Techstrong Gang – July 17, 2024
Mike, Mitch, Amanda and special guest Chris Blask, explore why Google might be buying Wiz, a provider of a cloud-native application protection platform (CNAPP). Then, they take a look at the root causes of a raft of breaches involving cloud platforms such as Snowflake. Finally, the gang turns its attention to how deepfakes enabled by artificial intelligence (AI) technologies are, for better or worse, sowing more seeds of distrust.
Transcript
Hello everybody. I'm Mike Viser. Alan Shimmel is still on vacation, but we're gonna be talking about some awesome stuff.
Nonetheless, Google is reportedly gonna spend, oh, roughly 23 billion to pick up an outfit called Wiz, which is a maker of a CAP platform. Then we're gonna jump into, well, snowflake and all these single points of failure that are starting to show up in the cybersecurity landscape. And then finally, we got deep fakes being targeted at the Olympics with Elon Musk, and it's just a giant party.
And who knows, maybe I'm a deep fake. We'll be back in a minute. All right, welcome back, everybody on the gang.
Today we have Chris Blas joining us Once again, he's north of the border as always, or at least for a while until maybe it cools down and wherever he happens to live. Chris, welcome to show. Hello World.
All right. And then of course, as usual, we have Mitch Ashley, our resident technology expert on all things cybersecurity and DevSecOps hanging out in Denver. Mitch, good to see you.
I, I can't, one up. Hello world. So I'll just leave it at Chris's.
Hello world. Thanks, Chris. All right.
And then finally joining us today from the great state of Texas is Amanda Ani, who runs this text drawing AI for us digital CXO and tech Strong it TSM Man, as always, good to see you. Good to see everyone. All right, well, let's get started, shall we?
Hey, Mitch, I'm gonna throw this first one to you because, well, I'm not sure everybody knows who Wiz is that Google's acquiring, but it's apparently there maybe largest acquisition ever, and it's something called A-C-N-A-P, which I think stands for Cloud Native Application Protection Platform. One of those, uh, tongue rolling phrases that Gartner coined not too long ago. But, um, walk us through this deal a little bit and why we should be paying attention.
Yeah, CNAP, it's not what, uh, c-level executives do on the afternoons at 2:00 PM so that's a different on the CAP. Um, anyway, so the rumor, the rumor, I guess a rumor, or I'm not sure how totally confirmed it is, wall Street Journal came out with an, with an article, I think it was Friday, uh, talking about the potential acquisition or that they're into acquisition with Google. And, uh, what of course got everybody's attention.
Um, Wiz is what about a 4-year-old startup, um, very well funded. I think they have about or whatever, or a billion in, in funding, if I remember right. I think their last valuation was about 12 billion.
So the, that Google wants to pay double pay 23 roughly. Uh, looking to do that, of course, got all of our attention. Like, okay, so how do I sign up for that program?
That's a startup's dream. Um, you talk about unicorns. So it's, it's interesting because, you know, where, where Wiz is focusing is right in the middle of the whole move to cloud native move to microservices and containers, and how do you manage Kubernetes and secure it?
And it's, of course, you know, the more the market moves to it, the more you need solutions like that from Wizz and others. So it's, I think it's directly recognition, um, by Google that, you know, they need some additional security capabilities, uh, to manage the Google compute platform and all the microservices and cloud native things that you're doing on it. Now, obviously, Wiz isn't just a, uh, platform for, uh, for Google's, uh, compute platform, but, or cloud platform.
So, you know, that's one question is will they kinda continue to go after the broader market? I would expect so, at least for the short term. So we'll see as this deal comes together as it finalizes, sometimes these rumors come out and the next day the deal happens.
Other times it kind of hangs out there and maybe it dies on the fine, maybe it actually happens. So I think it's just significant just to see Google saying, this is important. The so important in security, we're willing to invest this kind of money in it.
And of course, it gets the interest of every VC investor and startup, uh, even non startups in the land who are kind of thinking about maybe an acquisition would be helpful to them. Chris, um, synapse, were supposed to be kind of on one level, a roll up, right? I could aggregate all my different tools into this platform.
Many of the tools became features, and my total cost of security was supposed to be lower. Um, of course, there's a big gap between theory and reality. Are you seeing, you know, the, the organizations that you've talked to actually deploying cnap PS and, and what drives that decision?
Yeah, I think that the, the only answer to the short note that fit in here is yes. Um, and, uh, it, yeah, we're always looking at, you know, where have we been right now? Where are we?
Where, you know, where have we been? Where have we, where now what's happening right now? What does that tell us about the future?
Right? And as Mitch said, there's lots of reasons for this. You look at valuations, you know, the financial side, you know, the function side.
What are they trying to do? And if you're trying to guess where we're going, you know, you say why now, right? Why not earlier?
Why not later? And to me, this one just kind of makes sense, right? And the, in the, in the supply chain world, right?
You know, right now in the whole software build material world, so much of the conversation is about how do we put all this stuff together, right? And you get into these edge complexities that in the case, you know, Google hasn't really had to address until now. Now they kind of do.
You know, and it's, you know, we're, we're always as security people or a tech professionals, people who care about the industry, you know, worrying that there's some cliff or, or barrier up ahead, you know, we need to deal with. But, uh, but we keep getting there, right? And, uh, you know, to harken back to the last episode I was on gonna talking about CISOs, right?
You know, cso, the CSO role is fairly obvious. You know, the, these sort of functions and features are fairly obvious. This when is the time to do it.
I think this acquisition is another good example of, it's about time for this one. Mitch, do you think that we'll see the other cloud service providers follow suit because Google bought Mandy and, and clearly it's making a bigger deal about security than the other guys are. At least that's my impression.
But, um, will there be kind of further rollups in your mind? Oh, no, absolute. Absolutely.
Be more re-ups, um, whether the other cloud providers acquire companies, you know, they'll have to fill, fill a gap in their offerings. But so many folks, you know, Microsoft and Azure and, and AWS have a pretty rich set of security offerings already. Um, so I'm not saying they won't do acquisitions.
They certainly will. I mean, I think security is a, a ripe area for continued acquisitions because, you know, I actually just posted on this, uh, the other day in LinkedIn, you know, headlines about another breach. I know we're gonna talk about this in a little bit, actually, aren't headlines.
So they aren't news breaches that button every day. We're all numb to it. It's organizations are looking for, what can I do?
What else can I do? Is there more other frameworks? Is there processes and incident response?
Is there technology that I can be using? What do we have to do to kinda help help stem the tide, or at least assure the shore, the walls, the, the di if you will, from, uh, breaches occurring? And so we, we really need to turn our focus to what solutions and approaches are working.
And I think the cloud vendors are in a perfect position to not only market what they do, but really communicate effectively about what customers are doing with their solutions. 'cause they can talk about it on a broad basis, right? In our cloud, here's how somebody uses blah, blah, blah service from either us or another vendor.
It's a great time for the them to partner with, uh, security vendors as way as well already in their ecosystem and, and nuance too. Well, let me follow up on that with you, because Google bought manian, and one of the things that they seem to be positioning themselves is a provider of cloud security that goes beyond their platform. But do you think organizations are gonna look to Google for securing not just the Google Cloud, but other clouds and on-premise environments?
Well, you know, if you're, if you're Microsoft Azure shop, you're probably not, you know, hunting up the Google marketplace. But then again, if you know somebody like a Mandiant or a Wiz or maybe already a customer, you may not necessarily jump right away just because Google bought them. Unless you see actions taking of, okay, it's clearly this is now gonna become Google centric.
It's really how committed are, are they to the broader market? And do they leave it alone and let, let Wiz be whiz, or do they make it, uh, Google Wiz and now it's just about Google, move on to this other platform tomorrow. Know it's like, let's do that in 12 months, right?
'cause we've got so much invested, not just in the technology, but in processes and training and people and, and operations around certain technology. So I think, I mean, it could be wise for Google to leave it a market solution. Um, and, and, and really, I think they have a much bigger addressable market if they can address things that are happening in, uh, Oracle Cloud as well as AWS and Azure.
Chris, what do you think about that? Because it seems to me we live in this hybrid world now, right? There's on-premise environments, uh, multiple clouds, most organizations have two or more.
Um, from a security perspective, do I want a platform that addresses all of those? Or am I gonna line up on a particular platform with a solution? It it, it, it always depends, right?
You know, and, you know, for the vast majority of organizations are relatively small, right? And, you know, the, not just the security, the whole Google platform, you know, how many companies, uh, around the world, uh, just use it just works as opposed to sourcing out a bunch of different parts. You know, so anything these, you know, these major platform providers do, you know, that allows the, the bulk, the 80% of organizations out there to have one, uh, you know, as few as possible people in to turn to, that's just pragmatically good.
Now, as you flip the opposite end of the spectrum, if you're extremely high risk and you have extreme resources, nation state, you know, uh, critical, uh, manufacturing whatnot, um, you still need to have the in-house capabilities. You have to be able to make the choices on the ground where appropriate for you. So in in that world, again, you know, you know, no, just because you're a large organization doesn't mean you don't have infinite resources.
You, you need to have partners you can work with who can aggregate the, the features and functions you need into consumable platforms and packages. But there's still no, you know, there are no is not, and may never be a single solution to the, to the complex cases. Hmm.
Amanda, under the heading of AI is the answer. What was the question? Do you think that pulling all this data into one central location here for Google, using a CAP is kind of a, a, a piece of a larger AI strategy for Google?
Well, I think any good company is going to try to assess their deficiencies and where they could be better. And AI presents a new threat in cyber as well. So, I mean, I think it, it's a, it's a good strategy to partner up with another company that can provide, um, options that maybe they can't.
Mitch, following up on that, do you think that AI played a role in this strategy? And, um, how do I kind of make this work if I've got all this data in one cloud versus another cloud, and I need to show that to something that feels like a common, uh, AI model? What are the mechanics in making that work?
You know, I question, is it the AI that Wiz might be doing, or is it Google's AI that might be easily incorporated in a relatively new product, newly built, newly architected, like a wiz? Was that one of the considerations? I don't know that this is the case, but I could see Google saying, well, we can buy A, or we can buy b and b, we can really make some hay with ai, our Google ai.
Um, so I, I, I think at least I think there's a good probability it may actually kind of go Google down instead of whiz up. So we'll see, you know, what happens in the AI space? Your point about data and all these clouds is a really good one because, you know, we're, we're data is gravity.
We've talked a lot about that and, and where it lives as well as on-premise. You know, I, I think, but that's also a fact of life. We live in a world where most people, enterprises certainly are, are multi-cloud, sometimes not by choice, by acquisition and for other reasons.
So services and APIs and things like that make, make it more reasonable to use AI facilities. Maybe you're building it around Google's strategy, but you're not completely living in Google's cloud. I think that's just part of the architecture that, uh, people consider.
And where is our center of gravity for where our data, maybe even our AI lives, and is that, you know, one of the major hyperscalers, or is it somebody else, you know, a philanthropic or open ai, whoever it might be, that's, uh, you're gonna build your strategy around. Hmm. Chris, are you optimistic about the state of cloud security?
And I think we've talked about this in the past, but, um, one of the challenges people have is it's not so much that the cloud platform itself is any more or less insecure than anything El other folks might have, but we just don't seem to have the right workflows and processes in place, and it's just hard. So will this get easier as we go along? Ian, you know, by now I'm optimistic about almost everything, right?
You know, I think all this reports out in the end, you know, but either grand sweeping, you know, across the industries kind of statements, you know, for you, for me as an individual tactics, uh, end up being really, really important. Um, but so, but broadly, no. I mean, you, this, this, it was 1991 or 92, right?
Working with Belt Canada, you know, selling firewalls and, and hearing, you know, say, Hey, our customers can't manage these. Maybe we can manage these ourselves. So now we're 30 something years into manage security.
And as you say, the whole concept of cloud, you know, what was it 10 or 15 years ago? You know, it's just somebody else with the computer. It's like, that's right, you go and have to run it.
So generally, yeah, it's all gonna work out. You know, they used competitive pressures, you know, to Mitch's earlier point, there's always gonna be breaches. You know, breaches are back, don't be one.
However, you know, since the world is like that, you know, when breaches happen or bridges collapse or whatnot, engineers learn lessons. So don't get your fingers pinched off in this one. Um, go back to my last name is most companies, and again, you know, most people watching this, the show, for example, um, don't have a ciso, right?
You know, that most companies don't have these capabilities. Stop worrying about it. You have enough problems with staying in business, focus on that trust Amazon or Google or whoever.
Um, but as it gets more serious, you have to take more ownership. So there are very good service that either, you know, listen to folks like this, listen to folks like Mitch who can tell you that, you know, over the last 18 months, no, you don't wanna do this right now, maybe next year. Uh, that's where the, the value of expertise comes in.
So it all depends on where you are. But generally, yeah, Mitch, to Chris's point, 'cause I've had this conversation with some folks out there, and, um, it kind of goes along these two lines. On the one hand, you know, they'll spend 10 minutes complaining about the fact that they can't find the skills and expertise required to make this security thing work.
And then when you ask them, well, why don't you lean more on external expertise? They go, well, security's too important to trust somebody else. So, um, where should we land on this whole, how much should I do versus the platform people versus third party service?
Well, it's, it's, that's sort of the internal builder, buy homegrown versus not. And by the way, I would listen to Chris Blast if you're gonna listen to somebody. Thanks Chris, but people should be listening to you for sure, for sure.
It's who I go to when I have a question. It's Chris. Um, you, you, I think you have to, you are relying on others 'cause you're using security products and technologies from third parties, and hopefully you're leaning on their solutions engineers and the professional services that can help you implement that, as well as what Chris was talking about around managed services.
Um, it, it's hard to just lift and shift and say, okay, it's all your problem now and you're gonna run security for us. 'cause security isn't just an operational thing. It's, it's, uh, as Chris Bets talks about it at AWS, um, it's a culture of security, not a security culture.
So it, it's really infused in how you operate, how you build software, how you make decisions about priorities around where your company efforts, what you invest in, et cetera. And that's, the security's the number one priority on everything. But it's, it's part of that, you know, you could tell whether security's important or not.
Like, oh yeah, what are we gonna do to secure this? Or, what's the security strategy? Let's make sure we're, you know, what is our strategy?
Why we're making this decision approach to do that. So, you know, I I've always been a fan of, find people that know more than you do and, and help, help gain your knowledge from them and your experience by working with them and what you need to grow internally, grow, grow that too. It's sort of a multi-pronged strategy.
I think it's a good sign when a company is proactive in trying to improve. Well, there you go to the Amanda's point. This is a developing story and it's part of the cybersecurity acquisition du Jos.
So stay tuned, we'll update you as this deal, hopefully maybe closes, but who knows, there might be other deals in the offering. We'll see what happens. 'cause the soap opera never ends.
We'll be back in a minute. All right folks, and we're back with what can only be considered the daily crime report. 'cause once again, we're talking about cybersecurity breaches this time.
It's, uh, extensions of the Snowflake breach that people have been talking about. This one involved at and t and Advanced Auto Parts. And then at the same time, speaking of autos, the folks over at CDK, uh, may or may not have paid a ransom.
We'll see. But suddenly all those car dealers are coming back online and no one's explaining exactly why. I'm Chris, let's start with you on this one.
To Mitch's earlier point, breaches happen almost every day now, and we're kind of getting innu into the whole thing. But have we created sort of a single point of failure here with all these, uh, cloud and SaaS platforms that we embraced? Because in the rush to co in COVID, nobody built their own thing.
So everybody went out and just kind of started using all these third party apps. And did we really think through the security implications? Lemme see if I word backwards with that.
Did we think through the security implications? You know, Lord, no. Yeah.
Why, why wouldn't we start now doing that? Yeah, we both, yeah. How do we get up important?
Um, I don't think a lot of it really had to do with Covid, you know, but, but you know, the rush to adopt things that, that frankly had been laying around mostly for 10, 20, 30 years, you know, do a little remote stuff, um, may have pushed a lot of issues, but I don't think we really could have gotten much further earlier. Right? It's not very satisfying question.
We always wanted to you, you know, why, why aren't things better than they are? But I can't help looking back and saying, okay, where over the last 30 years, where's the time focus at, you know, budget, whatever to do better than we've done now? So we keep walking into these tramps, to your point, you know, where everybody starts doing this, and all of a sudden, you know, that creates the vulnerability space that someone exploits.
And that's our next, you know, big defensive wave. Um, we keep surviving them. Most of us.
That doesn't help you much if you were a company or person or employee a, you know, who absolutely didn't. Um, but it's, it, I don't see an end anytime soon. I think people are alive today, will see the end of this level of thrash.
Um, but, you know, putting it all together, you know, we cannot, we still do not today have the ability on really any level, you know, you know, the supply chain is a good model for, but it's not just that. What is all the information you could have to make these decisions in advance while things are happening? Uh, how long would it take to get that information longer than you have?
So, you know, to that end, yes, we keep making a single point of failures that sweep up a lot of us, fortunately all at the same time. And diligence, you know, will have a positive effect on that for quite some time. Mitch, are there steps, things people should be doing to evaluate these?
Uh, what essentially are third party risks, right? I mean, we went to use an application and, um, how do we know that the people who built the application or SaaS environment actually made it all the right security steps, or at least reasonable ones? I mean, there are compliance check marks, but a lot of those are the basics, right?
Yes. The, uh, the shared risk model, right? Which means I'm distributing some of the risk, meaning I'm really relying on other people and their services doesn't mean that the risk is actually shared.
'cause it's all still yours. Doesn't matter whether Snowflake had the problem, it's the customers of Snowflake that ultimately have the problem or whoever, you know, just, just, this is one of many, you know, I I think the headline needs to flip from what's the, uh, breach du jour or yet another breach today. 'cause because it, it, it is, it's just something where you're like, okay, so what at and t had it?
How many, okay, is that a big number? 'cause the last time I heard something else, that would seemed like a big number too. I, I think, and, and then now we get notifications on our LifeLock applications and everything else, or from Experian or whatever thing.
Like your, your information may have been stolen. I kind of assume it has already. So, and probably multiple times.
I, I, I think the process, if you think about security, we think about it as technologies. Really what security about is this continuous effort of continuously improving our security, not just operationalizing it, but 'cause security shouldn't be a static state. It should be a constantly evolving.
'cause the threats evolve. And also what we're doing, our environment evolves. If software developers are deploying code a couple times a day a week, or would maybe multiply it multiple times, tax service changed.
Kubernetes is wrapping things up and down as demand changes. Okay? That could change our tax service too.
We're using another third party service rolling out in a release coming up. So I think the, the real role of security is not bringing a beachhead and say, okay, we're good for a while. It's how do we continuously improve this?
What are the thing, what are we not doing? Who are we not talking to that might have some other answers. Has someone done a better job of implementing the NIST framework for this?
Um, I saw Chris Blast talking on, on, uh, Textron Gang about some of his work. Where do I find him? How do I go find out what that stuff is?
Oh, software supply chain. Okay, good. Good.
That's good. I'm gonna go, um, talk to Cassie, uh, Crossley about that. There's a lot of people doing really good work.
And I think that's, if you aren't doing that, if you're kind of not taking this as a constant thirst for learning and understanding, and how do I improve, um, then you're, you're certain to fall behind. And, uh, if you aren't kind of wired that way, I think it's really tough for folks to wrap up that flywheel and keep it running. Chris, I love your perspective on it.
If you, if you agree or you have some different views. Yeah. The first, first, uh, morning of the first security event, uh, of any sort that I've to where were launching, my, the first one I, my products, these two posts came up with a really good technical question, and I, I knew the answer to that when I was proud of myself.
I was like, aha, I know they, the thanks, they, well, when you came back and said, uh, I had a second one, and I actually knew the second, you know, answer to that. And I, I can't explain how little I knew about all this at the time. And they came back with the third one.
And I said, and at this point, I'm hyper tired before the date even started. Of course, I love Jed about buying caffeine. And I said, that's a great question.
I haven't any idea. But what you're really buying, you're not buying a product, you're buying a relationship with, with a group of people who take this personally. And if they find something like that, you say, Hey, what about this thing?
It's a problem. It's a real problem. They will live on anger and caffeine until it's fixed.
And that's it. And I said at the time, it's like, that's it. And it'll never get any better than that to your point, right?
So that most organizations, even organizations with the resources to have CSOs and have budget, you're successful come down to your ability to determine whether your partners you're working with care. What does that mean? Do they all wanna look like they care?
Yes. Uh, but you know, a lot of people in the industry take this really seriously and take it really personally. And that's the organic benefit.
You know, the actual digital tools are just the temporal whatever happens to work right now. Yeah, that sounds really hippie, but it's just kind of true. Well, let me follow up with you on that particular point, are security teams, and it, it's, it's a function of human nature rather than a flaw per se.
But are they too focused on the things that they can control themselves? So if there's an IT environment and they can go and apply the fixes, they're going to, you know, that's something that they can have an out, an impact on the outcome with these third party applications and services, even though our risk levels are rising, the security team, it's difficult to affect any change, right? I mean, what am I gonna do?
Send somebody a memo? I mean, so is that part of the reason why we're not focused on this expanding attack surface And try to find a concrete answer to this? You know, the the, the answer is just yes, right?
You know, the, the, uh, everything you says you, so we all try to control, we can con control a lot of security and success in business or anything trying to predict, right? You know, so the kind of problems we have with corporate, you know, for-profit security, um, breaches and operations are kind of predictable just in those words, you know, corporate for-profit, you know, what are the motivations? How do we get the resources?
What are the budgets come from? What do people care about? And it, you, you know, just, this is not, there's nothing fatalistic about that.
Uh, but you just have to realize those things are what they are. As security people, we love our standard feelings, which again, is very predictable. We should be self-aware to walk in and say, well, I told 'em what they need to do and they didn't do it, so I'm right and they're wrong.
Ah, sorry. You're a hacker. You're wrong.
You know, it's not just about hacking the, the digital whatever or having the right answer for the current security issue. It's about understanding, I'm trying to protect this thing, this company, this nonprofit, this government entity, it has these character characteristics and not be the subject of a conversation like this where we're all saying, oh, here's another corporate entity that I've hacked and breached. And if you look at 'em closely, you'll find out, yeah, you know, they kind of weren't taking it seriously.
And whose fault is that? Great question. C-suite.
You know, you should know that stuff anyways. It's all normal risk like anything else. And, and from the engineering and technical side, you shouldn't be surprised, you know, that you're asked for a massive budget to take care of something you're really passionate about, doesn't work in a, for-profit corporate world, you know, match.
Yeah, I think there's still, I think there's still also a lack of communication and there should be better communication between all departments and, and sometimes the, the action plan for when there is a threat is not clear across all departments. Mitch, I will posit, um, a theory, you can tell me how off base I am, but we have SOC two compliance, and theoretically all these people are supposed to be filling out a form and it basically says, yes, customer data is not exposed to internal employees, and we did all these check mark things. Do we need to take that to a higher level where we're creating some sort of, uh, independent third party service that's rating these third party platforms for their security capabilities so that people factor that into their buying decision?
Well, they, they actually do some of that today. You know, compliance is, there may be a list of requirements. Oftentimes it's what are your requirements and are you following that of is usually what compliance is about.
Guided through some framework, um, providers today, um, you know, pay people to do pen testing and, and social engineering and things like that. And they provide reports from those organizations. Um, so, so that kind of information, it's not a rating scale, but it is a, you know, semi your most recent pen test and what kind of issues came up and, and, you know, they've likely been resolved, hopefully been resolved, but it gives you a feel for the kind of issues that they've had over the past.
I, I think in addition to compliance and checklists and things like that, which are all helpful. And one of the things I wanna highlight is, uh, cisa Secure by Design Initiative. So this is taken a different approach.
Let's let's step back and say, how do we take security to a different level in terms of how seriously we take it across the organization? Kind of to Amanda's point, right? Rather than being in security organizations.
And I'll make sure everybody's doing enough to get by or what we think they should be doing, or enough that we can say they're doing enough. Um, and the security by design initiative, a lot of people have signed on to it, it's relatively new, but I think it gives some ideas, some guidance about how do you elevate decisions around security. So it's as important as what is the cost of this application, or what's the cost to build this, or what's the cost to, to, uh, move to a different cloud provider, whatever it might be.
Um, and, and I'm not doing it justice. gov/secure by design is where it is. There's a pledge.
People can take things like that if you want to take it that seriously, but there's a, some really good thinking, some resources that cisa and then also the FBI from some help from them to kind of help, how do you, how do you as a security organization turn it from just the cost of doing business and filling out compliance information to thinking about how you create kind of that, uh, culture of security I was talking about earlier. So definitely check that out. To your point, and we talked about this on an earlier show, and Chris, I'd love to get your thoughts on this, but, um, it seems like a massive amount of the legacy software we have out there, whether it's in a SaaS platform or on premise or whatever, is just fundamentally insecure.
So do we need to go back in and kinda restructure all these environments and maybe change the reward system to drive that? 'cause uh, we're so obsessed with new features and capabilities that meanwhile we have all this stuff out there that is, um, certainly not created with secure by design methodology thinking, that's for sure. Right?
And, and we do in the end, right? You know, and, uh, we, we rightly so I call out a lot of folks on these shows, but Ginger Wright and Andy Bachman and, uh, item Blue National Labs, department of Energy, secure by design stuff, you know, as, as I'll continue to say, when you see brilliantly interesting people doing things at a time, it may be time four, right? And so secure by design, you know, as a sort of concept, you can go back as many decades as you want.
And while the epic rans, you know, we should be doing it right the first time, but this time around is much more mature, you know, it, it takes into account things like, you know, I run a power grid, um, and then our grid does a lot of Windows seven and Windows xp, and it's not going away. Um, therefore, since I have all these things, how do I then, you know, design my overall system securely, um, so that the, a lot of these com you know, tactical complaints we have over time. I love, you know, I love the operational technology, ot, the industrial patrol system world.
And, uh, I can't tell you how often, you know, to this literal day today, you know, I see Windows seven and Windows xp and you can say, you know, that's massively insecure. Um, but you're saying that to someone who paid a million dollars for a laser cutting machine and they're going to, you know, maximize the profits on that, and if you upgrade, it stops working. So yeah, we'll, we'll get there, but we're not, well, we can design securely without, you know, doing the logistically impossible things and replacing a rhythm.
Mitch developers spend what percentage of their time trying to fix stuff that already exists, maybe 10% or less. Do we need to just change the, the hero dynamics of this and just say, Hey, we're gonna make sure that developers who are fixing stuff get credited with that and that compensation drives behavior and we're just kind got the whole compensation model wrong. Yeah, it's kind of the mountain of, uh, technical debt, right?
Or security debt. Another, another way to look at it. Um, you know, there's all kinds of stats about how long it takes to get a patch to a vulnerability into production, more or less fixing something in your own code.
Um, yes, that's something that we can do. And oftentimes people organize, okay, it's security debt day Friday, we're working on this and trying to make, you know, let's make another dent in this. Or approaches like that, or gamification of it.
Um, it, it's, it's hard because developers are usually rewarded on capabilities that they've shipped. You know, what features have we put in our software, we launched the product, all of that kind of thing. So I, I think, you know, the, the tide is maybe shifting somewhat secure by design is one initiative.
Uh, DevSecOps is really being rethought from the shift left approach of let's just do it earlier in the process, which is a good thing. Not to say that isn't valid, but let's think about security systemically through the entire security lifecycle or software lifecycle, whether it's something we do in the front end, um, as well as while we're building software, doing code reviews, whatever it might be, um, there was part of a, there was an announcement or a, a call from system and the FBI to, uh, make better use, more secure ways to make operating system calls through code. 'cause people would pass just a string as a parameter to the operating system and would execute whatever's in that string.
Well, guess what? That's a really easy thing to compromise. We can get into that, into that flow parameterize it, use the libraries, things that are secure of how it talks to the operating system.
Just improvements like that could make a big meaningful difference in the security of your software. So I think the other thing we also have to consider is, it's not just the software we're building, it's the infrastructure and softwares you're using to build it. It's the underlying tool chain and infrastructure.
That's where a lot of our supply chain software supply chain, uh, attacks start. Whether it's, uh, an image of something that comes into the pipeline or like what happened with SolarWinds is something in the CICD build process, it gets compromised, uh, through a vulnerability in, in the software there. So that entire tool chain has to be re-looked at and think, apply those same security principles that we have always done in the network world and think about segmentation and, and, uh, separation recoverability, things like that of how we not only build software, but how the process was as we use to build it.
And your your point, I give everybody a, uh, can't get a much more contemporary, uh, contemporary, uh, example. So as of Monday that, you know, this week on the, the CA SBO work group call is a public calls, you know, nobody speaking out of class. The Italian team came and give a talk about, uh, uh, depend seats, you know, just if you take the, you know, let's take a big look at dependencies and say, can I really tell are the, is the dependency information I'm getting really that reliable?
And if so, how, uh, how reliable it turns out. Yeah, no, right? So to your point, Mitch, you know, we have a, you know, a lot of things to put together.
And, uh, realistically, you, you're not in the position to put most 'em together now, you know, now, you know now, as always is the time to do is the things you can do and to plan for some of the things that, you know, 12 and 24 and perhaps more months out that, that you'll get into. Um, but you should be looking at, you know, this issue of dependencies. If that sticks in my head, you know, how is everything connected?
How far can I go? How deep can I get? You'll probably need to expand that bubble in, in the, in the near to midterm.
Alright, folks, I don't know exactly how we're gonna solve this problem, but I really do like the idea of once a week bring out your security debt. That would be a good place to start. All right, we'll be back in a minute.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Alright, folks, and we're back. And if you haven't noticed, every time that there's a major event, there's like a cybersecurity storm that follows it, and the latest one is the Olympics. There are, uh, many scams now being launched to kind of convince people to go to malicious websites, download code, all kinds of nefarious behavior.
It's the usual kind of thing. But this time around we're starting to see these things called deep fakes more often. The latest one involved Elon Musk and a and a voice like this that he was used within a, a scam.
And, um, I mean, I knew that on textual ai, you've been writing about the, the rise of these deep fakes using AI technologies for a while. Do you think we've kind of hit this thing where now it's mainstream awareness and people understand what they're looking at or, and, and hopefully maybe they won't be fooled as easily, or what's your, how do you see this evolving? Well, there is more awareness.
People are aware that it can take place, but I'm not sure that they're able to decipher what's a deepfake or an AI voice versus the real win. But we're still seeing lots of confusion in that area. Alright, Well, Chris, How do we kinda spot these things?
And I'll ask you this because we've been doing end user training forever and a day, and for the most part it's felt a lot like, um, you know, traffic school where you send end users to, you know, remedial training for how to spot these things. And AI is making that, or at least it's starting to feel like it's making that obsolete because well, um, it's too hard to detect. And now we have these deep fakes, they're using voice and video and all kinds of things, and maybe it's beyond the average end user's ability to see, but what's your take on what's going on with all this stuff?
Well, You know, like so many other issues, you know, this is, this is why I'm always talking about inevitability curves. You know, it may be, you know, a better way to say that is un inevitability, you know, at certain points we're not going there any further. And this is something that, that not just I, because of, you know, what I've done for a living, anybody who's thought about computer graphics and movies and, you know, the special effect over, you know, the last 30 years, they're moving be in a certain direction.
Along that line at some point is the ability to make video that looks honest to God, pixel by pixel, exactly like the real thing no matter what. It's, you know, so that's been coming regardless. You can see this, you know, decades ago now it's here.
Isn't this fun? The question in any such case becomes what happens next? And what happens next is not just one year, but a thousand, 10,000 years, this is not going away.
You know, the ability to say, Hey, that really is that piece of video, um, is part of the history now, it'll never come back. Not in the same way. Uh, so what do we do?
I think of Amanda's point, you know, this, you, this lines up with the malicious influence campaign sort of stuff that it can everybody that this information thing. So in the effectiveness of putting out something that looks like, you know, a picture, something that looks like a video, something that's really convincing is itself going there. Um, what do we do about that?
You know, longer topics, but I think the kinds of things we see, digital cybersecurity have a play there, but they had to be tied with real cognitive sciences. How do people think? How do we process information on a personal basis, not just, uh, not just corporate professional behavior?
Yeah, and I know I've heard some companies talking about digital water watermarks of sorts, but you know, how, how do we know that those can't be faked? It, you know, if it's online, it's at risk. So it's a, it's a hard, uh, process to solve this issue, I think.
Yeah. Oh yeah. I like, I like the term time transparency for a lot of things these days.
And this is a, a perfect one, you know, we all know, you know, do your own research and it comes down, how much time do I have? You know, anybody? I believe this doesn't require a, a grand intellect, you know, really taking the amount of time it takes to research something today really can't, or the key word there is time.
None of us really have that time, right? So we have to continue making assumptions, you know, as, as people always have. Um, but it's, yeah, and Amanda though, i, I personally, I think one of the answers is literally watermarks, but it has to get that next question.
You know, as we look at visual information, you know, pictures and, and videos and so forth, and there asking enough transparency under that, that I can tell, you know, the, you know, I liked the idea that we can somehow get a system where people can look at a piece of, of content and have a pretty good idea that there is someone behind that, you know, if they wanted to take the time to look, and if they did take that time to look, they would be satisfied to a reasonable level of satisfied that that was true. So I think the risk here as, as security people, as engineers, we usually look at the a hundred hundred percent solution, you know, and there's nothing in value before that. I think what we'll find is that good enough solutions, um, that provide an appropriate level of comfort on the per personal level that, you know, you know, I may not agree with this, but at least I, you know, I think it may be fake, but at least there's something back there that I can trace it, trace it to and say, Hey, you made a fake thing.
I also wonder if there's some way to tie blockchain technology in somehow to where, um, you could definitely trace it back there and know that it's real that way. That's right. io, that that, uh, open source project came from.
It was a, you know, two worsening company, Medi anda, you know, call us callouts as always. He and I were having a conversation about blockchain and security, and as we looked at it, you know, blockchain, of course, you know, distributed ledgers may or may not be contentious, but it, regardless of that, but as you say, Amanda, given that we have this example, you know, shared ledgers can get really, really good at non-repudiation. And as we make that easy enough, you know, so I envision a future where, you know, for example, I can take my Android phone, uh, poke, make, create a screenshot.
I've already chosen to create attestation all ledge somewhere that, that was me with my phone as far as we know, at least I, you know, scanned it with my fingerprint. And I took that screenshot. And anybody who can and should know that, you know, will know that.
Um, I think, yeah, I think people I would sign onto that, I don't care. I did take that screenshot. And if that provides a reasonable level of comfort, given that to our topic today, we all know that any individual, uh, image we see any, even now, any piece of video may just not be real.
How can we tell the difference time if we ask our friends look around and we don't have the time To, to your point though, like, let's go back to that, you know, unfortunate incident involving the assassination of, uh, president Trump attempt there. When I first came over, I think a lot of people were like me, and they kind of paused and they waited for more verification before they believed that the actual event occurred. Because there's, there's so much noise in the system now that, um, maybe we are getting to the point where we just don't trust what we see or hear initially, and we just wait for multiple trusted sources to verify something.
Amanda, is that where we are? Oh, yeah. The level of conspiracy theorists out there on that one, I was going down the rabbit hole reading comments, uh, you know, it was, it was staged, it was a fake video, you know?
So, uh, yes. All right, So go. Sorry, Michael, go ahead.
No, you go ahead And I think, you know, we all know literally this is, this week everyone's having these same conversations. I find them to be healthier conversations, you know, I've got extremely broad, uh, spectrum of, you know, political life, ideological friends and, and people that you, you know, would've expected a couple years ago to yell one through another, mostly arent. I think we're all growing up together with this and saying, alright, you know, I, and you know, the elephant in the room, and it is a good example.
It's, in my opinion, entirely too complicated and unreliable for any parties, you know, to have this one be a conspiracy. It so many things can go wrong, you know, and just not, it wouldn't be worth doing. You know, conspiracies do happen, but I think we're getting better at determining when and why.
You know, this is a perfect example. Lots of reasons. Lots of stakeholders have a lot of reasons to try to fake something like this pro and con or whatever.
Um, but I think we all decided, no, no, that's actually, this is real, this actually happening, right? I guess the one thing I do worry a little bit about is, but the internet, the theory was at least that, uh, it would be easy for multiple content providers to participate. And now I wonder because of DeepFakes and AI and all this stuff, are we gonna narrow the number of, uh, sources that we'll consider because not just outta personal preference or bias, but just be out of a trust issue, but in so doing we kind of reduce the benefits of AI and the internet, I kinda think we've done that already.
You know, my question is, yeah, I don't think we fall into the, uh, the, the, uh, eternal abyss and never climb out and, you know, George or Orwell turns out to be a fortune teller. Um, but you know, I'm, I'm more interested in when, you know, when the emergent properties of making those poor choices get endemic enough that, uh, you know, large chunks or majority of populations, you know, say, all right, I'm willing to do the extra bits so I don't have to deal with that. Uh, so I don't think we're getting worse.
I think we've been there for a while and we're being shoved on up on the sandbars where you have to make choices. I think everybody's starting to recognize those choices. Let me ask you another question about this.
So let's say you're the cybersecurity team and you're working for the Olympic Committee. I mean, how does all this stuff change the way you think about your job, your mission? Because there's football games, there's all kinds of events like this where the cybersecurity tactics and techniques have to evolve.
Well, you know, I've, I've, when I've done that sort of thing, you know, working with, you know, NFL teams and owners and stadium systems and so forth, and you know, what you do now, what are the risks and so forth. And, you know, I, and again, I think to our point, you know, this has been the one that, you know, up to 10 or more years ago, I started saying, okay, in the future, this is something you really think about. Just think about it, you know, you're a sports team, you're a venue and you know, you're a a big stadium, and at some point I hack in and do something, you know, that goes really, really popular.
Everybody knows all about it, right? Or cause a stampede or whatever. It's, um, by, in our case here, by putting something out there that looks really convincing to a whole bunch of bands, were already, you know, all, all excited and they all rushed the against or whatever.
It's, um, so there's no answer for an individual team, you know, that engage folks, you know, who've been thinking about this a lot, Tableau, Brower, sj, tur, right? And, uh, and get their thoughts on what you can pragmatically do today in your context. I think there's a lot of things you can do personally, I think, yeah, the organizational level, honesty is a, and openness is a wonderful thing.
You know, we all have a hard time believing this from organizations and corporations and so forth, but we do, we will at the end, you know, recognize, you know, some people inside who are actually serious about this, and it works well for them because they sell a lot of products, um, worked well. The rest of us could be actually get a partner we can rely on. Of course, then we also see sports organizations embracing the same technology.
That's confusing everyone. I mean, they're embracing it. So you see the Olympics, um, using AI to replicate al Michael's voice to give all the, the feedback during the Olympics.
So that's interesting. Yeah. Can I spa this?
This is the Olympics committee. You know, I don't feel very highly for the competence of that organization, so I, I think it'd be fun to watch the mistakes they make that we can all comment on and teach lessons to people never, never to do that sort of thing. All right, so, so we all get to benefit from those who go before us, right?
We salute you kind of thing. Yeah. What, um, as we kinda like, think this whole thing through for a minute, Amanda, do you think we'll use AI tools to identify DeepFakes, create it with AI tools, and this is just gonna be AI versus ai?
Um, yes. Uh, I, I think so. Fight AI with ai, it's kind of an oxymoron, but yes.
All right. But I definitely get the gist, right? You know, it, it, it is, but you know, you, we take sides all the day, all the time.
And I think we'll all find comfort being more comfortable about Say, yes, but it's my ai. I trust this one. So we just need, uh, some sort of, uh, trust verification system for AI that we all can agree on, and then maybe we can move forward from that.
But, um, it seems to me that that's a little bit hard, and we will see how that all evolves. But in the meantime, hey, I promise you one thing, everybody who shows up here on text drive TV is a real person because we verify them. So there'll be no, at least I hope not, there'll be no fake people participating in these conversations going forward.
Hey, Chris, Amanda, thanks for being on the show, sharing your insights, as always. Thank you, Mike. All right, and with that, folks, we're gonna end this section and move on to the rest of the tech strong TV lineup for today.
We invite you to check them all out, and we think it's gonna be an awesome set of shows. So stay tuned. com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content, featuring breaking news, blog posts, podcasts, and more. com to learn more.
com where the world meets DevOps.