Curing Hallucinations, Teaching with AI & Ransomware Retirements | TSG Ep. 877
Alan, Mike, Jon, Garima Bajpai, and Guy Currier (Futurum Group) unpack efforts to cure AI hallucinations and explore how Microsoft, OpenAI, and Anthropic are helping teachers harness AI in the classroom 🎓.
They also look into why the Hunters International ransomware gang is shutting down—what it means for cybersecurity.
Transcript
Hey, everyone. Ah, modern medicine. You gotta love it.
A cure for hallucinations. You're watching Textron Gang. Hey everyone, it's Alan Shimel.
Happy Thursday. Ah, jk. It's not really a cure for hallucinations for people anyway, talking about AI hallucinations, and can we have, we found something that actually works on this.
I don't know if it's microdosing or what, but, um, we've got an interesting gang of people to talk about our subjects for today. Let me quickly introduce you to them. We have, uh, John Schwartz, who's been up all night with the latest Silicon Valley news, Garima Bo Powell, our good friend, guy Courier, and of course, the Dean, Mike Ard.
Ladies and gentlemen, let's jump right into our first year, A cure for AI hallucinations. Anyway, shades of one Flew over the Cuckoo's Nest. Mike, what are we talking about?
All right, well, there's one of these companies out there that specializes in ai and they've been mainly focused on infrastructure optimization, but they've put out a, uh, an announcement saying that they have a framework now where you can go into these models and look for the variables that indicate that this is where, you know, for DevOps folks, it's kind of like a feature flag that this is where some sort of effort has been made to suppress an answer. Or is the root cause of an issue where the LLM is just plain old hallucinating. I don't know exactly how this is gonna work out, but it's fascinating to me because it takes on an issue that we've been struggling with forever now.
And part of the problem with these models is I have to go in and retrain them, or I gotta give them additional data to fix these hallucinations. And that's a lot of effort. And these guys are saying, now we can fix this in minutes.
Guy, I know you looked at this. What's your take here? Have we finally come up with an answer here?
Or is this kind of just maybe wishful thinking? It's not wishful thinking. It's the real answer.
Is it the total answer? That's really doubtful. Um, so let's talk about what this is.
Um, it's a really neat trick. Uh, so the way models work is they work in layers of processing, you know, the famous neural net and, um, what, uh, CTGT is doing, which is the company founded, by the way, by two, you know, 20 something Wonder kins outta UCSD, go UCSD. Um, so what what it does is, uh, what they're doing is, uh, sort of inspecting the inference as it goes and finding the layer where the hallucination so-called occurs.
Now, I think there's a little bit of slight of hand going on here, because to a large degree, what they were, uh, working on was programmed bias or censorship, in other words, models, um, that, um, for not through the training and through the source data, but essentially through tweaking of the model, um, won't answer certain prompts or, or will answer with hallucinations. Um, so the neat trick is, you know, they start with this sort of listening post that sees how, um, the inference is going through every of these, you know, thousand, thousand million whatever layers in the model. And, and they are repeatedly hitting the model with prompts that they know or believe very strongly will produce the bias.
And it's almost like looking and seeing where what layers is is going off and lighting up most often when they do that. And then making adjustments to confirm. So when they amp up that layer, does it get worse?
When they lower that layer, does it get better? And that is a process that takes minutes. 'cause they only have to run, you know, a certain number of prompts can do it very fast.
And it's rel relatively mathematically defined how they do this whole thing. So that in the end, when in step three they make an adjustment, now you have an improved model. The slide of hand I referred to is if you have a bad training set, um, then, uh, or, you know, uh, if the training set, the data set is not curated, which these are huge data sets and they often are not, that is a source for hallucination and bias and so forth, famously, in computer vision where facial recognition doesn't work, uh, properly because of the training dataset.
So I'm not sure I see how this applies in the first instance, but it's still a really big announcement, um, kind of like deep seek where you're saying, wow, there's a whole lot that you can do without having to throw a thousand, a million GPUs and months of training time. And I think just to put this in perspective, um, we have been saying two things all along here. These are early days for ai.
We don't really understand how it works or the implications. Here's an example, a neat trick somebody figured out to quickly make models work better. And the second one is, and this is my favorite, always human supervision and human intervention is critical in using ai.
Well, and now we're talking about human intervention to improve models. I I realize it's all programmatically done, but the, the identification of likely hallucinations is confirmed by humans. So, um, this is, uh, really worth studying and looking at.
Yeah. I also wanna jump in here because, um, mean, GH has, uh, mentioned some positive sides of, you know, this announcement. Uh, being a DevOps, uh, practitioner, I always find interesting ways to see and challenge ourselves that what can be our next bet from a DevOps perspective.
So I see there are core components which, uh, gee has mentioned that, you know, how do we make, uh, our morals perfect. Then there is a middleware, which is in making, which is basically, you know, when you are prompting your system, how well you actually get the response, how do you monitor it, how do you infer it, and how do you interfere in the, uh, output? So that's the middle layer, which probably will be in making, and a lot of DevOps people are looking at it from an observative perspective.
And the third aspect is the top layer, which is observing, because there will be residual hallucinations. You know, uh, nobody has understood, uh, these models enough to claim that, you know, all hallucinations will be gone through this, uh, you know, announcement. I think there is a controlled approach and, uh, interrupt, uh, probability is kind of, you know, also being challenged here because explaining AI distance remains still remain difficult, right?
So there's a lot more to, you know, added to it if you see from a challenge perspective, like how do you, um, cut down the over reliance of automation, for example, uh, uh, for in this scenario, um, there will also be evolving threats, right? I mean, how people are also looking at, you know, uh, better ways to do new attacks. And the attack vector is also broadening, right?
And last, uh, point, which I think he also touched upon is error versus intent, right? I mean, we have to be very careful when we, uh, you know, deploy such kind of technology because human in the lead is, uh, is having an essential kind of, you know, uh, element to it when we are, uh, dealing with emerging technology. So, I mean, there is no silver bullet.
Again, uh, it's hard to separate the accidental from intentional misinformation. You know, am I the only one who sees the irony in trying to figure out a Chinese based AI and, and trying to get them to remove the censorship? I don't Think there's irony in that.
I think it's a damn good thing That the censorship or that we're trying to remove it, that we're trying to remove it. Let me use the, the tired old phrase, low hanging fruit. It seemed plausible, surely to these two researchers, uh, um, uh, that, um, examining deep seek would likely produce, um, easily found bias that they could then correct for, remember this, these biases, they call it censorship.
I think that's correct. There are layers in the model where those biases have sort of essentially been placed by human beings, and they're finding them and neutralizing them. And I, I think that, that, it's not really ironic, uh, to me it is a sensible way to go about the research.
Um, and it just so happens that, uh, China right now is an authoritarian country while capitalistic and tries to control information. Famously, I don't think they exactly deny it. So there you go.
They're not the only ones. Um, but true. Let, Let me, it could be some one of the worst ones, though.
I do wanna say that from a government standpoint, It's all relative. But let, let me, let me make a distinction here. I think there's a difference between human intentionally introduced bias slash censorship, right?
Such as in deep seek, not talking about the Erman Square, for instance, right? Versus some of the hallucination just where the fri did he make, did they make this up from that? We saw in, in a lot of the AI models more earlier on.
I don't, I don't see him quite as much anymore, but you know, I still remember when asking it to write an a bio a my own bio as a test, and it would make up, yeah, it would just flat out make up stuff. So that's the sleigh of hand. I was referring to Alan, which is that, uh, their test cases and their proof of concept have to do with intentionally placed bias.
But my view, my analysis of this is that the exact same technique could be used to find hallucinations. When you have a set of prompts that produce hallucinations, you don't actually have to care whether it was intentional or not. You can still find that layer in the model that shines when you run those prompts and you can still make those adjustments to, to, to the vectors, to, to produce a better result.
I think Gary's point is a perfect point, which is that what I, I'll rephrase if, if you don't mind, Gary, which is, we, this is a step, it's gonna have a reaction, and then we'll need further steps. And this will be development, just like every tech wave we've ever had. I'm excited about the whole idea that I could actually use an open source model now with some level of confidence that the answers are gonna be right.
'cause I have some level of control over that. 'cause historically, up until now, we've all been independent upon the AI model provider to put some level of governance or some level of control in that. And frankly, I'd like to see them all get outta that business.
And all of us just take responsibility for how we're gonna use these LLMs ourselves. The feature validation part is very interesting because, uh, this brings dynamic control. You know, if, let's say our compliance and regulatory, and I mentioned it over and over again, that the, if they wake up and they, uh, catch up this emerging technology wave, there's a lot which can be done through this dynamic control.
And, you know, if you bring observability and the prompt, uh, engineering in the loop, I think there's a lot of more, uh, trust getting built up for, for these technologies. So the, the problem though is, I mean, look, if, if it hallucinates writing my bio, I know my bio and I can easily tell it's a hallucination, unfortunately, you know, we've got a problem with fake news in this world, as it is. Most of the population, at least here in the US can tell the difference between fake news, conspiracy theories and tinfoil hats, right?
They're gonna have a hell of a hard time figuring out what's real or not that the AI is spitting out to them. So Mike, to your point, either you trust nothing or trust everything, or, you know, how do you know what to trust? And so putting it on a, a personal responsibility thing, it's your responsibility to make sure the AI's not BSing you is, is I think, going to be beyond us.
Yeah. And, and this is kind of a little peripheral to the issue, but I mean, I, I remember seeing a, a, a report in rock, you know, and, and the, the bi the amount of bias that's evident there bordering on blatant, blatant antisemitism, and it's actually getting worse at the same time. Musk talks about starting a third party.
But I, I mean, that's, this is something, the one, just going back to hallucinations though, is this is, I think it, it's, it's very encouraging news, a potential game changer. I mean, one of the headaches, lingering deterrence or, uh, obstacles in the wider use or trust of AI is, has been this case. And anything that addresses it, I think is positive.
And, um, so I'm very encouraged by it. Does this just work on deep sea, or this will work on any model in ai? No.
Well, it'll work on a neural net. Not every, not every model's in neural net, um, in the, in the world. And, and no doubt, uh, we will start, uh, experimenting, um, further, I mean, in the origin of ai, it wasn't always a neural net.
It's also has to be a feed forward neural net probably. And some neural nets are recursive, et cetera. So I don't wanna get too wonky.
Um, but the, the essential idea of, um, monitoring the propagation, 'cause that's kind of what it is of the prompt through the model. Um, it, it would have to be adjusted, I think, for, for other types than feed four neural nets. But, uh, you know, that's, again, more development for later.
For now, it just applies to, to feed four neural nets, which would be most of the generative AI models, if Not all. Those are the common ones we use. You know, Mike, I, I almost wish we had our friend Chris Blas on today's show and here about how his civic minded ai or whenever it's called, It's really, well, see, I'll tell you what's ironic, sorry.
At the end of the day, brands, quote unquote, and people, we still are the one, those are the ones we are going to be turning to and relying on because the systems are too complicated. And no, Mike, I don't think we can do it ourselves. If we can, we'll be using some kind of open source tool that does it for us.
And that means an open source organization that we're trusting. I mean, it still all comes back around to human supervision intervention, human interaction. I would like to distinguish between ourselves and the definition thereof.
There's a difference between ourselves as a you and me, and, and a retailer who has some AI capability can go in and control this stuff themselves. Now. And I think from an enterprise perspective, this is huge.
I mean, it's all got us individuals, but it's me as a company, I now have some level of confidence, a lot higher than I did before of what may or may not be in that AI model. So from that perspective, I think this is gonna drive a lot more AI models into production than anything I've seen lately. Uh, I don't wanna sound too negative about this whole thing, but I think, uh, one point which I'm trying to make here is it's, AI is becoming like a drug.
You know, the more you use it, you more you get addicted to it. And think about my 10-year-old kid in the house who has hands on chat, GPT, I just wanna kind of ensure that, you know, we understand that human accountability is, uh, of course required, but there is also concern about how do we use this technology who is behind, you know, how we regulate this, right? I mean, gee, I interrupt you.
What does it do to a 10-year-old, right? So I, it's the Wally Syndrome. While I, you know, from the movie, you know, Mike, I think I sent you an article last week I was reading, are, are we gonna lose the ability to write, right?
Because we're relying on AI to write for us. Are we gonna lose the ability to code when AI's doing all the coding? Are, are we destined to be corps floating around in some servo chair and our ais take care of us?
No. No. So think about the history of music, okay, around 1900.
Kurt Vonnegut had a great, a great statement about this. I wish you could remember. It was so clever.
It basically said that in every town and every village in the year 1900, there were all kinds of people with middling to fair ability to play instruments because they would get together once a week and they would play, and people were entertained. And the radio killed that because everybody could just beam in expertly produced music. So has the overall musical ability, average or median musical ability of the US or the world population gone down?
Yes, have, but you know, that was a shift, that was a change. So good writers will still be good writers who are human beings, who may very well use ai, but will be responsible for their final output. And it will either work or not work, and there will be fewer.
I'll Tell you that there are, when I consider that, you know, a lot of the people who have been filing copy, yeah, I'm not even sure they know how to write This. This is also true. On that note, we gotta take a break.
Yes, Mike? Yes. We'll come back.
Um, we're good. You know, speaking of this whole subject, we're gonna continue with teaching AI to teachers. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back and we're gonna talk a little bit more about usage of ai, but this time we're talking about how to train folks how to use it. But we're now training the teachers, or at least hopefully John, all the big AI companies seem to have gotten together and they're saying they're gonna have programs to help teachers make use of AI in the classroom and understand how it works. I kind of agreed at this initially with a, wow, that's awesome.
And then, you know, my pit of my stomach kind of went, well, I don't know how that's gonna turn out. So what's your thoughts here? Well, That's, yeah, I had to say I had the same reaction.
So, philanthropic, open ai and Microsoft announced with the American Federation of Teachers, which is one of the nation's largest, uh, teachers, unions, this creation of a AI training center, which will first be in Manhattan. They're gonna spend $23 million over the next several years. You know, actually when I saw that number, it, to me, this is kind of a personal aside, to me, it said a lot about where AI thinks about education and, and, and teachers $23 million.
And you compare that to the billions and billions of dollars these same companies are gonna spend on the infrastructure and investment in ai. So that's something that I, I kind of wanted to bring up. But the idea is that this academy is gonna offer this free virtual training to, uh, the, uh, union members.
There are about 2 million, um, K through 12 educators in particular. And the goal is to, to, to get at least maybe 400,000 people in person at this facility over the next five years in some, in some manner, to teach them how to use AI safely and ethically. Now, that's a very kind of broad sweeping generalization of, of the use.
So I reached out to a couple of teachers and talked to them, and their takeaway was they were highly encouraged, but I, and I, this is a big, but they, what they want to do is they want to use AI to create their curriculum much more quickly and efficiently, but they're also concerned about the exposure of it to their students. So there's still this misgiving that they have. But all in all, it's encouraging.
And I, and also within the context of the idea that a lot of these companies already have some sort of education partnership or initiative. So, OpenAI, for instance, has a partnership with California State University, um, you know, to bring its software to 500,000 students and faculty, philanthropic is introduced clawed for education. And, uh, Google has struck deals to bring its AI tools to public schools and universities.
I think what they want to do at the bottom line is as AI takes off, they wanna avoid a repeat of the whole STEM situation. They want more students to have access to technology, and they want the people who teach them to have that access as well, and have some sort of knowledge base to, in which to teach them and make people more comfortable because it's inevitable. Now, I think Garima mentioned this earlier, it's, it's, it's like a drug and it's spreading.
And I think it, this is just facing reality. It was something we have to do. And I think it's also something that the government is looking at, especially as it comes to competing as a country versus China and others.
Okay, so I, I got some thoughts on this. So blank, John, I agree with you at first blush. What a great idea, what a noble thing for these companies to do, right?
Because, you know, you can have kids who are self-taught figure it out playing at home. But isn't it great if you had teachers who are competent in this and able to teach it to the next generation and, and make sure maybe that they still know how to write and they still know how to code, but they use, they leverage AI to 10 x themselves to, to be better. But then I thought about a personal experience, iha, when my oldest son was in high school, his high school had all these like, areas of concentration and one was technology, and they sent a thing home looking for parents who, technology savvy to join our tab, our technology advisory board sounds perfect for Alan Humel, right?
I'm a tech dude. I'm in tech. I volunteer.
I wanna be involved in my son's education and make better education for the community. It was public high school. And I went to the technology advisory board meeting, and as it turned out, much like this AI initiative, it was sponsored by our good friends up in Redmond.
And it was great. The school had licenses from Microsoft office for Microsoft VB Studio, for Microsoft security tools, for a lot of Microsoft stuff. And I, I raised my hand.
I said, what about if we want to use, maybe it was Google or whatever, the open Libre or whatever an alternative was, or any alternative. And they said, oh no, oh no, you could use Microsoft. If you don't like Microsoft, you could use Microsoft.
And if you don't like that Microsoft, you could still use Microsoft. And so that's my only fear here is in doing this, are they locking? Apple did this in the education market in the eighties and nineties.
Every school you went into only had Apple computers. 'cause they were big in education. They were the education computer.
Are we locking in these players to train the next generation of AI users only on their products? See, that's, and we gotta work worry about. So They're going to raise these students if all goes well, according to plan on their technology.
You're, you're absolutely right. So they gained an early advantage by seeing, they Lock in, they lock in the DM word, they lock in, But they also see this, there, there's a statistic like two, two thirds of students, like 70% of students use chat GPT in some aspect, and only 30% of the teachers even understand what it is or know how to use it. Oh, abso, I, I agree.
It's a smart move. It's just, but I, this is like a marketing play too. You're absolutely right.
Oh, now you're starting to get at it, John. I also also see, I know, Yeah. I also see two big problems being a mother of, uh, a kid.
I mean, there are two big problems. And the problem is bigger than what Ellen, you mentioned, right? I mean, it's not only, uh, tech lock in.
Think about this, you know, this is not funded by the government. So this 23 million is funded by capitalist. And how they would re uh, benefits out of it is first of all, influencing the curriculum.
It's not only technology lock-in. So how would you, uh, I like imagine that the curriculum for the next generation would be influenced by these tech giants. And the second problem is that when you will train teachers, and you'll have all the data, right?
Who owns that data and how do you make use of that data? Are your next generation teachers being, you know, AI bots? Think about this.
So I think that, again, there has to be some kind of governance on top of this, these initiatives, because I feel very nervous as a parent if this happens to, uh, the kids, which, you know, so I'm, I'm gonna play into your paranoia. And, and, and so, uh, Trump signed this executive order in April, this White House task force in AI education, and they're asking for these public-private partnerships for K to 12 education, by the way, and ai and its Houston academia. And my concern is, who are some of the companies they're gonna be working with?
Because they are, in a sense, they're already working with open AI on the SoftBank, uh, Stargate project. So I suspect we're gonna see these names crop up. And again, it's like as, as, um, Alan pointed out with Microsoft, it's not just education.
They, this is lock-in strategy no matter what. The market is the exclusion of others. So, good guy, you wanna say something?
Go ahead. So it seems like Alan is playing the Mike Baard role. He's scratching his head and saying, gee, you know why this is, they're just trying to lock people in and, and, and listen, it's a good point, John.
You made a great point. Darma too. But I am, I'm gonna play the Allen role, and I'm gonna call b******t on this.
This is bull Pucky from beginning to end. The $23 million is a tell. This is a marketing effort to say, Hey, you know, we realize that, uh, AI is, uh, worrying you.
So, so we're gonna train the teachers. We have been through these before with other areas of culture, society, and technology. What do you think this training is going to do?
What do you think its purpose is? I've taken these trainings, not in ai, but in other things. The whole idea is to sing you, to sleep with happy.
Talk about how you can cooperate and it's gonna help you and it's not dangerous and all this other sort of stuff. And as far as the substantive, practical matter of how do I utilize this tool to be more productive, to especially to produce higher quality stuff and to be more reliable, that's gonna be completely absent. I have no faith in this whatsoever.
And I, I love anthropic. I think Claude is awesome. I love what Microsoft is doing.
Uh, I will leave it to everybody else to decide why I didn't mention the third brand that's in this announcement. Um, so, uh, that's great. And I'm not calling evil on anybody.
I'm saying this announcement and this effort is horse crap from beginning. No, But it also, and you know, the also thing, guys, this thing just fill, fizzle out, $23 million is nothing. I mean, this is, this is, They'll keep the marketing up, man.
They'll keep it up. They'll keep the, they'll, they'll keep the brainwashing of the teachers going. Like, you know, teachers are, are, are great at teaching.
They're not necessarily experts in how these types of tech systems work, right? I, I will defend the teachers because a missed several, several of 'em are my cousins, but they're smarter than you think. Yes.
And Randy Winegart, the, the, the head of the tea, the, the teacher's union is no fool. She's, she comes outta New York. I come out of, we've known her for years.
Um, I'm, you know, so I'm just like, I think they'll see it for what it is. But you know what, when you, when you're starving in the desert and someone opens up a hamburger stand, it's a good business. Um, right.
You, you, you know, you can tend to get a little choosy, less choosy about what, what kind of meat it is. It's, it's meat. It that being said, though, to the point made about, well, we don't have government regulation on this, and these tech vendors can unduly influence the, this organization, And we just passed a ban in the United States on government regulation of ai.
Well, why Is second, why is that any different? No, we didn't pass that ban. I, I think it was taken out, guy.
Oh, okay. But sorry, my bad. But Why is that any different than tech influence on the government itself?
It doesn't, hasn't big tech kind of bought this lock stock and barrel already? Yes. Same old s I'm gonna use the S word again.
Same old s I'm just saying like, I, I, it's, this is, you know, a velvet glove. The iron fist is everybody trust ai, use our ai, use All ai. But that being said, hey, so what, what would be the alternative that we'd like to see?
We'd like to see the government undertake a training program to make teachers teach AI better. Right? And that's gonna take dollars in a time where what has passed guy is you could use your vouchers to go to an alternative school and public school teach, you know, so public schools will get increasingly less, at least in the US I'm talking about increasingly less resources that they'll have available for things like teaching teachers about ai.
So if we don't have these private public partnerships to do it, we can't, we don't, there's just not the resources. That's a bigger discussion. But I'll just say that in, in the long term prospect, I'm optimistic and not because I think the government needs to intervene.
Fair enough. All right. So all we need is a bigger version of this.
Is what you're kind of saying is that Maybe with a little oversight. So it's not, you know, so it's not, I mean, this is, this is a privately run AI academy for teachers. That's what this comes down to.
I, I don't have a lot of faith in the education department, department of Education, especially when the, they had A, I thought it's going away. It's A one, right? Right.
Yeah. No teaching. This is sort of an oligarchy move, right?
Oh, yeah. You know, it's sort of absolutely. You know, the oligarch saying, don't worry, we will be your benevolent, you know, rulers.
But let's take a break on Textron Gang. Let, let's talk about cybersecurity. I had enough of the of Big Brother ai.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hey folks, we're back. And we are gonna shift the gear, as Alan said, to talk a little bit about cybersecurity. But there's one of these ransomware gangs out there call hunters, and they sent out a note saying, Hey, basically they're getting outta that business.
They even sent folks the keys to decrypt their data. And other folks are saying, well, maybe this is just another head fake. But Alan, what's your take on what's going on here?
You know, that these people suddenly wake up one morning and decide that they needed to do an active contrition. So first of all, let me say this is on an article on Security Boulevard. Should be in your ticker, check it out.
But Michael, you know, this isn't black hats turning to white hats. This is, you know, you're saying they're changing jerseys. What they're really doing is going back in the locker room, putting on just a different number, Jersey.
So you don't know which bad guy is which, but they're still bad guys. Right? And this isn't the first time these people have done this kind of, you know, change of, uh, change of protocol change, of, of attack, vector move, right?
They're, they wanted the big s ransomware as a service operators. And you know, this is now the second time where they're saying, Hey, we're pivoting. It's when you think about it, right?
This is a very mature ecosystem where you have companies that pivot, but let's be clear, they're not pivoting to the good guy side of the screen. They're not here to help you with your ransomware. They're not here to release new zero day vulnerabilities in a responsible disclosure method to prevent, or, you know, bad guys from hacking you.
That's not it at all. They're just saying this particular attack vector has gotten a little bit harder. It's gotten a little bit too crowded, a little too competitive.
It's, I'm not making the profit margins I used to, and we're gonna go find something that is, uh, profitable, maybe easier. And that's what they're doing. So they, they, you know, they have the same jerseys on just maybe different numbers, so you can't tell who's who, but they're still bad guys.
So are you saying, Alan, that uh, that, uh, this particular route of profit, criminal profit is drying up for them? So they're, they're shifting to another and it's waving their hands over here like they're Yeah, Yeah. I mean, overall, so the ransomware encrypting your data ransomware game isn't paying the kinds of dividends.
It was, let's say, during COVID three years ago, two, you know, two, three years ago. Um, for a lot of reasons, right? People are, are wise, better educated, so they don't fall for it as easily in spite of ai, improving the phishing, um, better, better solutions in terms of keeping offline copies that allow you to, to, to, uh, you know, reinstall or, or overcome the ran the, the encryption of ransomware, um, cyber insurance companies getting involved and knowing what, what the going price is and stuff like that.
Overall, ransomware, the margins on running a ransomware business are not what they were three years ago. There's probably lower hanging fruit, more money to be made doing some, I mean, even the ransomware people have moved from encrypting your data to doing something else, right? To, to hostage you basically to ransom you, right?
Ransom is not just encryption anymore. And so I'm sure we'll see them resurface with a new game in town, right? They go from three card Monte to the Shell game, You know?
So do you think that this represents some level of progress though, in the fact that they feel compelled to go shift? And is this an example of maybe where we're actually winning, or is this like a Charlie Sheen definition of what winning needs, If it'll make you feel better, you know, yeah. Where we, we we're making progress, but this is, this is the cat and mouse game that is security.
Before we called it cyber. And before it got so fancy, it's always been a cat and mouse. It it more than cat and mouse.
You know what, it's really like Roadrunner, Roadrunner and Coyote and the security guys are Wiley e Coyote dealing with Acme. And soon as Acme sends me a good unencrypted ransomware kinda solution, Roadrunner comes up with something else, right? We're, we're always a step behind.
And so nothing lasts forever, right? We still, you know, we don't have code red worms infecting us or you know, the love, the love virus or whatever it was called. This is like, this is the way of the world in security.
You move on to the next scam, right? You move on to the next attack vector, you move on to the next, you know, money maker in, in terms of how they're doing it. And they will, they did it before.
They weren't always what they are now, right? That it's just, this is security. Yes.
So, you know, it took us a little while, but we, we've definitely made progress on encrypted ransoms as a, as a vector. Mm-hmm. Or guy, let's look at it another way.
Won't they just come back with a more efficient model for doing the same thing? Who knows, maybe they'll use AI tools to start generating these attacks and they'll find a more economical approach and then they'll just be back doing it again. Yeah, I don't, I just, it sounds like Alan's saying what I was saying, um, roughly in the last segment, uh, which is that everything is old.
That's old as new again. It's just that's the criminals are gonna crime and if they are cyber criminals, they're gonna cybercrime and, uh, it's whack-a-mole all day long forever, right? That seems awfully pessimistic, but nonetheless, um, uh, you know, It's the reality.
It's human nature. Human nature doesn't change. So, No, but it's also the reality of being a cybersecurity professional.
And there's a reason why we have the burnout rates we do in cyber. There's a reason why we have, you know, some of the issues that we have in on, on human level with our cybersecurity pros because it, it is frustrating. You do make progress.
You fight the good fight every day. You fight the good fight, you try with limited resources going up against gangs like this that are, you know, making money hand over fist or well funded oftentimes are under the benevolent eye of a, of a foreign entity that allowed them to operate. And, you know, just, and, and it is a whack-a-mole game.
And, and after doing it for a while, you, you get tired of it and you, you kinda get jaded and desensitized and, and all the other bad things that come with it. And, uh, you know, it, it is, it is what it is. You know, black hats coming up next month.
I'll be out in Vegas doing video there. And, you know, that was always the premier place for security researchers to show, right? It's not RSA where it's the, the part the industry throws a conference for itself.
Black hat it used the least used to be, um, the place where security researchers go to show off their latest research. And I'm sure there'll be new vectors and new attack methods that are gonna be shown at, at, at Black Hat that take the place of sort of your encryption encrypted ransomware. Let me be clear, encrypted ransomware is only one kind of ransomware.
There are other ransomware, blackmail kind of things and stuff that are out there Point taken. But can, can we ask the wizards on the call, um, Gary Ma and Mike Ard is almost literally a wizard and his last name and, and John our, our Silicon Valley dean. Um, I feel like in the broad scope of history, crime has gone down and new, new avenues for crime appear, but why wouldn't they follow the same curve?
Now, it could take decades, but why crime went down, you know, across The world? Oh, no, no, sorry. No, let's get into that.
I mean, um, you know, let's take for example, the lottery. I can go buy a lottery ticket and it's perfectly legal, and yet I'm more than familiar with people who are still running numbers games down in places, and it's still very popular, even though technically it's illegal and the people running it are definitely mobsters, but we tolerate that. So my question is, back to you guys.
Are we really after eradicating cybercrime, or are we just trying to contain it so some level of acceptable cost that we can all kind of then wink at? So that's an old view of, of security, right? 5% cost.
5% to, you know, call it shrinkage, via cyber, via via security, via computer security. And to them, and that was an acceptable amount built into the model because they were highly profitable. It was built into their margins.
And, you know, this is before e-commerce was as big as maybe it is now, right? 5% was acceptable risk. And that right there guys, not just guy, but ladies and gentlemen, is security.
Security is not about stopping every attack. Security is not about having zero risk. Security isn't about whack-a-mole.
Every mo security is about managing risk. And so at the highest level, a good ciso, a good risk management team, looks at what is my risk from ransomware, from encrypted ransomware versus my risk from a zero day vulnerability on my cloud facing server versus the risk of other risks that I deal with in business. And they make a decision how much, how much will it cost to mitigate, right?
My, my risk of attack is 60%, I could mitigate it down to 20% at a cost of X dollars. It's an equation. And so do I wanna pay X dollars to take my risk from 60% to 20%?
Well, how about if I pay Y dollars and take it to 40% instead? Yeah, that's the annual loss, annualized loss expectancy that we've been talking about for years. And no, but always really put Practice, look at large enterprises.
This is especially retail e-commerce. This is what they go through. This is the exercise, You know, I'm gonna date myself, but I remember years and years ago, I remember writing about eBay and the fraud and how that was an issue, you know, back in the day.
And they would just say, look, it, it always comes down to a certain percentage of acceptable losses or instances of everything. And they would always, they always would give me a a certain percentage thing, but I always, the issue with me sometimes though is their percentage remain the same if the business was booming. So fraud in terms of dollars lost was, was increasing every year.
But you're, you're right, it's a formula for them. It, it's a, it's risk management. And at the end of the day, sometimes even good security people lose sight of that because we don't want even one attack to get through.
We wanna whack every single mole. Yeah. So let's, I mean, uh, also our technology to this mix, I mean, this is a business perspective, but if, you know, I talk about two things because I think it's essential to talk about the good work which we have done.
Organization like my three has also good, uh, done, uh, excellent job in, you know, protecting our businesses and laying out a strategy. And if you look at this particular, you know, threat vector, um, they have published specific white papers, how to contain them. So, uh, I would like to pat their back on the other side.
We also do not, uh, also shy away from the fact that quantum is coming, you know, so there might be some, you know, this is a emerging technology game, right? So we need to un ensure that we are equally aware that what are the next steps or next tactical steps in this process of, uh, you know, changing, right? So maybe that is something we, we should start to think about.
And organizations like Mitre and other, you know, organizations who are working in the space would be actively engaged in figuring it out. Uh, the next steps There. And there is, and you know, we're about outta time.
Let me close this segment with this though. Some good news as we sit here today, we are more secure and it is harder for the bad guys to be successful than they it's ever been. And every day we get better, they get better too, but every day we get better.
So especially for my security people out here, you're my people. We know how hard you fight. We know how hard it is doing this job, and we know how many holes you close and how many vectors you close off.
And the great work yeoman's work that security professionals do. And it is appreciated. And it, it does get better.
It's just in many ways, the the game is set. The rules of the game are set as such that it's impossible for us to total, to have total victory, right? Like World War II type total victory.
The bad guys are never surrendering. I don't care what these ransomware scumbags do. They're bad guys.
They're bad people. And that's who they are. We do the best we can.
So that's it. I'm gonna step off my soapbox. Is that all, is that like the cyber thin blue line?
Is that what that Was? Yeah, exactly. We'll be, wait, we've got a great tech drug tv, uh, show following this actually, we have, we have our good friends at Tech Field Day.
Steven and the Gang have a Tech Field day going on, so we'll, we'll have you take a look at that as well as Techstrong tv. We'll be back tomorrow with more. Until then, John Garima guy, Mike, thank you.
Thank you for watching this. Alan Hummel. We're out.




