AI Investments, Nvidia–OpenAI Deal & Cybersecurity Risks | TSG Ep. 930
Mike, Chris Blask and Jeff Reich dive into the implications of a $100 billion investment commitment that NVIDIA is making to OpenAI.
Then the gang looks at the rise of cyberattacks involving artificial intelligence (AI) technologies before delving into the reasons why systems remain vulnerable to ransomware attacks following a massive disruption involving flights across Europe.
Transcript
Hey, everybody. Does AI stand for artificial investment? Let's find out.
We'll be back in a minute. Hey, folks, we're back and welcome to Textron Gang for Wednesday. We're here today with Chris Blas, who's a veteran, and Jeff Rich, who's from the, um, identity Defined Security alliance.
There you go. And Jeff has been on the show a couple of times, but for those of you who have not met him, he is kind of in charge of this alliance that focuses on identity, which is awesome 'cause we're gonna have a couple of security related conversations in a minute. But first, let's start with this whole investment from Nvidia into open ai, which is valued at a hundred billion dollars, but it comes in increments.
Apparently it's starts at $10 billion a throw for, uh, open AI ordering Nvidia chips and return from building some data centers around those chips, which theoretically becomes this virtuous cycle between your customer and a supplier who's gonna actually keep building these things. Chris, I know you've been dabbling in AI for a while, but this is the latest in a series of these investments that we've seen and video invested in Intel. And one of the dirty little secrets of AI apparently, is that we are subsidizing the crap out of the processing of those requests, and it's costing companies a lot more than they're charging end users.
So the question becomes, is this sustainable? And what do you make of this investment? So, I don't know, there's a couple ways to look at this.
Uh, look at this. You know, there's centralization and fragility. You know, are we integrating more vertical risk, you know, into the same stack, you know, for all sorts of reasons.
Economic control, uh, of technical, technical architecture, um, the same time, you know, this is the space. You know, I, I don't know that I can, I can double think the, the decision makers, you know, if I were them, would I be looking at certain things, maybe, right? And the, you know, as you say, the the phased approach of it, you know, may indicate some thoughtfulness on the, on the decision makers.
But, uh, we will see, you know, there's, there's again, it's, you know, we have these conversations all the time, and in this show, we literally have these conversations all the time. We try to think of something new to say, and sometimes just need to say the same things over again, I guess. But, uh, um, we understand.
I think everybody understands over the last several decades, a hundred years, however we wanna look at it. We've, while we've advanced things a lot, we've introduced a lot of brittle systems, you know, single to supply chain, where I spent so much of my time where it's hard to get people to think that, we'll, we need more than just one thin line of linked attestations to, to know where things coming from. So we're looking at chips and, and, and that whole thing, you know, this, this particular issue, you know, are we concentrating risk, you know, getting some benefits for some stakeholders, but at the same time, um, making them the system more fragile.
Uh, so interesting. A lot of concerns, Jeff. Yeah, I would offer that, although, uh, those are the right points, if from a bigger picture point of view, there's, if I were them and I were doing this investment, kinda like what you said, the phase approach makes sense for two main reasons.
One, is there ever gonna be a profit? And I think we need to ask ourselves that question. I, I don't have that answer yet, but I don't see a definite yes down the road, you know, we're gonna have to wait and see.
Um, and the second one is, and it plays on the profit motive to a degree. There's a lot of other hidden costs with ai, the energy use, the downstream environmental impact and everything else around that. Not to mention societal impact, which I'm not gonna touch, just, just mention it, but not touch it.
You add all that together. I don't, are the costs really as well defined as Nvidia thinks they are? Is it simply chips?
I, I think not, I can't help but wonder if this will just set the stage for some sort of investigation for antitrust eventually, because you created this kind of tight ecosystem. And I can get to Chris's point, there's virtue in that cycle, but at some point, somebody's gonna complain and say, you know, basically Nvidia has locked out competition in this space already. And, um, Chris, you know, you've been around federal governments, it might take them a few years to wrap their heads around it, but eventually somebody's gonna come knocking, right?
You would hope, right? And it, it, again, if you go down this path, this is what governance is for, right? And, uh, but you know, Jeff, to your point, we tend to, as we always have, again, this is not new, you know, if you worked in a global security free length of time, you realize that policies in, in, in various, you know, geographies and jurisdictions are what they are, and they're evolving along certain lines.
Um, we have a certain arc for that sort of thing in the, in the current, uh, US administration. So, which raises the question for me, will they, it depends, you know, is this an era of where one of these big players, you know, the US of market, um, will actually re reward and ignore you, uh, risky behavior? And if so, that I doesn't change my long term view of this, that, you know, you know, open systems and democracy and capitalism, all these things work because they're self-correcting.
Any one actor can make Barbara, you know, bad choices, uh, or what may look like good choices, but turn out to be bad choices in the end. And if they, um, that's not the right analogy for a show like this. If they fail spectacularly, um, someone else will pick it up.
And as we discussed in this, in this show, in this forum, I have a lot of questions about, you know, how we're even allocating workload now, Jeff, power allocation, you know, the systems we're putting together have enormous benefits to be clear, we're going this direction, nothing's gonna stop it. The question now is, how many keystone comps, uh, mistakes will we make along the way? And this one, again, I, you know, the people at the top people making the decisions to be clear are not idiots, right?
And, and almost nobody is, right? When you don't understand the dec decisions people are making, you know, and, and, and organizations being, uh, uh, you don't understand decisions organizations are making. The people inside are, are acting rationally.
So, you know, I, I can, you know, in a vacuum, I could argue the pros of this. I can, I can argue some of the risks of it. The reality is how will it play out in the environment that we're actually in?
And we'll see Mm-hmm. Our friends in Europe are gonna ultimately the US the about you should say. Yeah.
So I have a question on that. Uh, extending a bit more. The UN general assemblies meeting this week.
I have trouble believing that the two letters, AI won't come up somewhere. Yes, right there, there is an actual session about AI safety that's being discussed at this thing, but I'm sure in the hallways, a lot of companies and countries are having conversations amongst themselves about what does all this mean? Because it does feel like, you know, us dominance of the sector.
So I'm sure there'll be some interesting things. But let's imagine you were sitting over at a MD, does this mean that you gotta pony up $10 billion to get a customer for your AI chips? Is that how this is gonna play out as well?
I mean, you know, how crazy does this get, Chris? What do you say? Oh, it's too easy just just to say yes.
Right? And you get back to, you know, again, you know, we, we use these acronyms and company names. There are people there, you know, there's a bunch, you know, as you get to the decision making cycle, not that many.
And they'll make their choices. And, you know, and, uh, and I'm not gonna advise them, or at least not for free, but I'm, but, uh, yeah, there's a lot of arguments to be said for, yes. I mean, look, like at, to my last statement, I can argue what might be the right or wrong thing to do for, you know, technical reasons or structural reasons, but there's also, we live in a reality, right?
And the reality, uh, like you say, Jeff, you know, we have, we have this going on. We have the UN general assembly next week, we have all sorts of global policy things going on. And when you're looking at the kind of timeframes and the financial investments, you know, you know, and the number of competitors, the number of entities globally doing these sort of things, you've gotta make your choices.
Um, and, and it, it, at the risk of to in fact, repeat myself, you know, this, this, you know, these things will play out. I have very strong opinions. The AI side of thing, lemme just take it there.
Narrative sovereignty is a term we tend to use a lot more in this is a civic AI and world we're talking about these days. And it's not, it's not, you know, quite a lot. You can talk about disinformation, misinformation, influence campaigns, and that's a, a real and present, uh, issue, but it's also in how we run our systems.
You know, of do I control the narrative sovereignty of my company? Do I actually know what I'm saying? What we're saying, what we say to each other, what we're saying to the outside world?
Turns out we haven't been doing that extremely well. And this whole ai, well, again, what we are calling AI this time around, uh, again, um, lends itself really well to that. So the attestation systems that that, that I and many others seem to think that we need on a global basis to deal with these sort of human issues, get back into corporate decision making, what is the right decision?
Are we making decisions transparently even amongst ourselves inside the company, um, or not? And, you know, so I look at these executives, they're trying to navigate worlds where literally, Mike, you and I, you know, this, I find this calendar year, particularly this thread of conversations every week to be fascinating, looking back at what I said and what we talked about in January or March or June. June was a, a huge month this year, right?
The world kind of changed in June. We're here now. If you are at the, in the corporate office, in the C-suite at a MD, how exactly do you navigate that?
That's hell of a question, right? And I'm happy to be an armchair critic and, and say what I would do, but it's, we need to recognize the reality of the, the decision of the, the, the, the situation, the deci decision makers in. And, and so anyways said at the long, long rant, but I think the kind of, so the narrative sovereignty, attestation systems, this is 99% of what I, and quiet wire and the open source civic ai we're all about.
We're applying this in different ways. And I look at this block, this topic, you know, this, this, what we're talking about here is yet another process that will be inflicted by the success or lack of success of that adoption of attestation systems, which is a little bit abstract and perhaps opaque for your, for your, uh, uh, for the viewing audience. But do we know what we're even doing?
And we, where we see these cartoonists sort of decisions we make, and it's, it seems ridiculous, but you get in on the inside and again, find out that the individual humans are be, are acting rationally. It's just that our systems aren't very rational. I suppose when I look at it, and Jeff, you've been around these kinds of decisions before and we, you know, whether it's job or whatever else, but it seems like within Nvidia, it's not just the processors, it's the Cuda software framework that they're getting everybody right to, and those APIs, and that's where the lock-ins gonna be.
We have seen fixes to this in the past. So will there just become pressure to say, Hey, we need Cuda or some clone of it to be open source and available and avoid this kind in, and maybe that's how we resolve this issue. Uh, you know, I can't think of an answer that's very far from that, because it really boils down to Chris, when you talk about is this gonna be a success or not for, um, commercial organizations, the definition of success is ROI for every investment, bottom line.
That's it. The fact that is the bottom line. So that's what they're for.
Yes, exactly. They're company, they're money making organization. That's why we create them.
Yes. So Even though a concentrated M word could potentially exist on this, which could bring a bigger RI, we still don't even know that yet. So I, I think there will be, first of all, at some point e either there's gonna be a disruptor either from some regulator that says, no, you can't own everything, or there's going to be a disruption from another organization that says, we have an alternative way to do this.
And by the way, it costs a lot less, and it, it may run faster. There's gonna be other benefits. One of those two collisions is coming down the road.
And like Chris, I don't know which one it is, Right? And, and the, and, and the, and the reality is that, you know, four corporations, you know, you know, we're sitting here armchair, but maybe, you know, and I've been in this position in major, you know, corporations, myself, I have a legal fiduciary responsibility made decisions that increase shareholder value. It's not just greed.
That's what the, you know, that's why we agreed to form this thing. It's called the company. It makes money.
That's why we spend time in and we take roles and responsibilities, and, you know, this may work, you know, doing what I would see as morally and ethically and, and technologically and security, a bad idea may be the right choice because you will make more money. Now, I may not be personally happy with that. I may think it makes our infrastructure fragile, and I think I'm right, but that doesn't mean that it's the wrong choice for those stakeholders to make.
Mm-hmm. I also think there's a fork in the road, and it's nearer then we think, um, if you look at all of this stuff that they're talking about for these kind of large data centers, it's built around training. They're really focused on, we're gonna go train super intelligence, or AI general intelligence, or whatever the term of the day is you wanna do.
And that's all well and fine, but I think that the bulk of what we're looking at in the future is gonna be the running of the inference engines. And that doesn't necessarily require Nvidia GPUs. We can run a lot of different processors in those instances.
And I also think that we're gonna see a lot of these models are gonna be distilled into smaller models that run more efficiently on those things, and are better trained and better targeted. So maybe, you know, as, as great as this all sounds, but maybe you know, this, uh, a GI and case involving Nvidia and open AI is, you know, high end computer science, but not where the action's gonna be. Chris, am I crazy?
Yeah. Hold my coffee. Right?
You know, 'cause yes, I mean, you, we've talked this about this on, on, in this, you know, you and I, and you know, on this show we've talked about this workload distribution. What do you really need? A, you know, we're using Einstein to open the door, right?
You know, so every time we're booting up an AI and having, you know, this huge power surge and to the, to the point of the segment, we need all these chips. Um, that's not really justified. It's not the kind of thing that lasts long term, 3, 5, 7, 12 years from now.
We're gonna do it that way. No, we're not. We're gonna have massively distributed workloads where a lot of things will get done.
You had a, uh, just in the last couple weeks, we had a great conversation on this, where old computers, so we're using old computers today to do modern things, and with AI and l with actual l LMS running on 10-year-old machines, because the actual LLM part of it isn't much, and it doesn't need to be right away. It's not talking to a human, it's, it's performing functions. So, you know, I would like to hope for all my, my, uh, uh, my, my nonpartisan, uh, uh, statements to date.
I hope they're wrong. I hope everybody bet betting on owning the castle and owning the key turns out to be wrong. And I think there's a really good chance that they will be.
This is all, you know, to my last point, a chance that they won't. Maybe they're making the right calls, but I don't think so. So, so, Chris, are they gonna convert those big data centers in in 10 years to big storage facilities that you can mention?
Basketball courts? Yeah. Yeah.
Community centers. Yeah. Yeah, they Pickleball courts, man, pickleball.
All right, folks, I think we're gonna leave it there. But I, I, I would be careful when I was evaluating anybody's financial statements, you know, if I'm taking dollars from companies that I invested in, does that really count as a customer dollar or is that some other thing that we should keep track of in a different way? We'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and under the heading once again of why we can't have nice things. There's a report up on Security Boulevard talking about how the bad guys are starting to do some stuff with ai.
And it comes in two forms initially, and this may just be the beginning of a larger trend, but the first one is they're actually trying to poison the data we're using to train these AI models. And then the second part of it is, well, they're actually starting to use these DeepFakes a little more aggressively. Jeff, you live and breathe all this security stuff.
Does any of this a surprise you? And B, what else should we expect? Uh, no.
So the only thing that surprises me is that it's now coming to light. Um, I, I think this has been here, you know, every single tool that you have, whether it's a shovel, a pick, a handgun, or a rifle, can always be used in two different directions at least. Alright, so here we are.
Um, now that we have ai that's a great benefit in society and what we're doing for decisions and how we, you know, invest our money and, and how we make our company work and everything else, that, all the wonderful things that can come from AI when used properly, the bad guys look at this and say, Hey, you know, that, that looks like a really good idea. I think I'm gonna use it too. So we, we certainly can't be surprised, one, at poisoning the data.
That's not a new, uh, that's not a new trick at all. And I, and Chris is violently, uh, agreeing with this one. Not a new trick.
They're you simply using a new tool. So I'm really not that surprised that we're seeing it. I'm surprised that it took so long for it to become visible.
I think it's been here for a while. This is kind of like a, you know, when you have a heart attack, you realize, okay, if I look back over the past 15 years, I can see all the warning signs and lifestyle and everything else that got me here. I think that's where we are with poison data right now.
I think there's more of it out there than we believe. Um, and the, the second thing with DeepFakes, and this is something that's really close to what we do at IDSA, you know, identity is, has now become the cornerstone for security in any system. Because no matter what, if you don't know who or what you're dealing with, you don't know who what's gonna happen in, in any way.
This goes back to, if you look back at military bases, back to, you know, probably back to Roman times when someone approaches, the phrase that's uttered is who goes there? They wanna know who you are, and in some cases find a way to validate it. We have better ways to do that now, um, than than Roman times.
So, identify who you are, validate who you are, and that's not happening well enough, often enough. Right now, we are still taking shortcuts. Many organizations are still real happy with using SMS as a second factor in, uh, in authentication and, and including financial institutions, which amazes me healthcare.
Um, I, I actually had a, an encounter with a healthcare professional earlier this week who asked for my social security number. And the number I gave, I gave that individual was 2025. That's the year we're living in.
You shouldn't be asking me for my social security number anymore. What are you gonna do if I don't give it to you? And, and completely befuddled and said, okay, I guess you don't need to give it to me, then.
Well, thank you very much. I wish more people would take that position not to be, you know, uh, either arrogant or aggressive about it. But when you add all that together with deep fake, the same principle applies with deep fake.
Now, as good as those systems have become, and they're getting better by the hour, they are getting better by the hour. What we need to do as security professionals is find a way to, and use that and leverage the same systems to be able to ferret out the ones that have a high probability of being real and have a low probability and, and should be weeded out or find another way to authenticate who they are. And there are good ways to do that.
Now, whether it's with a token or a pass key, or using geolocation, there's so many different factors you could use now available to us that don't involve SMS, that lets you determine it Now with, um, AI and DeepFakes and interactions from machine to machine, which is the one that people aren't talking about yet, but is certainly there, there are certificates as an example that really should be used, not a new concept, but if you have a trusted certificate with a, with a ca that you can, that you have faith in, you could have a much higher probability that whatever machine interaction your machine is having is valid rather than coming from a bad guy. So, uh, you know, I may not be making anyone feel any better about this, because yeah, the bad times are here with it right now. A lot of good times are as well.
We just need to keep up. We can't be lazy about it. All right, so do we need like a new hashtag hashtag no ssn, what do you say?
Uh, oh, you, you know, I wouldn't mind an OSMS, uh, you know, I, I, I could, in fact, I may, I may stare at that. Yeah, I think that's not a bad idea. Um, it has its place, but not for authentication.
Chris. Well, we Have, go ahead. For the uninitiated who don't know what data poisoning is all about, what is it that cyber criminals are trying to do here?
Exactly. Because it seems like, you know, I'm kind of hoping to poison an LLM that may have some impact. It seems like a long shot, or, or is there some other way of thinking about this thing?
Well, without getting too deep into the gory details, I just basically wanna, uh, agree with Jeff. You know, this is not new. There's almost nothing new about this whatsoever, right?
I think what's, what's but of the things that are not new, the most useful thing to, to, uh, pay attention to is this is a speed thing, right? And Jeff, as you were talking, you know, we're, we're the same era, right? You know, war, not war dialing, but well word islanding, right?
You know, the, the, you know, back in the day someone realized that, hey, if you just call phone numbers and a modem picks up, you know, what phone number has a modem, and now you can have fun trying to break into that modem and the network behind it and whatnot, then somebody else said, you know what, I can just take an entire block of phone numbers and write a script and have my computer sit here while I'm asleep and call one phone number after another. And, uh, that sped things up massively because all of a sudden, you know, you could hundreds and thousands in a night. And, uh, and for those of us on this side of things, you know, that was early in my career, right?
I was like, oh, wow, that, that's an interesting little twist. And then, then just to, just to make that story as fun as it was, you know, the response was, we will make it illegal. There's a law, I think probably still in the book, books in the States, if you call someone and hang up without saying anything that's actually against the law, or it was made against the law, so what the, what the heck what the hackers did was just change the code and add a little wave file that says, sorry, wrong number.
So if a human picks up, they say, sorry, we're a number. So anyways, without, uh, uh, going too far down the rabbit hole, this is the same sort of thing. The, the hackers, you, the bad guys, um, now have AI tools that speed them up massively.
If the defenders don't, you know, address that, you know, and use AI tools to speed yourself up massively can be done mostly by not listening to people like Jeff and I, right? You know, just, just go out and do it. Get a chat GPT account asking about, tell her who you are, what you're trying to do, a situation.
You'll move forward. Not as fast as the bad guys, but way faster than all the other people around you. You know, don't have to be faster than the bear.
Um, and, uh, and Mike, I'm trying to re work our call if I actually, you know, adjust your question at all. They're trying to, you know, put information into your system so that your systems betray you, right? Again, right over and over and over again.
This is another interesting way to do it. And there are literally so many, and because of LLM model architecture, the word layer isn't just a metaphor. There are so many layers to do this in that we could have individual shows talking about individual, you know, a laura layer.
You wanna stick, you know, poisoning in the laura layer, in the actual model execution as opposed to, you know, poisoning the data set. You're training the models. You know, we could do this all day long.
And, and, but Jeff, you, you touched on, I will try to end on this. We have built this entire structure saying, I have an attestation, I've got a certificate. Wait, heaven, help us.
We'll have two and we'll use text messages. Um, that's not how anything works. Every decision we all make to pick the next words while talking to you right now to walk across the street, to do anything, to be a human being, we have 3, 4, 5, 6 things we, we can attestations that we can navigate on.
We have built our entire security architecture on one. I'm gonna get the ultimate cryptographic authentication for Jeff. And I'll know that one thing tells me that's Jeff.
No two is a start, not very good. Three is fantastic, four is ridiculous. It's not exponential, but we have to have more than one line of brittle authentication to give us access to whether or not you're poisoning my ai.
Hmm. So Jeff, is this data poisoning stuff just basically amounts to, um, damage for damage sake? I mean, is there any monetary purpose to this for the bad guys?
I mean, or are they just trying to, uh, you know, destroy things for the sake of havoc and they're just really, you know, anarchist? I don't know. Well, well, I think there's certainly an anarchist component somewhere in the earth.
There always is when there's bad guys involved because they can, they can jump on the wagon and, and have a certain level of anonymity in the beginning. But I think there's a lot of different vectors at play here. Let's, let's start out with a big one nation state, okay?
If na, if a nation state decides it wants to poison, um, data, for instance, that's being used by, um, an AI system, the advantage they have is from the time they start the poisoning until this time it's discovered, they can either redirect a strategy, they can redirect weapon deployment or, or anything in between. They can find a way to exfiltrate, uh, data using it potentially. Because if you put, if you poison data in a certain way, you can put markers in there that say, when I get this data, I know it's data that I poisoned.
And when I get something that doesn't have my marker, I know it's real data. So, you know, there's an exfiltration opportunity that really didn't exist before AI has allowed that to happen at scale. Uh, you know, and, and those at nation state, there's those too.
Plus there's also the whole, can I bring this nation down just by having all of its system collapse on themselves? That's another one too, that, that has been tried in the past with electric grids at, at different, um, uh, eastern European countries, Estonian in particular, had it happen, um, quite a few years ago. Once again, not new.
So those are the nation state vectors. I think you also have, you know, um, competitive, uh, corporate competitive vectors, and I'm not accusing any given company, but let's face it, there are organizations out there, or at least individuals in organizations that have no compunction about saying, I'm gonna find a way to either get my competitor's information or destroy my competitor. Same methodologies I talked about from a nation state.
Um, and then you have the, um, the individuals or small entities that, that just want to say, I'm going to hold data ransom. 'cause you could do that as well. Once again, with those markers, you could say, I'm gonna hold data ransom and let an organization know your data is going.
You can't trust your data. You don't know what's accurate. I do, if you want your accurate data, you're gonna pay me and, you know, cryptocurrency.
So there's that. And then there are the anarchists that just anarchists rather than just wanted to say, let me see what I can screw up. Here I go, boom.
All of those are there. Plus there's probably some I didn't mention. So, um, gosh, it feels like I'm the harbinger of doom on, on today's show.
Well, the nice thing about, yeah, what I'm really enjoying about this period of my career is, is that, you know, well, you know, you're right. We get to bring a lot of the doom, but one of the things I've been saying all along is that, you know, regardless, the lights are still on, the internet still works, and, you know, does that mean you're safe? Oh, lord, no.
And there's a lot of things you should do, but will it all work out in the end, generally speaking? Yeah, just don't try not to be the end. Um, but I I love your exel exfiltration example.
That's something people really get to Yeah. Visualize and, and it's, you're exactly right. And also each of these things, again, recursors me back to my point that, you know, it comes up over and over again.
We're having, you know, we're gonna let AI be agentic and actually do things. How do we trust it? It's like, what do we do now?
Well, there's Bob. I mean, Bob's been doing this for 30 years and we trust Bob. Why?
'cause he's Bob, well, what do you really, literally mean? And we find that, again, we have, you know, sort of fragile systems or not in OT and operational technology, we find that you can trust Bob. And you know why?
Because there's a system or a process around it. It's not really about Bob, right? It's about you have a system in place.
It doesn't break if Bob makes the wrong choice. Whereas we have these IT systems where if one system makes a bad choice, you're, you're, you're done. It shouldn't be, you know, we should have, again, two, at least two factor authentication.
Three again, literally in the anti station world, there are 3, 4, 5, and six. There's not seven, there's not 19. You know, it's not talking about gigabits of everything we're saying that if you were going to make a critical choice and you have one thing to base it on, you are fragile.
That is a brittle choice no matter who you are. If you have two, that's, you can triangulate on that from your position to those two. And with three, you can make, uh, mature choices about risk and, and decision.
Without those every single thing, Jeff, to your point, you know, is just fodder for you and I getting to get more airtime talking about today's latest, you know, silly risk. Well, to your point, I to your point, I mean, I'd the point, point where I discover he has a drinking problem and then him, all bits are off. But, um, when you think about this for a minute, and correct me if I don't understand this, but as I understand it, it's, these models aren't like software that I just go patch when I find there's a vulnerability.
To your point, they're layered and all that data's in there. And once the model's trashed, it's trashed. And I gotta pretty much go and rebuild the model and replace the entire thing.
And this is not an expensive proposition or inexpensive proposition, I don't know, but it seems like it's a, it's a level of fix that's a lot more complicated than people might think. Let me push back on both those points, right? Because, you know, you don't trust Bob up until you find out he has a drinking problem.
What my response to you is that you made a bad trust decision in the first place. How on earth did you build a critical infrastructure system and be the person responsible? And it comes down to whether or not, you know, whether or not Bob has a drinking problem.
And whether or not, no, you build the system so that if one node in the system like Bob or Bob, um, you know, just, and again, you know, Bob doesn't have a drinking problem. Bob just got contacted by nation state actors who told him that unless he does certain things with a totally straight face tomorrow at work, his family, you know, won't be there tonight. You didn't engineer a system to allow Bob to save his family's life.
Forget your company. Right? You know, there's a level of willful, negligent and competence.
I will take this approach. I just think about this. Yeah, if you've made those decisions out in the world and live, and it's got worked, okay, to be clear, you have had moral and ethical failures that you should personally be held liable for.
And if things happen, if the dam breaks because you made the decision to build the entire infrastructure based on whether or not Bob has a drinking problem, you will suffer the consequences and you will personally inside your own head. And people, you know, people in these levels of responsibility think of many of the, you know, the, the great disasters and the people, the captain in charge and so forth. Um, it doesn't work well for them because you can't justify that.
So we've built a lot of fragile systems. Jeff, That sounded like your classic insider threat problem. Is that what we're really looking at?
Boy, when Chris was describing that, the two words Aldrich Ames popped into my head, and, and, and for those of you who don't know, either Google it or ask your parents, um, uh, but Ridge Ames was, um, very deep in the intelligence community and was trusted, I won't use air quotes, but that that might be a justifiable use of them, was trusted for decades with top level nation secrets in the us and it was discovered that he was selling them. Uh, and he had been selling them for a long time, and it's because there was a single threat of trust that existed. And he was Bob, and, and there was no way to validate Was Bob, was alder change compromised?
Why was he compromised? Was it something he did intentionally? Was he under duress?
There was nothing really, I mean, there were, there were certainly cursory controls put into that, but there was nothing to really figure out is that actually happening or not. And, uh, I'm not certain we're in much better shape now than we were then in the intelligence community. But I, Let me, let me riff off that and go back to Mike the second half of your question, right?
Which is similarly, you know, these are level of complexity challenges, doesn't matter what the, what the frame is. You know, we, we think you, you would ask are the, if the layers of software at a ai, is it now so far? No, it has been there for a long time.
If you thought you really had a handle on your software and you knew what, no, you're wrong. I mean, since you know, 10 lines of code, no, that's not how it works. You've gotten away with it because it has not come back to bite you yet.
But you've needed systems all along that, again, assume that you don't know because, you know, emergent properties, levels of complexity. Um, it, it's, this is, this is where my inevitability curve thing comes to because it's an evolutionary thing. Uh, you see genetically, you know, biologically all sorts of things happen for a long time.
And then there's some evolutionary crux, and it, you can say that all of the other things were bad ideas, which is true literally in its own way, but in their environment they were fine, but they had fundamental flaws that didn't. Saber-tooth, you know, saber-tooth animals have evolved eight or nine times in the history, completely unrelated. They have no nothing to do with each other.
What they had to do with is a high oxygen environment that supports, you know, strength being the, the, the main determining factor and coffee being delivered without asking for it. So as soon as that stops, they go extinct immediately. There's no second generation, they stop immediately.
So there's a lot of these inflection points, you know, punctuated evolution to come along and, and they point out that, yeah, believing that you knew what your software was doing in the first place was a, was not a long-term choice. All right, folks, we gotta, we gotta, we gotta move on to our next subject, but I will just throw out another hashtag we might consider hashtag zero trust ai. Who knows, we'll be back in a minute.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hey folks, we're back in. We've been talking about ransomware and I feel like we've suggested maybe we were making a, uh, some progress here and we were more cyber resilient than ever. And then along comes this latest attack where, um, cyber criminals are basically taken out the luggage system that's managed by a company and probably none of us ever heard of until this week.
Uh, and now, uh, we see travel delays and it's impacting everybody. And Jeff, I know you've been looking at this, but do we just have, or is the underbelly of it just too damn soft? Well, I, I think this kind of goes back to a lot of what we were talking about in the previous segment, in that there's a level of trust that we have because it, nothing's gone wrong yet.
And, and there's a phrase I use universe is meta is is, and I'm gonna have to stop and say it metamorphic. The, the universe is metamorphic. And whether it's a saber tooth tiger or an an IT system or an AI layer, no matter what it is, it will change.
It can't remain static. It everything has to move and either grow or die, change or die. So, um, yeah, there's a lot of fragility in there overall.
We still have solid systems and sometimes it's issues like what, what's been happening with, um, a baggage handling and boarding passes in the EU that occurred this past week that make us think, do we have enough backup systems or different levels of trust to make this work? A lot of airlines in the EU thought, well, it's down. That's fine, we'll just issue paper tickets until they realized that the paper tickets that they print came from the same system.
So they, they, they still had a single point of failure. They, they, they didn't fix that problem. So yeah, if you wanna issue paper tickets, that's a good, that's a, a good redundancy, but have it completely out of stream from the system that, um, yet you're currently relying on when that system, you know, turns over and doesn't work, right?
So there's that. I, I'm gonna bring up a tangential and I think it's important to actually all three, uh, segments that we've discussed today about, and it's the airline industry. Now, Qantas Airlines and I, I happen to, I was affected by this, although I only because my name's in it, not for any other reason.
But, um, on on June 30th, um, Qantas was comp, the data was compromised, I believe it was ransomware. And they got personal data for 6 million customers. That's a pretty good size number names, phone numbers, birth dates, things like that.
No credit cards, no passwords, no passport information. So there was really no PII involved there. That's good.
But what happened, and I really think it's worth noting, is that the Board of Qantas cut the short-term bonuses for all senior leaders by 15% because of that. And boy, if I, I'm ringing the bell for that one because not that I wanna see people, you know, e executives bonuses cut, but it's, we are finally, for the first time, it's 2025. And, and boards of directors of companies are saying, Hey, you are the ones running the companies.
You're responsible for making this happen. Something bad happened that probably could have been prevented. You have to suffer because of it.
And I am very happy that that accountability has started to show up. And I don't wanna get us too far from the whole ransomware and, and the systems we, we wanna count on, but that's a downstream effect that I think we're gonna start seeing more of. And that's a healthy thing.
All right, well see, there's another hashtag right there, you know, hashtag cyber bonus cuts, and we'll just keep going with that. But Chris, I gotta ask you this question. 'cause I know you've talked about this multiple times over multiple shows now, but why in God's name do we keep having all these single points of failure?
Are we unable as a, as a, as entities and engineers, especially just to look at these systems and kind of figure out where these things are gonna be? 'cause you know, in hindsight, at least it seems pretty obvious, but for whatever reason, we just can't seem to be able to figure it out. Well, we were talking biological evolution just recently, right?
And, and saber, saber tooth creatures. So you have to understand the reality of the situation we're all living through, right? So, you know, just sticking with biology for a minute, you know, you're following a certain path and you know, you reproduce.
There's another generation, another generation, another generation that is the right path. Now, will it extend indefinitely to the future, you know, past some punctuation event? Uh, maybe not.
Uh, but they're separate issues. And you know, in my very first, uh, cybersecurity show when we launched border where I think it was 92 in Atlanta, and I, I was brought up, someone came up to me with, with an oil refinery, and I said, oh my God, I forgot about oil refinery. You know, the whole oil ot world that I came from forgot about it.
And I went back to my, you know, little five people in a dog, uh, company and said, Hey, can we do anything for ot? And the answer was, sure, and we can go outta business because we'll get one customer As, and Checkpoint is out there partnering with sun and yada yada. And at the turn of the century, it had exactly the same situation running the firewall business for Cisco.
And we at the point that we had a, we were humming along doing 60, $70 million a month, massive, uh, uh, presence, and a whole team of, of Cisco, uh, uh, folks brought a whole set of oil industry to us. And as the firewall team, we looked at it really hard and had to come back and say, no, we can't actually do it. You know, I mean, and to be clear, I I have a fiduciary responsible responsibility legally to, uh, Cisco shareholders who are, include not just the rich and powerful, but you know, retired people and their, their income to put money where it makes more money.
And in 2000, um, as a vendor, I could not have fixed that. And therefore, you know, at least from that source, which is a major source in the world, there was no solution. So what we keep coming back to is, is not that, you know, we're bad people or met bad companies are making bad decisions.
It's just that there are intrinsic flaws with this when and if we hit various punctuation events, um, these are unlikely to survive the gap. And I think, uh, the point of, of this particular topic and this ongoing conversation we have over the last, what is it, Mike, a year and a half or, or or more of, uh, of these, these calls, and we all have all these conversations all the time, is that I would, I would assert, I would, uh, pause it, that there's a number of, of chickens coming home to roost, uh, type of, of, of, of extinction events that are gonna be driving home, these sort of things that, yeah, long, thin, fragile, brittle, one by one, by one systems, uh, um, don't survive the break. I don't know, Jeff, maybe we should look at this entirely differently, right?
And just tell people that cyber attacks and these things are now a fact of life and they are likely to delay your flight as much as a snowstorm, and we should just kind of suck it up. And that's just the world we live in. Well, I, I'm not sure I would use, we need to suck it up.
And snowstorms are more predictable, by the way. So, um, the, in fact, I am at, you know, two weeks ago when I was on this show, I was at an airport, um, when I did it, and today I'm actually, you can see I have my flying braces on. Um, I'm on my way to the airport as soon as we, uh, complete this for yet another identity conference.
It's it's conference season. But to, to your point about what's gonna get in our way, it's, we need to stop thinking about, we really do need to change our perspective, but I don't think we should just give in and say, well, you know, it's gonna happen. Sorry, nope, I, sorry, I've been in this, I've been doing this 50 years and I've never said, oh, well I guess that's just the way it's gonna be.
Never. Um, and anyone I know that's had success doing this has never said that. And it's always a matter of change your perspective, and it usually means expand your perspective.
As an example, uh, when I would do, um, incident response or incident response planning and training, I would always focus on don't focus on what event caused your issue. Co focus on the effect of the issue, because there's gonna be multiple factor vectors that can give you that same effect. What are you gonna do when that effect is felt?
And then it doesn't matter if it's a snowstorm or if it's a ransomware attack, or if it's a union strike, it doesn't matter if your flight's interrupted. You need another way to get to where you're going or determine that you're not gonna go there. So you need to expand your perspective to say, should my flight not happen or be delayed?
How else could I accomplish what I want to do? You know, do I go try to rent a car or take a train or whatever it's gonna be That it literally, you know, that's, that's what, you know, well, seasoned travel is we li I, you know, you know, you're saying that as someone who does it, right? Because, but I'm on a plane.
I, on a knowing that, that I have a connection, I don't trust the connection is gonna leave the ground. Sometimes they don't. What am I gonna do?
I'm standing in some country, um, and I, and I think, you know, we need, you know, getting into the organization themselves. And Mike note, you know, I, I don't think, because I love the, I love the, uh, the, the across the aisle sort of, you know, cynicism versus optimism, debates. We have, this mirrors a lot of my favorite conversations because maybe I'm wrong, but I think we are driving towards an era that isn't close.
I wouldn't put it that way, but I think you can see it from here. And it's getting, it's getting into the, the frame where even people of my age are gonna, uh, uh, uh, in our working careers live in that world where cybersecurity gets at, where defense gets ahead of attack. It's just that we've rushed ahead of ourselves, we build communication systems that communicate absolutely will communicate.
However, are they secure? No. Well, Jesus, no.
And, and just, just not even, I mean, on every level. Um, and we're backing into the fact that we actually need to make them secure. Now, an artifact of that is that everyone alive now is used to the idea that, well, cyber attacks and hybrids, blah, blah, that doesn't mean that's intrinsically true forever.
I think we are capable of building information systems that are a lot harder to attack than to defend. You just not, you just need to have things in place that, to date, we have never implemented yet. But they're, you know, they, and none of it really knew rocket science.
I mean, I've got my own opinions on the things we can do right now, but you can look back over the decades and say, oh, that's right. People were saying that 40 years ago, 70 years ago, 120 years ago. We we're just still in a very startup phase in our entire global communication system.
Mm-hmm. All right, guys. Well, we ran long on the first two blocks, so I'm gonna end this here, but I would give notice on this point, the airline industry many years ago noticed that there were just far too many plane crashes and they got together and all the engineers, and they decided to build more resilient planes.
This can be the same model that we can use, not just in the airline industry, but everywhere else we go to build more resilient IT systems from the ground up, because it's pretty clear at this point that we're just suffering because of our own lack of maybe foresight. Hey gentlemen, thanks for being on the show and sharing your thoughts today. That was great as always.
And thank you all for watching the latest episode of Techstrong Gang. Please stay tuned for the rest of the lineup for Techstrong tv. We got some awesome stuff as usual, and we'll see you all again tomorrow.



