Self-Replicating AI Malware, GenAI LLM Firewalls and Passwordless for DevOps – Security Boulevard Chats EP16
Alan and Mitch discuss self-replicating AI malware, Cloudflare’s announced firewall to protect generative AI LLMs and Alan’s interview with Anna Pobletts, head of passwordless at 1Password, about how devs and DevOps teams can improve cybersecurity by eliminating passwords.
Transcript
Hey everybody, this is Mitch Ashley. And I'm Alan Shiel, and you're listening to Security Boulevard Chats. Yeah, we're out on the Boulevard, Mitchell, on the Boulevard, man.
We've been doing this security podcasting for a bit of time here, buddy. But every time I, you know, that was one of the nice things when we picked Security Boulevard as the name for the security site is, uh, and, and by the way, thanks to George Sch, who actually came up with the name and owned the domain give, give credit to George. Oh, I didn't know that.
That's, I, yes, that was George. This is George's idea, but to me it always sounds like a Bruce Springsteen song. Yep.
Right. And here I am revving up out on the Boulevard. But anyway, or maybe it was The Kinks on Hollywood Boulevard.
Nah, that's a different one. Um, all right, Mitch, I guess we went right off the tracks from the get go here. What I thought.
I don't think we're ever on the track, but, okay. Yeah, but you know what, as long as we're talking about it though, of course, for those who may not know, security Boulevard actually was 15 years in the making Mm-Hmm. Because it grew out of the security bloggers network that we started back in 2004 or so 20 years ago.
Yeah. And, um, big announcement is we're changing the name of the security bloggers network to Security Creators Network. Mm-Hmm.
And who is part of it too? That's the big expansion Yes. Opening.
Yeah. Well, arms To, it's not just bloggers, it's podcasters, it's video people. It's anyone who's creating content regarding security or cyber.
Yeah. If you want to be fancy and, and, uh, and it, you know, we're not gonna be as rigid. If you had a marketing title, you couldn't be here or something.
It's a lot more open. And I, I'm waiting on the contracts now. We're gonna have a nice security bloggers or security creators network meet up at RSA.
That's, that's, that's a highlight for us at RSA. A lot of great things happen. Ours that's always been Absolutely.
A Wednesday evening event. Right? Yep.
We're gonna have a partnership there too. I'm, I'm very excited. More details to come shortly.
Hang tight. Anyway. Alright, Mitch.
We got that out of the way. Yeah. Well, let's talk about, you know, we can't, can't go too far into the podcast without talking about AI and, uh, I'm, yes.
I think there's a theme here today. There is Richie Jennings, our, our, uh, kind of blogger watch, right? Mm-Hmm.
Humble blogger watcher had a really great, uh, post about self, self-replicating ai, uh, self-replicating AI malware in ai. Yeah. I left off an important word.
Well, look, sooner or later, AI will be self-replicating. And of course, that's one of the principles of, is something alive or not right? Mm-Hmm.
Can it self replicate? Yep. General, but artificial intelligence.
Right? Yeah. But the, this is, this is sort of a doomsday scenario where the AI can be manipulated into sending spam and stealing information and passwords and doing all kinds of bad stuff.
Mm-Hmm. And, you know, I'm not saying it's going to be the end of civilization as we know it. Right.
That's why we need to slow down with ai. But from a kind of classical block and tackle cybersecurity point of view, this sucks. You know, I mean, I don't know how else to say it.
It sucks. It's scary. I mean, we, it is scary.
This is, you know, it's like, it's like giving, taking the gun from Sergeant Schultz and putting it in Victor d Drago's hands or something, you know? Yeah. Yes.
Duke Newcomb has got, yeah. It's got the weapon now. Whatcha supposed to do?
Well, a and it's, you know, a lot of the articles or a lot of the blog posts that Richie looked at, you know, ERs researchers are now saying, well, what can happen? What could, what could we do? Or what could the attackers do with generative ai?
With ai and how, how you could make it self-replicating this kind of thing. And so it's, it's not like suddenly we've been overwhelmed with this brand new attack and everybody's, you know, patching servers quite yet. But the part, part of it I, that I really get my head wrapped around is you could not, you could not only generate self-generate, uh, malware, but you could use, you could create ways of obfuscating what you've done.
So it isn't recognizable of what you've replicated. And now you're really into a world of, okay, that's doomed craziness. You can't tell craziness.
Right. Agreed. Interesting thought, experiment.
Agreed. Yeah. Um, scary stuff, Mitchell.
It is. It is. Well, well, let's, let's pull back from the brink.
Don't step over that. Collect, but don't get dead off the ledge. Walk me off the ledge.
Don't, don't update your will quite this minute. You know, if we save that for tonight or tomorrow. Mm-Hmm.
Um, you know, really interesting, uh, there's an article on, on, uh, security Boulevard about CloudFlare announcing unveiling their firewall to protect LLMs. Yeah. You knew this had to happen.
Interesting. It was CloudFlare that did it. Right.
Well, I got a couple of thoughts on this one, Mitch. Okay. First of all, I remember when you and I just recently, I guess it wasn't that recent, but it was late November, early December, we were at AWS reinvent Mm-Hmm.
And we interviewed a bunch of companies there around their AI Yep. Strategy and product offerings. And, uh, one of the themes that emerged was that a lot of these companies had made deals with the AI providers Mm-Hmm.
That their personal data would not get sucked into the LLM. Right. Or would not be available.
And one of the things that struck me then is wow, they're really trusting, you know, just because they signed a contract, it may not be the entity they signed the contract with. That sucks that information. Absolutely.
Yeah. But the fact that, that informa, because it wasn't that it sucked the information it was that used the information Mm-Hmm. But if that information is there, why that if someone else somehow got a hold of it Mm-Hmm.
And so I, I wasn't quite sold on the whole, oh, we signed a contract, they're not going to use it. You know, Ronald Reagan chu but verify. So now I guess it was only a matter of time until someone said, yeah, well let's just make sure that's not usable.
We'll put a firewall up around it. Well, was it, contracts are meant to be broken, rules are meant to be broken. So I guess Yeah, no, absolutely.
It happens. Doesn't mean, you know, best intentions and, you know, indemnity process. Well, like I said, it may not be the party to the contract.
Exactly. Yeah. Good point.
So, and you don't know where that date is going, and neither does not everybody knows. Right. It may, it may got, may have been put into something that gets released to one of the partners.
And unknowingly we weren't supposed to do that. You're gonna pull that back from an LLM that's already been trained on it. That's, you know, we've got a lot of stickiness to AI data and how that can train and potentially poison Right.
Data that's created from learning from training. Agreed, agreed, agreed. Agreed.
Um, you know, on the other hand you said, well, cloud, who thought CloudFlare would be the people to do it? Look, they're responsible for 25% or more of the traffic on the internet. Mm-Hmm.
You know, frankly, either them or Akamai, one of them had to do it, I think. 'cause they probably rep, you know, they could probably handle the, you know, at least now protect the greatest kind of attack surface, if you will, at scale. At large scale.
Yeah. Agreed. So I, I think that's, uh, a great thing.
I'm not quite sure how it really works. I haven't, I haven't been able to dive into the details. I think this was just announced like I believe, you know, like the fifth.
Yeah, no, just within the last couple days. Yeah. I haven't, but I, I just thought, you know, Mitch, you and I have seen firewalls from, what was the old Cisco, not the a was it a SP Was the firewall a, a something Was was their firewall.
Yeah, I remember That's going way back, you know, then there was the one that the guys who started Fortinet, the Y Brothers Mm-Hmm mm-Hmm. And that got sold to Juniper. It was, uh, not net something with the word net.
Net. I know. Um, don't make, you know, the Israel, of course, checkpoint.
Yeah. You know, sort of the, your classic firewall classic is what I'm trying to say. Yeah.
And then of course we saw the next Gen firewall, right. Palo Alto rolled that road, road to that Mm-Hmm. To billions of dollars in a very big public company.
Very success. Yeah. Next Gen firewall.
And then there was the waf waf Mm-Hmm. The web application firewall. Yep.
Right. And now we have the LLM firewall. LM firewall.
I, I'm really, I'm really interested to dig into this and learn more kind of what they're doing. And I think we may have to call some of our friends at CloudFlare. Yeah.
Yeah. And, uh, and see we, we might have some CloudFare CloudFlare content on Techstrong tv sooner than later. Anyway.
That'd be great. So it'd be great. Let's hope that works through.
But again, go check that article out. It's also on Security Boulevard. Um, then Mitch, the, the, the last one that I had that I wanted to throw up to you and see what your thoughts were, was, was, uh, an interview that Mike Ard did on Textron tv.
Mm-Hmm. I mean, I wanna make sure I get this woman's name right. Uh, Anna Pulitz from One Password, she's head of, get this head of password list for one password.
Isn't that, I have a little bit of an oxymoron there. No. But, um, anyway, Anna, you know, clue Mike into some of the latest, uh, uh, goings on in trying to move us off of passwords.
And in, and in this particular interview, Anna says, you know, developers and DevOps people can help by building password lists technology into the applications they are building. And I'm, I'm all for that. Don't get me wrong.
Two thoughts though, Mitch. First of all, if we eliminate passwords, what happens to one password? Well, uh, I, I have a feeling they'll carve out a role for themselves.
I know we'd put 'em on that commercial. I wanna be obsolete by the time I'm 25. You just have to sell right before you're obsolete.
Right. Sell, sell. No, that's not, I mean, you gotta have a place to store the pass keys, right?
I mean, it's, I guess you're trading off a digital version of, you know, something that's like, but isn't that replacing one password with another password? In some respect, it already does that today. Pass my password.
And other password managers will store your passkey when you create one for an app, a website that you go to, or logging into Google or whoever. So they've already started down that path. They're, they're, I think they're ahead of the curve now when it's all passkey.
Do you still need to, you gotta store 'em someplace. So guess, do you wanna put those in the browser? Probably.
I don't wanna put 'em in the browser. Now we're back to, you know, sending browser, browser. Well, I mean, is the browser the browser more secure than the password manager?
I hope? Well, um, or maybe it should be. I don't know.
But here's the thing. I do know, and, and this is from speaking to hundreds of people, not necessarily cyber folk, but regular people, civilians. And, um, no one loves passwords.
Everyone hates passwords. Yeah. Yep.
And anyone who tells you they don't repeat passwords or anything, like, that's full of crap. Because as much as I like having generated passwords, I know there's gonna be a point on my phone where I gotta access something and I can't frigging access it. 'cause, and so I have to do a password reset.
As a matter of fact, for many of my most important sites, I don't even f**k with it anymore. Mitchell. I just reset my password every time I log in.
It's almost easier. It's still hard. It is because, well, if I pick a, you know, I, I pick a generated password, don't expect me to remember it next time I'll uhhuh pick another generated password.
Yeah. And it takes a little longer. But this way I don't have to repeat passwords or have common ideas.
Um, I mean, and I've tried everything. I've tried the common phrases and series of words and all this crap. No one wants passwords.
Dude, as many entries as you and I probably have in our password managers that would consume more cycles than it would ever be worth. Trying to remember all of that. Yeah.
So here you could remember all of it. No, here, here's my question. I've been trying to think now, what is a way, could we have our password managers talking to the sites and applications that we use and doing like we do with Digital Sur Certificates?
Where is a TTL that it'll regenerate the password for us. So maybe five times every minute, you know, passwords are being updated all the time. So it's this a constantly changing thing.
And as long as we've got our password manager, we can get in May, you know what, that's, maybe that's a wild idea. Maybe it's a different, and then if you don't pay your password manager fees, do they trash 'em on you and you Yeah. Then they digital often.
Kinda like that. What was that movie where they erased your digital identity and you're a non-person. That's right.
You're a non-entity, non-person. You can't function well. But yeah.
Let's use AI to manage it and then some AI malware will steal it all. That's right. Back to our first start, back to our first Replic full circle.
Uh, I mean, I, I, you know, so I always believed that technology would solve this issue. And I always felt we'd go to some kind of biometrical thing. Mm-Hmm.
Base id, which of course can be faked or fingerprints, but there's gotta be something, you know, and especially in the age of ai, we need, we need better authentication Mm-Hmm. Of being real, um, of who we are. Because really at the end of the day, that's what passwords are about.
Right. Proving we are who we say we are. Yeah.
And two factor, and even passkey is using biometric or some other a device or something that has also authenticated you. It's gotta be. And, and it's gotta help.
You know what, Mitch, on that note, I gotta bring up something. You're aware of this that's going on here in Textron. Mm-Hmm.
Some clowns with Indian accents from area code 7 0 2. They're not smishing. You thought it was a Smid?
Mm-Hmm. It's not a mish Mm-Hmm. They're actually calling our employees pretending to be me, asking to go, asking them to go get some Apple gift or Amazon gift cards, Uhhuh, and give them the numbers.
That, that really was me, by the way. No, I'm just kidding. That was you speaking in your Indian and accent.
I think this is my deep fake Yeah, it's your deep faith. Now I'm just, I'm thinking, is this a warmup? Because somehow they're gonna clone my voice and it will sound like me coming up.
Or are they that stupid? You know, it feels like we're just at the beginning. You know, this is the next s scourge of, you know, we're gonna be living in this world of ridiculous requests, but we'll fall for some of them.
Right. You know? Mm-Hmm.
Whether it's gift cards or whatever it might be. Right. I need you to reset my password, set it to this.
Okay, I'll do that. I mean, yeah, I got on the phone today with one of our folks here, and he was like, no, I'm not buying you any gift cards. How do I know it's you?
And I said, I don't want you to buy me any gift cards. But, um, anyway, this is the crazy world we live in, in cyber. It is.
So I've got a, I've, things are gonna get interesting. Go ahead. I have, I have an important question that I needed to ask you.
And, and it's, and it's, it's a shift, but it's still security. So how in the world did the Harkens get somebody built in, you know, stuffed into the wall so that they could kill Duke Alito tra uh, tradies? How did, well, no, the person that happen stuffed in the wall, the person stuck in the wall was not killing Duke Alito a tradies.
He was gonna kill Paul, if you remember. Oh, oh, that was the, oh, that was the Paul that's, remember they had the seeker and then they had the person in the wall. That's, that's right.
Duke Lito or Treaties was killed because Dr. Yung Yun, whatever. Ey Ey ey.
Yeah. Right. They had his wife hostage and they were torturing her.
Yeah. And or so he believed she was probably already dead. Baron freed him.
Like he freed his wife, huh? Right. They broke his training.
Yeah. Yeah. They broke his training.
Um, the haronian are evil Mitchell. They are, they are. They don't care.
They're evil people. But again, if you've listened to our DevOps chat podcast, go back and listen to our last episode there. This is a continuation another where the book diverged from the movie, or the movie Diverged from the book was letting out that Jessica was the daughter of Baron Harkonen right now that came out and I think in the prequel books.
I was, I don't remember. And I read, remember most of the Prequels? Yeah.
Thereby, uh, Ryan Herbert and, and Kevin Anderson. Mm-Hmm. And yes, because this was the, you know, the, the Benny Jess breeding program.
And so they were always trying to combine the aches and harin lines marrying the Duke. Right. Mm-Hmm.
Now, I don't know if you've read the Prequels, but the Har Conans weren't always evil. I didn't, I have not read 'em yet. No, tell me more.
Yeah, yeah. Well, in the, in the very beginning at the, but Larry and you know, the, but Larry and Jihad, where they defeated the thinking machines, Uhhuh. Yep.
It was the Haronian was a, was a, uh, hero. The haronian family with the heroes. What term did you, or even then the ache?
Um, well, you'll find, I don't wanna let it out for people who might wanna read the books. Okay. You don't want, but they dealt, they dealt the Haron, even that lon stat and the way the houses came together, it was a nasty, nasty place.
Mm-Hmm. Another game of Throne scenario, huh? Yeah, very much so.
And, um, you know, over time, and of course the Chedi and Har so at the end of that pre recall, the three things there. Mm-Hmm. Uh, and then there's another three pre, pre recall of the families, the Chedi, the Harko, and I forget the family that the emperor's part of now, but the Emper Emperor's family.
Yeah, I know. I, which one talking about it, explain, it explains all of that. All of it.
It's a rich, it's a rich universe. The Dune universe. Yes, it is.
Yes it is. And you know, there's religious overtones to it. I mean, Paul Modi is very much a messianic figure.
Mm-Hmm. Um, I always felt reading the book that the Reman was sort of Middle Eastern kind of, uh Oh yeah. Jihad.
I mean, you think all the language and you know, a lot of it's comes from the Middle East. Yeah. Have you seen the articles, um, about, I've seen things where Frank Herbert was tempted to, but never did sue, um, star Wars and, and because if you look at the first movie Tine is doing Yes.
It's, and um, well without the spice and the sand crawlers that are going, there's your machines that are collecting spice. Well, these are collecting droids there, there's a lot of parallels to sage. Yeah, absolutely.
But you know what, even my wife who's not a sci-fi aficionado said that the Dune universe is so much more complex and multi-layered than Star Wars. Absolutely. Star Wars, a simple Western Good guys, bad guys.
Yep. It's serials, right? Yeah.
There are spirals within spirals. We haven't even talked about the face dancers and all of that plans. Plans within plans.
Yep. Alright. It's steeper.
Must awaken. Go watch dude Two. It's a great movie.
It is. Sorry if we spoiled anything for you, but you No, no, it's all good. Great, great, great stuff.
Good Security Boulevard chat. Um, did I talk about security GRA network? Yes.
I thought I did. Yes, you did. Right up front.
Right up front. Yep. We, so stay tuned will probably announce something.
So we'll look for more on that. Yep. Yeah.
Security Boulevard and other places that we are so cool. I'm going to RSA especially. Check us out.
All right. Hey Mitchell. Thanks a lot, man.
It's been a lot of fun. And guess what, you've been listening to another episode of Security Boulevard Chats on the Boulevard. This is Mitch Ashley and Alex Shiel.
Been you very farewell till our next episode. Take care everybody. Okay.
Bye-Bye.