The Evolution of AI in Cybersecurity – The Inevitability Curve Podcast Ep18
Chris Blask and Casey Ellis, co-founder of Bugcrowd, explore the evolution of AI in cybersecurity. They discuss the generative AI hype cycle, the challenges faced, and introduce a taxonomy for AI’s role in risk management. The conversation emphasizes the need for clear definitions of AI for effective policy and regulation. They highlight the importance of resilience, optimism, and community contributions in addressing emerging cybersecurity risks.
Transcript
This is Textron tv. Hello, my name is Chris Blak, and welcome to yet another episode of The Inevitability Curve, where we take interesting topics, hopefully we take interesting folks. Definitely.
And we try to see how we got to where we are. Take a look at what, where we are actually looks like, and with that, see what we can tour about where we may or may not be going. So with me as a good friend and the first, second time, uh, uh, guest on the show, because we recorded the first episode a year ago at RSA, um, that's not on the channel, you know, so we're, we're, uh, revisiting again, Casey.
How are you Doing? Well, Chris? Doing well.
Yeah. It's, uh, it was inevitable that I was, uh, gonna come back and speak again and, you know, excuse kicking it off with a terrible pun. Uh, but yeah, it's, it's good to be here.
Well, you, you, you're, you're right in, uh, you shot, yeah, yeah. Bad puns and, uh, and dad jokes and, uh, and maybe some wisdom. So last year, alright, so, so anybody doesn't know, you know, shame on you.
Um, but, so you are co-founder and chief strategy officer for Bugcrowd, which has taken, um, access to, uh, cybersecurity human resources and scaled it basically in an open source sort of way. Right. And last year we were talking about, and, and the company's done quite well, been around 10, 12 years, can I say, at this point, 12 Years now.
Yeah. Yep. And, and, and that taking that, uh, successful platform and adding what we call artificial intelligence today and working that out.
So last year we were talking about that, and as we were talking about in the Green Room, it's that it is RSA time again. You know, we have not just been talking about AI and I promise I won't say what we are calling ai, um, today, but, uh, we've been talking about it for a long time. It's, it's seeping its way into everything.
So where do you wanna start, you know, looking back to, Wow. Yeah. Um, yeah.
So, uh, yeah, it's, uh, thank you for, thank you for having me on. And yeah, my name's, my name's Casey. I'm the, uh, founder of Bugcrowd and also co-founder of a thing called the Disclosure Project, which is all about basically normalizing vulnerability disclosure, uh, and changing the operating environment for hackers that operate in, in who, who do their work in good faith.
So that's kind of my background. But, um, yeah, it's been, it's been interesting 'cause, you know, just thinking about kind of where we're up to last year when it comes to AI security and how the crowd sort of fits into that. I think, um, one of my favorite quotes, uh, at the early onset of generative ai, so look, we're talking late 22, early 23 I think it was, um, was that, you know, AI in, in 2023 was kind of like having a website in 1997.
So there was just this enormous, like stratospheric like hype cycle, peak in the hype cycle, um, and a whole bunch of things get kind of decided on, and, and, you know, people start building and people start to freak out and whatever else through that period. Um, but then we drop off that we get into the trough of, of despair, um, and then it kind of goes on to being kind of, you know, what it's gonna be in, in terms of a status quo into the future. And, and the interesting thing about it is that I thought that was exactly right, like AI hit and became very obviously a very powerful and therefore inherently dual use technology.
Um, but then the other side of it is the inherent accessibility built into generative AI in particular made it an issue of retail politics pretty much overnight. So like, everyone just panicked all at once. Um, and yeah, I think we're at a point now where, you know, we actually are starting to get some idea of what we're gonna use it for.
Like, I was getting asked by a lot of folk, um, you know, in the, in the venture community and in the sort of CISO community, all sorts of other places, you know, where I, I saw the AI security and AI kind of risk management industry going, and my answer even a year ago was like, we don't even know what we use AI for yet. So, you know, I, I can sort of be somewhat predictive around where it could go. But in terms of what actually ends up being important, um, I don't really feel like anyone's got a good answer to that yet.
So that's when we cooked out the, um, or cooked up a taxonomy, basically talking about like AI as a tool, um, AI as a target and AI as a threat and, and sort of having that as the top level things to be thinking about that, you know, start to allow you to create an overall risk taxonomy when it comes to AI security and risk management. AI as a tool is basically anything that reduces time to success for attackers or defenders. Um, AI as a target is basically the net new attack surface.
Um, so, you know, pickle file to serial, uh, pickle file to serialization with like reverse callback shells out of, you know, data models. That's not really a thing that we were dealing with three or four years ago. And it is now, like stuff like that as well as jailbreaking and all those kind of things.
And then AI as a threat to me is all of the unintended consequences that you get when you jam new technology into existing systems, um, with all this kind of competitive pressure and, and hype around it. And I think that third category is actually the one that scares me the most, to be quite fair, Frank. Yeah.
He had the emergent property side of things, right? And the, yeah, when we first talked, uh, a year ago right after that, I came home and if I'm not mistaken, yeah, there it is. Right above my head, I took a, an old electric rrc car, put a raspberry pie in it, you know, found something called donkey car, an open source ai, um, project, and got it running.
So I built my own little AI robot and we had it running around in the yard. That's awesome. And, and, uh, you know, so which, so I got to understand how we, 'cause you, you mentioned taxonomy.
I think that's really, really important because the more, particularly these public facing things I do, I find myself saying, and I don't find a way around it what we are today, you know, saying what we are calling today artificial intelligence, right? Because taxonomy's really important, it shapes how we think about things a hundred percent. And just, just this morning on another Techron gang thing that's gonna air the, the, the first day of RSA, uh, next Monday is you, you know, talking, talking this through.
It's, it's basically, you know, what, what we are currently calling artificial intelligence. I said in that segment, and maybe you can correct me on this one, but I really see as pattern matching at scale, right? You know, then it's, 'cause it's, it can do large language models because it can take just an enormous, that enormous quantity of combinations of words and make sense out of 'em and turn it into binary ones and zeros.
And they act on it as a computer system. And, but it can't do all sorts of other things. I mean, those two words, artificial and intelligence, are wrong to start with and always have been for decades, for Eliza and everything else.
'cause it's neither artificial nor intelligent. Yeah. Well, yeah, actually, and, and I agree on, I agree on the first one.
I think where we're at now with things like mixture of experts, models and, and just some of the ways that you can hook, um, different, you know, ai, machine learning, whatever you wanna call them, models together to, to, you know, basically mimic intelligence within a certain domain. I think that that's, that's approaching, you know, something that I would just over a beer in a pub thinking it through, through, through that lens would, you know, consider to be kind of artificially intelligent in terms of its capability. It's trained by human data, it's, it's programmed by people, all those different things, but it's operating in a way that is starting to approach it, it kind of being able to make novel decisions, if that makes sense.
Um, but for the better part, yeah, it's just like it's machine learning on steroids. I think the reason that we, we called it, we called it artificial intelligence, um, you know, partly like marketers like that term and, and VCs and, and the street like that term. So there was definitely, I think a, you know, a market pull in that direction.
Um, but when you look at some of the definitions of what artificial intelligence means historically, it's, it's, you know, the ability to interact with a computer as though it's a human. Which in reality, like we've been doing that with Google through an LP for a long time now. There's different variations of that that you could argue already exists.
This was just like a, it's designed to be human and it's interacting with whoever wants to talk to it in a way that mimics a human is reaction. I think that was the, the user experience shift. And I think that kind of prompted some of the, some of the blur in the taxonomy.
Um, but yeah, I totally agree. Like words mean things like this is a real, this is actually a major problem in the policy space, um, kind of globally at the moment. Um, because you talk about issues of like policy harmonization between, you know, different western countries trying to figure out what, you know, the, the sharp edges might be between western policy and, and you know, adversarial policy, all those different things.
Um, this whole thing of like, when we talk about ai, like forget about tool target threat when we talk about AI security, like what do we mean when we say ai? Like how do we actually, how do we actually like, for the sake of writing policy that's gonna end up forming law, um, or end up forming regulation that people like operate their businesses off and get fines based on and go to jail based on, and all those other things, you know, at some point in the future, like that matters a lot. Um, so yeah, there's a lot of very, I mean, I think we should probably just feed that question into, uh, into, you know, grok deep Sea and chat GPT and then, you know, sort of sum the answers up and figure out where we go from there.
Perhaps Whi whi which, which I think is a steering point is, uh, I is, is interestingly probably fruit, right? You know, and, and again, since last year, you know, I'm, I just tend not to be an early adopter anymore. If I ever was sure I watched things move along.
And when I think they get to a certain point, I start using them mm-hmm. For my own purpose, just to see how it works, right? Yeah.
And I hadn't, you know, I hadn't, uh, I think a year ago maybe I played with chat T-P-T-P-T-A little bit or whatnot. Um, but now I have it on my phone. I use it all the time.
And actually going to Google and finding the three words that maybe come close as opposed to just speaking to this bloody thing, you know, inaccurately and, and you know, and it, so it's on the, the two sides of this usefulness is fantastic. Just saves me bloody time. Yeah.
To the point that that, that I recommended to, you know, to multiple friends that I know who are, you know, having extreme hard times at homelessness, right. You know, if you're out on the street, what do you need? You need to talk to somebody now, a person's advice, it's gonna be accurate and very good, but it's something to start with.
Yep. And it gives you that much that fast and, you know, so it's, so it's gotten just practical in everyday uses in, in, just in replacing Google and things that we're used to, you know, looking for information. And, and on the, the, the second part of that though is get your thoughts on this because I love looking for this.
Where are the errors? Where are they messing up? 'cause you can feel the Oh yeah.
You know, the, the system behind it by what it gets wrong and why it gets wrong in those patterns. Um, yeah, no, yeah, yeah. No, a hundred percent.
And, and I mean, I think that's, that's the part where this, you know, I, I, I got pretty involved in some of the safety. It's a really interesting space. 'cause there was, you know, when, when AI first dropped, there was a, a stop the training until we figured out how to regulate this stuff.
Kind of letter that went out and, and I got asked to sign it and I said, I actually said no because it's like, listen, this is actually great power technology. So if you abstract back up to, to like a international relations level with this stuff, um, there is gonna be effectively an arms race on supremacy when it comes to, to AI and to put the brakes on advancement based on safety. Like, it was a hard thing to do because as a, you know, as a dad, as a husband, as a human, that side of me is like, yeah, we should probably think about stuff like that.
'cause it seems like a good idea. But then thinking about it at the system level, the international relations level, it's like, that's actually not gonna work. Um, that's gonna put us at a tremendous disadvantage in the west if we, if we do that.
And, um, yeah, that turned out to be pretty accurate when you look at, you know, some of the, um, some of the, like the timing of some of the moves with deep seek and, and some of the, um, like ways that I think that was, you know, potentially intended to have more of an impact on the American Stock Exchange than it was on the technology environment at the time. And, and in terms of how it was released, right? So there's all of these different system level issues that are popping up.
You know, going back to like the integrity of the system that you're working with. I feel like that's sort of got lost in the process a lot. Like pe-people, you know, I think folks that have been using, or that start using, um, large language models as their replacement Google, um, or their replacement search engine du jo, right?
Um, not to get too vendor friendly with the thing, but you get what I mean. Um, there is a suspension of, like, to me there was a suspension of critical thinking already in progress, kind of prompted by social media tied to machine learning that, you know, you can look back and sort of see starting to show up in like 2010 to through 2012. And it kind of went from there that I think AI is sort of accelerating this idea of like, you know what the computers know, I'll just ask them and trust the answer based on whatever I get back.
Um, I think you've gotta be really deliberate as a human at this point in history to care about backchecking, um, and, and, and to care about like where things are coming from. Like what is the system that's generating this? Like if I, I actually did this at home.
If you load up deep seek, um, you know, an EU trained model and an American trained model in, in like a home lab, and then ask them all questions about what they see as the future of, of global order, um, you know, 1, 2, 5, 10, 20 years, they'll all give you answers. And if you sort of start to dig into that, you can see that there's incredible bias in each of those models that's very different. Which makes sense.
'cause they're from different parts of the world, right? So like, yeah, there's all of this stuff where it's just, we're just kind of consuming it as a population. Um, that, again, it's one of those things where I don't necessarily have a good answer for how to, how to slow that down or prevent it, but I do, I do worry about the suspension of critical thinking.
I, I do worry about kind of the delegation of creativity, um, you know, just different sort of impacts on, on how we think as a species going forward. And, you know, we'll see how that sort of sort of thing plays out. But I think we've seen some evidence of that over the past 12, 24 months even.
Right. And I can't, you know, I can't, uh, can't and have no, uh, uh, interest in denying any of that. Right.
You know, I, but there's a, however, right, and this sort of comes into the theme of this, this show, right? And, and like this iterative thing I keep looking at in life is when there's, you know, quite often you see some commonly held, uh, belief of a future that's like 99% likely. Like we all, everybody agrees 90, that's pretty well gonna happen.
Yeah. And some bad thing, you know, from, you know, my early childhood, you know, the, you know, I, I grew up expecting to be, you know, growing up among the, the, the rubble and leading a, a radioactive survivor group and so forth. Um, and who's to say that wasn't most likely, you know, maybe, you know, that really was 70% likely, but 30% unlikely sometimes happens.
Yeah. Sometimes 1% unlikely happens. Right?
And that's the, the, in my experience, that's the thing to at least shoot for if you can see, you know, looming problems, you know, keep looking at the gap where, where they might not be. And so going down that path, I put perhaps an un unwanted amount of, of faith and trust in practical application of theory and, and science and so forth. And there's nothing like running our lives, running our businesses, you know, running security systems that makes us actually implement things and argue them out and put them in place and see, see them work and down the paths of cybersecurity, the things we need, you know, to have supply chain 30 years from now, maybe three years from now, you know, where my thing even works at all, you know, means that at some point in the future we have to have reliable systems that can move in, you know, information in near real time across many individual organizational and jurisdictional boundaries.
And all of the policies along the way need to be interpreted accurately enough Yeah. For the use of that information. Yep.
I can see that spot, you know, coming in, in the future. And it's not 300 years from now, I said 30, maybe it's 30, it's not quite three, except maybe in some sectors, maybe it really is three depending on the condition we're living in, in three year. And I think we could build that.
Yeah. Which will, you know, we look at the, you know, the, the position of our future selves, you know, 10 years from now when we're standing here with the answer, we know 'cause we've already built it or at what, whatever point it is, what is it we are going to have already known? What is it we are going to have already figured out?
Yeah. And I think, you know, wrapping this into some sort, sort of form of a question, I guess looking forward, I think the practical application of these things in, for example, security, you know, where I can take this A-I-L-L-M thing and process the massive amount of information that I could never consider before and get to a reasonably workable, mostly correct. Professionally handled to your, to your point about critical thinking, not something that anybody's gonna read and say, oh, I'll act on that, but a reasonably pared down a thing that a human being can use.
Yeah. It almost has to be not Yeah, no, I like, I, I definitely agree with that, especially when you're talking about, you know, scaled systems. I, I, I think some of the concern stuff I was, I was calling out before is, is more in terms of like the individual and, and, and how they kind of interact with the world, right?
If you scale that out or if you build out the need to scale out actually ingesting and interpreting the rest of the world, then it becomes a thing that's almost like an, an a non option at this point in time. Because as, as you know, your average customer, your average consumer in cybersecurity, your average adversary is now using AI to basically reduce their time to success. Um, that's gonna create an asymmetry in your ability to process that and figure out what you're gonna do in response.
And that's just on the detection and response side of things. I think it actually goes to how, how we think about getting proactive and, and trying to protect ourselves as well. 'cause we, we know that we can't get around to all of it.
You know, I think, I think at this point in history, in the security industry, um, there's like two groups of people. There's, there's those that know that we're not gonna get around to fixing everything and, and therefore prioritization becomes the most important thing. And then there's those that are basically still in like ostrich risk management, where it's like, if we just ignore the problem at all, it'll hopefully go away, which we know doesn't work, but good luck to them.
Um, so this idea of being able to get to that prioritized answer as quickly as possible, no matter what you're doing, uh, I think AI is a tool to, to distill the grunt work and get you to the things that you can actually apply yourself uniquely to as a creative human being. Um, that's what it's good at to me. Like, like anything that sort of satisfies that pattern, to me, those are the things that AI are best at, is best at doing just in general.
Um, so yeah. Right. And it, and it's in this, and I think, you know, I think, you know, I make this, make this statement even more firmly.
I firmly believe, right. You know, that cybersecurity is, is a good model of the, the philosophical angst we go through. Right.
You know, because it's easy to say, well, nothing's gonna gonna change. It's always going to be, it's just the next round. It's just, you know, and if you're in this industry, you know, have been for any time you've been through several, you know, you know, trends and fads and it's all about this, and it's all about that, and it's easy to get cynical and say it's always going to be the next thing.
It's always gonna be this way. Right. But that begs the question, you know, that, that there's only, you know, binary conditions for things, right?
The things can't get better or worse, they can only be good or bad, and I don't believe that's the case. Yeah, yeah, Yeah. Yeah.
I fully agree. I look at cybersecurity, you know, as relatively well baked. I think we're 80%, 70, 80% along the way of, of building the tools we need to build secure cyber systems, right.
And they're mostly generally applied in reasonable, you know, everything from firewalls to encryption and all the basic tools are generally out there. So if you're a a adversary, you've gotta be relatively good these days. And you know, the old days of just being able to have a connection to any host and just spamming with passwords until it cracks, those are pretty, pretty well over.
We've raised that bar In the Yeah, I think I, I think for the, I think for the better part, I do think I'd, I'd sort of disagree with that a little bit in the, the adversary is adapting and they're changing their techniques to kind of match that 'cause to, to me that sort of sums up the nature of what we do. I, I'm not a pessimist in terms of like, oh, nothing's gonna change. It's all, all staying the same.
But I am, I I think a, a kind of a realist in the sense that like, you know, someone leaving their front door open and then someone else coming along and exploiting that, um, is a, is a phenomena that predates the internet by a couple of thousand years. Right. Um, 'cause like bad guys gotta do, they gotta, they gotta eat.
And you know, folks, no matter how security conscious or well-intentioned or other, otherwise they are, are gonna occasionally do the equivalent of leaving the front door open when they shouldn't. So like this combination of, of human behaviors and human incentives, I think, you know, for as long as that exists, there'll be, there'll be crime and there'll be a need for us to find our way into the middle to be able to kind of mitigate that. Right.
Um, and you know, you, you look at sort of what's happened over the past really five years, but we've started talking about it in the past too. You've got nation states that are opportunistically hosing everything they possibly can to get shells to, to save for later. So you, you know, you flex typhoons, you sell typhoons, your, your initial access brokers out of like Eastern Europe and other parts of the world, um, because it's still possible.
They're, they're out there just going and getting whatever they can. The thing that's interesting to me on the back end of that is that attackers are, are becoming more adaptive with how they make use of that stuff for their end game. So it's not just I need to, you know, break into this network, like bypass this firewall, access this data base, exfiltrate the data, like a simple sort of hack like that, or a straightforward hack like that.
It's, you know, how do I leverage cloud? How do I leverage like data dependencies, third party dependencies issues in the supply chain, like the supply chain connection graph. Like all of these different things that are available to an attacker to get their job done.
Um, and they're getting better at that. Like they, they understand that like, figuring out how to traverse the ecosystem that we've collectively built as an internet at this point in time is kind of their job as the bad guy. Um, and then whatever we throw up as a, as an impediment to them is, is, you know, that's, it's an opportunity to differentiate.
It's an opportunity to, to sort of compete with their, their bad guy peers, so to speak. It's an opportunity to actually, um, step out in front as much as it is a pain in the butt for them. I'm sure.
So, like, there, to me, that's the nature of it, right? And, and you throw AI in on top of that, what you end up with is these, this acceleration of like the oodle loop, you know, the, the like defender does thing, attacker response to thing, and innovates defender recognizes that innovation and figures out how to defend against that. And it just sort of does that, there's a cycle time to that that I think, um, AI accelerates on both sides.
Um, it's definitely accelerating on the, on the attacker side of things and, and, you know, thinking about like the future state where that oodle loop gets kind of too tight for, for us to fit inside in terms of how we think about what we should prioritize defensively. Uh, I can see that coming up as a thing that we need to really have a serious think about over the next couple of years. That kind of point, right?
Yeah. Yeah. And then that's a, a lot of the current day in there, you, I, I basically agree across the board, you know, these are these times, you know, and, and yeah.
You know, I'm trying to say, find a way to say this one thing without making an outright pro, you know, plug for your company out this, but the bug crowd thing, I like that. You know, in our conversation a year ago, there's this evolution, you know, this idea that like, I'm going to have on, I, I'm, I'm big company A, B, C, and I'm gonna have my security team and I'm gonna have and build walls and it'll all be fine. Yeah.
And you build a business off of connecting people with a bunch of lots of folks or, and you know, now, you know, enabling with AI and going down that path. Yeah. And, and I think that's always a thing, right?
And this, you know, AI is gonna replace us, eh, maybe, maybe not. I think it'll enable a lot of people. I mean, I could see everybody working in cybersecurity right now, still not getting bored, but being able to do their jobs better.
But I think the point that, try this analogy, you know, you know, I know the evolutionary analogies could use way too much in this, but I just can't help myself. Sure. And one of the, you know, the dinosaurs versus the mammals is sort of a almost two cartoonish one I like is saber tooth, uh, mammals and apparently evolved eight or nine times, you know, completely unrelated, not genetically related.
This just when conditions are so conducive to, you know, success being for like, being really, really big and having really, really big teeth. Yeah. That's the winning solution.
So if you're alive at that point, you say, that must be the best solution You win. Yeah. But, you know, over time, conditions change at all.
Turns out those are really fragile, you know, species, they, they die off and they're replaced by smaller and more resilient, more redundant, uh, systems. And I think so much of what we're used to in information security and cybersecurity as a subset of that, you know, is is is perhaps in a sort of saber-tooth era where the adversary are always a monstrous things and we assume that's the, the, the, the stable model. We're still in a very early ages, right?
Yeah. I spend a lot of time thinking about that. I like, I think that's, like, that thesis is a hundred percent right.
Um, like I, I, I think about that a lot, you know, partly as, as someone who is like in an, at this point in time on an older generation in the industry, right? Like you think about technology generations, like I've, you know, been around for a long time doing this at this point in time, and it's, I mean, honestly, just you To crap it. Let's face it.
Yeah, Go ahead. Just the acceptance of that thought is confronting enough, but then it's like, okay, well what, what are the things that I've, that I have as like baseline assumptions around how this works that are maybe aging out? Um, but then the other side of it to me is like, you know, the, the, like Gen x gen, sorry, gen, um, Z and gen alpha, like they're gonna inherit this problem.
And everything I've seen from, from like hacking with people and then with watching folks interact on, on the platform and in kind of a collaborative, you know, crowdsource, tacking context is you've got, you know, I like my generation's gonna understand infrastructure and the network layer and, and some of these kind of fundamental plumbing aspects of, of how networks still work today in a way that, um, someone from Gen Alpha or Gen Z probably won't, mostly because they're just not native to it, right? Like, that's not, that's not their, their kind of technological home ground, uh, hometown where they grew up, like they grew up. And the flip side of that is that they've grown, grown up in the interface.
They've grown up looking at business logic, all those different things because everything's so abstracted in terms of their, how they work with technology, therefore, they're more conversant and more native with how to manipulate and how to exploit that stuff than I'll ever be. And we can both learn, you know, the specialty of the other side in some ways. But I've, I've got a theory that like the stuff that you're na you're natively dropped into, like you can have a native command of that because it's just in your DNA at that point, right?
Um, so to me it's sort of, you know, the whole evolutionary thing, all of that. It's like, where does this go? I do think there are primitives, um, that are, that, that basically survive that.
Um, and I mean, I'm talking about like core primitives, um, you know, the idea that like, Like cyber crime, um, or, or, you know, like adversarial cyber behavior is an inherently human problem. Like humans catalyze that problem. Humans are ultimately, if you dig through the root causes responsible for the, the flaws and the vulnerabilities and the design antipas that enable that.
So therefore there's this aspect of human creativity that is sort of necessitated to feed into that gap, because that's just gonna be completely novel every time. Right? Um, yeah.
And then, you know, just, just some of the ideas around like, security should be all about, like, it's an economics problem in a lot of ways. Like, we should make security easy, make secure easy, and make insecure obvious. Um, because folks don't wanna spend money on the thing that they're trying not to do, which is ultimately what getting hacked is, right?
They're trying to spend money and spend their time and deploy the resource on getting the thing done that they want to do. That's like this whole idea of like the economic balance between investing in resilience and defense. It's like businesses don't wanna do that, and capitalism sort of doesn't tell them that they should.
Um, we're not actually structured to reward this stuff. So therefore, as like cybersecurity solution is in a capitalist environment, our job becomes to make as secure as easy as possible for them from an execution and as rational from a cost standpoint. And then to make insecure as obvious as possible so they can figure out, you know, what the priority is, right?
Like that to me is still, you know, I'm talking like an old fart when I go through all that stuff, but to me like that, that those are things that I think were true 40 years ago and are still true today, no matter what generation or what part of the stack you happen to be focused on. Right? Well, there's something you said there that really makes me think about this, you know, then we're nearing the end of our time, right?
So this is that future part. And I think, you know, in as much as anything I said about saber-tooth eras, you know, has any bearing on this, you know, put, put to deposit, right? I think, I think we're, we're approaching the end of, I think the fact that, you know, as you say, you know, working generationally, cross generationally, you know, that's a more mature statement than again, old folks like you.
And I heard and said in the beginning of our careers, which was that old people don't know anything and, you know, right. And those board members are so stupid. I mean, I can't believe they got their jobs.
I told 'em how wrong they were and they didn't gimme the budget. And, and, and so that we're, we're, this entire practice is maturing itself along with the infrastructure we're building and, and we're responsible for securing. And the, and the, I see, you know, there's, you know, it, when I talk about inevitability curves, what I picture in my head is more of a half pipe, like, you know, a a a snowboarding thing.
It's not a straight line. This is a realm of possibility. Think it's less likely up on the sides, but if you get up on the side, now you have a whole new future outta you.
Right? So, you know, don't get my optimism wrong. I may be wrong about this.
Maybe the French revolution didn't work out. Maybe, maybe, I Think you're right. There's like, you know, that truism, like there's two types of fool, the one that says that this is old and therefore good, and the one that says this is new and therefore better.
Like, that's a, that's a old, old truism. And, and like, to me, that's another one of those kind of primitives, right? It's like no, like neither are true.
Like the truth is actually somewhere in the middle. If you can get those two points of view together to collaborate on the problem that they're actually trying to solve, as opposed to like, I'm right. Which is not the problem.
I think we can fuse making sure that people believe that I'm right, um, you know, as individuals as the primary problem to solve, as opposed to like, no, like, why are we even doing this in the first place? It's to make life difficult for the bad guys, and it's to make it easier for people that are trying to do the right thing and trying to do good, you know, in what they're building and all of that stuff. Right.
Well, I, I think, you know, I I, I like, I have always liked the economic, uh, um, drivers in cybersecurity, right? You know, much to the consternation all my friends and peers, right? Because I see it as literally an evolutionary thing, a nutrient gradient, right?
This, these are the energy molecules that these, that this, you know, project, this life form, this biome, this ecology, this ecosystem we're creating, use this to build the things we want to build so we can be distasteful about the source of money. But unless where, where it has money that's, you know, it's a Petri dish. Yeah, yeah, exactly.
And, and the, you know, and, and I think, I think I hope, you know, the economic drivers, you know, ahead of us, you know, in the relatively near term in the next five years and during this decade, will continue to drive us towards more positive outcomes and, and, and easing some of the consistent, whether the, you know, hacker infrastructure problems or hack our brains problems. Um, Yeah. Yeah.
I, I mean I, I know we're bumping up on time, but with, with the inevitability curve side of it and, and, you know, throwing the ball out 10 years time, I, I do think some of the fundamental assumptions that we apply to, to a flat global internet, uh, probably gonna get challenged fairly heavily over the next period of time. And at that point, you know, the role of networking, the role of the interface and, and kind of the nature of those abstractions becomes pretty important from a security, confidentiality, integrity standpoint going back to where we started. Right.
Um, you know, I do think that, um, I I, I, it's one of the things I love most about cybersecurity entrepreneurs. Like we can sort of look at things and realize how deeply broken a lot of the infrastructure, the, the world relies on is, and how much of a miracle it is that anything works at all to begin with. Um, and still have this sense of optimism around a brighter future.
And like being able to actually look at, take some of those problems and turn them into things that are more resilient that are, you know, better just in general. So, you know, I I, I refuse to budge from that overall point of view, but I do think that, yeah, there, there's some, there's a lot of black swans circling the lake, um, at the moment. And I think there's, there's some starting to land in various places and just thinking about like what that does in terms of accelerating shifts in, in how the internet works, how we think about like our overall cyber space, um, and, and then what we're doing around securing it.
I think that's a really good thing for people to put their futurist cap on and think about a bit and not get too gloomy about. 'cause some of it gets scary when you, when you think it through, but if you sort of come back to this idea of no, as a species we're resilient, we go forward, we've got solutions and we've got this shared sense of ownership and wanting to, you know, work for the good of the collective as well as for ourselves. Um, you throw the hacker spirit on top of that.
I think we can come up with some pretty cool solutions as we go forward. But yeah, it's, um, it's a good one to think through and actually game out a little bit. I think.
Well, I, I can't think of a better way to end it, uh, than that, you know, throwing the hacker, uh, spirit on top of it. 'cause I think we, we have to, and we do. It's a human thing to do.
It is not just you and I, you know, all of you out there. You don't think you're hackers. You're hackers.
Yeah. You know, think about how you got through last week and that, that thing you did that wasn't supposed to work that way, but you figured it out and you did It. Yep.
You tipped it upside down, you saw what fall out, fell out, and then you reassembled it into what you wanted and needed. Like that to me is the hacker spirit. Yeah.
Well, thank you for your hacker spirit. Thanks for your friendship. All the work you've done over the years for Wayne, like today.
Absolutely. Good to chat. Thank you.
Appreciate it. See you too. And everyone else out there.
Thank you very much. Uh, take care of yourselves. We'll see you again on another episode of the Inevitability Curve.
This is Textron tv.



