ethical sort of guardrails around AI to, to hopefully get better about these things. Yeah. Alan, can I disagree with you?
I'm you, I, would I be insult? Well, lemme disagree with you because I think there are two parts to this. In one case, and let's remember how, I don't know how many people remember when Microsoft started their own little AI bot or whatever, it became a flaming Nazi within like a day and a half or something like that.
Now that had training data, because there's a big difference between the two things we're talking, the, the hallucinations and this issue because with, you know, the, the Microsoft thing, which we have to consider, they were training it from Twitter or wherever else where they were just listening constantly to Nazis, for lack of a better way of phrasing it. Now, the thing that concerns me and what we should really be taking away with it is we now have an AI where somebody put their finger on the scale. Because what happened was the reason it was tailored was if you go on rock, rock was actually surprisingly neutral.
And the problem is Elon's fanboy did not like the fact that it was sping facts. Yeah. And they're like, gee, what do you mean that, you know, does, you know, like vaccines don't cause autism, you know, and it's like, how could you say that?
And then all of a sudden they're scratching their head, gee, I have to keep these pe these lunatics happy. And they went ahead and whatever they did, there was an intentional tweak because rock was good. I didn't like some of the things, but it was factual.
When I check rock's facts. Now it went the other way. And that says there was a manual intervention.
And that, frankly, that happened because much to disagree with you, Alan, it wasn't like the public did not support, you know, or was not happy with it. No, the, the, the public was This was Elon unhappy, this was Elon. No, But Elon's fanboy on there were not happy with the fact it was giving what they consider too liberal results.
And they, so they went ahead and they tweaked it to give less liberal results instead of just pulling facts up. So I I, I have a theory on that though. Ira, look, AI hallucinations, if you want to call what happened with gr hallucination or AI spouting misinformation, false information, there's two reasons these kinds of things happen.
One is if the AI is trained in a cesspool, which the internet is in many places today, if you train it in a cesspool, don't be surprised if it's spout cesspool type of information. The second thing is if you intentionally poison it, right? And maybe that's what happened here in Grock, it was intentionally poisoned.
So it's where see where you get your training data is part of the problem. And that is like, hey, if I want to train it on truth social, which somebody might want to, you will get a set of data. If you want to train it on Google data, hopefully it'll be a little bit better.
But the reality though is that, again, I still wanna make the point that the hallucinations in the legal case, that is just people not understanding AI answering, you know, like these LLMs trying to answer a question and trying to give a good answer without having a factual answer, uh, compared to training data, which Has pulled it out. So I think there's, I think there's a big difference here between these two cases that we're talking about. One of them has a responsibility of the expert to do her research to make sure the data that she is presenting to the courts is accurate and to rely on an AI to spout cases when you go to, when you, if you sit at bar, you're sitting at the bar, you know, to, to just prove that you have the knowledge base to do this, and you're not getting an AI to assist you in your bar exam.
And I would expect that, I mean, if I was the, that, if that was my lawyer that ended up doing that and had that, that happen probably should fire them. And I think that there needs to be, from you looking at us as people that are using AI and how we use AI and individually, how we are trusting that information, we can't, when we pull that information, we have to trust but verify. Yeah.
You know, it's interesting, I'm, I'm glad you brought this back up, Kimberly, because there's, there's somebody who keeps a database of this issue and there have been I think 156 cases in which lawyers cited fake cases generated by ai. But then I, then I think about, you know, where this is going and at the same time, yeah, right. It's not surprised that the number is escalating me despite the Well no, but never underestimate how lazy lawyers are.
Let me just finish my thought though. Oh, that's what I was saying, Alan. No, look, I've been there, I've done that.
But here's the thing. I mean, we we're, we're talking about all these things, but there's a number that jumped out at me yesterday is $4 trillion if Nvidia just went over that in the market cap and Microsoft's next. So we're gonna see an escalation of AI gone wrong.
AI doing My own me. Well, I know, but I'll give you, so look, whenever you think of lawyers, I think of doctors maybe because I did a little of that kind of stuff. But, you know, we reported earlier this week, um, Microsoft released a new tool for diagnosing, for diagnostic medical diagnosing for x more accurate than human doctors.
That's great. But what's gonna happen when the, when the it misdiagnosis and someone dies as a result, it's a little different than the pillow guy citing bad cases and not, you know, I would, I would point out two things. One is it's frigging awesome that people found 167 instances where AI went wrong.
I mean, maybe there's thousands more, but maybe there's hope that we can actually find these things. And then b my biggest issue with all this AI stuff is all these things are designed to be behan and they keep coming up with answers instead of just saying, I don't know. It's okay to say, I Dunno.
Well, fair mean there's a, you gave, you gain more credibility when you say that, when you answer, I don't know. To a question. Well, well for a legal brief you can say, I don't know.
And I think one of the problems is, and let's face it with Mike Lindell, first off, it's a very public case and you also have a client who's broke. And if I was his attorneys, I would spend as little effort as possible, hopefully not violating the law. But to your, you know, to Kimberly's point, absolutely correct.
You expect the lawyers, I mean, frankly, at some point, I think somebody's gonna release their own legal LLM that goes through documents that fact checks their, all their LLMs. And they are doing That now. They are starting to do that Now.
You know, my, my son worked on that in his law reports Coming through. My son just graduated law school up in Boston, and at his school they have a legal technology lab and they're actually working on that very topic, um, as well as others. Yeah.
But it still comes down to the point where yes, any lawyer should have fact checked at the fact a judge ruled on it. He was, or she in this case, was relying upon the attorneys to submit factual documents instead of, now we need judges to submit, well Submit. But the judges look, the judges to Verify what they're saying.
The judges don't read these things. The judges look at the facts, they tell their clerk, this is how I want you the decision to go. And it's the clerk's job to go do that kinda work.
And, you know, these are kids who just graduated law school for the most part. Anyway, Hey, we gotta take a break. This's an interest.
Another interesting topic that I'm sure we'll be revisiting on the gang. Let's turn to security though. Let's talk about software supply chain.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hey folks, we're back and we're talking about software supply chain security, which has been a top of mind issue for a lot of folks these days. com where the question was put to C-level executives about whether or not they had any visibility into their software supply chain. And half of them said they didn't.
I, I looked at this whole thing and I kind of smiled and I went, wow, C-level executives actually know they have a software supply chain. So, um, you know, is this becoming a board level issue or you know, is this something, um, that's a moment in time because there's just too more noise in the system or what's going on here? So with regard to whether or not it's a board level issue, the answer is, uh, for over or board does oversight for oversight purposes.
The board should at least know to ask the question, what are we doing with supply chain related issues? Because supply chain attacks have become a major problem. Companies have been ruined because, for example, there was a bit wallet application where they uploaded malicious software into their core code base.
And I think what's happened is over time, and a lot of people, if you're not in the programming space, don't really realize, but PE code has not like code used to be written originally. Maybe there were a few library programs around to implement some basic functions. But lately what software is becoming, why you can start implementing generative AI to write software is because programmers have started not to write their own code, but to pull code segments together from lots of different places.
So that's number one. And a lot of people are not tracking well, where they're pulling these software packages from. And that's a serious problem.
And that's why you have supply chain because the code you pull from could be malicious, the code you pull from can have bugs and all this sort of stuff that you don't know until you know. Now the issue is once bugs are reported, you know, there's no understanding of where they came from or where your own software came from. And if you're impacted, this is why a soft SBO m software bill of materials has become a critical discussion in the cybersecurity space as well as in the coding space.
Because you need to understand where these packages are being pulled from to know whether or not you have potential issues. So for example, if you're a defense contractor and you're pulling code in from China, that's a problem in all likelihood, as an example. However, the other things are, the other part of it is you might know where you are pulling your code in from, but you don't know where your vendors are pulling their code in from.
And then, so you have first level problems of writing your own codes, second level problems of pulling in other code, you might purchase third level problems where you're pulling in code that other people have written. Then you have the, where are these people pulling their code in from? And in some cases, supply chain attacks have been down four or five levels of coding where smart criminals have gone in and figured out, wait a second, I know this program pulls in this library of code and that program pulls in that library of code and that program pulls in that library of code.
So I'm gonna embed something, a malicious piece of code five layers down that I know will eventually be pulled into the software of my target. And that's why these software bills and materials are critical. But it's also why it's so difficult because you, if you have LLA or generative AI pulling software together and it, it has to track and maybe it can track better than people, but this is a concern that it's a ma, you know, you use the term octopus, but it's a massive octopus with countless arms and arms of arms and arms that boards need to start putting some governance in place.
But it's a serious issue. And if you don't have a firm understanding, and even if you do have a firm understanding of where software is coming from, you're still likely not fully visible and this needs to be addressed, then I don't know if the study goes as far into the depth or it was a trivial marketing study, but it needs to be addressed. I'll say it that way.
I mean, you know, the, the gist of the survey was if you don't have visibility, you're much more likely to suffer a breach than if you do have visibility. I don't necessarily buy into that. I think there's visibility and visi and then there's visibility, right?
Well, I, yeah, I mean that's, well, I think at least if you're starting to look, you'll come up with a more obvious ones. But like I mentioned, when it's five layers deep, that's where you're gonna start having the problems. And you know, this is where, again, governance like, it, it, it's a pain to change how people program and force them to write their own originals code again.
But in some levels that's, I I, that's, and until it does, you're gonna have these issues and you need to have better cases. That's another, I have another solution. Look, we do, we live in a world of Franken code, right?
Apps today are built by stitching together components. All of these, almost all of these components are downloaded from different repos. There's your choke point before you download a component from a repo, the repo has to sort of bless it and say, as far as we know, this is the, the latest version of this component.
It's been verified, you know, vulnerability wise, it's not been tampered with. The check sum is right, blah, blah, blah. There is a very natural choke point at the repo, wanna call it a repo firewall maybe, where we can make sure that the components that the developers are using are safe.
And at the same time, that information goes right into your sbo. Well, well, let me actually say how that, how that did not work. Because there was a case, and again, the bit Waller case, I think I mentioned, where what happened was there was a common software utility, like, I think it was a compiler or something, and the guy who wrote this compiler that was used by millions decided, I give up.
I don't want do it anymore. So the person basically let his domain expire. Somebody else reregistered the domain, got the email that was sent to verify the person's identity.
They took the compiler software, embedded malicious software into it, recompiled it, it was then a legitimate piece of software from a supposedly trusted person, and it made it all the way up into commercial products. But that, but that, that piece was not in the repo that that's the issue, right? It was, we saw that.
I wonder, did it happen? Was it, was it open VPN Irie years ago? It turned out there were like two people that maintained o open VPN in the whole world.
And, and it, you know, it, it got a vulnerability and introduced into it. And the idea behind these repos is there's, I think there's more girth going. Anyway, hey, we've gotta end it today.
I'm sorry. It was a great discussion. I wish we had another hour, but we don't.
Kimberly, IRA, John, Mike, of course. Thanks for joining. Thank you for joining.
We hope you've enjoyed Textron Gang today. Stay tuned for Textron tv. We'll be back Monday with even more fun and more, more, more ai, more security, more DevOps, platform cloud and everything else.
Have a great weekend everyone. I'm Ellen Shimmel. We're out.