Techstrong Gang – July 10, 2024
Alan, Mike, Mitch, Amanda and special guest Guy Currier, CTO for Visible Impact, an arm of The Futurum Group, discuss whether it is nobler to build artificial intelligence (AI) models or simply invoke models that already exist. Then, they move on to the underappreciated need for faster networks in the age of AI.
Next, the gang turns its attention to the pressing need to migrate away from passwords to embrace passkeys, following the discovery of a cache of nearly one billion passwords stored in plain text. Finally, in a new edition of Byte Me, Ira Winkler addresses why the concept of “Thinking Like a Hacker” is wrong.
Transcript
Hey, everyone. Here's the question of the, of the day. To build or not to build AI models that and more on text Textron Gang.
Hi, happy Wednesday, everyone at Alan Shimel here at Textron Studios for a Textron gang. We've got a great gang line up and some great meaty, juicy topics that we wanna hit on. Um, I wanna let me introduce you to today's gang.
I wanna start off with this is, I believe his first time on he's, you know, he doesn't even have his colors yet. The, you know, not a permanent gang member. We're giving him a tryout, but I think he's gonna do great.
He's part of the, uh, visible Impact team at Futurum Group. He, well, our friend Mike Vizard knows him for a long time and if Mike vouches for him, he becomes a friend of his, not necessarily a friend of ours yet, but Guy and Guy has Bronx Credit and he has Bar Bronx credits too. Extra points for that.
Lemme introduce you to Guy Currier Guy. How are you? Great.
Happy to be here for Yes, the first time. Uh, Mike and I do go a long way back, um, and, um, it's great to be here. Thanks.
Thank you. All right. But you're not in the Bronx anymore, right, guy?
Where are you these days? In spirit? I'll always be in the Bronx as well as my, uh, my other place in my youth, Minneapolis, Minnesota.
So I carry both of them with me, but I'm in Austin, Texas. Beautiful. Welcome and thanks for joining us Guy.
Um, also joining us today from deep in the heart of Texas, San Angelo, Texas. It's our editor for Text Strong, ai, digital, CXO and so much more. Amanda Razani.
Hey, Amanda, how are you? Hello. Good.
Glad to be here. Glad to have you on. And then from deep in the heart of Texas, up to the top of the Rocky Mountains.
Joining us is our CTO and, and Full and, uh, UR group, CTA, Mitch Ashley. Hey, Mitchell. Welcome.
Uh, Good to be here. We're about halfway up to the top of the Rockies, but yeah, I didn't know what you meant. So, go.
They Get higher, I guess the day is yet young. You can still get higher. Yeah.
Well, I'll, I'll sign on when I get up there. Yeah. All right.
And then I'm happy to be having joining him back at my left hand here. Also, hailing from the Bronx, but back home in lovely Boca Raton. It's our Chief Content Officer, Mike Vizard.
Hey, Mike. And I was in the Bronx yesterday, so there you go. You were in the Bronx.
You did not bring the Yankees much. Good luck. I went to the Saturday game.
You went to the game They won. Okay. Yeah.
All right. Well, maybe you did them. Maybe you should go to every game.
That's what I did. But, um, anyway, Mike, welcome back. It's good to have you back here.
So guys, opening up to build or not build AI models, right? Building your own AI models. You know, this has been, uh, an evolving subject, an evolving question as we've gotten more comfortable with vector databases and LLMs and small language modules and all of the ins and outs of this and, and training.
Mike, what, what's the story here? There's a story on text drawing ai. It's about a survey that volter cloud service provider, um, sponsored.
And they hired SMP intelligence to go do this survey. And, and you have to read it closely because they went very narrow on who they were interviewing. So they went after folks who had AI expertise already, and they were working for mid to large enterprises.
But it was surprising to me to discover that on average, those organizations were already running 150 models on average in production environments. And there's this ongoing debate as to whether or not you should build AI models, because some folks are saying that we won't keep pace with the big hyperscalers who are investing in this space or OpenAI, and you'll always be behind the curve. And then others are saying, I don't wanna be dependent upon those people.
So, Mitch, what's your take on what's going on here? Can I get by with rag alone, or is everybody gonna need to build something that looks like an AI model eventually? Well, it, it was a very interesting study, like you said, it just kind of pointed me to these are people who've been doing this for a while.
You don't go from zero to one 50 and nine months, right? If, if you do, you've got chaos. Um, so I imagine a lot of those models are machine learning as well as maybe some, you know, uh, cognitive models, expert system models, things like that.
And definitely large organizations are doing a lot of their own model creation. They're using third party to do it if they don't, if they're new to it. Um, and they're for forming, you know, data engineering, AI engineering teams to do that kind of work as part of their processes.
Now adding generative ai, so you get into the rag, uh, part of it as well as, uh, vector databases and things you mentioned, Mike, that, that are part of that ecosystem, the technology that you used. I was surprised by one 50, even I guess in a large organization, you think like a really large bank or insurance company that that would make sense. You know, think about it on that scale.
But I would think a, a mid-size organization having 150 am models would be pretty unique. It, it was really clear though, that, you know, they had made investments and they see more investments coming or being made in AI in the future. They're kind of bought in, right?
So it's beyond the pilot trial stage. It's, we're gonna keep accelerating our adoption. And there's also a heavy reliance on the third parties to help people get that domain expertise to be able to build these kind of models, which I think a lot of people have to rely on.
'cause it's just very scarce to find AI talent. So maybe somebody can use this as, as a report to kind of help justify. Yes, we're not totally on the bleeding edge, even though internally we may be, uh, there are others that are out there doing this.
It's just, you need to find the right partners Guy. Um, is this just the age old bill versus buy conversation all over again as we kind of look at AI models and, uh, will most people wind up buying rather than building? Well, I think most people will do both.
And I think it is the age old discussion, and it's the age old framing of it as one or the other, when in fact, uh, not only is it a continuum, of course, um, but different stages of development of, of ai, um, require different types of work. So one of the things I noticed in the story was, uh, how frequent these models were, proof of concept. This is a way for AI developers to learn to try things out, um, to learn how models work.
We have to remember, these aren't all generative ai, non generative AI models have been around for quite a while, uh, for prediction, for recommendation, that sort of thing, you know, so yeah, it's the same old story, uh, all over again, just maybe five times as fast. What struck me is they are putting all this investment into proof of concepts, but when they find ones that are valuable, that they don't have a way to, um, move forward at that point and be, uh, have a plan for success. So that was interesting.
There needs to be a little bit more but plan there in place. Yeah, that's a really good point, Amanda, because a lot of people are trying to still understand what's the right problem to solve with what kind of ai or should I even be using AI to do that? Um, when I've talked to really large organizations, enterprises that have been doing AI for a while, one of the roadblocks they run into is just managing the models You get.
It's like version control of software, but its own kind of complexity for expert system models, AI models, and there are platforms, kind of AI ops platforms for managing that. But it's, it's easily, imagine having all those things out there. And now what do I do with it?
Do I keep it up to date? What data feeds into it? Who knows all that stuff.
It comes with its own kinda workflow complexities and data management requirements, which I'm guessing it's part of that, that roadblock, the hit It's own lifecycle. I mean, um, I think there are, there are maybe three life cycles related to ai. 'cause there's the model training, there's the model tuning, and then there's the rag part, um, which is not quite as germane to this.
'cause we're talking about building your own models, um, but tuning models alone, uh, that, uh, tuning more general purpose models is a critical path right now for a lot of the use of generative ai in order to make it more specific and differentiated to whatever your organization does, not just the industry that you're in, but how your organization operates. So that complexity, which comes straight out of the dev world, um, is now applied to really what are, not applications themselves, but services, parts of applications. I mean, Mitch, when you talk about, um, what purpose are you putting the AI to, one of the things I I like to say now is there really isn't any such thing as an AI application.
There's AI injected into existing applications, and there are so many ways to do this that just scoping and trying to figure out a, what you're trying to do or what you're trying to add to an existing application, and then b, how to get there quickly and productively and safely. That's enough to handle already. And that's where the build your own sort of comes in.
It's just, it's not pure build your own. The number of organizations out there that can build robust, reasonably active, re reasonably accurate large scale models is very limited because of the compute power required. But the ability of almost any organization of any size to take something that has been trained, uh, for general purpose and then tune it and then add it maybe with RAG into an application that's a lot more accessible.
And that's critical. That's where that one 50 number comes from, in my view. These aren't just models, these are many different instantiations of something being used throughout an organization.
All depends on how you count. Well, look, to me, this is gonna be a classic of the have and the have nots, right? In order to build your own model, you're gonna have to have a level of scale of resources that I think are going to leave out a lot of the S-M-B-S-M-E market, right?
I think it, it plays to the larger enterprises. Now, can we get third party providers who are going to give us models based upon vertical or, or, you know, some other demographic kind of data? Yeah.
Is it gonna be as good as a custom built model? Probably not. Especially over time when we get better at building custom models like this.
And so what you're gonna have is like what we have in many other areas of technology, if you have the resources to do something custom, you're going to do it and you're gonna have an advantage over someone who bought something off the shelf co software versus custom written software. Now, s does offer, you know, some advantages in that a lot of people use it so they get more feedback and it, it moves along. But clearly if you have the, the wherewithal to build your own custom models and do them well, I think you'll see the rise of these, what they're calling smaller and now mid-size language models.
Mm-Hmm. I will tell them from specific domains and people will use that. And I think you might see smaller companies down that path, but we mentioned that, um, you know, I grew up in the Bronx in the seventies and eighties, so I have trust issues and, and, and My, unless we know Mike, unless We know, and and my issue with this is like, all right, so if I'm gonna use the OpenAI or Microsoft or Amazon or Google or whatever it is, I'm not a hundred percent comfortable that they won't change the licensing terms or move the goalposts and what will happen to my data after I kind of share it with them and through a rag methodology.
So I'm kind of more inclined, at the very least for my most critical data, maybe to build my own, if I can find that way to make that easier. And I think tech will get easier. So, Mitch, I don't know, am I crazy or what?
Well, you're, you're spot on in this way. Earlier this week, um, it became public that OpenAI had a security breach in 2023. I had investigated, went to the board, but they kept it all private.
They didn't tell anybody externally until now. It's just coming out. And secrets were stolen.
I stolen and I assume for, uh, accessing via APIs, I'm not sure what else data was taken. So, you know, trust is, is goes a lot of areas. It's not only the, to what you pointed out of what's the agreement and how I can use the data and are they gonna use my data.
There's also just the security of a service that's a, that's a hosted model or hosted generative AI type of application. You know, I was thinking about the other part of this that, um, we often don't talk as much about is to do machine learning takes massive amounts of data. The reason why machine learning works is 'cause you have very large quantities of, of data.
I mean literally terabytes of data that, that you feed into these algorithms because that's what it, especially if beginner do unsupervised, where it goes and figures out patterns, it doesn't know what patterns mean. But it figures out the patterns and learns from that. Uh, supervises more guided, like this is a car that's not a car.
You know, some, some way of instructing the, the algorithms of what matches what you're looking for. And it learns what those patterns are. But that's only 'cause it has a lot of data that comes with it.
To Alan's point, what medium, uh, sized enterprise SMB organization is sitting on a mountain of data that also has been kind of feature set groomed so that algorithms can actually use that data in, in an, in an application to guy's point, you know, as, as supplementing to an application. That's a lot of investment for people to make. And you don't do that as a small company.
So I think there is a, we're creating sort of this AI digital divide also in company size organizations. Yeah. Sometimes when I look at that old space, I go, so data, if it's like money, like you're saying to me, let me put my money in a bank that I know that someone's trying to hold up every other day.
So, But, but, but that's the internet. You know, I this OpenAI hack to someone that I saw someone pose a question the other day. Geez, I I wonder if that the fact that they were hacked makes it possible that the Chinese can hack them.
What makes you think they did in order? Hell Yeah, it does, You know, trust in your data being secure in the internet, you know, that that could be the fourth biggest lie. I don't know.
I, I could, I wanna checks In the mail At least if I can hang out in a smaller spot that maybe no one knows as much about, I might not get in as much as the thought Okay. But Have to be faster than you not the bear. Right?
Right. But, but you know that, so that's the whole cloud security thing too, kind of way too. But the other, the, the flip side of that is because I recognize that I've created such a target and I I've amassed multiple data sets or what have you in this case, I also have more resources to make it more, right?
Is the, is the Amazon, is the AWS infrastructure harder to hack than the, the average infrastructure at a data center? I would say AWS infrastructure is more secure, but all the processes involved in my moving the data into that environment and all the stuff that I connect to it is way less secure than if I was just sitting in my own little private cloud somewhere. It's not the, it's not the AWS infrastructure itself that, or, or any of the big providers, um, where security is, is lacking or unavailable.
It's the fact that they're part of the world. They got a gajillion users, everybody's trying to get in there just to do their regular stuff. Um, and you're relying on all kinds of, uh, uh, good faith action everywhere and, and intelligent, you know, uh, uh, capable, experienced activity by all of these different customers and users and so forth.
That's, that's the problem. The size of it. Yeah.
All the a w security doesn't prevent you from keeping your S3 bucket open to the world. Exactly that. Right.
If you do that, okay, you do that. I do wanna say one thing, which is that, that, um, Alan, I think your point about the digital Avaya is, is, is, is a good one. It's a really good one.
The size of the models right now for the largest, you know, general purpose models, the foundation they're called, they're been called foundational models, is puny compared to what they're gonna be in two years. The amount of data is puny. Uh, we've seen this over and over again.
Something that seems huge, seems huge, massive, unprecedented now becomes ho hum shortly. So I think that there actually is a, a great opportunity for the mid-sized and up and even smaller ones to do their own thing with AI by using the foundational models and tuning. Because tuning doesn't necessarily take all that data.
It takes well curated data as opposed to large amounts of it. And I think that that's the model that we have now. The trade off of building your own even mid-sized model is time.
You can get to market much more quickly by tuning something that exists than by recreating it. Yep. Speaking of time, we're about out of time for this subject right here.
I guess time will tell, continuing the rift on, uh, on what to build or not to build. That is the question. We're gonna take a break here on Techstrong.
We're gonna come right back though, with another AI topic. This time it's networking in the age of ai. Stay tuned.
You're watching Textron. All right, folks, and we're back and we're continuing to talk a little bit more about ai, but in a much different context. Networking.
It seems this is an area that maybe we've been overlooking, but a lot of the networks that we have today weren't really designed for the massive amounts of data that are gonna be flowing through them in the age of ai. And looks like Intel at least, is reviewing a, uh, chip let slash system on a chip thing that they say will help optimize network traffic from CPUs and GPUs. But, um, guy, let's start with you.
What's your sense of what's going on here? Have we kind of uncovered, shall we say the weakest link in our whole AI setup is the network? Oh, yeah.
Uh, no, no, no question. Uh, it's really, I'm really happy to see a developing arms race in, in high-speed networking, uh, for ai and also sort of, it's sort of originated in the HPC world. So, um, there's the Ultra Ethernet Consortium, um, going up against InfiniBand, which is sort of the gold standard right now.
And now we have this OCI, uh, all designed, um, to provide, um, uh, higher and higher and more and more reliable, uh, bandwidth data transfer, whether it's CPU to CPU or, or more, more, uh, increasingly because of ai, GPU to CPU, the, uh, the Intel chip, um, multiplies about 16 fold. Um, the current standard from InfiniBand, which is about 256 gigabits per second, we're looking at four terabytes right now in this sort of prototype from Intel. And, uh, we were just talking in the last segment about the importance of massive amounts of data to get a reliable and accurate ai.
Um, obviously, uh, getting that data from near term memory, um, or high bandwidth memory through high bandwidth to whatever the processing units are typically GPU, but not always, um, that makes the entire process that much easier. That's why I was saying like what seems large today may not be large just in a couple of years, because as the bandwidth has been the main bottleneck, that has been the main, and it's not just a question of having, uh, a whole lot of data that you can bring that any one time, a larger model, more data into the model. It's not just that.
It's also avoiding things like packet loss, retries, ensuring that the data is available. And one of the interesting things about, um, this OCI chip from, from Intel is because it uses optical, you can actually situate the data and the GP or CPU up to a hundred meters away from each other, which makes a huge difference in terms of the physical layout of the data centers, how you run power and cooling. I mean, it has an enormous impact that I agree with you, has been, has been largely overlooked.
And I'm really happy to see more focus on the network. Now, You know, what's old is new again. Uh, I've seen this story before.
Um, first of all, let, let's guide to your point about big numbers. Let's really try to wrap our heads around four terabytes per second. Four terabytes, but yeah, Terabytes, excuse me.
Yeah. Four terabytes per per second. This is like light years distance to me, right.
You know, the fact that we're even contemplating it. But secondly, look, I remember, and, and so do most of us on this panel, 'cause we're of an age, not you, Amanda, of course, but the rest of us gray hairs or no hairs here at urban age where you know that, that bus speed, remember the bus speed of your, of your motherboard Mm-Hmm. And the old PCI card slots when that came out, how much faster that bus was, and that was the bottleneck for a while, right?
How fast can we move data from ram memory into on, on chip memory and, and stuff like this isn't the same thing. You know, the numbers are, you know, the guy's point, the numbers are ridiculous compared to the numbers we dealt with back then, but it, it's the same thing. But it also is again, a, a trend we see in technology when, when someone sets a new mark, the rest of the of the system needs to be brought up to that speed.
Mm-Hmm. And no sooner does it get up to that speed and you say, boy, we did it. We're up to that speed.
What are we gonna do with all this speed? Someone else comes along and says, I got a killer app that's gonna need just a little more. And, and so it's this, it's almost like war's law kind of, of, of, you know, machination.
So I, you know, I don't think we'll see the end of this. I think it just keeps going up and up like that Guy. I wanna follow up on a statement.
You made puny data. What's the definition of that? It's A Bronx turn.
It depends on your time window, Mike. Yeah. If you're trying to think two years ahead, it's all puny now.
Uh, it's not really puny. It's big. It's big because it's unprecedented compared to what we were doing just a couple of years ago.
Mm-Hmm. I've been around long enough, although I still have most of my hair. I have been around long enough, um, to remember when, you know, whether it was gigahertz or gigabits or gigabytes or whatever it was, 10 or 20 seemed like a huge number.
And now it's not sufficient, um, for any reasonable AI inferenced service, for example. It's just not. And that's crazy.
So that's why it's, it's crazy. Hey, Mitch, to um, to Alan's point, connect to DOT for me, if you would. Um, when we're looking at networking and storage, I don't think everybody remembers or appreciates the impact that has on utilization rates for the GPUs that we're all freaking out about the fact that we can't find and, uh, makes those things incredibly inefficient and we wind up spending a fortune on GPUs that are sitting idle waiting for traffic from networks and storage systems.
Do I have that right? You got that right. And add, add to that, we now have systems on a chip, right?
So we compact everything into one chip for speed and efficiency, but if your data starved, doesn't matter how, how fast or efficient it is. I think another thing that was really stood out to me about this in thinking about is, is you've now separated the transfer of data through optical, which means it's gonna run at its own frequency, its own technology separate from the, the frequency and the speed and the power of the chip. So you're not dependent upon ramping up, uh, the speed of that processor to get more through data throughput for it.
That's all driven by, uh, the optical inputs. And to guy's point, you know, it's hard to imagine a hundred meters between, it's between my desk and your desk across the office, Mike, we networking or GPUs or something. But imagine a data center where you're, you're transferring that kind of data between, you know, systems in, in, in there.
I I would think you're talking about like not just chip to chip transfer, but also source data to your point, right? I need to get that outta that database system, right? I need to get it out of that memory database or whatever, wherever that's located, get that in and out of that system outta of CHIP or NPU or GPU, whatever's processing that.
So it, it's, it's really kind of, it, it's, it's interesting and it's also kind of hard to imagine, uh, we're operating at these kinds of speeds. Of course PCIE was, you know, phenomenal. That was, you know, back in the day, Alan.
Oh my gosh. Wow. And I could put two PCI boards, right.
Have the faster game at 60 frames for a second. So it's worth noting real quick that, uh, this OCI, um, uh, prototype, it uses PCIE five really. So we're still PCIE mm-Hmm.
It's worth noting that ultra ethernet is still ethernet. Yeah. Fascinating.
Well, we don't Really have IRQ conflicts anymore. I miss those. You do.
Well What, wow, I had some other thoughts when I was reading the article, it struck me the optical chip lit uses a lot less power. Um, and you had mentioned about, um, the layout and the cooling and all that. So if everybody used it, would it have less strain on the power grid?
Thinking about the big picture, is it a better environmental choice? Absolutely. I have noticed, I just wanna say a profound lack of attention when it comes to AI development to, you know, power conservation to sustainability and that sort of thing.
It gets lip service, but the desire and the need to be part of the space race is far outweighs. However, Amanda and team, the thing is that the data center manager's problem is enormous when it comes to packing all these GPUs in packing CPUs in and getting them to run when physical proximity has had to be so important because of latency and other reasons, right? Getting the data to right next to like literally within 10 feet of at at worst is that's out the window now.
And you could put all the GPUs on another floor or underground or next to a water source or all kinds of things that you couldn't do before. Yeah. Somebody was telling me that there's more groundbreaking of, uh, new data centers in Northern Virginia than they've seen in the last 10 years, just in the last year and a half or so.
And where all the electricity for that is coming from. I'm not entirely sure, but Guy, let me ask you another question here. So let's say I have more efficient networking and storage.
Does that mean I can get by maybe with lower cost GPUs? And we're not all necessarily gonna have to rush out and buy this latest generation is super high in GPUs that people seem to be building, and maybe we can be smarter about it. I think we can.
I think it's maybe, maybe it's what, what do they call this? This is the permission structure for doing that, uh, because of the under utilization and bottlenecks that you were referring to earlier. I have to say that, um, I think that a lot of the, like non GPU approach, CPU only approaches to AI training, uh, and inference and, uh, you know, less elite to GPU approaches have been valid for a really long time.
Um, they're just not as safe a decision to make. You wanna get the best and the greatest. So this, this does help chip away at that.
There's so much that you can do without having to have elite GPU based, you know, systems. I think they'll get more energy efficient when the market demands, they're more energy efficient. That, that's again, a, a, a reoccurring theme in tech, right?
There's, there's old cowboy wisdom guy that says, never mistake a clear view for a short distance. How long before all these networks are up to snuff for what we need them to be? Huh?
Oh wow. We, um, it's gonna take a couple of years at least, I think. But you said all, let's say the 80 20 rule, 80% of them.
I think that the big providers, um, you know, the, the, the big, uh, hyperscalers and IBM and Oracle and all those folks, they're gonna be very fast and very fast means 12 to 18 months. Hmm. Yeah.
I think that's optimistic, but Well, that's what, now we're not talking about OCI Alan, I'm just saying in general. It's like, No, I know, but I, I think to your earlier point from the last segment, what we think of is very fast now. May not be so very fast in 18 months, and certainly won't be very fast in 36 months.
And I, I just think that it's, this is an arms race or a space racing. You just keep building and building. Anyway, we're gonna take a break here on Techstrong Gang.
We're gonna come back and we're gonna move away, I think from ai. We Wanted to plug the, uh, networking event at the Tech, the Field Day folks are adding. Oh, yeah.
Speaking. Before we close out the books on networking, let's give a shout out to our friend Steven Foskett and team at Tech Field Day, where they are, uh, it's day one of a two day tech field day on networking, and we'll be streaming it live right here on Tech Drunk tv. Uh, at the end of, uh, tech Gang today we have a full tech, strong TV lineup, including this Tech Field day, so you can check it out.
Tech Field Day is also streamed live on the Tech Field Day LinkedIn site. And, uh, the recorded version, I believe is available on the Tech Field Day YouTube, but that probably won't be up for a day or two or more, but you can catch it all right here on Tech Trunk tv. His Tech Field Day is now part of the Tech Trunk TV family.
It's getting hard to remember everything. It, it is, it's hard to remember any everything as it is. I already forgot what I'm with Ira Weer table.
We'll come back to him. Let's take a break here. Well, let's come back and talk a little bit about Security Rock U 2024 Password cache and the rise of Passkey coming up next on Textron Gang.
All right, we're back. As Alan said, we're shifting gears to talk about cybersecurity, which is always one of our favorite subjects here. And we often disagree about a lot of things related to that.
But, um, there's been discovery of a new cache of passwords that are in plain text. There's nearly a billion of 'em. Researchers over at Cyber News kind of found these, it seems like they've been collecting these passwords for a long time, so it's hard to say how many of them are still relevant, but, um, a lot of people don't change those passwords.
So there's probably some fall from all of this than, and all this is happening at a time when we're trying to convince people to maybe move away from passwords to embrace pass keys. But Mitch, um, walk us through exactly what's going on here in terms of a, how big an issue is this, and b, what is a pass key and how do we get there? How do we get there?
Well, as you said, it's unclear how, uh, fresh any of these passwords are. I think a number of 'em, I think the report or the article said about half of 'em are pretty old. I I almost look at this as this.
This is another, I'm gonna bon you on the head until you get the message about passwords. People look at this, this is so easy for us to collect and we've been, been collecting and we'll do versions of malware and all kinds of techniques to get 'em. What, what it jumped out to me is your password alone is not a security measure because it's too easy for it to be compromised.
Not just you're having it, but in where it's stored in whatever service or online application you're using. So if all you're using is a password, you don't have a secure account, whether it's your bank or whether it's your email system that you're getting email from. If you're using passwords and we all do, you have to take a multi kind of security approach, right?
You need system generated password. It's not password 1, 2, 3, 4, or my kid's name 2024, you know, or a rock U 2024 is my password. Um, all those can be, you know, broken too easily.
But to prevent those kind of hacks, you want a system generate a password. You also want to be using a password manager because system generated passwords, you're never gonna remember, but you can make 'em longer, which makes 'em more secure and harder to break. Not impenetrable, but it helps.
Um, you also want to be using two factor or multifactor, right? Every or organization should, every application they use as much as people. It's a pain for us to get out that authenticator app or send a text to ourselves, um, or, or some other method, an email.
That's another way that some, you know, have to jump through multiple hurdles to leverage a password that they may have gotten, um, up to and including doing SSO and as I mentioned, authenticator AppSec. And there's a lot of things that it's, it's a combination of approaches that you have to take in using passwords. And if you're not doing that, you know, you will be hacked.
Those passwords are gonna be hacked and they're, they're already probably hacked. So, and you Yeah, go ahead. No, go Mitch, finish it for please.
Well, I was just gonna say we'll talk more about passkey, which is kind of the passwordless approach. Um, you know, using the fact that you authenticate through another device like your phone, which has some biometric or other, or other authentication. So that passkey capabilities relying on another de another factor, right?
And device that you have that's built a trust relationship between that device and whatever service that you're logging into. But I think even Pasky are still a mystery to people. They're not sure what to do with that thing.
Why we haven't done a great job of informing, by the way, here's what, here's what a pasky is and here's what you do to use it and why you wanna use it. He just said that you're a Yankees win 2024 password is a bad Idea. Yeah, I I never used that as a password.
Um, but I'm glad I didn't. But look, I think we're looking at this all wrong, right? We're blaming the victim for being a victim.
Who out here? Raise your hand, likes using passwords. Who out here likes trying to think of a password that I'm gonna remember when the average user has something like 150 passwords or 150 different sites that use passwords and you wanna have a unique one for each one?
How, who, who, who wants to play that game? No one, no one wants passwords. Don't blame the end users though for using passwords when it's the app vendors and the infrastructure providers who say pick a password otherwise you can't use my app.
Mm-Hmm. And so, you know, okay, well I'll take that easy choice and hit generate a password that I know I'm never gonna remember, but I'm gonna put it in my password manager. I'm gonna pay the extra money so that the password manager is not just on my computer but on my phone.
And then I gotta remember my master password. 'cause I gotta enter that every time I go into my password manager to get the he generated password for this. And we're gonna hack that one anyway And we're probably gonna hack in anyway.
Passwords suck. Everybody hates passwords. It's not end users saying, please don't take my passwords away.
Nothing would make me happier than I take one password and tell 'em, go where the sun don't shine. I'm done with passwords. Well, I, I agree with you about don't blame the end user.
Well, you shouldn't be doing stupid passwords, but other than that, don't blame the end user. But Hold on a second. Yeah.
Most, most hacks don't happen because they physically, you know, uh, what's the word? Power up? Uh, you know, broke through your password encryption.
In other words, oh, you only had eight characters. You didn't use a special character and you only had one number. And we phys what?
I forgot the word. What did, when we physically Like brute force hack it, Brute force, that's the word I'm looking Dictionary attack, you know, that Kinda thing. Yeah, no, it's a brute force attack.
No, most, most of these hacks happen from this kind of stuff where somehow or another they broke into a password store right? From a particular vendor and they have a whole cash, here's a billion passwords. God knows how long it took 'em to mess that.
But they already know your password when they're going into your account. They don't say, oh, I know Mitchell's email and I'm just gonna group force start with password one and group force my way in there. No, they know your password.
That's where I think most hacks or breaches are coming from. Oh, they phished you. Yeah, they use those, they use them in a brute force attack and try, you know, to try thousands of passwords over time to log in with your email address.
'cause guess what? That's usually our user id. Yeah, but don't you think most of the attacks happen when they already have your password, they got it from your bank that they into or, or whatever.
They use phishing to get your password right or some other method, right? To get it. Or worse, they get, they use phishing to get someone else's password and that's how they finally With credentials.
Yeah. You know, I'm gonna, I'm gonna disagree with the blamy of the victim thing, and I'm gonna go back to some Bronx analogies here. But if I take my fancy car, drive it to certain sections of the Bronx Shade, the bonfire of the vanities, And, and I and I and I, and I leave the windows open and the keys are in the car and the car gets stolen, cops are gonna come take my report and then they're gonna shake their head and be somewhat sympathetic.
And then when I go home, they're gonna go have a beer somewhere and go, did you hear about this idiot? Well, that's typical cops in the Bronx, right? The fact of the matter is, yes, we can choose harder passwords.
Yes, we can all use password managers. Yes, we should sign up for the multifactor authentication. The onus is on the tech industry to eliminate, make obsolete the use of passwords.
And if passkey are the way of doing it, I'm all for it. Mitch, I agree with you. We've done a s****y job, a crappy job.
Excuse my language. We've done a crappy job of explaining what passkey are and how they work and why you should be using them. But I will tell you, whenever I am given the option of using the PAs key on a particular login these days, I choose it every time.
And then I wait for it to tell me that go check your iPhone, your iPad, your watch, your wife or whatever, uh, to get to get your pass key. But I I I love using them and not having to remember more Passwords. Time out for a second.
Speaking little s****y jobs. We do not exactly explain what a pass key is. So Mitch, take a crack at it.
What exactly is it? Passkey? So, so what it is, is, um, it's generating a secret, um, because you're logging into an application and it's, and it's saying, would you like to generate a pass key for this application?
If it's the first time, like let's say in your Chrome browser, whatever, it's, it's going to rely on a Chrome application to say, is this okay? Is this somebody is trying to create a pass key for this application to log into this Google app or whatever app? It's, that generates a, uh, a token, a security token based on private keys in the background, public keys that they're exchange just a normal PKI exchange that says this is this user because we trust the device that they're saying they are who they are, their, their phone.
Um, or it can be a, it can also be another computer. As long as it has some kind of, um, uh, you know, biometric, uh, verification on it, then that has key. It is a key, of course, you can't remember that either.
So it gets stored in your password manager just like you would a password. And then it fills that in the next time that it comes in supplying it, it can also be built into the browser and other options too. So it's, in a way, it's a password, it's just, and it's a system generated password.
It's just done with PKI in ways that, you know, are much, much more secure. The problem is, it to me is the user experience isn't seamless yet. No, too many times you go to an app say, I wanna, I wanna generate a pass key for this and says, I I I love the message.
I had trouble generating a passkey. See your administrator, right? How many people are gonna go call up the help desk and say, I can't generate a pass key for my home email system from work or whatever.
So it, it's got a ways to go. Um, but I also, I also want to, I wanna agree and disagree with Alan. Agree on one point, disagree on another one.
You know what Alan, the day passwords go away or the day email goes away. I would love email to go away if email would go away. I would spend the rest of my life trying to get it rid of passwords, but it's never gonna happen.
There will always be passwords out there. We're always gonna need some methods of protecting as much as you and I and everybody else hates them. On the other side, we need our tech vendors, the people providing services to us to enforce better security, not just generated passwords for us and save 'em in your browser, but force two factor authentication.
Google did this a while back where they're gonna start forcing it and, and it's improved everybody's security, but the provider can do mo more things than just generate a, a, a good password per se. And you know, you're doing it for the betterment of your customers. 'cause you don't want your customer data, your customer's access to get hacked.
And I think that's a responsibility that the tech providers have. So let's make security better for our customers. I think there's also a cultural aspect to this in, uh, app application development and, and in the, the applications the vendors are are, you know, developing and providing of, um, you know, let's, let's assume a breach, let's assume breaches already exist and let's, let's develop accordingly.
Um, I'm not talking about zero trust, which assumes that no node can be trusted to be secure. I'm talking about, um, the fact that containment and minimizing, you know, blast radius, um, are also important. It it, it takes me back to this, you know how all these discussions tend to be so binary, black and white, either nothing allowed or, or everything's wide open.
What do we do? I think that a lot of these systems are already compromised. And to the extent that we can drive a, an application development culture that takes that as assumed that is within the tech industry and it's better controlled, trying to get people to create good passwords.
I have a couple of thoughts on this as far as the personal protection obligation on our end. I love the facial recognition, which bypasses everything. Um, first of all, I guess my question is, um, do we think that's pretty safe just using facial recognition or maybe we could use two biometric, uh, methods, facial res recognition and voice recognition or something like that.
But as far as the password, I was given a tip a few years ago that I try to use and I'm wondering what your opinion, is this a safe password option? I have just come up with sentences because I can remember a sentence maybe a little bit easier so I write out a whole sentence as my password. Well, I don't know, but I, I know one thing and if I had to see my face every morning, I'd be scared.
Crap. Um, but, but I will tell you, with ai you could probably fake face and voice. Mm-Hmm.
Potentially. But in, in any event, Mitch, I I almost went to raise my glass when guy said Glass radius, huh? Oh yes, absolutely.
It's okay. Let's, let's do it for guy blast radius. Aw, You know what we, uh, we, what was that?
Wasn't it? DevOps of value down. Anytime you use the word blast radius, you have to do it.
Secret word. So I'll, I'm gonna, I'm gonna you because you said ai, I'm raising my guys To you. Go for it then.
Um, anyway, guys, we've gotta, I, we could talk about this all day, I'm sure. And Amanda, you had some, some good points there. I sometimes use sentences too, by the way.
Um, but we, we need to take a break here. We've hit our three, uh, topics, but we've got some bonus material for you. First of all, you know, in continuing our tradition of, uh, Andy Rooney, uh, kind of one-offs, we, us we have two Andys though we have, sometimes we have our friend Bob Reman, Rob Bob, and then sometimes we have our friend Ira Winkler.
And, uh, today we have a bitney segment from Ira Winkler where IRA's gonna talk about. Mike, do you remember, Uh, something he's angry about? I Do.
I do. He's gonna talk about, Who is Joe Biden Biden? No, uh, he's gonna be talking about why thinking like a hacker is not always a good strategy.
That that's absolutely. So he's gonna counter that, that idea with some really good thoughts about it. And Ira was a person who knows from this, right?
If you know anything about his, his career and history. So here's, uh, bite me with Ira Wink, the Ira Winkler segment on why thinking like a hacker may not be the best way to approach security. Hi, this is Ira Winkler with today's edition of Bite Me.
The one thing I wanna really address, and you know, frankly it's gonna be ironic coming from me, is I really hate the concept of thinking like a hacker. Like we have to think like hackers. And that's somehow a good thing.
Fundamentally, it really isn't. And let me be honest, I made my career by doing penetration tests. I'm thinking like a hacker.
Early on I made my reputation taking over banks, stealing nuclear reactor designs and the like, the reality was, was I had such little impact in actual security programs. It was amazing. And let me say I did have a good impact, but it was little.
And what I mean by that was, let me tell you when a, you know, thinking like a hacker might work, in other words, performing a penetration test and so on. So for example, if you want to go ahead and you need to get management attention on how bad your security is or the fact security needs to be improved, that's one thing. If you have a mature program in place and need to find some additional vulnerabilities that might not be of accounted for to see where your blind spots are.
Perfect example of when to use a red team. Think like a hacker. You know, another case where you have software, you think you have a good process in place, you want to go ahead perform application testing by, you know, hacking the applications.
Okay, great. The reality though is that this is only useful after you have a strong program in place and thinking like a hacker is thinking like an amateur. Because frankly I like, again, I've been involved with Walmart's program, HP's program.
I've consulted probably to give or take two thirds of the Fortune 100 at one point in time or another. And the reality is you don't want somebody who thinks like a hacker, thinking like a hacker. Oh, think outside the box.
That's not a good thing. By the way, that's another present SE session. But the reality is you need to have figure out how do I put together a comprehensive cybersecurity program that's resilient to attacks by quote unquote hackers with my Dr.
Evil quotes that also takes care of 99% of the problems. But you can think like a hacker, you have to think like a security professional. And this means you have to go ahead.
You have to understand your limitations, your bud. You have budget limitations, you have political limitations, you have personnel limitations, you have human resource limitations. And I mean by keeping your people happy, keeping them well staffed, et cetera, et cetera, et cetera.
And you have to go ahead and secure against all the world's potential ills within very, very harsh limitations. You don't have the luxury to think like a hacker, oh, I'm just gonna come in from the outside and do things nobody else can. Can you have to go ahead and think, look, I need to put a systematic program in place that is repeatable, that is addresses all of the concerns of the organization that says, Hey, yes, thinking like a hacker.
Hey, if I just shut off everything, that would be perfect, but I need to enable the business to run as a ciso. And you cannot go ahead and have think like a hacker. You have to, the most brilliant people there are are CISO of Fortune X companies who are out there realizing they have a plethora of vulnerabilities, a plethora of attackers, and they have to put a program in place that accounts for regulations, that accounts for privacy concerns, that accounts for just about every concern an organization has on top of the limitations of budget, people training, et cetera, et cetera, et cetera.
You can maintain a strong cybersecurity program thinking like a hacker and thinking outside the box. This again is a topic for another presentation, but the best hackers don't think outside the box. They designed the box.
And as a cybersecurity professional, your job is to figure out how to protect that box from re being redesigned. And I know that's a very fine line in differentiation, but thinking like a hacker, you know, oh, I'm gonna go ahead and do this and this and this. Awesome.
But that's if you are, let, let me give you this concept. Basically in large programs, they do have people who think like hackers. That is probably one to 3% of a large cybersecurity program.
So if you're dealing with a cybersecurity program of over 500 people, they might have five people going ahead and doing the red teaming and the like and periodically higher outside companies to figure out where are the vulnerabilities they didn't plan for. Where are the vulnerabilities that the box has produced? And that's the right use of it.
But fundamentally, you don't think like a hacker and even a hacker inside a large cybersecurity program doesn't think like a hacker. They think like a security professional because it's easy to do what I call pulling a nelson, which is going, ha ha, I got you. And I did a lot of gotchas throughout the decades.
That was not overly useful. The gotchas are only useful when I found systematic problems that need to be addressed and could be addressed in a comprehensive way. Yeah, I could pull out a zero day vulnerability.
Yeah, I could pull out a few things and get in. Getting in isn't the hard part. Protecting people from getting in is the hard part.
And too many people are fascinated with hackers and they need to stop that. They need to be fascinated by the cybersecurity teams that are out there on a daily basis stopping attacks from all over the world. So don't think like a hacker.
If you want a challenge, think like a cybersecurity professional. That's Ira Winkler for this edition of Bite Me. One thing about my friend Ira Winkler, he's never short on his opinion and he's not afraid to share it.
It's great to have him and thank cyra very much for that. com and we'll get it over to Ira and he can address those to you guys. Before we wrap up, Mitchell, I know you wanted to talk about a segment coming up on Text Trunk TV today.
Yeah, I really wanna highlight, um, an interview that I did with Cassie Crossley. She is an author of a new book, new book came out in March. Um, it's on software supply chain security.
But what I think is unique about her book, she has a couple of decades of work in security and in software, um, at a company. 'cause she works at Snyder Electric who deals with hardware as well as embedded systems as well as software. And so her, her book on supply chain security is looking at hardware, firmware and software and how you think about that supply chain.
And she kinda wrote it for multiple audiences where you're a software developer, you're a hardware engineer, or you're firmware engineer, you're a compliance person, you're in a leadership role, try to make a really accessible book. And, and wow, I mean talking to her, you, you'll see she gets going and you just kind of sit back and listen and learn. So, uh, please watch that segment 'cause Cassie is fantastic and I think you'll get a lot out of what she's do, what she's doing in her work.
And uh, there'll be a link in the description to the book, uh, at O'Reilly. You can get it there. All right, that's on Techstrong TV today.
As I mentioned earlier, we also have our tech field day, day one of Networking Tech Field Day on Techstrong tv and that's gonna be, if you've never seen a Tech Field Day, it's pretty cool. Mitchell and I participated in one last month, um, with Guy actually Guy did too, didn't you? Yeah, with Guy Now that I'm thinking about it.
Yeah. Um, so do check out Tech Field Day, check out the rest of our Techstrong tv. We will be back tomorrow for our great Thursday show.
Can't wait to have that one with more gang members. But until then, Mike, thanks very much. It's great to have you back here in Warm Sunny Florida, and I don't care what you say.
I'll be in the race tomorrow. You'll be in the race. And then we've got Mitchell guy, your very first, uh, Textron gang.
Thanks Guy Gets a thumbs up, right? He can come back again. Yeah, I think we gotta get him some colors to wear.
There we go. And then Amanda is always great Job. This is so funny because I knew I knew to wear the colors and then I just, I just, I, I know what to do.
Alright, next time, next time, we'll get you, Amanda. It's great to have you on. com and we'll see you soon on another Techstrong gang.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security bloggers network.