Techstrong Gang – August 5, 2024
Alan, Mike, Mitch, Jon and special guests John Willis and Tracy Ragan take a look at just how open source many of the large language models (LLMs) that are being made available are. Then, the gang dives into the all the CrowdStrike lawsuits that are being filed before discussing the overall state of application security.
Transcript
Hey, everyone. Happy Monday to you. You know, we've got a little bit of ai, got a lot of security.
It is Black hat, or as some of us in, in the industry, say it's summer camp in Vegas, in the desert this week. So we will go heavy on security. Um, we've got a lot to go over with you.
You're watching Textron Gang. Hi everyone, it's Alan Shiel for Textron. So, as I mentioned in the opening, happy Monday, it is blackout Black Hat Week summer camp in the desert for its cybersecurity friends, uh, tech Strong will be out there in force, along with our friends of Rum group.
And, uh, we have a lot going on. We'll be streaming live from there. We'll be doing a Textron gang from Las Vegas on, uh, Thursday, the last day of Black Hat, right before Defcon starts.
But that's further this week. Let's talk about today. Monday morning, rise and shine.
We got a lot to go over with you. A lot of security, somewhat AI we want to talk about. But let's first introduce our gang members.
We got a full boat of, of gang today. Um, first of all, well we'll go west to east again. We're gonna start out west with our Silicon Valley based editor extraordinaire.
John Schwartz. John, welcome. How are you?
I'm good. It's good to be all with all of you. Absolutely.
Hope you had a great weekend and, uh, ready to rock here. This busy, busy week. John, you'll be out at Black hat this week.
I will be. I will be with you and Mitch in the cast of thousands. Yes, Very good.
Looking forward to seeing you. Um, I guess next is New Mexico East or west of Colorado. They're kind of about even, aren't they?
Just straight up? I think we're pretty Even. I think we're pretty even.
Well, I'm gonna go with you first, Tracy, 'cause we like you better. Um, holy kidding. Goodbye.
But, but she, you know, a regular gang member here, always willing to help out and pitch in. Well, part of the tech stroke family, she's also the CEO of Deploy hub and open source Linux Foundation board member extraordinaire. Tracy Reagan.
Hey, Tracy. Welcome. Well, well thank you Alan.
It's always great to be on these because it really keeps me frosty. It's, I have to do a lot of reading and a lot of research, so it's fun. Alright.
It keep, keeps you going. Moving from Tracy just up north and actually going up in, in, uh, altitude as well. It's our CTO and Ur CTA and we do love them all.
Getting aside. Mitch Ashley. Hey Mitchell, welcome.
I'm feeling the love this morning. You know, it's security week and you know, here we are. So absolutely excellent.
Moving from there, though, deep into Alabama. It's, it's our ai, DevOps, cloud author personality, Baer, Gallup, John Willis. John, I haven't done one of these with you now in a couple weeks.
I'm always out when you're on, so it's great to have you on here with me. Hey, Alan, it's great. I agree with Tracy.
It's just fun 'cause you know, you, you gotta dig in and do a bunch of research and it, it's like, oh, I didn't know that. Didn't know that. So, yeah, so it's pretty cool doing this.
So I enjoy, well, we enjoy having, we enjoy having all of you on and joining me here locally in our Boca Raton Techstrong headquarters studios. It's our chief content officer celebrating a birthday this week. So let's give him a big shout out for that.
He's 21 plus again, our own Mike Ard. There you go, man. There's a portrait in my basement that's getting older instead of Me.
Yeah, it's just kind of voodoo. Put it on that. Well, it's great to have you here, Mike.
Alright, let, let's jump into stuff. Our first all, our first kind of topic block today is the rise of open source ai. I have some thoughts on this, but Mike, why don't you kicking, Well, let's jump in a little bit because early on everybody said these proprietary platforms were so far ahead that no one could catch up.
And then recently it looks like, well, Google's been showing some interesting stuff. Apple's been showing some stuff that's meta and mistrial and there's all kinds of open source models out there that are rather robust. And it looks like the open source community's catching up pretty quickly.
John, I know you've been researching this stuff, and I do mean John Willis, what's your impression of what's going on here? Yeah, no, it's, uh, it's, you know, I think we've had this conversation. You know, I think, you know, I think most people who are sort of afraid of the, you know, the sort of the large proprietary models, you know, like are rooting for this open source.
And I think it's been been debatable with like, we've had these discussions, can it catch up? And, you know, I don't, I'm, I've been optimistic all along, but I think recently, um, especially Apple's recent announcement, um, you know, some of the stuff that Google's doing and meta of course. Um, but yeah, the Apple stuff is really good.
The thing that's really interesting is it's sort of a fake open source. You know, you people talk about open source, it's a little bit different in, in sort of generative AI because there's really sort of three components. One is what did you use to train the model?
What are the weights that you use to train the model? And then the code. So you gotta be sort of buyer beware when you see open source.
'cause the code could be open. Uh, but the, and even sort of the sources could be reasonably documented, but the, um, the weights are sort of, were not relatively documented, you know, and, uh, and Apple, you know, I think Apple has just come out across the board, you know, the, the sources, you know, in fact the, the whole project they're creating is in state account, uh, for Lang Lang large or for language model, sorry. And, uh, and so they like, it's, it, I I think in some ways it might be the most, um, extensive version of an open source.
Uh, you do have the Google, um, Gemma stuff, you know, where they are producing the weights and the code. Um, but I don't know, they're so involved in this sort of, uh, this sort of other project that's going on that seems to be funded or a lot of research by Apple. So I think the Apple thing's really good.
You got sort of meta, you know, the, the, the LAMA three one stuff. And, uh, but one of the last thing that's really interesting too, so if you look at their licenses, they, they also have these sort of weird licenses too. Like they're not like, you know, our classic open source licenses, just sort of the, the Google, um, what do they call it?
It's sort, it's a Google specific, they have an Apple specific license. And even though they sort of read open the, the devil's in the details. Like I, I was at Missile Defense, um, was it last week or two weeks ago?
And I was asking 'em, you know, 'cause there a lot of these government patroller in this, uh, quandary of like, I can't really use, you know, open models right now or the sort of SaaS based models like, you know, GPT. And I said, well, what are you doing? What meta, like meta three one?
And they were like, yeah, it's not clear because some of these models have responsibility clauses. And, and some of 'em, I know I've been told by, you know, by sort of DOD from missile defense that they, um, they have, um, sort of no warfare or military use or like, something like that. And it's not clear, it wasn't clear to the people who were implementing AI there that they could or were able to use that license.
And I haven't, you know, I'm not gonna spend a whole lot of time going into Google's license or Apple's license. But there are, both of them have responsibility clauses. Uh, so yeah, Well they're not, they're not standard OSI licenses, right.
Mitchell and I had a run in with that about 15 years ago. Check through your own license. The, the Google license is a little bit more accepted than others, but it's still not true.
OSI and, and I think John, you, you're onto something there. And for those organizations, like a government type of organization that need clarity, liquid, you know, clear clarity on, uh, licensing like that. If it's, if it's some one off license, it's gonna delay adoption there.
But I, I, I think there's something else to look at here though, guys. Open source as a business model. What, what, what some of these companies who've made making moves Apple and meta.
Well, they're not the market leaders, right? You would, I would have to say market leaders probably, you know, obviously open ai. Google has been doing a ton of stuff, maybe even Anthropic with Claude, Google, Google's Conflicted.
'cause there's a proprietary model that they have and then there's an open source one. So Yeah. But that, that's not conflicted.
That's Google. They do that with everything. But, you know, the, the, but the bottom line here is these guys are trying to get core back market position by cloaking themselves in the open source banner.
Mm-Hmm. And, and as John points out, you know, maybe, maybe not open source, but that's what they're doing. They're doing this strictly not for any kind of goodwill or, or, you know, benevolence, they're doing it to try to get back in.
'cause they, Well, if you look at Apple, you could clearly see they, they, they talk all about the on-device model, right? Like, so that's, you know, I mean, so they're, they're saying, um, well, from what I've read, right? Which is, I don't know everything, you know, but, uh, is that short, John?
Yeah, yeah, yeah. It's so many hours in a day, right? But, uh, hey, um, you know, there, so that a lot, a lot about the on devices.
So you think about like, okay, where can they win? Right? You know, you know, so you got the sort of the, the open ai, uh, on your device opportunities within the last, I don't know, six months or four months or three months, right?
And, uh, you know, run chat GPT on your phone, uh, you know, so that, like that strategic product, right? Like how do you know on your sort of, you know, Mac, your iPhone, your, um, dev, you know, iPad, all that. So I think there is something there.
I think meta, you know, Mark Hale has a really good, when you get him on, he's a touch strong gang guy, um, good friend of all of ours, but he's, you know, he thinks there's like a sort of a, like you think about meta, like, you know, how does Meta made their money all along, right? Just figure out who all the people are, interact with your technology, and you'll make crazy money on it. So like, I think there's a play there.
So, so I don't know, you know, like, you're right. It's not just benevolence, right? They're not just, Hey, we're gonna be good guys.
But it is that combination that, you know, that like, you know, that sort of line have all vendors, you open source, have dealt, let's say, you know, even back in the DevOps stuff, the chef, the puppets, right? They create, uh, a lot of value with the hope of getting value back, right? Well, So The, um, the Apple model they released, I think they even said, it's probably not gonna make it into product.
It's really there for experimentation and learning. And so, which is a different kind of catch up strategy, right? You mentioned, um, them being behind, you know, where the, where the opening eyes and et cetera the world are.
So it, you know, one of the, one of the biggest things, biggest questions I have about open source models and, and there's, you know, hugging faces has got a lot of stuff on it, is, um, you know, it's another, is this a security week? So I'll bring up the security, it's another attack vector for someone to, you know, go in and change weights, you know, train the model differently, whatever it might be. And so, you know, I think if you're using a popular model off of hugging face, okay, maybe there's some, you know, obscurity through lots of people using it, maybe not.
Um, but do you go to a trusted source, like, um, open AI or Apple or Google, whatever trust you put in them to get models for things that you may not understand how it works more or less, you know, be able to build one yourself. And let's not forget that they are working with the university system to build these, uh, to build this model. So they're not doing it completely on their own.
Um, they are working with, uh, you know, college graduates and college, you know, undergrads to build these models. And I, to Alan's point, I think we have to, we have to understand why they would do that. Well, the more that they can bring in young developers, um, and build trust among that community, the better off they'll be for maybe a, you know, a 13 B model instead of a seven B model.
Uh, so there is definitely, it's, it's not all, you know, coming from their heart. They're being smart about the market. They're understanding that, um, this whole idea in the past of vendor lock-in and some of these tools is not something that, or, uh, enterprises even wanna, uh, be caught in.
And these are core pieces of software. So, you know, yay, I'm glad because, you know, a lot of times I hear that open source is going to the wayside because of security issues. But when we see something like this being brought forward as an open source offering, it tells me that open source is still strong and alive, and it is the way to, uh, really establish yourself in the market and to, um, bring in young developers, uh, along the way.
And that's part of their, that's part of the strategy, I'm sure. John, can you clarify one point? So based on all the things you described with the licenses and the use cases, are they trying to contain the forking of these LLMs?
I mean, it seems like one of the things that we like about open source is people will take things and build and expand upon it. But how constrained are these things? No, they're not.
I mean, that's the point. Once you open up the weights, I mean, brought up a Griffin point you, I, I was talking about on the last one, we talked about the research about, you know, byte codes in in models, right? And what was I, I, I donate, like, they're showing like how people are escaping out of inference engines, not even training inference engines, getting into Kubernetes clusters, escaping outta those, and actually getting on shared physical hostess on Amazon.
I mean, this was target face, but, um, but yeah, I mean, if you read the Apple, um, particularly, I mean, when you start producing the, the, the, the weights, I mean, you are basically telling people, Hey, you know, you've got it all now. And I, you know, I think, you know, you know, if I had to say it's gonna be something about, you know, probably SBOs if, you know, if, if the industry gets, you know, good like it, but it's, it's not too different what we see, you know, like, you know, like all these new, um, attack vectors like Mitch brought up, right? Like you, there are people doing sort of retraining to re training or training weights that are creating, you know, sort of nefarious results.
Uh, but like the, what was the node? The guy who moved two, two blank spaces in a node application took 30 internet down, right? Like a few years ago, right?
Mm-Hmm. Uh, like this is the, the, the blessing and the beast of open source. We just have to get wiser.
Just, you know, like you think about all the dependencies, what in a large bank right now, you know, it's, it's, it's, it's scary. The code. Like if you drill down to some library, it's like literally production code that is literally written by kids, you know?
Um, you know, and, and again, that's sort of like the sbo, you know, a shout out to Josh Corin for really one of the originators of that. But, you know, the executive order that jo it, um, and now it's sort of hopefully close to link factor. I know we're gonna talk about that.
You guys are gonna talk about that later. But, but the point is, yeah, we've gotta sort of learn from our mistakes, learn from how we did things in the past. And, you know, and, and I think you're, you know, we're gonna have to come up with a mechanism to identify models by some type of timestamp or some repository that says that these are the, the ones that are trusted.
And, uh, you know, um, so, but right now, I, I think there, it's still the wild West, right? People are just saying, you know, here's, here's the code, here's the weights, and here's the data. Have a party.
In fact, they want not About it. They're promoting that, you know, what could go wrong? That is the point.
What could go wrong? That is the Point. Have a party not, yeah.
No. Okay. All right.
Hey, we, we've got, we're gonna take a break and then move into a couple of security segments here today. Before we do though, I do wanna give one shout out on the AI stuff. You know, if you're watching the Olympics on Peacock, uh, the Salesforce people been running a bunch of ads for Einstein.
I dunno if any of you have caught that. They're really funny ads. And, and like the, when the person uses the Einstein to do whatever they're doing, they, they get like a Einstein wig and mustache and everything.
And it's, it's actually pretty good. I don't know. I think it put AI in a good light.
But let's take a break. Let's come back. Speaking of good light, our friends at CrowdStrike are probably gonna be running up some legal bills.
All this, some more. You're watching Textron Gang Cloud Native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud Native now. All right, and we're back. And as promised, we're talking about the law as one of those cases where Knight follows Day.
Lawyers are following lawsuits about this CrowdStrike Windows outage issue. That doesn't come as much as a, as a surprise, but, um, Delta is looking for, I think, 150 million or so. And you multiply that by the number of people affected, and suddenly this becomes a rather large potential number.
And I'm assuming there'll be class action suits and all kinds of fun things, and shareholders are also now suing CrowdStrike. So, um, the mayhem has ensued. John, what's your take on what's going on here?
I mean, I can CrowdStrike withstand the, these number of lawsuits. Are they actually liable? What are you hearing?
Well, ed Baston is probably one of the per people you do not want to p**s off in, in a situation like this. I mean, um, I interviewed him a couple years ago. He was a keynote speaker at CES, and he is obsessed with the technology of Delta and the customer experience, as well as they were working with airports in their terms of deploying their technology.
So they're likely to sue, as you mentioned, the CrowdStrike shareholders have sued. There's gonna be a cascade of actions in all likelihood. I talked to Daniel Newman at Futurum Group about this.
7 billion in cash at the end of their last fiscal quarter, and about $750 million in revolving credit line and insurance policies designed to mitigate the impact of legal claims. But it's going to be a Torrance, and if their stock is paying the ultimate price, they shave like $25 billion in market value off of the company because of what happened with the outage of, it's, it's, it's interesting in that CrowdStrike is the very victim of the interconnected digital system that we all write about. It benefited from it.
It has a good reputation despite what happens. But it also has a number of dependent mega corporations who were knocked out in the case of Delta. They were, um, I think they canceled more than 6,000 flights, maybe in nearly 7,000, which to put it in context, that's as many flights as they had in 2019.
So over five days, they lost 6,500 flights. They had to manually reset 40,000 servers. They have a, a, uh, a crew tracking system that was knocked offline.
So they couldn't coordinate the pilots and the flight attendants, the flight of leads. This left half a million of their customers looking for their luggage and try to rebook flights. So expect the, the legal actions to continue, especially, you know, this weird thing too is Ed Basher was embracing this digital transformation idea, right?
The last several years. A number of companies did, and a lot of them bet on CrowdStrike in part, to help them make that trans transformation. And now we're seeing the dark side versus the benefits.
So, um, it's could be a rough patch for CrowdStrike for the next several months. Oh, Look, Delta could track their flights on a, a whiteboard, um, yellow bed or yellow bed. Some sneaky two.
We talked About that. Here's deal, right? You know, the CrowdStrike shareholders, I, I think they're suit problematic, but they probably have, you know, policies that cover that.
Um, but as, as far as Delta and some of the other CrowdStrike customers suing, good luck. Read you a eula, right? I think absent gross negligence and, and you gross negligence is a very high bar to, to cover absent gross negligence.
I don't think they can sue for this. I, they might be able to request an arbitration, but I don't think, I, I think if you are a customer of CrowdStrike, I, I think your ER's going to, well, four your right to sue them. And if you're not a customer of CrowdStrike, you're a Delta customer whose flight got canceled, you don't have standing to sue CrowdStrike.
'cause you're not in what they call privity with them. The one, just a real quick point, I'm sorry to interrupt. The, the, the one thing that I think they have more of a, an issue with, rather than the lawsuits, just the customers in the, the, the fact Oh yeah.
That, that's gonna be another thing. But They're gonna scare away potential customers. Absolutely.
But you know what, John, we've learned this over and over again in, in cybersecurity. Customers have very short Memories. They'll come back, right?
I know it's happened in give it Nine months to a year. And this is way, way back in the rear view mirror. 'cause there'll be 1200 other breaches.
The Short term incidents beyond that will be significant. Yeah. The publicly traded company, they're gonna, they're gonna have some revenue fall short falling.
I think the investors is a real pay. Like, I mean, losing 25 billion market cap is, you know, in like a week or two, right? Like that's, Hey, there, there's no guarantees in the stock Market that, so the was suing them these retirement funds, right?
And so there's a whole like, like, but That's a different thing. Are they gonna invest whereas their trust going? In fact, there's a, what's interesting, remember David Bowles, the Bush V Yes.
That's a good point, John. There's a Plymouth. Yeah, yeah, yeah.
There's some big guns that is this large retirement, um, fund outta Texas. Um, that, that they claim there's 20, they have a percentage gain for about $20 billion worth of loss. Um, you know, so yeah, I think there, the, the, in the whole, um, uh, the, the, the, the institutional investors or the sort of the, the, the retirement fund type, those fund large fund investors, I think that's where it's gonna get.
I would, uh, It seems to be You take your chances. I'm sorry, go ahead, Tracy. I just wanna bring up two, two points that we're not talking about.
You know, I don't, I'm not an attorney and I haven't, I was actually traveling with this staff. We did Stay in the Holiday Inn Express last night. Yeah, I Did.
I wanted, I, I mean, what is Microsoft's, um, you know, obligation in this situation and what were they doing from a DevOps perspective? They got that problem into production so quickly. So I think it speaks to two things that we should be, we really should be talking about as a broader community.
Number one, should we be having a company like CrowdStrike have that kind of access into these production environments? And number two agents are, um, invasive, uh, and it, it broadens the, uh, it not just an anomaly like apparently in this case, but it doesn't broaden the attack surface. So do we really need to have these additional agents, even for security running out there?
We can. Well, the eu, something else the EU says you do, the EU specifically a few years ago said that Microsoft had to open up the kernel to these, these products to make changes. Microsoft's churn is blaming the EU in part for what happened.
Yeah, You, It's interesting though, Tracy is that, that what's really interesting to me is that the way these companies are approaching it, meaning Microsoft and CrowdStrike, CrowdStrike's very transparent about it. Kurt is apologizing. He's trying to be out there as much as possible.
Microsoft is as quite as a church mouse. Uh, it's what I'm saying. Where, where's Microsoft?
I got 20 bucks that says during discovery, somebody's gonna find some emails that says, geez, we knew all about this and we were alerted to this and we didn't do anything about it. 'cause we've seen that play now, what, three to four times involving Microsoft cover Up course of the Crime. I think the liability here, Alan, is, is not that a bug was created and got into production.
They have processes in place already to try to drive quality into the product and improve that. I think it's about the distribution of software. That's where the, that's where the underbelly of this is, is they pushed the software out to massive amounts of customers very quickly without There's limitations of liability In the No, no, I, I understand.
I'm just saying if you're gonna claim negligence, I think that's where you're gonna, you're gonna have, well, it has to be gross possibility. Now, is it gross? Is it cardio?
Does it compare to what everybody else does in the industry? I mean, there is no standard for this, so I don't know that it's gonna be successful. I'm not a lawyer, but, but like, if I was there at Bowles and I was suing, uh, de I'd be suing Delta.
Because here's the thing, right? That was a kernel change. And there's no evidence, you know, like everybody talks about CrowdStrike and Microsoft responsibility.
What was Delta's responsibility? 'cause I will tell you, I've been inside that organization, and you would never put a vendor patch on a flight control software system of a plane that was in Fleet. It would never happen, never, ever, ever happen at Delta.
But somehow in that organization, their, it doesn't think the same way they do in every other silo. And the fact that there was, you know, at least it, it, it's sort of a counterfactual from my part, but I'm pretty certain there was sort of this authority bias where, because it was CrowdStrike, I mean, but imagine any other vendor giving a bank or an insurance company or a, he, you know, healthcare, a hospital, a patch that is in sort of an in fleet core business application without testing it. You know, like, John, you're right.
Software. Can you imagine what the Delta software developers were thinking? Can you, I am quite sure that a, a Delta software developer has no access to, to make a change at a, at a component that it is such a low level that could impact so much so that that authority bias is coming in the Would let this patch go through like this.
It it's, it's the s you know, kind of thing. That's a good point. But let, let, let's, you know, let, let's look at that.
Let me play conspiracy theory here, right? Delta was never known as an airline. No, I'm only kidding.
That's a different conspiracy. Um, but the, the, the conspiracy theory here is, is the CEO of Delta blowing smoke to, to obscure or to, you know, blame from themselves for what they did and do here Speak loudly and divert from what really the Issue might be. Exactly Right.
He's ultimately responsible for what happened. Sorry. Right.
Pay no attention to our screw up over here. Here's, here's where you gotta look. Right?
That would best protest too much. Right? I Think there's plenty of blame to go around and that's clearly been established, but I would say that as the evidence comes out, reckless disregard Mike Trump, what's Ever in your ULA Agreement?
Those a fight. That's a fighting word there. Go easy on that.
I think it'll be interesting to see where this goes. I really do it. I'm telling you, it's, it doesn't rise to gross negligence.
I think we rename this the mayhem segment where the fight broke out. Absolutely. It's the, the crazy part is we had multiple levels.
We had CrowdStrike themselves that should have caught this. Then we had Microsoft and then we had the end user customers. But as John pointed out, there's some kind of authority bias that said, let it rip and we can't do that.
And, and there's not a single developer that works for, for Delta that's allowed to do that. Yeah. Why Stri is allowed to Be careful all those people writing ebi.
Tracy, this is an important point too, but I, I slam this in 'cause I think it goes right with what Tracy's saying, which is the other part is that, you know, that, that some argue that this, this is emerge behavior and might not catch it with testing then, then pay them money to get a digital twin. You know what I mean? Build it.
You know, like, do something like that literally allows you to emulate emergent behavior. Um, if you, you know, if the, the Penalty is, you Know, um, you know, the kind of loss that they've had and the industry loss, you know, so Absolutely. I Well, it should have been Delta that was pushing that forward.
Right? It should never have been CrowdStrike that was pushing that. I like, I like Tracy's line letter RIP is kind of the it equivalent of Hold my beer.
Yeah. Hold my look. I'm gonna, I'm gonna close this segment down.
I want to close it though. Bringing it full circle. This segment was about lawsuits, not just about the other stuff.
And when you're talking with lawsuits, right, there's a big difference between the truth, justice and what happens in a courtroom. So we're gonna take a break. You're watching, uh, text and gang.
We're gonna come back and let's talk about how secure is our software really. Anyway. Mm-Hmm.
We'll be back in a moment. All right, folks, we're back. And as mentioned, we are right in front of Black Hat and all the cybersecurity people on the planet are headed to Vegas, or at least a significant portion of them.
Yet there's a growing body of evidence in the latest. There are reports from GitLab and another one from OX Security that suggests that the software that we have out there is not nearly as secure as we hope. And this is a recurring theme that's going on out there.
And we have established that maybe software is more secure today than it was 10 years ago, but that doesn't mean it's any level of comfort. So, Mitch, let me ask you straight up, um, what is the state of application security in your mind? Well, I think here we're talking even supply chain security, right?
Including App AppSec. Um, well first of all, this is a FUD article. This is a FUD study.
Um, yes, there's lots of bad things out there. It's like saying another data breach happened. Okay, big deal.
People don't care. They move on, right? They don't pay attention to this.
I think it's more when I see articles like this or studies like this, and I understand, you know, GitLab had it commissioned. It's really what are we doing to help people develop secure software or secure the supply chain, whether it's coming in from, you know, docker base images or open source, um, repositories and package managers, things like that. I, I think we have a lot to address in our supply chain security.
Um, but I don't think throwing around numbers like this study does helps us much. Okay. So what, what are you gonna do about it?
You know, it doesn't point to any specific remedies that you would take, um, other than of course, I'm sure GitLab would be happy to talk you what they do, and they've got some good stuff to do it as well. So I I, we have a, I think we have a long way to go. And it's not just the software that we are building, it's also the underlying tool chain that we build it with the technology platforms that we're using for our pipelines, flowing through DevOps processes and to release it into production.
'cause those are, that's, that's where the supply chain tax are also happening. Let me ask you this. So one of the things that is in the study is that, I think it was about maybe a third of organizations are actually doing something around DevSecOps and about an equal number, or actually training developers going to Black Hat this week.
You know, who's not going to Black hat this week? Developers. Exactly.
Well, that they go to RSA. No, they don't. They do.
I'm kidding. Um, look, both RSA and Black hat are security shows put on by the security industry for the security industry. And in spite of all the shift left and all of the things we've spoken about, about getting, you know, breaking out of that silo, we've also discovered that developers don't wanna be security administrators.
They, they care about quality, right? They wanna develop. No one says I wanna develop insecure code, but, you know, they're not security pros and you're still gonna need security pros involved in this.
They need to be brought into the fold of the broader IT team, not bring everyone into the security team per se. Right? And I think that's an important distinction.
Um, you know, until all of our code is written by ai, and John, I know you have thoughts on that, um, this is what it is. You know, this is, there's gonna be security issues. All of that being said though, I, I would venture to say that our software ha is of higher quality now than it's ever been.
And we continually do improve it. But this is not an easy problem. And people who want simple solutions for hard problems, that's a big problem in this country beyond cybersecurity.
And I wanna, it's hard. I want, yeah. I wanna point out that there's some reasons why that that study may have said that deployments are happening more frequently.
One of the reasons is that we're more companies are moving, uh, to a decoupled architecture. Mm-Hmm. Which means smaller parts are moving on a, on a, a more frequent basis.
Um, secondly, when those smaller parts move on a, a more frequent basis, it's pulling in more, uh, open source, potentially open source packages, which is where most of the vulnerabilities are being found. So now we have replicated those vulnerabilities across multiple containers. So as Alan's pointing out, this is a, this is a complex problem, and as we try to get on top of the vulnerabilities, um, we have more vulnerabilities coming.
So it's like an avalanche. And you know, I'm gonna say that for, you know, at Black Hat here, you can talk to anybody out there about the market for zero day vulnerabilities held us back for years. We had not only the government, but the big companies not, uh, announcing and not telling us about those vulnerabilities.
So we're way behind, we are way, way behind the, but the final point I wanna make here is that I don't think that we can code scan our way out of this problem. I believe that the chaos, the, the, the theories around chaos engineering and the ability to respond to vulnerabilities, high risk vulnerabilities as quickly as possible, is where we should be thinking. And that is, that is in that DevSecOps, uh, uh, kind of responsibility layer.
And yes, security needs to come over and start working with the DevOps teams to start solving these problems, but I just don't think we can stop them from coming. I think we can, um, decrease their, uh, their, our exposure to them. But we've gotta get better at fixing things in production.
Um, kind of like CrowdStrike, right? Why did it take so long to fix that? Why, why was it a problem that had to be, I literally had to reboot servers.
That is a, that's a horrendous way to have to address a problem. But anyway, um, we've, we've gotta get better at response and figure out, you know, what happened and the root cause analysis later. And I keep talking about this and I hope that people start hearing me and saying that we've gotta figure out ways to respond to these vulnerabilities as quick as possible.
'cause I don't believe we're gonna ever have a perfect software supply chain that has no vulnerabilities. You said several really good things there, Tracy. One, one that I wanna highlight is, I believe on every CISOs scorecard, uh, is should be their ability to deliver software to production quickly and smaller bys, smaller packages.
Uh, because you, you may not need to deploy 10 times a day, you know, just in general it updating software, adding new features. Maybe that's, if your culture is not ready to accept software that quickly, that's something you're working towards. But the day you do have a problem fix, we need to deploy an open source, uh, bugging our software that's got a vulnerability, whatever it might be, or something really serious happening that's causing corruption or security issues.
The ability to get, get something into production reliably and safely is extremely important. 'cause you don't want to try to jam it down the pipeline and get it into production and just hope that that fixes without any collateral damage to, to other issues. So my my point is, your ability to deliver software, um, under an incident into production is as much of your security posture as any other measure.
You know, it's interesting, you can apply this study to almost any industry. You think classic American capitalism in our haste to produce too much too soon. We sometimes sacrifice quality and safety.
And if you indulge me, Alan, remember Upton Sinclair goes all the way back to the jungle. Mm-Hmm. Trying to mass produce things as fast as possible.
And sometimes that comes at the cost of the health of your workers, of the consumers and software is no different. And The environment in general, right? Yeah.
Right, right. So it's repeating itself. I think Tracy's right, we'll never solve this a hundred percent, but I do wish maybe we would take three days outta every month and just focus on security technical debt and go back in and kind of clean up our mess a little bit and take some accountability and responsibility for this stuff because it's not happening enough, in my opinion.
In a country where half of the people don't have a dime say for their retirement, you think they're gonna take three days a month down to thick slope wear? Yes, I do. Yeah.
Wow. I can wish Birthday Mike. There you go.
Um, alright. Hey, I think that's gonna call it a wrap on, on text strong gag. John, Tracy Mitchell and John, thank you all for joining us, Mike.
Thank you. Uh, you'll be holding down the fort here while we're out in Vegas next week or this week. Party all week Long party.
Well, it is his birthday party. Mm-Hmm. Um, until then though, this is Alex.
She will enjoy your Monday. You've watched Textron gang, we've got a full Textron TV lineup coming up right behind this, so don't go anywhere. Thanks for joining us.
We'll see you tomorrow. I'm Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from strong research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research.