Techstrong Gang – October 21, 2024
Alan, Mike, Mitch and special guest Chris Blask and Tracy Ragan discuss how artificial intelligence (AI) agents might soon resolve our DevSecOps issues once and for all.
Then, the gang turns its attention to why the U.S. Army is helping small businesses to implement best cybersecurity practices before diving into why the U.S. Department of Justice (DoJ) is running a Bitcoin scam.
Transcript
Hey, everyone. Happy Monday to you. Here's the good news.
An AI army of agents might be coming to DevSecOps. Speaking of help, the US Army is out to help secure small businesses who ask for them and the DOJs in the, in the crypto scam sting business. All that and more are on Textron Gang.
Hey, everyone, happy Monday. It's a shimmel for Textron. I'm sorry I'm not in our studios in Boca Rat today.
I actually just got in on planes late last night, and so doing this one from the hall office, which I, I don't normally do. But, um, nevertheless, we've got a great show lined up for you. Today we're gonna talk about how AI can agent, I do mean agent, um, in DevSecOps Automation.
We're gonna talk about that comes out of a, a panel I was on at the recent OpenText virtual conference on DevSecOps, which is very good, and I highly recommend you guys going to check that out. Um, we're also gonna talk about the US Army wants to get into securing the small business space. Someone's gonna do it, I guess.
And then lastly, crypto, uh, crypto gang, uh, scams being run by the DOJ. Wait, like we don't have enough crypto scams to begin with. Anyway, though, let me introduce you to our panel who we're gonna discuss it with today on this fine Monday morning.
Um, first of all, joining us from, I, it looks like home in New Mexico, still not in Fort Myers. Uh, she's the CEO of at one of our steady gang members here. Tracy Reagan.
Hey, Tracy. How are you? I'm great, and good morning, Alan.
Glad you're awakened. You're at home. It's nice to see you at home.
Yeah, it is. It's, well, it's good. I haven't been home very much and I'm leaving again this week, so, um, yeah.
But we will get there Anyway. Um, Tracy, nice to have you joining us from, I think it'll be his last dial in from Canada, because he's soon to be headed to part south, our resident security and just, uh, all around life expert Chris Blas. Hey, Chris.
How are you? I'm good, Alan. Yeah.
By the time, uh, this goes to air, I'll be back on the solar power boats in Florida, being a solar power gipp. All righty. Looking forward to lots of posts from, from the Twains, as we call them.
Right. Um, joining us, he's back home in his pair of top the Rocky Mountains. It's, it's our CTO and Futurum.
I guess. It's a new one now. Fu VP of practice lead come up something else.
I don't know. Practice lead. Mitch Ashley.
Hey, Mitch. Welcome and congratulations. Hey, thank You.
Thank you. I'm excited to be, uh, to, uh, playing this role now. And, uh, by the way, um, you know, I was traveling back from San Francisco last night.
It felt a disturbance in the force over the weekend, and I realized, oh, Alan Chimble had a birthday. He caught up with me again. Happy birthday dude.
Thanks. Mid show. You're welcome.
I, I appreciate it. Yep. You we're the same age again.
We are Again, I wasn't gonna make a big deal of it, but I guess you did. Okay. We love You, man.
Happy birthday. Thank you. Does this mean I have respect?
Does this mean I have to respect my elders again? Oh, you're really not to making a guy feel good. Okay.
I, rather than the, the wise guy from the Bronx up in the top left, he's our chief content officer, Mike Ard. Hey, Mike. Thank you.
Happy birthday. Thank you very much. All right, guys.
So Mike, I, I kinda laid out the blocks, but let's go over to you. You want to set this up? Yeah.
It was an interesting panel that you were the host for, um, at an OpenText virtual event. And one of the things that came out of that is their chief security strategist was at least putting out the theory and sounds like a reasonable theory that AI agents are gonna enable the security folks to be a lot more proactive about securing software supply chains than they have been able to be in the past. Because, um, they can get in there now and set a bunch of policies that will be automatically implemented as code is written.
And they don't need to be in the way, and they don't need to sit at the back end of the process and start, you know, telling people to start over again. 'cause that's the conversation nobody wants to have. So, I know it's rare for me to actually say that there might be some good news here in the DevSecOps land, but I'm, I was kinda hopeful I might bearded.
Here's the good news. Uh, so, so, you know, listen, here, here's the deal. Like everything else, things can, there's, there's two sides every coin, and AI certainly poses a potential risk to security teams.
Uh, when we look at it from a code perspective, how much more code is gonna be written via ai? Um, and, and it's not always maybe of the highest quality or most secure, but on the other hand, there there a lot of advantages to this, right? Number one, we could, AI is never complacent about security.
If you tell it not to be right, it doesn't blink. Um, number two, it, it really does do what you tell it to do, you know, to the best of its ability anyway. There's a lot less human error, obviously, right?
Unless it's in there from, to begin with. The third thing is though, as we spoke about on this OpenText panel, the ability to have agentic ai, right? Agents that are crawling your code as you write it, or as it's put into the repo, or as it moves along the CICD pipeline, and either flag things to be corrected, or in fact, actually remediate and correct them themselves.
And, you know, think of it, I'm talking about an army of agents like to go Carl Sagan here, right? Billions and billions of agents, because I, here's, here's, I got some good news too. It's not just the code that we're developing now.
We could set this agent army loose on the 6 trillion lines of code or whatever it is that's out there already, and, and have it check it to the A and those a, like I said, the AI agents, they don't take off. They don't pick, you know, set 'em loose, let's attack on security debt and Right. What a wonderful world that would be.
You know? And so I get all too rosy on you because I don't know how soon or how realistic that is. But, you know, we, we could harness AI to, to attack what, and, and really make a big debt in, in this security debt.
And, and the quality of our code that's coming out of our CICD pipeline, it's like putting quality control people into the assembly line at the car factory. I think it's, it's Alan, if you think about multiple threads of roles that AI can play, right? It's not, it's gonna solve it all by, you know, detection and reporting bad news to developers.
Not gonna solve it all by fixing every vulnerability or, uh, insecure code that might've been created. But if I, I'm a firm believer, we've gotta go from move, move from generic or general, um, LLMs to very specialized around how, how to write secure code, how to fix code so it becomes secure how to apply patches so we can, so we do, we have agents that are very specialized, right? Not every agent has to do 50 things and maybe just does this one kind of thing is in Linux systems to patch certain kinds of vulnerabilities or upgrades, and those things grow and expand over time.
So at the same time, we'll still need to flag things that are potential issues that we may not have bots or agents to fix. So it's, it's not a flip the switch and we solve all of our problems. It's gonna be this kind of parallel tracks, but we see less and less reporting and more and more, um, you know, fixing and Tracy, I know in, in your heart of hearts, you're gonna say, yeah, but it's not just code, it's configurations, it's things in the repository, it's scripts, it's all kinds of other stuff that has vulnerabilities or security issues in it, or credentials stuffed in it, all that stuff.
Okay. Te it up for you. Trace.
Nah. Well, I think one of the things you didn't mention is commitment. Mm-Hmm.
Right? Commitment is, um, commitment to fixing the problem, uh, is not there. Uh, I think it's a great idea.
Uh, I mean, as a junior developer, I can't even tell you how many memory leaks I had in my car. If I had something as I was coding, it corrected my memory leaks and said, Hey, you just did this. Just like it does when I, with Grammarly, when I spell something wrong.
That is a huge, huge, uh, uh, help for, for developers, but I don't even know if they're gonna be needing that because most of the code's gonna be generated without the memory leaks and the problems in the first place. And they're going to be using that code to, uh, assemble their, their applications. But commitment is a problem.
We have had OPA for how long, and we haven't put policies in place in the DevOps pipeline. So are we gonna get excited because it's an agent that's doing it? I don't know.
Uh, but we have the tools today to do much of what that, uh, your, your OpenText panel talked about. We, we do have the knowledge to pull together policies and put stop blocks in places where we need to, when we know teams are not currently going through all the steps that they need to, to be as secure as we can be. And ultimately, it doesn't fix malicious code.
It, you know, nobody, no, for the most part, we're not sitting there writing malicious code. We're making mistakes and it'll catch those mistakes, but it's the malicious code that we, we should be more concerned about. And that is not gonna solve that problem.
So, to your point, Mitch, I believe that chaos happens and we should look, be looking at chaos engineering and their practices, and how do you respond to vulnerabilities? And at this point, we are not doing a good job of collecting all of our DevOps data to be able to match a vulnerability to all of the containers that it's, that it's running in across thousands of endpoints. And that's what we're trying to do at deploy out.
That is our huge focus because chaos happens and we have to be able to respond to it, whether it be a vulnerability, a malicious piece of code, or somebody just made a mistake in coding and put a negative, you know, put a positive sign and instead a negative sign and deposited a penny into their account every time something went through. Right. You know, chaos just happens.
How do we address it? And I don't believe that AI is going to fix everything. You know, I, I, but machine learning has got come a long way.
And machine learning. We know we talk about these new AI uh, practices, but if we had the data now in the DevOps that we were collecting in DevOp, the DevOps pipeline, imagine the machine learning workflows. We could already be putting in place the pattern matching we could be doing, but there's just not a commitment to do it.
And maybe teams like me, we should be going, Hey, we do AI to do this so we can get funded and solve the problem and put a little, a little AI agent in the background to say, we are ai. Right? Well, AI never heard nobody's, Tony Montana said, Yes, gas.
I gaslighting annoys me though, and I don't like to, to do that. The record For the record, Tracy, I've always told Mitchell he has a problem with Commitment. So all those memory leaks I created are now coming back.
So Alan, on that virtual event, are also talking at John Willis. And John, you know, was on a rant about the fact that, you know, I don't know if it was a rant, One Of the element, but basically he was, yeah, he was saying that people aren't trying these tools enough and that, you know, they're convincing themselves to do nothing. Him and Patrick Dubar on the same kind of preaching, the same gospel as they said about the, you know, the new church of, of AI and DevOps.
But, um, Well, kind like Gentech AI is the new gen ai, it's the new popular term. I think most people have a gen phobia, and they're not gonna be wanting to rely on AI agents doing things autonomously. Just like we don't let autonomous driving happen quite yet.
There's a human in the loop, right? Maybe it fixes things, but, you know, as a guided process. Well, that's what I'm saying.
We haven't even implemented policies, right? We can, we could be using OPA across our demos, pipe pipelines at least just says this policy was not complied to stop. Something as simple as that.
We have not done yet as a larger community. And maybe teams have done that. I'm not saying nobody's done it.
Obviously OPA is super popular, but we could apply these tools that we already have to get 80% there without having to be talking about rebuilding. You know, this whole system around agen Toki and having AI agents, which already are a problem, adding more problems to the, to the soup, does not make it a better tasting soup. Well, however it plays out.
I, I see, i, i feeling the opportunity to finally put the G and GRC, you know, we've been talking about that for years, to be really clear. There's been lots of risk of compliance and no governance, you know, and you guys, you know, uh, did a better job than I gonna explaining where we are with this particular topic. But I think governance is, you know, like within the realm of the pos possible in areas like this, in the foresee future for the first time ever.
Yeah. No, it's a new day. It's a new day.
No doubt about it. Tracy, one, one suggestion from the marketing guy here in the middle. Um, if Deploy Hub is about stopping chaos, maybe like get smart, right?
And Maxwell and Agent 99, we put you in a black wig. You could be, and, and you're taking it on chaos. It is almost Halloween.
We're not very far away. You know what you get get the shoe phone, the whole thing. Hello, chief.
Uh, Well, smart. I think that's a great name for a product. Get smart.
Here we go. Um, but anyway, Wait. Hey, How come it never really worked out the way it was supposed to in that episode, right?
He'd called him with his little foot bone thing and, you know, it was always a bad scene. It was the cone of silence. That was the best.
The code of silence. I was just gonna say, we gotta speak. Okay, let's bring down the cone of silence.
Oh, look, that show what? It's a funny show if you ever get to watch the on classic TV streaming or whatever. com, the, uh, link to the Open Text virtual event.
Uh, and I, I did, I did talk with John Willis on that. I was part of this panel that I thought was really good. And then I did a, a one-on-one, uh, with, uh, OpenText, uh, I think Chief of Product Marketing or something.
Or maybe it was just product. I forget right now. It's, I've done so many in the last two, three weeks.
It's crazy. Um, yeah, there's a link in the article, uh, yeah, to the OpenText, what's a week in there? So please check that out.
Um, all right, let's take a break here on the gang. We'll come back and we've got more for you. Let's say the US Army is here to help secure your business.
They want you, all right, you're watching Textron Gang Cloud Native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud Native.
Now. Hey folks, we're back here where we are onto our next block. And well, the United States Army has this new contracting service that they put out, and a lot of that involves small businesses.
And one of the things they just did is they said they're gonna help small businesses become more secure, uh, if they participate in this contract process. And Chris, I want to come to you, 'cause I know you don't hear this very often, but as the United States Army is setting a good example here, 'cause it seemed like to me, um, big companies should be doing the same thing. They're all dependent upon these small organizations that don't have the cybersecurity expertise required.
So maybe we all should kind of like, reach out and secure our extended networks of companies and families that we depend about. Yeah, I think about our three topics today, and the common thread is governance. You know, the last topic we're talking about governance and DevSecOps.
We're talking government events, and we think about that differently. But it's the same sorts of things. You know, I'm just writing code, I just wanna write code.
And you tell me, I, there, I need some governance, I need some oversight. It doesn't feel like it's helped me much. And as we were just discussing, maybe we can make that easier, because without that, you end up with other problems.
And, you know, not to overstate the importance of government. I do a lot of work that work a lot with, you know, you know, US Federal government and so forth. They have roles to play, but they can't solve all your problems.
But I like this kind of threat where this strikes me a little bit, perhaps as what we're doing in space. You know, NASA's trying to be less than building the Rockets organization to agency and be the more foster innovation a whole Fred, we can get and have a star in your conversation around that if you wanna right now. But, and that's a good example.
So, yeah, and I think you, you, you may have a point, big organizations out there, if you have an interest, you on supply chain is a big deal these days. Maybe part of your supply chain operation is to be, as you say, doing this sort of thing in the private sector, but helping the small cup base reliant Mm-Hmm. It just needs some good branding instead of Geek Squad.
It's Geek Platoon or something, you know? And I think it needs more money. One up At your door.
You Do? Oh, yeah, Yeah. No doubt.
The money is not there. I mean, I mean, what I think the article said, there's a, there's 97 Apex offices and 26 million, which is about 250,000, you know, a, a, a team and Deploy had works with Apex. They've helped us get our cage code and we're going to go out after some funding opportunities.
And they're pretty swamped with doing work with small companies. I'm, I'm struggling to see how it would be implemented well through these Apex systems with people who don't know anything about this, this topic. So they're gonna have to bring people on who can sit in their offices and work with these teams.
And at 250,000, that's maybe one really strong person or two Okay. People to push it through, uh, for the small business. I mean, we have one Apex office in New Mexico, and that's gonna serve how many businesses.
I mean, we, we, and believe it or not, New Mexico, it does a lot of work with the DOD and the DOEA lot of small businesses. I don't think that they could cover us one office at 250,000. It's a good start, but it just isn't, uh, it's, it's not gonna make big enough dent.
And many of those companies, we talk to 'em, they don't even have DevOps pipelines. They're still do doing a lot manually. To me, this is the kind of good idea government program that screams out for a private public partnership, right?
I think, I think the, the government should be the, had the Army in this case should be the catalyst of this. But I don't know, you know, I mean, Tracy, to your point, am I gonna go put billions into this? Well, my guess is they'll probably bring on Edgewater to do most of it.
Edgewater is a, you know, national consulting firm that does basically DevOps for the, uh, for DOE and DOD. So they probably will do something of that sort. So we'll probably see that Edgewater's gonna get a big influx of cash to do that kind of work.
So it, it, it has to, that's the only way it's, it's gonna get done. And That, and, and that's, and, and there you have it, right? Mm-Hmm.
That's the government wants, right? Uh, the, the beltway mandate gets there. Pound of flesh.
Chris, lemme ask you this. Um, we are in this election cycle, and yet I still don't hear cybersecurity and locking down our country and small businesses is kind of a theme in that general election conversation. And is it, is it just because nobody wants to talk about it, they don't care, or they just don't realize that 80% of the economy is dependent upon these smaller businesses that are kind of under siege and don't have the resources to fight the fight?
Oh, that's a complicated one. I think in part, we're tired of it. And in part, you know, I I, you know, you know, the disinformation campaigns, you know, when you start using those sort of techniques, what you're trying to do is we get population's interest in fact, right?
You know, and so that whole topic is raising up a whole lot of fact. And, you know, and, and by whatever definition and how you define, so I think we, we get our, our structures, and I don't wanna sound too pessimistic about this, you know, you know, peptide makes better solutions, uh, evolve. But you look around the world, you know, the European partners have done a much better job what they structures to help people define realities.
So you can tackle these top issues. You talk cybersecurity at all to anybody, you know, you better know what, you know, have some cot narrative, you can guide them along. But if you start saying that, you know, government is gonna help us have the truth and information and information systems, you know, you're starting to backfield already.
And I think we have enough to be freaked out about. We have enough to be freaked out about. I mean, every time I listen to Trump, I'm like, oh my God, the world's coming to an end.
And then I'm like, well, wait a second. Down to One candidate here will probably tell you computers caused cancer, who's never really used Exactly. You the short of tweeting on his phone.
Right? And if you don't believe in climate change, why should you believe in cybersecurity too, as well as end costs? And, and, and Rudolph on the other hand, I I though it hasn't been foremost in as a, as an issue because of the be, you know, it's about the economy, stupid.
But that being said, I, I do feel it necessary. You know, I'm old, dude. It's my birthday, Mitchell and I are older now.
Chris is of the same age around us. Mike, you're not far behind Chay. You're the, you're the kid here, but I don't Think so, but I'm like, I like that you think that Okay, Hands making you feel good.
I'm a gentleman. But anyway, uh, I I I feel like, Hey, hey, Joe Biden, you know, he's not gonna be president one way or the other. He's not running.
But the, the cybersecurity guidance, you can't get anything through our Congress. We don't have the will, the political will to get stuff down. Chris, to your point about that they have maybe in Europe.
But when you look at what Joe Biden, CSA, CISA has done and what the White House and their executive orders have done around cybersecurity, it's been more than any other administration I've seen in a very, very, very long time. So to say that the president administration wasn't serious about cybersecurity, I, I think it's is a outright lie that I'd hear on some entertainment network into masquerading as a news network. Well, I mean, it's, it's passed.
He has passed off market at this point, right? You and look at the last administration, Chris Press talk about, you know, his continuity in governance, not Flying for opening his mouth. He did it, but did a fantastic job.
So it did a really good job. Fired, do the election. The infrastructure, you know, is, you know, in yeah know has, uh, bond.
I think we have to keep in mind security is not a voting issue. It's not what voters, you know, campaigns are about something totally different than, you know, day to day, week to week, month to month politics, right? So it's, you know, maybe my credit card got stolen in so many name got stolen, but people even that we were so desensitized to it, it's not even, even in the, on the radar is an issue for people at least to vote on.
Right? So I, I think to your point, Alan, you know, what, what Biden did with the executive order, not an order, but he came out with the, you know, the Yeah. Several S yeah.
The FDA and you know, two others that are now mandating SBOs. You know, there's a number of things that have cascaded that he has directed the government organizations to do, um, as opposed to enacting laws. You know, that's something that government do it yourself.
Do it to yourself for yourself first, and we'll build from that. And it's making an impact. And he started doing that.
He, he started doing that really early in his administration. I, yeah, he, you know, with the open SSFI was on the board in his first year at the open SSF, and we were invited to hang out in Washington DC with their, uh, with NIST and some of the other, uh, homeland security and a round table and talk about what needs to be done. So they started that, that was on his plate, uh, without being talked about.
And maybe it's better that we don't talk about it because it will become some kind of a deep state issue and we don't want it to go there, like climate change, you Know, it's science. Oh, that's Exciting. I disagree on the, I disagree on, there's one point, I think it is a voting issue because not so much my personal credit cards, but I think everybody knows either works for a company that's been impacted or knows somebody whose company's been impacted by this.
And I think it's a, and I've seen the level of disruption to those businesses and, and it hurts those businesses and it, and it hurts their ability to give folks raises and be competitive. And so I got a feeling that a lot more people are aware of this beyond their credit card issue. Chris, you got some, And I'll say it's a voting issue in as much as you do or don't believe in our system, our, our government.
And I think the, I we looked at supply chain multiple administrations in the last couple very different administrations. What gives me a lot of faith in this over time, regardless you to certain extent he was in, is that, you know, presidential executive orders are not ramped up by somebody who just got elected for four years. We're presented to those people by our peers, you know, in the government, our friends and so forth with the step together.
And was the supply chain executive orders across this current and the last administration and the one before them lineup surprisingly well for the natural interest. You know, because these are, you know, whatever you're trying to do politically in the White House, your options are what they are. And in cybersecurity, this is a very pragmatic world.
We keep driving down towards systems that are improving over time and they Improve. I'm still gonna disagree. It won't be a, it won't be a voting issue until I can't get power at my house turned back on for three weeks.
'cause the grid went down. Yes. Um, my taxes are going out because the government's bailing out every, every big company in the world because they're suscept they've gotten so much financial impact from security breaches until it hits people personally.
It's not a vote voting issue. Um, well, I I'll tell you how it could Become A voting issue, though. I'm not saying it can't, I'm just saying it isn't.
Oh, Wait, whoa. I'm saying it's part of, but it's not center stage is we're thinking cybersecurity, financial loss, or Mitchell in your case, critical infrastructure. In your example, when we talk about nation state espionage and nation state cyber warfare, right?
That's something I don't think gets enough play on the political stage. If you, if you were to take away North Korea's ability to make money from hacking, they wouldn't be exporting rockets to Russia or sending troops up there. Oh, they probably would be.
'cause that's less people they have to feed. Um, right. But, but you know, you look at North Korea, Iran and what they're doing, they're constantly, uh, you know, this whole axis of evil that we live in now we live with, right?
It, it's kind of, uh, it's kind of at a Boris good enough, and Natasha, you know, come, we go get squirrel and, and, and the, and the, the, the Chinese loose means squirrel. Look, this is why you tuned in. It's kind a little snippet from show.
I'm getting this what network Allen watches on a regular basis, classic TV channel, cartoon Network. Yeah. What, what the Chinese, do you know what the, what what's going on?
I mean, they, they, they're constantly probing constantly. I, I did an interview, um, I don't even know if it was on, they're all running into each other now. If it was on the Dextro gang or just a one-on-one interview about a recent report of a, of a Chinese hacking gang.
Right? And, and, and, uh, you know, with with ties to the government over there and, and what they've been doing. So, um, I Think, well, we have it, we have to have more informed voters if they're gonna make decisions on things like this.
I mean, I believe that we've learned, well, And I got Princess Leia, but I want to hear more about what Princess Leia has to say before I make a decision. And when, when that's the state of your politics, you want more informed voters. Does any anyone ever mention these undecided years?
So, wait, I, I have to tell you, so there I was watching one of my favorite programs, which is CBS Sunday Morning a couple weeks ago. And they did a piece on Finland. Uh, and Finland has been having such a barrage for years and years of misinformation coming out of Russia that they now teach kindergartners how to recognize fake news.
So we're, we're new to this, but other countries like Finland Art, they were graders. They were showing first graders identify fake news. Why can't we have that?
But no, We have to, we, we have to understand that this, this, this is part of the cybersecurity problem, right? It all comes together. So we do have to have more informed voters.
We do have to have this discussion at the, at, at, at kindergarten, apparently, because that's how they have solved it. But it's not gonna get solved, um, by one The world did most informed voters can, you can imagine your five-year-old coming home from school. But Dad, that's fake news.
Yeah, exactly. Exactly. That would be amazing.
They'd probably have taken out as public school for that. But I think It's similar to Nets ops thread though, right? You know, you know, I'm all for, you know, teaching critical thinking and I'm all for, you know, teaching developers to write secure code.
And, you know, to the point of the first piece, you know, real governance in DevSecOps has been too onerous. Maybe, you know, what we call AI today to make that easier. I think we still need those sort of tools in the misinformation, disinformation space along with better thinking space.
Well, Unfortunately to, I think Tracy's right though, Chris, I think you gotta start this in kindergarten and you gotta, people gotta grow up with it. I think we've got some lost generations in between there and there. And I think we can afford adding another zero to that 26 million that Apex is looking at spending across the United States, Especially if they'll help deploy hub defeat chaos.
Oh, that would be awesome. I would love to do work with them. Alrighty.
Maybe it'll, The phone we can apply for. Absolutely. Let's take a break here.
I think we, we've hit this one. We're gonna come back and, and, uh, the government running, running, running crypto skis. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. All right, folks, as promised, we're backing.
Yes. We're talking about the Department of Justice is running a crypto mining scam. They get people who are abusing cryptocurrency.
I guess they're trying to protect the folks who have cryptocurrency, um, from running the additional scams. So they're gonna, uh, okay, I don't know if they're gonna continue to run this, but they've indicted some folks on this whole issue. And Chris, um, a before we get into the merits of the thing, is it just, from my perspective at least, it looks like the government's getting savvier about how to run these kind of initiatives and they're getting better at all of this stuff.
I do remember being at an, an event went out a couple years ago and, you know, they couldn't even spell cryptocurrency back then. The important thing to remember in security is the criminals are stupid. Right.
You know, and this is, we have this Hollywood idea of these masterminds, you know, these criminal masterminds who are gonna haul out volcanoes somewhere, one step ahead of the law. But they're mostly just lucky one that in, uh, the late eighties in South Carolina, I worked for a New York Mafia money laundering organization, a whole other story. But we look around and we see people getting away with primes and Not knowingly, Not knowingly.
I was just a, That's important to say, I was Going back rock right now. It's a, it's a different, uh, thread, but you can see people breathing laws and getting away with it. You think they're really smart and they're just not as law enforcement is hard.
Governance is hard, right? But, you know, you change the, change the play route and you say, yeah, the government is getting smarter about these sorts of things. This great movie, uh, everybody wants to watch The Hitman.
And it just came out last year. It's a based on true story. If you have, we all have this idea that you get really angry at someone, 'em to go to a CD border of town, you'll get a higher hitman.
Those don't actually exist in the real world outside of movies. And it turns out pretty well, you know, uh, I'll just say a hundred percent of the time when you make that beating and you're in the, the CD spot beating with someone, it's a police officer, because that happens all the time. Right?
So these sort of scams, yeah, you can get away crypto those scams and off and dumps all these sort things for a while because 1 1 4 hasn't caught up with you, but it's not a good plan. So if you ask I somebody, if, if they painted houses, they're gonna tell you what color, right? Yeah, I was gonna say that.
I, he obviously did not grow up in New York, Mike. No. Well, It, it can work.
You, you bad activities can work for a while. You know, my favorite, uh, No, you know. Yeah, No, I mean, well the, the truth of the matter in New York is somewhat closer to Chris's reality where they're not all cops, but they're informers for cops and they will turn you in.
Yeah. No, You know, You know this, this whole story, um, you could kind of take crypto and replace it with a different word, whether it's stocks or, uh, land values or contract value. It, it's inflating things, uh, you know, falsely inflating them, uh, to basically scam money, right?
The, the, you know, the, the, the scam du jo is, yeah, exactly. I was in Austin last week in a, in a repute hotel. An AC hotel, which is a Marriott Bonvoy hotel.
And I, I happened to pass the ATM machine, you know, the obligatory ATM machine that you get in a hotel. And, and the blue screen there said, you know, we dispense Bitcoin. And I'm like, who the, why would someone be buying Bitcoin at an ATM?
So I asked some of the people I was with there, I said, yeah, do you know this ATM dispenses Bitcoin? And evidently that's the preferred currency for drug dealers. So you, well, what do you do?
Get a piece of coin? Do you they some sort of QR code and I take it to my local drug drug deal and knock on the hub cap and say, gimme a hit. And, and what do I give them?
You know what I mean? Or do I click phones with them? Like, how does an at TM dispense b?
And okay, I'm ignorant and I'm old now, but has anyone ever gotten Bitcoin out of an ATM? No, haven't none that, Not yet. The only reason to do it might be to pay off some ransomware, dude, somewhere.
I don't know, Maybe ransomware and the drugs. I think cryptocurrency has gone through its phase too. If everybody used to talk about it was the AI of its time, right?
And I feel like it's, uh, you know, I think most people have decided maybe it's not, you know, the big moneymaking new world that we had thought about Down here in Miami. It was crazy, right? Because we, that was like the crypto capital and you know, the, the, the arena where the play was like crypto carina or whatever act it was, Yeah.
Tons of money being invested into it. It's just insanity. And then, Alright.
And yet this has become a political discussion, right? We have Elon Musk and some of the crypto bros are upset with the government for not, uh, being more active about driving cryptocurrency. And so now they're supporting Trump.
Maybe he should put $80 million into buying the candidate of his choice. Well, I think he's buying the, I think he's buying a cabinet seat of his choice is what he's buying, no doubt. And it'll be transportation or who knows, maybe, uh, maybe the treasury.
But you know, there's another thing on this similar topic. Uh, Steve Taylor, uh, was talking about it, that the Treasury Department used AI to recover a billion dollars in check fraud schemes. Um, they didn't get in into detail of what they did, but they did say they were gonna share their, uh, their learning with other departments.
But, you know, I'm, I'm always, you know, kind of Debbie Downer when it comes to ai, unless it, it's an area that it works well. And I believe this was machine learning and doing pattern matching on, on, um, check drafts or check fraud schemes. So whatever we can use for however we can apply AI to catch the bad guys, I'm all for it.
So I, I saw, you know, so here at Boca where I live, um, Lexus Nexis bought, um, I forgot the name of the company that this guy Sam had started. But anyway, the, um, the Lexus Ne Nexus fraud solutions are here. And they once brought me in and gave me some demos of kinda stuff.
They, and they work in partnership with the IRS and other federal agencies. And yes, they do do machine ai, right? Machine learning to spot trends, right?
They, they look at real estate transactions and they, you know, by looking matching real estate and transactions in the neighborhood to people, they'll, they'll spot crime gangs and, and all kinds of, you know, tax frauds. And, and I mean, it's, it, it is pretty sophisticated. Am I, am, am am I the LA one who's scratching his head a little bit going.
So the Department of Justice Justice that is, is spending time and effort protecting the integrity of a digital currency used primarily by drug dealers and ransomware perpetrators. I mean, I guess it's a something to be done, but I'm just wondering, you know, there's like only maybe a hundred things you can do, and is this really gonna make the list? I don't know.
I don't think those are the people getting ripped off, Mike, I'm guessing, I don't know, I don't have the data, but I would guess it's the, the mom and pop, the, you, you know, grow family wealth. There's your chance to do that through crypto. All this, all the, you know, kind of push to, to get people to move into crypto, I would guess is more the uninformed public rather than the, you know.
Yeah. Crime syndicate. You know, I, I've gone through many booms and busts in my life as I'm sure most of you have.
And, and there comes a point where you realize you're in, right? I, I remember, I remember I was still living up in New York and I was in New Jersey getting gas and you know, you can't pump your own gas in Jersey, right? The guy gotta come out and pump it for you.
com stocks to buy in like 2000. And I said to myself, when kid in the gas station is, is day trading time to sell? It wasn't much longer before that.
And then around 2007, I'm sitting in an airport and I see these two guys that were just like plumbers, frankly. I, you know, I mean jeans and I mean, not, not to there's anything wrong with plumbers or anything, but they're sitting there talking about how they were buying and flipping three family homes in the real estate boom. I said, type to get out of the real estate.
It's the same thing. I know, I know family members who were trading in Bitcoin and other cryptocurrencies because they heard of a friend of, a friend of a friend's uncle's, brother-in-Law who made a ton of money on it. And so they all opened up these, these crypto trading accounts and at least three of 'em in my wife's family.
'cause I, I like to think my family's a little smarter though. Look, no, no offense to any family members watching at least three of had their accounts hack and stolen and they lost everything. 'cause they're not in short accounts.
You must be on the third floor at your house. Well, within distance I got the door closed And Allen now is a great, a great description of machine learning and pattern matching, right? Yeah, absolutely.
Alright. Yes, that's exactly what you just did. Um, Mike, do we have anything else before I wind up divorced here?
No, but apparently I'm willing to bet that those family members know where there is a ATM that dispen of the Bitcoin. Go figure. All right.
Hey, this has been a great conversation, everyone. I appreciate it. What a great, what a great way to start the week.
Uh, we will be back all week with more text on gang and I guys imagine as we get closer to the election, it'll get more and more zany. Um, but we also have a full day of text TV for you today too. So stay tuned for that.
Immediately following this. Tracy. Chris, I can't wait to see you up here on in the boats in Florida, Mitchell.
I, I actually, I'm gonna see both Mike and Mitchell Cube Con's in a couple weeks now. Within a month. Yeah.
So really excited about that. Um, until then though, this is our Tracy will be a c**n too, right? Tracy C**n?
Tracy? No, no, I'm Not going. Oh, okay.
I don't like going to those big ones. I like small conferences. Okay, well you're gonna miss a lot in Salt Lake City.
Okay. Um, I probably hide in my hotel room most of the time. It's like, ah, I didn't do that.
You know, I have to tell you, Aon like Salt Lake City, um, There's just not enough women attending q om for me to go. Okay. Sorry.
I'm just being honest. I gotcha. All right.
Hey, so I think we'll call it a wrap. This is Alex Schmo for Textron. We hope you've enjoyed this Textron gang.
Stay tuned for Text Trunk tv. Everyone. Have a great day.