Exploring CVE Management and Microsoft-OpenAI Partnership | TSG Ep. 925
The gang examines the future of the Common Vulnerabilities and Exposures (CVE) database, raising concerns about funding, management, and the need for more private sector involvement. The conversation then turns to Microsoft’s partnership with OpenAI, unpacking financial agreements, safety commitments, and the lingering implications of OpenAI’s nonprofit roots. New consumer products may be on the horizon as these dynamics reshape the AI landscape.
Transcript
Have you heard about the new Spielberg movie? Saving csa? You're watching Textron Gang.
Hey everyone. Welcome. Happy Wednesday, man.
It's, you know what Wednesday is right? It's a hump pump pump day. These weeks are going so fast, though it doesn't, it seems to be a little more than a speed bump than a hump.
But happy Wednesday to you. We've got a great lineup, great stuff to talk about today. Let's jump right into it.
Um, let me introduce you to our, our speakers for today, our gang members for today. First of all, sporting a nice city view that, that looks new. Yorky to me.
Um, it's good to be home. He's, uh, Futurum, COO, Dan O'Brien. Hey, Dan.
Good to have you here. Hey, Alan. Good to be here.
Absolutely. Joining. Dan is Kate Scarsella, who we found out is up in the Boston area.
Still got the classic New York, Boston, I think the Yankees of, well, they just played the Red Sox, but Kate, welcome. Thank you. Nice to be here.
And of course, joining us from out in the, my Rocky Mountains, our, uh, futur analyst, Mitch Ashley. Hey, Mitchell. Good day.
Good day. Rocky Mountain. Hi.
Absolutely. Now it's a little early for that, isn't it? Is it ever?
Okay. Um, anyway, Mitch, let's jump in with you. You know, there was a big to do, a big brewer a couple months ago, whether CAW was gonna be funded.
Of course, they've had some high level departures there. Friends of ours who we knew pretty well. Um, and then the whole thing came up with funding.
CVE. Was Mitre going to get funded? Who's gonna maintain CVE?
Should we maintain CVE? Is it a PRI private company that, or so sort of nonprofit that should maintain, maintain CVE? Well, thesis seems to have found this as its new mission for being that they're gonna save and maintain CVE.
What's the story here? Well, it's a bit of, uh, musical chairs, right? Do we have enough chairs to, for, to find, uh, funding for the CVE or do we need private funding?
Can it still be done by the government? It, it was pretty disruptive when this was announced a few months ago about this is no longer gonna be funded. Uh, we're stepping away from it.
It's gotta be a private thing that the industry takes on. And, and while disruption is never fun, especially something as significant like this, the security industry, it did cause us to kinda re-look at, so what are we gonna do? And is there a better way to do this?
And I think some of the reasons that people thought, should we still be funding it or doing it the way that we're doing CVEs, uh, the common vulnerability definitions and database is how accurate is it? Are we, do we using it the right way in terms of really helping us not only communicate and collaborate on it, but how does it lead to outcomes that help us not only react to, to vulnerabilities, but potentially things that are out in the wild? So yeah, CSA has stepped up and said, we're, you know, we're move CVEs into what they're calling the quality area era, excuse me.
Um, where they're focusing, not just communicating and collaboration, but more around accuracy and consistency and, and, um, ensuring trustworthiness in the, in the vulnerability information. I don't know if they're trustworthy of it was necessarily in question, but that's what they say that they're gonna emphasize. So they put together a plan that they've, uh, set out in a, I guess a white paper kind of form about strengthening the governance and, and modernizing how the program works and the infrastructure for it, and expanding the community participation, uh, and making sure that, you know, it's maintained, uh, as a vendor neutral kind of oversight.
I don't know that those things, again, were in question necessarily, especially the vendor neutral. I think it was pretty vendor neutral, though. You and I, Alan, we've been in security since, you know, early two thousands.
CVEs themselves have led and spurred, you know, many a startup, including some, um, so it, it, it is an, an engine for, you know, new innovation to be able to use this information as it, we take it out to market. So we'll see where this goes next. And, uh, you know, this is a pretty recent thing.
Uh, I, I'm guessing the reaction's gonna be pretty favorable. We just need some consistent, this is gonna happen. It's supported whoever we get behind it.
That's great. Let's move and, and make sure we have this information that we can work from Kate as a security professional, what do you think about this sort? Well, the, um, I, first of all, from a Mitre perspective, I really had liked that group.
I've always liked that group. I've always respected, um, the techniques and the sub techniques that they had. And so I would get concerned about having to reinvent the wheel.
It doesn't make a lot of sense to me. I don't understand personally, you know, they talk about quantity to quality. And I, while it is so important that right now that we have the right information, and I fear that in this period of transition, that what we can't afford is to have the drop of, of critical information that actually is impacting when I talk about critical, critical infrastructure.
And I worry that oftentimes we are having people who are leading these charges who don't know about cybersecurity, who haven't been around. Like, I mean, I, same here. I've, I've really been doing this since, you know, the early two thousands.
And I continually find people who are jumping into this mix with opinions. And to me, it just continues to look like Groundhogs Day. And if we, there's no building there, there's no like putting, like, we are gonna do this and we are going to move forward as, as we do this with, um, it's almost like a spaghetti strategy.
Like, I'm gonna throw a spaghetti on the wall and whatever sticks we're gonna go towards that I don't feel like we're building. And, and with Mitre, what I saw was that they really looked at the attack methodology and, and how it's happening. And, and I think that that strategy was crucial in helping us understand.
And I'll, I'll just add one more thing that it was in front of, you know, C level people over and over again. There was a commonality to the attack methodology. And what I would continue to hear is how do we deal with privilege escalation, and how do I deal with lateral movement and how, and, and like, those were the top two that I would continually be asked.
And of course, we understand, we understand that because of the length of time that, that the bad actors are, are able to go undetected and then privilege escalation, which we see over and over again, you know, on gaining access. And I don't, I, I hate that we're messing so much with this personally. I, I do.
So, Absolutely. You know, first of all, consistency in anything this government does is kind of an oxymoron, right? So this is, this is, this is this month's plan.
Yeah, it's true. Next month will be a new plan. Two months ago was a different plan.
But let me, let me take off my journalist hat and put on my security person's hat, right? Because I've been to Mitch, like you said, we've been security people for going on 30 years and CVE, there are a lot of people who have valid concerns. We have too many g*****n CVE numbers.
How can I track 200,000 or 300,000 CVE numbers and, and really try to, you know, fortify my, my infrastructure with it of using that. However, CVEs are a backbone of our security posture, of our security processes, right? Mitchell?
Yes. Startups have been launched around CVE management careers have been made around managing to the CVEs, the Mitre organization I think was the perfect organization for this. 'cause it was quasi-governmental, right?
You had governmental, um, funding and governmental involvement, but with private as well. And, and they did a heck of a job all these years. Why fix something that's not that broke?
Is it it, and especially fixing something that it in, in that is in and of itself broke, right? When Jen Easterly was shown the door there when our friend Alan Friedman, uh, of SBOs was shown the door there when they purged all of the people at csa, right? To me, this seems like whoever's left at CSA is looking for a lifeline.
And the CVE is their lifeline. Hey, we'll be able to get funding. We'll have a reason for being here.
If we say we maintain the CVE database, I am of the opinion that it, this is the perfect opportunity to correct a lot of wrongs and do it right. I would like to see an organization, a not-for-profit organization formed, whether it's under the auspices of the Linux Foundation or Eclipse or Apache or something new altogether that comes out and says, we're gonna do this. Right?
We recognize what some of the issues were around the abundance of CBEs CVEs. You know, there were just too many, but we're gonna do it right. And we're not going to be subject to anyone's beck and call or political whims or, or what have you.
Right? Let's put together a consortium of industry government, and not just the US government. Let's get the EU and some of the other responsible players in here, and let's form a worldwide foundation that manages our common vulnerability database, because it's too important to mess around with.
And until we get to that point, this is all to me, just theatrics. That, that's my point. Yeah, It's a great idea.
I I, I, it's a phenomenal idea. I, you know, So unfortunately I already have a full-time job, so I, I, I can't be the one doing this. But if any of my security friends are out here watching, we need to do this.
Maybe the, you know what I'm gonna call my friends at RSA conference. This is a good thing for them to get involved. I was just thinking RSA, why not start something up with Yeah.
Let, let's, let's get a hold of them and see what they do. Someone has to do this. It's, it's a good point because I don't think the model is, uh, why fix what ain't broken?
Why break what ain't broken? You know? So, so it's the, uh, Silicon Valley break things, you know, and worry about the details later.
And it'll, it'll shake out one way or another, which is, which is the whole showing people to the door and, you know, for political reasons or whatever the reasons are. It, it never made sense to any of us why you would pull the plug on Mitre, especially for funding this kind of activity. 'cause it's really the lifeblood supporting the industry.
Could we do some new things? Yeah, I'm sure we could. What do we do in the age of ai?
Is there something we can do better? Is something we can do to help with either the accuracy or the felony or the response to, uh, CVEs that we do put together. And there's a lot of things I'm sure we can do in, in today's age, if you're gonna not only modernize, but maybe rethink or redesign how we do this kind of a, a process.
But in the meantime, you know, uh, you gotta pay the bills, you gotta protect the network. You gotta protect all the critical infrastructure. You gotta protect all of our, you know, digital assets.
So you just don't shelve that process and then kind of wait and see what, what, what forms, you know, if a new galaxy perform, uh, forms up and starts to work on this problem, it it's an ongoing threat. So, really, in my view, I think the a the attitude or the approach we took is actually puts us at great risk, great national security risk. Not just for our national infrastructure, but our businesses, wall Street, all of those things.
'cause we rely so heavily on CVEs that said, you want a reason to go out and raise sponsorship funds, Alan, whether it's RSA or somebody else. I think companies would step up in a heartbeat to say, we'll contribute to that. And not just vendors.
You know, I think, uh, financial, No, no, I think end user enterprises would be, Yeah, a lot of companies that would say we want a neutral yes. Yes. And we want a healthy vendor ecosystem that is, uh, putting the right kind of products.
Matter of fact, we'd love to see a, you know, revitalization of that and see some new things happen, some new innovations in industry. So let's use this as a spark to, uh, really create the next era of how we do this. Agreed.
That's a great idea. Yeah. Love it.
Agreed. And this needs public private partnership, right? I mean, that's really the role for the government to play here is there's a lot of great efforts.
There's a lot of folks who wanna be part of a solution. Um, you know, government really is kind of the organizer of last resort here and, you know, the funder of last resort. Um, but, you know, this is, this is the equivalent of, you know, like getting rid of an FDA or an NTSB, right?
You know, it's just a little bit more in the background of, you know, everyday people. Um, and so I think it's not getting the attention that it would if it was some of those more visible things, um, for, you know, things that people feel like they consume more regularly on an everyday basis. But, um, you know, this is, this is a national distance and, you know, national security issue at the end of the day, um, really need to step up and get this fixed.
I mean, people, people will know about it when, when it hits the fan, I'll tell you that. You know? Exactly.
So, all right, let's take a break here on the gang. We're going to come back and we're going to continue our cyber focus today, talking about Microsoft. Are they grossly negligent when it comes to security?
I dunno. You're watching techron Gang. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey everyone, welcome back here to Textron Gang. Um, you know, uh, Senator Ron Wide, and I believe he's from Oregon, is asking the FTC to investigate Microsoft's gross cybersecurity negligence as a threat to national security. My goodness.
Okay, I'm gonna ask you to kick this one off. All right. 6 million people.
It's a lot. Um, the entry point for this came from a malicious link and a contractor, you know, clicked on it. And, you know, as typical, um, as we've seen, you know, everything falls, right?
So it went over to, um, reached, uh, escalating, you know, that whole privilege escalation, Microsoft Active Directory, privilege management and everything else. So the technical vulnerability here, um, was a well-known attack, uh, for credentials, uh, via a weakness in, um, kros authentication. And the core part of this was Microsoft continuing, uh, the default support for our C four.
And many of us know that one there. And basically, you know, the argument here is that, you know, why is this continuing when we've known for a very long time that better alternatives exist? Uh, the other question that he raises, um, and I think it's actually good logic here.
I don't think we need to, you know, beat up Microsoft, but, but the logic here does make sense to me. And that is, you know, you talk about, you know, Microsoft talks about, you know, well, you know, for critical infrastructure, you know, we need to keep this open. We need to have backwards, uh, compatibility.
1%, uh, presently, and, you know, and then going, so, so how does that make sense? 1% of the people who are still using RC four and, you know, but yet critical infrastructure is impacting, you know, it has a possibility of impacting us all. Like, you know, at 90 plus percent.
So does does that make sense? I mean, when do we finally just shut, shut it off? I'm a big proponent of, you know, let's just shut it off and let's, let's see what happens.
Uh, but that's me. So he raises the point about national security and systemic risk. Um, and what can Microsoft do here, uh, to really change, change up this risk that, that he sees that's impacting critical infrastructure?
So, Mitch, thoughts, Mitch, you wanna go? Yeah, I, I do. You know, I'm thinking of, um, a conversation we had earlier on an earlier show about when, uh, some, so there's a quality issue with something coming out of the factory you enjoy.
Just don't fix the item that has poor quality. Go back and fix the factory. I think we have a fundamental issue with security technologies, both the security standards, uh, that we put together, but also how they're implemented.
And here's what I mean, I'll draw an analogy with, um, IOT devices, right? For forever. There was never a way to update IOT software.
It just went out there. It lived out there forever. The vendors didn't have a way to update it.
They didn't really care. They didn't really maintain it. They just knew they were gonna replace it, right?
'cause it was replaceable technology year over year, but it didn't get replaced. It things to live out there for much longer, have much longer life. The same thing happened with security standards.
So what do we see in iot? The vendors start building and upgrade mechanisms to be able to do updates and things like that. The challenge, and I'm not saying it's an easy thing to do, but how could we reassess how we design the standards themselves and also implement them so we can upgrade them in place more easily without it being, you know, a rip and replace a major process.
And this is everything from, you know, uh, PKI hierarchies and keys, uh, to KRO standards, encryption standards. I mean, it's a big effort to go from, uh, Shaw 1 28 to 2, 2 56. You know, it is not a small thing.
Um, and again, maybe this is an area for ai. How could we redesign this process? I, I would invest my effort instead of, you know, trying to rake Microsoft or whoever the next company has crossed the coals for, you know, not making their customers keep up to date with the latest things.
Um, and really let's address the systemic issue. Yeah. So, and I I, oh, Kate.
No, no, Kate, you go. Well, I do ag Absolutely agree with you, Mitch, that we need to, um, I like, and it actually ties to our, our previous story, right? I think we're at a time right now where we really have to rethink what we're doing and going forward.
For many of us who have been doing this for a long time, we understand, we know the building blocks, you know, it's time to build things, right? And, you know, really think about redesigning things, right? And yeah, it's a good, good point there, Mitch, that that's Kind of why I got into DevOps, right?
To, to get security right. Earlier on in, in the process. But let me, so let me take off my journalist hat this time and put on my lawyer hat.
This is not gross negligence, ladies and gentlemen. Yeah, right. There is, there's legal definitions of gross negligence and this ain't it, right?
This is a politician politics Yeah. Making, making hay. Now, could we make things better?
Yeah. Could Microsoft be better about trustworthy computing as Bill Gates called it all those years ago? Yes.
Should we be complaining to the FTC and calling gross negligence on this? Absolutely not. That's slanderous.
I, you know, Kate, I always yes. 1%, right? 1%, you're yelling bloody murder if, if you're making them change it.
And, and so these things need to get done. The problem we have overall in security is we're always playing catch up. We're always three steps behind.
So now we're gonna try to fix this, well, this morning, 140, uh, packages in NPM from, from no less than, uh, CrowdStrike, I don't know if you guys saw this this morning. 140 CrowdStrike packages are found to contain malware. Some sort of new worm that's able to get into these packages and deposit malware that steals credentials and everything.
It's kind of a new vector. It's a new worm. You, you, you know, that's the problem in security.
You know, we're not the French in World War ii. We can't set up a imaginal line so that the, the tanks come around us and leave us there. Yeah.
You gotta fight tomorrow's war, not yesterday's war. Yeah. And, and We, and that's what we need to do.
Go ahead. And, and, and that's something that we have said on, on the show before, right, Alan? Like, we're not really planning, um, for tomorrow.
We're fighting yesterday. And the strategy defense in depth, I mean, we've heard this, I've heard this a lot, Right? Yeah.
Our whole life, right? Yeah. And I feel like, and believe very strongly that it's not a strategy that has been effective.
And if it was, we wouldn't be in the position that we were today. And when we talk about offense, a strategy of, of offense, it's so different. And if we don't start playing the offense strategy, and that doesn't mean, let me start an offensive, let me start to attack countries.
It just means that I have the ball where, you know, Hey, this is football season. I have the ball. How am I gonna get down, down the field to, you know, score points?
You know? And we don't think that way. But if we were to think that we have the ball, how does that strategy change with cybersecurity?
And that's the question. I, I think, and it, it's perfect, you know, with CrowdStrike, you know, In the immortal words of Hank Strm, let's matriculate down the field. Just get us an ation.
Uhhuh Uhhuh. He, I think you said it well, I mean, you look at the rhetoric here and it kind of screams of, you know, a politician with an agenda. Now obviously Microsoft has, you know, somewhat been the poster child of create the problem, sell the solution.
Um, but you know, I, I don't think you can really hold the vendor too accountable here, right? I mean, the end user has some responsibility as well. And you know, at what point as a vendor is building a platform that is supposed to serve, you know, almost everyone do the edge cases where, you know, people are kind of falling behind and, you know, building up technical debt and, you know, not, not kind of modernizing at some point, you know, I think it falls back on the end user, not the vendor here.
It's really good, good, good. Uh, example, because, uh, that happened with the crowds script. Not, not the most recent, you're talking packages, but when the outage happened, yeah.
And of course Delta scream bloody murder and sued them. But of course, you know, they were, they were the, the worst of the worst of not being able to go out and actually rebooting their systems. It was like, at, at what point does the consumer have some responsibility?
It's a shared responsibility model at the end of the day. Mm-hmm. Yeah.
I mean, it's like your home, right? You can have locks on your door, but at the end of the day, if you don't lock your door, you know, are we gonna go see this? But then you got the cloud, which adds another element to it.
And it's sort of like, well, you just rent a home and what, what responsibility does the landlord have? Right? You, you put your lawyer hat back on, didn't you?
No. Well, yeah, you'd never take the lawyer hat off. That's the problem with lost lawyer historian Responsibility model a little bit, right?
The cloud shifts the responsibility model a little bit more back to the vendor. But you know, there's a lot of control. The end user still has, you know, even in how they set up.
Well, And that was always the thing about cloud security, Dan, yes, the cloud vendor has capability to do some security there for you, but ultimately it's the end user who bears the responsibility when the stuff hits the fan. You, they don't want to hear that, oh, AWS didn't do this for me. Well, no, you put your infrastructure on a WSI used you, you are responsible.
And, and that that's the, that's the fact. But, you know, I don't expect anything to happen out of this. You know, Alan, Alan, just to throw one other, not not to to get too, um, futuristic about it, but I've, I've talked for some time about sec, about software being not a static thing anymore.
We used to release software, it would live out in production for months, maybe years sometimes. Uh, but now live in the world where software gets updated near continuous, not quite continuous, but it's something that is evolving. And I describe it, it is, software is not fixed like a rock.
It's fluid like water. We have to think about security the same way we have to stop thinking of static security. I put it out there and it lives until I do something about it.
And we live in a world where the doing something about it takes people and resources and money and time, which is why things get left behind. 'cause it's just not worth it to go deal with the problem. That isn't a problem yet.
Right? Or now we're a big enough problem. I think we have to think about designing security, not just in zero trust, but continuous zero trust, if you wanna think of it that way.
This Was J Frog's thing Mitch out in swamp up last week. They call it liquid software. Liquid software, exactly.
And it versionless. Yep. There's No versions.
It's continuous. It's continuous. But it's continuous security too.
Exactly. And that's why, that's I think, the model of what we need to shift to of thinking, because we live in a world where we could do this now. And I know that was part of their AI announcements, and that's part of a way AI can potentially help us, especially, you know, AI is, is going to be writing more and more code for us.
Not just at, at a point in time, but continuously in the background creating new code that it's writing itself to do new things. Now, of course, how we regulate that control that or o other issues. But the same thing can happen in security, right?
So a response may actually be it creating a process or it writing some security protocol adjustments or changes or, or code that responds to an incident because we're at such a volume, nothing can re you know, I go to this conferences where we're reducing alert fatigue, that's all great, but we, even at that level, we still have alert fatigue. We don't have enough fee people to respond to vulnerabilities and software to attacks on network. This has to be automated.
And the smarter we can make it, the better we protect ourselves. I feel If only we had a, you know, very transparent, trustworthy, central database of vulnerabilities that the agents could bull on, right? We'll call Back.
What a great idea, Dan. Maybe we can do something. Lemme write that down.
Thank you, ma'am. I, I even got a name for it. AI Needs good data, right?
You know what? But here's the sad part, guys. Kate, you're security person, Mitch, Dan, you've been around the block enough.
Is anything really gonna change? We sit here, we talk, we pontificate, we ize, if that's a word. Um, we, you know, all of this.
Are we gonna be having the same damn discussions in 2035? Maybe it won't be me discussing it, God willing, but are we gonna have the same damn discussions 10 years from now? Yeah.
It's a game of leapfrog. Continuous game of, yeah. Yeah.
So I, I'm, I, I hate to be the kind of, it's all about money, but it is all about money. As soon as soon as someone finds a way, a way, a model, an innovation, whatever, to make money doing it differently, they'll, they'll do it. They'll jump at it.
And if it is successful, others will jump on that bandwagon. So I've, I've, you know, as long as I've been in security, I feel like we're doing what we did When you and I started, you know, 25 plus years ago. We're like, we're doing the same s**t.
We're just doing it a little differently with a little better technology. And it evolves and it improves and, and it evolves. You know, let's really get some serious innovation happening in security.
Let's really invest not in the latest startup that solves some point little problem that does a little bit better than Cisco does it. And we're gonna sell it back to Cisco. Yeah.
We'll make money at it. Let's really invest creative and innovative ideas that are gonna move the ball, not just 10 yards, but into the end zone and maybe into the next day. It is all and, and law of diminishing returns, right?
You know, at a certain point, the spending the next bit of money doesn't justify the ex extra bit of risk management that you kind of get. Sorry, Kate, go ahead. No, no, I, I have to say that, um, in my age, as I grow older, I've become a Pollyanna.
And I don't know when that happened. Would've saw, alright, Well your stuff admitted. That's the first step is admitting the problem.
But I believe that we're gonna change this. I really do. This is my Pollyanna.
Sh you know, like, I believe, I believe that we're gonna do this. I believe that we are gonna solve this problem only because if nothing else, because we have to. And I believe in, you know, I wasn't a big adopter of ai, but now I'm like, man, ai, let's embrace it.
Let's see where we can take this and let's change up this story. So in 10 years, I can't have, I can't do this over and over again. Like in my mind, like we have to change this narrative where this is going.
So the Pollyanna and me lives on and we are gonna have a different story. And hey, three years. Three years.
We have Three years is ambitious. God bless. Two years, two years left to God here.
What I believe in, I was gonna ask you to get into politics, Kate. Amen. I was, I was looking for a church here.
Going on. Alright, Hey, I believe we need to take a break right here. Uh, we're gonna come back and we're gonna change it up a little bit.
Let's talk a little bit about ai 'cause we don't talk enough about AI and, um, but we're gonna talk about stock markets and all kinds of good stuff. You are watching text again. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey everyone, welcome back here to Textron Gang.
You know, I, I had an interesting conversation with my friend John Willis today, and he, we were talking about the progression of users of o of AI and of chat GPT, you know, and, and we, we, we tend to, we live in a bubble. We we're tech people and we think everybody's using AI and everybody knows what it is and everyone knows all the history when the fact of the matter is yes, open AI is probably the fastest to a hundred million users of any technology ever. You know, it's pretty, it's cut and dry.
However, a hundred million users plus still pales in comparison in a world of 7 billion people. And so we forget and open ai, the whole open ai, I not-for-profit, the Microsoft involvement, even in the a hundred million users, I bet, you know, a overwhelming majority are not aware of the unique corporate governance and structure that OpenAI had or has. And, you know, you know, absolute money corrupts absolutely with all this money in there.
People are trying to figure something out. Dan, I I've laid it out for you. Why don't you finish it up and take us into what's happening now.
Yeah, for sure. Thanks Alan. So, as you mentioned, you know, founded as a nonprofit, the nonprofit controls, you know, the potential, uh, you know, profit entity, a super complex corporate structure and governance model.
Um, you know, let's lay out the facts, right? Microsoft's got 13 billion into open ai. Most of what they've been, you know, kind of, you know, negotiating around is, you know, really the restructuring approval needed, um, to take this thing into the, the for-profit world, you know, the equity stake that micro Microsoft will get.
The revenue sharing agreement, the technology access and the a GI clause. Um, and then all the commitments on safety, right? You know, early on in the partnership it was focused more around model exclusivity.
You know, Microsoft being the primary cloud recouping their investment, you know, with profits. And, um, you know, though, I think, uh, my open eyes come out and said, you know, probably not profitable until 2029, you know, looking at $44 billion in, in operating losses, you know, between now and that timeframe. But, you know, you take the financial backdrop of this thing, there's an incredible amount of value creation happening there.
There's also an incredible need for funding moving forward. And, you know, ultimately this move, I think is about, you know, securing the capital needed to, you know, kind of meet the CapEx requirements of continuing to drive the business forward, right? You know, the ability to, uh, you know, to tap in, in IPO potentially next year, you know, raise a significant amount of capital.
We've already seen this in, you know, some of the talk around the Stargate project with SoftBank and Oracle, you know, numbers like $300 billion being floated. Um, I think OpenAI is targeting a valuation of about a a half a trillion dollars, right? And, you know, Microsoft seems to come out with, you know, something that's probably on the order of a couple hundred billion.
So, you know, something roughly equivalent to, you know, eight to 10% of, you know, Microsoft's market cap, um, is kind of the amount we're talking about here. So it's, it's not insignificant at all. Um, but ultimately, you know, I think both parties realize that they need to get past this, you know, kind of restructuring effort to really extract the value from it.
And, you know, everybody's willing to negotiate on, you know, kind of the terms that need to change moving forward from what they've been, you know, to, to fund the CapEx and really seize the opportunity. I, I've got a few things here, Dan. First of all, to your point, I just wanna make sure our audience realizes this, that $13 billion Microsoft invested was not your usual investment where they got stock or even options or warrants or anything.
It was $13 billion as part of a rev share, right? And Microsoft was gonna recoup that money in, in rev share and profit. Secondly, my understanding is just last week, Larry Ellison, you know, got about a 34% bump into his net worth because Oracle came out that open AI is pledging $300 billion to Oracle alone for, for this AI infrastructure.
So Dan, if they're gonna raise a half a trillion, you are talking about giving away 60% of it in one to one customer to one project, one, one transaction. They need to raise I think a couple of trillion dollars. They need to raise Nvidia kind of money just to, to pay these bill, you know, to pay that Piper, that's a lot of, that's a lot of cabbage.
It's a lot of cabbage, right? Think about what, what you're talking about. The other thing though is I, I'll, I'll mention this and then open it up to the, to Mitch and Kate and Dan, you wanna come back?
Here's the fly in the ointment. Our friend Elon, don't forget, he was a founder there and he was, he supposedly was big into this not-for-profit piece of it. He didn't like what they were do.
Well, there's back and forth about why he left, but one of the reasons is he didn't like what they were doing. He, of course has XAI and grok, right? He's pledged to open source that everybody's pledging to open source everything while they're all running to the trial to feed open ai.
Yeah. So, you know what, what, what I, I can only imagine the lawsuits flying, but I'll, I'll throw it back to the, to the gang. What do you guys think?
I, I just relate it to, if it can be related to my own personal experience, having run a for-profit company at a much tiny, tiny, tiny fraction of a fraction of a size of what we're talking about here, owned by a nonprofit company. And that is e even in that particular relationship, I'm gonna mention the specifics of it, um, but it complicates things when a nonprofit owns for-profit entities. Now the, the, the hospital systems see, have figured this out 'cause a lot of the hospital systems are set up that way.
A nonprofit owns all these for-profit companies. But when you start out as with an more of an altruistic nonprofit, that was what originally open AO AI was about, is doing this with safety and, you know, protect protections built around what we want AI to become. And of course then the for-profit part of it starts pushing it outside of the bounds of that original goal.
I think some of those, those, that fabric of that original mission still complicates the factor here. And at some point you have to say, look, we're not, the, the ownership of this is not about that mission anymore. We are about managing for-profit entities through this nonprofit company, et cetera, in this structure.
And let it be what it's gonna be or, or spin it off and do your own thing as a nonprofit. Just stop the complexities of it. Not saying that this still isn't complex at these numbers of this size.
It's still hard for me to kind of keep those numbers in my head. But I think that is is also an undercurrent of this too. 'cause all, many of us said, what is, what does open AI wanna be when it grows up?
Well, I think it wants to be a company that makes a whole ton of money, is what the market's saying. Yeah. I mean, to me it's like, do you guys remember when Tesla, in the heyday of Tesla, they were the only game in town for EVs?
You know, they had like three x the market cap of Ford and gm and one has to look and say, if that's a car company, and these are car companies, I'm not saying Tesla is not without value, but is it three x of Ford, three x of gm? You know, it, I think we're talking, I mean, correct. I I'm not a stock market expert, but Nvidia is about a $4 trillion market cap, right?
I believe Microsoft's like at a $2 trillion market cap. Yep. Open AI has to be approaching that to, to afford the kind of deals that they're talking about.
And, and, and keep in mind, Dan, as you said, this is a company that's gonna bleed 44 billion red dollars between now and 2029 or something like that, right? 44 billion. Do you know, that's, that's an insane amount of money.
Well, investors are discounting the future, you know, potential profits and cashflow and voting that there's still a lot of money to be made here, right? And I think what they're trying to do is really kind of remain a little bit true to the original mission about really advancing AI safety. Um, and you know, the nonprofit may end up with, you know, a sizable endowment to drive AI safety priorities while, you know, kind of separating from the for-profit entity.
So I think they're trying to get to the win-win here. Um, certainly, you know, the original investors in open AI are gonna win. Microsoft is gonna win very big.
Um, and it seems like they're trying to maintain, you know, some of that credibility around the other mission, uh, the original mission and, and, you know, really fund that AI safety thing through the equity stake. Do you think, Dan, that that sort of solving that through some kind of a structure funding, that that original mission if that happened, is that sort of separate the, the conflicting concerns and let's open AI be the pro for-profit company it needs to be, and let open AI that's the nonprofit be what it needs to be and stop complicating the concerns. Do you think that's standing in the way of some of this?
I think it is. I think that end, you know, a fair number of lawsuits are standing in the way of this, but I think a fair number of luck. Yeah, for sure.
But let me, let me just, not devil's advocate, but let me give you another spin on this. He was reading a post today by a PhD in stem, A woman who's talking about, you know, they bought Johnny Ives OpenAI bought Johnny Ives, uh, company for about six and a half billion dollars. And supposedly we're gonna start seeing these, uh, consumer business consumer products coming out next year.
And the rumor is, is that one of them, basically, it's not a phone, there's no screen, you know, but it's a device. I don't know if it pins on you or it's in your glasses or wherever, but it's a device that's your constant companion and kind of whispers in your ear and tells you, you know, it, it summarizes conversations you're having and what people are saying. It tells you where you're going and what you have to do.
It reminds you, it, it is your alter ego. And you know, it doesn't have a name yet. I didn't, there's no pictures of it, but that, that's kind of the buzz about what this new device, you know, that Johnny Ives team was working on, is working on.
And Sam Waltman says that that alone, that alone is another trillion dollar business for open ai. So I, I'll close it out with this. If they go public, I'm in Friends and family.
I hope so. Alright. Hey, if we have nothing else, we're gonna wrap up this version of the gang.
What a great, great conversation today guys. Dan, Kate, Mitch, thank you so much for participating. Thank you out there for watching.
As usual, we have a full lineup of text Drunk TV immediately following the gang. If you're watching this Wednesday morning live. Um, if not, you can go to Text Drunk TV or the Text Drunk tv OTT app where we have not just tech on tv, but Tech Field Day.
We've got some six five Media, some future group stuff. You could get that on iOS, Android, apple tv, Roku, and Amazon. So check out the OTT app.
We'll be back tomorrow with a fresh gang and fresh topics. Until then, on behalf of Techstrong, futur and everyone else here, we're out.



