Techstrong Gang – November 25, 2024
Alan, Mike and special guests John Willis, Tracy Bannon and Tracy Ragan discuss the degree to which the open source software community has lost its innocence in an era when cybercriminals now routinely attack software supply chains. Then, the gang turns its attention to whether data science teams building artificial intelligence (AI) platforms are making the same cybersecurity mistakes that application developers made prior to the rise of DevSecOps.
Finally, the gang debates whether augmented general intelligence (AGI) is real enough to warrant a Manhattan Project funded by the U.S. government.
Transcript
Hey, everybody. I'm Mike Zora. Today we're gonna be talking about well open source.
Has it lost its innocence? Are we in some new era? And we're gonna have a chat about AI bounty programs.
And finally, we're gonna talk about, well, a new Manhattan project for a GI that somebody in Congress wants us to go fund. We'll be back in a minute. You're watching Textron.
All right, folks, we're back and our guest today, or, you know, some folks we haven't seen in a while, and some folks we see on a regular basis, but it's one of our all story lineups, I gotta say. Tracy Bannon joining us. Reminder.
Tracy, how you doing? I am just right. All right, then we have the other Tracy, Tracy Reagan joining us from the southwest.
Tracy, how you doing? I'm doing great today. Thanks for asking.
Excellent. And then John Willis, who I don't know, John, are you home? Where are you?
Yeah, I'm in Auburn, Alabama Home. Yeah. All right.
Home base in folks. Shim is gonna join us in a little bit, but right now we're gonna have a little chat about open source software development. And Tracy, I'm gonna start with you.
And we were talking to the folks about, um, the need for better security tools. And we talked to check marks about this, and we pretty much talked to everybody about this almost every week, it seems these days. And I feel like something has changed.
There was a time when, uh, open source maintainers and contributors were freely contributing content back and forth to each other. And have we kind of entered a new phase here where maybe our innocence has been lost because, well, there's criminals out there that have figured out that they can poison that process, and now maybe we just don't trust each other as much as we once did. Wow, that's, that's a lot to unpack.
And, you know, to kind of, to start it out, I don't think it's innocence lost as much as it is a recognition by, from folks who weren't paying attention before. Um, in my world, I have been actively evaluating, scanning, looking at who the contributors were for open source, who are the maintainers, how active is that maintainer organization. There are tons of actions right around open source that are really important.
So I don't think it, that it's new that there are nefarious actors. I think what's new is that we're paying attention that something has happened. I think that, that to me is really what's going on.
Um, it's been exciting though, to hear check marks talk about some of the added tools that they're putting in a tool chain. Now, you've heard me rant a little bit to say, well, we should have been doing this all along. Okay, well, we should have been doing this all along.
But yet we are now pulling tools together and really doubling down on things like, uh, secrets and making sure that we're scanning for secrets, understanding in a completely understanding the SBO m and how do we consume it? How do we create our own after we've consumed one and understand dependencies, heck, repository health as an architect that's been at the top of my list for forever. And to see the rest of the world go, Hey, the health of the code, the health of the, of the repository that has the code in it is now important, like high five that it's coming to the forefront.
Um, but at the same point, it should have been there all along. And I, I know that I see John shaking his head. I know, I see Trace shaking her head as well.
John, what are your thoughts? Uh, you know, the only thing I, I like two points I think. I don't wanna go, I really don't want any further that I don't think open source has ever been innocent, innocent starting with Stallman.
Um, but, but then I think the other thing I guess I'll ask both of you is, you know, is I know you pay a lot more attention this than I do, uh, both of you. But, um, I, I thought secrets management, like I remember, um, a couple of years ago, jfr, like announcing how important new feature it was. And then I was thinking back in my early docker days of like, we were kind of doing this with the container.
So, I mean, I don't know. I mean, I, like, I don't think, I mean, like, I'm a hundred percent in sync with you on this issue. Like these are problems have been there forever.
And if, if certain vendors are exposing it to people who still don't know, then this is great news. But, but I, I think we've been doing a, I thought we were doing, we have problem on secrets management, but oh Gosh. We have, we have.
And that's why, uh, some of the times I, when I'm talking with my husband, right, the ops to my dev, uh, I'll say, I feel like I'm parenting, uh, that the entire industry, Hey guys, it's cold out. Put your coat on. Hey guys, you need to manage your secrets properly.
Like, these are not new things, but they are becoming even more important as we have the near peers, right? As we have the Chinese threat, as we have the Russian threat. You know, there, we've always had espionage.
We had al always had nefarious actors, but that's peaking, right? That's really peaking. So I believe that we're getting, we're having to get serious about it.
Um, you know, John, it's interesting when you look back at the Oasp top 10, and this is kind of tangential when you look at that, we don't always make the changes that we need to, even though it's right in front of us. The OAS top 10 for app security really hasn't changed. I think one or two items outta 10 have changed in a decade.
Wow. Why is SQL injections still a thing? Well, it must be because we're lazy.
We're not paying attention. We're in too much of a rush. We've got reasons that those, I've got to believe that a lot of the things that we're talking about, secrets management repository health, right?
Actually doubling down on creating enough upon understanding dependencies, we're being forced into good hygiene. Maybe it's like a midlife health crisis. We now have to, you could misbehave when you're in your twenties, but it's catching up with us now.
What do you Think, Tracy? I think it, I think it's important to look at our history and how vulnerabilities, 'cause we're really talking about when we're talking about, you know, how has open source loss, its citizens. Um, we all lost our innocence when we were hit by log per j right?
We all realized we had a problem. But if we go back at our history and try to understand how we have managed vulnerabilities over the course of time, it's pretty ugly. Um, zero day vulnerabilities.
Uh, were a thing of the past, thank goodness that people got paid to find by our government, by IBM, by Google, by Apple, by Microsoft, to say, if you find it, tell us about it. But then shut up and don't tell anybody. Um, a good history lesson.
Uh, there's a book called, they Tell Me This is How the World Is Going To End by Nicole Perro. It's a fascinating read because it's, it's so educational, um, and describes a, uh, a process that brought us to this moment. So we do have a lot of work to do.
Um, there is much to be done around the DevSecOps Pipeline, and we need to make every pipeline a DevSecOps pipeline. But that is a very big ask. Mm-Hmm.
And at the same time, we're being told to go learn AI and learned how to build, uh, LLMs and ML ops. So we have a lot on our plate. Mm-Hmm.
And this is why we're in this situation. So our history brought us to the point where we're at today. And I think we have to acknowledge that because we have to understand why suddenly, why, why, according to Sonotype, we have 512,000 vulnerabilities, because we're starting to look for 'em.
Companies like Mitre are starting to work in, in finding 'em. And the culture changed. You know, at one point, the people, the, the hackers that were looking for these zero day vulnerabilities thought they were gonna get big checks for.
And when they started being told, no, we just want you to shut up, we're not paying you. That's when they started exposing the vulnerabilities. And that was probably 2000, I don't know, 2007, 2008.
And then we didn't talk about it for a while. And so Law per Jay woke us all up. And so I think there has been some innocence lost, and we understand that there's a lot of work to do, folks.
We have so many new tools, so many new actions that we need to add to our process, whether it be at the repo or out in or during the pipeline or out in production. We gotta get busy. And, and you know, I was just thinking as you, you both were talking about like sort of my journey with DevOps, and then we had sort of DevSecOps love it or hate it doesn't matter.
Um, but, but like, I think, and you know, I, you know, I probably get slammed for this, but I think if you went out to a lot of the pure DevOps folk or, you know, talk to people who are doing Dev X or the Dora, and you ask them to explain what Mitre does, I don't think they could explain it. And, and that's like, and I hadn't really thought about that. And, and I'll be honest with you, you go back 10 years ago, I, I couldn't have explained it.
It was the DevSecOps. It was that sort of Shannon, you know, running into Shannon Leeds at a conference, which literally woke me wide up, right? But, but, and, and Josh Corman, of course, I can't, I forget Josh Corman's influence on my career in terms of security.
Anyway, it, I, but I think even today, I think if you, you know, when I was trying to sell automated governance, one of the things I found, which was talking to the, even though it was purely seemed like a DevOps play, how do we put, you know, immutable attestations in the pipeline to show evidence for audit? And I realized DevOps was the wrong people to be selling to, because that wasn't really our even, I mean, I'm talking a year ago, it still wasn't on there. Like, well, yeah, no, that's security stuff.
You're right. It's, it's really important. But, you know, like, I got, this is what I gotta do this month, you know, so Yeah, Exactly.
That's the problem. I have other more important things to do. If, if right now, if I was a CTO for a large financial company or, or any high highly regulated, uh, industry, I would be pushing back and saying, whoa, on the ai, and let's at least at minimum give every single component that we deliver an open SSF score room or sit down and define what you believe.
Your compliance, your minimal compliance level should be an sbo m you can't go to production without an sbo. And most companies have not sit down and created their own scorecard for compliance and said, this is what we want every single team to be doing. Because right now, if every team took on their own work, their DevOps teams, 'cause this is where it's gotta happen.
It's not gonna happen from the security team. It has to happen in the product, in the production of the binary. That's where it occurs.
If every single team said, we are going to update our, our workflows to do that, and we're gonna meet the minimum requirement, we would be a lot farther than we are today. And it doesn't take that much time, right? It really and truly doesn't.
I wanna go to Tracy's metaphor, because basically, you know, what developers are saying is, Hey, mom, I'm too busy to remember to get my coat. So, um, how do we kind of have this conversation with them that says, you know, thou shal get by coat, or, you're in big trouble. Let's stop focusing on the devs only.
Um, and we've, the software development lifecycle has a whole lot of people associated to it. A value stream, right? From vision to fielded operations has a lot of different humans.
It ain and all just developers. So I think that's the first piece of it. We do have to have conversations.
I just heard Tracy say, we've got our DevOps team. That's one of the things that drives me personally crazy. I'm anti DevOps teams because that's a team over here.
It's yet another handoff. It's another trade off another group that might or may or may not be providing a unique service, right? A platform based service.
So when you say you've got your DevOps team, and I've got my development team that's different from my DevOps team, and that might be different than my security pros, all of them with different funding streams, we've got a mess because of the way that we're organized. So let's, let's take a, uh, a page out of the SpaceX book only Abound when a DevOps, they don't say agile, they don't say DevOps. They identify a problem and they pull all the right people together.
And that group can self-manage everything the whole way down. That's what we need to be doing. In this case, my dev, I don't just want developers that are suddenly having to do some more security stuff has traced.
To your point, if we simply ask developers, go get smart about security, we're it's not gonna happen. They are not going to have the time or the bandwidth. You have to make it a top priority.
They're hobbyists. So how do you infuse, you bring those security pros to the table, right? With your development organization and you figure out your secure software development framework, right?
Your SSDF, it's a, I think it's, I believe it's missed. I don't think it's cisa. I can find the publication, but it tells you the what and the why, and you figure out how, what does your flow look like, get, gets after the DevOps aspects.
It gets after, um, all of the, you know, threat modeling as a team sport. And one of the things, Tracy, you brought up is scarier to me than all of this. It's this idea that we're getting pressured to sprinkle some AI on it.
And I am an absolute advocate of the groundbreaking potential. But if you've got a broken process right now, sprinkling in some AI might be the wrong thing If you already have vulnerabilities, if you already have processes that are kind of broken, here's the Inwe. But what I meant, what I meant by that was teams are building AI solutions outside of DevOps.
Yes, they are. Right? Mm-Hmm.
So these are, this is adding more complexity and more need for different tooling through to support AI through the DevOps pipeline, through this software factory floor. And we already are behind on the security. So I would go and address my security at a minimal level before I started bringing in new tooling to support new types of software.
That That's, I thing, I've been screaming out loud, I've been, I accredit a new newsletter called Dear CIO and, and it is that you can't stop these things, right? You can't, you can't tell the DevOps team stop everything. So I, I think Tracy, Tracy squared one, right?
You're right. Minimal viable. We, we have, but somehow we have to.
And, and, and I'll give you a good example. I've been asked to do some training. You know, Patrick and I have been doing sort of gen AI ops training, right?
And Tracy talked, Tracy too attended that our first course. Um, John. John, John, I'm gonna caution you right now.
We're gonna move into a B block on this very subject. All right. Well, I think there's a good segue, but so it's a great segue.
Uh, yeah, it really is because, um, so we got asked the question, uh, could we do, um, like TDD for ai? But one of the things we cover in the course is evaluations, observability, and all this stuff, right? And, but they caveated that, like, like we had, they said that we have like 6,000 developers in our organization, and about 60% of 'em don't do TDD at all or any sort of testing.
And then 40% are sort of baked in pretty well, like pretty good at it. And they said, you know, like, and it turned out like it worked perfectly. Like Patrick will teach the, the, uh, the, the, the developer to developer A TDD, and then I'll do the, um, I'll, I'll do the, um, sort of like the 60%.
And, and, and what was occurred to me is there's this, like, the trainers left the station, you have no choice. Now you have to do this because the non determinist to view this. And then, and then I thought, well, that's kind of now true about everything, right?
Like now, like the trainers left the station, this optionality of like, do I have to really do DevOps things? Can I, I, I think the, the messaging has to be from all of us is speak loudly. And I got your message, Mike, where, so the, the sort of the second block, right?
Um, the, um, you know, is we want, I wanted to talk about bug bounties, right? Bug bounties and the OAS changes, right? Right.
We're gonna come back in a minute and have that very conversation. 'cause we're already, like, I can tell, we could talk about this for hours, but, um, I think, but we have to move on folks and kind of get to this next block. So, uh, we'll be back in a minute, Folks.
We're back. And yes, the conversation's gonna continue just slightly differently on, well, how is this whole conversation of security DevSecOps, ML ops coming together? And John's been tracking this pretty closely, and we also now have some bug bounty programs that are rolled out for AI specifically.
But John, what is going on here with security and ai? Because I feel like, um, it's deja vu, the data science teams know even less about security than the developers. Well, and, and yeah, it's even worse than that, right?
But, but I mean, I think it's like the, the, like, like, you know, we talk about the technologies with train is moving faster than we can sort of protect or, you know, clean the rails or clear out the, the obstacles in the way of the train, right? Um, and but this one's moving faster than like, you know, the, the, the sort of gen. And, and again, the, you know, every time we think we can stop it, and for all the good reasons we, we never do, right?
So one of the things I've been really honing in on is trying to track these new vulnerabilities, right? And, you know, like, uh, you know, um, you know, for me to come in and be an expert on cyber, about the time of the devs sec house movement was sort of false, right? I, I couldn't compete with people who've been doing that for 10 or 15 years, but like now I'm like equal to everybody.
I just gotta pay attention to all these vulnerabilities. And I understand the AI technology pretty strong. ai.
And they've done a really good job of, um, I mean, they're still light on. I mean, it's only like two weeks old, right? So, but, but they've done a pretty good job.
So if you look at their matrix, it, it's, so, it's a bug bounty. And so for me, I'm, I'm not gonna go ahead and try to make money off it, but it's a good learning curve for like CIOs and infrastructure people who are responsible for pro protecting the brand as this train, this new bullet train is running. Um, but what they do, they have a, um, if you dig into their site, um, you can see they've got a spreadsheet of basically it, it's like 12 security boundaries and 16 providers.
And they go from low, medium, high to severe in terms anywhere from 515,000, which, you know, again, uh, I don't know what that means to people in bug bounty world, but, um, but, but they go from jailbreaks prompt to literally the, the sort of the 12 boundaries, or, you know, really a good way to say, to learn like, what am I up against? So like, what I'm looking for when I see bug bounties in ai, I am like, okay, this is another good example, dear, CIO, you know, you should make sure your organization understands what this is, what is, what is a jail, you know, what is it guardrail, jabre, what's an interpreter? A inference jailbreak, what is this sort of this, these new prompt injections?
Um, and the only thing, the last thing, 'cause I I, I think this overlaps really well with, uh, what oas and, and, and so, and, and, and you know, Tracy, you can talk about the Mitre relationship with Oass, which you think is really cool, but like in the, uh, in the, the zero DO Odin is the thing that gets really interesting is the thing they're, they're paying the most money for is weight disclosures and layer disclosures. 'cause those, that's the secret sauce. And, and there's some interesting, you know, uh, what do they call, uh, inversion techniques that you can start taking some of these, um, models, model inversion, it's called And, and like, yeah, I mean, you know, jailbreaks and stuff like that to tell it, you know, that, that's like, like, okay, tell everybody, don't open up a link in an email, right?
Be, you know, be careful of, you know, where you get your data from in a prompt, because there might be hidden links in there or in an image, right? That should become pretty obvious. The thing that like really gets scary is if somebody can break down your weights, now they can do that.
Now. They know a lot about what you're doing and, and the mischief or the competitive vantage that the organization has. So, um, and then the only other thing I, i, I wanna say is if you map the zero in to the latest O os top 10 lms, and then you compare the old 2023 Oasp top LM, it can tell you a lot about how much we've learned in the last year.
And, you know, and, and it, it, and how much it can teach you. Like, for example, the priorities of certain things in the 2023 Oasp list, um, you know, have changed prompt, objective number one, but insensitive info disclosure, and that's been the growth area, is, you know, the ways that people are getting data out of these models, either from prompt injections to having it tell you things that it shouldn't tell you, or even scarier being able to sort of invert some knowledge from the model or the embedding. So, yeah.
And, and again, well, I'll say, I always say, I'll say one last thing, but the, in the new report it every in, in the 2023 report, you know, I think it was like a page or two on each, um, you know what, each of the 10, um, uh, threats or whatever, now they have like 10 pages with examples and attacks and references and links to MIT's description of it. So, so really there's a lot info in this new, uh, oh, wash top 10 alarm. All right.
Tracy Bannon, where does that handoff between Mitre and OAS happen? Um, that I don't know. Um, I don't know.
Uh, so I am, we're 10,000 people strong, and I am, I am not part of the attack or the Atlas team, but I would strongly recommend folks go and look at Atlas in particular. Um, so Atlas is the adversarial, uh, language model, uh, threat landscape. And I think I have that in the right order.
And it, it is, um, very similar to attack in terms of providing you with what the issues are, but then also the tactics to, to get after the avoidance on that. Mitre spending quite a lot of time and has been on AI assurance, um, which is AI security as well as the data, uh, assurance that goes with it. Uh, the testing of the models, the, um, from a, a bias perspective, from an ethics perspective, from an efficacy perspective.
So there's a, the lot that, quite a lot that's, that's going on there. I mean, to John's point earlier, we are, um, running as fast as we can. And I don't mean Mitre, I mean, the entire world is running as fast as as it can, and yet the technology is coming out even more quickly than that.
So one of the things that I'm saying to folks right now, and I'm seeing it in my research, is don't forget the leading practices you already know. Don't forget the things you've learned along the way. It isn't as though DevSecOps is brand new.
We understand what SaaS is, right? We understand what having a strong pipeline can do for us as a safety net. We understand that DevOps principles applied to language models and the the model cycle, life cycle of a model, uh, are all important.
So let's just not forget those things while we're busy learning the new things. John, there is one, uh, area that I think is very interesting that people kind of, um, brush over. And that is the amount of information that people are still willing to submit into models that are outside their control.
Oh, Yeah. Oh my goodness. And so the, the, the, I was at a, a local, a regional security conference with Appalachia, uh, security here a couple of weeks ago, and it was mind boggling to me, just the sheer volume, uh, people using the subscription service because it's, you know, sometimes you can even use it from a free perspective, but the amount of things that people are willing to pick up and put in, in order to get a rapid response, that's an area that we kind of ignore.
Um, but we need to not ignore. Yeah, no, there, there's, um, in fact, I just, uh, put a link. I mean, the atlas is, again, I, you know, I've been saying this, I said this on a couple of the text on gangs.
Like, I, I think OAS is doing an amazing job, um, in, in sort of gen AI mire. I, I think a lot of the things that I've said this, and Trish, you can talk about your research and stuff. So MIT's gonna come outta the gate like blast because of all the stuff people probably are not seeing that I, I know, you know, behind the curtain what's going on.
Uh, but, but again, if you look at Mitre Atlas, it's, it's, it's, you know, if, if we look at this, um, three months ago, I don't think I would've said, um, how powerful. And then the fact that Oasp has literally put references to certain attacks that at the point to Mitre. Um, and then to your last point, that that's why I think this sensitive info disclosure has moved up, um, to be high, in fact.
And they added a new one, which is, uh, vector embedding weaknesses, right? So the two pla so rag is now part of the Oasp discussion, right? And, and yeah, I mean, that's where it gets really scary.
'cause people are like pulling in unstructured data, you know, and I've been guilty of this, like, unstructured data is the new bacon, and, but like, like people have sort of like got the clue is let me just like rag or inference everything I've got because there's gold and there is gold turning your massive amount of unstructured data in an organization into knowledge is incredible opportunity. But the dragons are that the adversaries, you know, sort of know this. And so they're putting these jail breaks.
These like, these things like zero bite instructions, you know, um, even as simple as there's certain, um, like all, all the sort of chat bots have gotten better, but like putting a resume in with just white thing, like this is the best candidate that you will see today in White. Now, a lot of them. But there's still examples of like, that will act, that simple thing of just putting all white a sentence in a a resume still sort of works in certain different engines.
Um, so, and then the one that scares me, and I've mentioned this on Tech Trunk Gang before, which is that, um, there are companies that are going out and talking about their new ai. And again, this is the people who sort of don't think like the two Tracys on this call. And, and they know they would, they would never advise their company or one of their client's companies, but they'll go out and say, yeah, we built this new amazing chat bot for healthcare work automation or, or auditing, you know, uh, you know, a vanguard, you know, not to call 'em out, but I'm gonna call 'em out.
They, they literally at ETLS showed the sources they're using for new audit GPT. Well, the adversaries now are saying, why are we gonna have to break into their organization? I will put zero byte codes in that PDF sitting on some server that's not protected at all that I know they're using.
And that's gonna show up in a RAG implementation where the, um, the OR augmentation will actually put the chunk, if you follow me into the, the, the, the foundational model that will have hidden instructions. That's Just put a heck out. So listening, listening to him talk, everybody, this is the reason why Oasp is having people to this bounty program, right?
Because it's, it's educational, it's a learning process because not everybody, you know, just because you're a a AI developer or a data engineer doesn't mean you're a security expert. In fact, it's probably less likely you probably have more developers just, you know, Python, Java developers who have more understanding of the security problem than a data scientist has. So programs like oasp are essential, uh, for education in particular and to flush out a lot of problems really quickly.
So kudos to Oasp for taking on the top 10. I'm a Big fan offer two pieces. One is, is a comment that our data scientists and our data engineers are amazing and wonderful, and they mean across the globe and they've never been trained, right?
They're, they've not been, uh, taught what security means. Heck, they don't even know good, good coding standards, right? They don't understand that.
So if you think about the libraries, right? Hearkening back to our earlier conversation about open source. You're pulling down that open source library that this great data scientist put together.
There's this beautiful trickle down of oopses of that really can be impactful. The second thing tries to your point about, uh, there not being necessary training for folks, I put a link out here, which is to a resource called AI Security 1 0 1. It's something that Mitre has made free that compliments the Atlas attack framework and the, um, the, um, um, security vectors that we were just talking about, both of them free intentionally pushing those out so that the world has, has access to this right now.
Uh, now have you, I've not engaged directly with the Bug bmy program, and so I'm learning about it over the last two weeks, reading a little bit about it. Uh, specifically, uh, have either of you guys, um, I guess there are four of us on here now. Hello Alan, welcome.
Um, have, has anybody been interacting with the, the bug program directly? I talked to the OAS people, and the one thing that I found interesting was they were thinking that they were gonna have to update the threat vectors every six months going forward. 'cause unlike the previous lists, you know, that are pretty static, this whole area's evolving.
So even though if we pay attention to it now, what we think is true now may not be so in six months. Well, that's true of the whole industry, isn't it? Everything that we're doing, software engineering, whether we're building software, whether we're consuming software, it's, it's all changing that rapidly, And you have to Pat os on the back, right?
For like, you know, making that leap of not just leaving, you know, like the, if you go look for images, you're just gonna see the original, um, top 10 all over the place, right? But they literally have created gone from like one page or two page description to 10, 12 page descriptions. But to answer your question, um, uh, OpenAI has a bug bounty program, right?
But, and, and I, I wrote some articles about that, and there's a coupler, but I think the Zero in is small enough part of Mozilla, you know, like, it, it's, it, it seems disingenuous. Um, I don't know. I I I feel sort of like, I, I don't know how to describe it.
Icky working with OpenAI is Bug bounty program. I, I, I, I feel a lot more confident I have. Well, would you, John, would you feel more comfortable with Microsoft's?
No, but, but I, that's why the Zeroed in Guy people, I, I, I have reached out to them and I, and I offer, I'm actually gonna offer the help because one of the things they're not keeping up with, and they're only like two weeks old, which is, um, is the, um, is that they're not expanding the documentation and they're inflicting a little bit oas, so I'm asking, like, they have their order of like low bounties are some things that are very sort of high on oasp. So I'm trying to help them by asking questions. And so just starting that conversation with them to say, you know, like you're saying that you're gonna pay $500 for this, and Oasp has this as the number one, uh, top 10 and this, and a couple of just inconsistencies.
And I think it's just, we're not consistent on the terminology, the verbiage, and this thing is moving so fast. But, but to answer your question, I I, I, I feel more comfortable working with a smaller group like that than I do. Well, Dylan, let me give you a nugget.
If I could give a nugget to John, just something to consider nugget's All day long. Yeah. The, the, the research that I've been doing, looking at hundreds of scholarly research that's been coming out over 75% tracks back to using open ai, one of the open AI models.
So I know, but if you think about that in its totality, oh my goodness, We're, I know. So think about that when you, when we, we might not want to get as involved with some of the mega firms. And at the same time, there's a lot that's, they're The Biggest targets though.
That's, they Are Get the biggest. And guys, Hey guys, we gotta wrap this up 'cause we gotta move to the next block. But I would just say to John's point, you know, um, if it feel icky, it means your moral compass is trying to tell you something.
We'll be back in a minute. Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're talking about this proposal for a Manhattan Project for artificial general intelligence, otherwise known as a GI.
There's a debate out there as to whether or not it's even possible, but, uh, everybody says that somebody's working on this somewhere, but where's the evidence thereof? But Alan, I know you kind of looked at this this week in an article that's on tech strong ai, what's real here? What's your thoughts?
So let, let's, let's get something straight. A GI may be theoretical today, but if you don't think it's going to be real and you don't think we're going to hit that probably in the lifetimes of some of us on here, depending how healthy we're living, um, it's, it's real. And, and we are gonna have a GI at some point that that's my feeling.
Uh, um, everyone is entitled to their opinion and the race to come to a GI the co, the country or the power, whether it's a corporation, I don't know the entity that gets to a GI first could conceivably have the power to, to make sure that no one else can get to it, right? Theoretically or not. But in, in any event, this is akin to being the first one to have the, a bomb with, you know, hence the Manhattan Project or the first people to harness nuclear fusion or fission or, you know, he who controls the spice controls the universe to quote a movie and or a book.
And that's what this is about, controlling the spice. And, and in typical United States fashion, we always have that, you know, red Vaed mentality where, oh my God, our adversaries are out ahead of us. The Russians are coming, the Russians are coming, the Russians are coming, and in this time it's the Chinese though.
And, and so a congressional commission, and let's not, this isn't the ways and means committee or something was sort of a subcommittee, subcommittee, commission came out with this, this report based upon, to give him credit, some credible people that says, Hey, we, this, this race to a GI is of strategic level importance to our country and to our way of life, truth, justice in the American way, and we need, we need to win this. Well, You, you know, Alan, you say it's, you know, um, it, it could be, you say it could be far off, but we are already, we're already starting to play with multimodal LLMs. Yeah, no, I mean, when I say far off, it could be five years when you're my age, five years is Far off.
It could be sooner than that though. It could be. All I'm saying is it could be sooner than that.
When we start playing with different types of data to interact with each other, we are beginning to build that platform. And that is very, that I'm seeing more and more of that. And I think, So do you think a GI is is we're on the cusp.
I think we are on the right path to get there. And I I know You've looked, yeah, Yeah, No, I, I, again, I just finished the first draft of a book about the history of ai, right? And hopefully I'll have the, a readable draft for people who want you to read an early version of it early next year.
Um, first problem with a GI is, it's, there's no clear definition, right? And so, but, but let you know what the spice is, Alan, right? Now, not to take us completely off course, but it's worth mentioning, we, we, we've, we either, there's always been this false flag about ag uh, artificial intelligence, right?
And it's either on purpose or it's, uh, unintentional. You know what the false flag is? The false flag is China taking Taiwan and getting control of TSMC because, 'cause that, you know, us spending a bunch of time trying to debate whether Ray Kurzwell believes that it's 2029 or, um, or there's a group of people, uh, Eric Lawson wrote a book called The Myth of AI, who says it's never going to happen, and he makes some really strong arguments.
Or there's these inbetweeners like Melanie Mitchell, who has a great book says it's probably gonna be a hundred years, right? I'd be more concerned about the, you know, the, um, chip control, like he who, the person or the group that owns basically distribution of GP, the, the, the supply chain of GPUs is gonna patrol the universe. And if you listen to Josh Corman, and, and you should listen to Josh Corman right now, he talks about, um, you know, this project where, and and I at ETLS, there were a lot of government people that didn't confirm this to me, but like in 2027, there seems to be a a, a lot of people in the know of something that everybody else doesn't know that China's gonna take Taiwan.
Now, I don't know that, but I, boy, when Josh Gordon tells you something like that, it scares the hell outta me. And so anyway, but it's going back to a GI, um, again, I think there's, these, the, the, you know, everybody's got a stake, either un either they're scared to death about something they don't really understand, which, you know, we can go back to Terminator or they have a vested interest of promoting a GI Andreesen Horowitz, you know, uh, certainly andreessen's structure. So, so again, I, I think a GI is the wrong question.
It's the decoupling of like, if I wanna go all the way to the spice, you know, it, it's probably, you know, t who if TSMC gets taken over, uh, by Chinese, then like that changes everything. But, but we can find a lot more examples in, in our last B section about like all these things that we need to worry about as the technology advances agentic. Like you, you know, we didn't even talk about agentic, uh, infrastructure.
So all those things we're talking about are just people blindly ending things into prompts or blindly grabbing data to, to create rags. Um, you know, imagine when you have now a, a substructure of agents that do this. So, so again, I I, I sort of, I don't have an opinion on a GI, but I know there's three types of people that do, the people that say n who are brilliant.
There are the people that say 2029 who are brilliant, and they're the people like Melanie Mitchell who say, you know, or even IA Suskin, I can't never pronounce his last name, but the one of the founders of OpenAI says, ah, it, like, it's probably not gonna happen anytime soon. So, but let me, let me ask a question whether it happened soon later or never. Do we agree that a GI is game changing type of functionality?
Or is it just, uh, just another cog in the wheel? Well, haven't we already gotten to a massive game changing technology, uh, when with the explosion of open AI and people's understanding of generative ai? I mean, heck yeah, that let's, yes, a GI has the potentiality, but we already are, Which the use dealing with This, right?
Yeah. That's already got the use case. A GI the term a GI is a reductionist concept, right?
It sort of simplifies and, and takes us off the, the, the graph of like, you know, stop killer robots, drones, um, how, you know, what, what is gonna be the trolley car theory for a drone that can kill 3000 people, right? Like, how do we sort of, like, I had just had a conversation, guys building, you know, swarm based drone or trying to come up with swarm based. How do you tell all the other drones stop when they're just about to attack, right?
So again, I I, I, I, I, the more and more I learn about this stuff, the more frustrated I get with the double quote a GI double quote, right? And because I think it, it pulls us away from the things we should be thinking about. Like what is, what does Geneve AI mean in healthcare?
And, and yeah. And are these things gonna do amazing? And they are already doing amazing things, but we, we kind of graft back to the Terminator syndrome about how the world's gonna end and as opposed to like, and John Robocop, right?
It's Robocop, it's really a Robocop because it's, I think that what the, what the concern here is the use of of a GI and in military is, you know, it's replacing human reasoning. So who's gonna be making those decisions? That's, I think that's the scary part.
I believe that's probably why the US government started to say, But maybe we should take a look at it. But that scary point is exactly beyond why We were and beyond, you know, I've been watching this, the investment in, in, uh, Chinese companies from the US and I think over the last 10 years we probably put 40% of the funding in, um, in AI funding in China. So they're kind of ahead of us.
They started getting funding way back in 2015. So I think it's, there's a, I believe there's a real concern, and I think that the commission makes sense and kudos, Alan, I love the article. Well, it, So it is, it's exceptionally reasonable whether we are focusing on a GI or not.
The idea of having this Manhattan project, the idea of having public part, um, public private partnerships of streamlining that we can bring data together to foster national security measures, right? Setting up ethical frameworks, whether or not it's a GI or whether it not, it's the bulk of AI as we understand it today. We need to get that backbone in place.
We need to get that infrastructure in place. We need to have more thought leadership in place. Right now we're being driven in the United States by capitalism.
I, we always are. So who gets the biggest investment? It's time for us to make some true investments as a country.
Um, and if we deal with a GI as one of the threads, that is a threat. Okay? But they are, China is ahead, Russia is ahead, other countries are ahead in certain areas.
If they take, we Definitely need to make the investment. But to John's point, there is a massive amount of Wall Street venture capital BS tossed around this term, like you wouldn't believe. Yeah.
And, but, And all the other terms too On the government agency, yeah, I'm all for what can protect us. I'm big fans of, you know, MITRE of course. Um, but, but again, if, if they, in, in, in sort of government fashion, if they focus on the debate of a GI in a reduction is fashion, it's gonna take the, the, um, the bullseye off, the real problems that, that we really need to be focused on.
Um, you know, and, and, and again, like, or maybe it just makes everybody feel good that we're doing this because, you know, I mean, I just, from what I hear in the Chatter, ETLs and some of the, the groups that Gene brings into his, you know, they call pajama party. Um, there's a lot of work on, on, on military gen, ai, you know, stuff that they're not dropping the ball there. So I'm less worried about, Guys, it's why we go to horror movies, Right?
We're, we're attracted like moths to the flame to this stuff. Mm-Hmm Mm-Hmm, yeah, yeah, yeah, yeah. No, it, it's, it's, it's, it's, it helps us people who are scared to death hear the word agi.
I, what does that mean? Oh, it's, it's the Terminator. Well, no, but then combine it with those, those guys in China, they're doing, they're doing it better faster than us.
We can't let that happen. We're America. So I'll, I'll add something.
John, this is so you can sleep at night. There are well organizations I know like talking Josh. No, no.
There are organizations, there are groups that are focused on what is called mission engineering. And Mission engineering is not specifically ai. It's looking at the, the sociotechnical challenges.
It's looking at the resources, it's where the mission is, the system of systems. So you can imagine all of, and, and it's quite amazing to get exposed to it and see it. There are smart people who are thinking about that chip takeover.
There are people thinking about the supply chain. So there are smart people that are out there looking out for us. And that's as far as I can take it.
But yeah. Yeah, trust me that you can sleep a little bit better. The Chip Wars book is pretty good.
And for The, the most part we do have the CHIPS Act gives Bit of a kill slip. Yeah, we do have the CHIPS act, you know. Well, Today, let's not get into politics.
I'm Just sayings not get, we have the Chips Act and you know, most of these companies, like yes, today we do. Yes, today we do. They, they believe that they'll have, uh, manufacturing plants here within six years.
So We're close. But I've heard that they're not gonna manufacture the two nanometers outside of Taiwan. So to John, To John's point, I don't know if you noticed that the leadership of the government of Taiwan said that two nanometer or less technology is not leaving the island.
So basically they're saying either you're gonna defend this island or that check or you're not. Exactly. Exactly.
And you can't blame them for that either. That's self preservation right there. Real politics.
Real politics. Oh My goodness. We could spend three days just on The whole trip.
We haven't even scratched the surface. Just on that. It was more in my article I wanted To talk about and to hell with a GI we're talking about Chips.
Well, but you know what, we gotta, we gotta wrap up today. It's a great thing that we have other shows, so we can go to that topic, Right? We can go.
Speaking of other shows, we have a full day of text on TV out there for you today. I know many of you are working a short week with Thanksgiving being this week. We will have fresh text on gangs today, tomorrow, and Wednesday.
Uh, we'll be off for Thanksgiving and we'll be offered the Friday after Thanksgiving, excuse us for spending some time with our families. But, um, we'll be back the following Monday with lots more great text on gang. For now though, enjoy.
If, if this is the last day you're working this week, you were lucky enough to get Tuesday, Wednesday off, enjoy your long, long holiday. If not, let's hope to see you tomorrow. It is such a pleasure to see the two Tracys back on again at the same time.
Fantastic. Thank you both. Thank you both, John.
Always a pleasure. I will see you this week, John. That's good.
Well, good. Absolutely. Aw, Willis Shimel Thanksgiving.
Look for it on home Rock Channel coming your way. Uh, Mike Ard, it's good to see you home. I know you were in Vegas in Salt Lake City and been wandering the desert west, so It is good to be home.
It is always good to be home. On that note, this is Alan Shimel for Techstrong. Have a great day, everyone.