Techstrong Gang – February 21, 2025
Alan, Mike, Mitch, Chris Blask and Lisa Martin, the CMO Advisor for The Futurum Group, delve into the impact tariffs are likely to have on the IT sector before discussing the degree to which our software supply chains may be defenseless.
Then, the gang turns their attention to how artificial intelligence (AI) is being used to program serendipity.
Transcript
Hey, everyone. Trouble with Tribbles. I mean, tariffs.
You're watching Textron Gang. Hey everyone. Happy Friday.
Thank God it's Friday. It's Alan Shimmel here for Textron Gang, and thanks for joining us. We've got a lot to go over today.
We've got trouble with triples and tariffs. We've got software, software, supply chain issues, and serendipity is a strategy. Or as some might say, throw it on the wall.
Um, a lot to go over. Let me introduce you to our gang members for today, though. First of all, joining us out west.
She's still pretty in pink, not red for Valentine's Day, but think today it's our own marketing guru, radio host, everything. Little bit of everything. Lisa Martin.
Hey, Lisa, how are you? Hey, Alan. Great to see you.
Excited to break into AI powered Serendipity in C Block today. I'm excited for it as well. Any, I always like serendipity where he reminds me of the, the ice cream shop in New York.
Aw. Yeah. We used to have one down here, Boca at the Boca Resort, but they closed it and been missing it since.
But I'll be in New York soon. Maybe I'll stop. It's gonna be a little cold for ice cream.
But anyway, welcome Lisa. It's great to have you here joining us. Our man, he's not lost at sea, but he's out at sea.
Resident security expert defender of the Maple Leaf. Our own Chris Blast. Hey, Chris, how are you?
Loving life. Hankered off. Marjo key.
M-A-R-J-O-E. You can Google maps that to see where we are today. And, uh, glad to be here.
Looking forward to the conversations. Is Marjo key, uh, settled? Are there people living on there or is that just No, It's, yeah, it's an island.
It's a hundred, a hundred yards sort of north or south 50 yard east or west, you know, north of, uh, uh, the sugar loaf keys. Yep. So the Snipe keys kind of cut the lower keys in a half.
Yeah. And the east side is the quiet side. So we navigated over here last night after visiting friends and family in Key West and spend the last week with Donna on board and enjoy the manatees and in hers.
Absolutely. You're still south of Marathon? Yeah.
Yeah. Lower, lower keys. So the, the top of the floor reefs is about 300 square miles of shallow water here that these boats were designed to build for.
So, excellent. This is their home stomping ground, Enjoying the weather's. Been well, it's been a little windy up this way, but the weather's been nice otherwise, besides the wind.
So, enjoying my friend moving from the Florida Keys, which is it about, well, zero sea level. He's on sea level. Up to the Rocky Mountain Highs.
It's the guitar man, Mitch Ashley. Hey, Mitchell, how are you? Hey, good to be here.
Best Friday ever. No manatees around here, but, you know, Hey, we got the Rockies and, you know, got other stuff. No manatees, huh?
No manatees this week. All right. If you ever see a manatee out there, you let us know though, right?
Boy. Uh, yeah, we've definitely lost the coastline from Sea of Florida. Yeah, it'll be, it'll be quite a, a thing.
Alright, moving from Colorado to Harrison, New York. It's cold. It's cold, and, and we're stocking up on wine beer from Europe because, well, it's gonna get more expensive.
Well, isn't that a great segue? He's our chief content author of Mike Ard. Mike, you know, I, i I, I said something about Tribbles, but I bet tariffs.
Mm-hmm. We've got troubles with tariffs perhaps here. I think, uh, grant, you kick it off.
This Has been foreshadowed for some time now, but we've seen Acer raise prices 10% because of tariffs. I'm sure others are gonna follow suit. And we're taking a look at a little bit at how all this stuff is gonna impact technology.
The big tech companies, all the way down to the people who make laptops. Seems like everything's gonna get a little more expensive. And it's not clear to me that it's for a good reason.
But Alan, what should we expect? I think we should expect a kick in the rational exuberance where it hurts, right? Irrational exuberance.
It's what made this country great. And then every time someone pulls the plug in, and this could be the plug coming out here. I mean, look, I, I call this issue tech sovereignty, spoke about it yesterday on my shimmy, says LinkedIn live segment, and you'll be up on YouTube.
We, the consumer, meaning all of us as consumers, are the ones who are gonna get hurt here, right? Because not only does our technology wind up costing us more money, and, and let's face it, for some of us, we'll say, we'll bite the bullet and pay more money. 'cause I need it for some of us, it'll just move that technology a stone too far right?
To, to, to do. But we shouldn't think for a second that it doesn't have a reciprocal thing where our technology, our goods become too expensive for people in those markets. And some of those markets are pretty damn big.
And so this has a, a rebound domino effect around the globe that we wind up. Just that we, like, we have data sovereignty where we're gonna keep our data just on our boor in our borders. We're just going to keep our technology within our borders, and we'll all wind up driving those little bad cars that they had in the Soviet Union right before it collapsed, because we don't have access to other vehicles, right?
Because the other flip side of this is, it stifles innovation, right? If I'm, if I'm in essence selling in a walled garden, a protected market, right? I don't have to worry about external competition.
Where's my, where is my, and I can't sell to external markets 'cause I've been shut out. Where's, where's my motive for innovation? Where is, you know, where's the market at work here?
So this is gonna put a hurt. I, I don't realize, I, I think America is rah rah, rah, but this, this cuts both ways. And it's gonna put a hurt on these larger American technology companies who need the world market to make the money.
They do. We can't make enough money just selling to a US market. Hmm.
Lisa, there's a cascading effect here. And I wonder if marketers are talking about it yet, because, um, if I can't hire, or if I can't keep enough people employed, then I start to lay folks off and then it has a cascading effect through all kinds of vertical industries. And suddenly the people in who might be working for, I don't know, Dell or hp, pick whoever can't afford to buy that car, and then et cetera, et cetera.
So quite literally, are we, you know, in Alan's point about to shoot our toes off, It's a really precarious situation that we are in. Uh, over the last couple of weeks we've seen China reacting. Mike, you mentioned Ace is already saying, we're gonna have to raise our prices by 10%.
I think it's a challenge for, it's gonna be a challenge for every organization to understand how this is actually going to unfold, how it's going to impact the end user, the consumer of whatever product. It's, whether it's, um, an acce or laptop or something more from Apple or a product you're buying on Amazon or eBay. And I think that from an employment perspective, uh, organizations are gonna have to be really mindful about how they're hiring, who's on their teams, what talent they need to have to be able to combat the price increases that they're no doubt gonna have to invoke in order to survive and make the money that they were used to making.
I don't know. I don't know, Chris, you know, is this buy American? How far are we gonna go?
Do I have to wait for a laptop that's gonna be made in, I don't know. I'll pick Ohio or wherever it might randomly be. That might be, what, three years from now?
If I'm lucky. If you're lucky. I was gonna say 20, 35.
Now even I can't find anything good to say about this. So look, you know, the, you know, this is a freedoms issue, right? You know, free market capitalism, freedom of speech, democracy, all these things, open source, you know, free internet.
These are very American topics, not uniquely American, but very, this is one of our founding principles. And we've watched, and you know, maybe all of us here have had some hand in, you know, selling products to countries like China, you know, who want to have the great firewall that want to have the close this. And we've watched Russia go through this in the last, you know, five years trying to have the, you know, the, uh, every man's, every nation's an island, you know, uh, approach to things.
And in my opinion, we rightly look at that and say, fine, go ahead. You will reduce your competitiveness. Go geopolitical globally, economically, and, you know, we will stay open and engaged.
But tariffs are a thing, you know, sometimes you need to do things free, free of speech, you know, doesn't mean you can yell, fire in a theater, you know, to have, uh, free markets and, and proper, you know, uh, cap capitalism. You need, uh, some rules. And if you look at, I correct my focus on supply chain.
I've looked at the presidential executive orders across the Obama, uh, Trump, Biden and Trump, uh, and this current administration on supply chain. And I, you know, interestingly kind of line up, there are some reasons to do things. You know, the two political sides can throw this back and forth.
You did it too. You did it too. But what we're doing right now, blanket, tariffs, you know, this is the great firewall thing.
Again, we're gonna make a wall around America, and that's going to work better than it doesn't work in China, or it doesn't work in Russia. No. Yeah.
This is not, this is not a useful approach. And we're just doing a big transfer from the consumer into the government. Every tariff is a tax on every product that goes from the private sector into the public sector, which again, you know, is not particularly an American approach.
We like to have money in private hands so that people can innovate as opposed to shoveling it into a federal coffer. Hmm. Alan, how silly, when did this skit?
Because I remember being down in Florida, and you go to the mall and people would be coming up from South America, various countries, and they would buy a suitcase and then load up crap, and then they make like, they owned it the whole time. And so, you know, are we gonna see Americans doing airport overseas? Yeah, I mean that, that, but most of the goods they were buying were not made here.
They just bought 'em. Here they go game from China for the most part. Or Thailand, or Vietnam or wherever else in the world, right?
Because, you know, it goes back to Tom Friedman's flat Earth capital goes to the, it's like liquid. It goes to the lowest, you know, to the most efficient place usually. And now you're kind of messing with the natural laws of physics there, if you will.
But how bad can it get? Let me give you the worst case scenario, actually, let me, in a best case scenario, other countries retaliate and they put up their own walls. And we all live in this walled walled garden where we all keep our own, we all consume all everything we make.
And that's a best case scenario. If you believe, you know, the rose colored glasses and from the, if you believe the people with rose colored glasses, the world will come begging at their knees to please give them access to the US market. They can't exist without it.
I don't think that's what's gonna happen. So with, thus, we have this world garden where Europe is its own market. China's its own market.
The US is its own market, et cetera. But it gets worse. It could get worse.
Canada, Mexico, go make deals with China. China go make deals with Europe, as a matter of fact, Europe, China, Canada, Mexico, the rest of the industrialized world as we know. It says, you know what?
We don't need America between the six seven of these markets with three times the size. Let America keep America. We're gonna do our own ai, we're gonna do, we, we proved we can do it cheaper and better.
We're gonna do our own space systems. We're gonna grow our own food. We're gonna do our own tech.
Thank you very much. Google, apple, and Microsoft. Nice knowing you.
And this is, you know, the, I grew up in the seventies, you know, and, and watching this play out through the eighties, you know, the free market, remember the, the when the GOP when I was a Republican, right? You know, is, you know, the argument was you shouldn't be able to, you shouldn't limit the US federal government shouldn't limit an American citizens rights and ability to do commerce internationally. You know, again, certain tariffs, rules, you know, we're not talking about, well, We weren't allowed to bribe people, which you can now.
Well, right? Yeah. And just Want to throw that in.
And we won, right? The Cold War, you know, we, we got China and Russia basically to accept capitalism. I mean, you know, that whole argument that we were making back then that that has driven positive change in the world.
And now we're arguing the opposite. You know, smaller is better. Lock the doors, put up the walls, historically, as it look across nation states, that's a very normal thing to do.
You know, the modern era and the benefits we have are predicated basically on not doing that. So now we're adding to the, adding to the, the, the drag on the system, which will slow down economic growth and everything that goes along with it. Yes.
Well, one of the things that this does is it forces everyone to start looking at their supply chain and what alternatives do we have. And where it hurts is where you don't have alternatives, whether it's shipped from Taiwan or, or China, um, or, you know, goods from Canada for building homes and, you know, things like that. So it, it's, it, it's something that I, I saw this interview and I actually had someone who said, no, tariffs aren't attack, aren't attacks on us.
There are attacks on the person who makes the goods. And the interview was also with the second party who was a importer of goods. And he explained, he said, no, I've been doing this for 30 years.
It sits on the dock until I pay the tariff in order for the good or good to enter the country. And, you know, I don't, I don't eat that. That goes into my pricing to my customers.
So I think America's gonna learn pretty quick what tariffs are really about, where, who really pays those, uh, those amounts. And, you know, what's politics and what's the reality of it. So I I, I also think that a lot of this is bluster, you know, to try to, you know, pick it out the big hammer and wield it, swing it around.
As soon as you hear people complaining about it on the news, being interviewed by the local TV station, it's not gonna be pretty. Look what we've done for the price of eggs. Look those eggs, that's, that's probably A lot as it, yeah.
Let me, let me wrap up a little bit on this. You know, I lost my thought there for a second, Mitch. What the eggs thing, but what, what we have, or what we're going to have is, you know what?
Cancel my thing. I forgot what I wanted to say, right? We gonna Talk about troubles.
Let wait, wait, let me, let me jump in there and then you can kick It. All right. You go, Mike.
All Right, so let's take this to its mp logical conclusion. Would we see Alan, US companies deciding to move their headquarters outside of the US because it just made more economic sense for them to pay taxes somewhere else? Well, if, and, and if the markets are there, look, it, laws of physics don't change.
I, you know, that's a science fact. Everyone's entitled to their own opinion, but facts are facts, right? It's another hard lesson I think we have to learn.
Facts are facts. Opinions are like buttholes. Everyone has one.
So if it makes economic sense to move your headquarters outta the US 'cause you have economic advantages and selling to a bigger market, making more money, it's gonna happen. That's, that's the way of, that's the way markets work. You, you know, it, it, it is what it is with that.
And I, you know, who can blame them? Quite frankly, who can blame them? You gotta go where, where your business is.
I just wouldn't recommend calling someone else's opinion a butt hole. But that's a different topic. Well, sometimes I do.
But, but here, here's the good news. Here's the good news. If all of these countries stop taking guns that we manufacture here, think of all of the guns that'll be available here.
That's the good news. Or the guns that might never get made. It's another thought.
Oh no, we won't stop making guns. We're America. America.
We make guns in America. America meka. So I mean, it, it's gonna be an interest as it plays out.
It will be interesting, certainly nothing else. We'll take a break here on tech strung gang. Let's come back and talk about software supply chains.
There's, it feel like we shoveling sand against the tide. We'll go to our boat person right after this Discover Textron group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And if you hadn't noticed, there was a report about the Lazarus group, which is associated with North Korea as attacking various software repositories that are out there. And I feel like we've talked about this issue before, but I cannot help but wonder if these hubs are essentially the defenseless because, well, maybe all the warnings and concern about DevSecOps just gets lost in the noise. Or Chris, is there something else at work here where we can't seem to get our act together around the notion that these things are a part of the attack surface?
Well, we we're getting our head around it, right? You know, and the, you know, the, I I was just thinking I should know this. I don't know if we share the backgrounders for these segments with, uh, the viewers, but if we, we should, right?
Because there's a article, uh, uh, on the background on this one about, you know, are we defenseless in supply chain? And, and the short answer is for most organizations, kind of, yes, that's where we are. And we always have been, always have been.
This has been a known issue for a long, long time. This is about off, uh, inventory. It's no, you know, do you know who you are, what you have, what it's doing, and what's going on around you?
It's one way to look at situational awareness on that. Do you know, you know what? You have no, right?
Just inventory of the hardware in organizations has been, has evolved. Well, we have asset inventory stuff and so forth. Inventory of the actual software, what's in the software.
That's where we are right now. That's, this is, you know, when we talk supply chain now we're talking about people putting code inside the code that you actually bought. And the people who bought it from didn't Know that It was there because they're including open source libraries and whatnot.
And there's been no way logistically and economically to do better than that until about now. So the, you know, and then that background article, you know, as we're talking about in the green room, I think defenseless is the long word, is more defensible. You know, is this reasonably something that you as a small organization can defend yourself against now?
No. Um, however, you know, there are major vendors. There are thanks and other organizations have been working on this for years.
It is can be done quite well. And I think in, in the, in the right sectors with the, that have the resources and have the motivation and so forth. I think in the next, you know, in this decade, you know, in the next several years, we will see some systems that are remarkably defensible and defended from these sort of attacks.
Uh, but we're just not there yet. Not, not, not for everyone. Well, right now we talk about the software supply chain security, and a lot of that is talking about what are the software that goes into our software creation process, whether it's open source or NPM packet managers and, you know, PII for, for Python.
You know, it, it's, I think it's almost one step beyond that, though. We're at a point where we need to think about this as software supply chain integrity. Just like we do software, supply chain integrity for products, right?
It isn't just the Tylenol that someone broke into and put in some, you know, foreign substance that we don't want in our, in our bottle of Tylenol capsules. It's the ingredients that go into making, you know, the product. And in this case, we're talking about software.
And so what are, what is the integrity of all of the ingredients of software that's, whether it's libraries or, or repositories or our own, as well as the manufacturing process, our own tool chains. So we, I think we have to kind of trace it back one more step and learn the lesson that we did in the physical supply chain about it's the integrity and the, uh, provenance of where things came from, uh, in really knowing what's going into our software. And ultimately, that's where it's headed.
That's what you have to do to really secure the whole supply chain. In my cynical moments, Alan, I will look at this and I will say, wow, we've been talking about this for a while. And then I, I wonder if the cyber criminals and the folks over in North Korea like read these discussions, watched these videos and said, what an awesome idea.
And now we're gonna see more of it because they figured out that they can do it. So how much of this is kind like, you know, we kind of led them to the right idea. No, well, look, the bad guys never miss an opportunity to take advantage of a, of a weakness, right?
They're constantly, they're not, they're, they're not me too guys. They're not followers. They're always probing and figuring out.
But this is an obvious, this particular thing we're talking about here is sort of an obvious whole weakness that's been exploited number of times. Here's, here's the real facts, and I think most of our audience probably knows this. 'cause we deal with a lot of developers and a lot of cybersecurity people.
But for those who don't, let me, let me explain it to you. 80% or so of the components that go into any app that you are using today are probably open source or preexisting components that get stitched together Frankenstein style into an application. These open source or pre-ex prefabbed components aren't just existing out on the edge wherever the edge in the cloud is.
They live in something we call repos repositories. And there are some very, very big repos. Uh, the, the, uh, nexus repo artifactory, GitHub itself is a huge repo, right?
There's probably less than a dozen reposts that probably account for 90 plus percent of all the software components that go into every application that we use today. That concentration represents an opportunity for supply chain security because there's an obvious choke point. That choke point exists when you download that component from a repo, it's gotta be downloaded.
I've never understood why we haven't put the onus on these repo managers to check the integrity of the software that's being downloaded from the repo. If we could do that, we'd go a long way to improving our software supply chain security. Now, I recently had a conversation with a security vendor who actually manages one of those large repos Mitchell notes, who it is, I don't know if they've announced this product yet, but they're doing just that.
They're gonna put, you wanna call it a firewall, Chris, you like firewalls, you wanna call it a firewall at the repo that says, Hey, before you download it, I'm gonna make sure this is the right file. It's the latest. It doesn't have a known vulnerability if the check sum is correct, whatever.
Right? But we're not gonna let you download an insecure component. Now, the real win will be if someone says, I can make one firewall that works across all of the repos, not just any one repo.
'cause as I said, there's probably less than a dozen that you wanna hit. But if we could do that, and I don't know for the life of me why we haven't done it yet, right? But if I, if I was gonna go start a company, I go do that right now, go build a repo firewall that works across the 10, 12 biggest repos, and I'm gonna filter out any bad stuff and watch what it does for our software supply chains.
Chris, I saw you had your hand up. Go ahead. Yeah, you know, I've always loved supply chain, uh, because it just begs all the questions, right?
You know, firewalls are great, right? I started my career in firewalls, and it's a very simple thing. On the edge of your thing, you should probably do a stop, you know, supply chain, you know, threat intelligence, you know, spreads that we've done it in the last 20, 25 years.
You know, how do I actually get outside my walls? You know, again, to our, our first segment topics like that, and we were pretty good at that. But with supply chain, there is no single point, right?
And a number of us have been working on this for a long time. I think I, I think I have a, a vision. I, I think a view on architecture that I think works has been tested enough, but it's, you have to include yes, repos.
And I've been working with, you know, various repos and so forth over the last couple years. They've been going down this road, they're getting better. They have a role to play.
But when you look at the entire supply chain, you take, you know, a a high demand sector and put all the pieces together from the ISAC that's already sharing information and the vendors and the integrators, you have a lot of choices. You know, the simple, the sort of firewall answer is, I am going to take all of my supply chain information and get in, in advance and have it in one spot. And that makes you think through the, the fact that this is not how anything works.
You know, it's a dynamic. What we really need to do is represent our entire supply chains. And this to my earlier point in critical enough industries that can be done today, and I think will be done in the very, very near future in real time ways.
So at every regulation, every contract, every agreement, every really, every, the, the characteristics that define my relationship with my supply chain partners and their supply chain partners is not just something I can call legal and pull up in two weeks, but is actually acting. So when I want, for example, an SBO from a third tier provider who had, and everyone has agreed in advance, and I will get that within 12 milliseconds, I'll have it in 12 milliseconds, and I will have the right, and then What are you gonna do? But then what are you gonna do?
Yeah, we could do a whole, we could do a whole half hour on that one, but, right, because that's what, again, supply chain forces you to go through all the steps. And they're not infinite. And in our entire industry, for my, you know, decades of doing this, we're addressing the firewall.
We're coming up with one thing at a time. That's a good idea. It needs to be done.
But putting it all systemically together, doing the dirt, gently, holistic detective agency, inevitably curve sort of thing takes a long time. But we're getting there. And, and supply chain is one of the things that forces us to work through each of those steps where we find we have, I think we have workable answers at each of those steps.
We don't have the workable system that ties it all together. You know, I, as much as I'm all about s software, supply chain security and, and think that that's critical for us to do, seems to me that though, that that's a step along the way to zero trust software. Let's learn the lesson from security, right?
We can firewall things off, we can protect things. Um, but until you're in a world where I don't trust any software that's part of that I'm building software from, and that's, that's the attitude you have to have of, you know, just because it came from Google doesn't mean that I trust it or just 'cause it came from this repo. And I know the repo said that they are gonna secure.
It doesn't mean that I believe that it's, it's secure. It's sort of the old trust but verify. Maybe it's don't trust and also verify.
That's the whole zero zero trust model. And I think that's ultimately where we have to go to, to be able to, to secure This. So my, my problem is though, and this is, this is the problem in security.
If security is too much of a pain in the ass, no one wants to do it. And is what you just described too much of a pain, PIA, 'cause if it is, it's not going to get done. And maybe that repo firewall resides not at the repo, but at the gateway to my supply chain.
But somewhere you need, look, I'm, I'm a child of network security, that's where I, I got introduced into security. It's all I know, Right? But, but that's my point, Alan, is, is just knowing that you go through certain certifications or you fill out my questionnaire that says that you follow good security practices still doesn't mean something can't happen.
Something can't get into No, I want that. I wanna scam that. So you have to, the zero trust, I gotta be able to defend, defend against wherever comes from.
Well, I gotta be able to test whatever I'm taking down. I gotta be satisfied that it's Legit. I'm act, I think I'm actually making the point you're making, okay.
Which is at zero Trust. Once again, Mitchell, you and I are in violent agreement. Thank you.
Absolutely. Hey, hey, Lisa, you know, as j listen to this conversation and you got all these guys talking about security, I'm just reminded of that phrase that says, you know, every company's a software company and I have a really warm, fuzzy feeling right about now. Yeah.
Yeah. I see two parallel paths here on the marketing side and the learning side. On the marketing side, any company that's a software company needs to be able to explain because trust is currency with its customers, how they're sourcing software, that it is secure, that they can guarantee that.
And then on the learning side is this for developers and organizations to be continually educated about all the things that are popping in, whether it's from a Lazarus group in North Korea or other bad actors because the cyber attack landscape is spreading. So amorphously, I really see two parallel paths on the, on the educ, well, continual education side, but the marketing side as well, because consumers need to understand that what they're downloading, the apps they're interacting with, for example, even if they don't understand the technology, that the data secure, it's, and is kept there. And that's something I think is a huge challenge for any organization these days.
Seems to me software should come with a warning label. Oh, it does. Yeah.
That's the s form. You can't tear it off. It's a federal offense, Just explicit lyrics.
That's all. Yep. You know, there's sort of, there's sort of three phases, right?
You know, you know, in each of these things as we're saying, we've all been aware of this, we issue forever, right? You can mandate something when it's impossible and nobody will do it because it's impossible. You can mandate something when it's possible and enforce, you know, or, you know, whether internally a Manding firewall in 1990 cost a hundred, uh, million dollars a year, right?
And there were 10 or a hundred of them in the world, mostly internally mandated organizations, you know, said, this is worth it. This expense is worth it for us. Um, but at a certain point, by 2000, if you don't get a firewall, you're going outta business because you're losing money.
And I think this, as I said, I think right now, if you are mandated internally or externally to really secure your supply chain, and you really should, you can do it. It's expensive. It's a, it's a cost.
But I think we'll move fairly rapidly as these things go into the point where if you don't do it, your, your costs are higher. 'cause a lot of benefits other than, other than security logistics and management, knowing where your stuff is and spending less time and money running your world is when security really gets adopted. But it's not a burden.
I think we'll wait and see on this. All right, let's take a break here on this one. We're gonna come back and we're gonna talk about serendipity is a strategy.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
All right, we're back. And we're talking about serendipity, which in my mind at least is a happy accident that I discovered something and it was all not pre-programmed, but here we are in age AI and some of those social media folks talking about using AI to well, program serendipity. Lisa, walk us through how this works, because in my mind, these are conflicting thoughts.
That's a great point. It, it's a bit conflicting in terms of the use of the word serendipity and what it means in real life. But you picture this, you're scrolling through Netflix or Spotify or any sort of streaming service.
You're not sure what you're in the mood for, and suddenly a movie pops up or a song or a playlist, and you just think that's weird. But yes, that's what I want right now. That's what's known as AI powered serendipity, where it's using multimodal machine learning and taking all these explicit and implicit signals.
You are giving the service to surprise and to delight you in hopefully a non-creepy way. So what it's doing is it's looking at different data types, textual data. What are you searching for, um, in your search queries, for example, uh, visual data.
Are you pausing? If you're watching Netflix, for example, are you pausing or hovering over certain thumbnails? Maybe you're a big fan of, of beach scenes in movies, and you pause on lots of beach scenes.
So it's starting to get those implicit signals to be able to tailor the experience for you. And then it's behavioral data combined with the visual, visual and the textual to understand what you're clicking on, what you're scrolling on, that sort of thing to give you the idea is this really hyper-personalized experience that's gonna deliver something that surprises and delights you. But what we have to be concerned about is ai, algorithmic bias.
Algorithms used to be deterministic. If you like a, then you'll probably like B And now we have all these other signals coming in, taking note about what we're doing, how we're interacting with an app, for example, to serve up content it thinks we might like. But we have to be concerned, any company that's using this, and companies already are, I think have to be really, really explicit with their users, because trust is currency as we talk about all the time.
And if you're, if my data about what I'm hovering over is gonna be used to help me, I want to know that as a consumer at any sort of product. So data privacy, I think needs to become much more transparent for any organization that's gonna be using AI to surprise and delight customers in this serendipitous way. How far will this go?
Because, um, it's not just me. I mean, I'm friends with Mitch there, and if the machine knows that, you know, he likes Batman, suddenly I'm gonna get all this weird Batman s**t from him because we're friends. And you know how all these groups that we're in kind of send a signal, right?
Yes, They do. Those are more signals that are coming in that the devices, the software is interpreting. We talked about this the other day with Alexa and all the things that it's doing and sharing from a data perspective, like people in your household, people y your friends with email addresses.
So the, the concern there is how do you stop this spread? How is it contained in a way that is applicable to this end user only so that they get an experience that is delightful rather than creepy? Um, I don't know whether those lines, I think those lines are blurred right now.
I think we're gonna see more of that, because I don't think, I mean, right now you, you look up something on your laptop for a product and then it appears all over your social feeds that you're scrolling on your phone through, um, are, are our friends and associates and people that we have text threads going to get similar information. I think it's highly possible, and it's probably already happening. Well, first of all, Mike, you should be watching more Batman, but that's, that's for another conversation.
Um, your life would be much, much enriched. But anyway, um, yeah, so we're talking about, just if you wanna combine the two topics, serendipitous is sort of happy accident is, you know, my unsophisticated definition of it. Um, and, and that's what machine learning is doing is in essence it's taking and doing rich analysis around, uh, user's behavior.
And it's doing that, of course, on large amounts of users. So it's doing more than just correlating. This video is tagged as a cartoon character, comic book character, and, and it's Batman.
And so is this over here? So let's suddenly start showing you Batman clothing or something, or, you know, trinkets. Um, it, it's really looking at the behavior of the user.
And so that can take into a lot of factors. It can take in time of day, it can take in more recent patterns, can take it, take into account historical patterns. Um, it can also take into account other people who have similar patterns that you do that you may not share exactly the same thing with.
And learning from your reactions to what I think might be a serendipitous behavior. So popping up that Batman reference might be, yeah, that's very cool, or no, that sounds like Mitch and I don't like his stuff anyway. Um, but you know, it's part of it.
It's, there's a, uh, sort of a fine line between personalization and creepy, right? At one point, is it okay who, you know, who's watching right now? How did you know that too?
That was really great. I really appreciate that. That was super valuable.
I'm glad it happened. So Chris does this, Chris, does this not feel like a recipe for the perfect online scam and a little social engineering and I take all these signals and I kind of send you something that's like so spot on you, you just can't help yourself? Well, on that thread, I mean, this is going on right now and it has been for a while from the Cambridge Analytica, you know, dust up to, uh, to today the issues are the same, right?
The same tools we need for marketing demographics, right? You know, as a vendor, you know, I don't wanna spend extra money on advertising and marketing and outreach because my competitors don't, you know, and I do the all go of business, right? And has been true since the dawn of time.
You know, you know that on a stormy day 50,000 years ago, that everybody gathers by this rock and you have all this raw fish you would like to, you know, trade for things. So you, every Friday you're there. You, we know these demographics, you know, the, the, the, the, as you said downside of this, this is, we are and have been open and not just open, but actively exploited by malicious actors.
You know, we using nation state resources down to the individual level. You know, this is another path down, you know, part down this path. You know, the risk for exploitation, further exploitation, the, the sort of nightmare scenarios are unacceptably high.
You know, again, my, my hope for this one is that as this, yeah, I, I think we're already, we're already there, right? At peak, creepy, uh, the creepiness factor will be enough to drive the necessary and entirely possible adaptations from a security and privacy perspective. So that begin by reducing the creepiness factor, reduce the actual risk of malicious exploitation.
I think some of it's in the delivery too, Chris. 'cause if you can imagine if it's something you trust, like let's say you do have a bot that personalizes things for you and says, Hey Chris, I found this really interesting reference. I think you might like it.
You are like, okay, okay, I know who that is. I know that even though it's a bot gave it to me versus suddenly this popping up in my feed. And like, how the hell did it know that, you know, a lot of it is, is the delivery or the source of what you, would you view the source of how that got to you?
Yeah. Well, You, you think about it as, you know, AI's gonna give us assistance, right? Everybody gets an assistant, they get a stack, which is wonderful.
But look how this plays out in a really effective organization, a good, uh, corporation. You got the CEO for example, sitting there and all these people around him helping that person make decisions. Then the negative version, you have some royal court where the monarch at the center can't actually see the real world anymore 'cause they're surrounded by syco offense and corruption.
Well, This sounds Familiar and right. So yeah, this can go either way. It does go either way, right?
It can either be very helpful or it could be its own disease. Lisa, lemme wait. Lisa, Chris used the phrase, I just wanna check in with you on this, Pete.
Creepy in there. We're at that point right now, I mean, I just heard a bunch of marketers say, challenge accepted My dear. Oh dear.
Oh my view, exactly the line I think between hyper-personalized, delightful experiences and creepy is so thin. It's, it's blurry. But I think it's, I think it's a dotted line right now.
'cause we're seeing companies already do this. We're seeing organizations in media, entertainment, social media, for example, hospitality already using multimodal machine learning in this way to be able to deliver these delightful experiences. But any marketer would need to be aware of how are we doing this?
What are the outcomes that we're delivering? And can we explain the, how we're doing this to our users to maintain their trust, to show them it's not creepy. There's no algorithmic bias happening here.
That's a huge job for any organization. Marketing can take the charge there because that line is so dotted and maybe very sparsely dotted at this point between relevant, contextual and creepy. So here, I, I have a bright line for creepy, right?
It's one thing to use machine learning and AI to say I'm in the Batman Club. So I probably like Iron Man too, though. That's a DC to Marvel thing.
Maybe not, but you know, it. So it's one thing to, to gather my, what groups I belong to on LinkedIn, Facebook, what have you, who people I follow on Twitter or whatever. It's another thing.
And, and then present products or things to me based upon that. I, I, I get that. That's part of the thing.
And I don't think that crosses necessarily. The creepy, creepy is when I'm talking to my child or my wife about something and I get a popup for that thing. And this is like the Lisa, if you remember, I think it was last week or the week before a case was started in California against Amazon, that they were listening in.
Listening in is creepy message to marketers. Don't be listening in. If I'm giving you permission to track where I go online, what groups I interact with, what banners I click on, I get what I deserve.
And, and you know what, sometimes I do get some very serendipitous kind of things that I didn't think of. I especially like it when they recommend movies or TV shows that I've never heard of that I wind up loving, right? I've caught a lot of those lately, but I don't like when they're listening in.
That, that to me is, that's peak creepiness. Creepiness. I completely agree with you.
So that needs to be a key message. We're not let that, we're not listening unless you're opting in specifically You wanna do that, God bless you. But you know, to me that that crosses the creepy line where I'm not gonna buy stuff from you or, or, you know, contribute to your creepiness.
Well, and, and this is where I send my supply chain thoughts. 'cause yeah, again, as a vendor, if I was that vulnerable to that sort of, you know, creepiness, you know, crashing my market, it's possible that I would might go to this extent of saying, we will give you, you know, a trustworthy to a given, you know, high level of trust, little archive of everything we ever touch, touch, record everything right there, all the time in your hands, not in ours. That sort of thing.
'cause in, in, again, supply chain context, we have to have those things have to, in the near term future in certain areas to run anything as a, as a product, vendors serving consumers, you can put that sort of thing together. You just, you know, go over the fence. Not only are we not listening, we will be really absolutely clear with you.
Everything we touch, everywhere we put it, why not? But you have to lose. Maybe That's where we headed it.
Well, well, well, Jeepers creepers. I got all this email from Batman that I gotta go answer, so I gotta go. Okay.
Boy. Wonder. I'm Iron Man.
Hey, we got it. We gotta go though 'cause we're outta time here on Text Drunk Gang, have a great weekend, everyone. Um, stay tuned.
Monday we'll be back with even more Great Text Drunk Gang and Text Drunk TV material. It's been, it's been a crazy week here. So much going on.
I'm telling you. This show is therapy. Mitch, Lisa, Chris, Mike, thanks for joining us on The Gang.
Thank you for joining us on The Gang. Stay tuned. For the rest of Text Drunk TV is Alan Shimmel.
We're out.