Techstrong Gang – August 8, 2024
In this special edition of Techstrong Gang, Mitch Ashley, Jon Swartz and Alan Shimel check in live from the Las Vegas scene of the Black Hat hacking conference. Mitch, Alan and Jon give you a bird’s-eye view of what the themes and big stories are at this year’s Black Hat. If you didn’t make it out to the conference, this is a great way of staying in the know.
Transcript
Hey, everyone. We're out here live in Vegas for Black Hat. This is gonna be a great special edition of the Textron Gang.
Hi, everyone. Happy, uh, Thursday to Your Greetings from Wonderful Las Vegas, where it's hot enough to roast meat on the streets. Um, luckily we're not out on the streets.
We're in our studios here at the Luxor Pyramid directly next to Mandalay Bay, where Black Hat's going on, and we've got a special edition of Black Hat Techstrong Gang. I'm joined today by two of our, my fellow, uh, tech strong correspondent and gang members who have been covering Black Hat with me. Let me start off, first of all, attending, I don't know, his 20th black hat, maybe more, something Like that.
Yeah. Uh, my friend CTO here at Text Strong as well as CTA at Futura. Mitch Ashley.
Mitch, welcome. How are you? It's Hot enough.
The eggs are cooking eggs on the street. Absolutely. I, I feel like when I go out there, I'm baking literally the inside out.
I'm not sure I have souls that lep your, are nothing, You know, don't pay any attention to that climate change. But anyway, but we're not here to talk about the weather. There's plenty of hot stuff going on at Black Hat.
Speaking of hot stuff going on at Black Hat, we're really happy to have for the first time in person. Yeah. At a Textron gang.
It's our roving editor extraordinaire, the one and only John Schwartz. Hey, John, How's going? It's great to have you on You guys.
Um, by the way, Me in person, in person, I, um, I had a cab driver take me in. He told me we're gonna be in a cooling period today. He said it's gonna be down to 1 0 9.
Oh, good. We had that to look forward to. Yeah.
That's Until, That's crazy. October here, I guess. Alright.
Till October. He says it's gonna be hot as hell through September. I Thought it already is.
Yeah. 54 straight days. I Mean, look for hundred.
I'm not one to talk. I live in South Florida where our humidity is crazy, but this is oppressive. I don't know.
This might fall under cruel and in human punishment to being homeless here, living on the street. Yeah. I, I actually, I mean, I mean, we're not, I don't only need to digress, but I was talking to a couple people here about how do you survive in these conditions if you're homeless.
And it was, uh, it's just gonna fry your brain. I, It's one way of getting rid of the homeless situation. Geez.
That's Not a great way. Yeah, no, don't, don't give anybody ideas. I heard they're building high Speeded Rail to San Francisco.
Uh, well, there's a project to go to Los Angeles, which will take at least a decade, but I've heard about these projects off. Well, I'm just thinking that that would make like the Homeless Express or something. Oh, Come on.
Yeah, yeah. I know. Just, just, sorry.
No, but hey, it's not all about the weather. We're here to discuss Black Hat and I, I've been going to Black Hat for a couple of years myself, I think on my first black hat, Mitchell and I probably at the same time, 2003. 2004.
Oh, 3 0 4. Yep. And, you know, I, let me just play historian for a second, guys.
I, when we first started going to Black Hat, it was at Caesar's Palace, Right? Mm-Hmm. There was no exhibit expo floor.
The, the, the vendors were in the hallways and they had little stands in the hallway, and then we had breakout sessions in the rooms and the breakout sessions. It wasn't everything in security. Excuse me.
Mm-Hmm. It was truly about hacking. Mm-Hmm.
We didn't even call it AppSec then. No, it was about hacking. You know, like, and, and I remember crazy things.
Barnaby Jones, right. Making the ATM machine spit out cash. The guy from Cisco got shut down from talking about did, uh, a vulnerability that was out there, the wall of sheep, Wall of shame.
Yeah. Ball of, oh, the Sheep. There was sheep.
Yeah. And they, you, and you know, we go from Black hat directly into Defcon Defcon still at Rio. Right.
It's crazy. Um, today's, and I said it before, today's black hat is War RSA in the Desert. So by by implication, to me, that was always sort of, well, it's an imitation of RSA and you can never be as good as the original.
I think it's a recognition of, you know, when we started coming, people that were doing hacking or research, white hat kind of work, that was a, you know, way off edge case. Only a few people were doing that, right? Yeah.
Relatively, yeah. The Rest, the rest of the folks were maybe becoming security engineers. Right.
Well, but no, it was also, you know, black Hat back then was known as the place where like the feds, Right, right. Mitch was mentioning Interact with the hacking FBI Presidents. FBI was there.
Yeah. Oh, there was a ton. And It was kind of tied together as our, it was a black hat.
Devcon. There's One thing, well, the, the previous owner and former of course owns Black Hat now, but, uh, Robert, is it Robert Moss? I forget his name.
Morriss. Anyway, the guy who started Black Hat, he started both of them. So it was a continuation though.
Def Con was a little, always a little edgier. Mm-Hmm. To tell you the truth, I didn't talk about it.
What happened to Def Con, but back then, Not even gonna go there. But Dr. Black had RSA in the desert today.
It's not edgy like that. It's all things security, and it is sort of RSA in the desert. But I'm gonna tell you something, with all due respect to my RSA friends, and I love the RSA folks, this might be bigger than RSA.
It kind of almost feels that way. So I talked to one of the organizers yesterday, and she told me there were about 17,000 people. Is That all this Year?
Yes. She thought that was a high number. I, I, I did 17.
17. I was told last year I had 40. Okay.
So if it's only 17, it's substantially smaller. Smaller. And RSA is, RSA is Just like a PT Barnum.
Well, you know what, so is this Yeah. And if you're gonna do a circus, what better place to do it? Vegas.
Vegas. Vegas. Right.
Got the best venue Here. Um, you know, but they, both, both of these shows are by the security industry for the security industry. And they're very much sort of that insider thing though, as you know.
John, you've been a mainstream media guy. Yeah, Mitchell and I, not so much. They're, they do attract a decent mainstream media, So, right.
So, uh, the Associated Press reporter is the moderating the keynote, or moderated the keynote on Wednesday, which is about election integrity and security. And I think fairly or unfairly, what CrowdStrike did was it garnered a lot of publicity, especially on CNN, today's show. So it raises the profile of the show, which I think in a sense helps the industry, but it also kind of cheapens the viewpoint for the masses.
Right. They, they have a overly simplistic, almost kind. Well, it's At least common denominator Dooms day of like, oh, something went wrong.
You know, this, these were ex that was an extenuating circumstance, high hope. Um, but Nonetheless, you know, I, uh, we, we've spoken about this on text Sean Gang, right? Yeah.
About crowd, the CrowdStrike situation. What was interesting, and I'll be very candid, I don't come here and do a lot of interviews with vendors. I come here to see my people.
And I, you know, we had a chance to see some folks last night. I saw, I've been seeing a lot of people in the hallways and the, you know, the water cooler conversations not, there was a lot less sympathy for Crouch Drive. Yes.
Than I thought there. Oh, So interesting. I, so I heard a lot of venom directed toward Delta.
And I think we did, we mentioned this in the show a few days ago or a week ago, that they, in a sense, hung CrowdStrike out to dry, or they didn't, weren't entirely responsible, a culpable. And I also heard a fair amount of, uh, side swipes at Microsoft, and it's kind of what, what, what happens, right? Right.
So there are three parties involved, but that's interesting. Why were they, so, um, what, what were they So, uh, put On I, my, honestly, my opinion, jealousy. Petty jealousy.
You know what, George Kurt's done a hell of a job building that company. We know George, of course, Mitchell from Poundstone and McAfee, and it's a decent company. Did they have a crappy QA for their updates?
Yes. Will they do that again? I bet you Hell no.
'cause you could bet before they put any updates. If they do, then you can really, you've gotta, but if they do, it's another story. But I, I said this before.
I'll say it again. It could happen to anyone. Yeah, Exactly.
And it has. Yeah. And, and that's why, to the credit of Palo Alto Networks, I've mentioned this before, they refuse to talk about this and, and, and, and Right.
Find glory. But, but how many, my, my email is littered with requests here for Black Hat to talk to companies who would say how it wouldn't happen had you used their stuff. Yeah.
What's the economic impact? What's the society impact? What's that impact?
Find some real news. Go play in front of your own house. I, I think, I mean, what I, what I get off my line, right?
Um, what I, what I've heard, and just talk kind of at the CSO level, more of the kind of, uh, security leadership one is, it's a huge wake up call for everyone to say, what are you doing? This could happen with anybody's software that you're using. Not agreed.
Not just CrowdStrike. Yeah. So they, they improve their process, but you, as the receiver of that software, those updates, whatever it is, you have to have the ability either to stage it or to recover if something serious happens.
So it pointed out a huge weakness of go set these devices out there. It's got endpoint software on it. Let's just forget about it.
Um, the other, and I said this to a, to a ciso, and, uh, he said, I just said the same thing happened an hour ago, which is, is if all we get out of this experience, and I say all besides the financial damage and things, but it's always get, if all we get out of this is a better CrowdStrike, better quality, um, better distribution of their software, then we missed a huge, really valuable learning opportunity for everybody. Both if you're supplying updates as well as if you're receiving 'em. So it's, I think hopefully, if we can kind of keep that part of the conversation going.
I, I don't need to bash CrowdStrike. I, I mean, I give kudos to Kurtz for being a standup CEO. He is the one guy who was claimed or accepted responsibility very much.
And, you know, and since he took some bullets for some other folks. Yeah. Um, and I think the, the truth always usually comes out, right?
And so we'll see, But it's not dominating the conversation. I don't think CrowdStrike is here. Maybe it is the people that are trolling to get us to talk to 'em, Probably opportunism market up.
That's just like the lowest form though to me of trying to sell a product is benefiting from somebody else's dire Situation. We would never do that. We would never do that.
No. The press, mainstream press never did that. Or product companies would never do That.
You know what, it sells newspapers. That Makes sense. Oh, the best place, best day to be the be a security salesperson.
It's the day after a breach or some incident. Right? That's Unfortunately, it's Christmas in July or August.
So my, my granddaughter would, they, she was going with her other grandparents up to Oregon, and she was asked peppering them questions about Christ CrowdStrike. Really? She was four years old and she was four years old.
All these questions about it. And 'cause so she's referring him. He goes, so how is he covering that?
What is he, what is he gonna say about it? And my daughter-in-Law was trying to be diplomatic about it. I said, I said, you know, I'm not, I don't work at, uh, Dow Jones or USA today anymore.
So it's pretty, it's more tempered, you know, it's a little bit lower temperature. Yeah. But, you know, we, we could sit here and say this all we want.
Right? We could sit here and say this all we want. But the fact of the matter is that these incidents which do rise up to the mainstream media, I think in the long run help, it does help the security business.
Because That was always So with visibility, Right? So a colleague of mine, the paper years ago, we did a book, and one of the things we found out about cybersecurity or something that was always driven home is that most people are unaware or don't care about a topic like this unless they're directly affected. Right?
So the fact that so many people, unfortunately were impacted, it raises a level of awareness, which kind of plays into, I was gonna make a pivot, I guess, to, um, Wednesday's keynote panel on Secure Elections and Integrity, which also plays into this narrative that is our election gonna be safe? I mean, this is, I think there have been more elections, or there will be more elections this year among more countries affecting more than 2 billion people who could conceivably vote than there of. So we have the us, India, France, Britain, Venezuela just voted, and it kind of brought, brought into focus AI and the generative ai and the concern that the election results may not be in, they'll be influenced in a sense by people's perception.
So they're gonna be susceptible to misinformation, um, in various forms. They already are. We are seeing deep fakes.
Nothing really huge yet. I mean, maybe we'll find out later. But there's also this one interesting thing that, that people mentioned to me where that's just the DFAS that hurt the other candidate, but DeepFakes that actually enhanced the image of one of the candidates.
Like in India, there was a candidate whose deceased father was speaking on behalf of the candidate, even though the person had been dead for seven years. And there's, I've brought up the idea. If you, if you perform, say you have a rally before a disappointing crowd and you're unhappy with the results, could you conceivably add people to the crowd and make it look as if it's Standing moment that that wasn't done in the inauguration in 2016?
Yeah. Mm-Hmm. And there will be more of, of that, um, this, this idea though, and again, it's like you feed off deception and you create this narrative narrative where people don't trust the system.
And I just go back to, so it is just gonna happen again. Yeah. So here, here's my point with that though, and why I am against it, all that does is feed into the narrative of one of the parties running in this election who want to cast doubt.
Yes. They're already, they've got their lawyers lined up and they want the perception to be that this is a suspect election here in the us. I'm not talking about Venezuela.
Venezuela's already been proven, well proven. But enough parties have come out and said that that election was stolen. Yeah.
Right. The reports, the, the reporting was done, but I'm gonna say this, I'm gonna say it loud and clear. I think the record is like 67 to zero for every lawsuit that was bought about the last elections, election fraud.
We don't have an election fraud problem in this country. And anyone who's telling you we do is just setting the narrative because they're anticipating having to make that argument. Now, is social media influencing people?
Will AI enhance social media? That that is ability to Exactly. People, Right?
Yes. But this is, there's not a new problem. AI's a new technology.
It's Kind of like accelerating the social media issue. Like going back to 2016 in particular. 2020 lesser extent.
Yeah. And there's always that fear. And I remember talking to Alex Stamos, who used to be at, um, Facebook.
Facebook who is whistleblower until he left on bed in their bad circumstances. Mm-Hmm. He says what scares him is this idea that there maybe is something happening that we just don't know about in history repeating itself.
And he thinks it's very likely. And also I think part of his conspiracy theory, which has a lot of validity, is a lot of the companies were cutting back on the security side of things during their scaling back of operations. Right.
So it's unwitting and it's a financial decision, but it's a financial decision that comes with a risk. Well, it's interesting 'cause you're not gonna pull back DeepFakes. You're not gonna pull that back.
Misinformation. Um, it's not going away. I mean, whether there's detection capabilities saying this is not, you know, real or whatever.
I heard a saying the other day, it kind of resonated with me as the, the only real remedy to misinformation is communication. What I do You say the only thing we have to fear is, is fear itself. Right?
Well, that's true too. But the know World War ii and, and, uh, who is this, uh, f the British minister? Yeah.
Or, oh, that's right. R it was fdr. RFR.
Yeah, you're right. Church. Different.
Well, can I ask you guys a question? Sure. So this, I talked to a couple people who had extreme viewpoints and one of 'em At a security conference.
I Know, well, this one was a little out there. It was like, you know, we've have a history of Chicago politics. Mayor Daley, his machine, the 60 election 68 0, 60 election.
Right. 1960 KFK and, and Nixon County. And he mentioned that in 2000, in 2004, he spoke before North Carolina legislators about how, in a sense, voter security was susceptible in terms of the actual tabulation of votes, which he, he said he proved to them.
Of course he Did. And then Chris, and then Christopher Krebs came along and tightened things up only for Trump to oust him and then try to unravel things. Is that, is there any, I mean, is there any evidence or suggestion?
I'm say it can happen. There's never been any voter fraud of any sequence or consequence in this country. Conversation comes up with what the outliers, and on the flip side, I have others who say absolutely no, no, no.
For The only outlier look you wanna say. And yeah, it's, it wasn't only daily, it was the mob and everyone else in Chicago that supposedly Joe Kennedy made the deal with, and then Bobby Kennedy turned, you know, back stabbed them or whatever. But I don't think that was what it Yeah.
Is either to tell you the truth. But in modern history, and by the way, those were still, that wasn't digital voting machines. It was very different.
Yeah. Well, yeah. In, in our country today, we have yet to see evidence of any widespread voter fraud.
And, and in Florida where I live, you know, our anti-war governor spent a couple of million dollars creating a separate police force for elections integrity. And the only arrest they've ever made were Republicans voting for Trump. Multiple, multiple types.
Yeah. So, but, and even those, they weren't enough Small numbers, but needle. Yeah.
I also think about, when I think about Z fakes, I think about just deceiving people to the point where there was even, there was a robocall, right? For Biden where he dissuades people from voting and a prime. I think there are people who generally do, do not know there is a primary that in general election.
So you, you kind of build off of that. And then there was the, uh, Kamala Harris deepfake that Musk Posted Posted, which reached hundred 50 of democracy. Yeah.
150 million views. I mean, that's, that's what worries me, actually, more than it worries Me too, Is undercutting people's confidence or just preying on their ignorance at times. So, uh, you, you did a quote of FDR I'm gonna do a quote from an another Great American s sims of sims, you know, I'll paraphrase him.
Right. An educated citizen is our best customer, Is Yeah. Right.
And yes, the problem we have in this country are too many people who are not, I don't want to use the word sophisticated, but are not sensitive enough, let's say, to, to fer it out, obvious things like this. I think we also forget that there are far more many people who don't distrust the integrity in the elections that are, you know, are fine with it, versus those that are, I think we're passeng majority, We are about the Yeah. We hear about the craziness.
We Yeah. The people running on here saying that it's illegal immigrants Exactly. Who Are voting that gets all the attention, social, the people yelling fire.
Right. And everybody else Behind building. But again, it's people who are, what they're looking to do is make the ground fertile for when they, You know, I, you know, then also I will take an arrow for mainstream media and, and, and I mean, looking back the normalization of things of people that we shouldn't be doing that with, in a sense, it kind of gives them a forum to, to mis spread their misinformation.
Sorry. And I, and it just, it even goes back to I New York Times and the way they treated Biden versus Trump's cognitive dis dissonance. Absolutely.
And CNN sells newspapers. CNN's basic idea is like, we'll give 50% airtime to each side, even if one of the sides is utterly crazy. You know, this is, this is just a flaw that just hasn't been addressed.
So, you know, again, let's Bring it back to blackhead. Oh yeah. Because I'm sorry we went off on that tangent that Jim, but it is, I mean, look beyond election related integrity issues, other themes that we're seeing here at Blackhead this year, as always, there's always a bunch of vendors out here who are looking, as we mentioned before, with CrowdStrike, right?
To step on, someone's back to get ahead there. The, there Were there. Well, uh, I ran somebody at Splunk, uh, she's part of their, um, security research team, and they came out with a survey of 1600 security executives.
And they found, and this is something we've talked about probably before, that a third of the companies or organizations they work for do not have a policy, whether it's data compliance or security compliance. And so in a sense, it's creating this disconnect. And I'm also hearing the, the, now I'll use a different word, the conflict between the top management and the rank and file.
So in the haste, again, to adopt generative AI as quickly as possible, oh, they, they are moving so fast that they're not, security is a sec secondary concern of theirs. Right. Which is always happening.
It's, it's not just Ative ai that that's not New. It's not new. Right.
But now they're afraid though, this, this technology moves so fast that in their haste to get there, they are in a sense, cutting their own throats or slitting their own throats. And there's a lot of talk about, um, for example, I know, um, Talos at, at Cisco, um, put out a blog post Mm-Hmm. Just yesterday talking about securing LLMs, which I went to a session that, um, had a number of folks from their search team.
And one of the things I was curious about is, you know, there's always traditional security, kind of what we, we started out in Allen, right? Which network security, and how much is that spilling over or expanding into software security, supply chain security, ai, things like that. And in some organizations it is many, I think it's not, but the, the attack vector, the comp complexity of the surface.
Yeah, yeah. We've Gotta protect, it's almost expanding exponentially. And if you're a security professional, it's already so many things to know, so many security technology skills, et cetera.
How are they gonna protect that? So I, I think we're gonna end up with some specialists, you know, people that are zap sex specialist, AI specialists, you know, data security. And, and maybe that's happening in a number of organizations, but I don't know any other way that a security team can just say, yeah, we're meeting our requirements.
Right. The, the Splunk person did was referencing talu and they were mentioning, um, large language models and trying to find ways to secure them, whether internally or through a third party. And this misperception that defending an LLLM is out of reach.
Mm-Hmm. Right. And that was something that she, she brought up is she also mentioned prompt and objection Attacks, prompt injection data, Parts, injunctions a way of poisoning.
Yeah. Yeah. I mean, here is the deal, in my mind anyway, AI is, is going to exert new pressures at different points of the security, uh, spectrum.
We are not gonna be able to defend those unless we employ AI to help defend it. Right. Right.
You gotta, it takes one to know one kind of thing and you 'cause at the scale and speed that needs to be done, I don't know if you could do it with humid. Um, that being said, You know, so that leads, sorry to interrupt. No, no, go.
So part of this 1600 person survey asked a question about gen ai, will it benefit attackers or defenders? And it was an even split in terms of Absolutely. I I think it is.
But, but this is the way of security. I mean, this is, I mean, yes, it faster with ai. Yeah.
But it's always, you know, what is the Andrew Shafer about DevOps is you get, the DevOps you get is the DevOps you deserve. Mm-Hmm. It's the same is true with security.
Security you get is the security you deserve. Meaning if you prioritize it and do the right thing with it, you'll get a decent level of security. If you're looking it as a cost center and a checkbox Mm-Hmm.
You're gonna get that level of security. And I think that's what, that's the message that's here. Um, but, but AI is certainly a big, big Yeah.
Here at the black hat this year. Yes. Security is friction in the AI rush is what a couple people were saying.
Yeah. Well, but security, I Mean, security is always friction. It always, I remember we did, John, we did survey, it was a couple years ago already asking developers the security slow down your development cycles.
Like 80% said yes. Right. 60% on the next question said they want security to do that because they realize they need a break in the system.
A handbrake, Something's gotta catch it. So why, you know, that made me think about what just happened with open ai, right? Yes.
Okay. More people left and, and, and I think you could probably come to the conclusion, there's a recurring theme at OpenAI, which actually applied to Meta where they build things so fast, they break 'em along the way that kind of Altman is channeling his Zuck inner Zuckerberg. And these folks, the co-founders are going to Anthropic or somewhere are starting their own companies.
I wanna ask you about that too, because that, in a sense is happening with open ai, right? Absolutely. Mitch.
No, I, I was gonna say, I think I wonder if data and all, all of our policies, and I think about all the forms that I fill out with companies that we do business with, right? Do you have these policies in place? How do you protect BII all that kind of thing.
AI doesn't work with that data. That's the rocket fuel of, of ai. Is it sort of the concern about data that will put some of the controls around, particularly LLMs, but machine, machine learning, things like that?
Yeah. Is is that the place that's gonna put some kind of sensibility of security around how that data's being used in those LLMs or, or machine learning, uh, language machine learning, uh, algorithms, things like that. Uh, it, it was interesting too.
I went to a session last night with the open cyber security schema framework, which is a collaboration, a group of a whole bunch of companies, um, AWS Splunk, a number of people, Comcast, number of folks. And, and they're working on the problem of just how do we exchange security information, right? Mm-Hmm.
Across systems. It's one thing to throw your, all all your logs into a Splunk or to a, you know, Sumo logic or whatever application. It's another to say, well, we need the context and the intelligence of all that data.
So we, because just looking at one system or one sim or whatever it is, isn't, isn't enough. So there's still just some fundamental problems that are challenges to work, and they, they're making some really good progress. I like what they're doing.
So shout out to, to the folks doing that. Um, so it, it's good to see people working on sort of the nuts and bolts of what we've gotta fix Sure. For the start.
So, but I guess my ultimate point was that in many ways, to me it comes down to the data protecting it, as opposed to how do we protect devices and all the things that we do both that too. You think we gotta take a break? I don't, I think we, we went along, we blew through a few breaks.
We're gonna take a break here on Textron Gang. We'll be right back. Hey, everybody.
We're back here, uh, talking from Black Hat. You know, Alan, I, you, we've been doing security for a long time, John, you've been covering it for a long time. For, for quite a while.
I felt like the security industry was kind of deft of new really true innovation. And I'm not being critical of other people, though that sounds very critical of it. It's just like a lot of the sameness, right?
A lot of intrusion prevent. We've been doing that, a lot of endpoint security. We've been doing that.
A lot of good things happen. So I always look for like what's new and unique. And some of it is coming up because of AI and uses of ai.
Um, but I had a, a conversation with actually the, the former former CISO at, uh, Salesforce, who also was the head of security for Xbox at, uh, Microsoft. John Alkin, I think is his last name, if I say that correctly. Um, with Aria, he started up a company two years ago and his, you know, entrepreneur story, right?
I had this problem with the company that I worked in. So I went out and I started a startup to, to address that. It wasn't quite that directly connected, but pretty close.
And, and, uh, interesting. What they're doing is, you know, we've always had this data exhaust that comes off of all these tools and applications and things like that. So they're doing some unique things around leverage that information to, and then adding more graph contextual information to say what's, what's Alan doing?
Right? What is the, what is the data objects or the applications or the, for locations or whatever it might be that you're, that are happening. And you can use that for compliance reasons.
Like, here's our policies, we have things outta compliance. And, and you can also, just to get a bigger picture, what I thought was particularly interesting, Alan, was John was talking about at some point going into an automation mode of applying policy. Like, oh, you shouldn't be doing that.
So, or let's apply this without human intervention. It reminded me of the intrusion detection, moving intrusion prevention days. But we, we have a lot of that, this kind of matured In our product, right?
Absolutely. You know what the security, the world's changed since those, those days, Mitch, where we used to be very hesitant to allow security tools to automatically take action. Right?
Not just alert, but again, it goes back to my comment before about you gotta, you gotta fight fire with fire. Mm-Hmm. When Things are going at this speed, if you are not going to play at that speed, go home.
And, and so I think we're all a lot more desensitized or more likely to allow automated security to take place now that works against you. That had, had we done a little more QA before we rolled out the CrowdStrike plugin, maybe we Well, that's the trust, right? Right.
I mean, and maybe there's assumed trust for whatever reason, company reputation Is, I, I, I don't know Until it's Not, I don't know if it's trust or desensitization. Mm-hmm. Right.
I, I, my phone was here last night, and look, there was a time when I'd go to Black Hat, I wouldn't plug my phone in On Oh, yeah. I didn't take my credit card. I, I had stayed in the, you know, I had my own incident.
But that being said, I, I logged onto the wifi here at the hotel last night. Yeah. Saw I was on, I saw your stuff.
I was watching what you're doing, And I figured as much that really wasn't me in the picture, Mitch. It was a deep fake. I Wish it was me.
It's all right. It my Facebook. I know it got you Going.
And it is on Facebook Now. It's on Facebook. Good.
Good. Anyway, the point I was making was when I did log on online, immediately a bunch of my apps started updating and I thought for a second, oh my God, on a black hat, and they're updating my apps. I, I said, nah.
It's just is the way it is. They update every time, and so far nothing bad's happened, but, um, but this is the way of the world. So I think we are in an age where, you know, automated response is the, the rule of the day.
Yeah. And we don't even know it. I mean, one things, things like the CrowdStrike and Defender and other others do is look process.
I mean, we know we down, we don't inside cars our application in our systems, so we don't even know about Yep. Can I, can I ask a question of both of you? So we, you referenced Mitch, like this idea that's true, right?
Th this, there's this concept that in, uh, cybersecurity hasn't, is there has been a lot of sameness or repetition. D what, first of all, why is that? And then second of all, does, and you, I think you kinda answered it, does gen AI create a kind of killer app movement in addressing things that hadn't been done before?
Mm. You know, I just, because I think of other industries, like even like smartphone chips, you know, they advance, advance and, and cybersecurity is kind of a little bit different, different pace. I, I think it's the, the mental paradigm shift, if you wanna think of it that way, of defending, you know, our job is to build the best defenses and to keep as much out as we can and respond if we have to.
Now we're live in a world of, everybody will get hacked multiple times. It's, it's matter of fact, your response is even more important than, than your defense. Not that it's less, but in terms of your ability, if you can't respond quickly, and that's pushed all the way up into your software development team, right?
You may not need to push 10, eight updates an hour into production, but God forbid you need to get one a patch out there quickly. You don't want it to be the first time, you know, it's like, I don't know how to, I don't know how to hit that golf shot. Well, you've hit it 20 times before you know how to hit it, right?
So there's been, been that shift both from defense to response. I think the other part of it is thinking about network security versus the entire environment security. And that's what's changed.
And Does that interconnection intertwined? It is system that, yeah. Forced, I mean, It's like the human body is like holistic medicine versus, you know, okay, here's your ctal nervous system, while there's a lot of other things happening, right.
And how do you think about, you know, but, But as you said before, we're moving back into a major specialist Mm-Hmm. Well, A specialist, but in a context of something, right? Versus I'm a firewall guy or I'm a, you know, an ops person that does just this thing.
I, I think the, the security team as a whole has to operate in a, in a context of what are we trying to protect? And the whole thing is what we're protecting, right? And some of it, we don't have eyes on it.
We don't have eyes into what's happening in the development team. So how do we fix that address that, now your question about gen ai, I think that'll make, that makes it easier to get to information that maybe easier to consume it for people working up in their career. That I don't think that's the solution.
At least not to this problem. Okay. So also, John, to your point about why we don't seem to see radical change in security, you know, I've heard Brad Feld told me something years ago about technology in general, 95% of what we see is evolutionary not revolutionary.
Mm-Hmm. You know, those revolutionary things are, are like you could, you know, they're signposts generative AI bursting on the scene in November will be two years. That was kind of revolutionary.
The move to the cloud 2005 revolutionary, the commercial internet, 97, 98 revolutionary. Everything else in between is evolutionary in security, even more so. It tends to be evolutionary.
So the security you see today is not the security we had 10 years or five years ago. It's very different. Better in many ways.
When You say more kind of, when you say evolution, is it an incremental It's very incremental. It's very incremental. I'll give you an example.
Was at an event last night talking of some friends of mine, one of them CMO at a, one of the first sort of, uh, API security companies, right? API security burst on the scene maybe four years ago. Mm.
Four and a half, five years ago. Where, 'cause we realized a majority of the traffic on the internet is API communication, right? And most organizations didn't even know what APIs they had, let alone how they were configured and what their risk was.
And, and so that first generation of API security companies job one was, Hey, what APIs do you have? Let us do a scan and figure out what APIs you have. And there were about a half a dozen companies that raised big money, had high, high market billion, you know, unicorn valuations.
And they're basically gone right now. They're done. Right.
One of them had a decent exit to Red Hat. The other ones have fallen on some hard types and we don't hear about API security quite as much as we did four or five years ago. Even two, three.
Yeah. Yeah. But there's a, a new class of API security companies now that are just focused on focused like SaaS based programs that you use, which are basically working via, uh, APIs.
Mm-Hmm. So it's like SaaS API security. It's very specialized.
It's an evolution from, and they, and they don't start with the, well, what APIs do you have? They start with, these are your APIs, here are our risk points, here's how we gotta configure them. It's that next, next level of evolution.
And, and so we see that a lot in security in general. Right. Mitchell mentioned firewalls.
I remember a time where checkpoints, oas, uh, you know, partner system and we did this, it's still secure. Right? Right.
That's how originally it boo was border guard. Before it was Strat guard, it was border. That's how border guard workers the firewall.
Yeah. Um, and then, you know, that gave way to more advanced gen firewalls and Fortinet type, you know, and net screen and Juniper. They all, you know, Juniper bought net screen.
That, but, you know, fi the firewalls today are very different. Can there be like a rev revolutionary defense app or like some sort can that happen even as you build a defense? Something That's it.
It's interesting that kind of, I I, I mean that, that's what I meant by, you know. Yeah. You don't see like massive innovation or like something that's really transformed, like generative AI hitting the market.
The closest thing to that was, uh, blockchain, which got tons of attention and lots of over Got nowhere then we're nowhere. 99% of people struggle to figure out That it's a category. Right.
Well, here, here's what, here's what I wanted to say is maybe the revolution is zero trust. 'cause that's a very different way of thinking about I don't trust anything. Right?
Mm-Hmm. Segment everything Concept. That that was definitely sort Of a revolution.
That's a, that's what what I mean by that model change A concept, right? Other revolutionary kind of concepts were, Mitchell mentioned it before the whole move. It used to be that you would put 98% of your resources into thwarting an attack.
Mm-Hmm. Protection. Now, you know, the norm is to put a decent amount of resources, if not 50 50 into response.
Okay? Mm-Hmm. Um, there was no such thing as threat intel and threat alerts when we were there.
Right, right. When we started security today. That's, that's a big business threat intel.
Right. And I could trace, you know, our friend Dove, uh, Joran, Amit Yuan's brother Dove was one of the first, he had one of the first, uh, threat intel companies. He sold it to, uh, Cisco.
Um, so there are the API security thing of four or five years ago, we do get these revolutionary new, uh, new battlegrounds, new battle, you know, places where we do battle, but, and, and then the technology to, to do battle at those new, uh, battlegrounds. It, it rises above it. But, you know, I didn't see AI babies the new one here, but AI was here last year.
You know, I'm not sure where that next new one is. Mm-Hmm. Well, it's, it security, it's traditionally been kind of the in the follow, right?
Right. Well, We Reactive, we did this then how to write, react to the action. But I, I, I'll give you the, My, my point was, I think today it's not all follow much more, lot more thoughts going into, like, you think about people talking about how do we secure LLMs?
They're not widespread everywhere yet. Right. But at least we're having the conversation.
The same thing with the quantum. Mm-Hmm. Right.
We've got quantum algorithm, quantum algorithm, quantum proof algorithms. I'll give you another example though. Coming outta this CrowdStrike thing, right.
How did CrowdStrike work? And, and you know, with that whole agent thing, so with the Wiz, which is, you know, hot company, well, depends how the market is today. Maybe that 23 B looked good or it didn't look good.
I had someone talk to me last night, I can't even talk about it, but they have plans, let's put it that way. Yeah. But it was interesting.
They, they do similar to what CrowdStrike does, but in a way where you don't need to have an agent where you don't need to install stuff into the kernel. And, and so I mean, they're smelling like a rose. Yeah.
Or like a wiz, um, as a result of this thing. You don't see them going out and doing that the same way Palo Alto does. Right.
I think there's a, you know, winners don't have to press, Right? Right. Um, but When you get to the end zone, act like you've been there right there before.
It's not, it's not like the first time. And but that being said, so is what they have revolutionary because they're doing it differently. No, it's revolutionary, but it's different enough where, you know, there's a clear fork in the road here.
Okay. And, and then going forward, there'll be people who play off that. And that, you know, when you take the long view of cyber, I, you know, I find it as, as like a, I'm a history guy or a history major.
I find that fascinating. Right. When you look at the evolution of these things and, and it's not gonna stop it.
That's, that's the way of the world here. And that's what makes Black Hat great. That's what makes RSA great and bringing it together is really, yeah.
That's what it's about. Well, you need, you need a critical mass Right. Of people to make this happen like that.
And, um, that's why I come, that's why I've been in security, right. Beyond, beyond meeting the great people. Anyway, hey, we're outta time here, John.
It's a pleasure having you here in person it to see you guys. Yeah, great to see you all person. Everybody knows you here, by the way.
Oh, they do. They, so you work at Textron, you know, shimmy. And you know Mitchell, I said you Work with him now.
Well, that's not always gonna work. Well for you, John. I just want to tell you next time, I'll just don't assume that's a good thing.
I, I don't think of ambiguity. There was a hint of ambiguity when they said that, so I, I don't make of it. Uh, but it's good to hear.
Enjoy it. Thank you. We are gonna be here the rest of the day.
We're actually gonna do some streaming. Well, actually, we're not streaming today. We are, we are doing some recording that'll follow up.
Of course, yesterday we streamed a bit. You could see that. And, uh, you know what, it's great to be a black hat, but for now, this is Alan Shimmel.
On behalf of Mitchell Ashley, John Swartz, thanks for joining us for this special edition of Tech Strang. Textron Gang live at Black Hat.