Techstrong Gang – September 3, 2024
Mike, Jon and special guests Chris Blask and Tracy Ragan dive into the latest developments surrounding the CrowdStrike outage, including $60 million worth of credits being offered to customers.
Then, the gang shifts its focus to concerns about malware being implanted in drones manufactured in China. Finally, they evaluate the increasing efforts by governments to arrest cybercriminals through bounties that lead to their arrests.
Transcript
Hey everybody. I'm Mike Ard. Today we're talking about CrowdStrike pays the price.
Then we're gonna have a little chat about drone Wars involving China. And finally, we're gonna have a discussion about taking a bite outta cybercrime. You're watching Techstrong Gang.
All right, folks, as usual, we have a great lineup today. Joining us from the Valley is the infamous John Schwartz. Well-known all over the valley.
How you doing, John? I'm doing well, Mike. Thanks for, uh, pointing that out.
That man, And then of course, still north of the border is our resident cybersecurity expert, Chris Bla. Chris, how are you doing? Loving Life.
Good to see you guys. And Tracy Reagan, who is down in the desert somewhere running her company and is, uh, gonna lead us off on this next block here. 'cause we're gonna be talking about, well, there's a DevOps angle to this whole CrowdStrike thing apparently, but CrowdStrike announced that it is giving 60 million in credits to people for their trouble that they have caused during their recent outage.
And, uh, that's on top of, uh, $5 million in cost that they have acknowledged so far. Um, Tracy, what is your take on all of this? We've now have the benefit of some hindsight, and in this whole process, as somebody in the industry, and you look at all this, what would you be focused on?
Yeah, let's talk about CrowdStrike for a minute. Um, you know, and the last time we talked about CrowdStrike, I, question two really was responsible for this. Is it CrowdStrike?
Is it United? Is it, or I'm sorry, Delta, or is it, uh, Microsoft? But everybody has a part to play.
But yeah, you know, it's probably the best thing for CrowdStrike to do, to throw a little love back to the community to try to get back on good terms. But I do wanna point out that I think that we have a, um, we have an interesting shift recently and what investors are expecting. 4 million, um, uh, in the same quarter as last year, now they're at 47 million.
They're growing at a pretty fast rate. And I believe that we have a short memory and throwing some fund, uh, you know, credits to potential DevOps teams to get into the security conversation. They're gonna do just fine with that.
I don't believe for a minute that CrowdStrike's in any kind of a precarious situation. And while I do believe that there'll be a, a, an initial impact on their earnings over the course of maybe the next three months, I don't think our memory's that long. And people will be going back to CrowdStrike and be happy to have some, some free credits to start thinking about how to implement some of these tools.
So kudos to them. I'm sorry, they've gone through this. Companies like Delta should be looking at their own DevOps process to make sure that they have proper security practices themselves and who could update these low level objects.
So I'm not putting all the blame on CrowdStrike at to this day. I still don't blame them completely. John, what are you hearing in the Valley?
Because the 60 million in credits is one thing, but these lawsuits could be significantly more than 60 million in right costs. Right? You know, the, this is Tracy said, and I think we've talked about this before, and I'm gonna, I'm gonna, um, back up CrowdStrike a little bit.
They're, they're, they're, they're taking full responsibility and the consequences and the fall with two larger companies who happen to be their business partners, first off. And George Kurtz has gone out of his way to be as transparent as possible given the situation. And it's unfortunate.
You know, the one thing I want to mention, Mike, is that I've noticed in the last two quarters, especially this quarter, and I'm gonna give you an example of something that happens that was very strange yesterday to me, um, during the earnings process, there seems to be an unusual amount of angst around earnings this time around, and especially the impact of AI on a business. And yet the specter of California about to sign into law this, we're a very restrictive regulatory AI bill. I got a text message yesterday, as soon as Salesforce announced its results from Mark Benioff to show me how well they did be so sensitive about these things right now.
And, and the fact that CrowdStrike is going through this unfortunate incident on top of the general angst in the valley is, is a blow to their name for the short term. This company has a very good reputation. And I think the way they've handled this is a, is, is probably as well as you could, given the circumstances.
You know, most companies, I'll even go back to open ai, they have these incidents and they don't talk about it until they're pub, they're forced to do so, and in a sense they try to get ahead of it. But again, in the valley there is a lot of fright and, and, and angst and fear over how people interpret their AI related sales or their security in general. Chris, the audience that matters most here, of course is the cybersecurity folks.
Are they trusting in CrowdStrike or do they perceive that this is just some sort of foul up on the IT side of the world and it doesn't really have much to do with the security that CrowdStrike enables? I'm just gonna pile on to the CrowdStrike love fest for today, right? I think they've done a good job.
They're good folks. You know, they, they, you, we look back, yeah, and we're talking about the impact on market cap and, and revenue and so forth, the financial impact of a breach. And we look back on a lot of the, the famous or even less famous or infamous breaches, and we find that a lot of the companies, you know, recovered just fine financially even when they've been awful, even when it was their fault, right?
So CrowdStrike has done, I think they've done exactly the right things, you know, how much was their mistake, was their fault or whatnot. We're not really talking about that too much because they've stepped up and said, alright, we own this one, you know, we're gonna make it better and move on. And that's, until we get a much more perfect cybersecurity landscape, that's most of what anyone can do.
Well, let me follow up with that on you. Is it, how easy is it to switch out a CrowdStrike for something else? It seems to me that it's a significant lift.
So it's not like I'm gonna go down and, you know, rip and replace something in my pc. This is, it would take you months to swap them out for somebody else if you were so Inclined, right? You know?
Yeah. So, so security has a lot of, Has a lot of theatrics to it, right? And it's very emotional.
We feel very strongly about it. But as you say, pragmatically, you know, if I'm a large company and I'm using, you know, something, you know, that I've been using for a long time and it's embedded in my processes and the company makes a mistake or I don't like them, they're going through a bad spot. I have to weigh what does it really literally mean to stop this?
You know? So yeah, this, this was not the kind of egregious lack of structure and stability because you started with this, but trust, and I'll say yes, you know, the cybersecurity community continues to trust, trust, CrowdStrike, you know, a lot of us are there and they've behaved well and you know, you can't look, you can't take anything for granted. You, you certainly can't take your customers for granted.
But anybody who, you know, gets too hysterical suddenly saying that this happened, therefore, you know, infrastructure A is gonna be swapped out tomorrow. It's, it's just the dark side of over enthusiasm. It takes a long time to swap things out, even if they're better, faster, cheaper.
The architecture in which some of these tools are being, um, uh, deployed under, uh, really needs to be reviewed. The idea of adding additional agents to an already very crowded community of agents expands our, expands a stack which expands the attack surface overall. Not to mention a mistake, and as you said it, this is an emotional decision.
And somebody who's been in DevOps and production, um, updates for a very long time, I just felt really bad for them. Everybody makes a mistake. And that was a huge one, right?
It was a huge mistake. So I don't hate them because I've been there, you know, the and who they're selling to have been there. Yeah.
I mean, it, it is this, this mistake and the way they handled it gives them a pass in a certain sense until there's this another mistake, hopefully, which doesn't happen. But, you know, the interesting thing too is I think during earning season, I'm not sure Microsoft or Delta were asked much about the July 19th incident. Um, and one other thing that Kurt said that is kind of a little bit of cautionary thing that could hurt them temporarily is he, he mentioned that the incident was in the final two weeks of the quarter when a meaningful portion of their sales typically close.
So this is gonna delay those deals into subsequent quarters. So the vast majority of these deals are remitted in the pipeline. That's something that kind of spooks investors temporarily.
So they, again, they suffer the effects more so than the two other larger companies. Investors are spooked. Uh, Nvidia reported a 30 billion earnings and they complained about it.
Come on. I Know, you know, that's interesting. I'm glad you said That.
That's Ridiculous. I'm glad you said that, Tracy, because on Friday's show we talked about that the nitpicking, and I think the nitpicking was over. The operating margins were down 2% year over year, and there was a concern about the return on investment in its long-term impact.
Meanwhile, tuum does a, uh, an, uh, research paper where they find that 92% of the market belongs to Nvidia what they looked at. And since the report came out, it's up to 94%. So yeah, don't dumb weep or cry for Nvidia.
All right, Tracy, let me ask you a couple of questions about some things. You said. Well, first of all, do you think 60 million is gonna be enough for credits to handle this?
Or will they have to bump that number up as, 'cause I feel people who are thinking about a lawsuit are gonna sit there and try to negotiate for additional credits to go to the middle and not have the lawsuit. But so I'm wondering if 60 million's enough, what do you think? It doesn't sound like very much, right?
Um, it's a, it's more than their quarters earnings though. So in terms of their size, I think they're being extremely generous. Uh, I don't, you know, I don't know how many of their customers will take advantage of that and try to push for more, but that's pot, that's a potential problem for them.
Uh, but I don't think that's gonna happen. I really don't. Because if you're not Delta, if you're another one of their customers who are not impacted in the same way, you can say, well, we didn't have that problem because we had a better process for making updates into our environment.
Delta's gotta figure that one out. So I, I just, I think the 60 million is a, is is plenty. And I don't, I don't necessarily think a lot of their customers or future customers are gonna be pushing them for more.
Chris Tracy brought up the whole issue of agents, and we've been having this debate about agents versus agentless forever. Um, but the folks who, like agents believe that it gives them more control over the environment and that they're necessary. And a lot of other folks are saying to Tracy's point, it's just more overhead in the system and maybe we can rely more on agentless stuff.
What's your sense of where are we with all these agents? 'cause a lot of them belong to security teams, You know? Well, both points are correct.
Right? And this is, you know, in this whole incident, uh, and Tracy, I love the Delta reference to, is thinking about how do we work them into this? Because I'll just say it, their problems are their fault.
You know, they, you know, if you don't understand where we are in the evolution of technology and cybersecurity and so forth, and you're responsible for that at a big company like, I don't know, a a big airline, um, that's your issue. Because to your, to your question, yes, we need more insight from endpoints. There's a lot in, in supply chain.
You start to look at, you know, software bill materials and working from the vendor down through the distributors now in ISAC and into the consumers and the, at the consumer level, you have devices, medical devices, out, out the wazoo, all of which we don't know the actual state there. It, so anyway, so there's a million reasons that we need more information from endpoints. But at the same time, the observation is that this is a cluttered space and it's making, it is increasing fragility.
You know, to our kind of point, if you start putting more useful functions that you can't manage that are more pieces in the stack on too many endpoints, you have to think through the whole thing. So just throwing any technology at anything is not gonna work. And specifically at this point in time, you know what, I have been on the, the selling side of agents quite a lot in the last decade, and I have any number of cautionary messages.
Anybody wanting to push an agent out, no matter how wonderful it is, you have to understand where people are right now. You can't take another piece of code and throw it on a hundred thousand desktops or an entire service farm with the other 79 agents who are there and get value out of it. Unless you understand how all this stuff is together and hardly leading one does, frankly, You know, Delta built its reputation, its brand name on, on its, uh, technology side, which always makes me kind of blanche with the way they've reacted.
You know, I, I'm not sure even Mike, do we know the status? I think Delta was threatening or murmuring about a lawsuit against CrowdStrike or taking legal action. Yeah, I'm not sure if that was a PR move or if they really intend to.
And that's why I was asking about the credits. 'cause CrowdStrike was saying that they were quote unquote willing to negotiate, which in my mind means more credits. But Tracy, let me ask you this.
Plain and simple, and it's a DevOps related question, but all of this is one giant misadventure in patching. What makes patching hard? Why is it so difficult?
What is the, what is the thing that seems to keep tripping us up? Well, I don't know the exact details of the CrowdStrike and why everything had to be rebooted. I assume it was something pulled into memory or something had to be re reloaded at, um, you know, at, at at start time.
But we have a, I just, we, we've, we've gone backwards in DevOps. And the reason why is because of these very complex, you know, high performance computing systems that are decoupled, whether it's running across tons of VMs or, or thousands of containers. Our DevOps pipeline has not kept up with that technology.
It has not figured out how to, uh, do things in a more truly automated way and move off of scripts so we can start standardizing and really understanding what we're pushing across the pipeline, bring in more tools that allows us to start tracking that kind of automated configuration management data. There is so much to be talked about in the DevOps space right now that we're not talking about. 'cause we're so excited about AI and security.
And by the way, AI just has added a flood of new agents on top of what we're already trying to manage. So we have made a very complex environment and we're still trying to run our DevOps as if it's a monolithic experience. So until we have figured that out and until we start re uh, revamping and step back from our old DevOps practices and say, how can we do this better?
And everybody's in agreement that that's what's gonna have to happen. We're gonna struggle in DevOps. We're gonna struggle with patches.
We're gonna struggle with deployments. Alright, Chris, I see you nodding your head vigorously. So I'm gonna ask this last question to you.
A lot of the debate now seems to be about, well, should I automatically patch things or should I, you know, manually do it and test every little thing that goes on? And is that feasible? Are we kind of stuck in some sort of quandary here because there's too much that needs to be patched to stay current to make sure it's secure, but we don't have the facilities to make sure that each of the patches actually works as advertised?
Where are we? I, well, so it's a tactical question. You know, the question is, you know, where are we right now on this particular issue, right?
And my comment really is along the lines of, you know, what you need to understand is we iteratively go through these periods where we increase thing and to get more and more and more thing, and we get to the point to where we say we can't possibly ever hand a handle a more thing. So we need to plateau that out. And quite often, you know, that increase in thing is gonna go on maybe forever, right?
So we're gonna have to change the way we do things. So right now is, you know, to your question, are there too many patches to realistically manage the way you've done it in the past? Yeah.
Are there gonna be fewer in the future? No. Right?
So today you need, you know, and I'll, since I've picked on, uh, Delta in public today, let's just keep at it. You know, they made bad choices. They did not think through how to do this.
And if nobody there understood this issue that we're approaching certain limits, and in this case how we deal with patching, that should be of concern for large, complex organizations at the, and that 10 years from now, we're not going to be doing it the way we did it today, or 10 years ago. I'm sorry. Right?
That's, that's why they pay you the big bucks. You know, that job should have been done by the CISO or somebody in the executive suite. This is not the fault of the people on the ground.
It's, you know, you pay attention. Where are you in time? You know, this is not a long term strategy.
Strategy. The next long-term strategy I'm patching is being developed. Now, if it's really important to you, you need to put more resource into it and come up with your own solution.
'cause it can be different for everybody. All right, folks, you heard in here, Hey, there's much to be learned for all of us from this misadventure. And the most important thing I would say to remember is E, but the grace of God go you.
Because what happened to CrowdStrike could happen to any one of us. We'll be back in a minute. Discover Textron group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right, folks, we're back and we're talking about drones. And apparently the Congress is worried that some of the parts that are being used to build these drones might be infected with things like malware from the Chinese companies that are building them. John, you wrote a story about this on digital CXO.
Give us the highlights, if you would, of what's going on here and what are the ramifications? Well, there are, you know, few bipartisan issues in Congress, but there's one thing they can agree on. There's both the House and the Senate looking at bills that would ban reply a ban to Gj DJI, drones and their alleged DJI clone makers.
So in the house there's a, a bill from a New York congresswoman who's very conservative in the Senate. We have, um, Montana senator from a Democratic party who's somewhat conservative. They each introduced bills.
And basically on top of that, last week, Tuesday, uh, members of the house have been accusing not just DJI, but the US based clone maker on zoo robotics and Hong Kong based con cojito tech as being fronts for GJI and being used as quote part of a cons concerted effort. It's toward current and prospective restrictions on its operations imposed by the United States. So basically there's a lot of national security angst over the prevention of sensitive drone gathered information that is going to be going to China.
So that's the impetus behind this. And intro from a larger perspective, earlier this year, Biden signed into a law measure that would ban TikTok unless the, unless by dance Divests. And also the US has slapped a 25% tariff on Chinese drones.
And several states have already banned the drones from uh, DJI and Tel. So we have this whole EC going on it, it's developing, but it's something that both sides generally agree upon and something that bears watching because it's gonna have a huge impact on the market in general because this is a major manufacturer. When we talk about DJI in That, in that market, Chris, it seems to me this is a recurring issue.
We run into all kinds of equipment, whether it's home routers or whatever else that we're worried that somebody's inserting malware into, and they all seem to be manufactured somewhere in China. Um, how big an issue is this? Does it go beyond drones in your minds?
And, um, is this something of a national security concern? Uh, in short, yes. You know, this, this is a big problem.
And, and it's in fact, exactly this issue is what drove me down the whole supply chain line over the last five years. 'cause we effectively have no way of knowing what's inside of anything. What does that mean?
Well, you know, in, in this sort of thing, if I put my, when I'm thinking defensively, I would try to put myself in, in the, uh, attacker's shoes. If I was the attacker, would I do X, Y, Z? And if I was, in this case, for example, China and Chinese, you know, military and so forth, would I put code in drones and take, would I do things with TikTok data if I possibly could?
Yes, absolutely. And if I was an American manufacturer, I'd have to think about those same things. And we just have this, this space where we can produce products and get them distributed knowing that no one can tell us what's in anything.
And, you know, looking at this, uh, at this, uh, uh, item before the show, I you thinking of last RSA, uh, the, the show, the big security show in San Francisco last spring. And there was a very, very large vendor there that had a, a big presence. And I was doing my show floor walk and it, they weren't, not every hour of the show, but at certain points they were giving away drones.
You just, they just give you a drone. So I thought that was so cool. I got one, I played with it.
And I, you know, looking at that night and thinking how, what would, if I was a bad actor, what would I do with this? What would I potentially put software that I can gather the data and so forth from drones and get them, you know, into the hands of a vendor that might say, give them away at a concentration of US security executives. So these drones, they take 'em only flame around your house and so forth.
And some of that video goes back to an adversary. I do that. Why not?
So I went back to the vendor and I said, when you got these little marketing drones, you know, did anybody do a security assessment of 'em? And the entrance course is no. And I'm not saying the name of the company 'cause I'm not picking on them because the reality is there's not much you can do.
You know, you can have a drone or not have a drone. You can get this issue with DGI and tick TikTok as much as I'm against, you know, that sort of censorship. You know, what, by, you know, however, commercial censorship, censorship, I guess I, I'm on, I'm on board.
You know, this is a real risk. We need to do something with it. You know, if you want to be a Chinese drone drone manufacturer or an American drone manufacturer and sell across that international boundary, at some point you're gonna have to embrace software transparency so that people can look at your product and have some clue on whether or not it's loaded with spyware, literal spyware to the state, and they, and we can't do it.
So you basically can't trust these things from a nation state perspective. No, we have Cut, go ahead. I'm sorry.
I was gonna say we have, uh, we're at a point where capitalism and national security is colliding. This is true. In fact, I'll go there right now then John, um, and Tracy, but I am just old enough to remember, you know, Richard Nixon going to China and they all shook cans.
And Henry Kissinger stood up there and said, China would help save capitalism and we would have these huge markets for US goods. And they Were our ally against the Soviet Union at the time. Right.
And, and, and fast forward to today, and we seem to be looking at a situation where, and I'm not particularly xenophobic and I generally like free trade, but it seems like, um, this deal is a little one-sided at the moment, no matter how you look at it, John, I don't know, what are you hearing from folks in the valley? So, yeah, one thing that I wanted to mention was that DJI had a very aggressive blog post in their own defense, and they mentioned xenophobia and they also mentioned competitive, uh, pressures from the us. But the one thing that, that, I just wanna throw this out.
One, one other thing. They mentioned a couple of special features they were going to to, to add to the drones, to, to, to kind of minimize the, the idea that the potential of gathering information. So that kind of set up alarm.
But, um, again, in the valley, China is considered the great imitator or the great, uh, steeler of intellectual property, they're considered a problem, right? How do you compete with a product that basically rips off your technology? So I mean, as I said earlier, there is, there are very few bipartisan issues in Congress, but there are also in Silicon Valley.
And one is just, just general, and I don't mean to be xeno xenophobic, but this general distrust toward China as a competitor, especially in ai. And now in this case, drones. Tracy, is there Anything I need to, we haven't, go ahead.
Oh, no, go ahead. Sorry. We have, we are not even talking about chips.
I mean, that is where our biggest danger is. And we buy so many chips, thank goodness for the CHIPS act that we do need to start manufacturing chips here because it is a national security issue. And it goes way beyond drones.
It goes, it goes into it. Chips go into everything we touch and do when it comes to electronics of any kind. And we get most of our chips from other places.
We don't build most of them in the United States. So it goes beyond just drones is what I wanna say. Yeah.
It's it's not just that. It it is, you know, drones are, and, and I know in the article there was an option to turn, you know, these cameras on or off, it's like, oh, that, that does, you don't get away with giving me an option. We heard those options from Google and those options weren't real.
Yeah, That was, that was kind of like throwing a little pitance there. Oh, we'll, we'll go out of our way. Yeah.
I'm glad you mentioned ships, uh, Tracy, because you're right that that is, that is a preoccupation here as well. It's just this general distrust and kind of, um, us, I hate to say this, but us first mentality, and again, I mean, in the AI race, everyone's paranoid, especially out here. And, and I just, I get that impression not just among the companies competing against each other out here, but internationally as well, and that that extends also to Europe and legislation and regulation.
It's just a, it's all very, a lot of pressure coming from the top down among the rank file. And I understand why it's so important. You know, we, we, we start businesses to make a lot of money, right?
But there's gotta be a part of us that says, we wanna make a lot of money, but keep, keep our, keep the us safe. Sure. So let's just hope that drives more manufacturing in, uh, the US and less in China.
And, you know, that's that. I feel like that's where we're at. We're at a crossroads when it comes to national security and capitalism, as I said.
And we're starting to address it. We're starting to fix it. And I think this particular, uh, bill that's on the floor is just a, a, a, a part of the process.
It's starting to bring forward the fact that we are allowing China to distribute very, you know, potentially highly sensitive equipment across the United States. And we're not even, we're we, we're just letting the door to be wide open. It's not even a back door.
It is a front door and it's wide open. Chris, to your point about the supply chain, I feel like the technologies around manufacturing are changing to the point where, well, if we can rely more on robotics, we're not relying on human labor as much, then can I not make the thing that I need to sell in the market that I'm gonna sell it in? And rather than putting it on a boat to ship it halfway around the world and in, so do we have more control over what software went into that and make sure that there isn't as much malware, and if I wanna sell in China, I can go use robots to make that thing in China and whatever they want to do, they can do in their own market.
But are we getting to a point now where maybe we have, uh, an antiquated manufacturing supply chain kind of concept that work here that we need to modernize because of all the security concerns? Well, I'll just take the, the fun answer. No, um, no, it, it's, it actually the, the, the state of supply chain and manufacturing, the whole global thing is kind of wonderful.
I, I kind of love the whole, love the whole space of it. And, but this is, you know, and I was there with Nixon and China as well, and I, I, I've always thought about this since then, we're complaining about China. But before that, weren't we saying we needed them to become, embrace capitalism and so forth?
And here they did, and they're out competing us sometimes. And so it's kind of the point of capitalism, it should drive us, and this is an, an area, I think the us I think the, the, you know, western world call us, what what you will, should excel at the US particularly, because what is our strip away everything else? It's not really about baseball and apple pie.
It's about transparency. You know, and this is, that's freedom of speech, open source code, the internet, the, the whole, you know, open democracy ideas that we have come down to the fact that transparency is better, faster, cheaper, right? And I think this is a great example where this whole idea that we need to hide our, we need to have this opacity.
We need to hide our i intellectual property, which people do for the record terribly. And if you think your intellectual property is safe, you're just wrong, right? So define what you really should need to protect, get down to just that.
Define who you should be speaking with, how transparent you should be, make that work so that I can say, I will buy this drone made here in, in, you know, made in the US made here in Canada, wherever. I don't necessarily trust it any better than one from China, but I would, if you can, let me see as much as I'm allowed to see of every step, what's in it, where it came from. And if you don't wanna do that and your competitor does, I'll just buy their thing.
So I think transparency itself is the answer. It's not about geolocating your manufacturing, it's about embracing, you know, you know, acknowledging the, the concerns your customers have. What is slowing down sales?
Well, I'm not really sure you're not spawning on it with your drone. If I can lower that barrier, maybe I can sell more drones. Now, maybe, and we've seen this in cybersecurity over and over again, working with friendly military folks who saying these, all these vulnerabilities you're fixing, we kinda like them because our opponents have them and we can exploit them.
And as security people, we had to say, look, sorry, we're, we're working on fixing all this. So right now, as a na nation state, you know, using these weaknesses to get an advantage, uh, sorry, the advantages will go away and trans 'cause transparency is more competitive, and your ability to stick code in, in devices and get away with it is not permanent. It will go away.
I'm kind of with you to a point, but who's gonna monitor the transparency and stick a label on it that says that this thing passed some sort of transparency inspection. Well, but again, that's, that's, that's not how any of this works, right? The whole idea of free speech and open source and so forth, is that the aggregate works it out, right?
And I'm think I'm talking strategy now, tactically, yes, you're in a situation, you need to look at your situation and deal with these issues, but strategically, we're not gonna find any approval, a single approval stamp. We need to keep building things more and more transparent so whoever our stakeholders are can reach their level of comfort to know that we're showing as much as they need to know and, and without taking more time than we have here, right? I keep seeing in threat intelligence and now supply chain, us building the technical and policy mechanisms to enable this.
And I keep watching these large capitalists or large and small commercial organizations say, huh, that actually shortened our sales cycle. There's a business benefit to being more, to being appropriately transparent. Again, not giving everything to everybody, but if you are a customer of mine, you should be able to see thus and such without having to spend six hours on the, on the telephone.
Yeah. Tracy, do you think we could find some maybe DevOps tools to kind of examine what's in these things and scan them from malware and make sure that they are what they purport to be? Or is that just a, uh, outside of our scope, I would think that you would have to be able to get down to the code to do that.
You can't do it based on the binary artifact that's been installed. So, no, I don't think that's gonna happen anytime soon. And I, I, you know, we could say that the government should have some court sort of a, you know, FDA kind of like an FDA program for products that we bring from China that could potentially have, uh, uh, senses of sensitive consequences.
But that's gonna take years to do. So, you know, what are, what are the solutions? Uh, I think the, I think laws and prohibiting some of these products from coming to our shores is the only, the only alternative we have at the moment.
And I think that, you know, everybody does things with the best intent. I don't think, um, not that I'm a huge fan of Nixon, but I do believe that he, his idea was that if we bring them into the fold, and there's a symbiotic relationship between consumers and producers, that we'll have a better relationship in the long run. But what he didn't consider, I don't think, as we look back, is the culture.
The culture is very different from the US and China. China can be more competitive. 'cause they don't, they're not pushing human rights.
They're not worried about having a 10-year-old, uh, doing the manufacturing. There's a big difference between the two countries. And they do have a, a, a, an advantage because of their human rights, um, uh, issues.
Let's just put it that way. All right? So it's a problem.
It's a problem that I think the only loss can solve at the moment. Okay? I don't know.
All politics aside, I believe money talks. And when you stop spending it, people wake up and pay attention. So maybe we should just stop spending it for a little while and see what the response looks like.
We'll be back in a minute. Discover Techron Group, the epicenter of tech innovation. We are your go-to, for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back.
5 million bounty out for some hacker out of Polaris. And, um, I don't, I'm not sure if they're going to be able to get this person, but it seems like a, the government is getting more aggressive with these things, but b maybe it's just me, but I feel like I'm kind of watching the 1920s all over again. We got wanted signs up for people.
We got, um, government officials ripping down servers. It kind of feels like, you know, watching GE break into warehouses and crack open all those cases of booze and go pouring down in the street. But it's not clear to me that any of that actually resulted in any, you know, final output that mattered.
But Chris, what's going on here? Well, I, I kind of have to agree. You know, I, I, you know, yeah, I'm trying to, when I trying to find an op upside, you know, to, to some things, sometimes it's because you can see how stupid it is, and we're doing more of it.
And this is at some point, gonna pile up and just force us to change the way we do things. So, as I was thinking about this segment, uh, before the show, and it's kind of hard to think of what to say. It's like, do I think bounties and so forth are a great idea, are gonna be affected?
Uh, no, not, yeah. Yeah. Maybe.
I don't know. Right. You know, you know, I'm not doing the law enforcement here.
Maybe there's, you know, some people need to be arrested and, but I, I think on, I, on, again, on average, when you see something increasingly to be done that isn't working or is making the product problem worse, you know that there's an opportunity at some point to do it differently and do it better. And, you know, as we're saying in the, in the last segment, you know, this, I, I, I agree with you, and I think economics at the end of the day will solve that issue, right? But to do that, someone somewhere, you know, in this case, some definition of us needs to prove a better model where we can get better results with less resources and be more effective, profitable, you know, safe, whatever it is.
You know, when I first saw this, uh, everyone, I, I thought of, uh, John Dillinger and I thought of Jagar Hoover and the Biograph Theater, that this whole idea of, of publicizing something or bring it to the fore of the mainstream to try to, in a sense, make an impact. And I'm trying to think in tech, there was a, uh, historic parallel, maybe even back to the, I'm gonna say the mid nineties when there was the offshore online gambling was a problem or an issue. So they started mentioning some of the figures and notorious figures they were going after, and they did made some sort of government, our federal government made some sort of inroads.
Now, now, online gambling of course, is everywhere, but back then, that was a priority, and it turned out to be somewhat successful in their, in their fight. But it took several years. So maybe I'm thinking this is the same type of idea, and I'm not sure even if, if this predates CrowdStrike, but this whole idea just of security and, and the impact it has throughout our digital economy, um, in that, that the spike in, in, in cybersecurity issues, I don't know, it's just, it seems to me almost kind of more of a kind of a, uh, wanted, we're gonna try to crack down on this, at least for show.
Well, I thought about this is a continuing story of the zero a day vulnerability market. It reminded me so much of that. It's like, this is now where that has evolved to, right?
We used to pay for, you know, you know, bugs of vulnerabilities that were found, and the government would buy 'em and say, sign an NDA so you don't tell anybody or IBM or Microsoft or whoever it was, Google that, that, that, that had the, the problem. I feel like this is an evolution of that. I really do.
And hey, government, I have an idea for you. Why don't you offer this guy a job for 250 million for 10 years to figure out how to fix a drone coming from China? Right?
You know, because it's the same, it's the same to me. It's almost exactly the same. It's just that now they're trying to go after the bad actors as opposed to paying them a, a very small sum.
And that's how, that's, you know, that is why we're so behind on managing, uh, vulnerabilities. Because so long the government spent and big companies spent time trying to find the person who, you know, get people to find them and then tell 'em to shut up about it. I don't know how that's any different than it is today with somebody doing what he's doing and them going after him to try to stop him.
You know, it's just an evolution of our zero day vulnerability issues. And when I read that, when I read the article, I was like, boy, that this is just how it, this is just how everything ends up falling together. It ends up to being a bounty and looking like a Dodge John er act.
And you know, if you haven't read this book called, this is How They Tell Me The World's Going To End by Nicole Proov. I would highly recommend it. It's an amazing book.
Um, and Nicole, if you're listening, we'd love to have you on Techstrong Women. All right. Well, Chris, back in the day when I lived in New York, there were mobsters.
And, um, the way they went about cracking those gangs was they would find somebody in the inside and get him arrested for something, and then they would get him to flip on the next one, and so on and so forth. And it took a few years, but eventually, you know, they would get to the head of the family. Um, there are still mobsters running around, so it doesn't entirely mitigate the issue.
But it isn't that the strategy that's gonna work here. It's the same one we just used to lift a couple of guys outta Mexico for the DEA, right? I mean, ultimately, is this a it issue or is this just old fashioned street crime kind of approach to, they just happened to be doing some digital stuff instead, Which is probably why my first answer was y you know, really ambiguous, right?
Because on a law enforcement basis, yeah. I mean, this stuff just works. And maybe this is appropriate in this case.
I don't know. Right. You know, and, and I think everybody on the screen here has spent a lot of time working with law enforcement.
You know, you get into individual cases and decisions can be what they are. And you know, something you said just, you know, I gotta say this, to be really clear, criminals are stupid. Right?
You know, this is, you know, we overthink the adversary so much. You know, they're these grand conspiracies, all these qualified people. And these, well, you know, the, the mafia, the, you know, there's these groups that are so, uh, capable.
That's just usually not true. And you can, to your point, you put enough pressure on an individual, it's amazing what humans will do. Like give you every name and all the data.
So sometimes it just works. And I don't think that ever goes away. But at the same time, I, I see headlines like this and I take a big ring of salt because that doesn't solve the problem.
It may solve a problem and, and more power to it. If it works, go for it. You know, this is like an inside journalism story.
But, you know, so that, this is a classic, this is a good story. It's a classic Forbes story. I say that out of experience.
'cause 25 years ago I was there, and these are the type of stories they liked. But also there, there's the government, the FBI has a cyber security team. They had one at least years ago and I visited in Pittsburgh.
And they had a list of people that they were looking to go after. They didn't publicize that list. So I'm wondering, in a sense, maybe this is kind of a new approach or maybe a, a sexier kind of headline grabbing approach.
'cause I'm sure they worked, law enforcement worked closely with the, the people who wrote the story. So, you know, if it, if it leads to something, it's gonna take years. But if at least it's some sort of progress, I'm all for it.
Well, under the ending of criminals are stupid. How do you get these stupid criminals to leave where they have no extradition, and then go to someplace where we can arrest them? 'cause that seems to be part of the trick here.
Um, and never ceases to amaze me. I think, John, you had a segment earlier this or last week talking about, uh, uh, the Telegram folks. And I was like, well, if you know you're gonna be the subject of an inquiry, why aren't you vacationing in France?
Yeah, He was the right one. He was arrested at the Paris Airport, right. Um, doff that, well, that was what, when, just going back to the online gambling situation, the way they arrested these guys, they were all offshore, right?
But they were dumb enough to travel into the US and that's where they were arrested. They were arrested at US airports. They thought they could, they could get away with it brazenly.
I'm not sure what they were thinking. And as Chris said that sometimes these guys are usually guys are stupid. All right.
So that you won that five star suite at a hotel, and the Riviera trick works, They had that, they had that scheme with the, where you get Yankee tickets or something, right? And they had to got all the guys go into a room, and then they would arrest 'em all Mobsters. Yeah.
Too funny. Um, Chris, just how much is the government spending on this? Because, you know, John was referring to the, uh, a team in Pittsburgh, but I think that's years ago.
But is it your sense that, um, there's more resources devoted to this issue these days? I mean, how much are we spending to go after these guys? No, I don't know the actual numbers, but, uh, I think there is, this is part of this, you know, in, um, inevitable curve, right?
You know, that, that we're looking at the adoption of these ubiquitous global communication systems over a period of say, 50 to a hundred years. And we're 30 to 50 years down that path, depending on how you wanna measure it. So, you know, it's, you know, we're, we're far, far, far from finished.
If something is going to become endemic, built in part of everything, it just takes an awful long time, right? And we still, you know, let's look at where we are. We still don't really have boards and c-suites really personally responsible for making really incredibly poor choices on how they manage information.
Um, but we're getting there, right? And, you know, everything we're talking about here, you know, with, with, with drones and, and international nation state and competition are driving us, you know, to evolve those, to take it more seriously at, at different levels. So law enforcement, um, certainly at federal levels, I think is, is no doubt just spending a lot more money at this now.
Um, and like a lot of things, I think they're probably could be a lot more efficient at the moment. Um, and, uh, and in, in a number of years, a lot better tools than, than, uh, they had today or a couple years ago. But, you know, as for the previous comment, at the end of the day, it's still just law enforcement.
So sometimes you're literally just doing the same, you know, Sam Spade work that has worked for hundreds and thousands of years. So nothing's really gonna change. Fundamentally.
Tracy, I was talking to the folks in Radware, and you might be surprised to learn that these cyber criminal syndicates are some of the most advanced DevOps shops in the world. And what they were explaining to me was that they've even moved away from taking over your little IO OT device there because they figured out that, well, all they really need to do is get some cloud services from Telegram and start launching attacks from there. And it's all programmatic these days.
So, um, I have to wonder if, uh, you know, they're paying more attention to our stuff than we are, and b is there something we can do with the software side to combat this stuff? You know, um, I think they're having a lot of fun. Yes.
And I think that they're pretty serious about what they're doing. Um, so they probably do have some pretty, uh, complex, you know, software, a software factory that they're watching pretty closely. But in terms of stopping this, uh, some of this stuff is just, you know, criminals might be stupid, but so are end users sometimes, uh, you know, clicking on something and I, I've done it myself and I'm like, ah, I can't believe I just clicked on that on my phone.
I'm gonna have to, you know, run some kind of security scan on it because it's so easy to get caught it, you know, by the criminals. It's so easy to be, to be tricked. Um, so how would it, how would we ever stop human behavior?
That is a tough one. But now when it comes to larger companies and what they're installing in their systems and what they're building their, um, applications with, we can get a lot smarter with understanding the software supply chain and where nefarious code is coming from, uh, as opposed to just using it and believing it's gonna be okay. But again, it's culture.
We have developers who are being pushed very, very hard to deliver solutions to customers. And do they have the time to, you know, investigate code, uh, that's coming out of the open source, uh, open source package. I mean something as, as as honest and wonderful as Log for Jake, you know, caused us all some really bad heartache for quite some time.
Um, so no, I don't think there's anything that we can do right now. Uh, maybe edu educating end users may be useful. Uh, I think that they target older people and these kinds of, uh, these kinds of, of, of hacks with this individual, you know, ransomware.
So there's probably work that the government can do just in, you know, community service and, uh, you know, notifications and teaching older people what not to do, teaching younger people what not to do. That's probably our best defense at this point because most of these break-ins, most of these hacks, uh, happen because somebody clicked on something. All right?
But all those people you're talking about come with varying levels of intelligence. So, um, how do we kind of enforce that, whether it's your grandparent or your coworker? I mean, let's all be honest, not all our coworkers are equally sharp and they're likely to download something.
Um, if they make a mistake, do we fire them or is it just at this point, you know, a cost of doing Business? Yeah, I've always believed in, you know, failing and failing fast applies to so many things, right? And if you download something and you're afraid to report that you've done it, you've got a bigger problem at your company that just, that one person downloading and realizing they made a mistake.
So please let your your employees know that failure is not necessarily bad. It's only bad if you don't report, report it, and you don't fail it fast. Uh, and, but this is not something we can solve for, you know, you know, a an 80-year-old who's trying to order groceries, See that John, we're probably, And that's the bigger problem, John, we'll full circle the Richard Nicks, again, it wasn't the crime, it was the coverup.
It always Is. It's all follow the money. Yes.
Um, you know, it did, it took decades to, to dismantle organized crime, but it did happen. I mean, it, that RFK, I mean, the sane RFK, uh, did lead that charge. I mean, eventually it did, it did happen.
So I I, I hold hope that this, there will be progress being made here. Well, eventually, I think those bad guys are gonna be as big a problem for the countries that host them as they are for us. And eventually we'll all turn around and say, you know what?
We got more to gain by cooperating to prevent this stuff than we have to gain by helping one of them commit some crimes overseas. But I'm optimistic on that point. Hey guys, I want to thank you for, uh, all spending some time with us again, as always.
And, um, thank you all for watching the latest episode of Texture on Gang. You can find this episode on our website and also stay tuned for all the great content we have coming up right behind that. We'll see you next time.