Do AI Dogs Wag Electric Tails | The Inevitability Curve Ep. 20
In this episode of The Inevitability Curve, host Chris Blask and guest Amelie Karan engage in a deep, candid conversation about the evolution, current state, and future of artificial intelligence (AI) within the context of cybersecurity and societal impact. They explore how AI has transformed over the last three decades, transitioning from an academic concept into a powerful automated decision science tool. Emily reflects on her early experience with AI and computer engineering in the 1990s, highlighting the early limitations and conceptual nature of AI during that period.
Transcript
Hello, and welcome to another episode of The Inevitability Curve. I am your host, Chris Blak, and with me today is a good friend, Emily Kran. Emily, how are you Doing?
Okay. All things considered All things, there's a lot of things to consider, isn't it? You know?
Yes. We're talking about in the green room, where do you even take this look? You know?
So, so we seem to agreed talk about the grand arc of cybersecurity with your background and where we are today. You know, that's enough context, but yeah, today, seriously, I, it feels like my cousin Vinny, you know, that, that that porch of the cabin scene, you know, where Issa tome is, you know, stomped or flipped. My biological clock is tick.
And Joe Peci, you know, he says, oh yeah, lemme get this straight. I the lives of these two boys. I read this.
And how many more things can we pile on this one moment? Yes. Yes.
So, so yeah, it, yeah. Our, our, so we'll talk about AI and, uh, and whether we're getting anywhere, because maybe that'll let us talk about the 8,000 other things are going on right now. It's the, it's the topic that seemingly just sucks the air out of the room.
You go in, you may go into a meeting and, and you're just like, here's this thing we're gonna work on. And inevitably someone throws out those two letters and it just like totally says, oh, wow. How can we exploit this?
How can we take advantage of it? And it never really kind of gets anywhere outside of that. So it's like the tar, you know, you get in there and it's the AI tar, Right?
And know there's like, we've both been at this, uh, like quite some time. And, uh, we've seen these trends and fades and bads and so forth. And sometimes the trend, and sometimes it's a bad, and mm-hmm.
I, I've been reluctant over the last couple years, you know, to see what we currently call artificial intelligence. To be clear, you know, the AI is not Right. Getting at all that maybe, maybe we will, however, right?
I really actually think it. I, I, I think we're at that point. So the fact that that companies and organizations are plowing around may not be, may not be proof that we're all wasting our time in another Fed.
Um, it may just be large transition. So I don't know. I think I made a positive there.
So let's go back anyways. Right? So, you know, ai, right?
Artificial intelligence, which is neither artificial. It is what it is. And it's not intelligence, It's automated decision science is basically where it is.
And I should know, 'cause that's my degree. And, and when I was, when I was an undergrad, part of the stuff I took was regarding, uh, they, they called it, um, general programming. I think it was, uh, you know, some lisp and prologue learned turning machines and, you know, all the overhead for that.
And, you know, coming from a background, originally I was originally a computer engineering major and then switched. 'cause I didn't want to be doing chips my entire life and got to touch on AI back in the early nineties when it was still kind of a, a whisper whisper network of people who were aware of things and, and now looking at where it's at. And it's really just more powerful decision engines at this point.
But people are relying on it to, to be agentic or, you know, create and steal art as it would be. I have a lot of friends who are, are creatives and oh man, that whole channel versus the security and tech people, they, they, they are very much on the opposite ends of, of where that may prove useful in the society we have today. So, Well, so let's go back to the early nineties when 1990, I was a South Carolina in South Carolina at General Electric and, and mm-hmm.
Jack Walsh was, uh, uh, putting in a video conference network. They put on a, our, uh, uh, we made big, huge turbines for power generation. We got this conference center.
And I was thinking about that saying, you know, at some point, you know, I think I was, I think I was, you know, at these, these, uh, um, brighten up to say something like point or 30 years. 'cause right here now at some point, we all have cameras. What does it even mean?
You know, how do we, how do we, uh, move that forward and here and here we are. And the same sort of way, um, ai, you're, you're actually doing AI back then. Um, and it was different than what it is now.
You know? So that's, that's a good span of time, right? Here we are with all you.
Now we're in the world where we have video conferencing and cameras everywhere, and we're starting to settle into what it means. We're doing shows like this, you know, you and I, and we're not even on the, on the leading edge anymore. You know, our our friends and family have mostly figured out how to use Zoom.
Even if you don't, you know, their face only shows up from here out. Yeah. How has, what's, what was AI when you were in school compared to now?
How, how? It was generally pretty conceptual. I mean, like, I look at what we had in the way of stuff I would explore around on campus.
Uh, you know, it was the early days of, of computer graphics. So, you know, the, the facts that we had, uh, a lot of the, the early silicon graphics machines that were between the art department, uh, that we had our, uh, the art school, um, and then the CS school, you know, that was, that was cutting edge stuff that would take forever to re re render a frame. Uh, we had, uh, I think it was an Intel sponsored parallel computing lab that was, that was, uh, in between the computer science department, the engineering department, but that, you know, big huge box with blinky lights and stuff like that.
But it was the, the early days of those things. Um, there was, you know, we also, the Robotics Institute, you know, the idea of, of sending robotics off to other planets, but everything was still controlled here because you couldn't launch the amount of computing you needed to actually have something fully autonomous. So, you know, back in the mid nineties, like that was the state of the art.
So the idea of, of AI then, uh, was still very conceptual. I mean, like when, when I was in class doing touring machines, it was like, you're sketching stuff out on paper. 'cause there's nothing there that's actually gonna do it.
Like, you could run a couple, you know, steps along, uh, those decision trees with simple computers, you know, using, uh, you know, a prologue or list those languages at the time that were designed for, for, uh, you know, kind of creating those decision trees. And now, you know, you take this 30 years on, uh, the, the, the fact that everyone's wowed. 'cause they can pop in a chat GPT and have them write up a cover letter or, uh, uh, adversaries, you know, they'll craft up some, some potential, you know, miss or disinformation or some, some phishing campaigns, save time savers.
Um, but, uh, you know, the, my biggest worry right now is thinking, you know, uh, just the data mining, like we are such a, you know, between then and now, uh, the amount of, of human knowledge or, or data that's been collected, it's aware and accessible, uh, is grown exponentially. And I think what people are just searching for is just ways to make use of that. Uh, coming from the federal, uh, side of the house when I was a pub, uh, public servant, uh, you know, just thinking about, uh, just my last station there for Health and Human Services is getting access to se centers for Medicaid and Medicare services and, and, and trying to make sense of billing.
You know, trying to just tease out potentially, uh, bad doctors who are prescribing opioids or, uh, folks who are defrauding, uh, durable medical equipment and teasing that out of those large data sets. But, you know, the compute required for that, the models for that, the inferences generated that typically AI is being marketed for, you know, even just five years ago weren't really kind of available. Um, you know, the stuff that was pitched from the, the H-H-S-C-I-O at the time was to, to help with smart contracts.
I think it was a tie on to the whole blockchain thing. But, uh, you know, leveraging these, these tools to kind of, uh, look up previous performance and stuff, but nothing along the lines of like wholesale creative theft or, um, you know, using this to do deep fakes and stuff like that, that was definitely not there. And, and that the threat model has changed versus the motivations of like, what we should be using, you know, uh, large machine learning and, and quote artificial intelligence, uh, to kind of go and, uh, uh, you know, exploit.
Well, it's, so I was thinking about that, that that timeframe, right? You know, so from paper mental, like literally, you know, at the, the sort of mm-hmm. In, in the top layer of the people who are thinking about this 30 years ago, favorite Ben.
You know, lots of things happen along the way. Um, but this damn thing that Sheko nameless otherwise will start talking to me, right? As, you know, with these electric boats I've been building, and I built this Alexa into it.
Um, you know, I've been playing with that. And, uh, and, and, you know, as, as just awful as, as it is as a consumer thing, having this voice in a pace I can predictably, if I enunciate particularly well, you know, control certain things around me and do things in a, in a real environment, I found that being fascinating how it worked and how it didn't. And then, you know, let's take us into the present.
You know, the current, I currently have two tap et accounts of the cheap one, the expensive one, you know, my personal one and one one for work. And, uh, and I'm honestly only a few months, three months, you know, really trying to use this particular product for a purpose, right. And I think I'm getting a feel for it.
Oh, I guess, you know, somewhere along the line between the two is, is, uh, you know, I took one of those electric cars in the truck and put a raspberry pie in it last year and put this Donkey Kong, uh, AI project on it, and sort of built a scratch so I can get one round of hands on it. And I see sort of a three layers of evolution right now. There's, there are projects like donkey car out there.
If you're a real hacker, you can build some LLM stuff and some AI stuff, you know, to, to do robots and, and so forth. There's consumer products like, like Alexa and Google Home and so forth, which as much as they suck, right? Gave us a sort market test of these basic capabilities if they're just, just at the barely survival level.
But al already, I'll, I'll get to my point, if I ever do, I hate it because I'm starting to use, I talk to this thing to talk to Chad, and we have deep conversations and explore complex situations and markets and political structures and, and everything else. You know, I'm not asking it to do anything perfect. I don't want it to make an AI art piece for me.
And I'm finding it just stunningly useful. Um, yeah, being able get things done by myself, it would take collaboration and working groups weeks. So all of that, I guess, you know, taking your well learned cynicism of the current craft, right?
Do you see it, you know, it's gotta get better over coming years. Are we on the trajectory to actually fill whatever you're thinking we're doing right now? Or is you think it's still decades away?
So again, kind of going on kind of the, the, the touching on my, at least academic history as well as my, the, the experiences I've had throughout my career, I, I think we're running into that kind of Moore's law aspect of ai. Like the, the fact that this is a is this is a technology that you can continue to throw more and more compute at, and it'll just consume it. It's gonna need more memory, more storage.
It, it, it's like a brain. Like if I, I guess that old, uh, uh, twilight zone one where, you know, it becomes the smartest man in the world. His head grows big.
I mean, that's like how AI is getting, and it's only gonna be more effective as that, that those advances are made. But I don't think we're proceeding at that level. So I think right now, uh, a lot of the AI companies are kind of struggling, I'd say, almost, you know, 'cause this is really just vector math and, and graph theory, essentially.
Um, you're, you're finding shortcuts. The tokenization is a shortcut for the shortcomings of our computing environment. Um, you know, if you could store the full datagram that's there to, to hold a full memory, um, that's great, but we don't have that.
So you're trying to create these neural nets that, that create these relationships between the tokens and so forth. And, and they're imperfect because they're not necessarily guided. It's, it's looking at math as math and statistics, again, graph theory and whatnot.
And, uh, I think that's the challenge is like, we've got, we've got the math down, but there, you know, the intelligence is not just rote memory. Uh, it's not knowing numbers. It's not performing a task.
It's, you know, right now, you know, as these stories come out, like more and more of this AI stuff is like mechanical turks. Like there's people being paid pennies overseas to kind of make it appear like, oh, wow, there's computer vision. No, there's someone clicking a button.
Like that's a, you know, it's like, you know, going through paid capcha kind of still. And, um, yeah, that, that we're, we're still at this kind of, don't look behind the curtain type kind of thing. I know, you know, if anyone's gonna watch this and, and make comments in the video or whatever, well, you know, uh, anthropic and open AI and Google are all doing these great things.
And these great, you know, AI scientists are doing amazing stuff. Yeah, this is great. It's research, and they're trying to apply it, but they're trying to justify, I think, the investment in it.
But there's a lot of other stuff. Is it even within the security community? Like, we need things to advance to a certain point for us to feel comfortable about, you know, lighting, someone else doing it to, I hate to say it, like dumb it down so that like, there are entry level roles for people to perform that are just totally kind of replaced.
Um, and, uh, you know, as you mentioned about having your, your Alexa or your Google Home Assistant or Siri do things for you, having these conversations and so forth. But do people want that? Like, I don't, I have a spouse.
I love talking to my spouse. I love doing things with my spouse. I'm, I like having deep conversations with them, having that with, you know, some chatbot just doesn't wrestle my Jimmys as it would be.
I mean, you know, it's like I, maybe I'm still that generation. I prefer to have human interactions and human thoughts, and the reasoning that you get from a human being, uh, the reasoning that I've read about and it's seen people show with AI stuff doesn't necessarily to me at the, the philosophical level. And even just the, the biological level of, of, you know, real thinking intelligence beyond just, you know, collecting knowledge.
Um, you know, I, I, again, it's, it's, maybe I'm waiting for the, the, the room of a thousand ais to generate Shakespeare, you know, kind of like the whole monkey and typewriters type kind of thing. I think we're, we're, I'm, I'm in, I'm on hold for that. And I don't see it.
Um, I, I, I admit to being, you know, seriously fanboy at the moment, right? And, and I know myself when I get like this, uh, at least one process in my head, you know, people looking around saying, this can't be right. No, no, you are all enthusiastic as you think you, you know, with this means, this means this, but you're gonna find out that there's a bag of cats, you know, have to be in the middle, and you're not gonna be able to do the thing.
And what you said about Moore's Law, uh, have thinking, 'cause this, I find myself, when we're talking to people saying, just imagine it. Don't just think about ai. Just imagine you had just ridiculous amounts of computing power to do stupid and trivial things, which is kind of true, you know?
And as much as mm-hmm. I like the uses I'm getting out, I'm having a lot of value in it. Um, however, right?
I prompt engineering my butt. I sit here and ramble for half a minute, you know, voice, text, pres, go and see what happens. You know, just processing my prompt and making any sense outta whatsoever, probably uses more power than a, you know, a Midwest town.
And since we're just, you know, since we're playing and we're building this stuff in, and you have people are actually using it and so forth, we talk about the, the path. And we have this vision that AI in the short actionable future over the next three years, five, seven years, is going to get to these stages. And yeah, you have maybe the second wall of th or more dynamics, right?
You know, we can't get there that fast just by throwing the exponentially more physical hardware, you know, computing power and, and electricity power at it in that timeframe. Well, It's like throwing, throwing nine women at to make one baby in a month, you know, type kind of thing. You know, it's a little bit of that.
You're trying to parallelize something that doesn't probably need to be parallelized. But, but let me, let me see if I can develop a counter on the other part of it, though. I think that, because what we, what I see happening is that everybody finally, and when everybody, finally then things happen.
Money, resources, right? The, the internet itself, sorry. Um, and the internet itself, when I, when I got it, you know, everybody around me was saying, no, no, you don't understand.
It's a research educational thing. And, and then the dot coms came along and it's like, oh my God, they're gonna destroy, they're gonna take up all the bandwidth. And I said at the time, and they're not being correct, but they'll probably add a lot of bandwidth.
They'll probably add so much that the other point, 1% that's left over will be more than us academics and geeks had in the first place, right? So, net, net, even though it's inefficient, it's a huge waste of resources. However, Nature of hobs of vacuum as it would be, right?
Yes. So, so this, so this, you know, with all these concerns, I, I think if we're right about some of these concerns, I get the feeling that the economic and social pressure to solve and is, is high enough that we will spend what it takes. Unless I, I, again, it's a Moore's law sort of fundamental that we just cannot push past it.
Yeah. Well, I, I think, you know, I, I arrived at college during eternal September, so I was, I was one of those, those folks, but I arrived at college versus on a OL when they opened up Usenet. And, you know, I, I started my website, the, the winner of 93, you know, so that was very early on.
And, and, um, you know, the, the idea of how you could exploit what was the internet at the time was, you know, you're still trying to find your way. What do you, what, what can you publish? What you could self-publish or, or create that would garner people's attention?
And I think we've just been in this cycle. I, I, I think, um, the whole idea of, again, people pushing to have resources for exploiting AI comes from the fact that, you know, my, my, my gig before the, this most recent gig, which is now the, the most past present gig that I, I've had due to my layoff, um, you know, I was working, you know, as a tech, you know, external technology relations. So I was, I was working with all the, the, the big, uh, tech companies regarding cloud and, and AI and stuff.
And it was interesting having conversations with them because they had all this hardware that they bought, uh, that was specific for a certain type, you know, certain purpose or whatever. And, and they wanted us to, to use it for another. And it, it was like, well, it was wasted overhead, you know, it was the, these, these, uh, servers were designed for the, for this capability, but, you know, we could reconfigure them to, to use for what you need to, 'cause we've already invested in it.
And then, you know, it was just this idea of just trying to make use of things that they thought they were gonna to use. And they're pushing that onto others. And, and I, I think a lot of it too is it's this, again, a sunk cost thing where some organizations, it went down the path so far, and now they're just trying to kind of justify having it there.
And I, I think, you know, most recently with my gig, um, you know, I look at what has was published for consumer use, uh, by that company, um, and what's being used internal. And they're also subject to, you know, looking at lists of, of solutions that are, are part of the organization, uh, that claim they have AI or LLM or Gen I or whatever you may have, you know, with the, the acronyms there that are included in things that they, they have licenses for. I don't think that company asked for them.
They just, AI showed up. It, it, it's, it's like the vampire, I don't think they necessarily invited it in. It was just, the fact is, is like, you're gonna have it whether you, what do you like it or not?
And then the stuff they build internally was to, again, going back to the, the thing to exploit, uh, and, and surface, uh, uh, insights from data. And that's where most of that is business intelligence use of, of ai. But you could just do that.
It's, again, it's statistics. You're looking at relationships and so forth, and, and there's been models for that for decades. Um, immediately slapping, you know, the, the nom d plume of de jour, uh, no d plume de jour.
There we go. There's all the French I know, uh, of, of AI on top of something and say it's, it's been enabled, uh, just I think makes people feel better. But what va what's the actual value add?
So the, you know, at, at these points of transition, I, and people, they become pertinent to what I'm involved with. Like I say, I get really enthusiastic and really worried because, and, and again, this, you know, to the theme of our show, this is always what I, what I mean about inevitability curves. And it's just, it's not, it's not predicting the future.
It's just saying there's a space of possibility. And as we move forward in that space, you know, our actions has changed the, the, the possible futures, right? This kind of sounds, uh, really simple, but, uh, but we're, you know, we have sorted and, and the, and there's not an inevitably curve.
There's lots of things interact. And if you're a anesthetic synesthetic, oddball like me out there, then you know what I'm talking about. And the rest of you are just staring at us like we're weird because, but it's, it's, you know, we are going, we are definitely going to have certain things happening, right?
And if we can't get certain capabilities, um, in the same sort of time, we're gonna have certain consequences, which are terrible, right? And in, you know, I think a half a dozen offhand, but, uh, you know, narrative resilience, narrative, serenity of sovereignty, you know, being able to have a conversation between two humans and not know and know whether the other one exists or not, or the words they're saying are correct. Or even if it was a real human, you know, by the time the, you know, this, your video gets to me, does somebody intercepted and awkward in the meantime?
You know, if, if, you know, those things are within the real and positive possible now, and if we cannot counter them, we get to the point pretty rapidly, but we just can't talk. So that's, that causes a whole lot of economic expression and pressures. But more fundamentally, a lot of 'em don't wanna, you know, and when the entire global population doesn't want something and is sick and tired of something, then all sorts of pressure comes to apply to, to fix it.
And the, you know, to see if I can scope that rant into, into our, uh, particular space, but, excuse me, cybersecurity and supply chain, I just firmly believe more and more that the, the more I spend in the time in that space, moving along that timeline, that we will not be able to do things like fly spaceships if we cannot have the kind of speed and visibility into all your supply chain data across, and know you're not gonna hoover it all up in advance. I mean, you have things in a ballistic trajectory, and you wanna know things about, you know, software seven, you know, 3, 5, 7 steps away and supply chain you need in the next three seconds. We have to be able to do that.
If we can't. I, you know, you and I are really good on the adversary side. I can think of ways to stop all these things.
I know with existing capabilities and tooling are where they are, those are definitely following their path. And anyways, right. The, the brittle moments, I guess, right?
How close, I think we're pretty close to that, to be honest. Um, you know, one of the things, having taken the role for doing offensive security, um, for AI at my last gig, um, yeah, I was bringing this up on another podcast. I was at the, the Red Team Summit last year, not this year, I missed out this year.
But last year they had an extra day added onto it specifically to, to focus on ai, like offensive security against ai. And I think the reason they didn't have it as an extended day this year was like last year, it was, I wouldn't say it was underwhelming, but it was like, we're still figuring things out. Uh, the old ways still work.
Um, and essentially this is just, you know, a different form of AppSec in a way. I mean, you know, you're still, your goals to traditionally are, you're, you're trying to get access to training data, data. You're looking at access controls are, you know, are back and so forth on that authentication.
Um, and looking at flaws to the algorithms that are in there, or the methods that are written in behind there. So, you know, the rigor required for, for quality, uh, is still there. And, you know, one of the, the things I, I think on the supply chain stuff, and I, you know, I brought this up at a a in another discussion too, is like, okay, so we have model cards.
Great. Awesome. Thank you, Google.
Appreciate that. But, uh, all of that's one pretty voluntary, and two, uh, it's really still non-standard. So there's nothing, there's nothing reliable there.
It's, it's way far away from sbo m uh, if you, you kind of wanna bring up the, uh, you know, that one, which has been flogged to death for a number of years, and bless, uh, you know, Mr. Friedman for, uh, Dr. Friedman for all his work on that.
But, uh, um, please tell me you don't have like a cutout hit of his head on a Popsicle stick. You can kind of bring into these conversations. But I mean, um, but yeah, but, but I, you know, I know, uh, Alan's off to the, the hbo, the, the hardware bomb, and I think that's, you know, the next progression.
But I don't think we really have that with ai. Um, so, you know, even what, what does exist as voluntary and to be able to do a, a sufficient audit, 'cause these things run on lots and lots of data, not lots and lots of code, lots and lots of data. Um, you know, there's no way to really kind of audit all that efficiently.
So you're just kind of trusting that everyone was upfront, transparent and, you know, fully honest with somebody. And I think that's should give people pause. Uh, yeah, I know I, you know, had, uh, gotten spoken to when I questioned the fact that there was not an AI ethics person on staff, uh, uh, my, my organization there, there, you know, there's legal people and so forth, but there's no ethicists, you know, and that's one of those things is like, that gets back to that question is like, are people, do people want it?
Do they want to consume it? We're, we're efficiently try, uh, effectively trying to expect organics us to, uh, you know, shoehorn something that's not organic into a use model. And if you're not adopting it naturally and you're forcing it upon, like you mentioned before, like how honest is that use?
Um, you know, for me, we've, you know, my spouse and I have had, you know, again, these, these, the, the, the voice agents and stuff around the house. But really it just gets down to it. Like asking that to turn lights off and play music, you know, it's, it is a step through series, but I'm not asking it to like, do my homework.
I know some kids probably do, but I'm like, I just don't, there's not a level of reliability there that instills a level of trust for me. And these are, you know, products from supposedly leaders in the, in the field. And I'm just like, this doesn't, yeah, it just doesn't, it doesn't reach to the level where I'm like, yeah, this is fine.
I'll, I will, uh, you know, hand off this, this task to them to do. And I assure there's plenty of people with using ncps to do things and, and all sorts of stuff to do part of their work. But, you know, day to day human life doesn't really work well with these tools right now, um, unless it's, it's seamless and organic.
Yeah, I don't, I just, I don't have that feel for it. And that doesn't even speak yet to the security behind it. I don't think, you know, the folks who are developing these models are not security people.
Um, there's plenty of times I've sat in a room and, you know, there's, there's not a security minded person there other than me sitting in the room. And, you know, it's their project, it's their work, but, um, you know, they're not trained in it. And unless they're willing to ask a question, it's, it would be me or someone like me in kindly interjecting to say, have you considered this?
Or, uh, when you're done, let me know. We'll, we'll go poke and prod at it and, and find all the holes and, and create more work for you, essentially. I mean, that's the interesting thing about the offensive security world is, uh, we create work for more people.
Um, and I think successful teams also try to make it not seem like you've just dumped a hete steaming pile of poo on their desks and told them to deal with it. I think those that wanna work with them and, and, and try to make things better are there, but I just don't get a sense that there's a lot of that out there right now. So let me, so we're, we're at that point in the conversation.
Let's try to look at in the future, and just, just today, I think, uh, um, I wrote an article for a Security boulevard, a Tax Pro property, all you all watching there, go click on it, click on an ad or something, I don't dunno, um, about, uh, sort of expansion of a LinkedIn post. You might have seen that, uh, or not that many years ago, but mental dos, mental denial of service. Mm-hmm.
Right. And I think, you know, in the, you know, in the cognitive security space right now, you know, we're in a extremely challenged spot, you know, as an industry, globally, as people, as societies and so forth. You know, what's real, what's not real, and so on and so forth.
And in that, in the update of the mental loss article, I, I think of it, I've tried to explain, remember the, the Good Times virus, right? I was very, very, Oh yeah. Oh gosh, yeah.
Email goes around, you know, for everybody doesn't know the story that says the, the headline is Virus, tell all your Friends, it's gonna delete your hard drive. And there was, you know, to be clear, there was no computer executable code virus called Good Times. It was an email and it got forwarded, you know, to all the, all news groups and all the mailing lists on the internet.
You know, tell all your friends, then everybody would jump in and reply all back to everyone and say, that's not a real thing. Stop doing it. And, and it, and it broke the internet.
And at the time I was young and new to all this, I'm just sitting there, you know, trying to avoid doing my actual day job and, uh, argue politics and space tech and so forth. And I, and I hadn't got into security yet at that point, and I just stuck my little hand up and said, Y all's saying it's a scam, and this is an actual virus. This is executable code that someone wrote, um, in their head.
They use their fingers and so forth. They type it into a keyboard, they transmit it across, you know, these electronic wires, you know, they, you know, just present an A PIA screen. It was read by input devices in my eyes, put the code in and made my brain, uh, do functions.
It made my hands move, made me actually press send, maybe me write this stupid email and trying to get everybody to shut up. You know, it's, and I got shouted down. It's like, no, no, no, you don't understand.
That's not how computer viruses work. And, you know, since then, you know, there's bread, you know, Brett going out there that, that, you know, he and I do all sorts of crap together. And, and his PhD thesis is where the bloody term came from.
So I've had plenty of chances since then to say, bread, did I miss something here? 'cause that still looks like a computer. Vi is the virus transmitted by computers is the Wetware virus.
Mm-hmm. And we're literally in this world right now, right? This is the way we do Yeah.
Take up consuming, I I'll use up processing power in your head. I'll use the time you have, you know, and I'll use that up for something else. I will lower your, the, the efficiency of your communications channels between host you and every host around you.
And if we don't find a solution to that, you know, we rapidly approach the point where we cannot run the power grid. We can't do anything. Right.
You know, nobody knows, you know, whether, you know, you know, any information not seen where their own eyes is real or not. Um, yeah. So we're at this crux, and, and this is, you know, to the, to the, to the point that I'm, again, not getting to, I think that's one of my concerns that I see right now, the potential in what we call I AI right now in helping us address some of that, you know, giving people the time to deal with human scale issues, you know, and, and imperfectly, yes.
But again, I, I think if we can't do that sort of thing in the near term, then, then I, I think we'll get ants. I mean, we have a lot of ants now. We have ants for a long time.
Yeah. I think, yeah, you, you do bring up a an interesting aspect there. I mean, that was something else I studied, uh, while in college I was, I I, I studied a lot of stuff in college, but cogno psychology was kind of the core of that.
Um, at the decision science of The house. You're the responsible one of us. I dunno if I ever said that, you know, but a lot of us in this crowd, like you're one of those people who finishes things and like admired Barely.
I mi mind you, I'm not really proud of my GPA after I graduated. But, you know, one of the, one of the things there was, you know, and I think this is well trodden, uh, cognitive psychology thing is just that, and I think this even showed up in, uh, Douglas Adams's, uh, writings. I don't remember if it was the Dirk Gently or the, the Hitchhiker's Guide one.
I'd have to require me to go reread it. But there's basically seven slots, uh, you know, in your brain that you can hold stuff, uh, resident, you know, you get that, that tip of your brain type kind of thing. And I think the joke was there, you know, uh, you know, all but one of them are full of penguins.
But in this case, like, you know, you have that overwhelming aspect of trying to keep things on the tip of your head. And if you can, you, I, I think what humans run on besides caffeine, uh, is anxiety. And, uh, that's usually created by just those, those check cycles through all those seven boxes is like, okay, I'm worried about, you know, can I, can I pay my mortgage or rent?
Do I have enough food on the table? Like, those are like four or five of those ones on there is just sustainment. Like, how do I get myself through my day?
And that's, you know, humans are just an anxious species. You know, we're, we're rabbits with a bigger brain, I think in a way. Um, and then like the three other slots, three or four other slots that are available, or those are the, the, the task driven type kind of things to, to actually like your work throughout the day.
Like, I've gotta go and, and manage this project and things like that. So that it's, it's, I think there're rather than actual like, facts and knowledge in those seven spaces, I think it's just little tiny boxes of, of cyclical anxiety that we have. But it allows us to function.
Our, our little, our wetware is just one of those things in those interrupts, uh, you know, something fantastical like, uh, you know, uh, some AI generated, uh, what, what's the engine now is the VO three vo OE three or whatever that's been out there where people have been posting the video of, of these newscasts that look really great and, and totally telling absolute crap. Um, you know, those are going to hit the eyes of people who don't have that filter, that they're just cycling so fast that it just gets sucked into that cycle. And now it just becomes part of that, one of those anxiety boxes.
And it's like, well, I, I'm worried about the state of the world today, and I'm gonna throw some fake news in there and, and that, that box starts to get hot because you're now adding that to that cycle and that those, those check anxieties. And I, I worry that, you know, as much as it's been marketed that, you know, these tools and systems are there to help help humanity and whatnot, there's that, that existential harm aspect of it that we haven't fully thought through of those implications. It's usually been given lip service, uh, Tim Guru from, uh, Google, you know, uh, they famously were, were let go for bringing up those types of cha those, those questions.
And I see more and more of that as she, she highlights a lot of those stories from, from other companies. And, and it worries me that a lot of that, that that human safety aspect has really, really been pushed to the side. It's like, well, they, they'll, they'll walk both ends of it.
It's like, well, we're not there yet, so you don't have to worry about it going rogue. But then they constantly push to get to that point where it can now go rogue. I think though, the most recent story out now is as the, the deception that the Anthropic AI does for the engineer, it uncovers, uh, you know, an affair.
Um, and ref, you know, basically tries to use subterfuge. So it's like, you know, so what angle do you wanna plan, like telling everybody it's safe or actually seeing all this stuff that it's potentially doing wrong? And it's like, if I'm, I'm a human person with those seven boxes of anxiety, I'm like, oh hell, I need an eighth box just to have to handle this existential dread.
You know, I need, I need extra memory. I know, I think I, you know, I think I've developed a, a certain, um, relief cycle. I see certain conditions that I keep seeing those around right now.
And, you know, look, my, my inbox, my anxiety levels and so forth are all maxed out. Um, however, yeah, right. The, the, you know, when something, when a problem just becomes so endemic, you know, if it is possible, you know, the pressure per solutions just get so high, you know, and I, um, and, and you know, how much, you know, influence game is, you know, because I, because I think that we're not done building the internet.
I think our big problem is, you know, as we talking about in the green room, right? We're in early in this conversation, we've been down these past you, when are we gonna, are we finally gonna get there? Are we there yet?
Um, and I don't think it's that we haven't achieved things or we've gotten things or whatnot as we're not done. We have not built and internet, not one. Yeah.
We had not built and finished one complete internet yet. And we have still a whole vast domains of security where folks like you and I have for decades said, yeah, that's really, we need to get to that. And the fact that we haven't dealt with human cognition at all at a cybersecurity level, you know, as a fascinating indicator that maybe we have some work to do, There's been some studies, but it's more or less that I guess everyone kind of considers that a soft science.
I think, you know, when I've gotten into discussions recently at my last employer about vulnerabilities and, and, you know, the discussions all circle around, well, can we put it into this tracking system? You know, is it, uh, uh, you know, this, this thing that feeds into another system which feeds into, you know, five other systems or whatever to track and hopefully, you know, help with remediation, but none of those address the solve vulnerabilities, the, the policy stuff, the human aspect, the, the things, you know, practice and, and procedures that need to get changed to keep them from occurring again. So, as you mentioned about things not getting finished, being built, I don't think we have a strategy.
I, I think, you know, the, in the sixties when ARPA net was, was born, we hadn't gotten to the point where, um, the the fact that, uh, you know, what are, what are you gonna do next? It's just like, we built it, people will come, but like, what's the end game? Does anybody have an end game?
And you know, this goes back to like I talk, uh, talk at length about like a sufficiently good strategy. Everything will eventually regress back to that, that straight line strategy. If it's a good enough strategy, it's resourced and it's, it's, you know, people agree to it and so forth.
But you're, you know, as you start out, you're gonna have a lot of this back and forth as you're trying to do path finding. Well, right now, internet ai, there's, there's no strategy. It's just kind of like we have this ball of, you know, nuclear energy here of, of just this, this concept and, and, and mph, uh, to go and, and exploit this, this new capability, the new shiny new thing as it was with blockchain, as it was with the internet back, you know, when, you know that eternal September thing, uh, you know, became rapidly commercialized rather than, you know, where it was originally a a, a research and a scholastic environment.
And now I think that that goal of acquiring money from that exploitation, uh, issues the concept of a strategy. Like, where are we going? Are we just like wandering through the forest?
Or like, do we, do you wanna go on vacation? Like, I, I wanna go from DC to San Francisco. Do I wanna take a wandering a route and maybe show up in a couple months?
Or do I wanna take a direct route and get there in a week? You know? Um, I've done it in two days, but that's besides the point.
I won't go into that too often. But yeah, I mean, that's, it's, uh, we, we don't have a strategy, I don't think everyone who says they claims claims there's one out there now. There's no strategy, there's no leadership.
Well, I'll agree with that. I, I, again, I, and I don't wanna, I don't wanna sound like I'm unaware right now being a mm-hmm. A, you know, Pollyanna caffeinated enthusiast and so forth comes with, with costs, but some opportunities as well, right?
Because when you, you know, when you get past, again, I worry about things like actually being able to do this. I worry, you know, the, the state of the world today, right? You know, the, the, the fact that on the human side, and I, I know we're getting, pushing at the, the, the limited of time.
But, you know, the fact that as threat actors, if I was a threat actor today, I wouldn't write a computer virus. I don't care. Right?
I would mess with people's heads that's working really, really well. There are zero, zero do zero, uh, defenses against that. Everything you and I have built, um, historically just doesn't deal with that human language.
Forget it. Right. You know, how do I, you know, understand it at all, Alexa, much less, you know, get the kind of nuance understanding of it that that would have any protective value in a human, the human situation.
So for everything else we're trying to do with it again, uh, the, the fact that we're actually it is forget ai, large language models like computer horsepower that can actually understand human speech well enough to, to get some of the subtlety, um, that smells to me like the kind of thing that future versions of our halls will expect to be built in to human information systems. 'cause otherwise, folks like you and I will just break them and do it now. Yeah.
Well, it's whether or not you're gonna do it subtly through, you know, coding and hacking that way, or you're just gonna take a, you know, the, the, um, you know, basically a sledgehammer to the, the data center. You know, like there's, there's two ways to to, to rebel against this in a way, um, or fight it if, if you're of that mind. But yeah, I mean it's, uh, yeah, I don't know.
I don't know what the future brings, but I know, you know, given my age, I'm probably not gonna be around here for when the world melts down. But, uh, be glad to exit before it does. Um, I have a feeling that's where we, I, yeah.
I don't wanna sound doom and gloom, but I just have a feeling, you know, just the, the folks in charge and stuff like that, I, I don't see this coming out with a positive ending right now. Well, you know, and, and is relative, you know, history will goman regardless, you know, they, you know, they mm-hmm. Could, you know, we may live through dooms days.
Well, you know, we're, we're chiropractic fans, right. You know? Yeah.
I don't wanna be fatalistic by any means, but Yeah, it's Okay, but there are, there, there are a lot of apocalypses, right? Yeah. You know, they end up being relative and so forth.
Um, but yeah, I mean, I think, I agree. We are, we are experiencing society, societal risk, you know, so the risks are happening right now because of the issues. We can't control the, the, you know, information system we built and mm-hmm.
And people who exploit it can, you know, there's a mismatch in, in, in, in capabilities. And if that is not fixing enough time, then, you know, structures, companies, societies can collapse and it can Right. Make be long dark gaps before we finally figure it out.
And, uh, there's gotta be a happier note to finish that on. But, uh, Yeah. Otherwise that's a whole other, that's a whole other podcast at this point.
'cause you, you touched on something I would've definitely gone off on a, a slightly more political tangent, uh, having, uh, she mentioned about those in charge and taking control of stuff coming from the federal space. Uh, yeah, I have an entire other soapbox to, to stand on talking about that, uh, uh, was very relevant to a point in time where I, I had space in that career area. So, Well, you know, the, the nice thing about doing these things, you know, that it is almost free.
We can record another one. And, uh, as you know, well, I'm not in this show, you know, I'm gonna, uh, not quite ready to, to say everything in a public forum like this. I have plans afoot that are going to play out one way or another.
You know, this calendar year, these next couple months and so forth, it'll prove or disprove some of my thoughts on, on that issue. Yeah. Like I think we, I think we have defensive and responsive capabilities there that Yeah.
And if you've watched this show this long today and you don't understand what I just said, then why are you watching this? A security gee show, you know, these things. Yeah.
Yeah. So I'm gonna have to stop it there, just out of sheer, uh, inability to make time, uh, scratch I even longer because you and I can do this forever. Yeah.
We just gotta go to that planet, uh, on Interstellar. They, they had Matt Damon on, and then you, you can kind of stretch that time there. Right?
Right. So, thank you for the time today. Thanks for everything you've done for the industry and saved the bloody world and Yeah.
And all the rest of us. And for being a good friend and, and, and, uh, and for wearing my hat, you know, you, you're in that small crowd of folks who Yeah. I was gonna actually having here with Scot.
Yep. Blasco, right? Yeah.
Every time I see her name, I they say, oh, that's one of those folks. Yeah. Yep.
I remember it With Disney Springs. Yeah. Headlights that probably came with that.
It was fine. I was more or less trying to find out where the rental car was in the, the parking garage then. Alright.
So thank you again. Yeah. Thank you all.
Appreciate it. Uh, everybody out in the world, you know, spending your time with us today. Thanks for that.
Uh, be good, be safe and come back where we'll talk about these things more.



