Techstrong Gang – August 9, 2024
Mike, Mitch and special guests Chris Blask and Lisa Martin, CMO advisor for The Futurum Group, dive into latest claims being made by Microsoft, CrowdStrike and Delta Airlines in the wake of a massive Windows outage before discussing the state of open source security.
Then, the gang turns its attention to the state of social media following a lawsuit Elon Musk launched against advertisers and a U.S. Department of Justice (DoJ) investigation into TikTok.
Transcript
Hello everybody. I'm Mike Baer. Today we've got Microsoft Pointing Fingers at Delta.
We've got a new novel Linux Exploit. And finally, well, there's been another social media meltdown around advertising that we're gonna dive into as well. You're watching Textron.
All right, guys, we're got a new squad for today, and joining us first is Chris Blas. Chris, how you doing? Are you still north of the border, or where are you?
Yeah, I'm still in Ontario, Canada. Land of the Freight. All right.
I don't know, when, when do you head back to Florida? Well, in September, there's, uh, actually, Mitch in your backyard, uh, September. There's an salama.
DHS is holding in, uh, Denver. So I'll leave from here going into Denver, and then go back to the boats in Florida for a while. All right.
We'll make Everybody in Denver's very excited about that too. We'll make sure Border of Security's looking for you, Chris. Okay.
All right. They always are. And I think, Mitch, you were still in Las Vegas, Brett?
I am, yes. Still in Las Vegas, uh, last day that I'm here for Black Hat. So it's been, uh, quite a conference.
All right. A lot of exciting things happening Here. Awesome.
And then finally joining us from the West Coast is Lisa Martin, who is our resident marketing expert over at Fitro. Lisa, how you doing? I'm doing well.
Excited to have some conversations today about some very interesting meaty topics. Yeah, it's strange times is all you can say. So, um, earlier this week, Microsoft released a statement in response to some of the comments Delta has been making about who was responsible for, um, the Windows meltdown.
And, uh, Microsoft went out of its way to say, Hey, we made all kinds of offers to Delta to make resources available. And I think CrowdStrike said the same thing about a day earlier, and they said they were all ignored. Um, and my question first to you, well, let's go to Chris, is what do you make of all of this?
It seems like there's a whole lot of finger pointing going on, and I'm not sure how productive it is. Well, I don't know about productivity. You know, there's a lot of responsibility they blame, you know, to, to go around as well.
Right? And I thinking about this before this, uh, this episode, I kind of got side with Microsoft in this one. Right.
You know, this is, and this is critical infrastructure. You know, the interesting thing we've found since the, you know, colonial pipeline hack and so on and so forth, and the in industrial control systems and critical infrastructure is you don't always hack need to hack the valve. You know, if I can hack the billing system, I can turn off the gas.
If I can hack the scheduling system, I can turn off the planes. And if you're running Windows xp, um, on critical systems or whatever, I'm kind of joking there, but I've seen XP recently in my life. Uh, maybe that might be on you a good bit.
There you go. Well, Mitch, you were at Black Hat. What was the mood at Black Hat about all this?
Because I'm sure that it was top of mind conversations for all those security folks. It, it's an interesting mix of, uh, I would call it a delicate dance of everybody's talking about it, but they're not talking about it too much. They don't wanna point fingers.
'cause everybody knows, you know what, that could have been us. We could have done that to our customers, or we could have been on the receiving end, or we were on the receiving end of it. Um, so it it's definitely, it, it hasn't overtaken the whole conference, and that's all anybody is talking about now.
If the outage had just happened or was happening during the conference, might be a different story. So, um, I, I think what every, I think the main thing that people are, are discussing is so what do we, what do we learn from it? And the assumption is that, you know, there's still a lot of respect for crowds, CrowdStrike and belief that, you know, the, the great transparency and we appreciate that they've demonstrated what we think all people should do under, you know, trying circumstances like this.
Um, but sort of the caveat is, but if the only organization that learns anything from this is CrowdStrike, then we've had an even greater failure, uh, because this can happen to other people, other technology suppliers, it can't happen to the customers who receive that. And it's pointed out, you know, several areas where there's a lot of opportunity, let's say for improvement. CrowdStrike has, has hired a security for another security firm.
They're kind of doing what they do for other customers to come in and examine their processes and, and, uh, do a little, a deeper dive to make sure that they've done an adequate validation. You know, one of those, you know, self-assessment is not the same as a third party assessment. So they're having someone else come in and, and take a look at that.
I don't know if that's for legal reasons, but they, they're certainly do that doing that. I don't know if people are talking enough about, uh, really shoring up our distribution of content updates and, and software updates. Uh, and being able to measure as those things roll out, do it in a measured way so that there is an issue we can turn off the spigot.
We're, we're, we're open the spigot in a controlled manner, uh, so we're not putting it out there for 90 minutes and then finding out the world's crashing. So it, it's definitely part of the conversation. But, you know, it's a security conference.
We're talking about 50,000 other things at the same time. There you go. Hey, Lisa, uh, what is your impression of all this from a marketing perspective?
Because it seems to be playing out in the public in a way that we probably haven't seen in the past, and I'm pretty sure that this was not in the marketing playbook for most companies Agree. It's well, the, the, the Delta Airlines side to me is, is the most interesting piece because there's a couple of interesting things going on there. While the CEO did apologize initially for all of the disturbance and, and challenges caused to passengers globally, he also talked about very, very methodically the CrowdStrike caused outage and said, we have no choice but to sue.
I think they were, they lost over half a billion in revenue. Um, 5,000 flights canceled over almost 10,000 flights delayed. But he's been on the circuit from a communications perspective.
And that, and, and really being very frank about, um, contradicting what Microsoft and K crowds check had been saying in saying they didn't offer us any help. Um, we know that that's been contra, um, that's been Satya Nadella has even saying it went all the way up to his level. They did offer help.
It was, it was denied or turned away or there was no response. But what, what Delta is looking for is financial compensation. So the CE has been very vocal from a communications perspective about placing blame.
Um, he's, but some of the things that he said, I, and I was thinking about their tech stack being some folks saying it's, it's gotta be antiquated because why didn't this happen that United Airlines or American Airlines or, or others, and they say since 2016, Delta has had invested heavily in it, uh, opex and CapEx. But one of the things the CEO said on Squawk Box last week was that they had to manually, um, reset 40,000 servers. So that manual perspective to me, says a tech stack probably is, is quite antiquated.
Um, what they have done additionally on the communication side is the CMO Alicia gentleman who I actually had on my marketing webcast, fantastic person, great leader, was actually at an airport, I think in Atlanta, helping passengers, um, for several days. So there was a nice concerted effort on the part of a lot of Delta employees. Uh, what they also have done buried in the website is a response for customers, allowing them to be able to do things like cancel flights without, uh, penalty, et cetera.
So kind of a divergence of communications is what I'm seeing on the marketing side. Um, I think they need to be more forthright and more, um, more visible to customers who clearly are probably still feeling the waves, the shock waves from this outage. Yeah.
Chris, I am not buying the, uh, antiquated tech stack conversation because of course, Southwest has an even more antiquated tech stack, and they were just fine. So, um, if you think that through for a minute, wouldn't Microsoft and CrowdStrike know that Delta was running, you know, uh, a legacy tech stack and, um, this wouldn't be, you know, new news to them when they woke up that morning? You know, Delta's one of their best customers, right?
Well, you know, obviously I can't specifically say, you know, it's an interesting, uh, way to look at it, you know, how much would Microsoft know about this individual customer, regardless of how big they are. Microsoft, you know, bigger and they've got a lot of, uh, uh, things on their plate, you know, so I I'll yeah, and it sounds right to me. Right?
You know, antiquated, uh, tech stacks are kind of everywhere and in, in infrastructure, and I know this is on the IT side of a transportation infrastructure, uh, uh, conversation. Um, it's cliche, and quite often there's good reasons you would have old tech there. And to your point, make, maybe the communication is between, in this case Delta and, and, and Microsoft could have been better.
But I think for our purposes and our audience purposes, what lessons can we all take from this? Um, that's one, yes. Make sure you're communicating well with your critical, uh, tech providers.
But I think Lisa's, uh, topic is, is really it, you know, we talk about a lot of things in, in security technology, uh, that map directly to business transparency. Uh, Lisa, you were just saying a second about make it easier to, to more visible, um, trust, you know, the implicit human trust thing, how we make decisions as people, as organizations, as businesses is something in the, in the cybersecurity world, we talk about in bits and bytes, you know, how do we represent trust and so forth. But this is, you know, and I'm not gonna sit here, you know, assign bla I don't know, you know, the real situation in these three organizations, but I think you can see the, the results as we're saying right now, one of 'em looks really silly, right?
And then reputational risk, you know, that putting your trust on the line is, can be more costly than messing up the tech. And it implies, in this case, we're talking the tech, it kind of implies reasons to question the tech. I think there's a lot of room for silliness all the way around.
Chris looking silly on this one. Um, and, and again, not, you know, hey, Monday morning quarterback, right? But I think whether it's customers, whether it's CrowdStrike, whether it's Microsoft, you can kinda look at each from each di dimension.
Number one is, you know, running with, if you're running XP out in the field or whatever version of an operating system, this clearly points out that remote remote management doesn't mean just remote monitoring and remote control logging in. It's like, what do you do in this case when it bricks a machine that the only way to resolve it is to boot into a safe mode? Can you do that from a remote device, uh, on a remote device?
And can you do that, you know, in an automated way if you need to, but at least you can. You can, you don't have to send somebody out to the field, open up the cabinet behind the TVs and, and sit there with a keyboard and try to boot the dang thing. So it, it, that's an area I think for Microsoft to look at.
And, and other operating systems, whether it's open source or, or others, is what is the true remote, uh, capabilities? Yes, you can put, uh, remotely managed power strips. So you can cycle on, you can cycle on devices over network protocols.
But what happens when you need to take it a step further and kind of get into the supervisor level, the admin mode, the, the safe mode, whatever it might be to do some work, to, to be able to bring it back up. And that's what was required in this case. It doesn't make sense to me why, so why, why was Delta so in such a worst case scenario, to go go there and do those things to bring up these, uh, computers than other airlines were, maybe they had just as big a problems.
They're just not vocal about it. I don't know. Um, you can, you can also of course look at CrowdStrike and say, all right, yes, you created a new template in your CrowdStrike Falcon agent, which helps you look at processes and other things.
And that template takes content that's updated on and on a regular basis. Um, but you also have an extreme high level, super protected level of access into the operating system to be able to do that. So you have to take extreme measures to make sure, you know, this is the, uh, Hippocratic oath first do no harm, right?
You, you don't need your provider to be the person that takes you down versus the attacker That doesn't help you either. Again, I'm being a little bit sarcastic, but you, you just have to be that cautious about it. And then, and then you have to look at Delta and say, you know what?
This is your stuff. And if you're just taking updates blindly from everybody across the world, this could happen, you know, at any time, at any time of the day in the future. And by the way, everybody else is doing the same thing, or a lot of us are.
And you, you have to look at everything and say, what has to be staged? What do we have to have control over? Maybe I don't want Falcon updating automatically.
I wanna update on a few servers and see what happens first when they're doing updates. And I, and I'll control how that's metered out to things we've kind of given over the update process to the vendors. So it updates my phone when it wants to update.
Well, what happens when it bricks my phone, I've gotta go see the, you know, the cell phone provider or the Apple store or whatever it is. So you, you can look at this from all dimensions, and I think the silliness look is really more of a what do we learn from this and how can we, how can we avoid this in the future? Because it's a super, I think, you know, it's, it's ripe for opportunities to do things better going forward.
Yeah. And to Mitch's point, Chris, a lot of times I feel like these incident management processes we have in place are written down in some book that has, you know, three inches of dust on it that nobody's looked at in forever. Um, and then when something happens, chaos rules.
So is the lesson to be learned here that we need to go in and kind of look at all our incident management plans and say, you know, well, what happens if this goes out? Or what happens if that goes out? And is that a form of, I don't know, chaos engineering, we need to look into what's, what is the lesson to learn here?
Well, as Mitch says, there's a lot of lessons to be learned, and that's certainly one of them, right, Ellen? And if I was talking directly to the, the organizations and the people involved, I would focus very hard on what you can do right now. Um, but I don't really know their situations that well, so I get a little hesitant to say, yeah, you know, kind of obvious, yes, your incident response seems to be lacking, you know, and your communications.
And you know, and, and again, regardless of the tech as we're discussing on the marketing side, you know, you can get all the tech wrong, you communicate this wrong, and you will do more economic damage to your company than the flawed net. So you obviously need to get that right, as Mitch is saying, it just seems to be some recovery problems that you're incident response, uh, uh, response plan, would it help you deal with? And it's just, you know, what we call, uh, assessments, right?
You know, of the, so the industrial control system isac, we created something called the situational awareness reference architecture to help people think through situational awareness. And we broke it down to know who you are, what you have, what it's doing, and what's going on around you. And each of those three, the last three of those four we've made a lot of advances on.
But this sort of thing just speaks to me, to me about the first, I think we as a global industry, as a community, have yet to hit the sweet spot and sweet spot in helping people figure out really who you are. So you can prioritize all these things because it's easy to time like this to say, well, you're obviously inso response, these dealing with senior remote management. But is that really the most important things?
Or based on who you are, I, I question any of our ability to really define that in any really good empirical engineering fashion. Not that it's not possible, but our mechanism is, are very mature, Right? Lisa, are the folks at Delta taking a big chance here with their careers?
Because you gotta ask yourself at some point, Microsoft responds and all this stuff is in public. Or is there gonna come a moment where the board of Delta's gonna look up and say, Hey, who's leading this company and what are we doing here? That's a great question, Mike.
I think absolutely. I, like I was saying earlier, all the how vocal the CEO has been against most, more CrowdStrike than Microsoft, but denying that help was, um, was offered, um, wanting financial, uh, retribution for the half a billion dollars that they lost. Um, that speaks, that's was very curious to me that why wasn't there a little bit more control or help from the marketing side to really make sure that the communications were handled a little bit differently and more transparently.
I think, um, there was a big effort, as I mentioned on that part of Delta employees, which was led by the Chief marketing Officer, Alicia Tillman, to actually go physically to airports and help customers. They have a great detailed response plan, but it's not as visible or transparent at Chris's point as it should be. So I think definitely, um, the board has reason to be suspect about who's running this company, who's also controlling the communications.
'cause it just seems to me that the CEO was saying what he wanted to say, and whereas I would've expected it to have gone through a marketing filter, um, to squash some of the things that he said, and I didn't, doesn't appear that that's happened. And you would think maybe a lawyer would've looked at that a little bit before. Exactly.
Exactly. Um, Mitch, has a bond of trust been broken here? And not just among these three companies, but do you think business executives are gonna be less trusting of what they're hearing from their tech folks?
'cause they're gonna look at this incident and they're gonna go, uh, yeah, I don't want that to be us. And they're gonna review all these relationships and say, Hey, you know what? Um, I'm not betting my career on these guys.
Is there something gnawing at, at, uh, the fabric of a, of a tech business relationship now, as a result of all of this? You know, it's interesting. I'm not gonna say who said this, but because it was kind of embarrassing.
I was at a, I was at a panel, uh, research researchers doing, you know, research into vulnerabilities and security flaws and things like that. And we're talking about the, the response part of this for an organization. And one expert, and he is an expert, Tom may know, know this person, um, said, well, well, just so you know, if, if it's a zero day exploit or something like that, that's completely out of your control, you get a pass.
I'm like, are you, you know what? Kidding me. Really?
Are you really saying that nobody gets a pass? Right? Um, it it, because there's the response side of this.
It's not just, you know, we didn't know about it, so it's not our fault. Well, you have to plan for the unexpected, right? You know, you may not know the unknown unknowns, but you, you do have to have a response to, or a process that you're, you're competent at and, uh, that you've tabletop, that you've ab tested, that you've prepared the organization for.
This isn't the, this isn't the once a, uh, year fire alarm test with the fire truck outside the building, we all get to walk out to the parking lot and then, ha ha ha, and then go back in. This is, this is something we have to, to game. This is something we have to make sure that our process supports.
And even if we don't have to invoke it, we have a si a situation where we might have, we could have go back and examine it and say, okay, under this situation, we did have to to, to start the process. And it can't be a dusty book sitting on the shelf, right? It has to be something.
We just know what to do. We know where the fire alarms are in the building. We know where the exit row is in the plane.
We know what the incident response process is for an outage, security in issue, whatever it might be. It, it just shows you that, um, the human side of this is just as critical, probably even more critical than what our suppliers are giving to us, because we're on the receiving end. So we have to have our ducks in a row to do that.
That's, that's hard. That's hard. Now, if in this case, you know, you could say, well, it happened to everybody in the industry.
Okay, it did, but, or not everybody, but a lot of people in the industry, but we suffered financial damage. Why? What are we doing about it to, to prevent that in the future?
Do we have the right suppliers? You know, do we wanna continue working with them? Do we need to look at something else?
Maybe if we're gonna react, don't make it worse. You know, it's one of those, let's be measured and thoughtful about what we do, but let's make sure we're prepared. Um, I remember doing a tabletop exercise on a, on a, uh, a disaster recovery scenario with an IT team that was running and, and someone said, well, if the data center gets too hot, we'll just send somebody in to open up the doors on the data center and turn the fans on.
It's like, yeah, what happens when there's a fire or a snowstorm and nobody can get to the data center? What do we do then? Right?
So you have to think about, don't assume the things that you, you think are possible because they may not be. And then how do you respond? What are all those scenarios?
Mm-Hmm. Lisa, I want to give you the last word on this. Do other tech companies need to go and tweak their marketing a little bit to say, Hey, we are a sa a pair of safe hands, you can trust us, and, you know, do we need like the Allstate commercial for tech companies?
I love that idea. That's a really, that would be fun. Um, you know, I think it, it will depend on the organization.
I think for sure. CrowdStrike, um, is probably diligently their CMO Jennifer Johnson diligently working on the messaging and the communications to customers to really clarify what happened, why it happened, how it can be prevented, and to repair some of that trust that probably was broken. Um, I've been to CrowdStrike's Falcon event before, and it's huge.
Customers love them. Uh, this is definitely brand damaging. What, what occurred?
Um, and so I think from a marketing perspective, other tech companies can learn from how CrowdStrike responds to this, because ultimately what has to be there that's currency flowing through every tech vendor customer, uh, relationship is trust. And that when, when that's damaged, the organization really needs to step up and ensure from a communication standpoint that they're swathing the concerns that the customers probably have. So I'm gonna be very curious to see CrowdStrike's earnings, I think, come out August 28th.
So just a, a couple weeks from now. I'm very curious to see how they fare and also what their message is to the extensive user base that others, other tech vendors can learn from. All right, well, hopefully they'll appoint a referee and send everybody to their neutral corners before things get any more outta control.
But right now things are getting a little wacky. Folks, we're gonna end this conversation here, and we'll be back in a minute to talk about well, Linux security 'cause Well, it's fair play. All right, folks, we're back.
And we're gonna talk a little bit about this kinda nuance in Linux security that resulted in a, something called a slick being able to enable, uh, cyber criminals to take over the entire Linux machine. And I think this exploit's been around for a little while, but I'm gonna let Chris explain it, but it seems to have escalated. So, um, Chris, can you walk us through this a little bit?
And then what is your sense of the overall state of Linux security and open source security today? Well, it'll work backwards with that. I think the overall state of Linux and open source security is pretty good.
Yeah. In certain ways, better than commercial, right? You know, it's a, I think it's a good exercise of, of the these basic open systems, free speech and so forth, self-healing, you know, let, let things take care of themselves.
And, uh, and as we're talking about the last segment, you know, the, the corporate and profit motivations, you are very real things. This is the world I spend most of my time in, so I'm, but I get it. But I, I think as we'll see through this, it's a, it's another validation of open source, right?
The, it ends up working out okay in the end. And as for the, the exploit itself, I find this most sort of fascinating that yeah, they, somebody will correct me no doubt, but it reminds me of the cheetah. You know, the cheetahs are almost all genetically identical because they are the perfect form, right?
You can't have a lot of variation and still be a cheetah. And not to say that, uh, you know, more fascinating exploits and this one will come along, but it is a very interesting stack of situations that leads us here. And as you say, this kind of exploit, you know, has been possible with variable reliability, not a lot, 40% reliability and so forth for quite some time.
What's unique about this is giving command and control of that, and without geeking all the way down into the stack of exactly how this works. I think it's another fascinating example that comes back to our sort of common theme in this, you know, this series of, of, of conversations that we have and a lot of the conversations I have, which is everything breaks, right? You know, so Linux is a great platform.
It runs basically the entire internet, you know, like huge bulks of it. And the X nexts, the Unix, you know, derived code is at the bottom of literally every device out there in every operating system. Um, but things break, right?
You, you all know, I'm, I like building boats and electric boats particularly. And one of the things I like about that is lots of motors and I, I see something with a single point of failure that's life critical. It makes me a little nervous, right?
Everything breaks, even your wonderful Linux servers will break. And for this one, yeah, if you don't know about this exploit, find someone really smart to explain it to you and see if it, it matters to you because it's a good one for bad reasons. Go.
And Mitch, you were at Black Hat. Um, I think ever since maybe long four j the open source community has kind of been beating itself up about security. What was your sense of the vibe at the conference about open source and security and what are people kind of thinking about doing about it?
Because a lot of times the issue is just, uh, there's a vulnerability that I can't fix because some maintainer has to fix it. And other times it seems like, uh, I wanna upgrade to the safer version, but I'm terrified I'm gonna break the application. How do we kinda have an adult conversation about open source security these days?
Well, I'm gonna, I'm gonna take a huge risk here and step into Lisa's domain and say, our new tagline should be, be a cheetah. That should be our, I think I'm gonna drop That for myself. Marketing people like, yeah, go back to your security conference.
Um, so, um, it's, it's interesting the, that if, if you really look at, so I was having a conversation yesterday, um, with one of our close friends in the security community community who is in a position to, to, because they manage a repository, uh, for the Java World Maven repository. And, and, and it's, if you look at how much Log four J is still out there, there's still a ton of log four J vulnerabilities that are unpatched still today, still today. You know, and, and you know, the, the problem is, it, it could be so far down the tech stack and what you, you touch, it could be in, in a layer of this, a layer of that, a layer of someone else who, who is using that.
And so updating it isn't just updating a vulnerability in your stuff. It's updating in that cascading, um, software chain, if you will, of software that's built out of other pieces of software, built out of other pieces of software. So it can be in there multiple times, and it can be in there, you know, getting all those people kind of on the court at once to run a play to get an update.
It, it takes a while. And there are, are you, you've also hit a good point, which is there are things that like, okay, be careful about updating 'cause that system's a little brittle. Um, or we just don't know, know it well enough, or we don't, do we have enough testing to be able to really know that we've got that, that risk out there?
I, I don't know what the solution is to be able to do this, but it causes me to think of, you know, maybe we should think about rethink how we do updates, how we design and architect updates to our systems or systems to be able to accept updates, um, so that they can more easily take updates. That's a, that's a complicated thing to say. I mean, there's a lot in there packed in there.
And it may, it may not be doable. May that may just be aspirational, but be a cheetah. Well, yeah, to your point about that, um, at your conference, um, the folks from CISO were there and they've been out pushing this whole notion of secure by design.
Um, Chris, I know you're connected to the government. I mean, um, how easy is it to do that? I mean, to Mitch's point, it sure is aspirational, but, um, we got a ton of stuff out there already.
So is all that stuff insecure by design and we need to rewrite it? Or what, you know, what can we actually hope to achieve? Well, Let me share.
Yeah, it's a good segue. 'cause in, in the, my government, my other private work right now, and in fact all my work right now, the most exciting thing for me right now is a really long set of acronyms. But the Department of Homeland Security, uh, cybersecurity infrastructure security agency, uh, ISAC as SBO m distributors kind team, right?
You know, so in, in, uh, the last couple years, I co-facilitated a, a, a set of working groups, uh, with D-H-S-C-A, um, and produced a document, uh, SBO m sharing roles and considerations. So right now in this TIGER team, we've just, uh, booted up, uh, under the CESA working Group, uh, structure. Over the next two months, we're gonna define the role of an isac, the information sharing analysis centers.
In that context, I find myself needing to distribute software bill materials. I didn't create some vendor or somebody else created this thing, but I need to get it to someone down street, you know, some you hospital or, or whoever. It's, and this, it speaks to exactly, to all these issues.
I think we need writ large in the internet, in the open source world, we need to embrace, uh, radical transparency, a term from the se, you know, uh, secure by design, uh, taxonomy. And I think that's, I think for security purposes, it's the right way to do things. It's inevitable.
I don't think there's any way to avoid, I think for business purposes, as we discussed in the, in the previous segment, and transparency, radical transparency in, in that context, it's everything. And again, this doesn't mean that everybody gets all information, everything's free, and we're all gonna kumbaya and, you know, live in the willows. It means that everyone who should have access to whatever information should have it as rapidly and clearly as conceivably possible, because that saves time, money, confusion, reputational risk response to incidents.
And the, the, you know, to your original question, I think what we saw just now with, with this Delta CrowdStrike Microsoft thing is a good example of three massive organizations, massive, you know, uh, uh, corporations with massive resources, still couldn't figure it out because it's bigger, not no one organization dup pick this, you know, we need systemic, you know, mechanisms for tran uh, transparency that's appropriate for the task all the time. All right, Lisa, I bet you didn't think I'd have a marketing question on this, but I do. I knew you would.
I think, I think you heard, uh, at least five or six different acronyms in the last five minutes that, you know, mean something to the cybersecurity folks, but to the rest of the world, they probably are gibberish. Does open source kind of have a marketing problem? Because we don't have, you know, this kind of call to action outta the government that says, let's rally the troops and everybody's gonna contribute, and we're gonna get corporations to work on transparency, and instead it's just, you know, a bunch of geeks in the back room having a chat.
That's always what I thought about the Lin organization. I think it's definitely, Chris, I think you get the nail on the head in terms of the transparency piece that meets to be there. But Linux organization needs to be transparent with the entire community.
Um, obviously it's, it's a quite a large community of, of, of tech folks who really, um, come together often. And I think that being transparent with what's been found, um, the level of threat, as we know, the cyber landscape is changing so dramatically all the time. Every organization, every business, every brand is vulnerable.
Um, I think that from a, a communications perspective, that is something that needs to come forward so that Linux can come at address the issue, um, talk about what it means and how organizations can prepare themselves to defend against it or eliminate it from being a, a potential, uh, cause of a catastrophic event as nobody wants to have branch damage. So I think that transparency piece that Chris talked about was really hitting the nail on the head. Mitch, we've been kicking around the term DevSecOps forever.
Um, you know, is that working Well? I, DevSecOps is undergoing a transformation in and of itself 'cause it's suffered from too many one-off labels, like shift left and things like that. And which is an idea, you know, for course for doing building in security into your software, it also means tossing it over a wall to developers.
I think the modern contemporary definition of DevSecOps is two things. One is think about the entire, uh, software that you're creating and all the elements that go into it, including things that are external, whether it's software coming off of a repository or a, a package manager, um, or from a third party update, whatever it might be. The code you're writing, the things that you're including with your code, you know, third party libraries, open source, all those components.
And, and that's about building secure software that you are creating with all of the components in it that aren't yours, and are those secure. And you have a way of, before you download it off of, uh, you know, GitHub, maybe it goes through a, your own security check process just to give yourself a, make sure that it's been validated to your, to your satisfaction. Then the second layer of it, which is one that we've not addressed very well, is the underlying technology or tool chain that we use to do the work of software creation, whether it's the IDE or the repository, or the CICD build process, test automation, um, artifact repositories, where things get located and how they're accessed, and the security of a, that entire technology under underwriting, underpinning our DevOps or development or whatever process that we're using that's subject to attack.
There's a lot of discussion here, um, at Black Hat about developers being the attack vector. If I can, if I can get a developer to download a package and that has something that gets installed on their computer or on a system, you know what, that's a great man. Talk about privileges.
I'm, I'm, I'm in, you know, the barn doors don't even need to be open. I'm already in there. So it's, we have to really rethink security both horizontally as well as, uh, sorry, horizontally.
It was vertically. Get my direction straight. Um, and think about it, think about it holistically.
I think that's what DevSecOps needs to evolve to. And there, and there's a lot of movement to do that. That again, is aspirational, but if you aren't securing all of it, you're securing none of it.
Mm-Hmm. So, Chris, how do we do this? Because, um, the developers, um, I think for the most part, security was, um, you know, uh, a class you didn't have to take.
It wasn't core. It was suggested, so they didn't take it. And meanwhile, the security people show up and they have a conversation with the developers, and the developers pretty quickly come to the conclusion that the security people have no idea how software is built.
So how do we put these two folks together in a way that creates something positive? Oh, that's a heck of a question. Um, we, I, I think, I think the answer is a human answer.
You know, working, get teams to communicate and so on. And so, but it's, I have a standing opposition to the idea that we're going, we, the security community are going to train everyone, and that's how we get security. I think it's, it's safer to assume that it is physically impossible or economically impossible, logistically impossible, temporally impossible to train everyone necessary and how to do security.
So as security people, we need to understand that and say that's the world we live in, which is why I always like working in critical infrastructure, you know, because you find out, I don't know if I shared this one, but in, in net in Columbia, there's a guy named Freddy who's been running one of the, the drinking water systems there for decades. And he now has all of these, you know, high, high tech, uh, uh, information, has the same physical building that's been there 50, 60 years, and just outside his door, he has a, a fish in a tank because of the bloody fish dies. He's turning the water off, right?
And I, and Freddy and his fish, I love that analogy for how we need to, to think through all this stuff, if it's really that important, do all the things right, you know? Yes. We still need to, to your point, Mike, there's way too much you need to know about security.
You know, it can't be this way forever, you know, a hundred years and 200 years from now, we're not gonna be training everybody who operates, say whatever people operate in a hundred years on how to do cybersecurity. But we still, we still need to, to make this better. Um, but it's, at the end of the day, all these things come back, back to, you know, what we talked about in the first segment, your incident response, assuming things break, you know, don't assume things don't break things, break your servers, your powers, your, you can go on all day and you can survive all sorts of things if you have taken it to the level that people, you know, who work out on the open ocean, you know, are, are quite good at.
See, that's part of the problem in software. We have the same basic metaphor, but it's a canary in the coal mine kind of thing, where we roll out canary updates and we see what happens and then we roll 'em back quickly, hopefully. But that doesn't happen enough, right, Mitch?
Is it? Yeah, it's, it's canary testing is great. Now what do you do if it, that doesn't work, right?
To, to Chris's point, assume it breaks anything can break, break along the chain. So canary testing might be adequate, but it might not be. And when it isn't, what do you do after that?
Right? So there, there's no perfect answer, but there is a, um, a measured response to anywhere along the process or along the technology stack or chain. Um, easy to say, hard to do, uh, to really think about that.
But assume nothing. I, I guess is the, the sort of phrase, assume nothing about what you're assuming in terms of people can get to the data center to open the door, uh, that will, that that, uh, software update process hasn't broken ever. We've never seen a break.
Guess what? It's gonna break some point or it's broken for somebody else. So that, that's, you know, Chris's, Chris's mantra of, you know, everything breaks, I think is exactly the right mindset now.
You just don't want to be in a China shop when it all breaks. All right folks, I'm gonna leave it here because you know, Mitch said the magic word assumption. We all know what happens when you make 'em.
We'll be back in a minute. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us will access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back in. Well, the legal fund never stops.
It seems that, uh, Elon Musk and the folks over at X are now assuming advertisers were, well, not advertising on the platform in some sort of strange conspiracy that is alleged. And at the same time, we're also seeing that the DOJ is kind of suing TikTok. And, um, I guess I'll start with Lisa here, but, um, is all this stuff given social media a black eye from a marketing perspective or people who you know, are gonna be less inclined to advertise?
And what do you think the ultimate outcome here is? I think that's a great question. You know, the brands that, that, uh, we're pulling out here, Unilever, Mars, CVS Health, orad are saying, you know, we have the right to put our ads on platforms that are not gonna harm our brands.
So they have to be the stewards of their brands as much as they possibly can be. We all know Elon doesn't really have a filter. So if he has marketing people, I don't think he necessarily listens to them.
Um, I think it's up to companies like CVS Health to be a a any brand to be diligent about where they're placing their ads, um, and what's just supposed to them, which was what this was concerning about with being against, um, pro Nazi content. Um, I think also on the user side, a lot of users are going to continue to flop to social media to connect with their family and friends. I don't, I don't see that changing, but I do see brands becoming much more, uh, diligent in terms of evaluating where they're placing advertisements and what it's next to.
What could that actually mean for the brand? Could it harm it? Uh, because the brand stewards are obviously gonna do everything that they can, uh, which they did in this case, to prevent that from happening.
Yeah, I see a lot of strange ads on social media and things that are linked that you would never think are linked, and you'll see a political ad next to all kinds of, um, nefarious activities, shall we say, that's being promoted. Um, Lisa, how come we don't have more control over what ads show up where? Because it does seem like, at least in my own personal experience, a bit of a mess on these platforms.
Yeah, the control piece is, um, that's such a hot topic and there's so much there that we could really dig into because the brands want control. Um, obviously the brands in this case are, that's what they're kind of, you know, really a affirming that we need to have control over where our ads are placed so that our brand is preserved. Um, I think on the user side, because we are so susceptible to just this, this kind of culture of the interrupt, um, I was reading an article this morning on TechTarget and got bombarded with other things that weren't related to the article I was reading.
And it's, it's frustrating that we don't get the chance to control that. I don't know that we ever will. Um, that's something that I think, um, would, is it, is it probably a story for a different time, but the brands are trying to do what they can to control where they show up, not necessarily thinking about the user's perspective of what things show up in their feeds that may or may not be relevant or may be harmful.
Mitch, it sounds like a technical problem to me. I mean, we got tags and we got ways of controlling what content shows up where, so how come we're not using 'em? Um, I, yeah, the same thing happened to me on the for site this morning, Lisa.
So I couldn't read the article 'cause it just kept popping up anything and everything. It, it was really trying to not let me read it. So it is, that's what it felt like.
I, I feel like if we think about this from a user experience, right? We're trying to get this information advertised is an important thing. So it's a rich part of our lives and it's what runs so much of our online economy as well as the broader economy.
Um, but we, in, in a technical domain, you know, not, not on TV necessarily, but in a web browser for example, w we use, so we essentially use a whack-a-mole interface, right? So pop this up, make them get rid of it, pop that up, make them get rid of it. And of course, I've never been guilty of doing that on any of our sites, but you know, everybody else does sarcasm, sarcasm.
Um, you know, and that experience made me rethink like, I wonder how many people I'm p*****g off right now by sticking up too much stuff in front of them and what do we need to rethink about? So immediately started go looking it at our sites. So I you, I think you just have to avoid the whack-a-mole part of it there is software control.
It, it, it's a dilemma. There's software to control this. I don't wanna allow popups.
Well, guess what? That now you don't get some functionality out of, out of, uh, part of your applications because you have had to disable that. Well, how about if I just wanna be able to disable advertising popups, not all popups, right?
Or something like that. So I think it's, we forget about the user experience. We just expect people to be click happy and click on our advertisements and which is, you know, ultimately what we're trying to get them to do.
But you don't wanna do it in a way, like, I'm not gonna read any more Forbes, ar Forbes articles for a while till they kind of figure out their, their what's going on. And sorry to pick on you Forbes, but I just happened to be on your site this morning, Chris, you are a target audience for a lot of these ads there. Folks are trying to influence you.
And, um, I guess I'd ask a question like, are you on social media and what sites are you looking at and what do you think is a good experience? Yeah, well, it's an interesting state right now. I think, uh, yeah, all we're, we're we're, what I think we're seeing right now is, is the factors that cause the major bends in these inevitability curves I'm al always talking about, right?
Yeah. So I love social media, uh, but it, let's keep in mind it's about 15 year role, right? We'll assume that's true for a moment and has been charging along in a single direction, and there's lots of problems with that.
And, you know, we've discussed them all along the way. And if you assume that that's going to be the direction of forever, you know, you're assuming it certain a number of things, my assumption is that that will go on until it reaches eight point and then it will inflect. And the fact that we have, you know, to our story of the day, um, you know, somebody suing their customers to be clear, the advertisers of the customers we're the product in social media and almost all social media.
That's what social media is. And when you start suing your customers as, as a, as a response to business issues, I think it may not be a really great idea. I think the legal side, you know, I, i, if I was one of the people being sued, I'd more be more worried about, uh, you know, shareholder lawsuits if I made the choices, you know, if I, if I advertised in ways at risk, the company's brand, their reputation in the ways that they're, they're saying the reason they pulled out.
Um, but we're reach, we've gotta, you know, social media is real. I love social media. I'm on Facebook.
I I have a lot of, you know, walled garden social media. My Facebook is, is, you know, the, a list of folks like us, me and Mitch, you know, us technical people, we like to have a place we can talk public enough. Um, but it's moderated and managed.
And for most personal purposes, I'm not a big fan of standing in the street corner social media, shouting at and arguing with every random person on the globe who wants to come by. Um, so X and platforms like that tend to lean into that, and they're running into these sort of problems. Um, not terribly surprised.
It seems to be about time for that. But, you know, again, media, you know, here we are, we are media and we're that we're part of the transitional thing between, you know, what used to be newsprint and three stations on TV when we were all kids and so forth to the Andy Warhol, you know, everybody's famous from 15 minutes, uh, uh, future. And it's, you know, there's things you can get away.
Yeah. Again, you know, to our point here, social media has gotten away with a lot of stuff because it's brand new and it's, but it's gotten to a scale. And this individual lawsuit is an example of where we are right now, where people can make these serious allegations and serious legal, uh, conflicts over things that we all know aren't.
Right. Last week in an episode we talked about, uh, um, intellectual property that night, similar to sort of comments, right? We're at a spot right now where our privacy, this privacy we're talking about, everybody understands this.
Everyone on earth, everyone in America, everyone in Canada, they all get these issues. Now we can start having those big conversations about how do we address 'em systemically so that we don't, I am trying to stay outta the weeds on this one. You know, the, yeah.
Having an individual own personally a, you know, a social media platform on the scale of nothing history has ever seen before, newspapers, and, you know, television stations don't compare without the, the, the frameworks or railings and so forth to make it at all predictable. I can't let Lisa, I get it a little suspicious when I see like tons advertising in these in a way that interferes with the user experience. Is that just a symptom of the fact that maybe the business model is flawed?
And do we need a different business model for these social media sites that doesn't necessarily always depend on some type of overt advertising? Yeah, that's a great point. I think I, I feel, uh, I'm a social media fan, like Chris says, I'm a big Instagram fan and, and the, and the ads that come in are really well chartered into me.
I do a lot of shopping through that. I have to say IF for it every time, like, how did they know I wanted this? But I think that, um, you know, brands, it, it, but, but on the, on the, the media sites, like we were just talking about, a couple of examples, um, Mitch and I, um, that's becoming really bombarding to where the user experience is declining or, or users' churn and like this, look, I'm not gonna look at this particular site for a while because I can't read the content that I'm looking for.
So from a business model perspective, brands really need to understand how are they impacting the user experience, um, with too much advertising that's having the opposite effect of people saying, I'm outta here for a while because I can't get to what from you site, whatever site it is what I'm looking for. So I do think that it, it requires a reevaluation of business models and think that you bring up a really great point with, with that, Mike. Yeah.
Let me ask you this too. It's the political season and are some of the social media platforms are taking, shall we say, or it feels like they're taking sides, and does that just push people to the platform that they kind mentally align with more so, and so if Elon is out there backing Trump, well then you're gonna get all the Republican minded people there and the democratic minds will go somewhere else. I mean, is that kind of Yeah, split?
I think definitely, I think we see it with the mainstream media as well, folks blocking to Fox News versus folks blocking to M-S-N-B-C or, uh, or CNNI think that i, I, I wish that brands wouldn't influence, wouldn't state their own opinions. Elon, like I said earlier, doesn't have seem to have a filter. Um, he's going to do what he wants because he's gotten away with it for so long.
But I think it's ultimately a brand's responsibility, social media platform's responsibility to be neutral. Um, I get them serving up content. If I'm searching for tons of things on Trump or Kamala Harris or JD Vance for them surfing up things to me that are related to things I've been searching for, I think that's fine.
But I think, um, they, they really owe it to the, the mass public to be as neutral as possible. And we don't see that from some of these leaders. I feel like we've forgotten them.
Michael Jordan rule, right? Republicans buy sneakers. I dunno if you guys remember that, but, um, somebody, I don't Remember that actually.
We Do. All right. Somebody asked him, uh, you know, why doesn't he take more of a political stance?
And his response was, Republicans buy sneakers. So I'm trying to be neutral. So something that we should all consider.
Um, I guess my, the last phrase I, I wanna have on this is maybe I'll give it to Mitch. Um, do you think that, uh, it's just effective to build a community these days? I mean, we see, say Reddit maybe being more of a community driven thing than just these kind of like spray and pray kind of approaches, which is how I think of X or Twitter, formerly known as Twitter.
Um, so is there, you know, to Chris's point, are we seeing groups of people flock to different platforms because those platforms are better designed for groups? Well, there definitely are platforms, right? It's a great example of, it has more of a community feel to it.
Um, maybe you could claim Facebook as that. I, I don't get that sense from, like, X doesn't to me have a community feel, um, as, as much as maybe some other platforms. So I think it's, I think it's a matter of kind of what the purpose of the platform is, right?
X and X has a such a mixed purpose, um, across so many domains. Whereas people tend to go to Facebook because they wanna keep up with family, friends in college or high school, uh, acquaintances, whatever it might be. Um, you know, LinkedIn, we're there for business.
So like when I see a political post on LinkedIn, I'm like, what the heck are you doing? Get outta here. I don't really care what your opinion is not right here.
I don't, you know, express that somewhere else where it belongs. So, you know, my, my, uh, my wife who is extremely wise about many things says to me, Mitch, just because you can doesn't mean you should. And I have to remember that a lot.
And I think that's, that's applicable for whether you're the C-E-O-I-I, you know, I, there are so many things about Elon Musk I don't like because of his political stances. And, and people now are aligning on brands based on the political stance of the CEO or the company, um, the, the CEO of, um, of a pizza company. You know, if they're step forward and they're very visible and politics will create, guess what?
You're, you're also gonna turn off a group of people as well as maybe attract a group of people. Do you really want half the population to say, I'm not gonna buy from Overstock because they're aligned with Trump or this company because they, they like a Harris or somebody? Yeah, I think, I think leaders, just because you can, doesn't mean you should contribute to whoever's campaign you want, but you don't necessarily need to be out there.
You know, there are other people that could buy your product and, you know, I won't buy a Tesla 'cause I don't agree with, I dunno, there's a lot of things I don't like about Elon Musk as brilliant as he is, and, uh, you know, he's smarter than I, uh, and richer than I will ever be, but that's all right. I don't need to give him my money. Other people that do align with him can.
So I think it creates such a backlash in this social environment context, whether it's on social media or, or not, that, um, leaders are, I think leaders are making huge mistakes by being so vocal about their politics. Lisa, as a result, and we'll let you finish this thought out, but, um, are we kinda, as marketers out there, are they becoming collateral damage in a, in a larger context conversation or somebody else's war? I'm thinking about, you know, what happened with Bud Light and then they got sucked in and, you know, it was just basically a beer commercial.
At the end of the day, if you didn't like it, fine, you don't have to watch it. But it became a much bigger thing. And, and so our market is gun shy of social media.
I don't think they're gun shy. I think there's a lot of, uh, Budweiser example is a great one that you bring up a lot of examples that, that they can learn from of what not to do. Um, Mitch is nailing it with the taglines today.
Just because you can, doesn't mean that you should, but I don't think that they're, they're being gun shy. I think that what they have at their disposal is much more data to become much more data driven and insight driven to, to be following what it is their users are telling them that they want to see. So I think they have at their disposal kind of an, an army of, of tools to become much more prescriptive and predictive, um, and less, um, offensive.
Um, now that's, so are they gonna take that stance? Are they gonna take the stance of, of being too, um, you know, aligned with one side or the other? But I don't think that it's, um, I think it, I think there's a, there's a really good opportunities there to refine how brands are communicating via social media and delivering what it is that the users are demanding and expecting.
'cause ultimately everybody wins in that case. All right folks, we're not gonna resolve this today, but I would remind everybody of the original social media site, it's a park in London. You can stand in a box and yell at anybody walking by and share your opinions and if they might even yell back at you.
And sometimes it's actually a lot of fun, maybe more fun than social media. Hey guys, thanks for spending the time with us and thank you all for sharing your insights. As always, Mitch, Lisa, Chris, great stuff.
The rest of you, please stay tuned. We have a huge amount of content coming right after this, and all of it is as riveting and as compelling as anything you're gonna find on social media. See you later.
I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research.