Techstrong Person of the Year, Apple’s AI Pivot, and Target’s Code Risk | TSG Ep. 998
Alan Shimel, Mike Vizard, Jon Swartz, Fred Wilmot, Gina Rosenthal, and Futurum Group analyst Guy Currier examine the merits of this year’s Techstrong Person of the Year award and what the selection says about leadership in the technology industry.
The discussion then turns to Apple’s decision to tap Google for AI support as it looks to improve Siri, a move that raises questions about platform strategy and competitive positioning. The episode closes with a look at the potential implications of a reported source code theft involving Target, highlighting ongoing cybersecurity and software risk concerns.
Transcript
2026 marks a turning point. Artificial intelligence is no longer just a tool. It's shaping industries, accelerating innovation, and redefining how humans build, create, and solve problems.
From engineering and medicine to finance infrastructure and everyday life, AI has become one of the most influential forces on the planet. That's why for 2026, we recognize AI as Techstrong's person of the year, not for what it replaces, but for what it enables. A future built together humans and machines predict.
2026. Join us. Hey everyone.
What are you doing watching this? com. You can register and get right in.
See what virtually the entire Futurum analyst team predicts for the 2026 year and what's in store. Don't miss it, but here's the good news. I know what you're saying.
Shimmy. I can't miss your show. I'm gonna watch the gang.
That's okay. The Predict 2026 videos will be available on demand there as well. So after the gang, then head over to Predict 2026.
You'll still catch most of the day. And anything you miss, you watch on demand, go figure. Welcome to Text on Gang.
Uh, here on, uh, Thursday, January 15th. Let me welcome our gang members. We've got Fred Wilmont, Gina Rosenthal for the first time since the new year.
Our Fred Guy Courier, and of course, our man in the Valley. John Swartz, our man in New York. Mike Ard.
I'm Alan Hummel, welcome to the Gang. Mike, let me kick things right off. Yes.
Today is Predict Day and Techstrong is, I mean, AI is Techstrong's person of the year. I know what you're thinking. Well, let's just dive into it because it is a somewhat controversial conversation in general.
Um, there, folks out there who would argue that treating AI like a person is a fundamental mistake. It's bad for your mental health. It plays into a narrative put out by a bunch of, uh, vendors of these tools that are trying to make them addictive to you.
And it has nothing to do with the actual, uh, output of these things. They're just a tool. So why are we kind of intriguing them?
Like people, I mean, I'm kind of in that camp. I'm all for ai, but for crying out loud, it's a machine. Fair enough.
com if people are really interested in diving a little deeper. But if you're gonna blame anyone on this, blame me. I I did it right?
And, uh, the reason I did it was for a couple of things. Number one, obviously I was playing on the time Man of the year or person of the Year. They, I, I don't know if time has changed it to person of the year, is they still call it Man of the Year.
Jeanie, you're shaking your head. They, they moved it to person. I'm pretty sure they moved it to person.
Yeah, Good. Long time coming. But keep in mind, I picked this theme way before time came out with their person of the year this year, which happens to be the architects of ai, right?
The seven or eight CEOs, leaders of the bigger AI companies. So it was, it was a, a a, a bit of a tongue in cheek on the time person of the year thing. But the other thing is, Mike, we may rail against it, and we may think we're smarter than the average bear, but the fact of the matter is, the population, by and large is evolving these relationships with ais that are very personal, very personable, right?
We, we've got, we've got a hundred and something lawsuits of people suing AI because they were using it as a therapist, or it, it helped, it encouraged teenagers to commit suicide. But unfortunately, the truth is a lot of people are carrying on relationships with AI almost as if it was a person. There are days I worry about my friend Chris Blak, you know, I love him dearly.
Somewhere I'm hearing my mother say, if everybody jumps off a clip, are you gonna jump to, Well, maybe, maybe, maybe that makes you a welling though. The other thing is, oh, sorry, go ahead. The other thing is, I kind of think back to the early, early days of the internet, right?
Like mm-hmm. The a OL days, like when it first started getting going, and remember the comic that said everyone on the internet, that is a dog who you're talking to on the other side, there were bots back then. You, they were easier to figure it out.
Yeah. You know, because of some, the simplicity of how they work. But, um, I, I think this is, I think it's very, very dangerous path to go down.
It was then, and it is now. It, it may very well be, but you know, this ain't your mother's a OL we're talking about, Right? Yeah.
Fine. No, I think, Uh, I think for Techstrong to choose AI as the person of the year is brilliance. I think if Time had chosen AI as the person of the year, that would've been horrible.
Or any other, let's say, mainstream, um, uh, me Media Outlet, because the tech strong audience and Techstrong is about it, especially business It where all over the place we are explaining everywhere. Um, and, uh, we expect our audience largely knows this is not a person. It's not even I, Mike would all due respect, calling in a machine I think is a mistake because what it is, is a simulation, and there is the rub that is the whole issue.
It is designed to seem like a person, while it has none of the other aspects of a person. And furthermore, that's really generative AI or LLMs more than AI as a whole. So by picking AI as person of the year, it, let's say it's a sarcastic choice.
And that's really helpful, um, to, uh, to say what it really, that it really is not a person at all, except possibly one day in the legal sense, much like corporations or people than legal or persons in a legal sense. Until, God, I'm sorry, go ahead. I'm new entity that sits between man and machine.
It's a machine. John, You know, I'm, I'm More, you're not wrong. I just think that's a bad label for it.
But go ahead, Jeff. Yeah, But, so I've, like Mike, I'm more about people and product, but in, in this case, AI is so inescapable. And in fact, I might make the argument that in future Persons of the year, we might have a agentic ai or we might have physical ai.
I mean, this kind of reminds me of like the record number of covers maybe Time had of, I think it was Nixon. And for si it was Jordan or, or Ali. I, I, I think it's inevitable in what we're doing.
I mean, no matter how we categorize it, it is the driving force, the major driving force in everything we use and everything we write about. So it's a great acknowledgement. And, but I also think this is just the beginning of, of, of seeing AI is, is a, it's dominant theme or narrative in everything we do, in every industry for, for the next decade.
See, I don't understand why we can't just talk about what it is. I agree with Mike 100%. I'll just go out there and say that there was a article put out by Emily Bender, who is one of the authors of the Stochastic Pure paper.
So she's a linguist and she teaches, I forget where she teaches, she's a professor and nana, I don't know how to say her last name. It's INIE, about the dangers of applying human, um, uh, of talking about AI and assigning it a human identity or anthropomorphizing any of it. And I know when I first started doing marketing for ai, I, it wasn't ai, it was HPC and machine learning and deep learning.
And they yelled at me if I tried to talk about AI is thinking or AI is doing, or AI is learning. No, it's not. People are making all of the machine parts appear like that's what's happening.
And I think that the common person, not just enterprise people can understand that. And I think it's very important that they do. I'm terrified.
I have been terrified from the beginning of those dogs looking all cute and doing the little dancing videos. It's just to cement that in our mind that, oh, they're cute and that's okay. Well, at the same time, they're down on the border doing very not okay things.
So it's dangerous because what the other part of this is how our information is being gathered into one place. It's being dumbed down. It's being assigned different things.
We're not doing anything to really take advantage of. There's not much being done to take advantage of what we can do with AI and go down that path and do the right thing with a program that's really, really good at math. Maybe that's a better word than machine, You know.
Also, I just like Peggy, backing off what you said, Gina, there's also this so-called productivity paradox. So there've been a couple studies that came out. There was one from Workday, and there's another from Kaunda.
And they basically show that, you know, employees are saving time with ai, but organizations are squandering productivity gains. 'cause they have to fix errors rather than strategic work, which underscores underlines the importance of human beings. So it's a, it's a, it's a crude work in progress.
And I think we should take that in mind when we, you know, we say person of the year that it's, it's, its a moniker for achievement. But this is kind of an early stage in which we're, we're, we're going through a lot of trial and error. I agree.
So let me, let me, uh, you know, I opened it up. I let people have their say, let me, let me now give me my, I'm gonna see back the time to the gentleman from New York here, and, uh, response, um, I'll reclaim my time. Yes, I reclaim my time.
So first of all, guy, when you talk about simulation, I can't help but think about Matrix Red Pill, blue Pill. Well, wasn't that really a, really an AI movie? And we just didn't know it back then.
You know, we, we, they did. Oh yeah, right. That was way before its time.
Now, looking, with hindsight, looking back at the Matrix, it was ai, we were jacked into some AI matrix, right? And, and thought that was reality for all. I know you guys aren't real, and this whole thing is a simulation from some ai.
But let me ask the, here's the definitive question. I feel like I'm at the Scopes Monkey trial. Let me ask the definitive question for you.
You like that, Michael? Let me ask the definitive question from my audience out there. How many of you have given a name, a personal name to your ai?
Or do you just call it Chachi pt? Or, or, or Anthropic or Claude or whatever? Gina, you're shaking your head, but I'll venture to bet and, and folks watching this live on LinkedIn or X or wherever you are watching, if you wanna weigh in, weigh in.
Have you given your AI a name? Because a lot of people I speak to have given their AI a name. And when you give your AI a name, you are, I forgot the word, not an Gina.
You mentioned the word, was it giving human mic? Yes. That's it.
Right? And that, that's a clear signal of it. And the more people who are giving it a name, the more people who are treating it like that.
Listen, I say please and thank you to all that you do or whatever I do. But you, you, you know why I do that? Because I don't wanna start treating real people like I treat an AI because it, I'm conversing with both of them.
And also, by the way, when I say thank you, every single time I say thank you to the ai, that's a reminder to myself that this is not a person. Interestingly, The AI though, tells you, don't do that. 'cause you're Right, because it spins up.
You, you know how much. Well, it's Just, you know, huge power. You what works for you.
This is what works for me. And even it works for you to remind you that this is not a person. I get it.
How many of you out there say please or thank you. The real people have many. I I'm not, not, not us.
I'm talking about, you know, out in the world. But the thing about a person, right? A person has empathy unless they're a psychopath.
But generally speaking, most people have empathy. And machines in this thing has no empathy. It has counting, you know, the, a simulation of empathy is not empathy.
So, you know, it can't be a person in my mind, Look, half the time when I do voice to text, they, they don't understand my accent. So I know it ain't a person. I'm the same.
Well, I think it's a common human trait to personify human traits into everything else, right? You name your dog totally. You like your dog to act like a human.
You talk to your ai, maybe treat it like it's a human. That is a super normal trait Human thing to do. But I don't think it it, I'm with guy.
I think if, if there was any other approach to look at what the actual impacts, uh, of the last year, right? From the perspective of what AI has brought to the table, we can talk about whether or not it's good or it's bad. It's, it's an unmistakable impact.
And that really, Fred, thank you. 'cause that, that's the, that's the, the bow tie on tying the bow here. That really was the point that this is, this has been in 2025 and will be in 2026, the story of the year.
And we see it here on Textron Gang. I try to follow it every day, no matter who's on, on the gang, what, what the gang lineup is. At least two out of every three stories are ai, two out of every three segments are AI related.
And it's not just us. It's everywhere. It's everywhere.
Though. I, I do, I have a confession. I do like to talk to non-tech people about ai because I think that's where you get the kind of the real deal view of how real this is, how useful it is, how widespread it's being used.
You know what people really think of it. And there, I will tell you, there are a lot of people who are scared to death of it. A lot of people scared to death.
I'm, I'm maybe add one thing. We Have to resocialize everyone to actually deal with humans again, because they're too wrapped up in their AI experience. I just wanted to add one thing, which is, um, the ai that's like a person is really one kind of ai, right?
Um, I was at CES uh, uh, this year. And, um, one of the demos that I saw was from a company called Accelerate ai. Most of what they do is computer vision related stuff.
That is ai, that is longstanding ai. What they're doing is, it's extremely sophisticated. So, you know, they, they're getting a live stream of the show floor and they use AI to identify people who are wearing backpacks or people who are talking or some whatever it is there.
It wasn't just recognizing faces in people. Uh, that is AI in every respect. And I don't think anyone would get confused and think that that's a person because there is no chat interface with that particular ai.
And, you know, predictive ai, there's lots of different types of AI out there. It's just generative AI is the one that with, along with LLMs produces, you know, this kind of person feel to it. Let's be real.
We've been talking about AI for years, you know, uh, AI ops and machine learning and all that stuff. No one would give a flying, you know, what had it not been for chat GPT and LLMs and generative AI bursting on the scene here? Was it, was it November or December, 2023 already?
November. Yeah, it was November Of 2023. So, you know, if you got it fluted that for, for many of us, when we talk about ai, that's still what we're talking about.
And I, I think a lot of the Gen AI will still rely on models, you know, back background that maybe you're generative. com. There's some amazing, amazing stuff as well as I'm announcing the winners of the DevOps dozen, I think around 1230.
And, uh, we also have the RSA conference analyst talking about what's, what's in store for RSA conference this year. Anyway, let's move over to B Block gang. You know, uh, we've got Google's getting serious.
That's SIRI. Mike, what do we got here? So I think this deal has been a long time percolating.
People have been talking about it and, but you know, it kind of plays into what we were just talking about. Siri was supposed to be my personal assistant and Apple was gonna lead the charge here, but then it turns out that maybe they faltered on AI and need a little help from Google. But John, you're closer to this.
What's going on? Well, you know, uh, a very wise man one, Mitch Ashley put it really well. He says the agreement basically signals this kind of pragmatic approach or phase in AI platform strategy.
So as you mentioned, Mike Apple has had some halting experiences with ai. In fact, they, they no longer have their AI head of, uh, of, uh, developments. They're, they're looking for somebody.
And, and in fact, this kind of plays into this whole idea that Apple's kind of making this decision to prioritize user experience and system integration over trying to compete in this arms race for LLMs. Um, they did have an agreement with OpenAI. I think what this signals is Apple is taking, again, I'll use the word, a pragmatic approach to ai because they've stumbled so badly and they've gone back to a partner who they've worked with for years in terms of search, which kind of got him in trouble for a while.
But in a, in a sense, it makes sense and it's been percolating, as you said, for a long time. And I also think it's significant because coming down the pike, I believe there are a lot of rumors that, that Tim Cook is going to resign, is going to leave probably in the first half of this year, and to be replaced by somebody on a more technical side. I think this is long overdue.
And again, apple, without trying to revolutionize everything is kind of going down the lane they're comfortable in, in terms of, uh, accelerating Siri, which has been a major disappointment of late. So I think it's very pragmatic and very practical for both companies. And it was a long time coming.
Boy, first, Mike Tomlin. Now Tim Cook, John, I don't know how much of this I could take. Poor guys, the new coach, I'm happy.
Don't worry. J Harbaugh's on the way. Yeah, yeah.
Well, they're the giants Mike's, that's why Mike's happy. But but seriously is, I, I, I didn't get a chance on this article. I'm assuming it is, it is Gemini, uh, powered.
So, yes. So Gemini will power the next generation of Siri, basically. Mm-hmm.
So I don't see any monopolistic thing there. Yeah. Got him in trouble before, as I said.
Yeah. Yeah. So in my house, there's an ongoing debate about, you know, Google, Android versus Apple.
So those of us in the Google camp are wondering, well, you know, if, uh, apple needs Google to DYI, why not just stay with Android and my Google phone? And why am I gonna go to the Apple phone? Just saying, Well, you know, security's a thing, right?
So it's important to keep that in mind. Spoken like a true Apple fan. Yeah, it sounds like they're so, it sounds most, most to me, like Apple is roughly licensing the model, and they'll probably contribute to model development.
Um, and, and may very well be hosting. I mean, apple has a significant cloud of its own and, uh, may well be hosting it. Uh, I, I applaud this in every sense imaginable.
And I wish the entire industry would stand up and listen and pay attention to this, because I feel like even still to this day, in fact, the only people I think who might be unhappy, the only person who might be unhappy, although it's not his nature, is, uh, Jensen. Yeah, no, no. Uh, um, at, uh, at Nvidia, the CEO of Nvidia.
Oh, Jensen. Um, yeah. Uh, only because I just, I feel like there's been just so much emphasis on training.
Everybody wants to have their own model. They want all, everybody's jumping into whatever cloud based model to start using it. But it is like the enterprise strategy started with training, train your own model.
I mean, doesn't it feel that way? It's still, it's, it's still this big hangover from hangover from that and Apple itself acknowledging, Hey, you know what, we might have, uh, you know, invested in open AI and been in a partnership with open AI and all that other sort of stuff, but we don't know how to make models. We, we just don't.
We're just gonna give up and use work with somebody who does. And I, I wish, you know, the industry as a whole, there's, there's these foundational models that there's like six, six companies in the world right now. Um, maybe in China there's more, but, um, county, China's, as it were, one company, um, can really develop.
I think one of them is gonna go under soon enough, and eventually a few more, and there'll be three. But there's so much to do tuning, additional training, small models, blah, blah, blah. But you can do, and Apple will do that.
Great. Great. So I, I have a different take on it, but Guy, you're right, right.
Brad Feld always taught me, you gotta be in the top three. If you're not in the top three, get out. But, but here's the thing.
Someone said it in the last segment about sort of, you know, this, this is, I think it was John, this, this, this is kind of the first stage of ai, right? That we're living through right now. The it, it's, it baby steps.
I don't think for most tasks that we're going to use AI for going forward, you are going to need one of these. I I call it a world model. I know world model has a different connotation than they're also called frontier models.
Yeah, right? Let's call 'em frontier models. That's a, I don't think you're going to use the frontier models for most of the tasks you do, right?
Because they, they, they're just too big. And, and to continue training them and, and, and, you know, keeping up with them is gonna be a job that you're gonna need to have a trillion dollar kind of market cap to make, to be the kind of company that does that, right? But I think the future is smaller models, specialized models, stuff that sits in front of that LLM.
Remember, they estimate 90% of the information that we store digitally has not been used on the frontier models because it sits behind firewall. That's who it was. I went to see my cardiologist, and he knows I'm a tech guy, and instead of checking my heart, we sit and talk about tech the whole time.
And, and I was explaining to him, if I could, if we could take all of your patient data from your practice here, there's four different doctors at the practice, feed that into a vector database, keeping it private, maybe anonymizing it, but using that data to help him better prescribe, better diagnose, better serve his patients, would he do it right? Because he was one of these guys, I'm afraid AI's gonna take my job, my kid's job. And I don't, you know, he was very negative.
I I converted them, I converted them. St shimmy, St. Patriot, Saint of AI here.
But that's the, I think the future, I think that's the future, not the frontier model for everyone. I think we have to get back to what Fred said in privacy, and also just making sure that that, um, any kind of biases aren't baked into the models that we're putting our data into. So I think medical is a great example.
One of the things that they've found, um, and, and we don't talk enough at all about what actually is happening to retrain these models and to, to sharpen them. And that's all done by human labor. I'm actually participating in some of that because I wanted to know how it worked.
And it's all done on, uh, a, a very time-based background. You have to go fast. If you don't go fast, you're out.
So lots of mistakes are made. The people that are also, um, hired to do the evaluation and to, uh, to qa, it also are trained on how fast they go and what happens. So all sorts of mistakes are being made.
There's been studies where some of the traditional, um, biases that doctors have just now started to overcome as far as from different ethnic groups and kind of, um, um, uh, therapies that should be recommended are sneaking back in. And my guess is it's because of some of this, this very, very fast pace of retraining and fine tuning some of these modeling. Yeah.
But It, but it's almost like a DevOps. Iterate, reiterate, fail fast, iterate, reiterate, fail, fast reiterate, it will, I mean, when you look at the deep seek, right? How are they able, well, depends if you believe they stole their stuff or not, but how were they able to, to, you know, to churn out a model comparable to our best frontier models at a fraction, because it was that forced training that that very rushed, you know?
But that's what I'm saying. Yeah. That's what's dangerous.
What's dangerous is if it's rushed, rushed and nobody's really paying attention to the details. That's where the finer parts of especially specific things like medicine, that the bias, if all the literature is consumed, and you've got somebody that's not really an, a domain expert that's doing the checking, they're just, uh, uh, an AI expert and they understand how to look at a prompt and how to look at a matrix to judge the prompt. They're not looking at the content and how it will affect everybody.
And enough of that happens, the bias remains in the model. And then that, so when, if your cardiologist puts all his patients' data in there, the results may not be what he would think they would be, because then the results are based on this incorrect fine tuning. And they, there's already studies out about that, that this has happened.
That that's assuming is not a cardiologist who's training it. But let me, let me give you another counter. Let's look at coding.
Let's look at coding. There are a lot of people, including, I'm sure people in front of me on this screen who say, look, AI code is inherently insecure, right? And, and historically it has been.
It has been. But when you look at the latest studies, now what we're seeing is the amount of vulnerabilities per x lines of code from human generated, right? Human written code, non-AI assisted code, the amount of vulnerabilities per x amount of lines has been pretty steady, right?
It hasn't necessarily gone up a lot. Hasn't necessarily gone down a lot. It's a, it's a baseline.
When we look at the amount of vulnerabilities found in vulner, in, in AI generated code, yes, a year or two ago, it was ridiculously insecure, ridiculously, it couldn't even get basic syntax, right? Then it started getting syntax, right? And then it started really focusing in on making security, making, you know, more secure code.
They estimate that right now, AI generated code is roughly generating as many vulnerabilities per X amount of lines as human generated code. It's on par. The thing is, human generated code is gonna remain at that level, and the AI generated code can continue to go down.
And when it goes down appreciably, then what do you, you know, then all of a sudden the human generated code is much more insecure. I think that's gonna happen with AI in general, iterate, reiterate, correct. Correct.
Right. The way we are rushing it now, it is new, but perspective, you know, hindsight and all of that, it's gonna continue coming down. I'd interested in your thoughts on that.
There's two things here that I think are interesting and I, I would say an expert training an expert system, you're always going to have better results. And I think those are, you know, so a, a cardiologist training a model with information, you knows you're still gonna have better results than, than not. But I think the Apple announcement is really more pitted for the everyman, right?
In this case. Mm-hmm. And so it's less about whether or not, you know, model training and any of that, none of that is approachable to the, the everyman.
And so now on my device, I have access to, you know, a, a higher authority of information that allows me to utilize with greater capacity. You know, a lot of the things that are on my phone, and the optimism of that is there are folks that have health conditions and they're not covered. And you know, you probably saw, but Med Gemma four B was released by, you know, Google this week and it's got a 50 to 55%, you know, accuracy.
Now you're talking about you can't get in to see a cardiologist or, you know, the level and cost and standing of your own healthcare is something you can, you can manage should you go see an expert. Sure. But that's not on the plate for everybody.
The, that's the optimism on that. But the, the concerns are right, and we saw some of this happen this week. I, I, I participated in some of this.
Uh, but the concerns are privacy. Apple has long held the grounds that privacy is tantamount, Google does not. And so there are implications here on the conflict, and the consumer will be at the behest of this conflict.
Uh, the one in the crosshairs, and one instance of that occurrence was, uh, a, a good friend of mine put a LinkedIn post out about, you know, his 13-year-old son was being notified by Google, right? How to subvert privacy controls, parental privacy controls so that, you know, on the 13th birthday, right? As they can move out of that Copa, you know, aside, right?
Privacy experts are very concerned about the implications of that. Wow. And it's pervasive.
So if you couple that accessibility with the implications of what that privacy exposure looks like, now you're starting to ask questions about whether or not the healthcare industry based on your phone's behavior and your activities and things like this, may be able to qualify you or disqualify you from insurance, from healthcare, from other things. Because the cost of those things, or the value is that transferable part, not the information that you possess. Those are the, those are the concerns, right?
Around some of that futurist part of that, Fred, you're just, you're just peeling back the very, you're just peeling Fred's just peeling back the very first layer mm-hmm. Of the, the, the, the, uh, blow back repercussions, whatever you want to call it. That application of AI to, to, you know, our life is, and, and to business is going to have, we, we can't even pre we can't predict 95% of what the repercussions are gonna be.
We gotta bring this one to a close 'cause Yeah, we do. But I also wanna acknowledge we've got some nice comments out, uh, in, in, uh, LinkedIn and, and other places here. And thank you very much that that's, thank you very much for the comments.
We're still figuring out how to incorporate comments into our show. I gotta get me a monitor that I could read right here on the desk. Mm-hmm.
Um, 'cause it's hard for me to read it out on my monitor out there, but, but thanks for the comments. And I see one that says, that's what I hear. Alan sounds like someone who agrees with me things, so I wanted to call him out.
Let, let's move on to our next C block though. And that is, uh, target bullseye Tar. I, so I read this and I had a deja vu.
Was it the HVAC Man or the Butler? It was, it was Hacked, right? Yeah.
So back in the day, target was one of the first, uh, you big scenarios where there was this hack of their HVAC system and they had a major breach. Now it's not clear what's going on here. I mean, at the end of the day, some hackers somewhere has some code that they have shown that apparently belongs to Target.
And they're saying they have the entire code both. And Target's supposed to do something about that with some sort of negotiation push. Brett, I wanna start with you 'cause I kind of feel like this is everybody in corporate.
America's worst nightmare is to wake up one morning and discover that entire source code for your organization is now outside of the four walls of the proverbial enterprise. And is, are we gonna see a lot more of this? I feel like the bad guys are like figuring out that the source code is like that key asset.
Absolutely. At fold disclosure. Uh, I was at Target for two months in 2013, uh, doing some cleanup work and, uh, analysis and the impacts then aren't nearly the impacts today.
It's your point, Mike. One of the biggest concerns is, you know, when you let somebody have access or they get access to your build systems, um, they have access to everything, not just the source code, but how you build the source code and what services you run, the types of technologies they have, and also all the tokens that you use to do that. And so there's a significant set of implications there.
I would say, uh, gathering 860 gigs worth of data is a significant statement. So to your point, and also to conversations we've had about using some of the AI XCC, uh, vulnerability analysis, uh, capabilities that last, you know, last black cat came, uh, and was deployed, uh, both, uh, in open source, the opportunity to find vulnerabilities in that right substantive, and also the cost is 500 bucks of own to, to build them. So when we look at what the implications are, it's a long, long road for them to find and see the things that are occurring there.
com is available, uh, without some zero trust access to that, and that is your build system, and it is an internally hosted environment that if that were true, that's an incredibly dangerous thing to do. Um, and some would say it's derelict, but in this particular case, the concerns that can happen is, like you said, a lot of the infrastructure can be exposed, not just the source code. So service names, IP addresses, environmental context, all of those components can echo for years, especially at the rate of change in an enterprise environment and an organization as biggest target, I'm sure the rapid advance to make changes to access, turning that off now and adding VPN and zero trust, gateway access for employees, uh, was something in the books.
But, you know, obviously it's been hurried along. Now, You know, Fred, you know this, I've been in the insecurity world a long time, really long time, 30 years when, when this happened originally to Target in 20 12, 20 13, I, I, you know, you were there, you know, over the, the couple years after that. We do, every year we do our DevSecOps event at RSA, and we were lucky enough to have some of the really good people at Target.
Uh, Jen, Jennifer Kaki, I think is one, or Frank Courtney Kissler from the DevOps community was there. Target did everything right after that breach to, to shore up. They had, they were having internal dojos and, and all kinds of things, and they did an amazing job, right?
For we referenced the hvac, it was a third party supplier who happened to be an HVAC Yep. Vendor who got into their system. The, the network was flat.
Once they got into that HVAC vendor, they had the run of the place and, and took what they wanted. That was then Target has come so far since then, though they've done so many Right things, good things by the book, best practices. What this really shows you is it could happen to anyone, any company, anybody.
They, it's just the nature of the beast. It's what keeps security people up at night makes us depressed. Because when nothing happens, no one gives you an attaboy or a pat on the back because that's what's expected.
But when the stuff hits the fan, everybody's got it on their face. And so I'm genuinely sorry that it had to be Target, that was part of it, got hit here again. But it, it just, it it's collateral damage.
It's the, it's the nature of the beast. We, we we fight with every day. Gina, is this that proverbial wake up call that we've all been waiting for?
Or are we just gonna roll over and hit the snooze button one more time? I hope people don't hit the snooze button. I mean, I, it, I I agree with everything Alan and Alan and Fred said, you know, if, if they were back on track and, and they made such big gains, like, man, what happened?
But, um, from what I read, they, they know that there is at least one employee whose laptop was compromised. So there, I don't think they made any, um, positive connections to those that being the cause or anything yet. But I mean, that's how simple it could be.
It could just be one person compromised and then just a really bad decision to have get open like that. That's just, it's hard to understand how a big, big company would do that. Um, so, um, it has to be, I mean, security, if, if you care about your data and you care about your company and target's not in a place, this is not a good time for this to happen to target, right?
No. So they, they're already having a lot of issues just with sales in general. Mm-hmm.
So this is not a great time for this to happen to them. Um, so you gotta wonder why, I mean, like, Fred, why would anybody leave get o you know, so accessible like that? Well, and to, you know, to, I want to echo also what Alan said.
You know, we can, I can, we can sit here and say, right, there's a zillion different ways that somebody can compromise a company. And I a hundred percent agree in 2013, even sitting around that table with a bunch of super talented security people, they were doing the right things then. Right?
It wasn't a question of whether or not that's the case. Today's universe, I wanna say is also a little bit different, right? We've also opened up a lot of outsourcing, right?
We've enabled people to, you know, from a development perspective, you start thinking about are there applications about I want to use, you know, copilot for this or this model for that, or there's a lot of ways that you could think about where that becomes more accessible than less. But it's a good question. I think a standing question, right?
If you were to, if I were to put Shimmy, I'm gonna put the CSO hat back on you and I right? From this perspective, we, we would say the, the garden wall and then the crown jewels, and when we think about what the dev environment would be, right? And the accessibility and the brokerage of what trust that has, right?
Is pretty much right in the center of that set of crown jewels. And so it is a little bit concerning that this is that available, especially with self-hosted normally folks, self-host, because they don't want to have a compromised cloud service, right? Expose all of their source good, right?
They probably weren't doubling down on this thing. So I want to get a little bit more information about it. Uh, I, I wasn't thrilled that there are folks that are saying, Hey, you know, so-and-so had an info dealer last year, and maybe that's why, probably not the right time to, you know, ambulance chase about what might have happened.
And if, if you were my auditing firm and you came in and did that work and you thought it was important to tell the news that, and I didn't disclose that probably won't use you again, right? So it's probably more to it like all things, but you know, it is a great, I mean, Jean, it's a great question. Like that is the, that is an element of the crown jewels.
Why is that accessible? Makes sense. I don't need to be mean here, but I'm gonna say, look, if you are walking around times Square at midnight with your wallet in your back pocket, and you get robbed, I'm gonna be sorry that happened to you, but at some point I'm gonna shake my head and say, you know, it's a little bit on you.
Well, no, I don't think anyone's saying, not saying that, I'm just saying it. A, it could happen to anyone, but B like, like G Gina asked why was GI open, right? And, and for those who aren't savvy to all this, here's the deal.
You, you store code in a repo. A lot of people use GI GitHub by Microsoft, probably the most famous or popular one in the world. That's a SaaS kind of thing.
But for large organizations who don't wanna trust their crown jewels to some third party SaaS, Microsoft GitHub offers a GitHub enterprise self-hosted version where you actually get to host GI yourself, right? You get your own GitHub, your own gi you could secure it, you could bury it in the bottom of the, of the ocean or in the sea, or in the space or anywhere, but you get to really, you know, lock it up. Well, why the heck wasn't it locked up here?
Is there is the Gina? That's what you are asking. Why does it get locked?
It doesn't make sense. I, I don't know, maybe it was locked and they had the keys, right? Who you know right now, we're speculating.
Right? And, and Fred, I agree with you. What kind of auditor goes out onto the press and talks about stuff like this, unless they're afraid it's coming back to them because maybe they didn't do such a great job on the audit or something.
There's, there's, we could speculate till the cows come home. It'll come out over time. It'll come, but yeah.
But To leave Target alone for a minute, you know, I feel like there's probably a lot more of these repositories out there that don't have that level of security you just described. And for whatever reason, we're gonna keep hearing about this more and more. Yeah, John.
Yeah. And a choice between speed and security. Uh, um, we, we know what tends to win out.
Speed wins. Speed kills though too, guy on that note. Sure.
Hey, we're gonna wrap up because you should go watch Predict 2026. I'm gonna say it one more time. com.
Um, Fred, Gina, guy, of course, John and Mike, thank you so much for joining us. Thank you for joining us. Thank you for people who comment, if you're not watching this live, you can catch us live every weekday Monday to Friday.
For those of you who might be wondering, I know next Monday's MLK day, we may not publish a text on, but I think we're gonna have a special MLK Textron gang episode, so stay tuned for that. Um, otherwise gang members, thank you. Thank you.
I'm Alan Hummel, we're out.