Techstrong Gang – January 22, 2025
In today’s Techstrong Gang, we discuss the open warfare in the WordPress community and the possibility of a fork of the CMS that runs more than 40% of websites. Then, we debate whether apathy has taken hold regarding cyberbreaches and explore if Allstate has been spying on drivers without permission.
Transcript
Did you know there's a war going on at WordPress? We're gonna discuss that and don't mess with Texas. All on Text Drunk Gang.
Hey everyone. Happy Wednesday. It's Alan Shimmel from Techron Group and you're watching another episode of Techron Gang.
As I mentioned in the morning, we got a lot to cover, including the literally wars going on over WordPress, as well as some don't mess with Texas warnings to our favorite good hands people. And, uh, it has cybersecurity. Have an apathy par problem.
Do people care about an apathy problem? We're gonna discuss that a more, we've got a great gang to discuss it with. Let me introduce you to them.
First of all, he's only gonna join us for our a block today 'cause he's off doing important things, what could be more important than being on the gang. But he's our future vp, uh, DevOps Cloud native expert, as well as cyber Mitch Ashley. Hey Mitchell.
How are you? Good to be here. I loved your opening.
It's, it's, it's our opening for the podcast. You're listening to another episode of That's Right. We've been doing that podcast for about 20 years.
Yeah. Um, but thanks for joining us today, Mitch. If even for a short time, then we're gonna go down.
We have a whole Texas contingent in here today when they heard it was, don't Mess with Texas Day. We had everyone in Texas lined up, first of all, joining us from snowy Austin, where he is working from home as to as not to contribute to the on on road, uh, hazardous conditions, another future of analysts as well as CTO and co-founder for Visible Impact, our friend Guy Aria. Hey, guy, how are you?
Good, good, good to be back. So funny how yesterday right after the snow fell, I was able to make it into the office today after a little bit of warmth and a little bit of ice, building up the roads are more dangerous. I see Amanda nodding at that.
Uh, there's just not the infrastructure here to, to clear out and the roads get more dangerous before they get better. So, here I am at home. Any reports of black ice?
Uh, no. You don't get reports of black ice here. You just get reports of accidents where you witness them yourself.
Got it. Texas drivers. That's what you get reports of.
There's always a lot of driving that stuff. Very often. Well, joining us from another part of Texas where it was also, they didn't get snow per se, but it was 18 degrees, uh, down in San Angelo way.
Our editor lodge here, uh, Amanda Ani. Hey, Amanda. How are you?
Cold. Good. I cold.
I wish there was snow. It'd be better if there was snow. Yeah, sometimes if you're going to get cold, you might as well might as well have cold.
Um, could be worse though. You could be up in Denver with Mitch where he says it was minus six, so, Oh, no, thank you. It was chill and I, I felt terrible.
I had to put on a long sleeve shirt today. It was like 63 degrees when I walked the dog this morning. It was raining though.
But joining us from warmer climbs, she's out in Silicon Valley. She's our marketing person, extraordinaire, expert extraordinaire, host, radio host, all kinds of good things. Lisa Martin.
Hey, Lisa. How are you? Hey there.
Good. I had to put on a puffer coat yesterday morning to get coffee. It was 39 In Silicon Valley.
It was nine. It's in the Valley. 39.
Wow. That's called, Yes. 39 in the Valley.
com. Should be paying us a royalty or something here. We we're doing the job for him.
Who's the guy from the Weather station who always shows up? Uh, Jim Cantrell or someone. Right.
Whenever there's a hurricane or a bed storm. I knew Bonnie to be our meteorologist. Well, Bo Bonnie was here yesterday, but you know, she's, she's, uh, doing a report on the, on the, uh, Paris Climate Change Accords.
But let's not go there. Um, anyway, that's our gang for today. We will talk about climate change maybe in another episode, I'm sure.
But for today, we're gonna kick things off. I mentioned there's a war, literally a war going on around WordPress centers, around Matt, Matt Mullen, who's one of the, uh, I guess I think he was one of the co-founders. Certainly CEO of, uh, automatic and Automatic is the company behind WordPress.
And if you don't know WordPress runs something Mitchell, is it like 45, 40 5% plus of all the websites on the internet are actually WordPress? It does. It's kind of the defaults It's a default for a lot of people.
Yeah. I mean, I don't want to say what we use 'cause it could be a security, uh, um, incident, but yeah, it is a default for a lot of people. And, and I don't know what, what, Mitch why don't you give us the scoop and we could all Jo chime in from there.
Well, the, the beef is Matt dropped this bomb of a blog post a while back, basically, uh, claiming WP Engine is freeloading off of the brand and getting too much benefit and Not, well, truth be told, I think he called him a cancer. He did? Yes.
I guess he did. Yeah. Cancer on Society of Cancer on Word Press.
Mm-hmm. That's, that's Matt Mullenweg, the, the CO of Automatic who's the CEO of Auto Automatic. And so it's, it's, it's battled back and forth.
Uh, he told employees that didn't agree with them, what he was doing. They could leave. And 177 people left the company.
He put a, a log, a checkbox on the login for WordPress that says, uh, you're not a developer that works for WP Engine. And in essence, so it, you know, it's, it reminds me, you remember back in the Tenable and the Snort days. That's exactly what I was gonna say.
Reminded me of Mitch. Yeah. You know, you guys are all freeloading Open source, re open source remorse.
Yeah. Talk to, uh, Mitch at HashiCorp Hashimoto as well, and, and others. Open source remorse, I call it.
Exactly. So it's, I think it's that repeat of that, you know, you kinda get a little, you know, heartburn. Um, what did I do?
Well, these people are making a lot of money off of my stuff, but it's open source, so they're allowed to, Well, there's a little bit more of intrigue here, Mitch. You in your usual Midwestern way, you're trying to be kind, but I think that's a darker side here. com.
He locked them out and then he started locking out anyone who spoke up against it or spoke out about it in, in true dictorial fashion. Right. Which is, it's not cool.
That's not cool. I'm sorry. org 8% of their revenue, 8% of their revenue for using free open source.
That's, that goes way, way, way over the line. Now, just to show you that I'm a fair person though, and I do look at both sides of the coin. com Techstrong.
All, all of our sites were hosted and, and still are, but not by WP Engine anymore. And we left WP Engine, Mitchell's, CTO, here at Techstrong. He can go dive deeper into it, but we left WP Engine for many of the reasons that Matt cited.
They don't, they don't give you the full WordPress experience. They're really not set up. I mean, at the time we were running, I don't know, a dozen or a dozen and a half different sites, and they weren't set up to support someone like, like tech struck.
No. They didn't have the depth of knowledge on No, they didn't Diagnose issues. And, you know, it, it's kind of for websites that are sitting around, still running, but not heavy use sites like ours.
No. Weren't, Weren't you talking yesterday? Yeah, go ahead, Amanda.
Well, I'm just curious. I was reading that article about them being locked out. He just locked them out of WordPress.
And I was thinking, um, couldn't this result in lawsuits if you get locked out of your own WordPress that you use, especially if it was for Business? No, they don't U no, no. That's not what they locked out of here, Amanda.
So, so there's WordPress, the open source, uh, web content platform, WCP, you can take that, you put it on a server and you run it. com. But what happens is a lot of the plugins for WordPress and a lot of the support and the updates to keep it current, the most secure version, you need to go back to the mothership to download or it's hosted there.
So yeah, there's like a management site where all that comes from, and that's what, that's what, so now all of a sudden it's, it's headless, so to speak. Yeah. And, um, and that's what he locked them out of.
Got it. Okay. That's, I was thinking that's crazy.
What is he talking Yeah. Now, so I get it. Right.
And I've also, Mitch, you, you alluded to, you know, back in the day when Mitch and I were doing Still Secure, we had Tenable security tip. They took Nessus out of open source. 4, after this version, it's no longer open source.
There'll still be a free version. We'll tell you whether, how you could use the free version, but it's not open source. We're not making the source code available.
And as time goes on, you can still use the open source old version, but we're not updating it. Mm-hmm. So I have a couple of questions.
Sure. First, I, I'm reminded of our discussion yesterday, Alan, about the operation of the free market and, um, you know, uh, um, WP Engine providing a, a, a service that didn't fit Techstrong. So Techstrong moved on.
That's the operation of the free market. On the other hand, um, one organization controlling, um, some essential operations of what is supposed to be open source or a freely available resource. That sounds like it's not the operations Free market.
Oh, it, it's not. It's, it's not For sure. It's not now.
So there's two sites in question here. org, which is the open source where you can download the, the, the source code, the packages, if you will, to install WordPress on your, on your stuff. com, which is a fully commercial site.
com or both. But clearly in open source, in the open source world, there's recourse here. You can fork, you can fork at any time, right?
You can take the latest version of WordPress and fork it and, and go on without Matt and Atomic and that whole thing. org to support that the researchers, you're gonna need a critical mass of those folks, and you're gonna need a big pile. Cash.
Frankly, atomic has a seven and a half billion dollar market cap. Well, that, that leads to my second question, which is, how sticky is this kind of a tool? Because, uh, on the one hand Off a WordPress for people is, is it's a big why paper, you gotta rebuild your guy.
You ain't getting off of it. You gotta rebuild your website. Not that it can't be done, but Yeah, I think it Word forking WordPress would be a different thing.
But that's different. You're just going to, you're gonna need a critical massive of developers. 'cause WordPress is all about the plugins, right?
You need a critical mass of plugin developers. You need a critical mass of WordPress, uh, researchers, maintainers, you know, everything that goes into maintaining an open source, keeping it secure of bugs. I mean, there's a lot of compatibility issues with WordPress.
It's a big undertaking. Now, to be fair, if you listen to Matt, you know, calling these people parasites, that's what we used to call 'em in the open source security days, right? You're a parasite and take, take, take and you don't give.
Um, and that's basically what he was calling WP engine. org site. That Atomic contributes.
You crying me cry. Go on for the seven and a half billion dollar company, right? Where WP Engine evidently minuscule, minuscule amounts of, of contribution.
You know, I get it. I, I get the, the open source parasite issue, right? This is why I really like what I call the foundational model for open source, where you take something like WordPress and you set up a foundation, a not-for-profit foundation, like a Linux Foundation or something, and you take out, you take out the competitive kind of, uh, go back and forth between Oregon in different companies, kinda Like putting it in a trust way.
It's putting it in a community trust where, and the, and the good, Well, there is a WordPress foundation, right? There is a, but I think it manages the license. Not, not that's a bad It.
Yeah, it's a GPL license. It's a straight on GPRI think V two license. Atomic is a, is a one man band there.
You know, this goes back to the prior era of op. When I do my, how I, you know, do open source history. I, I, I picture the first series of open source is what I call the cathedral and the bazaar, like the movie, like the book.
You ever read that? And it's like Dr. Richard Stallman and you know, down with the Man, free, free, free.
Then we went into what I call the Big brother era of open source, where you had companies like an Atomic, or at Tenable or IBM, who really owned these open source projects and ran them for their own benefit, their own profit, but under the facade of doing it for the community. And there was some good communities built like that. But then we had the foundational error of open source, right?
And the foundation, the Not-Profit Foundation allows for coopetition among competing vendors that no one, you're not doing it just for the sole benefit of one vendor who vendor who might be a competitor. And, and that's where we've seen open source blossom into the de facto standard that it is to today that just WordPress open source in general. And Alan, by the way, Alan, in his typical understated New York Long Island way, isn't giving himself enough credit here.
He, he wrote for Network World, PC World, whole bunch of magazines blogged for them all about open source Stories. I've been covering open source. I was involved, the, the stuff Mitchell's talking about with Snort and Nessus.
I, I was involved in that. Um, I've been involved in open source a really long time. Yeah.
This is, this is typical sour grapes, right? Matt is upset that these people are parasiting and making a, I mean, atomic, they're Parasiting or is he upset that he's not a billionaire yet? I mean, you know, well, I think he's dealing with, uh, something that literally he created.
Yeah. And it's, you know, it's position use a combination of messaging and statements and, and, and usually and actual strategic moves to try and gain some outcome that they're looking for. I'm just not seeing the Strategic moves.
We saw Ash Corp did this this year, last year. We saw Red Hat do it. We've seen Atlassian, I believe do it where, where, I don't know if Atlassian did, Mitch may know, but what happens is, is look, you build your guy, you're a founder, you know, you build the, you start the company.
It's all kumbaya. Of course, we're gonna want the community involved. Of course, we're gonna open source and it's all good.
All, you know, flower power war's not healthy for children and other living creatures. And My, my question is, why does he just go set up his own hosting company and take him out, compete in the market with him, and, you know, go for it. Don't quit whining about it.
Well, because he, well, I think that's, it's, this is his classic open source remorse. He now feels like he, they have single handedly financed and built this Goliath, Leviathan, WordPress, and here's this company that now is approaching a billion dollars in, in revenue or value. Who doesn't give back?
And it's not going Well. I, I thought this would be interesting. I shared that article on LinkedIn and got quite a few comments, and there's only a few times I see comments coming in on articles.
So I, I saw this was on the show today, sorry, copied some of them. So a couple of the responses to that share was it'll pan out. Open source has a way of using forks and taking off to different roads.
His governance and tight grip will force the community into some new development. I wouldn't be concerned as the core isn't being destroyed and the forks will bring even more opportunities. And then there was another comment, kind of similar.
It said, whether there's a migration, a classic press, or a new for open press, free press, liberal press, et cetera, the community likely will shift wherever the top bulk contributors go. And WP Engine will likely shift as well, Likely. And WP Engine may have the resources to make that happen.
And that, that's what you'll see. You'll see a fork. People vote with their feet, you know, vote with their forks.
And that'll never be a billionaire. Poor, poor Matt. That's a kind of Prediction.
It's a kind of a funny scenario to be in because, uh, WordPress to, to my mind was always sort of the, uh, I don't know how to, it's like the biggest open secret, or I don't know how to put it. Websites utterly necessary. Um, WordPress, uh, used by whatever it was, 43, 40 5% of, of sites or organizations.
And, um, I'm not sure that this little corner of tech gets the kind of, um, uh, attention that almost every other part of tech does. And yet it is supremely fundamental. And that's why I asked the question about stickiness.
I mean, you know, the, the, the, what, what would, what should we advise organizations that are listening to this or folks who are listening to this, does this mean you should invest some in diversifying your websites? I think the pain of that is great enough and the Outcome. Yeah, I don't see that as an option.
You Know, we are, I think, I think the commenters on Amanda's LinkedIn poster, right? The, the, the, the community. The community is self-regulating.
And they'll figure it out. It'll sort itself out. It will, it's just gonna be a little pain.
But look, you get like a good, a good old fashioned security bug in a WordPress edition, and you see just how big WordPress is, right? And how many sites are are vulnerable to it. It's crazy.
Anyway, hey, we're all way over time. We gotta take a break. We're gonna come back.
Mitch, I know you're hopping. Thanks for joining. We'll see you on the next text on gang.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey everyone. We're back. As I mentioned, our next block is called, uh, don't Mess With Texas.
It seems like the Good Hands people. I love doing that. The good hands people have, uh, maybe gone a little too far.
You know what, what's the commercial chaos is, is that the guy, what's, what's his name? He's always has bandages and he's causing all kinds of mayhem, not Kays Mayhem. Looks like Mayhem may have gotten control of the, uh, IT team there.
Amanda, what's the story? I love that. Yeah, those commercials are funny.
But yes, so Attorney General is suing them, saying they're collecting all their data without their knowledge. And, um, the article we posted, um, goes on to share that. Um, they, they allege that Allstate is collecting the data through their phones without their knowledge to put together a big database of how everyone is driving.
Um, so my first thought was, I just assume everything is being collected on my phone. And I, at this point, I could almost care less. I mean, my phone's listening to me every day.
At least you think that that's true, right? When you see the ads that come up, Well, isn't it also that where e if the data that they've been collecting, even if you're a passenger in a, a rideshare or a taxi, it's collecting that data. So you would get maybe dinged for speeding or running, um, a stop sign or, or anything like that.
So it's actually potentially causing even more harm to the people that are on this, uh, policy. Oh yeah, that's, yep. Yeah.
I have one of these apps on my phone, uh, from a different insurance company, USAA and, uh, as I mentioned a couple With Gronk, uh, I'm kidding. I'm kidding. You don't have that honor.
No, but, uh, I, I get to, I get to inherit the honor from someone else in my family. So, um, the app allows you to say that any given ride or whatever you are not driving, right? So This, this, nobody advertises that to you and you, and when I, when I noticed it, you know, I was like, oh, I better go Check.
I know all the apps give you that option, actually, guy. Right? Exactly.
Maybe just ussa. So here we, yeah, This old drug comes out of, you know, a couple of years ago it was progressive who started it, but now they all do it. Originally they weren't using your app 'cause most of your phones have accelerometers in them, so they could go by speed and so forth, but they weren't using your app.
They used to send you a little plugin that you would plug into the data socket of your, of your car, and it would monitor your braking and your speed and, and so forth. And, um, and any other information that your car was able to give them. And as cars became more sophisticated with lane departures and stuff like that, it was even more, and the good news was, or the purported good news was that if you did good by, you know what the readings were, you could lower your car insurance by 20% or something like that.
Sounds good. Yep. Until the first time you'll hit your brakes hard 'cause someone stops in front of you or something else happens, or, you know, it never worked for us.
It never, I never got a dollar of savings from using those things, so I just stopped using them now. Yeah. Now they put it into your app directly, you don't even plug into the car.
And of course, one of the first problems is, guy, exactly what you said is, or, or Lisa, you actually said it too, is how does it distinguish if I'm a passenger or actually driving? So now they've given you the ver the, the ability to opt out, but what a PIA that is, they get in the car and say, wait a second, I'm not driving or Betty yet. You know, I don't want them tracking me.
I'm gonna say I'm not driving. Even if I am driving and I'll put my car in the backseat, ha, but I'll put my phone in the backseat. You know, it's wrong, it's wrong.
However, the legal beagle in me says, you don't think somewhere in that little check box you checked right in the beginning when you installed the app, you gave them permission to do all that. You don't think their lawyers were good enough to put that permission in the app. You may not have read that fine print or you signed away your firstborn child too, but it's in there.
And so if you clicked in it and, and said, okay, I'm not sure what Ken Paxton, who's a very, very busy guy, I know, um, doing all the right things. I, I don't know if, if this case is a winner, it's good publicity. I think it's a political winner.
Yeah, it's, It's Publicity. I mean, you know, Amanda, I would love your perspective. You and I are both Texas residents.
We've known Ken Paxton for a while. Um, it's worth saying that, you know, he's running a large office doing a lot of very necessary work at the same time as he himself was under scrutiny and a case now dismissed or Document he's controversial. Things like controversial at the least You can say Yeah.
That you could say that at the least. And, and I don't think it's judgment to say he is clearly highly politically motivated. And you might say doubt as every elected attorney general, and that's fine.
So this is a win-win politically. Um, and it may do some good, it may do some good as well because, you know, uh, the, the, I'm glad you brought up the contract down because we all signed these contracts. We get these giant contracts, returns, conditions that are gazillion miles long.
And my uncle in Switzerland, who's now retired, and a former in one of the original gangsters of cybersecurity, honestly, back at lk, Barnick and Newman in the late sixties, he reads these, I don't know anybody else who does. No, I I know I don't, don't, So I'm guilty as charged. I do not read those Who could.
But, but here's the thing. Let's go after our favorite whipping boy, the insurance company. God forbid are we going to hear Allstate, CEO is shot dead in the street next because Another political win-win.
Keep going, Alan. You know, but, but I I, I get it. I get, look, I'm no fan of insurance companies, right?
I don't get me started. I live in Florida where we, you know, we have some insurance issues, but I I I think we gotta take the pedal off the metal of demonizing insurance companies. I, I, I'm Kind of insurance we all should be.
It's, it's it's group. You know, it's sort community risk taking so that individuals don't get punished, but insurance companies. But, But they are for profit Companies environment.
Mm. Yeah. Okay.
Sure. You know what I mean? If, if insurance companies were all co-ops that were not-for-profit and we just shared the risk, it was a risk sharing.
Um, Yeah. Those were the mutuals. Mutuals.
Like mutuals, Yes. Mutuals. That's what a mutual is.
Always think Kin. Well, I why they, I get why they would be doing it. As I think about it, I just expect my phone is listening to me and tracking all my data.
So I've come to that conclusion. I don't care much. But I get why it would be a concern because, um, if they use all this information in this database to say, oh, okay, now we're gonna change our rates and all the rates are gonna go higher because we're seeing that it's more likely, you know, from all their information they gather, it's more likely they'll be, uh, driving fast in this area or this region or, you know, making these determinations and then then changing their fees.
That could be a concern. But I mean, it was probably in there and we just didn't read those contracts. But, but what about if they don't change everyone's rates, Amanda, they just change your rates 'cause your hazard, That's what I'm assuming.
Like, oh, they drive faster in this region, or you know, this person we know, you know, even go individually, not originally. Yeah. If they start changing rates based on that.
Yeah. Yeah. So there's ano that's another term and there's no Recourse.
That's A concern. Yeah. That's another, Because nobody would know why community know about it.
And, and I, let me give you another little deep dark secret about our friends in the insurance industry. I'm not calling for violence, don't get me wrong. But you know, what they do is they form a not-for-profit consortium where they share data, right?
How do you know when they look up and see how many accidents you had, how many tickets you've got, what's your driving record? They don't always get that from the DMV. You know, they have in order to get around antitrust, they set up not-for-profit consortiums organizations that allow them to share data across carriers.
And that another Thing in the Ts And Cs, that's look, yeah. But that, that isn't the Ts and Cs. You know, I found this out both when I was practicing law as well as I actually used to sell security to a company down here in Florida, national NAI, I forget what it stood for, but this was all the workers' comp insurance companies in the us.
They pull all their data so they know what kinda risk you are as an employer, what kind of, how many claims as an employee you've had across different carriers. And, and it, you know, antitrust. Yeah.
But it's a not-for-profit. They're exempt. And, and that's what the insurance look, and again, I That's not bad on its You wannas own don't vilify.
That's not bad on its own because, um, you know, I mean, one of the, to, to give a an analogous example, law enforcement does not have similar network so that people can, I mean, they have some networks, but there's not, it's not really as cohesive so that people can cross state boundaries or whatever. And you know, why not Be, well, you know what guy, law enforcement is a government empowered entity and he is not doing it for a profit. Right, Lauren.
Right. That's why, that's why the rating issue about changing Amanda's rates. And so this term community rating has been thrown around a lot related to a lot of new prospective f laws under consideration and things like that.
Community rating is all about having people who are low risk help pay for people who are high risk. Nobody wants to describe it because everybody sits there and wants to say, well, if I'm a good goody two shoes, why am I paying for the people who are not goody two shoes? But that's, that's at the core of How insurance, well that's high health insurance as well, right?
Mm-hmm. That's the whole thing thing behind Obamacare, is you needed enough healthy people to offset the cost of paying for unhealthy people. And, and, and no one talks about the benefit of that, which is a benefit to society and the community as a whole.
It's not all of us all alone out there doing everything without any help from anybody. I think it's a huge benefit. Yeah.
And I'll say it, and I'll say it again. Take the profit out of insurance companies. It will never happen.
'cause their, their lobby is too strong and it's too big an industry. But if you took the profit out of insurance companies, A our rates would go down drastically, and b then you could have sort of that altruistic kind of thing, like Medicare, for instance, right? I i if we could do stuff like that, you know, maybe we could do things like lower the deficit and, and, and get a lot more things done.
A, a profit driven, and you look in Europe or where they have socialized medicine and, and stuff like this, they don't know. Oh Yeah. Half my family or doctors I've been saying for years, the core sickness of mm-hmm.
A healthcare in the United States is the for-profit motive. Yeah. And I just feel something a little morally OB object.
I'm a total capitalist, all right? But I still feel something a little morally objective, objectionable not to individuals, doctors and stuff, making good money, helping the sick, but industries that rely on people getting sick in order to be profitable. I just, there's something off about that.
I haven't thought about insurance in that way, but we make a compelling case. I know, but this is, this is, this is the problem with insurance. If we knew that, hey, all of our rates would go down by doing this, you know, behaving better, driving better, trying to live healthier, but that's not all, all that happens is more people make more money.
But again, let me be clear, that doesn't give anyone the right to go shoot someone on the streets in New York. That's just wrong. Right?
That's, that's not the answer here. Not the answer. What are the next steps though, in Texas?
I mean, is Allstate being really made to be a scapegoat here when probably all of the insurance companies have been doing the same thing for a very long time? What are the, what are, what are kind of some of the expectations of Texans where this is concerned? Yeah, you Ray the good point that, that was another thought I had when I was reading the article.
It's probably, aren't they all, I mean, it goes back to, I assume everybody's collecting all my data. Well, if you're gonna pick on one yeah, pick on a big one, right? And Yeah, And who's bigger than Big one based outta state?
Allstate's, uh, uh, not based in Texas. Unlike USAA, which is right, USA San Antonio, but I mean, all states. I mean, it's one of the big, it's probably Allstate, Geico, state Farm and, and progressive are probably the four biggest.
Anyway. I'm, I'm sure, Mandy, you're right, they're probably all doing it. But someone had to be the whipping boy here.
Uh, well, It'll be curious to see what, what, from a marketing perspective, Allstate says in response to that, Allstate gonna say, Hey, we, it, it's in the fine print. You gotta read it. It, And they could absolutely do that.
I to your point and be clear, Yep, be fine. And maybe, maybe here's, here's gonna be the upshoot, because you know how these things go after Ken Paxton gets his pound of flesh of publicity. The, the settlement's gonna be that.
Allstate's gonna put that in bold nine point font in the, in the disclosures that no one will read anyway. And, and will all go home happy. They'll make their money.
Ken gets his his scalp, and we move on to the next publicity stunt, such as Life in America. Anyway, let's take a break on text and gang. We're gonna come back and we'll talk about, do we have a cybersecurity apathy problem?
I don't know if I care. You're watching Text and Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey everyone, we're back here on Textron Gang.
Our next block, our C block is, does cybersecurity have an apathy problem? It's an article outta Security Boulevard. Lisa, what do you think?
You Know, it's so interesting, the data that was cited that shows the a kar study of over a thousand adults who they're seeing a decline in concern of, uh, compared to the previous year. Uh, and consumers are starting to become apathetic towards cybersecurity breaches because they're so common. The challenge is, and the data show in this study that there's issues with employees being reckless.
There's issues with consumers being reckless. And the employee side, we, we know that so many companies, every industry requires security training. So there's consistent training and awareness, but it's still, the problem lies with people, whether they're employees or they're consumers.
The, the breaches are so common. Um, I think that's part of why we're seeing the concern do down because they're happening all the time. Um, probably a lot of people who've had, you know, that your passport was appeared in a data leak, um, thought, well, I'm still able to access my Amazon or whatever I wanna do, um, regardless and don't care as much.
But something that I thought was interesting was that on the employee side and the consumer side, the consumers don't want to know that it's employees working at their favorite, you know, outlet, e-commerce outlet, for example, that are probably the cause and falling for this very sophisticated social engineering tactic that has happened. But a lot of employees are reusing passwords across, uh, work and online shopping accounts. The data also showed this, this number was high.
57% said they were comfortable using work devices for personal shopping. And that hugely increases the cyber risk. So the apathy that we're seeing is, is a concern in and of itself.
Um, 'cause there was some huge breaches last year at and t was breached. Hot topic was breached. We saw, uh, credit unions breached.
And folks are just saying, um, well, another thing that was interesting about the data is that there's a generational device. So from a demographics perspective, the Gen Zs want to hear from a company that's had a breach. They wanna understand the technical implications and what they should do on their mobile security, for example.
Whereas baby boomers are more likely to churn and find another provider that can deliver the same results. So companies from a marketing perspective have to reach out to employees and consumers and have different messages and different ways of mitigating challenges or breaches, if you will, um, based on who their target audiences are. So a lot of challenge there for organizations to get those right messages out to the right people in the way that they wanna consume them.
So hopefully that apathy starts to go down. Lisa did the, uh, did, did the study cover mostly sort of end user side? Like is the apathy the evidence here about apathy among end users?
Uh, or what about, you know, organizations themselves and their cybersecurity efforts or teams or what have you? From what I understand, to your point, it was end user focused, end users that are how they behave when they're employees and end users, how they behave when they're consumers. I don't think we saw anything from a cyber, uh, from an organizational perspective.
We know though that, like I said earlier, you know, so many, how many different security trainings have we all been through with all the various companies that we've all worked with? It's, it's required check the boxes, you pass the test, et cetera. But the behavioral issue is, I think at the crux of this, um, we're seeing people that just want to do things as they are.
They don't want any interruptions on the, whether they're employees or consumers with how they're doing transactions. So that behavioral change is a really big challenge to, um, to augment. And so we're seeing folks that just don't care as much because, hey, this is happening every day.
Um, I've been part of a breach before. I was fine. I don't care.
Yeah. And the predict session that, uh, that I did with, uh, with Amanda and, uh, with Hope Lynch, um, this was an element that we talked about. 'cause the, the prediction was, uh, um, 2025 will be the year, the fragile app.
And one element of this is cyber resilience and cybersecurity. And we didn't have the evidence. Uh, but you know, we have, we, we did discuss this general feeling that amidst all the storm of all the different things that developers of apps are trying to do, cybersecurity seems to be falling a little bit by the wayside.
There's a certain amount of laziness or apathy that that seems to be setting it. So that would be on the app builder and, and, you know, and organizational side as opposed to the user side. Well, yeah, and this was focused on the users.
So look, I've got about 25 years in cyber. It is not a new issue, man. You know, we call it in cyber, we call it desensitization.
You get desensitized. It's the boy who cried wolf. First time it happens, you say, oh my god, my, my, my, my valuables, my my my social security number, my everything is vulnerable.
What should I do? Oh, they're gonna give me free credit, monetary, hallelujah. Right?
And then, you know, the third time it happens, it's a little less climatic. The 10th time it happens, you don't give a crap the 20th time it happens, you're annoyed, right? But I've gotten breach.
I've gotten three, four breach letters in the same day from three or four different either credit cards or stores or organizations that had PII of mine. It's a, it is an ongoing sin of, of what goes on in our world. However, it, it's something that we are very desensitized about.
And there's a high level of apathy. So much so that with all of these breaches, and I've said it on here, I'll say it again. Within six months after the breach, whatever economic impact there was to that company is gone, their stock prices back where it was are higher.
It's forgotten. Even the boomers who churn, churn back because the one they churn to was the next victim of the breach. At the end of the day, we are a herd of zebras and we just hope that today's not the day the lion eats us.
Right? We could get breached, but they didn't steal nothing from me. Now, there are people in cybersecurity say, I'll tell you how you get people to get rid of that apathy.
Don't make the credit cards responsible, right? Because right now, look, you get breached. They breach your credit card, they bang it out for a couple grand.
You make a claim, you're in that within 20 minutes, your credit is is they, they give you the credit back and it's, you know, and they, they have subsumed the loss. They investigate it every once in a while they'll catch someone. But it's really of no consequence to you.
They give you free credit monitoring. You like getting those little annoying Equifax or, or, or TransUnion or, or, or the other one. I forget the other one.
And I subscribe to it. Experian, you know, you get your thing someone's made and you, you get used to it. It's, it's a total desensitization.
It is, it is the price we pay for living in a digital world. And I and I, and that price has largely been born by the banks, credit card companies, et cetera. Um, most people have never really felt the, the economic harm.
Now, people who were victims of identity fraud though, and I don't know how many of them you've ever spoken to in your life, but that's a frigging nightmare. Someone, you know, starts filing IRS returns in your name or start, you know, like ruins your credit 'cause you weren't paying attention. That's, that's a nightmare I wish on no one.
Um, yeah. And, and the thing about this past year, for the first time I started getting notices that, hey, your social security number was in the data that was taken. It wasn't just your name, your address, or your email, your social security number.
We have got to get off social security numbers as a unique identifier because you can't go get a new social security number. You're stuck with it. So all you can do is just then go monitor your and lock your credit files, which is a half-assed kind of response.
Social security numbers were never meant to be your unique identifier for credit or for anything else other than making a social security, you know, keep your Social security account. Um, we need, you know, we need to get off passwords. Hell yeah.
We need to get away from social security numbers as a unique identifier. Absolutely. Um, breach disclosure laws are pretty much reor, you know, they're started with California and most of the states have them now and federal that you've got a company must report a breach within a certain timeframe.
Um, and there has been times, look, the it, it cost the Equifax CEO his job at some point, right? A couple years back, you know, but it's just, that's the world we live in. You Bring up a great point about the desensitization that folks are just this study talked about.
They used the word reckless, reckless consumer behavior, reckless employee behavior. It's the person, but the behaviors are so hard to change 'cause they're so ingrained in who we are. We either don't care about this, that hence the increase in in apathy or the decrease in concern that this study reported, or, um, we just assume it's somebody else's problem.
I don't need to deal with it. There's too much information out there. I can't be responsible for this.
Um, but they want to hear from companies when there is a breach. We talked about the, um, the, the Cheeseheads Alan a few weeks ago. The Green Green Bay package.
The Green Packers Fence Store, work store, the pro shop was yeah. Was hack. And what surprised me about that was I think it was about 8,500 people that were No, no, That was tiny.
It was small, but it seemed like they actually disclosed that, um, far sooner than we're seeing other breaches disclosed. So organizations need to get better at that. It depends on the state and stuff.
Some within days, some within weeks, some within months. But here's another thing, the whole system of passwords that we use, right? The average person has 152 passwords and they tell us, don't repeat the same password.
You only use one password per se. Who are we kidding? Who the hell remembers 152 passwords?
So then you need a password manager, but don't lose your master password. And if you mess, the password gets breached. Or the password manager got breached as this happened with LastPass numerous times and some of the others, then they have your whole vault.
Anyway. So the whole system of using passwords versus biometrics or, or you know, other kinds of technology is, is, is again, we're just setting ourselves up for failure and desensitization and, and this stuff, you know, it's Groundhog Day. It's Groundhog Day, I Think, I think that's exactly what it's, I think live biometrics is the answer.
Real time biometrics. That's how you get into anything. You know, I look, I I think some of the more like Google and, and Facebook, some of the other ones I've been using lately that they send it to your other device.
Yeah. That you gotta, you know, you gotta actually do something. Um, not just two factor, but I mean like real biometric kind of stuff maybe.
But you know, as long as we rely on passwords and the average person has 150 passwords, this is again, the rule. You know, the game, the, the life we've chosen the problem Will, will persist. We won't see that change.
Terrible. As a security and guy, you spoke about the security people versus, you know, the consumer as a se a security person. It's disheartening because you can never win.
You can never win. You're always losing. Oh, honestly, so I was not in security.
I haven't covered security, it's not really my area. But, um, when I was at a cloud provider, um, I worked a lot with, 'cause it was a one, one of those kinds of specialty cloud providers. I worked a lot with really top-notch security professionals.
And that's, you know, going like back 10 years, eight years ago. And let me tell you, they were already jaded. Right?
And I think, I think it's, it's sort of endemic. Um, and It's why didn't drink, I'm only kidding. But if you've never read the Phoenix project, right, the sec the ciso, he's an alcoholic, right?
Because how'd you like to be? You know, you never know when you win because by definition winning is nothing happened, right? Yeah.
You say it's a perfect, It's a perfect storm. Yeah. Yeah.
It's a perfect storm. It's A hard, it's hard being a security person. And let's, let's, let's take a moment to acknowledge the security professionals watching this whom we're trying to find insights to, because we recognize your continuing contribution with almost no credit or recognition, honestly.
And they are my people. We'll be at RSA this year doing DevSecOps again. Come see me.
Um, all right. I think that's gonna wrap up a fantastic textural gang, guys, gals, thank you so much. This was a great discussion.
It's great to be here. Yeah. Yep.
Guys, stay off those roads and stay safe. Amanda, put the heat heated blanket on. Lisa, keep doing what you're doing.
It's all good. Yeah, we'll be back. Well, we have a full, uh, text strong TV day for you today, so check that out.
We've got some interesting stuff on there. We'll be back tomorrow with another gang. I can't wait to jump on it.
But until then, there's Alan Hummel for Text Strong. Have a great day, everyone.