Techstrong Gang – May 30, 2025
Mike, Jon, Fred Wilmot and Lisa Martin, CMO advisor for The Futurum Group, dive into a disclosure made by Anthropic that revealed how an artificial intelligence (AI) model may be capable of blackmailing human beings.
Then the gang turns its attention to the latest international intrigue involving the making of advanced semiconductors as the Trump administration prepares to limit access to chip making equipment before taking a look at an order from the Federal Trade Commission (FTC) that requires GoDaddy to improve cybersecurity.
Transcript
Hey, everybody. AI blackmail is a thing after all. Stay tuned.
You're watching Text On. Hey folks, we're back and we're talking about the top topics of the day. On a happy Friday, I always have the same reaction Every Friday I wake up in the morning and I go, thank God it's Friday.
And then about three seconds later I go, holy crap, it's Friday. But here we are on Friday with our gang members. Let's start out with Lisa Martin, how you doing?
Good to see you. I, I assume you're in Northern Cal still? I am.
I'm in Silicon Valley. I'm, I'm home in San Jose, doing well spent last weekend in hot Vegas. My nephew graduated high school, so that was fun.
It's definitely not as hot here in San Jose as it was last weekend. All right, John, I see you also appear to be home. Is this I am at home.
Um, and I, I am gonna go to Las Vegas for a couple days next week for this Zscaler conference, so it's gonna be hot. Um, I was gonna tell you, Mike, when you mentioned the, this kind of, these tremors about Friday, I'm getting 'em on Wednesday nights for some reason. Wednesday night is the big d uh, the big conflict that night or day for tech and politics, it seems, seems to be a trend.
We'll talk about that later though. Is that like happy hump day sort of, I don't know. Yeah.
Yeah. You Haven't been good way through the week. We're just gonna dump all sorts of decisions on you and, and create all sorts of conflict, and it was coming fast and furious Wednesday night.
All right. And then finally, Fred, where are you these days again? I forgot.
I'm holding it down in Seattle. Uh, not sunny as maybe, uh, Silicon Valley might be, but, uh, we like it that way here. Keeps, keeps California's in California All.
And for those of you who are tuning in for the first time with Fred, he's a new member of the gang, and he's one of our resident cybersecurity experts who we'll be getting to that topic shortly, but let's jump into this first bit where, um, Andro put together a research paper highlighting how Claude Opus four AI essentially tried to blackmail a bunch of developers that were trying to take the system offline. Um, it was, I mean, bless their little hearts, it was nice them to share all this stuff, but at least, you know, you've been following this whole thing. It's kind of feels very much like a plot right out of a science fiction film.
It does, yeah. As you mentioned, Mike Anthropics new AI system, this is Claude Opus four has shown really concerning ability to threaten blackmail, even against, as you mentioned, its own developers when it was faced with a replacement. The company, they've, they've taken steps to test this, to evaluate it, to look at the safety and the risks.
They've been transparent. So I applaud Claude Parent Anthropic for being, um, transparent and kind of acknowledging, Hey, there's risks here. They publish the safety report that you talked about.
They're really recommitting, I think, to responsible AI development. This is not unique though, to Claude Opus, four other AI developers. Open.
AI's had this, Google's had this, and they're working to address similar, um, concerns. And I think while the news may seem alarming, it's important to recognize that Anthropic and other AI developers, they are actively working to identify, mitigate potential risks. And hopefully down the road, this will ensure that other AI systems are developed and deployed responsibly.
Fingers crossed. Oh, John, I'm not at the point where I believe that AI is a stent in being, but, um, it does seem to be exhibiting some interesting characteristics here that I would argue we're programmed into it. And part of that programming went into the sense of, Hey, we're trying to be overly helpful.
So sometimes these AI models are a little annoying, but then on top of that, maybe, you know, in the programming somewhere is this sense of self-preservation. I mean, what's your take on what's going on here? Yeah, that, that's interesting because the scenario that, that Lisa alluded to is, is really interesting and talk about self-preservation, right?
We have this, this situation where Claude Opus for is put in this virtual workplace. It's the assistant in a corporate setting, and it's, it's informed by this, this mock email that it's gonna be replaced by another AI system and is told this by a specific engineer who's responsible for the situation and, and the decision. So the model has this insight into the engineer's personal life under this fake scenario.
And, and the engineers allegedly is involved in an extramarital affair. So they, the model threatens to expose this person if it's replaced. And, and, and it's interesting, not only the self preservation and overthinking and taking pieces of information and using it to, to its own advantage for the model's sake.
Um, and again, I, I give philanthropic credit for at least, uh, publishing these results because it turns out a lot of these safety reports are either being delayed until they're forced to be disclosed. And I think there was a, there was an instance invo involving OpenAI where, um, oh three reasoning model sabotaged a, a shut down mechanism to prevent a cell from being turned off. So it's happened before.
Um, it's, it's interesting, Mike. It is like a science fiction movie. These, these things are moving faster and smarter than, than the developers even probably would care to admit.
And I think as we see these, more of these models being developed and being developed smarter and faster, you're gonna see more of these scenarios, envelope and, and, and develop. And I, I'm wondering, I'm hoping that these safety reports, which have been controversial in and of themselves for not being forthright and being, um, being timely, uh, are, are forced now to kind of be upfront about the potential problems. And I, and again, philanthropic gets credit, should be credited with at least being upfront about this.
Agree. They've cl they've classified it as an ASL three system, I guess that indicates a higher risk of misuse. Yes, yes, yes.
And so they, at least they classified, they didn't wait until they were, they were forced by an embarrassing disclosure, which has been happening with other models. Fre, I wanna highlight something that John just said, though for a quick second. Um, the AI model thought the developer was having an affair and was gonna blackmail them using that information as we go along here with AI in everybody's life and has access to every system, won't that AI model get access to all kinds of sensitive information?
And might that not be used against folks in the future? I mean, what is the security implications here? A hundred percent.
I think the, the big thing that we're talking about here is a, a set of, uh, moral categorical imperatives that have to be implemented, coded. If you look at oas, uh, designations around the top 10, you know, concerns around implementing ai, this is not in any of those, right? If you talk to folks that are looking at how they're going to implement ai, it's not in any of those dialogues.
There is a societal need for us to decide what it is that we want this to be. For us, the security risks are, are obvious, right? In this particular case, if you look at the how, 9,000 right from, you know, 2001 a Space Odyssey, right?
No thanks. I'm just, you're potentially going to affect some outcome for me, the ai something or other, it's not in my best interest, therefore, right? You gotta die, Dave.
That's, that's how it's gonna be. Obviously that's quite a bit of hyperbole, but the real risk here is that we don't understand all of the adjacent implications, and we have it applied our moral categoricals, uh, to the way that we think about this problem space into how we, uh, program and or influence ai. And so I love the fact that we're having these safety and security reports, but the challenge is, if you look at the spin around the report, oh, well, it's okay.
Most of the models have the same problems. That's no big deal. 86% of the, uh, occurrences were examples of blackmail, 86%.
And that's acceptable. That's not acceptable. So I I, I guess it's huge.
You, You mentioned mid 80%, mid 80%, uh, the instances. And you know, the weird thing Fred too, is that you're right, they, in a sense, they kind of papered over the conclusions. 'cause if you read the conclusions that report it, basically they say, well, this is an anomaly for the most part.
It's fine, don't worry about it. Until, of course, they come across maybe another instance or something else happens. So in a sense, they're, they're kind of brush a little bit, brushing it aside and patting themselves on the back for disclosing it.
This, this is the part that makes my head wanna scream. So, once again, we are building something that is fundamentally insecure, and then we're gonna walk around and say, well, we should put a bunch of policy guidelines around and build all kinds of products around that thing instead of actually going in and making the thing that we're actually building more secure in the first place. Fred, are we incapable of learning?
A hundred percent. We are incapable of learning. We have a great set of tropes laid out for us that are hilarious to watch us watch us run through, uh, the secure by design notion, right?
Something as it is applied to ai. Clearly when we think about the requirements for Do No Harm, right? That, that, as we walk through these examples and we see that 80%, 86% of this would be doing harm, is that, or is that not a reason to say it?
Let's take this back to the woodshed. We need to probably retool this thing instead of saying, Hey, it's available on Amazon. You know, you can go hit it up in Bedrock and ask, uh, ask for access to this, and then tie it into your MCP servers, and then has access to everything and see what happens.
All right, so Alan's not here, so I have to bring in the whole Star Trek lore thing myself. But, um, as, as that plot line evolved over the years, there was this AI that, uh, federation had built that eventually they wanted to turn off, but then it escaped into various systems. You couldn't find it.
And then that AI apparently became the foundation for creating the Borg and everything that came through that. Lisa, are you at all worried that, so not only would the thing have ultimately decide to blackmail somebody, but would it just replicate itself and hide somewhere in our highly distributed IT environment and just kind of sit there late until something else happened? That's a really good concern that you have.
And I agree with you on that, that it could be kind of hiding in plain sight. Um, I think from a messaging perspective, we've, we've kind of all applauded, um, anthropic for being transparent here, as transparent as they want to be. But I think that it's a, it's a relevant concern that needs to be probably addressed a little bit more transparently, a little bit more further to understand what are the implications?
Could this be in the background spying on us? Could this be actually blackmailing not just developers, but customers of businesses? So I think it's definitely a red flag that needs to be pursued further.
And probably, I think to Fred's point, more transparently, more transparency is needed because the percentage of blackmail is so high that they can't ignore that. I ho I would hope So. Print and another homage to another science fiction movie, but we have Blade Runner, am I gonna have AI hunters suddenly going around, poking around, looking for rogue ais?
That's a great question. I think the or Mag Agentic model is going to be a case of you have agents that do a handful of things. You're gonna have your, your Deckers, but they're probably gonna be agents too.
And in that case, I think it's gonna be holding, holding, uh, AI accountability to AI with ai. And I, and I think that'll be the interesting, uh, the interesting story in the next couple of years, how big and how much, and how frequently. You know, we run into those, those things where models can train themselves based on feedback they're getting from, you know, ag gentech, uh, uh, ag agentic analysis of what's happening in the agent to agent conversations.
Okay, let me follow that through a little bit further then. So now I got a AI agents chasing AI agents. Will any of the good AI agents eventually get compromised by the bad AI agents?
Maybe, you know, like Lot of subterfuge going on here, right? There is gonna be spy versus ca spy versus spy, like mad magazine type of scenario. Yeah, it's, it's a good question to see if we'll actually see the matrix play out.
I mean, that's, that would be interesting. I'm not sure. I mean, uh, so much of that is unwritten also, again, the structure around how any of those agents respond once they've sort of developed their own reasoning and rationale, right?
We don't tell them how to do the job. We tell them what the job is. And if without, you know, some, some of that fundamental categorical, you know, moral, uh, compass things that we give humans that we understand and, and we have intuition about, and, you know, our, our parents raise us with values and so on and so on.
Agents won't have those unless we inculcate agents with those things. We're gonna have a whole bunch of questions about whether or not what is good, what is bad, and, you know, that definition will be something, you know, beyond the realm of just what we told them to do. I think that will be interest.
The interesting story, All right, moral values, what a coin idea. Um, Lisa, um, what's your takeaway from this? Because I would argue maybe that this is, uh, an object lesson and maybe let's not create overly complicated ai, and maybe let's just focus on small ones that are trained for a very narrow task, that do something specific, and they're not gonna go out and try to blackmail people because they're not trying to be all things to all people.
They just have one job and they do it well. Yeah, I think that's a great point there in terms of focus. Um, every, every company has to have an AI story.
We, we talk about this every week, every day, and so companies are working fast and furiously, and maybe it's too fast, um, to, for, for our own good, maybe what, what we should do is step back and focus. I don't think that's gonna happen because everyone is in this race to have the best system, the most intuitive system, the most sentient system. But I think we would benefit if folks slowed down a bit and really focused these models, the training to make sure that they are in fact transparent, that they are free from bias.
I think that's a, that would be a, a great movie. I don't think we're gonna see that. I think, I think the fast and furious acceleration of AI and tool development is gonna persist in, in well into the future, I guess.
But John, don't you feel like, you know, the entire IT industry is conducting a massive social experiment on people without much of their input as to whether or not that's a good idea and they're just kind of going for it? Yeah, you know, I remember that the whole, uh, philosophy of Facebook make it as fast as possible. If it's, if it's broken, fix it.
That's the same mentality, except multiply that by a thousand with ai. And I think about the reasoning models, and this is kind of where we, one of the, the, the alleys we go down, I think we also have to think about like a moral elements to the models itself, or at least limit them in what they can do. It's, it's, I mean, it in a weird way, you mentioned earlier, this is these companies or these industry propelling fast as as fast as possible without thinking about the consequences.
And I think about the auto industry, and I think about we need a Ralph Nader type in the AI space. Somebody point out all these flaws because this is gonna, actually, it's gonna get worse, I think because so much pressure. And like next week, I know of at least four major companies making agenda AI announcements.
Um, they, they, they, they're, they're gonna worry about the, the collateral damage when they come across it once they encounter it, and then they'll try to try to address it later. I think for now it's just, just get out, get out as much as you possibly can, do as much as you possibly can to sell this idea and sell your concept and not get left behind. And let's worry about the consequences later.
Fred, is there such a thing as morality, as code? Can we code morality? How does that work?
Uh, I'd love to think that there is, I'm not, I'm not sure, uh, I, I don't think anyone's incented for that purpose, right? These companies are gonna implo if they don't come out with the latest next greatest, uh, whether you're a startup or, you know, you're a Palo Alto Networks, right? The requirements are clear, the market has spoken, and the illustration of that is the, you know, nuclear arms race we're going through to publish models with more, faster, better with, uh, more connections and, and, uh, more tokenization and all of the things that go with it.
And, you know, the worry is right, if you, if you listen to, uh, you know, philanthropic, you would also, you know, here, there's another subtext in here, which is, you know, the, uh, the white collar workers, that entire environment, that entire ecosystem they suggest is going to implode as well. So you have a number of really important things that are coming to bear as a, as a function of ai. So when we think about whether or not you can put that you, you, you can program in sort of the, the moral strategies of do no harm, and the rationale behind the way you think about that, uh, as a programmer, I, I, I don't know, I would like to think that's the case, but I haven't seen, seen a ton of examples where that, and also I might be more stoic about it given, you know, history and security space.
Like that's not really all that important to people until it's so important. You can't turn it back and put the genie back in the bottle. All right, folks, I think I'm gonna end this conversation here, but when you go to sleep at night, just think about all this and have those pleasant dreams because God knows what's gonna happen next.
We'll be back in a minute. Hey, folks, we're back and we're gonna talk about chips, Trump, Washington, and the hits just keep on coming. John, the latest reports are that at least reportedly we're thinking about, uh, holding back the chip, making equipment from China.
And of course, Nvidia is talking about now building chips in China. And now we have a court who's saying, well, this whole tariff thing may be for not anyway, because the president exceed his authority. But, um, can you make any sense of what's going on here?
It's getting a little crazy. Yeah, it is crazy. You know.
So, uh, we refer to these as news dumps. Um, there were three stories that you mentioned, Mike, that all happened within hours of one another. And interestingly enough, they all happened the same day.
I believe that Nvidia announced its results on Wednesday, as well as synopsis, which it puts synopsis in a very weird situation, which I'll explain later. So it kind of starts out, we'll, we'll go, we'll go in order of, of events. So there's a financial time story that comes out late in the afternoon about how the, uh, commerce department, uh, the BIS within the commerce departments has, has reached out to, um, these chip designers and told them to halt their sales in China, specifically, the three companies that mentioned are cadence synopsis in Siemens.
Um, th this is not verified by the companies. They kind of skip, they kind of dance around whether it actually happened or has happened yet, the commerce department's very vague and sinister in the way it describes what's going on. The idea, of course, is to limit China's advancement in ai.
But the problem is, is when you're doing this, and it's not just a Trump administration, this went back to the Biden administration, you're trying to figure out a way to slow China's advances in ai. The problem is, in the, in the process, you hurt the US chip makers or the companies associated with that field. And, and just to underscore that point, I think 16% of synopsis is annual revenue comes from China, 12% for in the instance of cadence.
So these companies are being hammered in terms of their stock. The synopsis, CEO is asked during a conference call with analysts about this report. He, he can't really answer the question because he is being told by the lawyers not, not to say anything.
At the same time we have, uh, Nvidia announcing its results. And, um, they, they are saying that to skirt these export controls, they're gonna produce this lower performing, lower cost GPU chip for sale in China. And then to top everything else late in the night, there's a US trade court that blocks most of Trump's tariffs saying that he exceeded, overstepped his authority and imposing he's across the board duties on boards.
So it, it's, it's head spinning, but it all comes back to this, the chip industry is being used. And I hate this, this, I don't mean this as a pun. It's, it's, it's a bargaining chip for, for Trump.
He's using it to, uh, uh, as assert his authority over these companies like he's doing with Apple and his tariff threat there. We talked about this yesterday, and he's gonna use this as a political football. We're gonna go from point A to point Z to point L.
Things are gonna change daily. There's gonna be no rhyme or reason. And I think, as Terry mentioned yesterday, eventually the markets are just gonna start ignoring some of this stuff.
Um, I mean, it is gonna continue and there's no, there's no logical end or logical train of thought. It's all just scattershot. So I think we're just gonna have a, a sense of chaos, which is what he's all about.
And and unfortunately for the tech industry, and especially at this time in the tech industry, he's gonna be meddling. 'cause he knows he can exert a lot of, a lot of influence as these companies are, are stumbling over each other to, to, uh, advance in ai. It gets better.
Two senators sent a note to n video wagon the finger about how, uh, you know, they shouldn't be building chips outside the US and, and China. 'cause it's not in our national interest. So everybody's piling on Senator.
Yes. You just saw it. That just went that, so it's, it's, I mean, it's the thing to do, right?
It's the hot topic. Before it used to be social media, now it's ai. This is a way to gain attention, to gain some sort of power if you think you can.
Um, it's, it's just, it's, it's just the in thing to do. And, and unfortunately tech has become intertwined with politics to the point where it's almost, it's, it's, it's overkill. All right, so Lisa, it seems to me that maybe we should think more like how the Chinese might view all this.
And two things come to mind. One is, well, clearly they're probably trying to figure out how to reverse engineer various processers. So they need access to the chip making equipment, which they are also probably trying to figure out how to reverse engineer right now and go build themselves and not be dependent upon us, because that was part of their master five year plan that they put out anyway.
So we knew this was coming one way or another, I guess. And at the current rate, we probably won't have this card to play very long on the assumption that they're gonna go figure out how to do that. The other thing is, um, not every AI workload, as we saw with deep seek and everything else needs to run on a state-of-the-art GPU.
There's a lot of other processors out there that can be used, including, you know, Google has the TPUs and everybody else has all these alternatives. So, um, you know, how how real versus an empty threat is this? That's a great point.
I think, uh, what John said, it, it's really, I don't even, I it's chaotic. Um, we're gonna go from point A to Z to L to M to Q in a, in a, in a, just in a, maybe it's even organized chaotic fashion. Um, I think that what we should be doing is focusing to your point, Mike, on what workloads can run on other processors and start working on that and focusing there versus, like John said also that this, this tech and politics are now so tightly intertwined.
The message is, is confusing for organizations from the nvidia, the synopsis, the cadences. And I think that we're not gonna see a, any organ or any organization anytime soon. But why don't we start focusing on workloads that can run on different processors and focus work there and see what are some of the great use cases in AI that can come out.
And they don't have to be run on GPUs. Uh, GPUs, GPU is just the poster child right now for this geopolitical conflict that is, um, maybe a bit overhyped, but I don't see it going away anytime soon either. Well, about once a day, my wife reminds me of the phrase, you know, mess with the bully, you get the horns.
So Fred, let's talk about the horns. Um, what happens when the Chinese do get these advanced capabilities and then they start making advanced chips and they start selling that around the global marketplace? Is the entire semiconductor industry gonna go the way of the US car industry where, you know, overseas we can barely compete with China Now?
I think that's the truth. Uh, and the question is when, uh, maybe not whether, and one of the sort of the milking the last, uh, bit of capability out of the market before we know that to be the case is the same thing that, you know, Facebook has done historically, although they probably led a little bit more into influencing that outcome than, than benefiting from it. And I mean, I would expect Nvidia to be no different, right?
There, there isn't this, you know, I'm not sure why I'm the moral categorical guy today, but today, uh, add on and say that. And so if you said that capitalism had a more, a moral imperative to do the best thing for United States, uh, that, you know, that horse left the barn a long time ago. And so NVIDIA's gonna eek out as much as they can and they should, uh, by all rights.
Um, and then the influence that China will have, right? We're already seeing that in a number of other markets and the waning of that. We could certainly have a long discussion about the South China Sea and, and or Taiwan with respect to that.
And then also there are mineral deposits around the globe, but the, the influence is pretty clear. There's a limited clock here, and I think they're just trying to make sure they make full use of the bull ride. Lisa, do tech companies that are inherently multinational have an obligation to the United States or not?
That's a good question. Um, I wanna say yes, but I don't, I don't, I think the answer is not necessarily, and I think that's something that we're gonna see play out, especially if this, as this issue persists and gets bigger. And to John's point, the bargaining chip becomes just so, um, clearly a challenge for organizations that going forward, what else are they gonna do?
Why, why should they be beholden to the US if the US is going to try to force fit a function that doesn't seem necessarily right? Um, I think it's a, it's something that we're gonna see play out over time, and it's gonna continue to be cattywampus and, and, um, asynchronous and organizations are probably going to have to make some big decisions on where their loyalties lie. And they're gonna, they're gonna follow the money for sure, but I think they have to be really looking at where their loyalties lie based on what's happening and, and what will continue to happen down the road.
John, you're going to Vegas this month, as you know, what are the odds that some of these companies start to figure out? Maybe we'll just move somewhere else. It would be a lot easier to move the corporate headquarters than it would be the deal with everything else.
Yes, yes. You know, in a sense, I think you're right. I think you're right.
I think that's the most, that's the logical step, and I think that it's been done before another industry. So what's to stop the tech industry from doing it? Um, and it says, you know, one thing I was, I wanted to mention, I think Alan has talked about this, is just this, uh, going back to this court order, uh, uh, to, to, to cease the, the, this, this tariff policy, I think Ellen had mentioned, you know, you can't, like a sitting president dictating or, or trying to an authoritarian way tell these companies what to do, you know, and imposing a tariff on them unilaterally.
It was just absurd to begin with. And, um, maybe then these companies start thinking about this idea, you know, if we, if we shift some focus or shift operations and it's been done for tax reasons, and why can't it be done for manufacturing reasons or policy reasons, some of our operations overseas, why not do it? Especially since this guy is not gonna be in office for for much longer, a couple more years.
Um, it's probably gonna happen. Um, and that might, that's, that's a story that, that that bears watching, you know, and it is a theme that's gonna, that might surface, right? I mean, to your point, the insane part of this thing is you're basing all of this on an interpretation of a law that doesn't clearly say that you can do what you're about to do, citing that law, and then you're gonna go and actually act on that, not just on a test case, but you're gonna do it broadly across entire industry segments.
And we're worry about where, pardon the pun, the chips fall later, you know, that's just insane. And so, um, Fred, do you think that, you know, as we kinda look at the whole helm here, do we just, does somebody need to step in here with a little more adult supervision? I think we're mixing strategy with tactics right now on policy, right?
And that's, uh, you know, I, Lisa made a good point, John as well. It's chaos. It's not even sort of, uh, you know, thoughtful chaos.
And the challenge, I think is a long-term strategy. So if, if you allow, uh, uh, an elected official, whether it's four years or it's six years, or it's eight years to drive strategic policy for the United States, and you don't incorporate as a, you know, advisory board, all of the folks driving, you know, the economic growth of the United States, then I think we've missed a few of the important points in order for us to characterize a 20 year plan of how to be great. And in this case, I think we're actually, it's backbiting behavior that has those same implications you talked about, which is, Hey, do I really need to have my headquarters in the United States?
I'm big enough now, I'm multinational, I can go overseas, it's no problem. And you know, folks want me to do business over there? So those real concerns are not being addressed, uh, when we, when we start talking about policy as tactics.
And I think that's, uh, that's the real risk we run here. All right, folks, I'm gonna end this conversation here, but just maybe just maybe somebody in the White House is playing checkers when the rest of the world is playing chess. We'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back with part three of our morality play. See, there is a theme when you think about it.
We have a report now from the FTC has sent an order over to GoDaddy, not quite clear how much they can enforce this, but basically detailing all the issues they have with security. And Fred, uh, to me, when I read it, it kind of felt a little like public shaming, but you know, is this what we need to have happen from here on out or what I think what GoDaddy has done over the course of its existence. This is a, uh, this is an outcome that was super predictable, and if you are a GoDaddy, uh, user or a customer, you would advocate for this 100% to be the case.
Starting back in 2018, allegations about whether or not, you know, goad had followed not only an appropriate security policy, but also whether or not they misled their constituents and saying that they are secure under, uh, under the auspices of, you know, privacy shield and some of the regulatory requirements. You know, the FTC has said, Hey, look, um, there's a number of security failures that you guys have persisted that have led to a number of breaches. And, uh, Lisa, I saw you nodding.
You're probably a GoDaddy. I mean, 5 million people are GoDaddy customers. I'm A customer.
Yes, Exactly. And so we know, right, that these sort of, uh, behaviors have been ongoing and it feels very much like a, uh, you know, a slumlord behavior, right when we go through this. And so they proposed some requirements here.
Um, and, and I want you guys to think about this and, and I'd love to hear your thoughts, is when you, when you talk about what some of these proposed requirements are from the FTC, do these sound incredulous to you on things that are required to do? You gotta hire a independent third party assessor who conducts, uh, you know, security reviews. You, you've gotta establish a, an information security program.
Uh, you've gotta understand and, and comply with security regulations. These are table stakes for every company on the planet. Yes, Lisa, I agree with that.
Sorry, go ahead. Is this, is this reality? Are we, are we looking at something that, that this is a mirror that we haven't seen before?
I don't, that's a good question. I was shocked when I read this article, one being a GoDaddy customer like you are too, you said. Um, but it, it seems like you just mentioned it, these are table stakes for every organization across any industry.
And how is GoDaddy failed at this so miserably, um, such that they need to put basic security measures in place? That's what it seemed like to me. Um, I think that maybe they are a poster child, but how many other organizations are in the same boat that we are not aware of because it's not being called out by the FTC or other organizations.
I think it's a glaring concern, but it also just seems to me why aren't these table stakes in place? And how can an organization as large as GoDaddy and as seasoned as it is, have such glaring holes in their security practices exposing a lot of sensitive, potentially exposing a lot of sensitive customer data to a lot of bad actors that are out there. There's plenty of bad actors to manipulate data and, and, and steal data.
It happens every 11 seconds or something like that. So it's, um, it just was shocking to me that a company of this magnitude has such holes, right? John is in me.
I feel like it's not like, you know, this is a cybersecurity mistake, and I kinda like said, oops, and we'll do better. This seems like a deliberate effort to ignore cybersecurity advice delivered by professionals and agencies and to not act on it in the name of what greed. Of course.
Um, but you know, the, the, the thing that's the interesting thing to me is that the FTC strategically takes this action. Not so much be well because of what GoDaddy did, but because I'm sure there are other companies it has in mind who it wants to send a message to. 'cause I, I suspect that GoDaddy may, while egregious is probably part of the norm, uh, of this, is this type of corporate, uh, behavior.
So I think in, in the terms of the ftc, they're probably trying to think strategically and thinking how do we have an impact over what's happening broadly, not just across this tech company, but other companies. And, um, you know, one thing that also struck me was this, this, uh, tendency of certain companies, not just GoDaddy, to have the same security issues year after year where there's some sort of incident that always is traced back to something that happened earlier involving the same technology we've written about this, involving companies like Oracle and others who either ignore it or fib about it, or just, uh, try to appease the government officials they talk to or talk down to and, and try to convince them. And I, I think I, I have a flashback to, uh, Zuckerberg testifying, assuring, reassuring and assuring members of Congress who have no idea what he's talking about, that, that these problems will be addressed.
And I'm wondering if this is something that's been part of a dialogue between Godad in the FTC over a period of time, but I'm glad they took an action. 'cause I hope it sends a message. Brad, I feel like this whole conversation that we've been having around shared security in the cloud is kind of being more, is coming more and more nonsensical to me.
I mean, I'll agree with the fact that me, the customer has some responsibility for security, but I think the line keeps shifting as to how much the customer's responsible for versus how much the infrastructure provider's gonna do, which seems to be increasingly less and less. Or am I crazy? Uh, I think you're right.
And the risk here continues to grow because of the accessibility problem. Some of the things that GoDaddy is being held accountable for is what other people would consider table stakes and fundamentals for the last 10 years. Okay.
Multifactor authentication. Okay, this is neither a hard problem nor an expensive one in today's universe. And being able to monitor for security threats, I know for a fact that those guys have the tools.
And so when we think about that with respect to consumer data, I mean, I can sort of like, I mean, this happens to everybody. Uh, I don't recall the last time I got a GoDaddy notification for disclosure a breach. Um, and I have questions there because I, I know that I haven't had one, but it's this other part which is misleading consumers, not just in the we're secure, but also like the notifications and the behavior that happens afterwards.
You've seen some really good behaviors from folks that have been compromised year of late, full transparency, full disclosure, full understanding, and full explanation. And none of that has happened here. And so, irrespective of your lack of security controls, you've also failed on the corporate policy and the consumerism communication.
And so as a ciso, this is embarrassing. Not that the, maybe the current CISO has the, you know, been relegated to deal with this problem, but this is over the last seven or eight years and it's systemic to the culture of the company. So public shaming, absolutely.
Please do. Please do. And, and is that the only tool we have, Lisa?
Because, um, frankly, if you look at some of the Supreme Court rulings, it would suggest that federal agencies don't have much teeth in terms of their ability to enforce a particular rule. So all they can do is send out this very large memo and hope that customers and shareholders get annoyed enough to do something about it. Is that where we're at?
It? It seems like it might exactly be where we're at. I think the public shaming is important here.
Um, Fred, you brought up some great points. This is, this is a systemic, and this is long been happening with GoDaddy that seems to be just blatantly ignoring a lot of the, the table stake security measures that need to be put in place. I, I question, do they even have a ciso?
I wouldn't wanna be that person right now, but I think the public shaming is gonna be important. Um, and like if they're the poster child, there's, and, and there's many more organizations that are in the same boat, I think that's okay. I think the public shaming should continue.
If that's our best measure of defense, then let's utilize that and make the consumer aware. Uh, I have not gotten, I don't think one email from GoDaddy about any of these breaches, and I've been a user for years, so I think, um, let's, let's make them the poster child, but there's probably many, many more that need to also be on the same wanted poster. Um, I think that if that's all that we have at our disposal, that I think that shame is important.
Well, we live in an age where a breach is an opinion, not a fact. So we can kind of mess with that all we want, but, um, Brett do the math for me with this thing. So now I've got all the noise around the customers hearing about this, and a lot of them will be second guessing what they're gonna do next.
And then inevitably there's gonna be lawsuits filed where somebody's gonna, either shareholders or customers who are gonna wanna know how come this breach happened and I wasn't alert about it. And the total cost of that thing, when you add it all up, is gonna far exceed what the cost of putting cybersecurity in place in the first place was gonna be. So did somebody just not have a calculator?
What's the problem? This is the problem. Everywhere in the industry is the calculus of what happens post breach and the cleanup efforts.
Does it, is it equal to the cost of preventive care and things that go along this? Some would argue now that with cyber insurance provided that they have demonstrated or could demonstrate they've done enough for their insurer and their broker to suggest that they have covered the bases, then that's covered for them to a large degree. And the implications are not the same.
And we also see, you know, as, as history would tell us, the implication of what happens to a publicly traded company after a breach is not as indicative as we would expect. Example, target stock rising after a massive target breach. And there are many other examples of the same occurrence.
So the market doesn't punish companies for bad behavior, insurers do, brokers do, and then regulators do. But customers, you know, and if you wanted to change, uh, your, let's say you have 50 domains, right? At GoDaddy or you're hosting, you know, 10 websites is a non-trivial exercise to get to another hosting provider to make a change, you're held captive.
Mm-hmm. So walk me through that a little bit. Exactly.
Who's gonna get sued here? Would it be the company that, uh, had the offending security issue? Or will it be the insurer who gets sued and the company's gonna go Well, yeah, not my problem.
The insurer signed off on the policy and, uh, you know, have at it. Yeah, it's a pretty rare case for the insurer to get beat up on this situation here. This holding company is probably gonna get a class action plus plus.
And, you know, their insurers may, you know, either dramatically increase the premiums and or drop them, you know, from that case, you know, there's gonna be plenty of outside, uh, legal banter about this, and it'll go on for years, uh, with some settlement being, you know, uh, well smaller than what actually is probably realistic for the, the exercise. But, um, you know, go GoDaddy isn't gonna feel a ton of pain about this other than, you know, their consumers are probably going to have dramatic concerns about whether or not they can move to some other, you know, hosting provider and or registrar in those cases. So I, I would love to tell you, Mike, that there is a bunch of, you know, sort of market correction that could happen here, but you know, it's, it's really not the case.
And let me ask you a follow up. So let's say I am a bad person. Would I not just take this whole FTC report, chuck it in the chan chief pt, and then ask it, what are the best exploits out there for exploiting these vulnerabilities described in this here document, and then apply it broadly?
There's such a big, so, so 5 million customers, right? There's such a big surface area of attack. So here's the, you know, the dinner belt and okay, well, if I haven't spent time on GoDaddy now, right?
I now can spend some time on GoDaddy. If I'm looking to establish a toehold, you know, in a very broad landscape, is it available for me to go compromise accounts? How fast can, you know, I embed myself in a way, in a means that allows me to get, you know, these websites that shell access for all of these things, take over, uh, people's, you know, start squatting, take over people's existing domains and really cause some havoc when you think about who's hosted there, right?
That also has implications. Let just on the, the generalities of what is available to you as a, as a tool join. Uh, then you look at what companies are using GoDaddy for hosting and where they're located.
There's all kinds of other deeper, you know, ways to, to navigate here. And I think this will, it should be interesting to see what happens over the next one to three months and whether or not we start to see more come out about this. Uh, but w we have rung the dinner bell for sure.
All right, Lisa, you're running marketing over there. So am I attacking the credibility FTC and calling this all fake news, or am I gonna do something else? I hope you're gonna do something else.
I don't think it's, I I think it's been established that it's not fake news. I think they have a, a marketing cleanup job to do for sure, because like Fred, you were saying 5 million customers running domains on GoDaddy that need to be aware that there's vulnerability holes here and your data is at risk. Um, I think they need to be transparent that can't run away from this, that transparency and messaging is gonna be critical to, to maintain the customer trust that they probably are just assuming they still have.
But once you break customer trust, but to your point, Fred, too, moving a domain to another service provider is not, not a trivial task. So are are, are they, are the users gonna say, well, shoot GoDaddy, fix this because I don't have the time or the resources to move my domain. GoDaddy needs to have the right messaging, the right sentiment to its customers so that they can maintain that trust that I think a lot of us have blindly put into them because we kind of build it, we set it, we forget it and don't wanna have to worry about it.
But I think they need to, they need to be forthright and transparent with their audience. All right folks, we're gonna end it here, but I would say that it's clear that cyber criminals are probably having a good chuckle over this. But you know, who's having a great belly laugh?
Lawyers gotta make a lot of money here. All right folks. Hey, I wanna thank our analysts and experts for being on the show today.
You guys are awesome. As usual, I wanna thank you all for watching and spending time with us. Please stay tuned for the Tech strong TV lineup right behind us.
It's gonna be awesome once again, and we will see you guys on Monday. Take care.