Techstrong TV June 19, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, so there's a shadow cyber war shadowing this Israeli Iranian conflict. We're gonna talk about it. You're watching Textron Gang.
Hey everyone, happy Thursday, and welcome to Textron Gang. We've got a great show lined up for you. We've got some important things we want to talk about today, and we've got some important people to talk about it with.
Let me introduce you to our gang line up for today. First of all, I'm happy to introduce someone making his debut on our text on gang, but he's no stranger. If you've been in the world of cyber and DevOps and DevSecOps, I, I've known the man for a long time and thrilled to have him on here.
Let me introduce you to John Morello. Hey, John, how are you? Hey, Alan.
Good to see you again, and thanks for, thanks for having me. My pleasure. John, since it's your first time on, give people a little, be beyond what I said.
Give him a little bit of who John More is. Sure. So, like you said, I've been, uh, doing this cyber stuff for, uh, I guess 25 years at this point, going back to, uh, many years at Microsoft in the two, early two thousands, uh, then probably we're best known for, uh, the company we had in 2015 Twistlock that kind of started the whole container security world.
And we sold Twistlock to Palo in, uh, 2019. Uh, and we have a company now minimus, uh, that basically helps organizations reduce the risks in their, uh, containerized environments by giving them purposeful built, uh, images that reduce the number of vulnerabilities by 95 to 98%. So really dramatic changes in, in like their risk posture.
Uh, so you can see more of that and try 'em out at minimus io. But appreciate you having us all, Alex. Absolutely.
I interviewed Minims. Great, great, great product there. John, you're usually CTO.
Are you CTO at minimus? Is that I am, yeah. We, we all, we all have our little, uh, roles that we place.
Yeah, no, that's, that's your way baby Is the Yep. De is the VP of r and d. Same as usual.
Yep. Good for you. All right.
Moving on from John, our, we have another resident cyber expert we're thrilled to have on. She writes at Security Boulevard, as well as just really well known in the cyber media world. Our friend Terry Robinson.
Hey, Terry, how are you? Good. How are you doing this morning?
I'm happy to be here. Happy to be here, and glad to have you on. Thank you.
Glad To be here. So, moving from the East coast to the West coast, our, our Silicon Valley man on the scene. John Schwartz.
Hey, John, how are you? I'm good. How's it going?
It great to be here. I'm looking forward to the show. I'm looking forward to hearing what you have to say.
Hmm. And now we'll go. Well, there's no joy in Harrisonville today.
The mighty Yankees have struck out again. Is it about 30 innings without a run now, Mike? Yeah, I think it's some sort of contagious disease that's got the whole offense suffering.
Four, nothing coming off a two a one. Nothing. A two, nothing.
It's kind of disgusting. Let me just say that down here in Florida land, we're real happy to be celebrating our hometown Panthers winning a Stanley Cup. The second in a row, I, let me just, for the record, I'm a New York Rangers fan, but look, I live down here.
You gotta give the boys credit two Stanley Cups in a row. Not bad. So go Panthers.
Um, It's, it, it's the frigging middle of June, and we're playing hockey. How silly is Brett? It's South Florida and we're playing hockey.
It's silly to begin with, but what do you want? Anyway, let's get into our show real quick here. Right.
So, Mike, as I say, I teased in the opening, you know, there's a, there's a shadow cyber war of kind of ghosting or following this, the hot war between Israel and Iran. What do we got? Yeah, Terry has a story about the hacktivist part of this equation, but, um, there's also cyber espionage and all kinds of attacks on critical infrastructure.
And Terry, I guess, has this just kind of emerged as a, as a new front that needs to be battled in the same way we have more on sea and more in the air and war in the ground. There's war in cyber, So no sooner had Israel launched its strikes against the, you know, um, Iran nuclear infrastructure than the cyber theater opened up. Right.
And I think that, um, at to, to no one's surprise that that happens. I think that, of course, um, we need to start treating that, um, like its own, its own theater and have the defenses shored up, um, before this stuff even gets started. Uh, Radware was the one that first observed sort of an uptick in, um, activity and telegram channels, and they're, you know, from the actors that are sympathetic to Iran.
Um, and, but this is, this battle in cyber with these two countries is not new. You go all the way back to stucks net, um, was that, gee, 2010, um, when the Stuxnet worm was deployed to hobble the centrifuge critical to the, to Iran's nuclear program, and then DDoS attacks, uh, just a decade ago on US financial institutions. So, um, in, in early indications, there were claims by the Arabian ghost that Israeli radio stations had been shut down.
I think the one that it sort of concerned me and, and made me wonder why they weren't, their defenses weren't showing up, is that the Mossad website was shuttered. So I, I'm not sure why these things haven't been more protected. Um, in addition to sort of this disruption and, um, some of the damage that they can do, um, there's a huge disinformation campaign already underway, and as we know, the disinformation campaigns are extremely dangerous these days.
So John Morello, um, is the cyber community, uh, is the cybersecurity community watching this closely? Because there's things to be learned here. There's new tactics and techniques, and this will become, uh, something of an example that we cite for many years to come.
Yeah, I mean, I think there's, you know, anytime you have a major geopolitical event like this, and there's cyber response and cyber acts that are occurring as part of it, there's always an opportunity to large, just as there is on the, you know, kinetic battlefield. I mean, I think one of the things that's been most amazing, uh, in these conflicts in, in both Iran and in Ukraine in the past, uh, just few weeks, has been, uh, the use of drones as a way to really asymmetrically, uh, do things that, you know, historically would've required, you know, substantially more risks, substantially more military hardware and planning and so forth. But I mean, the, the notion that, like, for example, with Ukraine being able to disable, you know, a third depending on, you know, the numbers that, that you believe disable or destroy a third of, of Russia strategic, uh, you know, aircraft.
Uh, and with Israel potentially destroying substantial amounts of ballistic missiles on the ground using drones. And the fact that those drones were not launched from the territory of the attacker, but rather were launched from within the territory of the attack, I think is a really amazing, uh, thing. And frankly, something that, that concerns me a lot as an American, I mean, if you think about just having, like the free society that we do in the US where it's relatively easy to travel around, it's relatively easy to, you know, to import materials.
It's relatively easy to buy properties. You know, you can even, um, easily imagine adversaries, you know, purchasing properties, you know, close to American military bases and spending years developing facilities and, and capabilities for drones and be able to do things in the US homeland that historically, you know, the, the oceans had basically shielded us from. So I think there's a lot to learn from the cyber standpoint.
Um, you know, I think one of the things that's been interesting to me with it is there has been less obvious, uh, actions on the cyber side, which I don't think implies that there have been less actions, maybe just less things that have been visible. I think what, what what we don't know is maybe all those things that have occurred, you know, that have not yet made it into reporting like what Terry's done or not yet made it into the, uh, historical records that we'll find out years hints from now, which probably were involved in Israel having such, you know, exquisite intelligence about the locations of Iranian leadership. You know, there's a good chance cyber had a role in that.
Um, and, you know, there's really no telling what else cyber is doing to be able to inform Israeli war planning around the location of ballistic missiles, the status of the Iranian nuclear program, you know, and, and other activities that, that directly result in actual, like, kinetic decisions about how they go to, to battle. So, um, I think Terry's reporting is really interesting, but I think there's probably a lot more that we'll all learn in the coming years that, that it's gonna reveal more about how cyber was so instrumental in All of this. Yeah.
That blend of cyber and kinetic is, is gonna be something to, you know, to watch going forward. I honestly believe that they're codependent at this point. Um, and they're working in tandem.
Yeah. So, um, I think it will be interesting to see what, uh, kinds of actions emerge later on. Hopefully we find it out, out about 'em sooner rather than, than, uh, than later.
But I, I tend to think it'll take a while. But, but let me let, let's be clear, John, you mentioned the Ukrainian conflict. The, the fact of the matter is we've seen the cyber theater play a role.
I, I guess the first time I saw it that I remember was when, uh, Russia was going after the Republic of Georgia, right? They, they took out, they kind of instigated a coup and took out the President Shakia Valley or whatever his name was. They, they really, they shut down George's internet basically.
Uh, they also did it, I think in Chechnya when, when they had a, an uprising there. So Russia's been at a, a leader in this a while. Um, but I think in every conflict we're seeing cyber plays a role and there's, there's offensive and defensive aspects of it.
John, you mentioned intelligence gathering. I'm sure, I'm sure they, you know, they had find my iPhones on, on some of these Iranian leaders, you know, um, it's crazy when you think about it, you know, and, and then when you look though at the two combatants here, you look at Iran, you look at Israel, yes, there are Iranian hacktivists that are funded by Iran. And you know, they're, they're not slouches.
They're not slouches. I don't think if they, they didn't take down the Mossad site unless the Mossad site wanted to be taken down, because Israel had the advantage of surprise here. They knew what they were doing, so they probably had a chance to shore up before the attack.
On the other side, you're talking about Israel, the people behind unit 8,200 or whatever, 8,600 talking about the people who like, have invented a lot of offensive cybersecurity, though, let's not think that the NSA are, are choir boys, they're not. Right. Probably us is as guilty as anyone or as thick mid as anyone else.
I I, I hope so. As an American citizen, yeah, I hope that's The case. I mean, everything I've always learned, and, you know, having also been John in cyber 25, 30 years and sold to a lot of the agencies over the years before I got into this, the NSA still probably the premier outfit in the world, right?
And, uh, but the Israelis are no slouch, hence the whole Israeli cybersecurity industry. So you've gotta assume that they've been doing offensive and defensive type of, of operations that are, you know, thick and full there. Um, but, but let me put my bow around all of this.
Modern warfare is cyber warfare. Women's rights are human rights, modern warfare. Warfare is cyber warfare too.
And any, any combatant who doesn't put that into their mix is seeding out some really big territory. I suspect this has already gone global too, right? Because you gotta figure that Russia and North Korea are helping Iran and the NSA here is probably helping out Israel.
And so I don't, the con the physical con, I, I don't know, Mike, I don't know. Because you know what, if you are Russia and, and it's, and you could see it by Russia's public actions as well, you may not wanna, you may not want to get that involved in, uh, in this what certainly not leaving any fingerprints. No, but I, I'll, I'll also bring up another point that I think is, is like really, uh, probably very directly relevant to the IT backgrounds that, you know, I think all of us had, probably a lot of the audience has with you too, is, you know, we talk a lot about supply chain security and software supply chain security.
You know, you can see kind of the physical manifestation of that in at least a cyber adjacent way with, with what, uh, Israel did with Hezbollah and the pagers and, you know, the VHFA is, which was honestly like an in incredible operation. I mean, just like stuff like something from us, I mean, truly, truly, but it also really makes, I mean like, as, as somebody who's like, you know, very much into the industry, our whole business is about, you know, providing customers with secure software, images that include all this open source stuff. You know, one of the things that I think about often with this, and that there's not really easy answers to, is there are so many, uh, individual open source packages, libraries, projects, whatever you wanna refer to them as, that are fundamental to everybody's usage of the modern internet infrastructure as we know it.
And many of those projects are not things that are common sort of household or industry names. You know, like every, if I said Nginx, everybody knows that everybody's used that and so forth. But there's probably, you know, a few dozen individual tiny little components that go into making an n engine X build work that are much lesser known projects that might be maintained by, you know, one or just a small number of people that don't really have very much name recognition at all.
And, you know, you saw, I believe it was maybe a year or so ago with, uh, an example of, you know, what I believe was, was likely some nation state actor trying to compromise a, a, a compression library that was widely used in a very, like, um, you know, I think very, uh, skillful way that was not like an obvious kind of compromise that they were trying to poison that supply chain very far upstream so they could emanate down into lots of other applications that use that. One of the things that really concerns me is our ability as a, you know, frankly as a society, I would say to, uh, to, you know, that we're both reliant completely in our, in our just normal operation of all these systems that everybody, uh, uses that, you know, are frankly maintained as, as almost like hobbyist things in the open source. And it's very difficult to know, in many cases, are the people that contribute updates to those things, are they doing so like, you know, in a good faith manner to improve that?
Or, you know, are they potentially working for some kind of nation state or just motivated, you know, uh, you know, kind of hacktivist sort of actor there to do something to poison it? And you know, so far we haven't seen tremendous amounts of examples of that occurring other than like the one that I mentioned, and, and probably a few others. But I also always wonder if you really got into a situation where a, a major player in this, a Russia, China, United States, for example, felt really existentially threatened, what other cyber weapons would come out that we don't know about yet that are out there that would be very difficult for organizations to defend against.
'cause they already were running that stuff inside their environments. And like I said, there's no easy answers to that, but it's something that, you know, being in this space, being very intimate in this space, it's something that really I think about a lot and concerns me a lot. 'cause there's not easy answers for how do we reap the benefits of this kind of open source ecosystem while still being able to protect against that kind of threat.
You know, with, with this asymmetrical warfare, there's like a sidebar going on that's kind of interesting to me that applies to Silicon Valley in the beltway. And there's this emergence of, of AI and these AI contracts that are being awarded by the federal government for cyber defense purposes. So Monday OpenAI has something called OpenAI for Government Initiative, and they got their first big contract from the Pentagon on Monday, one year, $200 million.
So their AI tools are gonna be used for, for, for proactive cyber defense. Um, they also have a partnership with and oral, uh, to improve our defense systems. And it, it's interesting too that there, that we have, uh, yet another partnership between Anthropic AWS and Palantir to provide Claude models to intelligence defense agencies.
So you're starting to see these, these companies and, and for open ai, they really are, want to concentrate as much on government contracts as the consumer side. And so we're starting to see that development of that, that angle as well. And, um, it's gonna be lucrative and it's gain gaining a lot of attention and a lot of interest from AI companies.
It's gonna get scary because the bad guys are using LLMs to take vulnerability and create an exploit in a matter of minutes. And the attacks are gonna be essentially in real time. And we're not really set up to do that kind of defense.
So, you know, and maybe Amazon is, but most companies are still running around, you know, trying to manually update firewall rules and it's just gonna be crazy. Let me, let me bring it back to the Iranian Israeli conflict. You know, there's a difference between sympathetic hacktivist and the state itself and the hacktivists are nice, but it kind of sounds like Matthew Broderick to me.
Let's play thermonuclear war versus trained professional cyber warfare cyber soldiers. And, and I think the results you're seeing in the field probably point to the difference between them. Um, they're facing the website.
I mean, we're hearing reports that the Iranian, uh, the internet in Iran is, is very much on and off now. Is that the Iranian government shutting it down so that people don't shutting down descent perhaps, or shutting down, you know, information that could lead to Israel and and used for targeting and so forth? Or is it the Israelis shutting down the internet to affect Iranian communications?
Little or both. Maybe Ab absent. I mean, I guess that points to another problem.
It's kinda like the democratization of, of, uh, cyber warfare for less of a, for lack of a better term, um, has certainly made that a more complicated, um, picture, hasn't it? Like who's doing what to whom is the government involved? Yeah, you don't, you know, you don't know who the good guys, the bad guys and what the good guys consider good and what the bad guys consider bad.
It's all, it's all cyber to me. Anyway. Hey, let's take a break.
We, we've kind of gone overboard overtime on this one. We're gonna come back and let's talk about MCCs and DevOps. You're watching Techron Gang.
Hey folks, we're back. And as Alan alluded, we're gonna shift gears a little bit, maybe something quite not as serious, but definitely important and profound. There's this thing called the model context Protocol created philanthropic, and it basically provides a, a bi-directional link for AI agents to communicate and access data.
And now we're starting to see this in DevOps. New Relic and CloudBees are both at the forefront of kind of putting together early previews of this. But Alan, we've been around this block for a long time.
I think I'm gonna see, like every vendor in the planet is suddenly gonna have an MP server. You know, Mike, it's funny, I you are not kidding. I think I've already, it, it, you know, in this week alone, I've probably done four interviews around companies rolling cps, not counting New Relic and, and CloudBees, but what is it point to, right?
It, it points to everybody wants to cash in or at least be perceived as riding the agent AI wave. And, you know, what does it really mean? And I, I have this problem.
Where do we draw the line between agents and APIs, right? Or do agents now manipulate APIs or master APIs or use APIs? I don't know.
But certainly mc here, here's an an interesting thing. Anthropic floated this MCP protocol, right? And it has become the defacto standard now for agents talking to agents.
And that's why everyone's adopting building A MCP in, into their platform. Now, I, I see it a lot with the observability players for sure, right? And, and so New Relic to me was with all due respect, a little bit of a, of a me too.
I think CloudBees is out ahead. I I haven't seen GitLab and maybe C No, I think Jfr, JFR OOG has MCP, uh, in their, in their stuff. But certainly all of the DevOps players are gonna have MCP, uh, availability because it, you know, we spoke in cyber about the, the pi, the cyber store.
We were talking about software supply chains and stuff. That's what DevOps is focused on. Now, the the software supply chain, the CICD pipeline, and you're going to, you know, you're gonna have agents and APIs throughout this, and you, you need that m you know, if MCP is the lingo franca of, of this, you, you need to have that built in.
There is this debate about what exactly MCP is, because some people would say it's a variation of an API written in JSON. And, um, you know, and that's what makes it accessible. Other folks say it's a, something that sits between an API and a full boat connector, and it provides that level of integration.
But John Morello, um, are these gonna be like big fat new rich targets for cyber attacks? Because it seems like that would be the first place to go if I was a bad Guy. Well, I mean, I think, I think attackers like always naturally follow like the, the places where there is the most uncertainty and chaos and churn in organizations.
'cause usually those are the things that are least understood and most susceptible and, you know, most frequently changing. And so because of that, there's more opportunities, you know, to find potential weaknesses and, and vulnerabilities in that. Um, I, I do think it's interesting in this space that you, you know, like you see almost every new major wave of technology, Colin, following similar adoption characteristics.
And I think about, like, this is very akin to when containers really started coming out and, you know, the, the mid 2010s and people started using them and everybody, you know, was using Docker. And there was a few other like management frameworks that were like a big deal at the time. You had, um, you know, DCOS and you had Docker Swarm and you had Kubernetes and so forth.
But, but usually in these things, the industry sort of on its own, just as a, you know, free market, uh, evolutionary, uh, uh, path tends to, to converge around one set of standards for manageability. When you've got all these kind of like, diversity of, of implementations. You know, obviously in the container world that's been Kubernetes, MCP seems to be that around how do you programmatically connect applications to models.
Um, but I think the thing that's, that's really interesting about this from a cyber standpoint is everybody to Alan's point has rushed to say like, oh, we have Ancp two, right? How, how high quality that's been done, how rigorous that's, you know, it's been, you know, really threat modeled and tested and thoughtfully built and so forth. I think it's, it'd be be wise for people to have some skepticism about that, because to build something that's potentially so complex and sophisticated and enables access to data and resources that are, are not just complex and high value and sophisticated, but actually can take actions, you know, on their behalf, uh, is, is kind of a different level of threat than we've really seen before.
You know, like if, if you think about the securing technology, really up until the prevalence of, of all these, uh, AI capabilities that have, have really become mainstream over the past couple of years, you were typically saying like, I want to protect access to my data or to computing resources that if an attacker took control of them, they would still have to manipulate and, you know, run commands from them and basically act as though they were the owner of that resource. You know, but it was the attacker that was telling the compromise resource what to do. They be that to exfiltrate data or to be used as a node in some sort of dos attack or whatever you have for the first time.
Now, though, something I think is really interesting in that none of us really fully understand at this point, which is you can have attackers compromise that MCP layer and potentially through that access layer, be able to interact with models that can take unknown actions on their behalf. You know, of course, if they give it a sufficiently detailed and focused prompt, they can control that a lot, but you don't really necessarily know what it's going to do, not, not in nearly as a deterministic manner as as you did in the past. Uh, and so I think for, you know, for everybody in this industry, it's, it's a, a whole new world of potential risks and threats and scenarios to consider.
Uh, and frankly, I don't think anybody has really an answer for it, because we haven't seen enough of it in reality to know, like, what does that mean? What are some of the things that people are gonna exploit with it? But it's certainly an area that, uh, you know, that's gonna be very interesting to see how it develops in the, over the next few years.
Because like I say, it's, it's really the first time I think that a cyber risk could expose potentially open-ended, unknown potential downstream effects beyond what even the attacker themselves intends to do. Mm-hmm. Terry Robinson, how many days or weeks away are we from the great MCP server misconfiguration Crisis?
That's what I was actually just thinking about. I'd say minutes, Mike. Um, this just, just tore creates greater potential for misconfigurations.
You know, that's a, that's a particular source spot for me. I don't wanna say so spot, but I get annoyed every time I have to write about a misconfiguration. Um, but, but I think, uh, probably what John says, you know, aggravates that, right?
That sort of rush to market or rush to, you know, get these things out there and then that just makes the, the, the possibility of misconfigurations that much higher and that much quicker. I, I say minutes, I say it's happening as we speak right now, You know, let me, let me throw something else at it, the panel and take your thoughts on this. Are we rushing MCP, right?
Everybody's talking about agents, everybody, you know, we're all gonna have all of these agents. I've got agent 86, 99, 0 7, 0 0 7, all of these agents, and we're building these MCCs to handle all of these agents. But are we building like a lot of dark fiber, like level three did in 2001 when the internet boom kind of had died down and we overbuilt capacity.
When are we really going to use these cps? When, when will we really run of these agents going mainstream? I know everybody.
And that may sound, what's the word, treasonous in, in today's tech world, right? Because we're all about the agents. Actually, Alan, I very much, uh, agree with you and from the standpoint of like, I think it's good to have a bit of a, like a reality check and some skepticism on it.
Um, I can tell you, it's just being like, you know, in the venture backed world for the past, uh, decade now, the amount of hype and noise, um, that surrounds anything related to AI today, uh, is, is kind of overwhelming. And, you know, the, the money is, is flowing to, to kind of, for you to get any of the money that flows through that VC machine, you, you have to have some kind of story around ai. Um, I think, you know, all of us have used various ais, particularly like LLM type of implementations, you know, in our daily lives and work lives and so forth.
There's amazing stuff that they can do. I mean, like, there, it's, I'm not at all downplaying the capabilities of it, um, but I think that there's also a lot of sort of, uh, breathless, uh, talk that's probably not really realistic, um, today, you know, like, you know, you hear, I, I think the philanthropic CEO had some quote the other day that like, you know, uh, AI was gonna result in like 80% unemployment in two years or something like that. You know, like there's, there's aspects of this that, that Yeah.
He said, yeah, just he basically had John, yeah, basically he said whether it was like half the white collar jobs are gonna be lost within two to five years, but then the caveat always is that they're fundraising right now. So I think he's growing out as much fear as possible. Right, Exactly.
Well, I just think, like, to me, Elise, I think a lot back to like the, the very late nineties, early two thousands with the internet itself, where like there was similar predictions, like everything was gonna change and so forth, and obviously like it did, it's like a fundamental innovation in human society. And I think AI is the same thing, but you know, like the idea that that's all gonna happen like in the next two years, and that like, everything just kind of like magically gets solved and, um, you know, I I think it's probably unrealistic. I think much like the internet, you'll see like, you know, 10 years from now, five years from now even.
Yeah, exactly. Look, I, and there'll things where it's valid really good. Remember John, and you were around then, John, both Johns were around Terry, Mike, you were too, right?
com days, you know, you'd put together a PowerPoint of a business model, and you would claim in the PowerPoint that your present value was seven $70 million, and you're looking to do a post raise at a hundred, you've got no revenue, a business plan, and you lose 10 cents on every dollar you do, but you're gonna make it up in volume, right? And, and that model, you know, internet sch internet, it doesn't work. It's, it, it's, it's against the laws of physics.
And I think there's a lot of that same, what did he call it? Alan Greenspan. Irrational exuberance.
Irrational exuberance. There's a lot of that going around here too. And part of that exuberance is let's get an MCP server in here.
We'll see. Anyway, we're over time on this segment too. It seems we're over time on every segment you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide, our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back with our final block, and it's about a MD versus Nvidia.
And this has been a battle that's been long brewing, but a MD is now showing some chips or AI chips in actual servers that people can buy. And so the argument is is, you know, a MD John Schwartz has wrapped itself in this open source flag and is saying that, you know, Nvidia is all about lock-in, and they are all about openness. But the question is, is can a MD really catch Nvidia?
Is Nvidia just too far ahead and Know? Yeah, you yeah, yeah. You, you read in my mind.
I mean, it's, I mean, it's almost to the point that we're thinking, we're saying remember a MD somewhere that, that company, that other company, right? So there was all this ULA around NVIDIA's dominance. There was, where in the world is Jensen Wang?
We, you know, he has a special guest appearance at every conceivable a AI event the last two years. And then if we're not talking about them, we're talking about the FIEs at Intel. So somewhere a MD got lost in the shuffle, and, and it is kind of, it, it's unfortunate, even this company's reputation, which is incredibly good, I think in the Valley, it's a universally lauded CEO, and it's, and it's kind of avoided this whole political fallout with, with Trump and kind of maintained its dignity.
But they, in a sense, Mike, yes, as you said, they, they were trying to offer this clear message to differentiate themselves from Nvidia at their event in San Jose. And, uh, they wanna present themselves as this leading player in an enterprise AI market, and at least be in the conversation. I think that's what they're trying to do.
And, and the way they're trying to do it, I think core to it is this competitive strategy of a focus on open standards and interoperative approach versus Nvidia, which is mix of open source and proprietary approach. So in event, and sent in some way, and Alan has always said this, he's always driven at home in every major market, there are like three major players that are gonna survive. A m D's gonna be fine.
They're going to be a distant second to Nvidia the foreseeable future, but I I la them and, and, and, um, give them major credit for at least trying to differentiate themselves and kind of try to counterbalance this, this, this fusel lot of, of these constant Nvidia news. Um, so competition is good, and I think we need to have like another choice. Nvidia kind of scares me in a certain sense too, because they're too powerful for the own good.
I think of AD is the Jan Brady of, uh, chip Knickers. So the Marsha, Marsha, Marsha is, uh, Nvidia, But you know, what if, if I, I love the Brady Bunch reference, but if I had to pick a company to play this role, a M D's damn good at it. They, they played this to Intel for 20 years, and you know what?
As we sit here today, they did a damn good job, right? Intel was, for all intents and purposes a monopoly, but a MD stayed in the game. They couldn't go toe to toe with the Intels, but they stayed in the game.
I suspect it'll be a similar thing here, right? And then, look, Q day is coming, Q day is coming, and who has the quantum chip? And is that, is that guy gonna wear a synthetic leather jacket and go to every conference and, and Hey, well, I wouldn't count a MD out for the following reasons.
One is they're actually doing quite well in traditional servers, and, you know, most of the, at least more than half of the new servers that people are rolling out have a MD processors in there. So they have the, the chops to fight the fight and open source is it, it's a classic, you know, tortoise versus the hare kind of thing. Open source has historically been slow off the mark, but eventually wins the race.
So I don't know, Alan, you know, if I look at these open source libraries, developers like that, maybe eventually a MD will resonate with those folks. What, what I find interesting though, Mike, is if you, if you listen to Jensen CDA and the rest of the, of their software empire is open source, isn't it? I don't think CDA is open source, but, and the people who write it are all Nvidia people.
And Nvidia has a strong, I was gonna say, I think it's an example of one of those things that's, uh, you know, like I kind of refer to as like a, a quasi open source. I mean, like, technically it may be, but to like Mike's point, when it's completely driven by one organization, like all the contributors, the, you know, the people that actually own who can, who can do check-ins and so forth, all work for one company. Like, I mean, I guess technically it is how soon, but not truly community, John, how soon we forget because we're all used to what I call the foundational model of open source now, where you have the Linux Foundation, the Eclipse Foundation, Apache Foundation, and you have coopetition among competitors, and we're all kumbaya gathering around the maple, but before there was a, a foundational error, there's, there was what I call the big brother era of open source where every open source project was basically owned lock, stock, and barrel by one organization, and they ran it for their own benefit, right?
Going back in the security world, you know, Nessus was tenable and, and Snort was source fire and you know, it was open source, but it was controlled by them. And that that was the, that was the way open source ran until, you know, and in this big brother era of open source, IBM was good at this too. Um, so you know that that's the video.
Well, Ivid, I think this space is a bit different too, because there's such, uh, you know, when you talk, think specifically about what we're talking about now with a MD and Nvidia, it's, it's not sort of a general purpose software that could be run, you know, independently of the underlying hardware layer, right? It's, it's software that is to enable the capabilities of hardware. I think almost definitionally it's gonna be much closer.
You could have open source software, but if it only runs on my proprietary chip, Doesn't matter. It doesn't really matter What difference it make, right? Open source my toe.
But, um, but like, you know, I, I think we all would like to see a MD be competitive here. I think you wanna know the truth. I think Nvidia would like to see a MD be competitive, because if they're not, then you start using that M word and the m word gets scary, right?
I'll also say having just been at Microsoft for a long time during the early two thousands, yeah, honestly, like, it, like I, I would tell you, and I think most thoughtful people there would've said, you, you are better off when you have some competitor who is credible. Like, you don't want it to be winning, you know, 50% of the time, but you know, you wanna be credible, it keeps you on your toes, it keeps like, you know, some energy, it makes the market feel like it's something dynamic where it's not just like, yeah, it's just stuff like, it's, you know, I'm just gonna buy it and, and use it until it dies. Like, you really do need that.
So, I mean, I think you're right. Like if, if they're, if they're smart and thoughtful, which I, I'm sure, I'm sure they are. Clearly they've made an incredible business, so, you know, I think there's probably like, they wouldn't wanna admit it publicly, but they probably are more happy that there's like at least some competition that's out there.
Agreed. Agreed. I Feel like we're gonna hold this con, I feel like we're gonna have this conversation over again.
In theory, there should be a framework, kind of like the risk five people are talking about where having an instruction set that can run on different processors, and that should apply to GPUs theoretically at least. But the problem I've seen over the years is that developers, you know, for that extra 10 to 15% of performance they might get, are willing to sell their souls for lock-in. Well, the other thing I'll say too is having, you know, we, we do do use some AI capabilities and, and our product and, um, you know, I've certainly worked with a number of companies that, that are customers that, that, you know, are very focused on either building AI services or really focused on AI enablement of their products.
Um, one of the things that I hear consistently from them is just that Nvidia has really gone the extra mile to make the developer experience excellent. Like the, the ability to get started, the ease of use, the integration of the tools, that they've really done a very good job with that. So it's not just simply like, you know, they're here, they kind of had like a, you know, monopoly position to begin with.
One of the reasons that they've had that is they've made it as easy as possible for people to build on their hardware by having a great, you know, effectively like SDK, uh, on top of that. And, you know, again, hopefully a MD is able to replicate that and have an equally good developer experience. But you know, that, that experience is, is what I think you're referring to, Mike, is it's not even necessarily about like, I want a little bit more performance, but if, if my job is 20% easier, let's say by using Nvidia versus using a MD, I'm probably gonna use Nvidia, right?
Like, you know, like that's the, that's I think what, what drives a lot of those decisions. 'cause they are fundamental decisions made by the implementers. It's not like there's a corporate strategy in most places where you're gonna have, you know, senior management choosing what is the, the chip set manufacturer that they use.
It's gonna be done, done by the people that are building the software. And if, if that experience is easier on one platform than another, that platform's probably gonna win most of the time. Get get your goal in handcuffs out.
Right? Exactly. Alright, Hey guys, I think that's going to put a wrap on this episode of Textron Gang.
Good, good conversations today. Important stuff we're talking about. Terry, John, and John and Mike, thanks for joining us on the Gang.
Thank you for watching this. We hope you appreciate it. Whether you're watching it on our tech strung TV stream in the morning, on demand, on text drunk tv, or any of our sites or, uh, uh, YouTube text from tv, YouTube channel, or check out our OTT channel on Amazon Fire, apple TV and Roku, as well as iOS and, and, uh, Android.
So lots of places to watch this, don't miss it. And so tomorrow though, we've got a full, uh, text drunk TV schedule following the gang, so stay tuned right here. But for now, this is Alan Shimmel, we're out.
Hey everyone, it's Alan Shimmel. Welcome back here to Tech Drunk tv. I'm happy to introduce you to our next guest.
His name is Goin Gulati. Goin is the SVP and GM for data services at NetApp. Goin welcome to Textron tv.
It's great to have you on here. Thank you, Alan. Thank you very much.
It's my pleasure. First, I gotta ask you, I see a whole bunch of trophies back there. I assume it's not for data services, but is someone an athlete or what's going on?
My son who's 12, he's a geography geek. He is a second in the country right now, uh, for national geography. B, so good achievement this year.
Last year he was third, so he is definitely climbing up the ranks. Good for him. Congratulations that as a parent, you know, nothing, nothing makes you prouder.
So good for him and good for you. Huge honor. Huge.
Um, well we've, so we've got a little bit of background on you. You have a son who's a geography kinda expert, but Gogan, how did you come to be the SVP GM for data services here? Let's hear a little bit about your past.
Yeah, so, um, my last 15 years have been all in security and compliance. I was at Microsoft for 16 years, and outta, which after the first six years in Windows, I moved to Azure and moved to Azure Security and Identity Group. And so that's how the journey started.
I helped with a lot of the key management work that we did, rights management, slowly moving into data security, data compliance. So that was the first decade. And after that, I joined a startup for two years as their chief power officer working on, um, security and compliance.
Again, it was a, it is a financial compliance company. And from there onwards, I ended up joining, uh, NetApp. And NetApp.
You can see, uh, you know, we are the most secure stores on the planet. So the last two and a half years, uh, of my being at NetApp as the VP of VP and then the SVP of GM and NGM of data Services has been to really take the lead on bringing NetApp, um, as the most secure storage on the planet, helping our customer with cyber, you know, cyber resilience, right? From everything encryption all the way up to, uh, backup disaster recovery, ransomware protection, and so much more.
So it's been a, it's been an amazing journey and, uh, you know, we have put NetApp, um, which is, you know, on the map for that. So it's been, it's been a long journey the last two and a half years. But, um, but data services at NetApp is all about that, and I'm very just happy and proud to be where I'm right now.
Excellent. Excellent. So, Gogan wanted to, well, before we jump into our topic of discussion, you, you know, you mentioned NetApp, the most secure storage.
A lot of our audience knows NetApp. You know, for me, NetApp really started as network attached storage. Mm-hmm.
Right? Na uh, back in the day I was, it started a hosting company. I sold it to a company.
There was a roll up in hosting and what we then called a SP application service provider. And we had a lot of NetApp, we had a lot of NetApp boxes, you know, we were, we were hosting Lotus Notes, if you remember, back to those days, right? And man, could that thing, that thing would chew up, spit out data, you, you just couldn't have enough storage for your Lotus Notes, databases and stuff like that.
Yeah. But crazy. Um, but today's NetApp is not just those network attached storage devices.
It's not even just secure storage is, there's a lot to it. If you wouldn't mind give people sort of a picture of today's NetApp. Yeah.
So, sure. NetApp, NetApp is a, you call it the intelligent data in Infras company. End of the day, it's all about data, and your data always resides on infrastructure.
And, and that's where NetApp takes a premium. Um, you know, you know, podium location, if you wanna call it on that. Um, today's NetApp is about helping customers with four big, um, imperatives, right?
From data center transformation as it's happening. Um, you know, journey to cloud, and I'll walk through that. Uh, cyber resilience, we talked about it, you know, making sure your data is always safe.
And of course, you know, uh, the top of mind for everybody is, uh, the AI innovation side of the house and how, um, you know, it's all about data when it comes to ai, right? So data and compute, you put them together and, and the magic happens. And the way we have gone about the journey is that, of course we have our big enterprise storage business.
That's what we call it, the storage that you see, um, in the data centers. Um, we also have a very big presence in, uh, cloud storage. So NetApp is the only, um, company that actually has native storage called, for example, in Azure, we have Azure NetApp files.
Um, so it's sold by Azure and built in collaboration with Azure and NetApp because our customers love it, and they want to have that storage, our storage and our infrastructure available in Azure. Similarly, in AWS we have native storage. So it's not something you buy from the marketplace or you just take a virtual copy.
It's like you go to Azure and you choose our storage and you use it like, it's so good and so popular. So we have one in AWS, we have one in Google, it's called GCNV, uh, Google Cloud, NetApp volumes. So we had our storage in cl you know, our cloud, our storage is available in all three, the top three hyperscaler clouds.
Of course, our enterprise storage business is pretty big, but that's like the starting point. We have an amazing platform. We call it our, um, data platform that sits on top that provides all the right value.
The internal name is on tap on our operating system. And on top of that, we have the data services group. My group that provides a lot, most, I would say, if not all, of the intelligence for the infrastructure that's below, which is the data infrastructure.
And that is basically that helps drive all the four customer imperatives, uh, transformation data, standard transformation, cloud transformation, cyber resilience, and ai. So we do a lot of work in helping our customers be more from, particularly in my group and cyber resilience, getting their data infrastructure ready for ai. So there's a lot of work that we do over there.
Um, a lot of innovations, but that's what NetApp is. Wherever there is data, a lot of data there is NetApp because you require that infrastructure, intelligent infrastructure to, uh, really go after and, uh, you know, make yourself productive, make yourself more secure, et cetera. So that's what NetApp is, uh, for, you know, for our viewers and for our customers.
Excellent. That was a great description. Thank you, Gargan.
If it's okay, I'd like to turn now to our topic of discussion. You know, recently, IBM announced that they're building a whole new data center in Poughkeepsie, New York to house their first generation commercial grade quantum computer. And I'm, I'm blanking on the of the, I, it's not Stryker.
There's a, there's a name for this new, this platform. They're, they're coming out with very shiny like kind of box big boxes and stuff, but Starling, Starling is a new Starling. That's it.
Yeah, exactly. But whether you believe they're gonna have it in 2029 or not, look, Microsoft's invented a new claims to 'em, have invented a new form of matter for their quantum chip, and Google has their willow chip, and we're, we're hearing much, so much more. Quantum is gonna be real, and it may not be 20, 30 or 40.
It may be even before or Q day, right? Q day's coming when, oh my God, all of our encryption could be broken like that, right? What are we gonna do to keep our data safe?
Yeah. People are now getting real about, Hey, we gotta start preparing for Q day. We need to have data resilience for a post quantum world.
I'm sure this is something that NetApp is, is investing in thinking about already taking action. Tell us a little bit about it. Yeah, I mean, I think as, as you said correctly, the quantum, the post quantum word is real, is coming, is gonna become a reality.
We know that. Um, and the way I think about it, a lot of us internally think about it is as it becomes more real, it is gonna have a lot of implications on all kinds of computing that we humans do. Uh, and of course there are gonna be many other forms of computing that we are not gonna talk about in your, in this session, but there is definitely capabilities in terms of what the bad guys will do or the good guys should defend themselves against in terms of encryption and decryption, right?
Because it's all about security. It's all about protecting the data. And in today's word, as you know, every bit that gets transferred over internet, doesn't matter whether it's over TLS, you know, it's SDPS something we use today.
Um, data that's sitting at rest, or data that's sometimes in, even in motion, right? Like we, like when it's being transferred, gets encrypted with algorithms. And the idea typically is that these algorithms will encrypt a date on one side, and you have the capability to decrypt it on the other side.
And there are standards defined NIST standards defined for that. Uh, R-S-A-A-E-S standards, encryption standards defined for that. And all of that exists in today's world.
Um, and now if you look at, look at it from the angle of, well, can you break these algorithms? Can a, can a bad guy come in in between when data is in motion or when there's a, let's assume a malware attack happening in your company or, or otherwise, or can I take a discount of a computer or from a data center, can I take it and can I decrypt it with the key? These operations are typically very hard to perform because it requires a lot of compute to go and decrypt it if you don't have the key, right?
That's what this algorithm about. So generally, we feel safe in today's word, right? When somebody says, oh, just send your data over HTPS, or don't worry, even if somebody takes out a disc from a data center with your most important data or from your laptop or computer, uh, generally speaking, we feel pretty good because we know that these encryption algorithms are solid and it's not the worth the money or the vial to be able to decrypt them sensitive data.
But that's gonna start changing, right? When the, when the post quantum word arrives. So IBM saying, startling will be as ready as a data center in New York in 29, 20 29 is an example, group example.
And what, what they're basically saying is that they're gonna turn the game upside down when it comes to decrypting or encrypting. Um, and that's the word that we need to get ready for, uh, right. As a, as a, as a as, as as tech people as humanity, right?
Because we, we don't want to make, we wanna make sure that the bad guys are not going to be able to take these, um, new, uh, supercomputers if you wanna call them, or post quantum crypto computers and be able to start decrypting every sensitive data that you may have, that you may have stored somewhere. And that's where post quantum computing comes in. I'm gonna stop here for a minute, but I just wanted to kind of give that background in terms of what we should, what we should prepare for, what the word is preparing for knowing it's coming, whether it's 20 29, 20 30, 20 25.
Um, it is coming. Absolutely. Now, here's the good news, right?
I always like to give a little good news For a change. We're government and industry has been working together for a while, knowing that this day was coming, that Q day was coming, and for instance, NIST has put out post quantum algorithms Yes. Right?
That would, uh, help, you know, make our encryption not, uh, breakable and stuff like that. A lot of the, excuse me, a lot of the certificate providers out there, digital certificates Yes. Are already including these post quantum algorithms as, as part of their certificates.
A lot of the publishers, the Googles and so forth of the world are starting to say, Hey, you need to replace your certificates more frequently. Yes. So that we can incorporate the latest kind of post quantum, uh, yeah.
You know, post quantum, uh, technology into them. Yes. So we are, we are getting ready, we are preparing at some level, but for people watching this Kagan, how, what, what should they be doing?
Yeah. So I think, look, you're absolutely right. So the good news is that, as you said, NIST has published standards.
Um, and for example, um, they, one of the standards is just pure encryption. Like FS 1 42 a s or 2 56. Mm-hmm.
Um, or for code signing, like you said, there is the, um, FS 2 0 4 MLDS, um, you know, signing algorithm that you go need to go use or use the MLKM for key encapsulation. And I'm, I'm using these terms, you know, the audience doesn't need to know all of them, but generally speaking, the idea is what, what we have been asked to do correctly. So, and everybody's moving in that direction, is that you, we, from a, from an organization perspective, you gotta look through all your in infrastructure, your code signing infrastructure, your data encryption in your key infrastructure, and you're gonna look back and basically say, are these encryptions algorithms that I'm using, are they post PQC, post quantum graphy certified, and have been as a standard, have been, um, certified to be PQC, uh, secured essentially, right?
Post quantum ology is secure. And that is the key thing. For example, at NetApp, for example, you know, we announced a lot of this recently, um, as well, and we've been working on that, that for data addressed on any of our infrastructure and ware storage, we have a 2 56 enabled address, and the customer can go and use a S 2 56 to start encrypting and making sure the data is encrypted with AEs 2 56.
Similarly, with code signing similarly with key encapsulation, um, over a period of time so that when the PQC word hit 2029 plus, you know, it's gonna take a few years, we are ready. The, the customers are ready. Their, uh, their infras is ready to be able to tackle, um, these problems.
The of, you know, uh, a, you know, a bad guy coming in, stealing your data, and then being able to decrypt it, right? That's what the word has to prepare for. So whether it's Google and, you know, there are influencer companies and, you know, there are, um, big hyperscalers of course, that are moving in that direction.
Influx com data influencer company like ours that has taken the lead and basically said, we have these algorithms now available, but the organizations have to go take, play the role they have to go there, there is a, there is a, there is a, they, they have to take the premier role, their com, their security officers have to put a mandate to make sure to look around and see where their data is, for example, and where their keys are, and be able to therefore then go and say, I mandate this. We mandate as a company that we need to use post quantum cryptography to, uh, to make sure that we are safe when the time comes. I love it.
A absolutely. Kagan, we only do these for 15 minutes. We're outta time already, but let me ask you, it goes quickly, um, for people who wanna stay on top of this, and I think everyone really needs to be thinking about this.
Can you give us a few, I mean, obviously we should go to nist. Yes. Right?
And, and they're post quantum, uh, uh, information, NetApp, is there a place on the NetApp site we can stay on Restas of what you guys are doing on this? Yes, absolutely. com, click on cyberresilience.
And we have a lot of information about what we at NetApp are doing about PQC, about what PQC generally speaking is. How can our customers or, you know, anyone be secure, um, and, and protected from what's coming their way. So there's a lot of information available, you know, and I just feel proud to, to be working at the most secure storage, uh, company on the planet.
And we have a lot of information for our customers and our prospects and anybody who wants to go read about it. Thank you. Gagan, Gagan Gulati, SVP GM Data Services, NetApp PR on tech truck tv.
We're gonna take a break. We'll be right back. Hey guys, thanks for the throw.
We're here with Dino d Marino, who's the newly appointed CEO for app view X, and we're talking about encryption and post quantum computing and all these things that are happening around our ability to secure on data. Dino, welcome to show. Yeah, thanks for having me, Michael.
I think everybody's kind of generally aware now that quantum computing might break our existing encryption schemes and that we need to replace those things, but I'm not quite clear that everybody's prioritizing that effort and it's significant. So what's your assessment of, where are we right now? Yep.
I think your, um, your observations are, are accurate to what we see as well. So between the trade shows we've attended, uh, the customers that I've spoken to, I think you've got a very broad spectrum of organizations that are acutely sort of aware and on top of this challenge, and some that are still, they still believe it's a little bit of a cloak and dagger when they hear quantum computing. And so what we are seeing primarily is that in the highly regulated industries, so specific, specifically financial services, insurance, uh, those organizations probably due to regulatory pressure, are already sort of building a three to five year roadmap to be post quant already, uh, by 2030.
Uh, so when you look at that cohort, they're actually quite, I'd say, acutely aware of the challenge. Um, and I think they have both, both monetary and compliance reasons to be, but you go downstream to some other verticals and to your point, you see people still struggling their so shoulders saying, Hey, this isn't really a thing yet. We have a lot of time to sort of watch the market mature and see if the problem space actually comes to life.
So how long does it take to actually migrate, um, your encryption scheme, and are there certain things I should prioritize over other things first? Yeah, great question. So it takes a while, uh, as you can imagine.
'cause when you think of the world of encryption, uh, in a lot of cases we think of it in the terms of, let's say a certificate, a public facing certificate. And even those things as, as true as it might be to issue and revoke them, it takes time to sort of understand how many you have and then sort of create a program and a capability that discovers 'em, you know, then drives the revocation and the automatic renewal of them. Things get very complicated when you think of cryptography in code and what, by code, I mean software that companies build, as well as the crypto that lives on various endpoints, machines, containers.
And so when you start to look at companies that are stake taking this seriously, so again, I think of some of the big banks here domestically and in Europe and Asia, they believe it's gonna take the three to five years that NIST is sort of guiding as a, as a point of guidance for 2030 readiness to actually sort of discover all the crypto, which is step number one, understand the context of it, um, understand what it might break in their applications as they move through shorter to longer algorithms. And then being able to work with the business to start to sort of create a program for, uh, the proper sort of revocation and lifecycle management of, of the various forms of cryptography. So shouldn, I start picking different applications to maybe the more mission critical ones and focus on those first.
And I, 'cause I don't think I can do everything all at once, right? Yeah. I, I think, um, you know, you've got this post quantum movement and you also have Apple and Google, um, who are now sort of driving their public facing sorts to become much more shorter duration.
And so, you know, between the broader threat that you mentioned on post quantum, you know, some of the external certificate authorities and, uh, crypto infrastructure, that is gonna be likely the first jump point for an attack. I think in this instance you probably start outside in with a lens to mission criticality of applications. That's at least what we are guiding our customers for when we look at their sort of post quantum readiness journey, which is a multi-step journey, uh, which starts with discovery.
But I think that, that the cab forum, um, which is, uh, one of the, the most, uh, I'd say powerful authorities as it relates to all things cryptography, certainly as it relates to public certificate authorities. I is sort of, I think, driving an awareness for the industry and a and a validation point that, you know, outside in approach on this is probably where organizations are gonna have to start. Not only due to the threat, but just due to the fact that the validity of certificates is shrinking at, you know, at a, at a pretty rapid pace.
Also, we hear reports that nation states are harvesting encrypted data and the assumption that they will be able to encrypt it or decrypted later, sorry. Um, yeah. And so what do I have to be more careful about my existing data?
Because, well, I mean, three years from now, some of that data may no longer be relevant, but others might be deeply embarrassing. Yep. Yeah, I think this, uh, the concept we talk about is harvest now deeper plater, to your point.
That is a, that is a threat that we have not seen come to life. But as you know, uh, from your experience and, and even my past experience in cyber, unfortunately, once we know it's come to life, the attackers have, you know, got a very strong foothold in these enterprises. They've exfil whatever data have gotten whatever jump point to, let's say, uh, another organization, you'll think way back to the target breach that was actually this sort of motive for the original attack.
So the unfortunate reality is we don't know yet, Michael, what that world will look like. There have been no confirmed attacks that we were aware of on, uh, organizations from a, a public cryptography perspective where that, uh, that's been used. But I think the challenge will be, the good news is organizations that takes post quantum readiness, uh, seriously, even if their information's been completely harvested, uh, as they start to rotate, you know, for, um, for a better, no better term, you know, rotate their cryptography to quantum ready, even if the adversaries then try to use that against them, they'll actually be in a point of stronger posture.
So it is a little bit like everything in cyber and arms race. Um, but the good news is if they move to that posture, even if all their information has been harvested, that information to your point, would in theory be rendered useless. So I think this is why you're seeing the banking sector try to move so quickly due to the potential financial impact, business impact of, of these types of attacks.
You mentioned the speed at which we're seeing certificates renewed, that seems to be putting a lot of stress on IT teams. And I think it's only gonna get faster because people are starting to realize, well, even at 45 days, a lot of damage can be done. Right?
Yep. I think what you're seeing is, uh, the word automation, uh, even just in the last two months, it started to become much, much more of a point of, uh, of interest concern for, for customers to the point that even internally at app ux we're talking about, you know, autonomous, uh, automation, meaning we're going to have to go to a place where we almost treat all of this CRI cryptography as ephemeral. It doesn't mean that it's gonna be ephemeral day one, but from a design standpoint, I think we have to think of a world which we're already starting to see in, in containers as an example, because those by proxy are ephemeral, that we as the provider have to be extremely agile, not only in discovery, but in the ability to sort of pro provide context prioritization, and then work at the speed of, of which the attack surface is moving.
Um, but also the duration of this cryptography will likely be in the next 5, 10, 15 years. 'cause it is few points such a painful part of the infrastructure to replace. We're trying to do our best ultimately to future proof, you know, how we design products from that perspective.
How will I manage all of this when in the age of ai there's gonna be more code, more services, more tiny little things that all have APIs and interfaces that need certificates. I mean, the level of scale at which we're looking at might be a little overwhelming. Yeah, we, um, I mean there is already information in the market, you know, that, um, that we published even some of our, our, uh, peers in the industry that say there's anywhere from 40 to a hundred machine identities and a certificate would be an example of one.
And SSHG would be an example of one, uh, an API token, you know, that's authenticating one API to another would be another, uh, as would your iPhone, right? Or your laptop. And so there's about 50 to a hundred of these for every human being on the planet.
And that's today. And so when you think of the fact that, uh, for the baseball fans out there, we are maybe in the top of the first sitting as it relates to artificial intelligence and how companies are using it, we do expect this geometric explosion of machine identities to, um, to occur and it's already occurring. So I think for, for us, we, as an industry, I think standards become ridiculously important.
Like how do we, even our competitors, how do we speak, uh, in an efficient manner with our platforms together so that we can drive a level of consistency and understanding what cryptography is out there, what machine identities are out there that I think how we design technology for a hundred a thousand, 10 XA million x scale. I think it becomes the next challenge for our engineering team as we think about the problem space, uh, and the volume of information we will have to be able to process, calculate, and triage. And then ultimately, going back to it, you, there's no way people will be able to handle this without automation and without thinking longer term about how their partners, uh, and vendors are driving autonomy on managing this with some, obviously some lens of oversight.
Um, and the ability to drive, you know, detailed reporting on who's using what, where. Because to your point, the biggest challenge we're all faced with is that size of it. It's going to be just massively, um, more volumous than what we've seen, uh, up until now.
Who's taking the lead on this then? Because historically certificates were more or less managed by security people, but now I need it people to go in and change the schemes and the developers gotta get involved. So it clearly requires a village, but who's at the front of this effort?
Uh, yeah, I think it depends on the organization. So the maturity of the organization up today, uh, to till today, let's say sort of predicates who believes that they're taking lead. I think when you think of the world of other categories like application security, cloud security, it is going to be more and more of a joint effort.
'cause to your point, it's been reasonably a siloed capability that either the PKI teams, identity teams or security have taken a lead on. Now it's gonna require DevOps in many cases. In some cases DevSecOps should absolutely be at the table, and it requires some level of oversight from your chief technology officer, CIO ciso.
So we view this as a multi-stakeholder problem for sure. And there has to be an understanding that, yeah, well, cryptography is, you know, that weird thing that keeps all your applications secure. At the end of the day, it can also break your applications, which is why the, you know, the CTO and the app owners are gonna have to sort of partake in this journey, much like we saw with application security, where you had to bring security and application developers together to solve this problem.
We view this as, as a different problem, but a similar sort of construct of needing, um, you know, a program around crypto agility, which is sort of a term that the, the, some of the industry is using. Um, and it's gonna look a lot like developer relations did, I think, as to, uh, how organizations started to build more and more secure codes. So that's something again, our more, um, mature customers are starting to either think about or build inside of the four walls of their organization to tackle this issue.
As you kind of figure all these things out, what ultimately will differentiate somebody who says that they have a post quantum encryption scheme versus somebody else? 'cause it is, seems like every time I turn around lately, everybody's kind of standing up and saying, we have one. So which one you using?
Yeah, I think, um, unfortunately, if you think of a, a pre quantum world that we're living in, and we have lived, lived in, certainly on the public certificate authority side, there's been many, uh, distrust situations, which is an industry term that we use, uh, where from various re reasons the certificate authority itself becomes distrusted and in some cases, and there's validity to that. Um, and I think that it was right for the various forums to, uh, to sort of flag that these vendors weren't keeping up their end of the bargain on, on how the cryptography was working and the other standards they needed to adhere to. But in this new world, I think because of how agile things become, it's, I mentioned it earlier, standards in general I think become just sort of a table stakes thing that all vendors are gonna have to lean into.
And again, I think of the, of a world of, of discovery integrations and automation is what I think our customers will need to solve this problem. And they're going to need a level of agility probably in order to handle distrust situations where they will be able to maybe change from one certificate authority to another or one crypto authority to another, just based on how fast and agile, um, the industry is moving. But also, you know, the threats and the compliance standards are moving not only for our customers, but for us as the vendors.
So this world of agility, that crypto agility concept really speaks to it for me, not just on the customer side, but being able to manage even the vendors that you have to deal with and having some level of agility and not being locked in, if you will, to, uh, only one or two, let's say of your, uh, your currently trusted certificate authority advisors or partners. Are we gonna be able to maintain the level of interoperability that we've historically seen in this space, especially among certificates across all these different post quantum implementations? Or the standards gonna be so loose that maybe we'll have more friction than we're encountering or thinking we are gonna encounter?
Well, if you know the answer to that, let me know. I if there's a big question mark for us, um, because I think the problem we've had is, look, think of PKI, the original instantiation of on-premise PKI, um, you know, and, and many of of us out there have seen you, whether it's entrust or Microsoft's certificate authority inside the four walls of our organization, you had in many cases, years, if not decades to sort of manage the revocation or reissuance. And as we've talked about, you're not going, you know, from years to days as far as that speed.
And you're now, to your point, injecting a whole bunch of new standards in the crypto itself, uh, the length of the algorithms, um, who, who is going to validate those. So we are definitely, when I talk about integrations to my team, it's really to make sure that we do the best we can to stay on top of all the different standards that, um, that are gonna be pushed down or pushed into the industry. And I do think we're gonna see, uh, some issues because of the speed at which we have to move between now and 2030, which is sort of the NIST guideline date for post quantum readiness.
Um, and I think it's really early days we'll be, you know, happy to update, you know, you and, um, your organization as far as like what we're seeing out there so we can cascade that to the market. 'cause I think you're right, the speed at which everything's moving, I think standards are the right thing to do. There's just gonna be harder and harder to execute as a collective, um, community going forward.
A lot of folks may be hoping that some magical AI pill will emerge that will help us migrate these things faster. I mean, what work is being done to kinda improve that rate of migration? Yeah, I think, um, I think customers are, are okay to be pushing us to think about it in that respect, because I do think, um, you know, it's very hard to have a human oriented approach to manage a machine oriented problem, if that makes sense.
So especially one that's driven by, uh, a very, very extremely intelligent ai in many cases, the Gentech ai. And so when we think about how we design technology, again, it's very much trying to keep up with, um, with the way probably our adversaries are gonna use artificial intelligence as well as how our customers will. So AI, I think for any modern organization has to be sort of the crux of how you think of solving a lot of these challenges.
And we're no different. So we're having a lot of conversations specifically around how agentic AI starts to take some of the human workload off of our customers, starts to make some of the, the medium to sophisticated decisions that currently today the product, uh, wouldn't be trusted to do. Not because it's not a trustful product, but because we might break a business process, you know, do some of that testing that you see when certificates break, things that we can sort of offload on the customer.
And so I actually think AI becomes this, this extremely powerful, uh, capability for us. Um, and it may not be the magic pill to solve this problem, but I, I do. And I think our engineering teams absolutely believe it becomes a very big part of how we start to, to scale and match.
So the speed and sophistication of, of the problem space that we're in. So ultimately, what's your best advice to folks then about how to approach this whole issue as, as they, we look at it? 'cause it's twofold, right?
One is the pace is getting faster, and then two is I kind of need a major upgrade. I think for me, it, it's, uh, it doesn't start with technology, it starts with people and process. So, you know, if I were on the other side of the wall, and I guess at this point I am, because I'm accountable to my own customers cybersecurity programs, we are starting to talk internally about a crypto agility, uh, committee within our company.
And as I mentioned earlier, that's a combination of our product and engineering organization security, admittedly is the coordinator of it, uh, as well as, you know, downstream it. And, um, you know, making sure that we start to have the conversations of number one, understanding baselining, like, where are we today? You know, where and what do we have?
So think of posture as sort of step one of your crypto footprint, um, understanding the potential impacts both to your business as it relates to your homegrown applications. You know, your off the shelf applications, your cloud applications, cloud workloads, um, and then starting to prioritize based on I think two lenses for me, sort of threat, uh, as well as, you know, compliance and compliance. I would view, you know, things like the 47 day TLS cert, uh, movement that we're seeing.
Like that's something we just have to do so that we'll have to get prioritized and creating that roadmap that allows us to comfortably achieve, you know, that post quantum readiness by 2030. So in many cases, what's exciting being a CEO is you can almost use your own, you know, your own test case, even though we're not the size of a, a very large bank, but the concepts are, are very similar as to how we think we should set it up. So this sort of crypto agility committee is, is to how we're thinking of sort establishing, understanding credibility to then start the technology, um, migration, if you will, to a world where we're hopefully significantly more agile than, uh, the world is today as it relates to crypto.
All right, folks, you heard it here. This whole area that many of us have taken for granted for years. Well, we need a better plan than just crossing our fingers and hoping for the best from here, because bad things can happen.
Hey Dino, thanks for being on the show. Yeah, thanks Michael. It's always good talking.
I'm back to you guys in the studio. Hello and welcome to another episode of The Inevitability Curve. I am your host, Chris Blas, and with me today is a good friend, Emily Corrin.
Emily, how are you Doing? Okay. All things considered All things, there's a lot of things to consider, isn't it?
Yes. You know, we're talking about in the green room, where do you even take this look? You know, so, so we seem to agree.
Talk about the grand dark of cybersecurity with your background and where we are today. You know, that's enough context, but yeah, today, seriously, I, it feels like my cousin Vinny, you know, that, that that porch of the cabin scene, you know, where, uh, Marissa tome is, you know, stomped her foot, my biological clock is ticking the Joe Pesci, you know, he says, oh yeah, let me get this straight. I remember the lives of these two boys I this, and how many more things can we pile on this one moment?
Yes. Yes. So, so yeah, it, yeah, our, our, so we'll talk about AI and, uh, and whether we're getting anywhere because maybe that'll let us talk about the 8,000 other things are going on right now.
It's the, it's the topic that seemingly just sucks the air outta the room. You go in, you may go into a meeting and, and you're just like, here's this thing we're gonna work on. And inevitably someone throws out those two letters and it just like totally says, oh, wow, how can we exploit this?
How can we take advantage of it? And it never really kind of gets anywhere outside of that. So it's like the tar, you know, you get in there and see ai, tar pit, Right?
And know there's, I mean, look, we've both been at this, uh, like quite some time and, uh, we've seen these trends and fades and fas and so forth, and sometimes the trend and sometimes it's a bad and mm-hmm. I, I've been reluctant over the last couple years, you know, to see what we currently call artificial intelligence. To be clear, you know, the AI is not right.
Getting at all that maybe, maybe we will, however, right? I really actually think I, I, I think we're at that point. So the fact that that companies are and organizations are around may not be, may not be proof that we're all wasting our time in another fed.
Um, it may just be large transition. So, I don't know. I think I made a pause there.
Yeah. So let's go back anyways, right? So, you know, ai, right?
Artificial intelligence, which is neither artificial. It is what it is, and it's not intelligence. Um, so other than that, the academic is awesome.
It's automated decision science is basically where it is. And I should know, 'cause that's my degree. And, and when I was, when I was an undergrad, part of the stuff I took was regarding, uh, they, they called it, um, general programming.
I think it was, uh, you know, some lisp and prologue learn turn machines and, you know, all the overhead for that. And, you know, coming from a background, originally I was originally a computer engineering major and then switched. 'cause I didn't want to be doing chips my entire life and got to touch on AI back in the early nineties when it was still kind of a, a whisper whisper network of people who were aware of things and, and now looking at where it's at.
And it's really just more powerful decision engines at this point. But people are relying on it to, to be agentic or, you know, create and steal art as it would be. I have a lot of friends who are, are creatives and oh man, that whole channel versus the security and tech people, they, they, they are very much on the opposite ends of, of where that may prove useful in the society we have today.
So, Well, so let's go back to the early nineties. In 1990 I was in South Carolina, in South Carolina at General Electric and the mm-hmm. And Jack Walsh was, uh, uh, putting in a video conference network.
They put one our, uh, uh, we made big, huge turbines for power generation. We got this conference center. And I was thinking about that saying, you know, at some point, you know, I think I was, I think I was you, you know, at least, least, uh, um, brighten up to say something like 20 or 30 years.
'cause it was right here. Now at some point we all have cameras. What does it even mean?
You know, how do we, how do we, uh, move that forward and here and here we are in the same sort way. Um, ai, you're, you're actually doing AI back then. Um, and it was different than what it is now.
You know, that's, that's a good span of time, right? Here we are with all, now we're in the world where we have video conferencing and cameras everywhere, and we're starting to settle into what it means. But doing shows like this, you know, you and I, and we're not even on the, on the leading edge anymore.
You know, our our friends and family have mostly figured out how to use Zoom, even if they don't, you know, their face only shows up from here up. Yeah. How has, what's, what was AI when you were in school compared to now?
How, how? It was generally pretty conceptual. I mean, like, I look at what we had in the way of stuff I would explore around on campus.
Uh, you know, it was the early days of, of computer graphics. So, you know, the, the facts that we had, uh, a lot of the, the early silicon graphics machines that were between the art department, uh, that we had are, uh, the art school. Um, and then the CS school, you know, that was, that was cutting edge stuff that would take forever to re re render a frame.
Uh, we had, uh, I think it was an Intel sponsored parallel computing lab that was, that was, uh, in between the computer science department, the engineering department, but that, you know, big huge box with blinky lights and stuff like that. But it was the, the early days of those things. Um, there's, you know, we also, the Robotics Institute, you know, the idea of, of sending robotics off to other planets, but everything was still controlled here because you couldn't launch the amount of computing you needed to actually have something fully autonomous.
So, you know, back in the mid nineties, like that was the state of the art. So the idea of, of AI then, uh, was still very conceptual. I mean, like when, when I was in class doing touring machines, it was like, you're sketching stuff out on paper 'cause there's nothing there that's actually gonna do it.
Like, you could run a couple, you know, steps along, uh, those decision trees with simple computers, you know, using, uh, you know, a prologue or list those languages at the time that were designed for, for, uh, you know, kind of creating those decision trees. And now, you know, you take this 30 years on, uh, the, the, the fact that everyone's wowed. 'cause they can pop into chat GPT and have them write up a cover letter or, uh, adversaries, you know, they'll craft up some, some potential, you know, miss or disinformation or some, some phishing campaigns, save time savers.
Um, but, uh, you know, the, my biggest worry right now is thinking, you know, uh, just the data mining, like we are such a, you know, between then and now, uh, the amount of, of human knowledge or, or data that's been collected, it's aware and accessible, uh, is grown exponentially. And I think what people are just searching for is just ways to make use of that. Uh, coming from the federal, uh, side of the house when I was a pub, uh, public servant, uh, you know, just thinking about, uh, just my last station there for Health and Human Services is getting access toce centers for Medicaid and Medicare services and, and, and trying to make sense of billing.
You know, trying to just tease out potentially, uh, bad doctors who are prescribing opioids or, uh, folks who are defrauding, uh, durable medical equipment and teasing that out of those large data sets. But, you know, the compute required for that, the models for that, the inferences generated that typically AI is being marketed for, you know, even just five years ago weren't really kind of available. Um, you know, the stuff that was pitched from the, the H-H-S-C-I-O at the time was to, to help with smart contracts.
I think it was a tie on to the whole blockchain thing. But, uh, you know, leveraging these, these tools to kind of, uh, look up previous performance and stuff, but nothing along the lines of like wholesale creative theft or, um, you know, using this to do deep fakes and stuff like that, that was definitely not there. And, and that the threat model has changed versus the motivations of like, what we should be using, you know, uh, large machine learning and, and quote artificial intelligence, uh, to kind of go and, uh, uh, you know, exploit.
Well, it's, so I was thinking about that, that that timeframe, right? You know, so from paper mental, like literally, you know, the, the sort of mm-hmm. In, in the top layer of the people who are thinking about this 30 years ago, paper mental, you know, lots of things happened along the way.
Um, but this damn thing that she nameless otherwise will start talking to me, right? As, you know, with these electric boats I've been building, and I built this Alexa into it. Um, you know, having been playing with that and, uh, and, and, you know, as, as just awful as, as it is as a consumer thing, having this voice interface, I can predictably, if I enunciate particularly well, you know, control certain things around me and do things in a, in a real environment, I found that being fascinating how it worked and how it didn't.
And then, you know, let's take us to the present. You know, the current, I currently have two tap et accounts of the cheap one, the expensive one, you know, my personal one and one one for work. And, uh, and I'm honestly only a few months, three months, you know, really trying to use this particular product for a purpose, right?
I think I'm getting a feel for it. Oh, I guess, you know, somewhere along the line between the two is, is, uh, you know, I took one of those electric cars in the truck and put a raspberry pie in it last year and put this Donkey Kong, uh, AI project on it and sort of built a scratch so I can get one round of hands on it. And I see sort of a three layers of evolution right now.
There's, there are projects like donkey car out there. If you're a real hacker, you can build some LLM stuff and some AI stuff, you know, to, to do robots and, and so forth. There's consumer products like, like Alexa and Google Home and so forth, which as much as they suck, right?
Give us a sort market test of these basic capabilities if they're just, just at the barely survival level. But al already, I'll, I'll get to my point, if I ever do, I hate it because I'm starting to use, I talked to this thing to talk to chat, and we have deep conversations and explore complex situations and markets and political structures and, and everything else. You know, I'm not asking it to do anything perfect.
I don't want it to make an AI art piece for me. And I'm finding it just stunningly useful. Um, yeah, you, to get things done by myself that would take collaboration and working group weeks.
So all of that, I guess, you know, taking your well learned cynicism of the current craft, right? Do you see it, you know, it, it's gotta get better over coming years. Are we on the trajectory to actually fill whatever we are thinking we're doing right now?
Or is, do you think it's still decades away? So again, kind of going on kind of the, the, the touching on my, at least academic history as well as my, uh, the, the experiences I've had throughout my career, I, I think we're running into that kind of Moore's law aspect of ai. Like the, the fact that this is a is this is a technology that you can continue to throw more and more compute at, and it'll just consume it.
It's gonna need more memory, more storage. It, it, it's like a brain. Like if I, I guess that old, uh, uh, twilight zone one where, you know, it becomes the smartest man in the world.
His head grows big. I mean, that's like how AI is getting, and it's only gonna be more effective as that, that those advances are made. But I don't think we're proceeding at that level.
So I think right now, uh, a lot of the AI companies are kind of struggling, I'd say almost, you know, 'cause this is really just vector math and, and graph theory, essentially. Um, you're, you're finding shortcuts. The tokenization is a shortcut for the shortcomings of our computing environment.
Um, you know, if you could store the full data gram that's there to, to hold a full memory, um, yeah, that's great, but we don't have that. So you're trying to create these neural nets that, that create these relationships between the tokens and so forth. And, and they're imperfect because they're not necessarily guided.
It's, it's looking at math, it's math and statistics. Again, graph theory and whatnot. And, uh, I think that's the challenge is like, we've got, we've got the math down, but there, you know, the intelligence is not just rote memory.
Uh, it's not knowing numbers, it's not performing a task. It's, you know, right now, you know, as these stories come out, like more and more of this AI stuff is like mechanical turks. Like there's people being paid pennies overseas to kind of make it appear like, oh, wow, there's computer vision.
No, there's someone clicking a button. Like that's a, you know, it's like, you know, going through paid capcha kind of still. And, um, yeah, that, that we're, we're still at this kind of, don't look behind the curtain type kind of thing.
I know, you know, anyone's gonna watch this and, and make comments in the video or whatever. Well, you know, uh, anthropic and open AI and Google are all doing these great things, and these great, you know, AI scientists are doing amazing stuff. Yeah, this is great.
It's research and they're trying to apply it, but they're trying to justify, I think, the investment in it. But there's a lot of other stuff. Is it even within security community?
Like we need things to advance to a certain point for us to feel comfortable about, you know, lighting, someone else doing it to, I hate to say it, like dumb it down so that like there are entry level roles for people to perform that are just totally kind of replaced. Um, and, uh, you know, as you mentioned about having your, your Alexa or your Google Home Assistant or Siri do things for you, having these conversations and so forth. But do people want that?
Like, I don't, I I have a spouse. I love talking to my spouse. I love doing things with my spouse.
I'm, I like having deep conversations with them, having that with, you know, some chat bot just doesn't wrestle my Jimmys as it would be. I mean, you know, it's like I, maybe I'm still that generation. I prefer to have human interactions and human thoughts, and the reasoning that you get from a human being, uh, the reasoning that I've read about and it's seen people show with AI stuff doesn't necessarily to me at the, the philosophical level.
And even just the, the biological level of, of, you know, real thinking intelligence beyond just, you know, collecting knowledge. Um, you know, I, I, again, it's, it's, maybe I'm waiting for the, the, the room of a thousand ais to generate Shakespeare, you know, kind of like the whole monkey and typewriters type kind of thing. I think we're, we're, I'm, I'm in, I'm on hold for that.
And I don't see it. Um, I, I, I admit to being, you know, seriously fanboy at the moment, right? And, and I know myself when I get like this, uh, at least one process in my head, you know, people looking around saying, this can't be right.
No, no, you are all enthusiastic as you think you, you know, with this means, this means this, but you're gonna find out that there's a bag of cats, you know, happily in the middle, and you're not gonna be able to do the thing. And what you said about Moore's law, uh, heavy thinking. 'cause this, I find myself, when we're talking to people saying, just imagine it.
Don't just think about ai. Just imagine you had just ridiculous amounts of computing power to do stupid and trivial things, which is kind of true. You know?
And as much as you, I like the uses I'm getting out, I'm having a lot of value in it. Um, however, right? I prompt engineering my butt.
I sit here and ramble for half a minute, you know, voice to text, pres, go and see what happens. You know, just processing my prompt and making any sense outta whatsoever, probably uses more power than it, you know, a Midwest town. And since we're just, you know, since we're playing and we're building this stuff in, and you have people are actually using it and so forth, we talk about the, the path.
And we have this vision that AI in the short actionable future over the next three years, five, seven years, is going to get to these stages. And yeah, you have maybe the second law of th from our dynamics, right? You know, we can't get there that fast just by throwing the exponentially more physical hardware, you know, computing power and, and electricity power at it in that timeframe.
Well, it's like throwing, throwing nine women at to make one baby in a month, you know, type kind of thing. You know, it's a little bit of that. You're trying to parallelize something that doesn't probably need to be parallelized.
But, but let me, let me see if I can develop a counter on the other part of it though. I think that because what we, what I see happening is that everybody finally, and when everybody finally then things happen. Money, resources, right?
The, the internet itself, sorry. Um, and the internet itself, when I, when I got it, you know, everybody around me was saying, no, no, you don't understand. It's an research educational thing.
And then the dot coms came along and it's like, oh my God, they're gonna destroy, they're gonna take up all the bandwidth. And I said at the time, and they're not being correct, but they'll probably add a lot of bandwidth. They'll probably add so much that the other point, 1% that's left over will be more than us academics and geeks had in the first place, right?
So net, net, even though it's innovation, it's a huge waste of resources. However, Nature of hobs of vacuum as it would be, right? Yes.
So, so this, so this, you know, with all these concerns, I, I think if we're right about some of these concerns, I get the feeling that the economic and social pressure to solve them is, is high enough that we will spend what it takes, unless I, I, I, again, it's a Moores law sort of fundamental that we just cannot push past it. Yeah. Well, I, I think, yeah, I, I arrived at college during eternal September, so I was, I was one of those, those folks, but I arrived at college versus on a OL when they opened up Usenet.
And, you know, I, I started my website, the, the winner of 93, you know, so that was very early on. And, and, um, you know, the, the idea of what, how you could exploit what was the internet at the time was, you know, you're still trying to find your way. What do you, what, what can you publish?
What you could self-publish or, or create that would garner people's attention? And I think we've just been in this cycle. I, I, I think, um, the whole idea of, again, people pushing to have resources for exploiting AI comes from the fact that, you know, my, my, my gig before the, this most recent gig, which is now the, the most pro past present gig that I, I've had due to my layoff, um, you know, I was working, you know, as a tech, you know, external technology relations.
So I was, I was working with all the, the, the big, uh, tech companies regarding cloud and, and AI and stuff. And it was interesting having conversations with them because they had all this hardware that they bought, uh, that was specific for a certain type, you know, a certain purpose or whatever. And, and they wanted us to, to use it for another.
And it, it was like, well, it was wasted overhead, you know, it was the, these, these, uh, servers were designed for the, for this capability, but, you know, we could reconfigure them to, to use for what you need to, 'cause we've already invested in it. And then, you know, it was just this idea of just trying to make use of things that they thought they were gonna to use, and they're pushing that onto others. And, and I, I think a lot of it too is it's this, uh, again, a sunk cost thing where some organizations, it went down a path so far, and now they're just trying to kind of justify having it there.
And I, I think, you know, most recently with my gig, um, you know, I look at what has was published for consumer use, uh, by that company, um, and what's being used internal. And they're also subject to, you know, looking at lists of, of solutions that are, are part of the organization, uh, that claim they have AI or LLM or geni or whatever you may have, you know, with that, the acronyms there that are included in things that they, they have licenses for. I don't think that company asked for them.
They just, AI showed up. It, it, it's, it's like the vampire, I don't think they necessarily invited it in. It was just, the fact is, is like, you're gonna have it whether you, whether do you like it or not.
And then the stuff they build internally was to, again, going back to the, the thing to exploit, uh, and, and surface, uh, uh, insights from data. And that's where most of that is business intelligence use of, of ai. But you could just do that.
It's, again, it's statistics. You're looking at relationships and so forth and, and there's been models for that for decades. Um, immediately slapping, you know, the, the nom d plume of de jour, uh, nom d plume de jour, there we go.
There's all the French I know, uh, of, of AI on top of something and say it's, it's been enabled, uh, just I think makes people feel better. But what va what's the actual value add? So the, you know, at, at these points of transition, I and the people, they become pertinent to what I'm involved with.
Like I say, I get really enthusiastic and get really worried because, and, and again, this, you know, to the theme of our show, this is always what I, what I mean about inevitability curves, and it's just, it's not, it's not predicting the future. It's just saying there's a space of possibility. And as we move forward in that space, you know, our actions change the, the, the possible futures, right?
This kind of sounds, uh, really simple, but, uh, but we're, you know, we have certain, and, and the, and there's not an inevitably curve. There's lots of things interact. And if you're a anesthetic synesthetic, oddball like me out there, then you know what I'm talking about.
And the rest of you are just staring at us like we're weird because, but it's, it's, you know, we are going, we are definitely going to have certain things happening, right? And if we can't get certain capabilities, um, in the same sort of time, we're gonna have certain consequences which are terrible, right? And in, you know, I could take a half a dozen offhand, but, uh, you know, narrative resilience, narrative, serenity of sovereignty, you know, being able to have a conversation between two humans and not know and know whether the other one exists or not, or the words were saying are correct.
Or even if it was a real human, you know, by the time the, you know, this, your video gets to me, does somebody intercepted and altered in the meantime? You know, if, if, you know, those things are within the role of positive possible now, and if we cannot counter them, we get to the point pretty rapidly, but we just can't talk. So that's, that causes a whole lot of economic ion and pressures.
But more fundamentally, a lot of 'em don't wanna, you know, when, when the entire global population doesn't want something and is sick and tired of something, then all sorts of pressure comes to apply to, to fix it. And the, you know, to see if I can scope that ran into, into our, uh, particular space, but excuse me, cybersecurity and supply chain, I just firmly believe more and more that the, the more I spend in the time in that space, moving along that timeline, that we will not be able to do things like fly spaceships if we cannot have the kind of speed and visibility into all your supply chain data across, and know you're not gonna hoover it all up in advance. I mean, you have things in a ballistic trajectory, and you wanna know things about, you know, software seven, you know, 3, 5, 7 steps away to just supply chain.
You need it in the next three seconds. We have to be able to do that if we can't. I, you know, you and I are really good on the adversary side.
I can think of ways to stop all these things. And I know that existing capabilities and tooling are where they are, those are definitely falling their path. And anyways, right.
The, the brittle moments, I guess, right? How close, I think we're pretty close to that, to be honest. Um, you know, one of the things, having taken the role for doing offensive security, um, for AI at my last gig, um, yeah, I was bringing this up on another podcast.
I was at the, the Red Team Summit last year, not this year, I missed out this year. But last year they had an extra day added onto it specifically to, to focus on ai, like offensive security against ai. And I think the reason they didn't have it as an extended day this year was like last year, it was, I wouldn't say it was underwhelming, but it was like, we're still figuring things out.
Uh, the old ways still work. Um, and essentially this is just, you know, a different form of AppSec in a way. I mean, you know, you're still, your goals to traditionally are, you're, you're trying to get access to training data, data.
You're looking at access controls are, you know, r back and so forth on that authentication. Um, and looking at flaws to the algorithms that are in there, or the methods that are written in behind there. So, you know, the rigor required for, for quality, uh, is still there.
And, you know, one of the, the things I, I think on the supply chain stuff, and I, you know, I brought this up at a, at another discussion too, is like, okay, so we have model cards. Great. Awesome.
Thank you Google. Appreciate that. But, uh, all of that's one pretty voluntary, and two, uh, it's really still non-standard.
So there's nothing, there's nothing reliable there. It's, it's way far away from sbo m uh, if you, you kind of wanna bring up the, uh, you know, that one, which has been flogged to death for a number of years, and bless, uh, you know, Mr. Friedman for, uh, Dr.
Friedman for all his work on that. But, uh, um, please tell me you don't have like a cutout of his head on a popsicle stick. You can kind of bring into these conversations, but I mean, um, yeah, but, but I, you know, I know, uh, Alan's off to the, the hbo, the, the hardware bomb, and I think that's, you know, the next progression.
But I don't think we really have that with ai. Um, so, you know, even what, what does exist is voluntary and to be able to do a, a sufficient audit, 'cause these things run on lots and lots of data, not lots and lots of code, lots and lots of data. Um, you know, there's no way to really kind of audit all that efficiently.
So you're just kind of trusting that everyone was upfront, transparent and, you know, fully honest with somebody. And I think that's should give people pause. Uh, yeah, I know I, you know, had, uh, gotten spoken to when I questioned the fact that there was not an AI ethics person on staff, uh, uh, my, my organization there, there, you know, there's legal people and so forth, but there's no ethicists, you know, and that's one of those things that's like, that gets back to that question.
It's like, are people, do people want it? Do they want to consume it? We're, we're efficiently try, uh, effectively trying to expect organics us to, uh, you know, shoehorn something that's not organic into a use model.
And if you're not adopting it naturally and you're forcing it upon, like you mentioned before, like how honest is that use? Um, you know, for me, we've, you know, my spouse and I have had, you know, again, these, these, the, the voice agents and stuff around the house, but really it just gets down to it, like asking that to turn lights off and play music, you know, it's, it is a step through series, but I'm not asking it to like, do my homework. I know some kids probably do, but I'm like, I just don't, there's not a level of reliability there that instills a level of trust for me.
And these are, you know, products from supposedly leaders in the, in the field. And I'm just like, this doesn't, yeah, it just doesn't, it doesn't reach to the level where I'm like, yeah, this is fine. I'll, I will, uh, you know, hand off this, this task to them to do.
And I assure there's plenty of people with using ncps to do things and, and all sorts of stuff to do part of their work. But, you know, day to day human life doesn't really work well with these tools right now, um, unless it's, it's seamless and organic. Yeah, I don't, I just, I don't have that feel for it.
And that doesn't even speak yet to the security behind it. I don't think, you know, the folks who are developing these models are not security people. Um, there's plenty of times I've sat in a room and, you know, there's, there's not a security minded person there other than me sitting in the room and, you know, it's their project, it's their work, but, um, you know, they're not trained in it.
And unless they're willing to ask a question, it's, it would be me or someone like me in kindly interjecting to say, have you considered this? Or, uh, when you're done, let me know. We'll, we'll go poke and prod at it and, and find all the holes and, and create more work for you, essentially.
I mean, that's the interesting thing about the offensive security world is, uh, we create work for more people. Um, and I think successful teams also try to make it not seem like you've just dumped a hete steaming pile of poo on their desks and told them to deal with it. I think those that wanna work with them and, and, and try to make things better are there, but I just don't get a sense that there's a lot of that out there right now.
So let me, so we're, we're at that point in the conversation. Let's try to look out in the future and just, just today, I think, uh, um, I wrote an article for a Security boulevard, a Tax Pro Property. All you are watching there, go click on it, click on an ad or something, I don't dunno.
Um, about, uh, sort of expansion of a LinkedIn post. You might have seen that I put, uh, not that many years ago, but mental dos, mental denial of service. Mm-hmm.
Right. And I think, you know, in the, you know, in the cognitive security space right now, you know, we're in a extremely challenged spot, you know, as an industry, globally, as people, as societies and so forth. You know, what's real, what's not real, and so on and so forth.
And in that, in the update of the mental loss article, I, I think of it, I've tried to explain, remember the, the Good Times virus, right? I was very, very early On. Oh yeah.
Oh gosh. Yeah. Email goes around, you know, for everybody who doesn't know the story that says the, the headline is Virus, tell all your Friends, it's gonna delete your hard drive.
And there was, you know, to be clear, there was no computer executable code virus called Good Times. It was an email and it got forwarded, you know, to all the, uh, news groups and all the mailing lists on the internet. You know, tell all your friends, then everybody would jump in and reply all back to everyone and say, that's not a real thing.
Stop doing it. And, and it, and it broke the internet. And at the time I was, you know, young and n to all this, I'm just sitting there, you know, trying to avoid doing my actual day job and, uh, argue politics and space tech and so forth.
And I, and I hadn't got into security yet at that point, and I just stuck my little hand up and said, ya's saying it's a scam. And this is an actual virus. This is executable code that someone wrote, um, in their head.
They used their fingers and so forth. They type it into a keyboard, they transmit it across, you know, these electronic wires, you know, they, you know, just presents an A PIA screen. It was read by input devices in my eyes, put the code in, made my brain, uh, do functions.
It made my hands move, made me actually press send, maybe write this stupid email and trying to get everybody to shut up. You know, it's, and I got shouted down. It's like, no, no, no, you don't understand.
That's not how computer viruses work. And as you know, since then, you know, there's red, you know, right. Going out there that, that, you know, he and I do all sorts of crap together.
And, and his PhD thesis is where the bloody term came from. So I've had plenty of chances since then to say, Fred, you know, did I miss something here? 'cause that still looks like a computer vi, it's the virus transmitted by a computer is the Wetware virus.
And we're literally this world right now. Right. This is the way we do.
Yeah. I take up consuming, I, I'll use up processing power in your head. I'll use the time you have, you know, and I'll use that up for something else.
I will lower your, the, the efficiency of your communications channels between host you and every host around you. And if we don't find a solution to that, you know, we rapidly approached a point where we cannot run the power grid. We can't do anything.
Right. You know, nobody knows, you know, whether, you know, you know, any information, not seen whether their own eyes is real or not. Um, yeah.
So we're at this crux, and, and this is, you know, to the, to the, to the point that I getting not getting too, I think that's one of my concerns because I see right now the potential in what we call I AI right now in helping us address some of that, you know, giving people the time to deal with human scale issues, you know, and, and imperfectly, yes. But again, I think if we can't do that sort of thing in the near term, then, then I think we'll get ants. I mean, we have a lot of ants now.
We have ants for a long time. Yeah. I think, yeah, you, you do bring up a an interesting aspect there.
I mean, that was something else I studied, uh, while in college. I was, I I, I studied a lot of stuff in college, but cogno psychology was kind of the core of that. Um, at the decision science Of the house, you're one responsible, one of us.
I dunno if I ever said that, you know, but a lot of us in this crowd, like bounce, you're one of those people who finishes things and like Always admire. Yeah. And barely.
I mi mind you, I'm not really proud of my GPA after I graduated. But, you know, one of the, one of the things there was, you know, and I, I think this is well trodden, uh, cognitive psychology thing is just that, and I think this even showed up in, uh, Douglas Adams', uh, writings. I don't remember if it was the Dirk Gently or the, the Hitchhiker's guy one, I'd have to require me to go reread it.
But there's basically seven slots, uh, you know, in your brain that you can hold stuff, uh, resident, you know, you get that, that tip of your brain type kind of thing. And I think the joke was there, you know, uh, you know, all but one of them are full of penguins. But in this case, like, you know, you have that overwhelming aspect of trying to keep things on the tip of your head.
And if you can, you, I, I think what humans run on besides caffeine, uh, is anxiety. And, uh, that's usually created by just those, those check cycles through all those seven boxes is like, okay, I'm worried about, you know, can I, can I pay my mortgage or rent? Do I have enough food on the table?
Like, those are like four or five of those ones on there is just sustainment. Like, how do I get myself through my day? And that's, you know, humans are just an anxious species.
You know, we're, we're rabbits with a bigger brain, I think in a way. Um, and then like the three other slots, or three or four other slots that are available, or those are the, the, the task driven type kind of things to, to actually like your work throughout the day. Like, I've gotta go and, and manage this project, and things like that.
So the, it's, it's, I think they're, rather than actual like facts and knowledge in those seven spaces, I think it's just little tiny boxes of, of cyclical anxiety that we have. But it allows us to function. Our, our little, our wetware is just one of those things.
And those interrupts, uh, you know, something fantastical like, uh, you know, uh, some AI generated, uh, what's, what's the engine now? It's the VO three VOE three or whatever that's been out there where people have been posting the video of, of these newscasts that look really great and, and totally telling absolute crap. Um, you know, those are going to hit the eyes of people who don't have that filter, that they're just cycling so fast that it just gets sucked into that cycle.
And now it just becomes part of that, one of those anxiety boxes. And it's like, well, I, I'm worried about the state of the world today, and I'm gonna throw some fake news in there. And, and that box starts to get hot because you're now adding that to that cycle.
And that those, those check anxieties. And I, I worry that, you know, as much as it's been marketed that, you know, these tools and systems are there to help help humanity and whatnot, there's that, that existential harm aspect of it that we haven't fully thought through of those implications. It's usually been given lip service, uh, Tim Guru from, uh, Google, you know, uh, they famously were, were let go for bringing up those types of cha those, those questions.
And I see more and more of that is she, she highlights a lot of those stories from, from other companies. And, and it worries me that a lot of that, that that human safety aspect has really been pushed to the side. It's like, well, they, they'll, they'll walk both ends of it.
It, it's like, well, we're not there yet, so you don't have to worry about it going rogue. But then they constantly push to get to that point where it can now go rogue. I think though, the most recent story out now is as the, the deception that the anthropic AI does for the engineer, it uncovers, uh, you know, an affair, um, and ref, you know, basically try to use subterfuge.
So it's like, you know, so what angle do you wanna plan, like telling everybody it's safe or actually seeing all this stuff that it's potentially doing wrong? And it's like, if I'm, I'm a human person with those seven boxes of anxiety, I'm like, oh hell, I need an eighth box just to have to handle this existential dread. You know, I need, I need extra memory.
I know, I think I, you know, I think I developed a, a certain, um, relief cycle mm-hmm. When I see certain conditions, and I keep seeing those around right now. And, you know, look, my, my inbox, my anxiety levels and so forth, they're all maxed out.
Um, however, yeah. Right. The, the, you know, when something, when a problem just becomes so endemic, you know, if it is possible, you know, the pressure per solutions just get so high.
You know, and I, um, and, and you know, how much, you know, uh, influence game is, you know, because I, because I think that we're not done building the internet. I think our big problem is, you know, as we talking about in the green room, right? We're in early in this conversation.
We've been down these past. When are we gonna, are we finally gonna get there? Are we there yet?
Um, and I don't think it's that we haven't achieved things or we've gotten things or whatnot, is we're not done. We have not built an internet, not one. Yeah.
We had that built and finished one completed internet yet, and we have still a whole vast domains of security where mm-hmm. Folks like you and I have for decades, said, yeah, that's really, we need to get to that. And the fact that we haven't dealt with human cognition at all at a cybersecurity level, you know, is a fascinating indicator that maybe we have some work to do.
There's been some studies, but it's more or less that I guess everyone kind of considers that a soft science. I think, you know, when I've gotten discussions recently at my last employer about vulnerabilities and, and, you know, the discussions all circle around, well, can we put it into this tracking system? You know, is it, uh, uh, you know, this, this thing that feeds into another system which feeds into, you know, five other systems or whatever to track and hopefully, you know, help with remediation, but none of those address the cell vulnerabilities, the, the policy stuff, the human aspect, the, the things, you know, practice and, and procedures that need to get changed to keep them from occurring again.
So, as you mentioned about things not getting finished, being built, I don't think we have a strategy. I, I think, you know, the, in the sixties when Arnet was, was born, we hadn't gotten to the point where, um, the, the fact that, uh, you know, what, what are you gonna do next? It's just like, we built it, people will come, but like, what's the end game?
Does anybody have an end game? And, you know, this goes back to like I talk, uh, talk at length about like a sufficiently good strategy. Everything will eventually regress back to that, that straight line strategy.
If it's a good enough strategy, it's resourced and it's, it's, you know, people agree to it and so forth. But you're, you know, as you start out, you're gonna have a lot of this back and forth as you're trying to do path finding. Well, right now, internet ai, there's, there's no strategy.
It's just kind of like we have this ball of, you know, nuclear energy here of, of just this, this concept and, and, and mph, uh, to go and, and exploit this, this new capability, the new shiny new thing as it was with blockchain, as it was with the internet back, you know, when it, you know, that eternal September thing, uh, you know, became rapidly commercialized rather than, you know, where it was originally a a, a research and a scholastic environment. And now I think that that goal of acquiring money from that exploitation, uh, issues the concept of a strategy. Like, where are we going?
Are we just like wandering through the forest? Or like, do we, do we wanna go on vacation? Like, I, I wanna go from DC to San Francisco.
Do I wanna take a wandering route and maybe show up in a couple months? Or do I wanna take a direct route and get there in a week? You know?
Um, I've done it in two days, but that's besides the point. I won't go into that too often. But yeah, I mean, that's, that's, we, we don't have a strategy.
I don't think e everyone who says they claims claims there's one out there now. There's no strategy, there's no leadership. Well, I, I'll agree with that.
I, I, again, I, you, I don't wanna, I don't wanna sound like I'm unaware right now being a mm-hmm. A, you know, Pollyanna caffeinated enthusiast and so forth comes with, with costs, but some opportunities as well, right? 'cause when you, you know, when you get past, again, I worry about things like actually being able to do this.
I worry, you know, the state of the world today, right? You know, that the, the fact that on the human side, and I, I know we're getting, pushing at the, the, the limited of time. But, you know, the fact that as threat actors, if I was a threat actor today, I wouldn't write a computer virus.
I don't care. Right? I would mess with people's heads that's working really, really well.
There are zero, zero do zero, uh, defenses against that. Everything you and I have built, um, historically just doesn't deal with that human language. Forget it.
Right. You know, how do I, you know, understand it at all, Alexa, much less, you know, get the kind of nuance understanding of it that that would have any protective value in a human human situation. So for everything else we're trying to do with it, again, I, uh, the, the fact that we're actually it is forget ai, large language models like computer horsepower that can actually understand human speech well enough to, to get some of the subtlety, um, that smells to me like the kind of thing that future versions of our cells will expect to be built in through human information systems.
'cause otherwise, folks like you and I will just break them. Yeah. We do it now.
Yeah. Well, it's whether or not you're gonna do it subtly through, you know, coding and hacking that way, or you're just gonna take a, you know, the, the, um, you know, basically a sledgehammer to the, the data center. You know, like there's, there's two ways to to, to rebel against this in a way.
Um, or fight it if, if you're in of that mind. But yeah, I mean, it's, uh, yeah, I don't know. I don't know what the future brings, but I know, you know, given my age, I'm probably not gonna be around here for when the world melts down.
But, uh, be glad to exit before it does. Um, I have a feeling that's where we, I I don't, yeah, I don't wanna sound doom and gloom, but I just have a feeling, you know, just the, the folks in charge and stuff like that, I don't see this coming out with a positive ending right now. Well, you know, and, and is relative, you know, history will go in regardless, you know, they, you know, they mm-hmm.
You know, we may live through dooms days. Well, you know, we're, we're chiropractic fans, right. You know?
Yeah. I don't wanna be fatalistic by any means, but Yeah. But there are, There are all, there are a lot of apocalypses, right?
Yeah. You know, they end up being relative and so forth. Um, but yeah, I mean, I, I think I agree.
We are, we are experiencing society, societal risk, you know, so the risks are happening right now because of these is issues we can't control the, the, you know, information system we built and, and mm-hmm. People who exploit it can, you know, there's a mismatch in, in, in, in capabilities. And if that is not fixing enough time, then, you know, structures, companies, societies can collapse, right?
And it can maybe be long dark gaps before we finally figure it out. And, uh, there's gotta be a happier note to finish that on. But, uh, Yeah.
Otherwise that's a whole other, that's a whole other podcast at this point. 'cause you, you touched on something I would've definitely gone off on a, a slightly more political tangent, uh, having, uh, she mentioned about those in charge and taking control of stuff coming from the federal space. Uh, yeah.
I have an entire other soapbox to, to stand on talking about that, uh, uh, was very relevant to a point in time where I, I had space in that career area. So, Well, you know, the, the nice thing about doing these things, you know, that it is almost free. We can record another one.
And, uh, as you know, well, I'm not in this show, you know, gonna, uh, not quite ready to do, say everything in a public form like this public. I have plans afoot that are going to play out one way or another. You know, this calendar year, these next couple months and so forth, it'll prove or disprove some of my thoughts on, on that issue.
Yeah. Like, I think we, I think we have defensive and responsive capabilities there that, and if you've watched this show this long today and you don't understand what I just said, then why are you watching? This is a security gig show, you know, these things.
Yeah. Yeah. So I'm gonna have to stop it there, just out of sheer, uh, inability to make time, uh, scratch I even longer.
So you and I can do this forever. Yeah. We just gotta go to that planet, uh, on Interstellar.
They, they had Matt Damon on, and then you can kind of stretch that time there. Right? Right.
So, thank you for the time today. Thanks for everything you've done for the industry and saved the bloody world and Yeah. And all the rest of us.
And for being a good friend and, and, and, uh, and for wearing my hat, you know, you, you're in that small crowd of folks who Yeah, I was gonna actually have you here with me. Blasco. Yep.
Blasco, right? Yeah. Every time I see her name, I think say, oh, NAS Emily's one of those.
Yeah. Yep. I remember it.
Disney, I, Disney Springs. Yeah. Headlights.
That probably came with that. It was fine. I was more or less trying to find out where the rental car was in the, the parking garage then.
Alright. So thank you again. Yeah.
Thank you all. Appreciate it that everybody out in the world, you know, spending your time with us today. Thanks for that.
Uh, be good, be safe and come back where we'll talk about these things more. In the world of high stakes data protection, security is paramount and there's no more secure system than one that's air gapped. But what does air gapped mean?
And are we changing the definition of the way the word is used? In this episode of the Tech Field Day podcast, virtual networks are air gapped. Welcome to the Tech Field Day podcast, where each episode we bring together a group of experts from across the enterprise IT space to discuss a single topic or a premise related to enterprise it.
The Tech Field Day podcast is often recorded in association with one of our tech Field day events. This week we're at Networking Field Day. Tech Field Day is a part of the future room group, and we are excited to be bringing you some of the brightest folks in the IT industry.
I'd like to take a moment for our panelists to introduce themselves before we jump into today's episode. Hi, I am Carol Warner ese. I've been in networking for 30 some years and happy to be here.
Um, I'm Jason Ginner, been in in networking for, uh, 20 some years, and, uh, also very happy to be here. John Osmond from, uh, consultant from Albuquerque, New Mexico. Um, most of the work I'm doing right now is working with the state of o uh, the state office of broadband.
And I've been doing this type of stuff for the whole. Um, I have 30 years or so. My name is Tom Hollingsworth and I'm a practice lead for Tech Field Day here at the Futurum Group.
Let's jump into the premise for today's episode. It's an iconic movie scene, an aging movie star dangling from a rig attached to the ceiling, trying to hack into an unhackable computer with lights and sensors everywhere. The black vault at Langley is the most air gapped system we have ever seen on a movie or TV set, but today I'll just put it in a different VLAN and nobody able to get to it.
Right. This episode we are gonna unpack whether or not air gap networks, I'm sorry, we are going to unpack whether or not virtual networks are air gap networks. And the reason why we brought that up, up is because during this event here at, uh, networking Field Day, we had a number of companies who told us that their solution was air gapped, which, um, created some Problematic questions from the delegates because they're like, well, what do you mean?
Like, it's completely isolated, right? Like, I have to walk over with a floppy disc in order to upload information and there's an armed guard with poison ra darts that will shoot me if I don't have the right, uh, passphrase of the day and that I don't match my photo. And everyone's like, uh, no, we're, we're, we're just, uh, sending the traffic down in a different wire.
Like that's air gapped, right? So I'm gonna, I'm gonna open this up to my, my panelists here because I'm sure that they have a strong opinion about this. Why can't a network be air gapped as long as the traffic channels are just separated?
Uh, I think the, the term itself, air gapped implies there's air in between. You know, it's that it's a, the physically separate environment, not just virtually separate. You, you've been buying those vacuum sealed cat five cables 'cause there's air in those things.
Very true. Uh, i, I just, I just feel as though the, the term implies the, a degree of security where there's, there's a physical isolation from, from, uh, uh, the other things that, that that, uh, you know, uh, uh, that, that it could, uh, result in, uh, exposure from breach. So I think a virtual environment doesn't really, I don't think it meets that criteria.
Well, I'm not sure. Um, there are some instances where you can use virtual networks and have air gap. So if the routing process doesn't know how to get to a sub done, if you can't get to the network from, um, say the enterprise has a storage network that they don't want anyone to reach.
And if you can't get there from anywhere in the, in the network, then it is air gapped, even if it's on the same infrastructure. I, I just think go back to the days of enter cap and things like that. You can confuse this equipment to actually let it drop things from each of these virtual contracts into another one.
So I don't think we can actually say that an air gap is an air gap unless it's physically has air in it. I mean, my good friend John Pross, who was my Novell, uh, maj, was able to hide an entire Novell server on a network by, uh, changing ethernet frame types. Four workstations on the network could talk to that server.
Yes, it was plugged into the network, but we considered that air gapped because literally no one could talk to it if you weren't on one of those workstations. And it was because a principal was absolutely paranoid that one of the students was going to hack into the database to change their grades. 'cause I guess he watched TCE Bueller's day off.
So would, would you consider something like that where we do protocol trickery to hide things as being sufficiently air capped? Or do we actually need to unplug the machine and run it across the room to isolate it? I think there's so many other terms for, for virtualization of network.
Um, there, you know, we've got VRSI mean, you mentioned VLANs. I think that there's already terms for that, that level of separation. Uh, and, and again, I feel like air gap implies a physical separation, uh, a, a secure, uh, environment, a physically secure environment for, for that.
Then why do we keep using the term? Because I feel like isolated or secured or those words are way better to describe what we're offering. Why are we so hung up on air gapped?
So, So when I was talking about the air gap storage network, it's truly a isolated storage gap. I use the term wrong, and I think it's because a lot of terms sometimes are, um, sexier current or we once say marketing, right? Right.
And so when, when a vendor gets up and says, we are air gaped and then shows connections to the clouds and connections into the internet and collections from here and there and here and back to them, it's like, yeah, no, that's not air, air gap. And so there's a kind of a definition, and like in a car, there's a firewall, there's a space between the engine and the compartment where people sit. And that's an air gap.
And we expect the sort of same thing in a network. And so a, a real air gap is a separation. You can't get between the two sort of A DMZ, All of the, all of these separations, you know, we're networking.
We've been doing these things for years and years. It's all tunneling of some type. Don't care if it's a different framing encapsulation on an avail network.
It, I mean, two secure shell sessions from one person's laptop to the same router. Do you call that air gap connections? Because I mean, I've got two connections that don't, they don't run on top of each other.
Um, I think that, you know, when you wanna look at it that way, I, I'll change my mind. That's air gap. I mean, you, you've got the ability to keep things away from each other.
We've got separate channels. There's no way for things to bleed through them. So a lot of it too is, uh, level of risk you're willing to accept.
So what's my definitive definition of air gap? Depends on who my customer is or who's trying to get an air gap. So what do you need an air gap?
When you say you want a ear gap? And they might come and say, I wanted an air gap, says, do you want this? Do you want, no way ever anyone could get between things, even me when I've built your network.
So if you wanted, so that the person who designed your network can't get to some other piece on your network without walking to another room, that's a true air gap. But if you wanna say, well, you're an exception, um, it's okay if this under these circumstances of that can happen. So you have to really sort of define what do you want, what level of air gap do you mean?
Is it close? Is it like a centimeter, a millimeter, A yard? What, what about the folks that are, you know, the, the, the always theoretical, and I don't think it's theoretical anymore, the attack where you actually use air as the medium and you actually use sound to transmit things at that point.
Even an air gap isn't sufficient for these types of things. It's how do you build these channels and what, uh, you know, what modalities are there for them to actually move information from one place to another? And how, you know, is it tunneled there?
Is it tunneled here? Um, where where is the wrapping mechanism to get the data from one point to another? And what is it, what physical, medium, what protocol, medium things of those nature.
Well, I guess the question then comes up if, if we're building these ridiculously ultra secure networks, who, who needs them? But like, that's the thing. If you give me enough money and enough resources, I can make a network so secure, nobody will ever be able to get into it.
You might as well turn it off. And that's usually what we end up saying is, is the only way this computer can be more secure is if you only power it on to do certain things with it. But then that comes back to, well, how useful is that system?
And what kind of data are you storing on there that can never be observed by another human being who isn't like hooked into the borg hive mind? I mean, we, we know that the ultimate answer is gonna be someone in the Department of Defense who has secrets that are so secret that if I even knew they existed, let alone what they were, my brain would explode into a thousand pieces. Right?
I don't know that outside of maybe three things, there's any data that, that is that secure. Well, it maybe not, it's not secure, but it's valuable. And so if I came up with a next AI algorithm that's going to someone's example this week, create a ton of fertilizer for a penny, and then just sort of change the world, change the market thinks that information is totally very important to someone, right?
And so that information I might wanna protect 'cause I have a vested interest in it, I built it, I can monetize it, I can make a lot of money, or I wanna change the world and feed people, hungry people everywhere. And there will be actors that don't want that getting out. So it's sort of how valuable is the information?
It's not necessarily just security information that has to be separated and isolated. It's, um, just intrinsically valuable information maybe. Okay?
It comes down to, it comes to value, whether it's, whether it's intelligence or if it has monetary value. And then the piece that I start thinking about on this is what are the mechanisms you use to keep these things apart? Is it, you know, is encryption ability to, is there a way to do air gapping?
Can you actually say this thing is encrypted from this point to that point? So if effectively got an air gap that no one can get into this for a given amount of time. So what about quantum encryption, which we were talking about earlier this week.
Can we use quantum encryption where someone tries to listen and it changes the data so they know it's it's an alarm and it's there. I mean, like, do we need that? Well, But you, I think you guys are kind of, you're, you're, you're moving past an obvious problem here.
Um, John, you bring up a good point. Yes. This, this system needs to be air gaps so nobody ever can touch it.
Uh, you enabled file vault, right? You've enabled login, uh, challenges, you've disabled all of the USB ports. Uh, my good friend Edward Lecky just pours super glue into the USB ports on his systems so that nobody can ever access them.
Uh, you've made it so that the, uh, their sound deadening equipment, so nobody can analyze your keystrokes to figure out your password. The monitors all have those, um, polarizing grills so that you can only see them when you're dead on, right? I've just named off a whole bunch of things that will infinitely raise the security of your network without having to isolate that machine.
But what's the first thing that everybody wants to go to? Oh, this has to be air GAed. Think about the number of laptops that are currently running a program that if they're out of contact from a main control server for more than a week, they automatically wipe.
To me, that's just as secure as having an air gap system because if I'm not checking in regularly, data's gone. And, but yet we get back to Tom Cruise dangling from the ceiling trying to hack the knock list out of a Packard Bell 4 86. You just said hack.
How did that, how does that, how has the word hacker changed throughout the years from somebody that was clever in doing something neat to something that was kind of nefarious? So is air gap gonna change so that it's from, it's not talking about a physical air gap between things or is it some construct that we build that stops the immediate passing of data? And the irony is, is that the original hacker Captain Crunch, whistled DTMF tone in through the air into a phone receiver to hack long distance.
So not even a phone receiver is safe from hacking, but you're right. What we have gone from is people who are investigating technology to understand how it works and make it work better to, um, individuals who wanna be famous and deface things to now like highly commercialized nation state backed criminal gangs that are looking, they're rifling through executive emails trying to uncover new product releases. They're, they're getting into like, you know, uh, business Newswire, pr Newswire databases the day before something happens so they can make money off the stock so that they can turn it into Bitcoin so that they can then back a nation state government that's isolated from the world by sanctions and things like that.
That's a long way from a whistle in a box of cereal. So in a world where we think that as long as we unplug the machine from the network, we're safe, is it even possible that that's not enough anymore? You still have to worry about EMF and can you, I mean, you might have to be in a magnet, uh, enclosed space, A a skiff, a secure compartmentalized information, uh, center where basically it's, it's shock isolated and surrounded on all sides by deadening equipment and like, you can't bring your phone in there.
Although we've seen pictures of, uh, uh, members of Congress who just love to bring their phones into skiffs and, and the intelligence people who roll their eyes because you're not supposed to do that. And that was actually one of the things that I was thinking about was, uh, when you look at a lot of the way that information has been disseminated from supposedly secret systems as of late, you're right, this paper is colored fuchsia and has stripes all over it that says do not copy. And then I reach into my pocket and I grab the greatest, you know, uh, little minox camera that ever existed and like, and then I can upload it to my iCloud account.
So we've already found ways to get past that. I mean, look at someone like, uh, Edward Snowden or, uh, Chelsea Manning who basically plugged their iPod into their computer at work and was able to download files because it turns out iPods can store PDFs just as well as they store MP threes. And they were able to sneak a lot of information out there.
And that system for all we know could have been air gapped. So are we, are we over blowing this? Are we, are we holding companies to a standard that is unrealistic by saying, you can't call it air gap unless there's air in the middle when what we're really saying is you should change the terminology to refer to it as an isolated system or change it to a compartmentalized system?
Yeah, I think it's become an overused and maybe nebulous term, kinda Like military grade encryption, right? Yeah. Like That or military intelligence Or cloud, you know, just nebulous could mean a bunch of different things to, to different people.
And uh, you know, I feel like in the modern context of marketing teams have probably latched onto it to imply a certain degree of security. Um, but it doesn't really, I don't really think it fits the, the original context. It was, it was, you know, meant to, meant to have, Yeah.
So maybe it's sort of, um, we need to hold the vendors or the people who say my system is air apt a little more accountable and say, I accept when you say my system is isolated, my system can be secured, my system is this. But when you say air gap and I look up the dictionary, what does air gap mean? I expect isolation and so, and physical isolation and no possible, and you can't just say, well, it's air gap because the only people who can get to it are, uh, on your own site.
I, I would agree with you. Will you look up the word literally in the dictionary and tell me what it means? Um, no.
'cause if I get up again, I'll break my knife. Well, the thing is, is literally now liter, it literally means its own antonym because we have redefined what the word literally means. It means something that actually happened, but also something that figuratively happened.
I mean, let's be fair, the name of this podcast used to be something that in the entire tech industry said, oh, when I'm talking about something happening in a physical location, it's on premise. No it's not, it's on premises. However, we have redefined terminology over the years, right?
So why can't we just roll with that? What's the harm in letting them say that it's air gapped when we all really know that it's not really air gap, but we really can't change what they're wanting to say. Um, maybe, uh, folks who just be wary of the term and, and really get more information about what that means to the, when they hear air gapped, find out what precisely does that mean?
Because again, I think that the term's a little too ne ne nebulous to assume, uh, anything. Or when you hear the term Avenger says, my technology is air gapped. You just look at 'em in the face and you say, you know how you tell when avenger is lying, they move the lips.
And when you say the word air gap in your lips, you're live. But at the same time, we're practitioners, right? Our job is to make all of the sales lives come true.
No kidding. That's actually what one of my sales guys told me in my old career. How can we increase the security level of these, uh, systems that they say are air gapped to make them more air gapped?
Like what, how can we as networking and security professionals, I mean I I remember stories of snort sensors that had their transmit wires clipped so that they couldn't accidentally reveal their location to people that were trying to evade the IDS. I mean, it's a little extreme. I I don't need to carry wire cutters, but like, what, what can we do to help make this a better place so that maybe it's not air gapped, but it's ultra secure That's gonna come down to, do you want to do it at a physical layer?
You just talked about clipping wires. I mean, conceivably you could, if you knew where people were going, you could add a packet level, route everything to a dead end and a black hole someplace. So only the traffic you want going to some, going to the right place.
You do the same thing at any level in the stack. And, um, when, as I keep telling, every single one we're doing is a tunnel of some type, it's an ASCI tunnel from, you know, your keyboard into that router. If you're spear sheed in, at some point in that tunneling point, you can circumvent the traffic.
You don't want to be moving to black hole or die or go someplace where it's, where it's being assimilated and watched in any of those pieces so that you can keep track of it. And air gaps. Do you want, is an air gap gonna be something you want to look at the data?
Or do you just want to throw it away so that it can't be used at all? 'cause there's a lot of information that, you know, the stuff you would normally throw away knowing it exists as a very good, you know, might be pertinent to you as well. So maybe air gapping isn't the right thing you wanna do.
Maybe it's, I want to corral the data I don't want so that I have it as as an intelligence source. And it might be a just a discussion point. So if my customer comes to me and says, I got this technology because it can be air gap, make it so, and I'll, I'll talk to them and say, okay, what do you mean by air gap?
How isolated do you want it? How much effort do you want to separate your information? How hard do you want it to be to upgrade your devices when new patches come in?
How hard you want it to be for anyone in the universe to reach it, anyone in your organization to reach it, anyone in a department to reach it? And it, it sort of, uh, will, uh, open discussions. So let's have some more discussions about what you want to say.
So if the vendor might have told you it's air gap, eh, yeah, it's possible I can make it air gap, but you'll never use it. I can make it this, I can make it that how I make it so it works for whoever bought it. So it become a more general term that implies a high degree of security, But shouldn't really Dig into a potential for a high degree of search.
Yeah. Although it could be AirCap, it doesn't have to be, and it might never be aired. And then when they say, oh, well I bought it 'cause it was cool, but I don't really want that.
All right, let's figure out the mess stuff you got, how we can build what you need. Tom pointed out words change, we still dial our phones. How many people have had a dial on their phone for, Well, I mean, think about password complexity requirements, right?
Every CEO on the planet wants the, the highest degree of password complexity so that I can't get hacked until they have to change their password every 30 days and it has to be 15 characters long with four special characters, no repeated characters and no repeats of your password for the last seven years. And then they immediately go turn it off Or network access control and it, yeah, I can't see the server anymore, turn it off because I wanna be able to see this. But you don't need to see that ZTNA says you're not authorized to, doesn't matter.
I'm the boss. And that's usually where we start getting into those compromising situations, right? Is I've created a policy and everybody has to follow that policy except for me, because I'm different in special, I can totally run his route on my own box.
I know I'm not supposed to, but I know what I'm doing. How bad can it be? And we all know what happens at the end of that because that, just like every other story, the reason why those things exist, the reason why those policies are in place is to prevent careless mistakes from becoming massive disasters.
And you know, something as simple as accidentally publishing the wrong API key in a GitHub repo and now all of a sudden you have a $12,000 AWS bill next month. Well what if that API key was, I don't know, the IP address of a satellite imaging, uh, system that was, uh, flying over a terrorist camp in, in Africa. Now the DOD knows how to prevent that from happening, but does you know the contractor that just is getting paid $12 an hour to work on this stuff?
I, I don't have a good answer for that. Words mean things according to one of our great delegates, Justin Warren, and he's absolutely right. When we use a specific term to refer to some kind of a policy construct or physical security, we have to be sure that what we're doing is accurately describing the situation as it is.
And look, you've been listening to the on-premise it roundtable for years, so I will be the first person to argue with that, but sometimes we actually have to take a step back and ask what we're doing. And as I've said to a number of people, if you use a better term, an isolated network, a virtually isolated network, you're gonna get the point across. But unfortunately, that's talking to tech people who are very critical of poor word choices.
A lot of people who buy technology want to hear something cool. Military grade, um, advanced AI, quantum, you name it, whether or not it actually is, is inconsequential. If it has the right buzzword, people are gonna buy it.
And so the next time someone comes into your office and starts talking about air gapping something, my recommendation is to hook them up to a harness and dangle them into your server room. And if they can actually manage to hack into your servers, you probably need to have something that's air gapped. You should also call Tom Cruise because he's probably gonna find a new stunt person that will just about do it for this episode of the Tech Field Day podcast.
I wanna thank everybody for tuning in. Uh, before we go, uh, people wanna find out more information about where you guys create content and share your things. Where can they go, Carol?
Uh, LinkedIn for me. Okay. LinkedIn and Blue Sky.
LinkedIn will work fine for me and we'll have, uh, links to their, uh, LinkedIn profiles and Blue Sky information and everything down in the show notes. Uh, we wanna thank you all for tuning in. com/podcast.
com as well as on our sister site Tech Strongs tv. We'll be back next week with another great episode. Until then, thank you so much for tuning in and make sure that you're sticking to the premise.