Techstrong Gang – November 4, 2024
Alan, Mike, Mitch and special guests Tracy Ragan and Chris Blask dive into the state of election security as U.S. citizens head to the polls.
Then, the gang turns its attention to what is really required to achieve cyber resiliency. Finally, they discuss the degree to which the application programming interfaces (APIs) upon which the digital economy depends are actually secure.
Transcript
Hey, everyone. Happy Monday to you. It is the day before the official election day, though many of you have already voted, I hope.
So, we're going to be talking about election security of war. You're watching Techstrong Gang. Hey everyone, happy Monday.
It's Alan Sch for Techstrong and Techron Gang here. It's gonna be a crazy week. I got a feeling, you know, let's not, let me just caution you all, we are not gonna know who won the presidential election Tuesday night.
I don't care how late you stay up. It just doesn't work like that anymore in this C country. So don't rush to judgment, let the votes be counted.
We're gonna talk about the state of election security as well. But before I get into everything we're gonna talk about, let me introduce our fine Monday morning text on gang lineup. We've got some of our Prime gang, core gang members here.
Um, let me introduce you first of all. She is the CEO of Deploy hub, sitting out in Albuquerque, New Mexico, or near Albuquerque, New Mexico one and only Tracy Reagan. Hey Tracy, how are you?
Hey, Alan. And yes, I think I'm just gonna hang on this week and see what happens. 'cause I want the results Tuesday night.
We all do, but it's just, you Know, I can't help it. I know, I know. So we'll all be up till three or four in the morning waiting for those polls in California to close.
Like, we don't know how California is gonna vote, but, um, it is what it, you know, this, this is, and with the, well, let's not make this too much election. Let me move along. Move along, move along.
These are not the droids or candidates you're looking for, joining us from his boat where he's, I I, I guess you're still up in north Florida, if we could call it that. But heading making his way south like any good bird does in the winter. Um, our friend Chris Bla.
Hey Chris, how are you? Loving life, Alan. Good for you.
Good to be back on the boat. It is. It's good.
Yeah, I brought, I took my boat out of the, where we had put in for the hurricanes. So it's sitting in my yard. Unfortunately, it's still, as you know, you're out here.
It's really windy out and, uh, you got small craft advisories all over the place. And it's supposed to rain this weekend. I don't know.
I don't know if I'll be out on the boat, The weather. I got up, but two 30 this morning, the sail, uh, just for that reason. Yeah, pack every, You gotta hack the weather.
Well, things don't go good this week. I'm going on my boat. I might be heading to Havana, who knows?
Um, More Democratic states. Anyway, moving along. Moving along Hoola.
Moving along. Um, let's go to Colorado where we have the, the Guitar Master. Mitch Ashley.
Hey Mitch. How are you? Hey, Very good.
Very good. Excellent. By the way, I, you know, I, this is a compliment, Chris, I think in another life I could see Chris being kept Blas of pirate going up and down the Gold Coast.
I hear Chris looking for Gallion. Look at Pascalian Gallions for Ga, SC Mary for all we know that what he is used to. Yeah, He doesn't have a patch or anything on.
I don't see a carrot on his shoulder. Uh, Edwards taking, take control of a, of a Swedish concrete pirate ship, uh, during a storm on the open sea. So I think I actually am literally a pirate by international law, but There you go.
That's it. Not allowed in some international waters. Okay.
All right. And then still consoling, licking his feathers and wounds over his Yankees. Our chief content offers some Mike Ard, Mike, it's in the rear view mirror.
Now. Let's worry about, you know, concentrate on next year. We are gonna have an entirely different team next year.
We'll see how it all plays out. But You think so? I think so.
What Do you think the chances of Soto coming back are? Slung them up, Or you don't think they're gonna open the bank for 'em? Think somebody else is gonna open the bank and he is gonna ask himself, you know, does this organization have the will to win?
And I don't know if I can answer that question. Oh boy, this has hurt you. Hard.
I can see this is, this is a deep seated wound there in the, they, they ain't got the, they're the New York Yankees. 27 time world Champion, New York Yankees. Mike, don't forget it.
I don't know. It might be time for a new manager. We'll see That.
That I, I don't doubt. Anyway, let's, let's move on from baseball. It is election season, football season.
Um, let's Move on. Hockey season. Hockey season.
And it Is hockey season. It's also hockey season. Yeah.
Hey, what's the name of the Utah hockey team? Utah Hockey Club. Yeah.
The Utah. Utah Hockey Club. Woo.
Who's the market in there? Did they Change it to the yet? It might get changed To the Yetis.
To the Yetis, Yes. I know. I put in so many suggestions.
They should be the youths. I thought they look at those two Utes. Two Utes.
You can't be the y you can't be the youths. 'cause the college team is the youths. Yeah, the College team is the youths.
Okay, well, so much for that idea. Yeah. Would you like voir dire the witness, Mitchell?
Yes. Oh, Voir dire what? Dear You said Callow.
Anyway, all right, little My Cousin Vinny stuff going on. Um, but let's move on. Our first block today is on the state of election security.
How timely, Mike, you wanna kick us off? Yeah. The head of Ceases been out trying to convince everybody that these systems are indeed secure.
And we also have a couple articles about this up on, uh, security Boulevard. So feel free to check that out. But this all became an issue in the last couple elections.
'cause people were making allegations about voting machines and electronic voting. Chris, what is your sense of what's real here and what's not? Well, remember there, there's any method you use to hack a system.
You know, hacking is about getting to some goal by a non-traditional means, right? Uh, so we tend to think, you know, as computer people about hacking computer systems. And to your point of your question, I think the electronic voting system, you know, is extremely secure, right?
You know, Chris Krebs, you know, is in the industry, you know, well regarded across the board. I don't know anybody that doesn't, that has any questions about Chris's, uh, integrity. And he was in this role in DHS in the last administration during the election, did an, you know, an enormous deep dive with, with good folks on the tech being used today and gave it a relatively good bill of health.
But that's just the tech, right? There are human systems all over this. You know, the, the US Federal Electric system is actually yeah.
Follows downsides quite interesting and amazing. You know, it's, there are humans down to the county level, you know, putting in their own methods to make sure that the vote is correct. And those thousands of people do good work, right?
So I'm not very concerned at all about any substantial amount of, uh, election interference in that method. But at the same time, if you can get people to vote, you get people to believe, you know, the sky is following unless you, you know, vote. For me, that's a different kind of hack.
And as we all also know, the disinformation misinformation influence campaign is a nation state weapon used at scale, not just by Russia. The other classic, uh, um, uh, supervi in this case. But any, any, you know, competing nation states are doing these things to each other.
So obviously, China, Iran, and Russia and North Korea. And in, in that world, we have folks who are perfectly happy to take some effort to make Americans believe that lizard aliens are coming to, you know, stab it and purifier precious bodily fluids. I'm much more concerned about that as an influence than anybody actually logging in through a modem and changing boats on a machine.
By all means, young man in the Trevor Row. Okay? I think this is an ironic topic for me today.
'cause I was just at a, a, a event yesterday. I was talking to somebody who worked for the New Mexico Secretary of State, and they're kind, you know, um, she was a bit offended, um, by some of the discussion that's going on because they've worked so hard to implement so many security measures around voter registration, which is where the most, you know, if there's gonna be a breach, it's gonna be a data breach. Um, she talks about the level of pen testing that they do, the two-factor authentication, the just all the cybersecurity measures that they've been required to pursue over the course of the last four years.
And that still, people believe, and this is true, I've heard it come from people's mouths at a bar that I like to go to, that they believe that, you know, voting machines can be hacked because they're plugged in because they use electricity. So I, we have to keep that in mind. So I, I want to go, and I'm going to take this over for a bit, I call b******t on this whole thing, right?
There's nothing a matter with any of our voting machines. And ask Fox, who paid out $987 million or some crazy number because they said so and they got caught lying. This whole thing is nothing more than a, a jacked up b******t story created by Donald Trump and his and his minions, right?
They wanna sow discord. It's not a nation state thing, Chris. It's not China and Russia.
I worry about. It's the Republican party that, for the last four years, has tried to put human people in on these voting commissions to so to sow doubt and sow discord and upset lawful elections. They tried it in Georgia and thank God the court struck 'em down.
They're trying it in every damn state. They've got the lawyers lined up. That's good.
That'll be more lawyers who lose their law license for frivolous b******t lawsuits. And it's tying this country stands up and says, we're not gonna take it. You wanna win an election?
You win a f*****g election. You don't wanna, you don't play the games they're playing here. 'cause this messes with our democracy, right?
This isn't about election integrity. This isn't about voting machines. This is about one side has a clear strategy of just undermining public confidence in the government so that it's okay then to go send a mob to attack the capitol.
And as an American, I'm not gonna stand for it anymore. I say shoot 'em on site. That's where I am, You know, sociopolitical, I agree with you, right?
I think that we have, uh, one, a major party, you know, that's playing into this and is doing exactly what you said. However, right? You know, we need to look at this in the grand context, right?
This is really informational warfare, and it's not the usual propaganda sort of thing. We have everything from Cambridge Analytica to today. We're in an interesting spot where nation states are, you know, in St.
Petersburg there are, you know, hundreds of people at least spending full-time jobs sitting at computers pretending to be Americans. How many of them are being funded by Elon Musk Pac, who is creating fake Kamala Kamala Harris, uh, groups on Facebook with misinformation and it, and they've traced it back to his pact funding them. How many b******t groups have been set up on X?
Again, Elon Musk, you, you wanna talk about, they talked about in the last election, social media had an undue influence against Elon Musk is weaponized Twitter for whoever the ghost of that cesspool anyway, right? It's been weaponized. It needs to be shut down.
It shouldn't, it, it, something needs to be done here. This isn't a Russia problem. It's not a China problem.
It's not a North Korea problem. This problem is right here. The enemy is right here.
You need to disassociate the politics from social media ownership. 'cause that is a, that's been weaponized. You wanna talk about Zuckerberg or Apple?
None of them have gone to the, to the level of what we're seeing lust do with Twitter and through his pac. And if we don't take action against it, I, I fear for the future of our country. Well, you know, I think this is all driven by, uh, I, and I've felt this way for a long time.
I, I was on, I was in a different party years ago. Um, but it's the signs of, but losing power, right? The Republicans have been losing power because they've been losing popularity in, in the general, let me look at the general elections, right?
What the numbers are. And that's why they've taken focus on the legislatures at the state level. They've focused on the Supreme Court.
Now they're focusing on kinda the only way they can jack the, the, uh, presidential election and to, so, so discord. So it's a massive social engineering, you know, misinformation campaign to take it over, you know? And it, and you know, even the Washington Post now, the billionaires are, are subject to fear, right?
Not wanting to take a stand of who they would back or supporting their people who are doing it. They get the hell out of the way, let their people do it. And if they sign up for Trump, they sign up for Trump, or they sign up for terrorists, let them do it.
You know, it's, I I think it's, it's all coming to a head of, we have to take back our democracy, you know, if we, we really believe in the constitution and the things that, um, you know, are important to us in, in the flag and in our country and what we're proud about, you know, these are, these are people who are sewing discord, chaos. They're doing things that are not helpful to our society. And at some point, you know, you have to just say, that has to stop.
Or you go over here, you can keep doing that. But we're, we're turning down the volume on your, you know, if you're going to use social media to undermine the government, and we're taking it down, we have to, we have to do that. And it's more than just a free speech issue.
It's, it's an attack on our governments, and it's an attack on by, by people who are losing control, um, and losing power. And this is their own, this is their desperation. This is what they're willing to go to As a security person, right?
You need to break this out, right? You know, when you fight, stay as calm as the ocean, right? This is a very emotional topic for all, for everybody involved on all the sides.
You know, I, you, again, I agree with you, you guys and Sociopolitically, you know, I, I agree with everything you say. However, there's other Americans who feel very strongly that, that we're all wrong. So there's two things when, when you know, you're being attacked or you're looking at your protective practices, one is, you know, who is it?
How do I deal with them? And the other one is, why are they successful? And that's where, where I'm coming from, and yes, you know, nation states are investing billions and billions of dollars and have sophisticated structures to use this, you know, for those normal geopolitical purposes to distract to de road, you know, and, and again, in a conflict environment, I would do the same, frankly, right?
Within the bounds of, of how I would think I would win that conflict. So, you know, well, we here in America and around the world, this is not a US problem. This same problem is happening in countries all over the world.
There is, uh, a lack of trust. There's a lack of visibility. People don't believe anything.
So, and, and when you don't believe anything, despotism is as good as anything else, right? So we need to break this out. Well, Chris, This is right out of my comp.
If you get people not to believe in the, in the institutions, right? If you could get them to doubt everything, then make them believe unrealistic ridiculousness. And that's exactly the playbook here.
That's the playbook here. Oh, Absolutely. But, but what's different About it?
And so what happens, Please, Tracy, What happens too is once they believe that, right? Once they've swallowed, they've drank the Kool-Aid, their actions are coming from a place that they feel is good intent, right? Oh yeah.
They're wrapped in, they really believe that the election was stolen. They really believe they need to do something about it. So it's hard then to dig out of that because it's hard to understand that you made a mistake when you've, you know, when you're digging that deep, then you're trying to come from a place of good intent.
There, There is an amazing documentary on Fox. It's, it's like my, the brainwashing of my father or something like that is the name of the show. It's, it's a documentary, the film.
And it's really about the filmmaker's dad who basically drank the Fox News, Kool-Aid and had just went off the deep end, right? Yeah. And, And thinking he was doing the right thing for his country.
He's A patriot. A patriot. He's a patriot.
Mm-Hmm. Yes. And then he winds up on a bus going to the capitol on, yeah.
Yeah. Didn't he? Yeah.
I read another story. I, it wasn't in the Times, maybe was the post. One of them about these marines, this three Marines who participated in the, in the January 6th thing, walked into the Capitol and said, oh, we didn't know what we were doing until the video came out of them carrying the flags and putting a Make America great hat on some statue in the rotunda.
And then they were upset that they, they, they didn't get any promotions in the Marines and they quit the Marines. Good riddance to 'em. You violated your oath, son.
Get, get out. So, so, so I generally, I would, I generally agree on the conversation. However, I am not willing to sacrifice freedoms and rights that we we're depending in order to silence somebody or to, I'm Not saying silence them.
We, we, we need to find, we need to win this battle. If it's gonna be fought in the free marketplace of ideas. It just can't be something that we legislate and say, this social media platform can't do this.
And 'cause then we're, you know, going up against freedom of speech and playing into their hands. And likewise, we have to be careful with the rhetoric. And, um, You know, Using terms that, you know, encourage violence among people who may be a little unhinged to begin with, is probably not the way to go.
And don't underestimate the whisper campaign, the whisper campaign. It's amazing what sticky pads, sticky notes can do on a bathroom stall door, Chris. Well, the, the, again, the thing that's different about us, you know, the five of us right here, I, as individuals and human beings and Americans, you know, have this conversation, but we're technology folks, and this is an issue being driven and fostered by the technology that we have built, right?
So I think, and I, Mike, I couldn't agree with you more. I think we need to, you know, I think we win this, all of us. Yeah.
America wins this, and the free world wins this, and the world wins this by doing what we're good at, being more transparent, more clear, more concise, and not, you know, less obfuscated. And these are things that we as technology people can have a hand in. So I think there are, I mean, there's no, you, we're not gonna make a technology or any solution that, you know, proves who's right.
But I think we have such a lack of transparency, and that's the kind of thing that we as technology people could have a dent in to, to really change this Issue. Well, I don't really have an opinion on this subject, But vote but vote. But I encourage everybody, yes, you haven't voted yet.
I encourage you all to go out and vote tomorrow, and You don't have to tell anybody who you voted for. Well, that's a whole nother thing, right? And it's gonna be interesting how, how many women don't tell their husbands who they voted for.
What a terrible, what a terrible indictment of where we are as a civilization and society that in the year 2024, women have to be ashamed or kowtowed. Right? That they're not voting for who their husband's voting for.
I, you know, thank God I'm my wife. I, you know, that wouldn't fly at my house. Yeah, I would, I I'm not saying it's a large population, but Oh, I think it is.
It's bigger than you think. No, No, no, no, no, no. Let me finish.
But I think there's also, uh, some men out there who are not gonna tell their friends who they actually voted for either. Yeah. You know, there's that, there's the sort of the quiet part of it.
Well, Look, I don't like to publicly say which side I'm on, so It's hard to tell. Yeah. I don't think gender, if I look at the election results, has had any significant impact on the voting patterns because white women voted for Trump in both elections last time by Majority.
So No, no, no, no. So you, that's race, not gender. Well, gender has had a significant impact.
Joe Biden won. Women vote significantly over Trump. And, and, and Trump wins a male vote White.
It's a different story. You seen, you Seen that have the same issues that men do in terms of how they're splitting their vote. What I'm saying, I, you know, I I beg to differ.
I, well, They have r versus Wade. Now That only I, I think in this election, you're gonna see one candidate win the female vote from anywhere from 12 to 28%. And when females represent 53 to 54% of the voting electorate of, of the voting public, this is an arithmetic issue.
I don't care what they say about voting the machines. We'll be having a show on data analytics and elections on Wednesday, apparently. So, okay, Well, I say, I say, let's settle this at the ballot box in the courts where it needs to be settled and in the, you know, the realm of id.
But even in the courts, look, this was the, that was the strategy in 2020. They brought, what was it, 63 lawsuits or 64 lawsuits you wanna talk about? The Yankees need a new manager.
They were owe for 64. All they do is clog up the courts. And, and also, don't forget, you now have a lot more justices that our friend Mitch McConnell put in.
Who, who knows where they, you know, where their allegiances and, and how competent they are. So, you know, I don't want to go all out Pacino on you, but you are out of order. The whole system's out of order.
Said hello to my little friend. No, that no, no, no not and justice for all. And justice for all without bringing out the guts.
Anyway, let's take a break here. We're gonna bring it on down a notch. We're gonna come back and talk about cyber resilience.
You're watching Textron Gang Accelerate your DevOps journey at DevOps experience 2024. Join us for an exhilarating experience that will transform your DevOps practices. Explore emerging trends in DevOps and advanced platform engineering techniques.
Learn how to integrate security while leveraging AI to drive efficiency and innovation. Mark your calendars for October 16th, 2024. Discover how to improve operational velocity and foster a culture of continuous improvement.
Ready to elevate your DevOps strategy. See you there at DevOps experience 2024. All right, folks, we're back.
And as promised, we're gonna dial it down a little bit after throwing some red meat out there for Alan to chew on. But we're gonna talk about cyber resiliency and PWC has a survey out talking about how, well, a lot of folks don't seem to have this whole idea mastered. And the question I would throw over to Mitch is, um, are we thinking about the wrong things altogether when it comes to cybersecurity?
And we're not thinking about how to make our organizations more resilient to it at all. And we're just obsessed with maybe thwarting the attacks, but the attacks are inevitable. So maybe we should rethink our entire approach here.
What do you say? Well, it, it's interesting. It's a very large survey.
It's over 4,000 people that, uh, they surveyed, I dunno exactly the breakdown, but it, it, it's, it's, it's the difference of looking at are we doing kind of basic blocking and tackling? Are we backing systems up, et cetera. But the other half of it is, are you, can you actually recover from something?
And I think what what complexifies it in this situation is with ransomware and things like that, attackers go after data and they go after the backups of that. And that's a lot of the cyber resilience of it doesn't matter if you, if you've got a good backup, but it's been, been, uh, corrupted, uh, you know, it was good until it was corrupted. And that's, that's what they hold, right?
And that's what they try to get to. So I, I think the issue here is more you, you have to practice what you put in place. You have to make sure that you, you've gamed out and you do actual table talk exercises, just like we would a security incident process, right?
Incident response process. So what is, can you actually recover, um, if you had a cyber incident? And that's something I think it'd be really fascinating to survey.
'cause I think that's where you'd see the massive gap is whether you have the tools in place and they're being used is half, maybe a quarter of the question, three fourths of it is actually would they be effective under those, uh, stressful situations? And can your, you and your people and the processes you have go through that without kind of making snap decisions and filling in the gaps. 'cause you hadn't thought it through Chris, there's an implicit thought in this survey that says maybe we should be spending a little bit less on cybersecurity and more on cyber resiliency and reallocating our budget spending to the things that make the IT environment more robust and less likely to be breached in the first place, or at least recover from a breach.
And maybe, you know, we've kind of overfunded what some people now refer to as the cybersecurity industrial complex. I I would be fine with that, right? You know, so, you know, for the last 30 years I have really, really enjoyed working with operational technology industrial systems, right?
For all sorts of reasons. And, you know, each sector, the electric sector, transportation, maritime and so forth, you know, different use cases and criticality, criticality, resilience, right? You know, how, how important is it to make sure this doesn't break?
And you compare that to it and it's just not the same game at all, right? You know, it breaks all the bloody time and we just rebuild it over the weekend and, you know, which is just a bunch of cliche stuff to say. But I think at this point, at know very, there, there are, you know, very, very large organizations who have taken, you know, again, resiliency and safety are better words than security in the first place very seriously and done a very good job with it.
There are also very few of them, uh, most organizations, you know, have been nagged at by security people about doing things that they're probably not gonna do or that, you know, may or may not be effective. It actually getting some level of resilience that it's appropriate to them. So yeah, if you wanna reallocate the budget, call it actual business continuity instead of security where you need to encrypt something or do some, put some security practices in place, that will show itself anyways.
So I think there's been a tension in security now for at least eight to 10 years of how do we allocate budget from prevention to response. You didn't hear the word resiliency as much. It was prevention versus response.
And at one point I bet you it was 95% prevention and 5% response. But over time that that pendulum has swung. And I think overall, from a cybersecurity budget point of view, we do put more, uh, resources into response certainly than we used to.
And it, it's come at the expense of what we put into prevention or budgets have gone up. So they both, both sides had more, but the last couple of years, this term resiliency has snuck in. But I put forth the proposition that resiliency is not response, it's not synonymous, right?
Response is very clearly I've been, I've had an incident and this is how I'm going to respond. I'm gonna have crisis management, I'm gonna have backups, I'm gonna, this is what we're going to implement these, you know, this playbook, if you will. My response playbook, resiliency is something else.
Resiliency is designing my systems from the ground up to be resilient to, it's an acknowledgement that we're going to have incidents, but I'm gonna try to build the system that, you know, an incident will not be fatal. That we can minimize the damage of an incident. And that is resiliency.
And so I think it's important that we, we distinguish between resiliency and response. And the same way we went through this reallocation of budgets over the last however many years between response and prevention. We now need to put in a, a line item there for resiliency, not response, and make sure that that's getting a, the attention it deserves.
I'm not sure it's a line item. I think that part of the issue here is then it's really the responsibility of the IT organization to build a resilient environment. And it's just a matter of focus.
And there's always been this disconnect between the IT folks and the cybersecurity folks, especially around things like backup and recovery, right? IT ops runs backup and recovery. And they do that mainly from a compliance mindset rather than a security mindset.
And I think that we need to just go back into the IT teams and say, look, the way you design an IT system has, you have to put the security aspect of this thing and a much, much higher level of agenda and a much more forethought into the possibilities because I'm not sure that throwing more money at all, this is gonna make an ounce of difference if we don't have the right architecture in place in the first place. Well, half the part of the problem is that security is like a, I guess you could, let's think about a balloon. You know, you squeeze one in and the air goes one side and you squeeze the other in the other goes the other side.
It's cybersecurity is so broad that we, you know, for quite some time we've been focused on the, the, the production side on penetration testing, uh, and trying to, uh, you know, block intruders and we've put money there, then we run over and we talk about, you know, supply chain issues and then we try to put money there. But I think as this discussion is pointing out, we, it's not always the resiliency comes from a broader plan. And nobody has taken management of that broader plan.
You know, the security teams put responsibilities on developers to do things that they don't necessarily have the budget to do or time to do. And then, but they say, well, we we're, we're good on the, we're good on the, on the operations side, we've put all that together. Why are you guys not, you know, catching up?
So it's a, it's, it's, when I talk to companies, it feels like they're s they squeeze the balloon. They've got all this, these resources going to one side, and then they look at the other side and say, we're not doing anything there. Maybe it's a better, it maybe whack-a-mole is a better description of the game we're playing.
But I do know that there isn't, most companies that we speak to don't have a broad understanding of all of the defenses that they need to have to have a resilient cybersecurity plan. They see, they only see, it's like the, it's like the story of the elephant and the blind guys, right? They're all touching an elephant, but they're describing different things.
So there are so many ways that we have been that, that that security is an issue that it's hard to be good at all of them. And some companies are really good on one in one area and others are good in other areas, but we don't have a good full offensive system. Um, and everything that we do is defensive.
I love that visual, by the way. I'm sorry. Go ahead Chris.
Let's keep in mind that resilience is expensive, right? You know, I built two boats with four power systems, as you guys know, went through a hurricane, has had some damage, you know, it came back all all up. You know, resilience is really, really easy.
Build two, right? But if you say, you know, I'm gonna have two IT systems, I'm gonna have a backup IT system and just by two of everything build two of everything, you know, that's twice the cost. Unless all your competitors are doing the same, you're not getting there.
But I like about this way of thinking though, is is it forces, executives, leaderships to say, alright, what is our risk? Our risk is we can't be offline for five minutes or five days or five months, whatever. It's, you know, that would cost us x you know, the cost of, uh, a level of resilience that lowers that, you know, is y So you need to go through the process or you, or as an organization or You didn't have to talk in those numbers, Chris, you gotta talk business.
You can't talk, you know, our, our risk is, oh, well we have 7,564 known vulnerabilities, we gotta patch out there, right? That, that's not gonna, at the, at the board level, that's not, that's not the language they speak. And I think we're getting ahead of ourselves.
A a s civ is not resilience against resilient against leaks. And that's, we we're making the same mistakes that we made in security 20 years ago, Alan, 20 years ago, firewall check, intru prevention, check, check, check, whatever, whatever the security appliance of of the day was that we needed. We a put all those in there and believe that we've got a secure enough fortress to keep people out.
Well, it turns out there's a lot of other ways to get in, right? It's not really, it's not really secure. It's, it has, it has enough security that we think it's secure.
And not that I'm gonna label it this for the software world, but that thing about zero trust is, it's changed the paradigm, which now we have to do something where we don't trust anything so that we, because we know an attack can come from any, any device, any person, anywhere in the system. That's how you build in resilience. Okay?
You, you build in resilience, we have to be able to withstand not only the expected, but the unexpected. Uh, and How do you know the unexpected is, is you don't, you don't, by definition You have, you don't, but you have to have systems that degrade not fall down, right? And you, you can't prevent everything.
But you can, uh, you can design systems that can take a hit, but keep on standing, right? And I think to me, the, the big fallacy in our security, when we say software, supply chain, DevSecOps, shift, left AppSec, any of those terms is their point solutions. You know, shift left.
Oh my god, that's, that's as point as it solution as it gets, does it help? Yeah. Is it a good thing to do?
Yes. But that, you know, you, we un we know from the security world, it's the one place that you can get in that matters, right? And if you leave things open, people can get in.
So if you don't have a holistic point, holistic approach to security, and I think that's what we lack in our software approach to software security right now, period. So I I would say it's not just software, it's the whole system. It's the whole it, you know, it's not often I give Mike ARD credit, try not to, Well then why start now?
Well, Exactly. But, but what he said was there was, there was some truth there to what he said. 'cause here's another way of looking at this.
I think we do ourselves a disservice when we call this cyber resilience. I think it's just resilience. I don't think it's necessarily a security or certainly not a security only issue.
I don't even know if it's a security issue. The same way we build a data center down here in Florida to be hurricane proof, right? And it's not just having good backup and recovery.
It's making sure your windows are, are, you know, storm resistance and the doors are, and you have a backup generator and you have, you know, you don't have shingles on the roof that are gonna get blown away. You, you build a hurricane proof data center, same way our houses are down here are, that's resilience. It's systems design.
Chris, I no, It's pro process. Yeah. The Ukrainian grid 10 years ago, you know, when, uh, when Russia hacked the Ukrainian grid and brought it down, um, turned out that folks knew where the switches were and you turn it back on, right?
You know, so like, it is hard to say, you, we, you know, we can build you a, a truly resilient X, whatever it is. But you're talking multiple power grids, different parts of the world. And, and, and, and, and resilience is much more pragmatically achieved with business process.
Again, who am I, I'm an electric grid or I'm a final financial services agency or whatever, you know, what does I do? What, what happens if x you know, it all goes down, maybe phone calls work, maybe flipping the switches work, right? But it's, it is who you are, what you're trying to achieve.
And to your point, uh, Mitch, yeah, I mean, I, I said a second ago, you know, to ever everything that's not really resilient, you're right. Now I have two things that fail the same way. Great.
But quite often it's again, knowing who you are and how you do things and putting in an alternative way to do that should bad things happen. Hey, we gotta move along here 'cause we're gonna be short on time and we still got one more block to go. We're gonna come back and talk about API security.
I have a unorthodox view on this, but stay tuned. You're watching techron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right folks, and we're back with our final block and we're talking about API security.
'cause traceable AI has the interesting survey talking about how well, we're not very good at it. Basically. A lot of folks don't have a lot of confidence in their API security, and we're not even sure who's in charge of API security to be frank.
So, um, Tracy, let's start with you. But you know, when I look around, we are more dependent upon APIs than ever. It drives our economy.
And yet the more I look into this, the less secure those endpoints are than just about anything else we have. So, you know, do we have a problem here and what do we do about it? We do have, uh, a problem, but there are our solutions to the, to the problem.
Uh, it's a matter of accountability and who is responsible for implementing? And you know, it, this is a problem because we're talking about, you know, communication between these different applications and services, which is sort of the core of our software. Um, I, you know, when you look at API security and you look at what can be done about it, it, there is money that has to be spent on it.
There is training that has to be spent on it, but at minimum, folks, we should be looking at API gateways. And I'm always very surprised by how few companies use an API gateway and API Gateways have been out there for, for some time. Um, some are better than others.
It helps secure these endpoints. So let's get started there. The other discussion that we have to have in this area is the role of CISO offices in helping and improving API security.
Uh, this goes to, I, you know, I talk about this so often and I see it in so many different um, levels. The CD I always say this, the Continuous Delivery Foundation very doesn't have a lot of conversations with the open SSF foundation. The CISO office doesn't necessarily talk to the DevOps community, and the DevOps community may not be talking to the developers.
So developers are doing what they can. They have a lot on their plate. I sympathize, uh, with their position because they're not only trying to get code out and keep the company effective and agile.
They are having to deal with learning AI and they're having to secure their code and they're having to push all of these services out as quickly as possible. Where, who is really responsible for making sure, uh, that API security processes and procedures and tools are in place. I don't necessarily necessarily believe it is the role of the developer.
Now we're starting to go to turn into a, uh, having discussions around platform engineering. Is it the role of platform engineering now to start looking at how to implement better tooling and better practices and better scans and better approvals around APIs? I don't know where the answer is, but I do know that it's a constant problem.
And part of it is we don't necessarily talk to each other and there's no clear measures of who's accountable for taking care of the business of API security. The tools are out there, we can do it. We just have to give, put time and, and budgets in place to, to take care of it.
And I think that the more people understand that, you know, encryption and data threats come from APIs, I believe the more they'll understand why we need to pursue better practices around APIs. You know, we started this by talking about, uh, you know, election security. And I really believe that where there could be issues is in voter registration because that's the data and that's what can be impacted.
So when we think about the data, I believe that we will, we will become more interested in worrying about API security 'cause it is part the primarily communication to our data. Uh, so a discussion has to be had and we have to be, uh, we have to pull together in so many ways to address these security issues, particularly around API, even just down to API, uh, you know, documentation and governance. 'cause that oftentimes is not done.
I did Thank you for calling on me, sir. Uh, so, so to me the argument that that API security is not part of the CISO's responsibility is like saying the whoever's in charge of physical security doesn't worry about the windows. I only do the doors.
The windows are in your offices. You guys take care of windows. I don't secure put any security systems on that.
That's ridiculous. The, the A API's data where it's located encryption of data and all that information, it's part of your security plan, part of your security strategy. You may not be the one to implement, but you can't write it off as not as important.
Maybe you have a partner who isn't really a partner over in the CIO or the CTO that doesn't give a crap about security, and you can't come to an agreement on a strategy that's gonna work. Okay, well then you got a leadership problem. You need the leaders have to be bought into.
Security's important, but I I, whether it's not the job of the CISO to know how to do everything, how to do how to build software and, and how necessarily how to make it secure. That's the job of the CISO is to work with the organizations that are building those applications, including the end user community who are going, who are doing their own thing right outside of it to make sure we're protecting our systems, our data. Because who else is it gonna roll up to?
If not the ciso, I don't know who's gonna answer for it. They always push it back to the API, the the teams themselves to secure their software, though. That's where the accountability falls.
Yeah, they made, but they don't Necessarily necessarily have a budget for it. Well, that then, and then, then that's the issue. The issue is how do we secure our APIs?
And you've gotta enlist the security organization to say this is we need to allocate more money to that part of our security strategy, right? So that's, that's my opinion. I have an opinion on this.
So I will tell you that in my opinion, the biggest nothing burger in security over the last four years has been API security. Yes, a majority of traffic on the internet is API to API, not only external like Mike's API to Alan's, API, but you know, when we talk about, um, a multi-threaded applications, right? When we, when we container to container API communication, if you will, right?
That I call it internal API traffic, it's huge and growing very quickly. However, people vote in many ways, people vote with their wallets. Mike, don't worry, I'm not going back to block court.
People vote with their wallets. People vote with their eyes, ears, and you know, fingers. But they, they make their, they make their preference known.
API security people have voted it's impossible to get people. I've never seen something turn from a product to a feature so quickly, right? Every API security company out there, and there were several that were unicorns at one point have either been acquired and not for great multiples, kind of violated my rule of being the top three.
Um, it's not my rule, the Brad Feld rule of being in the top three. You know, you look at, and I'm gonna name names, no names, security was a unicorn. They were the industry darling for API security, aka I picked them up relatively cheap, really cheap.
Our friend Michelle McLean was at McLean was at one mention, uh, and they got bought by Red Hat. I don't remember the name off top of my head. You've got our friends at Traceable here who have gone through their own recent turmoil and, and, uh, turnover.
Um, I think the market has said API security. Hmm, yeah, yeah. The WAF doesn't work for it.
We've got these other things, web app, API kind of security measures. I don't know. It's whether because they don't really work or people just don't really see the threat and we haven't had a serious enough API attack where it hits them in the wallet or it's just too damn hard.
But certainly the industry has said this is a nothing burger. I think the jury's still out. And I think to your point, um, a lot of folks think the WAF is sufficient, but they don't realize the degree to which data's being exfiltrated or the business logic itself is being manipulated.
So it's not really about the underlying, uh, firewall. It's a, it's an issue that sits above that firewall. And I think a lot of the times when we investigate these cybersecurity incidents, we don't go deep enough to figure out what the root cause was.
So we don't realize that it's really an API issue. So I think that this is all gonna come around together as a bigger conversation. But right now, you know, in 20 23, 20 24, I'm gonna agree with you, but I'm betting on This.
Say that again, Mike. Which Brent? The one I agree.
20, 20 20 with 24. Yes. Yes.
Um, what I'm saying in 2025, this conversation's gonna come back, but I don't know if the existing platforms are the right answer because they are more cumbersome and add another layer that needs to get managed. And I think people are a little resistant to that. But I do believe that in 2025 we'll be talking about this.
Okay, you heard, Well, I wanna point out that there's some really good open source, uh, API security tools out there. And if you leave it up to the development team to solve these problems, they're going to reach to what's free. Because as I pointed out, they often don't have security budget.
They wanna spend their money on other things. So maybe that's part of the problem. I mean, we, you know, both Kong and Postman, um, have open source tools, and that's kind of how they started pushing their business.
So I I is out there. They're, they're good tools. I, I've spoken to several, uh, uh, marketing chiefs at these API security companies over the last couple years.
And clearly their research and their experience is Tracy, that the developer is not their customer. Their customer is the, the tried and true security guy, the ciso and you know, that typical sort of security sale, they don't even, they thought it might be the DevOps team. They thought it might be the developer, but they wound up not, not making their numbers and, and pivoted to selling to the security team.
And, and, and this is again, I think part of the people voting with their wallets on this issue. And, and maybe Mike is right, I if he said I'm right, I gotta tell him he's right too. Um, but you know, The part of the problem just comes back to who it was too early Security, right?
Know, maybe it's too early, you know, look, I've been in security a long time until you have a Pearl Harbor, it's hard to, to get the nation ready for war. And, and we haven't had an API Security Pearl Harbor that we know of yet. I think we had one.
We just don't know what Could be, could be. Anyway, guys, what a great show for the day before election day. I hope we've got your, your juices flowing.
You're ready to run out there and vote no matter what it takes. Don't be intimidated. Don't, you don't have to wear your buttons or hats.
Actually, you're not supposed to wear your buttons at hats when you go vote, but do go vote everyone. Uh, we'll be back tomorrow probably encouraging you to vote again and, um, oh, with your clicks by coming back. Wait, wait, wait, wait, wait.
I, I just wanna say, uh, I'm gonna personally endorse API security vote for API security Backing another winner, Mike. Good for you. Yankees, API security.
What's next? That's a, um, anyway, it's coming back. It's coming back, man.
We, we've got, we've got a full day of Textron TV following today's gag show, so make sure to stay tuned for that. We've got some great podcasts and, and interviews and sessions from events. There's a lot of good text on TV content out there.
Check that out. But until tomorrow, Tracy Mitchell, Chris, and even you, Mike, thanks for being here with us. I hope you've enjoyed this version of text or this edition of Textron Gag.
We'll see you all tomorrow. Good luck everyone.