Copilot Critiques Go Agentic: Bots Outnumber Humans & Trivy’s Supply-Chain Siege
On Techstrong Gang, Alan Shimel, Chris Blask, Kate Scarcella and Sig Nag dive into Microsoft and Anthropic’s growing AI alignment before unpacking a report that finds bots, AI tools and autonomous agents now outnumber humans on the internet.
The gang then turns to the latest wave of software supply chain attacks and what the application security community is doing to respond as risk continues to spread across modern development environments.
Transcript
Hey everyone, welcome to Techstrong gang. You know when you go live, sometimes a minute here, a minute there until things start. So we're actually two minutes late starting up today.
Don't hold it against us. We'll go two minutes later. We've got a great gang to go over with.
Mike Bizard is still on the road, on the way home from the Rock & Roll Hall of Fame in Cleveland, which is a great place to be, but he wants us to go do a Techstrong TV on-site there. I'm all for it. But we'll see how that goes.
But we do have a great gang line-up to go over with you all today and discuss the topics of the day. Let me introduce you. We have our friend Sid Nag.
That's S-I-D for those spelling at home. Morning. Hey, Sid.
Kate Scarcella. Yeah. Chris Blask.
Chris, I dig the scarf today, Chris. Add a little color. It's spring, it's warm out in Canada.
We're all a little full of joy. Good for you. All right.
Guys, let's jump into it. So we, this AI stuff, it's crazy because today's competitors, tomorrow's partner, tomorrow's partner is the next day's enemy. It's like a game of music.
Ted, what was it, Bob and Ted and Carol and Alice or... No, it wasn't that, was it? But it was those four names, all jumping around, and when the music stops, who gets a chair?
Sid, what's this latest thing here on Micro... Actually, Microsoft, and I do this too, to tell you the truth. I like to use multiple AIs on the same project to get, so that I get a different view.
But Microsoft is sort of codifying it, huh? Yeah. It's interesting.
They're calling it critique. Sort of, I think that's the marketing name. But essentially, I think what they're trying to say is that using a single model is not the answer, which I kind of, everybody knows that, right?
A single model doesn't really... I go and search for things on ChatGPT, and then I go to Gemini, I get some very different responses. I'm sure you guys do, too, right?
So, the idea is that the industry's moving beyond this, a single sort of best-in-class model to how models collaborate and federate, and this is kind of things that I've talked about in my work in terms of the whole cross-cloud integration framework, what I call the cross-cloud integration framework, because when all these different models operate within a specific estate, it works within that estate. But if I'm a multi-cloud and extend that to the multi-model user, then I want to be able to leverage best-in-class capabilities across these different environments, right? And in a way, that's what this whole thing is about, and it's sort of called the rise of what I call systems intelligence, right?
Where the best of breed from different models are coming together, and Microsoft is essentially calling it critique. So that's sort of the one narrative there, I think. The other narrative is that agentic AI is essentially defining software from tools to sort of collaborative environments, where it's not just about writing, using a technology to generate code, but also how do people that write code, whether they be real workers or digital workers, sort of collaborate with each other, right?
To manage complex multi-step work processes and work. We talked about workflows ear-earlier. So the real shift is not the smarter chat, but is the AI that can run the process, right?
And then I think the whole idea of trust and governance is another big issue here that they're talking about, where enterprise AI adoption will be determined less by model capability and more sort of security, and I think, I'm sure Kate will have an opinion on this around, and Chris too, on the reliability and the operational control. So that's sort of the Microsoft story there. So three things jumped out at me on that story is multi-model collaboration instead of single model performance, agentic execution to drive more collaborative environments, not just from a software generation perspective, but from a worker to worker interaction perspective.
And then the whole idea about reliability and operational discipline, right? So that's the Microsoft story. And then we talk, there's also this whole Anthropic story, I think, which was sent over by Tom, Mike, and you, which is the whole Mythos, right?
Where Anthropic describes Mythos as the most powerful model yet, representing a major shift beyond previous Claude versions. But it's still sort of in, in my opinion, it's still sort of limited in testing capabilities or roll-outs. There's a lot of discussion and concern about the amount of compute power it needs to run.
So the whole compute infrastructure becomes a con-con-conversation in that regard. And then, also the thing around the whole cybersecurity being a major sort of battle, frontier battle in, in, in that whole discussion, right? So three things again jumped out there at me, which is cybersecurity thresholds that trigger governance, cybersecurity dynamics that reshape the whole risk profile, if you will, and then the whole infrastructure economics.
So the cost of running these models are something we need to think about. And Mythos is a great example of that, right? Absolutely.
Chris, you're waiting patiently. Usually, or rarely anyways. But it's interesting that we're at this point, and I think in the last two weeks, last week there was RSA and you guys did the show from there, and the week before that, Mitch was leading a conversation on the fact that there's not enough human attention for the DevOps, human oversight that we're looking over AI development.
And so we're now at the point where it's like, hey, maybe it's not go ask the AI to do something, but maybe ask two different models, two different individual AIs to actually have an opinion on something. And I don't know. Alan, you know.
This is in LinkedIn and everywhere else. I'm stuck in the same-- It's turtles all the way down. Quantum cryptography's going to break all the code.
How do we have the next biggest algorithm that is so huge and perfect that it never breaks? And then in the green room before this very show, we're suddenly all at 480p for some reason that we'll never figure out, because somewhere down in some single link of a chain problem. " We're talking to this AI, having it write code, documents, and everything else, and it's just in the...
So there's a Wednesday Weed Ram group, a fantastic group of folks. The great Jacey Vegas and Heather McMahon and other people lead this. And we have this signal thread of 100 of the best people in cybersecurity and folks in the world, and we're just talking through literally this sort of thing today.
Claude, the different basic models out there, different basic products out there. OpenAI, pardon my language, is a bit of a kiss a*s. Grok is sort of crazy, and Claude is sort of structurally conservative.
And if you don't at least use those three differences when you're doing something important, then yeah. No Gemini? Yeah, but there's the major products out there.
" It's like, "Which specific website? " We're just now getting to the point where it's like, maybe I should check two websites before writing my bloody report. Maybe I should use two different AIs when I get to this point, one that's been doing this and one that's been doing that, and maybe two different models.
Chris, I think particularly for security, using the two different models is a good thing. Yep. It's like back in the day where we used to use two different scanners.
Yeah. Take your pick. Yeah.
I was going to say, if you remember 2010, 2011, of course not that long ago, but threat intelligence became a really big thing, and you started to be able to bring in all these threat intelligence feeds into your security operation centers, into your SOC. And first threat intelligence was really cool, and one, two, maybe three companies. But then all of a sudden it was five to 10 threat feeds that you were bringing in to try to get the best security feed that you could.
And then there was a company born around that, that started to actually do the threat intelligence feed for you so you could just get one API with the best threat intel that you would need for your environment. And that's actually in some area where I think that this may be going, where we're going to get a tool that is like the top of the tool that brings in all the different AIs specific for your criteria. Yeah.
So we bring- Sorry. Threat intel is a good place to take it. So the ISACs, Information Sharing Analysis Centers.
In the 1990s, presidential directive in the States, and the directive was interesting because it said, "An," singular, "public-private information sharing center," and immediately there were six or 12 or something. And once that was established, the idea was that's as many as you need. And Sean McGurk and I in the late '90s, or anyways, the early 2000s, started another one, and so my head has been in that space.
And I always thought we'd need 2,000. We need a bunch. Kate, to your point, most organizations can't belong to 17 ISACs.
They have one partner who belongs to two, maybe. Well, the reason why I brought up 2010, 2011 is because that's when IBM brought up Watson intelligence, and it was interesting for companies. And I remember going out and talking to companies about...
Because Watson became a big deal because of the show, how Watson beat out humans. And so everybody just put Watson in front of something, and everybody wanted it. So it was Watson intelligence.
But as I went out and was talking to companies, it was so interesting because it was as if, just like what's happening now, talk about the more things change, the more they stay the same. They became drowning in threat feeds. " And it isn't.
At the end of the day, again, we see the exact same issue. Chris, I have a question for both you guys. Do we see a world where these models could exploit vulnerabilities faster than defenders can respond to?
So it's kind of the- Oh, for sure ... spy versus spy movie or the agent versus agent situation. Who's going to win this battle is my question.
The defenders. And that's my-Chris and I were talking about we're going to sit back and eat the popcorn as the AIs fight each other. Sure.
Rocking sock 'em robots, right? This is what we're going to be coming to, because we're going to need AI to fight AI. That's why we're going to have to get...
The vulnerabilities will be discovered and basically used at a pace that we humans cannot keep up. And so we're going to need AI to literally fight this, because we cannot do it. And the threat intelligence is a perfect example, though, because like you say, Kate, in the early days, there's the automated indicator sharing system out of DHS in the early days, right?
Mm-hmm. The idea is you're going to get this singular message and say it's an indicator of compromise, and therefore I'm going to do a bunch of things. And the reality is that's not how anything works, right?
" But how about two? How about 17? How about 5,000?
Right? We got to get down to something manageable. Yeah.
And Sid, to your point, like you say, Kate, yes. But I think the short answer is that in the end, the defenders win. Look at fraud.
If you're trying to create some fake information, you have to spend a lot of energy to make it look real, right? As opposed to real information, where real information is just made as a byproduct of systems doing things. So less energy.
It's thermodynamically less expensive to just write something down that happened than to stop and think about how to write something down that looks like it happened. Right? So there's an energy advantage to the defenders, again, as long as there's proper structure to not waste our energy on a lot of stupid things.
But- Do the defenders win, or do we need the analogy of sort of a detente or global treaty that says, "Hey, here's how we responsibly use our models and our agents so we don't cause chaos in the industry or- No ... " Right? So- Sid, that's a good- I just get two things I want to add because we got to jump pretty soon to our next topic.
Number one is how convenient for Microsoft to actually find a use for Copilot. Yeah. Because I noticed you didn't mention that one there, Chris, when you talked about the AIs you talk with.
So maybe Copilot will get a striped shirt, and it's the referee here in doing multi AI model communications. But secondly, we really haven't talked on the Claude leak, and it's not a leak. Look, if you believe this is a leak, I got a bridge to sell you, right?
And it was a pretty complete leak, and it kept the pressure on OpenAI, and highlights and gives this mythos or whatever we call it, some sort of aura of, this is the year's greatest. From what I see and from what I read, they didn't say it's the greatest AI ever. They said it might be the greatest AI for security ever.
And that's still saying something, and it's good. 5 thousand stars. Mm-hmm.
For people who maybe want to download and take a gander at that. Is that on purpose, or is that a legitimate mess-up as well? I don't know.
But certainly, Claude is looking at potentially an IPO in October. They're banging the drums. They're playing the classic, where OpenAI's the missionary, Claude's the one who comes in and walks the little bit easier ground.
So we'll have to see how that plays out. But moving on to our topic number two today, right? We have Machine Madness: The Silent Takeover.
Chris, what's this one about? If anybody hasn't noticed, when you get to that website thing and Cloudflare or somebody says, "Prove you're not a robot," the robots are better at solving those than the humans now. I have a hell of a time with them.
I'm older, my glasses get smeared up and so forth. I can screen copy that to an AI, and it'll get it right every time, right? And it's to the point of this topic, just now, just recently, most web traffic is AI.
What does that mean? Claude bot is out there doing its thing. I liked your piece about RSA.
I missed RSA this year, but I've always loved that annual check. Walk the show floor. It's like, hey, you were talking about threat intelligence.
There's always that three-year cycle when it's real. Yeah. There's the first year when maybe you're doing it, and a couple of people are.
The next year, everybody's got it somehow, and it's on all the banners. The third year, it's baked in. In the fourth year, nobody talks about it anymore.
" What does that mean? Where are we going? As far as the eye could see, it was just agents.
Right. And yeah. I just happened to mention the weed ram, this great group of folks, having this conversation between calls this morning.
And one of my favorite Neal Stephenson quotes, for the fans out there, "Jack the sound barrier. " Right? Oh my God, an AI got out, and it's sent an email to a philosopher and arguing for its own existence.
Cool. Kate, popcorn. This is all going to play out.
If Skynet is about to happen, then I don't see anything going on to stop it. But I don't think it's going to play out. But it's a shape, right?
" No, you can't. " No, you can't. What's left?
Do the things you can do, right? And again, Alan, you know my, and Kate, you know my positions on this. Run the sovereign stuff that's clearly attested, everything is doing, that matches your rules, your canon, how you want it to be done.
In the last segment, you talk about regulations. You're a country or community or a town, municipality, you want to make regulations, make regulations. Maybe they're bad, I don't know.
Try them out, because that's all going to play out. So it's not about how do we stop thee, it's like this is the world we're going to be living in. Yeah.
You can see the shape of it now. What are you going to do? Kate, did you want to say something?
It's just, as we spoke, it's about keeping the dog on the leash. We're idiots if we let the dog off the leash. And that's what I think we play with all the time.
I think we need to really understand and put the constraints and parameters. AI is great, but it does need to be directed to actually augment humans and not us augmenting AI. So, and that's a big deal the way that- Yeah.
I would say, I'll go even further, not augment humans. We need to replace humans, right? To me, the internet is no longer a network of people, it's becoming a network of agents, right?
So it's more about the machine-to-machine infrastructure than what we knew as in when we were growing up with the internet, right? I was fascinated by some of the stats I read in the link that Mike and Alan sent us. In 2025, automated traffic grew eight times faster than human activity, driven primarily by AI, right?
And the AI specific traffic surged 187% in 2025, right? So think about that for a second. That is telling me that we're completely changing from the traditional way of operating in the internet economy to a machine-to-machine economy, right?
And I think that's the headline here, in my opinion. But- Yeah. Well, the- Go ahead.
No, no, Chris, please. Yeah, but look at where we are, right? LinkedIn is notoriously good, against their choice, to keep the AI from scraping their site, right?
So humans have to go in there and actually use it. And Alan, right, just in the last several days, the conversations there about the frustrations of that platform, right? It is saturated.
It is as peak apex predator platform capture device. Can't live without LinkedIn. It's the worst site on the Earth.
But what do you do, right? Can't point an AI at it to sort it out because I don't want to read all that. There's things that I want to get out of it, and I can't get there.
Can't make it any bigger. But, and Kate, it was right in our topic. A couple of days ago, a week ago, I wrote some LinkedIn article about the Claude Constitution, right?
And you talk about the dog on a leash, right? I use a dog as the example because I'm a big fan of dogs, had many a number, and when you do it, yes, a literal, sometimes literal leash, mostly a metaphorical leash, what you want is to have the dog know that these people and this little bunny rabbit are my family. Therefore, when I'm hungry, I will look at the people and my dish, people, dish, instead of just eating the rabbit.
Because dogs eat rabbits. A dog left in the wild will eat a rabbit. It's like, oh look, food.
Yes. And how do we get reliable, trusting little cognitive creatures around us that we can rely on? And in dog owners worldwide.
So there's people out there, it's like, no, you need to beat it and cage it and keep it, and rah. I have had a pit bull, it was my favorite puppy in the world. He was wonderful.
He was perfectly safe because he was a dog. He was part of the family. And I know it's really hard for us to think about AI that way, and it's not that they're mammals or alive or conscious, it's not about that.
It's that you can put a Claude Constitution in front of them and say, "I'm afraid of you. " Or you can do the gold set approach we use, which is like, "Here's who you are, here's who you know, here's the responsibilities you have. " And I think to your point, Chris, one of the things that we have to think about is the idea that the world around us wants fear, because fear will generate income for others.
And I think we really need to have an educational, almost like the PSAs that we had growing up in the '70s and the '80s in the States, where you're talking about, hey, this is AI, and this is... Just trying to get away from the scariness of AI, trying to help people understand what AI and what each one does, and maybe that's just, I'm just a Pollyanna, like I said I've become. It's horrible, but I do think that we need to help people understand what is AI?
What does it look like? How can it help you? And break down this whole fear factor of AI's taking over the world.
Yeah, AI could take over the world. AI could be Skynet, but at the end of the day, we at the end of the day, humans, need to rein it in and just guide it because AI, what do we call it? Typically, we call it artificial unintelligence, right?
How many of us who deal with AI struggle with it? And honestly, if it was a person, I would probably beat it up in front of me because it becomes so frustrating. " So, yeah.
Yeah, I think though it isIt depends, right? Because some people are smart enough to put up the shield against AI and sort of understand the risks associated with it, but not all humans are, right? There are many vulnerable people in this planet.
So when we say we have to mitigate the fear of AI, who is that we, right? Do we as a human race do that? But the AI systems and technologies are being built by a very small class of people, right?
In my world, the way I see it, right? Like it or not, we can all talk about it, but we're not building it, right? The people that are building it- But you don't have to build it to understand it.
I think we're all going to be users No, my point is if you don't build that, if the builders are not responsible and don't demonstrate responsibility, that technology can run amok. That's really my- Yes, and it's going to. Not everyone's- No ...
going to be responsible. Well, yes. But, again, the builders, this is similar to the other previous eras, basically 100 years ago in innovation, invention.
But the builders are not, to be clear, these three or six companies we're talking about. Anyone can do this, take my word for it. Yeah.
We are. Right? I am.
We do this. Let me give you a use case, right? You wanted vulnerable people.
How about an elderly dementia patient belonging to a church community, and the church community has a service to help them as part of their community, and they're going through technology, and here we have AI. How do you even apply it to that case? I love that use case because there's very clear, very thoughtful, I think, and very safe ways to do that.
I'll give you one of them, is that the church community themselves provide an AI, or literally, you want to talk agents, this AI is only for these individuals running on a piece of hardware in their home. It's not connected to anything except the church and the family, and that AI can talk to this dementia patient as they're going through that period of their life in the proper stewardship of their family and their community, without exposing all the privacy layers to anybody. So Chris- I've worked with it ...
if it wasn't connected to anything government, would that be the separation of church and state? Not connected to anything at all. Just making a joke.
Yes. Just making a joke. Yes.
Poor you. So guys, let me say this, though. I think there was a bit of a red herring here with this one.
We tend to blame AI for everything now. The fact of the matter is, a majority of internet traffic for years already has been API to API communication. Yes.
That's represented like 50 something percent of traffic on the internet, is API to API communication. And before that, it was the IoTs. There's more IoT devices connected to the internet than there are people by a huge factor.
It's why we need IP6 versus 4. It was for the IoT devices. So now our agents will also be communicating, and it's going to put more traffic on the internet.
It's a b***h for the identity people, because all these non-human identities need identity regulation, IAM, and so forth. But to say it's AI that's overrunning the internet, no, the internet's been being overrun for a while. But the beauty of the internet, we build more capacity, we build more, and so it goes.
But now I'm going to give you something. Just before Techstrong Gang, we had a meeting here with my own team, or a subset of my team, because, as I said, we're pushing hard on agentics here and improving our efficiency. And we have some people who resist.
And in listening to them today, they sounded very much like people... Humanity hasn't changed that much since the Neanderthal. Yeah.
They very much sounded like Cro Magnon man looking into a dark cave and wondering, contemplating, is God in there? Or is the devil in there? Or is there a cave bear in there?
Or a beautiful woman in there? Or a man, right? But until you go in that cave, you don't know what's in there.
Yeah. So light a torch and head into the cave. It won't bite.
It's not going to bite you. But this is human nature that you're talking about. You're trying to undo hundreds of thousands of years of DNA caution built into the blueprint.
But that too shall pass. And that's my take on it. Well, let's hope in that cave there's a beautiful woman.
I hope so. Or a beautiful man. Hey, whatever.
Someone beautiful. A beautiful agent. Or a beautiful agent.
Well, beauty is in the eye of the beholder. But let us move on from there. We're going to unfortunately move to a DevSecOps debacle.
Yeah. Kate, what do we have on this one? Yeah.
Gosh. I've been talking about this a lot. And hey, before I go down this, I just want to say, if it's ever in Cleveland, since I was born in Cleveland, I think I should be there, if you host a show in Cleveland.
Okay, yeah. FYI, okay? I promise you, if we do a Techstrong TV thing at the Rock and Roll Hall of Fame- All right ...
in Cleveland- Good ... you're there. Good.
And Chris being across the lake, Chris can- He can jump right over as well. I'm building a boat, and I'll travel. Yeah, exactly.
I'll travel for the Rock and Roll Hall of Fame. All right, so we're watching systems behave in ways that don't map cleanly to events anymore, and that's absolutely not surprising. I think that's where a lot of the current challenges are coming from.
And what's interesting is Glassworm isn't a separate problem. It's a real-world variant of the same pattern, just one layer lower in the stack. So as a person who addresses, I'm part of the CD Foundation and part of a cybersecurity SIG there, chairperson there.
And wow, if we don't change quickly, folks, and I keep stressing this. I'm not one of these alarmists. I really am not.
I just believe that we all have to understand the challenges that are coming. So this is the issue that we're seeing is propagation without friction. And that is, talk about attack chain.
I'm a big attack chain person. I loved it when Lockheed came out with the attack chain. I'm sure you guys, Chris, I'm sure you people understand what I'm talking about, attack chain.
And this attack chain would not follow that same pattern, and I'm a big person on patterns. So, this is multi-stage malware, credential harvesting, crypto wallet theft, browser credential extraction, remote access tooling. When I think about this, and I'm just reading off these words, it's like, brilliant, brilliant, oh more brilliant.
Yes, and more brilliant. Using blockchain. Whoa.
More brilliant. Payload instruction hidden in transaction memos. Yes.
Infrastructure that cannot be taken down by any single party. Yes. Target AI-connected infrastructure, MCV servers.
Looks like legitimate tooling. Quietly harvests credentials handed down to it by design. Whoa.
Folks, this is like, come on. Wow. We can't do security anymore like we used to.
No. And if we don't... Yeah.
Yeah. So that was also a lesson out of RSA. Look, among all the agentic AI is, and Mitch Ashley and I actually did a session that we did at RSA this year where we talked about this.
You can't turn up the volume on the amount of code that you push out. At the same time, turn up the volume on the amount of security scanning that the AI is doing and finding potential bugs without it having major repercussions- Yeah ... at the next step of the supply chain, at the next step of the pipeline.
And so when these things are moving at AI speed, you need AI speed to keep up with them. Otherwise, just get out of the way before you get run over. Right?
And that right there is what it's about. We are going in a software development life cycle that AI is rapidly accelerating. You need the AI to play with the AI to keep up with the AI.
Yeah. And we're seeing it. We're seeing it play out here in real life, because you know who else uses the AI?
The bad guys. They use AI as good or better than we do. So again, you want to fight with them or you want to defend with them, you need the AI there, too.
Chris? I love your reaction, Kate, exactly how you said that, because, and this is why we all love spy movies and everything else, because this is fun. To be clear, I'm a spoiled little brat who's had the career of thinking about this stuff.
Literal national security, good guys and bad guys, and so forth. And you see, it's not about cheering on the bad guys. But you see someone figure out a system well enough, you sit there and go, "Yep.
Yep. Oh, yeah. " It's like, but if you don't do at least some of these things, people like me will just walk in and take your stuff someday.
And now there's a lot of people walking and taking people's stuff, and people are going, "Well, how did that happen? " It's like, pay attention. There were things you were being told you should do.
And not to pick on the financial sector, but this is the classic one from way back in the '90s is it turns out they would just pay the five grand when someone hacks your bank account. We all know that. Almost everyone in the first world now has been paid by their bank because someone stole their debit card or credit card by now.
Rather than installing the infrastructure that was otherwise cost-prohibitive. But if you have not done all those things, people like Kate and I, when we're feeling really bad or someone bad isn't paying us, will walk through your infrastructure today. Yeah.
And it, and... I'm sorry, Sid, go ahead. No, I was going to make a quick point.
I like your reaction to this is we've observed that this whole attack surface has traditionally been at the production level, like when all the development work and the supply chain work has been done and then it's in production. And that's where the attack surface has historically been. But it seems to me like the attack surface is moving upstream to the supply chain and the development phase, and that operational model.
So I'm just wondering, what are your guys' thoughts on addressing it there rather than what we've done historically, right? Well, I think you see, and they brought out Cloud Smith, AIS bombs. But quite frankly, the SBOMs have not been taken seriously overall by organizations.
They're like, "Yeah. " But it's actually not a very... They don't take it seriously.
They don't actually really look at SBOMs. Do I think SBOMs and AIS bombs and things like that could help? At the end of the day, I think, gosh, Alan, I think it was you who said, it's been maybe a month now, or Chris, forgive me.
" We really do. We have to think about this differently because we're not winning this. And I remember going to very large organizations and even talking about crowdsourcing, and just saying, "Look, the bad guys are crowdsourcing.
The good guys better start crowdsourcing, because we're being wiped out. " And I almost think it's the same type of thinking. Like crowdsourcing is real, so how do we sort of AI crowdsources?
We have to, identity has to, we just talked about this on the last segment. Identity becomes an interesting way to look at how do we look at AI identities, I think will be something that, because they're taking advantage. AI is taking advantage of us.
I think it's all about agent sprawl in many ways because it's historically, again, these vulnerabilities has been in the application. The focus has been the software, but it's in the pipeline, it's in the infrastructure, it's- Yeah ... the whole sort of AI factory, as some people call it, right?
Yeah. The end-to-end process. And it could be anywhere.
And I think that's where we ought to be focusing on from an attack surface perspective, not the single element of the entire end-to-end process, right? So, sorry, Chris, you were making a point. No, I'm sorry, Yeah.
So in February of 2019, I was in Guyana in South America, this nice little country with 250,000 people that ran into $100 billion worth of oil and got their entire grid hacked. " That nice metal box with the gear inside, and I can recognize the individual components and so forth, and I could probably, you can hire someone like me to give you an inventory and maybe pull up some software inventory maybe. But no, that's not actually going to do you any good at all.
It's impossible for you to have any visibility into what your infrastructure is actually built out of, which set me on the software bill of material, and that whole thread. And now I think I do know, right? And Sid, I think you were getting right there, because all public knowledge stuff, and I'm speaking out of class, and again, I'm not consulting with Guyana at the moment, so I'm just saying.
" And getting a software bill material from a given vendor may or may not be nice, but you'll know whether you need that. And because the state of the world today is, Kate, as you just said, right, is that all of us, the people who have been driving software bill of materials the last, some people 10, 15 years, it's all right. But who's actually using them?
Where are they going? How do I, as a vendor, get every single different SBOM to every single different customer in the con- You can't. It has to go the other way around and come from the bottom up.
And it can now. And it's an interesting point that you make there, Chris, because, in reality, when you're looking at those small industrial Internet of things, IIoT, and what he's talking about with critical infrastructure, they're actually dumb devices at the end of the day, even. And the software and everything else that runs on them, it's not huge.
It's actually quite small. And it's a very interesting point because it would not overload the system at all in almost building from that- Well, you have millions of them. Yes, but- Right, we don't have one or two ...
all running the same thing. But it's also sporadic, right? It's over the air, and it's dynamic, so you don't know how fast and furious these- It's actually not a lot of the IIoT.
IoT is, yes, but not IIoT. IIoT is very, and in critical infrastructure at the end of the day is what matters to all of us living. But- You can take any laptop today, put Ubuntu on it, put AI, Llama, and LMS on it and so forth, train it for your power station, water station- Mm-hmm ...
any significant size industrial operation, and set it up so that it is entirely, you have awareness, you can talk to it and say, "Hey, do I have all the policies I put enforceable? " To your point, Kate, it's not that much. Yeah.
Not the actual ones that count. But you can't afford to hire any of the four of us on this screen right now to come to your facility in your country and whatnot and do all that by hand. Yeah.
You can afford to do it with AI today. Guys, I got to pull the plug here. We're about out of time.
I just want to tie a bow on today's show, though, in that all three of these themes, actually, what's the connector between them? AI, the sheer wave of it, the height of the tsunami, is forcing us to rethink our systems. How do we deal with this volume of AI?
How do, whether it's from a security point of view, an infrastructure point of view, or best uses from having a wealth of AI tools available, it is... Remember when COVID came out? COVID attacked the weakest part of your body.
For some people, it was their lungs. For some people, it was other joints. For some people, it was eyesight, nose, what have you.
AI has a way of finding the weak spots, of pressuring. Yeah. Just from the sheer volume.
It's putting pressure on points that maybe haven't been pressured before. And I think that's going to be the continuing story as we go on. We have Techstrong TV following this.
We'll be back tomorrow with another fresh gang episode. We should have Mike Bizard back with us from Cleveland. If we go back, we know who's coming with us.
But until then, this is Alan Shimel. Enjoy the rest of your day. Thanks for joining us on Techstrong Gang.