Techstrong Gang – September 23, 2024
Join the gang on today’s discussions, including “putting the bomb in SBOM,” and how it could forever change supply chains. Next, the FTC said what many of us have been thinking all these years — large social media and streaming providers have been eavesdropping on us.
Finally, we tackle the pressing question: When does the risk of AI security become too much? Mitch Ashley, Tracy Ragan and Chris Blask join Alan Shimel to explore these timely and important topics.
Transcript
Hey, everyone. Happy Monday and what a Monday it is. We've got a great show lined up for you.
We're gonna put the bomb in SBO around supply chains. We're gonna talk, have you ever felt that you were being watched, well, maybe you were with, by those streaming and tech companies and just what level of, of risk is acceptable in AI security? All that, and more you're watching Techstrong Gang.
Hi everyone, it's Alan Shimel for Techstrong Gang. Thanks for joining us on, on this lovely Monday. As I mentioned in the opening, we've got an amazing lineup of, uh, news and stories we wanna cover, and I got a great couple of gang members here to cover it with me.
Let me quickly introduce you to them. First of all, our resident SBO m security and life expert, right? I think he's still up in Canada today as far As we know, As far as we know.
My friend Chris Blas. Hey, Chris. Good to see you, man.
Thanks for joining us. Thanks for having me. Good to see you guys Absolutely joining us.
I think she's still in New Mexico. Um, yes. She looks like she shut the window, like now there we illuminated her.
It was like on cue, the one and the only Tracy Reagan. Hey, Tracy, how are you? I'm great.
It's raining and cloudy here today, so I don't have my normal, like feet angelic look with the sun shining In. Same here. Same here.
It's been raining and cloudy all week here, but we we're thrilled to have you joining us. Thank you. And our, our, uh, final gang member for today is text my partner, text Drug, CTO and Futurum, CTA, Mitch Ashley.
Hey, Mitchell, how are you? I think good, good. Thank you.
I think we've got the coasts covered and kind of good. Good. South the north.
We're doing pretty good here on the game. Okay. No, we're going northwest east.
Yeah. Altitude wise, we sure, sure do. Well, you are the highest person here, but we, you know, altitude, right?
Yes. Yeah, that's what I'm talking about. Um, anyway, let's jump right into it today.
So, look, last week was probably the most pivotal week ever in the, in the era of supply chain security. Now, normally we talk about software supply chains, and when we talk about SBOs, they're not the kinds that explode. But last week was a, I don't want to call it a red letter day, but it was a a day that will go, or a week that will go down in history for the ultimate.
So to this point, supply chain attacks. Chris, I'm gonna ask you to comment on it, but before we do, look, it's easy to be kind of glib about this and talk about SBOs and bombs and supply chain attacks, and, but I, I don't wanna lose sight or belittle the fact that a lot of people died. A lot of people got hurt, and not all of them were terrorists, and not all of them were Hezbollah members.
They were children and, and other stuff. And, and so no matter what we say here, I I don't want us to lose sight of the human cost of this supply chain attack. But that being said, Chris, what's your take on this?
Well, you know, I like to look at things over time, right? And so this whole supply chain thing for me really began in October of 2018. I can nail it down to a particular conference, cyber senate.
You know, the great James Nebu, uh, uh, puts us on, I was chairing this thing, and we had a panel on supply chain. And someone, you know, about halfway through it, someone said, to be clear, there is no supply chain security. Nobody can tell you what's inside anything with any level of authority that any of us as security professionals would accept for any purpose whatsoever, right?
In early in 2019, stomping around Guyana with Tim, with the great Tim Roxy, um, helping them with, uh, an infrastructure attack and had to say, he was like, there is no, there's nothing anybody can tell you about what's inside anything. So that set me on my, uh, bill of materials when we say bomb in this contact, that's a bill of materials, which is a ancient way of saying, and I'm selling you something. And inside this boxes create this hay wagon, whatever it is, X, Y, Z as as agreed.
io, the digital bill of materials, uh, Medi and Azar, and I dreamed that up in, uh, uh, were both at Unisys at the time. It's now an open source project. So my, my biases are clear, go out there and play with that if you like, but the need to be able to say, you know, to the appropriate level, right?
You know, I'm putting this in space, or I'm put using it in a military application, or it's for critical infrastructure. Who touched it? What's in it?
Where's it been? What's happening, right? We have a lot of historic ability to do this, but we've gotten ahead of ourselves.
And, you know, the, the events, as you say, you know, any nation state, you know, any military conflict, global conflict, uh, environment, this happens. So where can we find any hope in this, you know, whatever your opinion, we all want to know, uh, to the, to this extreme case, you know, that the physical stuff we're using is safe. Um, but we see the software bill of materials, as you said, you know, the software bill of materials efforts since about that time, 20 18, 20 19 has gotten pretty advanced right now.
And the Department of Homeland Security, the CSA working groups, you know, we're working through how do we tie all these things together from the producer, through the distributor, through the consumer, you know, so that we can track the software. And I think, you know, without going too long on this one, as we can do that, then we can answer these sort of risks as well. You know, we need to, and, and it's not just for, for security.
We functionally, logistically need to have these automated automateable systems in place where we can track where we put things. Well, my, my thought is, and I'll throw it out to the whole panel, is last week, the boundary that right where the, the era of no supply chain security has to end, because that is, this is the, the nine 11 moment, or I don't want to elevate it to that, maybe or Pearl Harbor, but you know, this is, this is the day the world changed. This is the week the world changed when we look at supply chain security, right?
And, and things will never be the same, Right? And, and, and again, as you say, you know, to be clear, this is a real human tragedy story, right? You know, lots of people have been hurt.
Doesn't matter where you decide you're on, that's not a good thing. Um, however, it's forcing us forward. And we see, You know, just from my own myopic perspective right now, um, I and Phil Engler at the, he at the Healthcare ISAC Information Sharing Analysis Center are leading a tiger team under DHS looking at how a distributor handles this SBO m information.
I'm not creating it, I'm not consuming it, but I'm one of these perhaps infinite links in the middle. And how can we maintain the integrity and all the appropriate attributes so that we can pass down this critical information so that someone, you know, uh, who's got a medical device in a hospital scenario, for example, can be appropriately comfortable with that device is reliable. They know who's touching and what's in it.
So this, and to this point to sort of literally, you know, last week in some, uh, some extent this has been even in the supply chain community, a bit of an esoteric conversation. Like really the suppliers and consumers who, you know, how do we ever gonna, you know, deal with an actual entire supply chain? Well, as we discover in Lebanon, unless you do that, at some point, we will not be able to have nice things.
So we're just now getting to the point to be able to have these conversations and enunciate the structures that if you've find yourself in the middle, what do you need to do so that, you know, during, again, in this case, um, I don't know if it made it clear yet, was it, did this happen during manufacturing? Did it happen during shipment? But since It's, oh, it's been, it's been clear ev evidently what happened here, this might have started in 2018.
It actually probably started in 2022. Um, if you believe it was Israel, let's assume that for a second, though. I don't have proof of that, but it obviously points to this, uh, Mossad or whoever set up a front company based in Budapest, Hungary that licensed the brand name of these beepers from a company in Taiwan.
A reputable, well-known beeper pro producer in Taiwan. They licensed the name to what they thought was a legitimate company. And this company has been producing beepers, not just the ones that got to Hezbollah, but you know, these models for the last two plus years, and evidently any that weren't destined for Lebanon, did not have the special bill of materials in there.
And, um, the walkie talkies that exploded were labeled for a Japanese company that stopped making that model of walkie talkie over 10 years ago and had that, that model name, that moniker has been pirated many times around the world. You can buy it, and it's actually made from a, a wide range of manufacturers. So this wasn't a fly by night, let's do it yesterday to start today.
This was well thought out from 2022 at least. And then the real question is, how did they get Hezbollah to buy them? Did they, and that's a question, did they bribe a Hezbollah, uh, procurement officer to buy these beepers?
Did they have a, you know, a swar, the Lebanese sales guy that they hired to sold to Hezbollah, did some, would get paid off for Hezbollah to buy these? Or was it just pure coincidence, or not, not coincidence, but just good salesmanship to get, you know, they, they gave them a really good price that they couldn't, uh, you, You talk about this, Allen being kind of one of those, i, I don't know the word you use, but a seminal event, right? Where things changed because of this happening.
Uhhuh, It, it, it reminds me, we've talked about this of, um, some of the ways that, um, uh, bad software can get into open source, right? Through kind of infiltrating projects. It's one of the, it's in the category of, well, we thought this was possible.
I mean, it's, you know, we've, we've imagined a scenario like this before. Matter of fact, there's tons of movies about how many mission impossibles or, you know, born Adventures or whatever out are out there that have some variation of something like this. But we never imagined somebody would actually either try it or could pull it off.
And this proves, yeah, it's actually possible. If you're, if you are good enough, you can pull off something. This, this is a complicated thing, you know?
No, this is A great movie. There's no doubt. An This is an EPT advanced persistent threat, right?
It is one of those slow and slow, and it comes over time, and by the time it hits. And, and I think it's, it's also a metaphor for software. I mean, it's, that's what ransomware is.
I mean, that's what embedding things in Solar Winds was, it's getting it into the supply chain. So I, I'm hopeful. And Chris, I'm curious too, and, uh, Tracy, you know, what lessons can we learn about this from a software supply chain perspective?
Uh, we're still understanding what happened, right? But Yeah, we're so many Go, Tracy, I picked that one up for you really nicely. Yeah.
Well, you know, as Alan pointed out, and I didn't know this, this is a learning experience for me on this call today, is that this may have taken years and years and years of planning for them. Um, if we think about some of the more recent, um, software supply chain hacks, uh, one of them was, uh, at the lyker, uh, happened back, I believe in April. I can't remember now what it was called.
There's been so many since. But that was a long-term, uh, project, uh, that, uh, that particular contributor that he worked to build trust, his pull requests were being accepted before he ever introduced a, um, nefarious piece of code. So I believe what we can learn from this is that we have adversaries who are always looking at ways to attack always.
And in the software, uh, world, it's probably easier right now than even getting an analog tool to become a bomb, honestly, because we have such a massive, complex system of shared components and open source, uh, code that is used in highly critical and sensitive areas that we have some real work to do ahead of us. And as I will say, out almost every call, uh, our pipelines are too complex, even to build in something as simple as scanning for an sbo. So how do we, how do we catch up?
How do we put the focus back on security and not get so excited about AI all the time? I don't know. But we do have to remember that most of these security problems in the software world, were not baked up yesterday.
They, they've been, they've been working on it for a while. And, and I think that y all three of you have touched, and I think that really marks the transition, right? You know, as, as we all have noted this is a complex nation state attack.
It took a lot of work and make a great movie. Um, and as we move forward from this, that'll become lessons less. So, the case, you know, this took a lot of resources, a lot of time.
It still does. And I wanna say this one on the, on the air, 'cause I'm sure we're hearing from friends and family, don't worry about your devices. Your phone is not a, a risk, you know, this, it took a lot of effort.
But 10 and 20 years from now, if we haven't put better, uh, custody chain of custody in place, then maybe you should start working about it, worrying about it, because it will get out of the nation state world into the, you know, backyard hacker world. But, but, and I, go ahead, chase. I wanna point something out too.
Let's just think about, um, security at the DOE level. Let's just assume that somebody hacks our, our, our grid infrastructure. Let's just look at one state.
What they went through when their infrastructure went down in February of 2021, I believe it was when the, when Texas had a massive storm that took out a good por portion of their electrical grid. There were 700 people who died. Four and a half million people were impacted by that.
That is a much bigger bomb than what, what Lebanon just went through. So it, it is a, it is a real and serious and catastrophic, potentially a catastrophic, catastrophic problem if we're not being diligent about it. And I don't believe we are.
No. And, and Chris, to your point, how do we know, how do we know our phones are safe? How do we know that there's not a back door that the Chinese can listen in on because they're manufactured there?
You know, when Mitchell and I were selling software to the DOD 15, 20 years ago, it was sort of an unwritten rule that they didn't buy checkpoint software. 'cause the rumor was Mossad had a back door into the checkpoint firewalls that would allow them access. And so though it wasn't officially on any paper, it was a real hard thing for them for sale.
I wouldn't wanna be a checkpoint salesperson selling to the feds back then. Stuff like this kind of makes you think, well, maybe they weren't wrong, but, you know, how do we know Chris? Well, I'll, I'll take an unusual for me stance, and I'll start at the dark side.
And, because the short answer is you don't, you know, there is, you know, I mentioned those, those cases my recent past. And if this really matters to you, you have to face the fact that you don't know and build your world around that. And maybe that's okay.
Maybe you can build a, a protective process that assumes that you don't know what's in anything. Um, but that only goes so far, which is why I think we're on this particular curve. You know, there is a future and not distant future where if this persists, we can't keep the lights on, right?
So we will either have developed the solution for this by then or not. And I had mentioned the, the dbo, because dbo is too early for IT time. We'll see if that sort of thing works.
But it's something I'm pitching kind all the time. We need an open attestation ecosystem, like SMTP for email right now, no company can make, this is why we open source the DEB bomb, but where appropriate attestations can be put in electronic format, so that if I, for example, have a device, like a pager or a phone and I own it, or I'm the IT administrator or whatever my role is, I can right now see every attestation from every party that's, that's had a, a hand in that. And even that will never be infinite.
And in this case, it wouldn't have helped much because I, I, I caveated at the beginning, 'cause I'm not sure on this, but I, I think you're right about the manufacturer. I think it was a second battery, in which case they would say, yeah, it was us. So you would know all along it was them.
It's just a bad them, you know? And so you would still suffer the attack, but you could go back and say, our, our, our process of vetting our suppliers and their supply chains need work, needs work. Well, so today you can't tell frankly, No.
But, but this is, you know, this could wind up being a huge push, you know, for the, the chip act and the make it here in America, manufacturing in America thing, because it, it could undermine the entire global supply chain economy where, crap, I'm not buying nothing, not made right here with real Americans on it or, or Canadians. 'cause we trust the Canadians, right? Um, you know, and that's it.
I'm not, and if I buy something in Taiwan, I bet I damn sure make clear that that's the company that made in order that they license it out to someone else. You know, what the heck with it? I'd rather buy something made in America and, and it's going to, does it increase that isolationism of I'm not, I don't trust them.
I don't trust, trust That, you know, the only reason I'm so paranoid is 'cause they're out to get me. Right? Well, and yeah, Well, there Isn't that as well.
And I know what you're talking about. You're just described zero trust policies, right? Yep.
That's, that's, It lends itself to software too. I don't want my stuff hosted over there. And you say order ghosted right Here in America's.
And what you're doing in that process is you're coming up with data points to determine if you should trust a particular provider. And what we don't have in software are good data points. Um, that's why SBOs are so important, because the data points are absolutely critical to be able to have that zero trust policy.
So I think that there's, there should be a, we should have more discussions about what a zero trust policy is, how it works, where the data comes from, and can ai, even though I'm not a, you know, everybody, I, I'm always boo booing ai, maybe this is an area where AI could help us, because it's pattern matching, right? What you were doing, Alan, is pattern matching. Where did it come from?
Where, who was the manufacturer? That is what, that's a perfect example of how AI could help and it could potentially help in every industry. It doesn't have to be just software.
Now, the, the reaction to this kind of a supply chain attack is probably something like, let's pull in the, you know, tighten things up, who our suppliers are, make sure they're doing what we think they're doing, what controls do they have in place, you know, you simplify things, you narrow it down, and like, how do we make sure that it's not one of these false companies set up again or whatever. So you kind of pull in, pull in the reigns a bit. Do we, do we need such an event in, in the software world where we're gonna do that?
We're gonna like, well, wait a minute. Maybe you don't use every open source piece of software that we're using. Maybe do we really need that?
Maybe we don't need three of these vendors. Let's get this down to one that we really know we can trust. It seems like we almost need, not that I'm hoping we have this, but what would get us to change that behavior?
There's the let's create SBOs about things and know what's in it. There's also the, well, let's reduce the possibility of having and, and put in the controls so we don't have it happen also. But I, I mean, what's it gonna take?
I don't know. I don't think this is gonna gonna be that event. I, I think this gonna have profound impact.
But anyway, guys, we could talk about this literally all day, let alone all show. But we can't, we've got a lot more to come. Let's take a break right here.
We're gonna come back and talk about who's listening it. You're watching Textron Gang. In a world where every line of code powers the future, every keystroke can introduce new threats As software evolves, so must security, it's time to rethink how we protect our digital world.
Join the leaders in DevSecOps and AI at the OpenText DevSecOps Virtual Summit on September 24th. Discover how innovation is transforming software delivery faster, more secure and smarter from AI driven security to the truth behind cloud security. Get the insights that will keep you ahead of the curve.
Don't just watch the future unfold. Be part of it. Register now and secure your place in tomorrow's world.
I know it's happened to you, right? You talk to someone about something, a particular object, a movie or something. You go on your Facebook and there it is.
Someone's trying to sell you something that you just spoke about. And you said, I know they're listening. Whether it's Facebook or Alexa or one of the streaming giants, any of the tech companies, we've all suspected it.
Well, now it seems the FTC themselves are calling out some of the streaming giants, uh, and conspiracy theory, I don't know. But there's this been, this vast surveillance, uh, program underway. They, they're alleging, perhaps, but Mitch, I'm gonna throw it over to you.
What do you, what do you say here? It goes back to the telephone companies listening in, you know? Yeah.
Before you even had cell phones and all that. Well, yeah, they're, when they have a court order. But here we're talking about, you know, social media companies, streamers, things like that, really paying attention to what you're doing.
I remember when I worked on one of the first video in demand services, we had a big debate about capturing the key clicks of everything a user did on the remote. Well, there are lots of good reasons why we would wanna know that. Well, there's some reasons why they may not want us to keep that.
Or if we sold it to somebody, and it was a real dilemma. We, you know, we, we kept it, but we put some controls in place. I don't know, whatever happened with it.
It's probably now being sold to, to you, to you, whatever you use for social media. Some Hungarian company making beepers. Making beepers.
Heck no. Oh my God. So I mean, this and it, and it's a real thing.
Uh, uh, just to give you a real example, uh, it's just in the news here recently in Colorado, uh, they, they have reduced auto theft, uh, people stealing cars from your driveway or whatever, by 30% in the last year, a drop of 30% in one year. And it's because they, they started using the, um, cameras that capture your license plate number, you know, to tell if you're out of date or whatever on your registration. And they used that to track down, um, stolen cars.
Good thing, good outcome. But there's been a backlash of that, of, well, yeah. But if you know that, then, you know, where I went this weekend, you know, the five trips I took to my, you know, whoever friends I shouldn't be visiting or whatever it might be.
What are you doing with this data? How long are you keeping? It's caused this big uproar.
And, you know, unlike a, um, social media service where we all sign those rights away in the eula, you know, that's a government thing. It'll, it'll work out however it works out. But we've given those rights away in most cases.
And this report's all about that. So, is there re regulation that the federal government needs to step in to put some controls in place? We, we all know we're not fans of, of those kinds of things, but it happens too.
Curious, curious. Um, you're, you're, you've worked in, um, software, I don't know if you've worked in, in government kind of situations, but Tracy, have you ever had that dilemma of like, well, do we keep this data, is this data we really should retain? Um, mean what would happen if it got into the wrong hands or some entrepreneurial business person at our company decided to sell it?
Sorry, I've, my, my, the upload just, just started happening and I didn't hear the question. Oh. Have you ever been in that position where you, you might be collecting data in your software that, Hmm.
Maybe. Or should we be doing this and what could happen if it got into the hands of somebody we didn't want to have it? Absolutely.
Um, you know, right now, that's, uh, something that we discuss often. Um, because what Deploy Hub is doing is we're gathering SOM information. We're, we're versioning it, and we're constantly scanning the vulnerabilities associated to it so people know if they have a, a VA new vulnerability running in production.
So we are now aligning vulnerabilities to SBOs. And is that a problem? It could be.
'cause it makes it easier for somebody to do something bad, but it also makes it a lot easier for people who are trying to do good things to fix the problem. So there is a balance that you have to, uh, kinda weigh out what is the risk, and do we collect the data, and how do we protect it? Chris, you've done it.
What do you think? Well, I, I, I think this is directly related to the last topic, and Tracy just touched on that. Right?
You know, in, in the same way, as I said, we need an attestation ecosystem somewhere out there for lots of reasons. Supply chain is one of them. This, this is another one, because just like, I can't really entrust, you know, the attestations that I'm working with, somebody says, Hey, we made you a pager, or Hey, you know, we made the software.
Did you really, you know, if it was important, if this is life or death, or I'm going to court, would I trust what I received from you? And as I've looked through my entire career at processes, you know, intellectual property always comes up, you know, corporations get really nervous about intellectual property in a lot of situations. And you say, well, what are your productions now?
And they mostly non-existent, you know, hope and faith that your employees kind of understood the contracts that they never saw, that you wrote with the partners that they had to work with on a daily basis. So I think this particular issue is, is one of these that have been building pressure so much. And like you say, we all know it.
You know, those of us on the screen here, we know this technology really well. And I have no trust that I have any visibility into where my personal data is of who touched it or the ability to get It. Well, what's watching you at any, you know, who's tracking you, right?
Right. However, I think that this, this a amount of both the social, you know, the general aggregate population level desire to have that visibility and instances like we're talking about insecurity all the time. And, you know, again, the physical security with, uh, uh, incidents, uh, over the last week in the Middle East cybersecurity, we need to have structures and processes that allow us to have appropriate trustworthy visibility into how our personal information is handled.
And I think to actually have that, we also need to have the right laws and policies. And like you say, Mitch, hopefully not regulations too much, but we need to have a structure that says, if I'm going to be company A doing thing b, I will have process C in place so that as I collect customer data, and I will always, by definition is handled properly, that handling properly thing is not necessary. Right?
Now, of course, this Report coming out, you know, from a government agency is listed, you know, with a whole bunch of recommendations about Congress should pass comprehensive federal policy legislation to limits surveillance control, what you're collecting should, companies should have to report that they should have policies in place, la la la la. So I don't know if any of those things will happen, but, you know, we could, there are already, um, policies I'm aware of. Um, there's one called, um, term PRI privacy protection.
I think it's Copa is the name of it, but it hasn't gone anywhere. It's about teens over the age of 13 protecting teenagers. Anyway, there, there, there Has been, I so look, we could have the government in install these rules, which will take some sort of willpower on behalf of the government, their prospective purchase, and come together and do something.
Well, my dad would say author Batards. Yeah. And that not, not, not in this particular iteration, or, you know, the public themselves can pressure these companies that we are fed up, dammit.
And we're not gonna take it anymore. And, and so in that rain, I, I recently saw, I think it was, might have been better with Instagram, put in some, some rules, or maybe it was Apple, about teenagers and screen time and, and stuff like that. And, and maybe we, we can do some of that, right?
I, but here's my point. Even if it's the social media listening in and, and though they, you know, when I knew the whole thing was full of crap when Amazon started, when they started selling the camera covers for Alexa, if they, if they weren't listening or watching, they wouldn't have sold the camera cover. But anyway, what's the difference between watching me, what I'm doing, and what products I, I may have on my kitchen table versus tracking every one of my moves across multiple different websites to see what my, what my digital footprint is, what I search for, particularly on Google.
And Google owns my search history and you and sells that. These are all different facets of the same right. To privacy.
Now, our Supreme Court says we don't really have a right to privacy. That was one of the reasons behind Roe v. Wade, right?
ROE was a privacy, uh, uh, case. And so I don't, I don't look to the courts or the government to help us on this. I think if it's, when people get fed up at where they're gonna shout out the window, like in the movie network that they're fed up and they're not gonna take it anymore, is when we'll start seeing people pushing back on this and, and the tech industry people saying, Hey, I think we got a problem here in Houston And we are a global community, right?
So they, I think that what, what, what's occurred, I believe is that, um, from the perspective of the United States government, uh, we have given over those regulations to the European Union, they have started defining those. Um, they've already started defining, you know, privacy practices and policies. And because we're a global community, the companies in the US have to comply with those EU requirements.
So unfortunately we Or not not do business in those countries or Not do business in those countries, which no companies crisis crazy enough to say, I'm going to, uh, ignore most of the, you know, most of Europe. So what we end up with is the United States not being a leader in this area any longer, which is a kind of a crime because we should be at the table, we should be making, helping make those decisions and be part of the conversation. But we've been taken out of it.
I mean, everything that we were look to is to, we look at the EU for everything we do and software in terms of regulations. I mean, I, I California, But to some degree, but yes, Eu, California tries absolutely, and you know, good for them. But I think it was on one of our gangs earlier this week or last week, Mitch, where wasn't it, is it Apple Intelligence is not gonna be available in the eu?
That's right. Yeah. Because of their recent, uh, they're going into effect the AA privacy regulation.
Yep. And, and so Apple intelligence is only available on phones here in the us, not in the eu. So that's a case where a company and a big company made a conscious decision that I'm not gonna comply with their onerous regulatory policies.
And I'm not saying they are onerous. Well, The was percent of your annual revenue. So Yeah.
And then Who loses out there theoretically, right? The, the citizens, the consumers who don't have access to that technology now, it's crazy. Well, and, But, and these are all examples though, of those forcing functions, right?
You know, so as you, as you're saying right now, if you're not gonna do GDPR, then you can't sell sell in, uh, Europe. But if you're not regulated by that and you choose to do the book, I think all of us would see of the right thing, and your competitor doesn't, and it introduces costs, then you just go outta business anyways. Right?
You know, but I think this is seen that way at this point. And that's probably correct. You know, given everything we said, uh, so forth in this show, it would be unnaturally hard and expensive to do the right thing in a lot of these cases be because the companies and the monetization has sort of rushed ahead of the implementation.
Um, but, you know, either through economic pressures, customer pressures, you know, I, I like seeing when the technology and the processes we want just save you money, right? I think there's a lot of that in this, you know, maybe not today, but I think companies will continue to find year over year that it's better, faster, cheaper to manage the this information correctly. You know, you, because you're either gonna alienate your customer base or get fined or just spend more time responding to things, You know, it doesn't have to be pioneer either.
I'm not speaking for Apple, but you could imagine Apple might say, well, let's not go into the EU right now with ai, let others be the Guinea pigs. Get the 10% of your revenue punitive fines. Let them make the mistakes we'll learn in in our other markets, in US and other places.
And then go and then introduce our AI once kind of this ra the pave road has been paved a bit. That that would be an okay strategy too. Maybe there's some near term, you know, financial impact from that, but it's a lot better than 10% of your annual revenue.
Yeah. Be, be, could that, and that 10% of your annual revenue is the potential fines that the EU can for violations. That's what went into place is the enforcement and the ization.
So It's, it's a crazy thing. Good stuff. Alan.
We could go along forever on this one too. No, we can, but you know what, I, I'm sorry. I need to, we need to break here 'cause we otherwise people are gonna spend their whole Monday.
These people have work to do. Uh, well maybe you don't have work to do, but we're gonna take a break. You're watching techron.
Dang. We're coming back. What level of AI security risk is acceptable?
Stay tuned. Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hi everyone.
We're back here on Textron Gang. As I mentioned before the break, what level of AI security risk is acceptable? We've got a good article over on text drunk AI on this.
But, um, Tracy, look, you know, every new technology I've ever seen introduced, there's always been kind of ankle biters, knee biters, choke holds about, Hey, the security on this is too weak, we can't use it. What's your take? Well, I think we have to back up for a minute.
Um, you know, developers are being asked to do quite a bit, a lot actually. And more and more every day they learned, they now have to learn to use AI in their coding. How are they going to, you know, leverage those technologies?
How are they gonna be more productive? And we're asking them to add security just to pure coding, right? They don't even understand AI yet.
And now we're seeing that we have to now learn how to secure ai. And when we haven't even figured out how to put SBOs in our, uh, in our, our pipelines, we have, we have a real issue with, with this, we have a big issue with this. I mean, a, maybe AI becomes easier to exploit, you know, nefarious, uh, problems like data poisoning.
Such a, that that would be a simple way to, um, to really impact an AI application or bad examples. There are so many ways that they could attack these models. Now, um, one of the interesting things in that, uh, article, it's a great article, I highly recommend everybody read it, is there's a, a something called AI goat by this company called ORCA Security.
And they're making an attempt to teach us about how AI can be exploited. Now, do we have time to, to do those tutorials? I don't know.
And the Linux Foundation has several tutorials out there on just, uh, open source, uh, security issues and how to protect yourself from them. But we have to implement it. Upper management has to start thinking about adding more time for training for, for software developers.
So it, this is a long road. We have a long road to be able to start protecting ourselves against problems in AI when we haven't even approached it with problems in code. And probably the first place.
And the most important place to start is just, um, APIs. How are we going to secure AI APIs? And that is something that developers can get started with fairly quickly.
Uh, regardless of the testing, the AI testing tools that need to be added to the market, the security tools that need to be added to the market in order to start protecting ourselves with either regular software supply chain security issues or large language model attacks. There, this is a very big scope. We're, we're facing a lot of, of adversarial issues.
If we can make analog, um, you know, pieces of analog equip, but turn into bombs, we could do a whole lot with what we have in the software world. And it's a lot easier to get that stuff into the software world than it would be to change a supply chain of a beeper. So how do we, how do we start addressing it?
It's education. We have to start with educating developers, giving them more time in their schedules to take these courses. And I highly recommend, I'm gonna go play on AI goat.
I, when I saw that, I was like, oh, this is cool. So everybody go out and play on ai goat. That's my recommendation.
And upper management needs to really be thinking about this problem as an education issue and a training issue, and not leave it up to a developer to go figure it out themselves on their own time when they've already got plenty to do in their lives. So that's my take. This, This reminds me of Mo when we moved to the cloud, there were a lot of things that happened of leaving S3 buckets wide open, not disabling controls that you should not enable.
And in the orcas data from ORCA Security on this report, this article talks about 45% of Amazon SageMaker buckets are easily discoverable. 'cause they're not randomized bucket names. And 98% of organizations are using the service, have not disabled default route access.
You know, so, so even just the basic blocking and tackling, you know, it could be maybe this is happening out in the business unit and they don't have those kind of guardrails in place. Maybe it's a rush to go to market. Maybe it's just like, well, wait a minute.
Let's, let's kind of make sure we're doing this the right way. So it's, yeah, it's go, go. But it's also fundamentals, right?
We're making the same mistakes again, as well as the more sophisticated things that we need to make sure we lock down. Well, starting with a low hanging fruit, unsecured APIs, unsecured AI APIs, that is the, that's the lowest hanging fruit. That's the easiest way to get in.
We need to at least, if we could identify four developers, kind of the, the, the, the lowest hanging fruit for them to start addressing, I would say, um, a AI APIs, unsecured APIs is a problem across everything that we do. And that we have tools right now that can help us with that. Right?
And that takes me to my, you know, thinking about this topic before the show's, like, you know, we have, what is AI risk? I, you know, I think can think of three general categories, everything from Skynet, I'm not worried about that. That's not anywhere on the horizon, um, to problems with the AI itself, you know, having, you know, compromised AI and whatnot.
And I think what we're talking about here is the one that I was gonna bring up, which is just AI gives you the opportunity to, uh, um, perform your mistakes at scale and speed, right? So we already have these problems. You add AI to that.
Yeah. You may not have that one little problem. You may have one big problem all at once.
And there are ways, as Trace is saying, to actually get inside that oodle loop and do something about it. Yeah. The, the tweaking parameters, right?
In a, uh, in an LLM, um, we talked, I think it may have been last week or maybe the week before about, uh, reasoning that they're building into it. And I, I said the reasoning sounded like we were training a dog. And so, so is, if it's that simple, who's reasoning and how can, can the reasoning being manipulated with some tweaks of parameters?
And yes, it can, so the data poisoning is a really critical problem, but I don't think our developers right now have the ability to fix that. But they can learn, they can learn about what these issues could potentially be, and they can start securing their APIs. So, you know, I've said this before and I'll say it again.
It, it, this is a universal truth about security. We will have better AI security when companies customers demand better AI security. And until they do, we won't.
Because why should they? Right? Why, why should companies do that?
I mean, Aker and I, Avi and the GR team at a great team, and there's a great serving and, you know, AI go, you're talking about, I mean, they, they're a security company, of course, they want us to do, and they're doing AI security, and of course they want us to do that, but until the consumer, the customers say, Hey, we need better AI security, it's just that's, but they're not Gonna say that. What they're gonna say is, what I said last week, I don't trust ai. Yep.
And they, maybe we were talking About Salesforce RAG actually say that, and it hits someone in the pocketbook, right? And it Yeah. And it causes an action of not buying your service or Whatever.
Then, then watch how quick they do that. Yeah. So Salesforce isn't gonna get my business by offering me something that's gonna go out and talk, potentially talk to my potential customers through some kind of a robot chat.
Really? What is what it is? I I don't trust that, right?
I don't trust what that's gonna say and who it's gonna hit, who it's gonna talk to. I, and we talked about autonomous driving. Yeah, No, but Salesforce is a great company that listens to their customers, and they will get those little survey questions that say, do you like this?
Do you trust this? What can we do to make it better? Why aren't you using it?
And if enough people say that, Tracy, they'll do it. But if people say, I would just like to tweak this way or that way, but they don't mention that, that trust issue or, you know, trust is 12 in the top 10, then they won't. And, you know, this is, this is market capitalism at play here.
Interesting stuff. Anyway, trust. Yep.
What a way to end the Monday. We have got an amazing, we've got an amazing week of, of more to Chris, Tracy Mitchell, thanks for joining me on Gang Today. Hey, if you're watching this, hope you've enjoyed it as much as we've enjoyed doing it.
We, um, we've got a full text, drunk tv, uh, lineup following today's gang social show. Stay with us here on Text Drunk tv. Uh, you can always of course catch episodes of Text Drunk Gang on Text Drunk tv.
You can go back and watch past episodes. It's also available as a podcast on, uh, all your favorite podcast channels. So check it out there, Chris.
Speaking of podcast, your podcast is rocking and rolling. Yeah, the inevitability Curve. We got, uh, half a dozen or so episodes every week.
We're, uh, talking to an interesting person about where we've been, where are we, and maybe where we're going, or, you know, sometimes where we're not going, you know, and it's a, it's a fascinating conversation. Had, uh, Rakesh, uh, bia, uh, this week who's, uh, running, uh, uh, the digital cyber side of U-S-A-I-D, right on emergency response. So it's, uh, very cool.
I'm having fun, looking forward to more of it. And it'll be available on Textron TV as well. Also, just a quick snap announcement for Q4.
We're looking at launching OTT of Text Trunk TV so soon you'll be able to watch it on your favorite streaming. Uh, and, but I promise we won't be surveilling you. Um, but until tomorrow, then that's gonna be here for Text Drunk, uh, text Drunk Gang.
This is Alan Shimel. We're out.