Techstrong Gang – August 16, 2024
Alan, Mike, Mitch, Jon and special guest Lisa Martin, CMO advisor for The Futurum Group, discuss how cyberattacks are being used to target the Trump and Harris presidential campaigns. Then, they dive into what technologies will be needed to thwart Deep Fake attacks by tracking the provenance of content.
Finally, the gang takes a look at the issues that led the State of Texas to sue General Motors for the way it collects driver data.
Transcript
Hey, everyone. Happy Friday. We've got a great line up in show today.
You know, politics is a dirty business and it stays dirty. Of course, AI is making it even harder with deep fakes. And what, what's is GM collecting data Without our knowledge, I don't know all this.
And more today on Techstrong game. Hey everyone, happy Friday. I'm remote today.
But, uh, it's Alan Hummel for Techstrong, and we've got a great gang and some great topics to go over with you all today. Let me introduce you to who we have. We have a big West coast contin contingent today with our, uh, roving editor extraordinaire, John Schwartz.
John, welcome. How are you? It's good to be here.
Hello, Alan. Hi, everybody else. Thank you.
And also joining us on the West Coast is our, uh, CMO Maven and host of, of her own podcast, as well as FU group analyst, regular gang member Lisa Martin. Hey, Lisa. Lisa, it's great to have you on.
Great to be here, Alan. I'm so excited to dig into some of these topics with you all. Yeah, no, it's meaty today.
Speaking of, well, not meaty anymore. He's, he's shedding weight before our eyes. I, I've very own CTA and CTO.
Mitch. Ashley, Mitch, you're looking, you're looking Pel on there. Well, I thought you were gonna call me Maven there.
You paused for a minute, but you know, I'll, I'll take that. That's great. Okay.
Well, if you wanna It's wanna be a Maven. You can be a Maven. Mitch, it's good for Lisa.
It's good for me. All right, thanks. You a maven.
And then joining us and, and holding down the, for in our Boca Raton Studio headquarters, it's our Chief Content Officer, Mike Ard. Hey, Mike, how are you? I'm good.
How's everybody else? Good. Great to have you on.
So guys, I, I mentioned a little bit in the, uh, in the, uh, open, we've got some great topics today, but we wanna start off with this continuing story around, uh, hacking of, well hacking or attempted hacking of both of the major parties. Political, uh, both of the major political parties, campaigns. Um, you know, we came out, John, I think you did some work on this, a black hat that the Trump campaign where it had come at the Trump campaign was compromised.
And right at, at the time at Black Hat, everyone was fearful that something was gonna happen, but they didn't know what it was gonna be. So they expected a repeat of 2016. It turns out, in a kinda weird way, it's happening.
I mean, one of the main themes I heard at Black Hat was that, and somebody put it really well, they said, AI combined with social media has created weapons of mass deception. Right. And we think about it, you made it to the point earlier at the beginning, which is so true.
I mean, it's always been dirty. If you think about the Daily machine in Chicago, Tammany Hall in New York, local e elections in Texas, back in LBJs days. But now AI has kind of helped turbocharge phishing attacks spearfishing.
And ironically, in the case of the Trumpet Trump campaign, the person who was caught was our friend Roger Stone, the old dirty trickster from the Nixon years. Yeah. So he was the guy paid leverage to get the information from, I think, um, Mitch, maybe you can des describe this organization called Oil Rig, but I think it's just, it's just really interesting.
One of the other things that I wanted to point out was that at, uh, black Hats, Jen Easterly, who's at csun, she's a director. She's, she was actually H sta M-S-N-B-C yesterday. She's talking about how elections are complicated and, um, I can guarantee that things will go wrong, as she said.
So she foreshadowed it. Maybe she had an inkling of what was going on. Uh, but in this case, it's an Iranian group versus the Russians.
Although the Russians and the Chinese are probably gonna get involved eventually in this campaign. And just, to me, it's interesting. It's, it's, we're discovering it maybe earlier, it's maybe more, uh, pronounced and it was before, but it's going after both campaigns.
And it will be interesting to see what, if anything we can do to tamper it and, and kind of minimize the threats to just, not just data breaches, but misinformation and DeepFakes. So let me just kinda lay out what, where we are as far as we know is, and if anyone has more information jump in, but it does seem Roger Stone was compromised via a spear phishing attack, um, through, I guess through him or maybe others. They haven't announced.
There were some documents that were not for public, uh, dispersal that were, were, uh, compromised. And then someone purporting to be Roger or someone with an a OL address, an anonymous person, uh, sent around some of these documents to some of the media organizations. I think the primary one was sort of a background on, on, uh, JD Vance, the, the VP candidate.
But unlike 2020 to the media organization's accredit, they didn't jump at this bait and start, uh, uh, publishing it and, and, and, you know, letting the mud fly. They actually called it out and, and, you know, the FBI and so forth got involved. Um, now it wasn't just in the case of Russia going after the Democratic candidates in I guess 2016, it was 2016.
Right. Um, not 2020, I apologize. But in this case, it, if this is the group behind it, they seem to have also made similar attempts to infiltrate the Democratic party.
I mean, look, at the end of the day, they just wanna, so chaos. What I think is really ironic is you mentioned Roger Stone. Well, he's the one who was reaching out to Julian Assange and WikiLeaks last time.
Mm-Hmm. Right. Trying to get them to release this data.
And now there is no WikiLeaks to do this kind of dirty work. So, you know, the, the crows have come home to Roos for Mr. Stone.
But Mitch, you had a little background on the oil rig Iranian group, and, and there's no doubt in my mind they're a proxy for either Russia or China, or, or they're out. But Mitch, if you wanna fill in Exactly. Well, by the way, Roger Stone was compromised long before 2 42, got ahold of them.
But that's another, that's another segment. Um, sorry for the politics there. Um, they, they are, they are a group who's sort of, uh, agnostic.
They'll work, they're mercenaries, right? They'll work for anybody who, who wants to hire them for their services. And, um, you know, a PT, the name kind of the, that's been relabeled is a, uh, security term for advanced persistent threats, which usually means like, it's a low and slow attack, right?
You don't notice it, right? It's happening over time. It's not like suddenly, poof, we got attacked and we gotta respond to it.
Which tend, you tend to not notice as quickly. And this way it, it, it just reflects that they're tactics because, uh, oil rig uses everything from, you know, getting into websites and creating watering holes where people go to and then get infected, uh, to, uh, spearfishing as we mentioned, uh, earlier. Uh, and, and also, you know, they use the standard lateral attacks.
So lateral movement when they get attacks, um, there's some interesting technologies we're gonna talk about in the next segment around DNS sec. But I think what's interesting is, you know, spearfishing, this is probably just the tip of the spear. I seriously doubt if Roger Stone is the only person who got compromised, right?
They would've gotten into his system. They go after credentials, and then they'll move into whatever areas. So we could see both for Democrat and for Republican parties, um, you know, this kind of ongoing deluge of information that just gradually sos chaos.
'cause we find out, oh, this person sent that out, or this is internal email over here. So I would expect to hear more about this. Lisa, do you think that this is gonna have some repercussions through the marketing efforts of all these campaigns because, um, you know, historically marketing in the political sense at least has been mud slinging, but now we don't even know if how real the mud is.
Right? That's a great point. You know, I think marketing has a really important role in maintaining a brand's cybersecurity posture.
Whether that brand is, um, Amazon or the brand is one of the candidates. And the first thing there is really brand reputation management and crisis communication. You know, a a well prepared marketing team can help a brand, a candidate to really quickly communicate with constituents, with stakeholders and media to help mitigate brand damage.
I think also another thing where marketing can be really helpful here is in the consistent communication and awareness, you know, it, it's, they have to be able to help people, the masses become skeptics, to, to really be able to discern what's real and what's not. It's hard to, I think my favorite thing that happened this week was the, the deep fake that Elon tweeted a couple days ago with him and Trump dancing to stand alive. I was like, wow, they've got some good moves.
But ultimately, you know, marketing collects a lot of data on people and needs to be very transparent with how data is used, what data is collected, how it's stored, how long it's retained. So that ultimately what a marketing organization can do for a brand is to enhance trust. And I think that's where we get into a lot of muddy waters.
To your point, Mike, is that trust layer. It's so easily broken these days. And, and marketing needs to help brands to help its constituents be able to detect or just have that kind of deceit meter kind of go up with, is this, is this accurate?
Should we believe this? So I think marketing can play a pretty big role in the cybersecurity posture. Hey, Lisa, can I ask you a quick question?
It seems like the era of response into these kind of situations has significantly changed, is, you know, if you spill a cup of coffee on the, the floor, it's a coffee spill, you spill it in a rushing river, nobody notices, right? Yeah. These things move so fast and maybe you can over respond to it and give it more life, or maybe it just doesn't matter.
It'll, this too shall pass. That's a great point about over response. I hadn't considered that.
I think ultimately the response needs to be consistent and needs to be transparent. Um, they need to also be working along with it folks, the security folks, to understand what's the implication here? What's the impact that we've seen to then, to your point, Mitch, be able to really balance what's the right level and consistency and a frequency of communications.
I don't think we've seen over responses. Um, I don't think we've seen that yet, but it is something that brands need to be aware of. What's the right balance to get our constituents believing and trusting in us and what we're putting out there.
Mitchell, I thought you said a Russian River. Yes. I didn't mean Russian.
So there, what the deal with coffee and Russian rivers, poor vodka. But anyway, I'm drinking some Russian coffee this morning. But, but you know what's interesting is the response or the lack of over response, the restraint of the media this time versus in previous election cycles to I think, yeah, It's a give this oxygen.
Yeah. It's a, that's a really good point. Uh, melan, that's just a matter of maybe guilt or just being completely used or played back in 2016 Sense of campaigns.
Well, maybe smartening up Smartening up, right? Learning from your mistakes. Yeah.
Although we still make mistakes in, in terms of covering a certain candidate. But, you know, the interesting thing too is that the campaigns last time in, in 2016, it was John Podesta, who's a pretty high profile campaign advisor. Yes.
He was the guy who was victimized. So we have the same kind of parallel thing happen. Although, as Mitch said, there are probably multiple people and it's metastasized, you know, since it went, it went through stone, um, or stone was, was played.
Um, but yeah, you're right that the whole, the whole media postures has gotten a little bit smarter about it, although it continues to normalize and make mistakes, but it, it looks a little bit more savvy. And I wonder if maybe if it's even more savvy and it, I know it's not exactly the same thing, but CrowdStrike in a sense, heightens or maximizes the media's exposure. And maybe a little bit of basic understanding about what these systems can do good and bad, and how quickly they can create damage.
So I I, I have a theory on this, right? I, I, um, I saw Chuck Todd, you know, former, uh, meet the press host at a, uh, a lecture I, I attended, I don't know, maybe seven, eight years ago. And, and he said at the time that both the media and the public really had a hard time with social media, with, with digital kind of information separating truths from fiction, how not to be played, to put it in your terms, John.
Um, and that it was gonna take time, but eventually both the media and the public would learn how to kind of separate, you know, the, the, the cream from the crop and, and how to, you know, be better and not, not be, you know, quite as let around. He said it could take up to 20 years. And, and I, I think it might take up two years.
I think he's years. But, um, but maybe the, you know, because if they don't get the intended result they're looking for here, and it's still early in the election cycle, God knows what they're sitting on. But if they don't get the intended result here, is it as, is it as inviting a target?
Is it as forbidden or fruit next cycle and the cycle after that? And maybe things go, you know, the inflammation goes down, if you will, and things get a little better. We, we can hope, Alan, to what degree is it to try to help one candidate versus the other?
Or are they just trying to disrupt democracy to the point where nobody believes in it? Uh, I'd let, look, let's, in, in 2016, I think clearly Russia was trying to help Trump. They, they were not big Hillary Feds and Hillary and Putin had a history.
I think in this cycle, it, it is much more about just influencing our elections, disrupting democracy, if you will. And, and let's be clear, guys, the US doesn't, the US election is not in a fishbowl or in a vacuum. We're not the only election where tampering is going on, right?
There's been a lot of tampering going on over in Europe, in Africa, Asia, south America. Well, in South America, they just decide who won. And regardless of who voted, they, he just, they just announced it won.
But, um, but, you know, election tampering worldwide, I would say via digital means election tampering has been going on forever. Right? It's the second oldest revision.
But, um, more, you know, digital election tampering, hacking like this, I think is, is on the rise worldwide. Yeah. You know, they kept, one of the, the phrases that kept cropping up at blackout was, uh, zero trust.
Like maybe that's an ultimate goal is just to just so, so much chaos, mayhem, misinformation that you just don't trust institutions, period. Mean that's an ultimate goal for some groups, John, to be fair, Don't we In the US kind of give as good as we get? We're not exactly, you know, squeaky clean all the time.
Oh, no, no, no, no. It goes back our influence. I mean, I I I can get political.
Maybe I, I'll just mention the CIA, sorry, I, I know we haven't probably talked about this, but I just, this idea of the us being lily white and innocent in all this is, is bs. I mean, we're as guilty as probably as we are as victimized and Gambling here. There's gambling going on.
What are you talking about? I'm clutching my pearls Are, are you bringing your hand back? Okay.
Um, but you know, I, I think you, we'll, we'll wrap this up, but I think the important thing I wanted to leave our audience with is, guys, it's not even September right? Happening your earlier, it seems, yeah, We still got two full months here. Yeah.
Whether this hack has more legs to it and information, or the next hacking will, or some ai deep fakes, you know, wreak havoc somewhere else that I, I don't think this election cycle is gonna be as smooth as it's, and it's been far from smooth with one candidate almost, you know, a hair, a hair away from being assassinated, another one dropping out. I mean, the, this, it's been a crazy cycle full of surprises. I don't think we've seen the last of them in terms of hacking and digital.
So we'll take it from there. Anyway, speaking of AI and deep fakes, we're gonna take a break here on Textron Gang. And when we come back, we'll, we'll be talking about deep fakes.
You're watching Textron Gang. All right, folks, as promised, we're back. And we're talking about deep fakes and the need to track the providence of content.
Um, this week, Digi Cert acquired an outfit called, uh, ra, and they, ostensibly, their primary business is just to help you defend against DDoS attacks. And they have a DNS server to do that. But in the course of the conversation with their CEO, it became apparent that these technologies are gonna play a critical role in helping us thwart these deep fake kinds of attacks.
'cause we're gonna be able to track hopefully, uh, where content was originally created and how recently and who created it. So Mitch, um, walk us through, if you would, some of the technologies maybe that we can use to combat all these issues before they overrun us. Well, the, um, the Dig DigiCert acquisition, RA has a couple of technologies.
They have some of the traditional DDoS production, um, you know, caching, content filtering, things like that, out firewall kinds of capabilities. But at the core of it is a different kind of DNS technology called DNS sec. It's based on specification.
It's been around for a while. I worked with a company Secure 64 back in the mid two thousands, um, around this. And it's really, you know, DNS is just software that runs on, on Linux or Unix computers and it that can be compromised, right?
Just like anything else. com, right? When they're really not.
And now your, all your addresses are resolving to some other, uh, internet address instead of where it should be. That's, that's in the kind of e the hierarchy of DNS servers. So DN ssec is about protecting thing, everything from not only what's, um, kind of what's running on the machine, but protecting memory, protecting the operating system, strengthening it, which I think is an interesting move for, uh, DigiCert.
I mean, as a PKI digital certificate company, you know, very, very prominent in the industry, um, you know, acquired some businesses along the way. It, it's, it's one of the core pieces. P some people think to authenticating content, and its providence where it came from.
com versus something else pretending it to be so think it positions them. It, it's not the silver bullet to solve this, but I'm, I'm a strong believer that PCI digital certificates are, are part of this solution that has to be underlying it because that entire, um, technology is built on an ecosystem of trust into certificate authorities who are issuing those certificates saying Textron Group is Textron group. That's, that's who they are.
And that domain really is theirs and run and operated by them. So, you know, I, I, uh, I've been covering Digis search for years. I interviewed the CEO and most of the executive team multiple times.
I usually go to their in-person, uh, uh, user conference, which this year is virtual, but we'll, we'll be working with them on it covering as well. I, I did an interview with one of, and, and they, by the way, they have some of the smartest people when it comes to PKI and certificates and encryption and all of these things, uh, quantum, I mean, they, they, they have an amazing bench. I met with one of their really, really bright people on this issue last year, at their last conference.
And, you know, at the time, and of course this is pre-acquisition, obviously, the thought was, look one way to to, to bring some, you know, sanity to the whole deep fate AI issue, was that every graphic would have a certificate. Just like, you know, every, every container has its own digital certificate, every instance of a server, right? Its certificates are not just for people identities anymore.
The same way every instance of AWS has a, in an AWS, you know, has an identity the same way every container has an identity the same way every iot device has an identity. Well, every image would have an identity, and there could be some sort of watermark, if you will, certificate to, to make it, to make sure that it was legit and it hasn't been tampered with. Um, Mitch, I don't know enough about the technology here to know if this falls into that along with the DNS sec.
Um, there was an interesting article I I mentioned to the gang in the Washington Post today about using AI to ferret out deepfake DeepFakes, which you're done with AI as well. Lisa, you mentioned something before about the, the deep fakes that must put up of him and, and Trump dancing or whatever. Well, if I'm not mistaken, that's a new service that Elon has rolled out at x, where if you're a paying a member, you can now create graphics.
I'm not gonna call it deep fakes, but you can create graphical images using public figures like that, that previously you these, he was verboten, right? You're not supposed to be doing deep fakes of, of these things, but now if you're a Twitter paying customer, Elon's gonna let you do it, you know, and he's the one screaming about, about security and so forth. So I don't know what the, the deal there is and whether that's gonna lay out, but he also posted other deep fakes of political opponents of his, the which One, which, Well, I wasn't naming names John.
Yeah, that was, Yeah. See, that's, that's the one thing, sorry to interrupt. That's the one thing that kind of concerns me, especially the proliferation of deep defects on a platform like X, which clearly has an agenda based on what's been going on.
It also clearly has rules against doing that. Yeah, exactly. Well, the rules at X really, um, yeah.
Um, this is the other thing that concerns me too, is that, you know, the defects can be done either pro or, or con, I mean, they can be done to help a candidate. And I think somebody mentioned to me an example in India where a politician's deceased, long deceased father was in an ad. I heard that Help the candidate, you know, so I'm wondering, you know, people that you assume people may know better, but I mean, in that case, it, it would be difficult.
But I, I can see a scenario where we see these creations on a platform like X or any other type of pro weather, Democrat or Republican site, kind of helping a candidate under the very, very flimsy circumstances, not outright false circumstances, and swaying a number of people who are not well educated on the, on the topic. Let's go back to Lisa for a second. Are marketers concerned about this?
Are they aware of it? Yeah. To the whole point of content Problems?
Well, if they consider it an arrow in the quiver, that's true. True. Good point.
Yeah. You know, I, like we were talking about in the last, um, segment, marketing has a definite role in helping a brand cybersecurity posture. And I think that includes marketing, helping thwarting deep fakes.
It's a number of things that marketing can be involved in, partnering with the tech folks on the technological advancements. Mitch, you did a great job talking about that with respect to DigiCert and Ccaa policy changes, uh, societal awareness, uh, and marketing can help communicate all three. I think it's absolutely necessary.
I was actually talking with, um, uh, uh, talking about and and tech target report that came out yesterday. Uh, a company called Pindrop that's, and, and some looking at some of their peers that are helping, uh, are now enabling what Amit Sana, the CEO of DigiCert, um, talk about is that from a Providence perspective, there's going to be technologies that are gonna allow end users to be able to submit content, um, to platforms like, um, uh, like Punjab, for example, like, um, reality Defender, so that they can evaluate what parts of these audio, video text, um, are synthetic. And what marketing needs to do is help raise awareness.
Um, John, you kind of hit on this, educating the general population about the risks, the consequences of DeepFakes, um, creating content that highlights, um, some of the potential harm that could be caused by these deep bigs, like the misinformation that we're seeing. But also I think marketing can help brands promote authenticity and transparency. Um, developing campaigns to show, uh, the importance of people being vigilant to verify, uh, information sources develop counter messaging as well, so that it challenges the spread of the deep fake information.
And then partnering with the tech technology folks and the security folks to understand how can the end users be enabled to do this on their own and get, you know, quick responses so that the spread of misinformation is maybe, um, reduced or mitigated to some degree. Well, you know what always scares me, especially in this election side, last few election cycles, and with the advent of ai, what have you, everything's faster, right? Speed is coming, the information is coming at as faster than we can possibly consume it.
So if you flood the zone with 25 lies, you know, vast majority of them are gonna get through. And so that always scares me, like the speed in which you're trying to bat this down, just look at a one of these press conferences or a a a a debate. It's just, it fact checking in real time is, is almost become that way.
If you consume anything through social media or, you know, wherever you get your information, that's gonna constantly be a problem. I mean, we will get better at defending against it, but it will, it will always persist. Mitch, how long will it take to get to this?
Because, you know, from my perspective, content Providence can't come here soon enough, but it seems like there's a lot of pieces and parts that aren't quite gel. It, it is, it's, it's a kind of akin to email security, right? There's been some things to help prevent spoofing, but that took specifications.
It took, um, people who create the email server software to agree on that. And then how you have to set up DNS to be able to authenticate whether this someone's trying to spoof your domain. Um, I know some efforts when I worked at Cable Lab, there were some efforts around trying to use PKI to help set up a a an ecosystem for, for content.
And the problem is, is you have, you have to do it with everyone who creates content and everyone who distributes content and everyone who consumes content. And that makes the problem extremely complex, really big. Um, maybe you could carve off an area and say, you know, let's take the top, uh, digital newspapers, you know, the ones Alan reads or, or whoever reads and say, well, let's start with that and have some way of authenticating and knowing that this is, this is actual authentic, uh, authentic content.
Now we do that today because we trust who the New York Times is or the Washington Post is. And that goes on to a site that they manage and control, and then we accesses it over a secure browser. That's all well and good until that site gets compromised.
And then we don't know if that content's real anymore. And that's our challenge around this, is every piece of content on there would have to be tied into a PKI kind of trust or something else that would, would help us. So it, it's just, it, it's radically changing how we share and authenticate content, Mike.
That's why this isn't an easy problem to solve. You know, what, and it, bringing this full circle back to the DigiCert acquisition and, and my conversation with them, Mitch, that that is the key, right? We saw a huge, an exponential uptick in, in certificate use when we went from using certificates just for human identity to using certificates from machine identity, right?
Mm-Hmm. But then call se in terms billions and billions. Um, now if you wanna start using certificates or PKI or what wordmark, whatever you wanna call it, for every graphic, for every piece of content.
It doesn't have to just be graphics, I guess, but for every piece of content, I mean that, yeah. I, I, I just can't, I can't, I don't think the human mind can get their mind wrapped around Where this has happened, Alan. I mean, we talk about blockchain, if you've heard about that around crypto, Maybe that's an answer.
You're right. That's all built on PKI, that's what lets you trust. I don't know whether this entry in the log is authentic, but I use PKI to to validate.
I don't know who you are, but it knows who you are. And other people trust who you are. That that is an actual, um, valid entry.
And that's, that's what underpins the entire crypto market. So it's not impossible, but in that case, they created an a separate ecosystem to do it, right? Kind of had to be built from the ground up this way.
And that's why I was saying maybe that's the way to do this with content. You just have to kinda rebuild the content ecosystem from the ground up. Again, not an easy thing to do.
Hey, John, can you reach out to your desk and pull up one of those newspapers? I know that you're squirreling away there. There's one is that was a Mercury Chronicle.
Is that not the most New York Times Absolute form of authenticated content right there. So maybe we need to go back to print and things you put in your hands. It's a crazy idea.
Foley, We could have, that's why I got outta the business. Oh my God, it's dying away. But that's another story.
No such Thing as counterfeits, but yeah. Okay. Yeah.
Well, in some cases, yeah. Um, I won't go down that path. S sarcasm Either.
Yeah, me too. Snorky sarcasm. Sorry.
Yeah, I, I mean, how, how many we're all either I'd look at my children, they wouldn't know how to fold in New York Times to read it. I was, I, right, there was an art to folding the tide sort origami to it. Did you Explain?
Really? Sorry. I asked him.
I I, can I tell you something really quickly? I went, I was in Las Vegas. It, it was about a year ago.
I think Mike May have been at this conference. It was like the Service Now or something. And I was desperate to find a newspaper.
So I would go into a liquor store and there's like this 70-year-old guy there, and I say to him, do you carry newspapers anymore? And the guy just started laughing at me and said, what's a newspaper? And I, I said to him, you're, you should know it.
He goes, I, I know this don't exist anymore. Good luck, my friend. And he sent me on my way.
Yeah, I know. We're not getting there. There were rules to how you read the paper on the subway, right?
Not only did you folded, but you had to make sure that the person sitting across from you was done with their section as you were kind of looking at Your side right before you turned it Well and there was delivered or By, or you used as a back the whole, I'm sorry, go ahead. No, it was over boy, by the neighborhood kid. I was one of those kids.
That was the, Was I was a news kid. Parents, if they messed with anything, you go talk to their parents. Take them down.
Yeah. Sorry. 1, 1 2.
They'd, they'd read the paper in a certain way so the, those would read the tabloids with the, with the page. Three girls would hold it at a d at an angle. So you couldn't see what they're looking at.
I don't think we're returning to paper guys. I don't care. Mike.
John, how much you pin for it. You know, I'm, I'm a dinosaur. I like books.
Like I have a, oh, I Like books Behind me. It's just like 1300 pages. It is like a phone book.
But I, you know, it hurts me to read 'cause literally have to ke keep it up. But, um, yeah, I'll, I'll hold out forever. Uh, we still have email.
Maybe it's coming back. But, but, but here's the point. Here's the point though, guys, if this becomes a big enough problem, necessity is the mother of invention.
We gotta do something. And that's, to me, the issue. Anyway, we're over time on this one.
Let's take a break. We've got our third block coming up on this splendid Friday and a full Textron TV ahead of us. You're watching techron Inc.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, we're starting off now on our third block. And the state of Texas has decided to sue General Motors for the waves collecting data from drivers.
I guess General Motors is interested in, uh, what they can find out about your habits for driving and maybe your insurance records and whatever else that they want to bill us. But Lisa, I know in a previous episode we talked about, uh, Oracle having issues where they settle, they, what feels to me is a similar case outta court. Um, is this just gonna become a bigger issue and what's going on with all this data that companies are collecting?
You know, I think it is gonna become a bigger issue, and we're seeing the state of Texas, we're not seeing it at the federal level, where we're seeing at the state level come in and say, Hey, this is not okay. You cannot keep using all of this data collecting in one without the driver, the owner of the vehicle, being aware of it. And two, use it for purposes that you're not being transparent with.
I think, um, the transparency is key. We talk about marketing all the time, my webcast every other week, and we talk about the value of data, and there's so much data marketing has become a science, um, in part because of the data and the AI that runs on that data. But there's the flip side too, where, um, marketing organization, well, brands partnering with marketing with it, with security, with sales, need to start looking at what are we collecting, uh, in this case, uh, on, on the owners of GM vehicles in tech, in the state of Texas.
How are we using this data? Where are we storing it? How long are we retaining it?
And are we being transparent with those millions of people affected? And in this case, no. And I think it's something that we're gonna see more and more as, you know, organizations have to comply with things like G-D-P-R-C-P-R-A in California.
I think we're gonna see more of those data privacy and regulation acts at the state level. Um, but I think another thing that, that I was thinking about in response to this particular, um, lawsuit is I had, I was with a family friend recently on Cape Cod, who's in her eighties and has a brand new car and isn't thinking about all the data it's collecting on her, was concerned with how much tech is in the car. That is hard to understand.
So we have drive people out there in different generations that are out there driving that aren't even thinking of, what is this collecting on me as I'm operating this vehicle, and where is it going? So I think what marketing needs to be able to do, and I've talked about this before, like kind of like a broken record, is it's the transparency, communicate to, um, the drivers, the owners, the, the types of data that are being collected. Why, what's the purpose?
What's the scope? And be transparent with how it's stored and needed. How long is it retained?
Also, manufacturers need to obtain consent. Um, I I ob explicit consent. I'm sure that there are probably things in, you know, when you go in in and buy a vehicle, it's a three hour process.
There's a ton of paperwork still. There might be things in there where you're signing or just initialing and it's allowing them to collect and use your data, but you're not aware of it because it's not explicit. I think it needs to be that, and I think they, that, that organizations need to work with marketing on data minimization.
What is the minimum amount of data we need to collect and why? Um, and ensuring that, so the marketing, marketing mar marketing partner with IT and security are doing what they can to ensure that the driver data is secure. There's no unauthorized access use, it's gotta be encrypted, et cetera.
It's, it's a partnership, but it's definitely something that I think needs to be explicit. And I think this is the tip of the spear. Yeah, you're right.
I and Lisa is spot on. You know what's interesting is the Texas Attorney General is Ken Paxton. He's the same guy who is part of the group that sued Google, along with the u, the Department of Justice.
So if he does it, I, I assume Latian James in New York will be looking at certain companies. California will be in the same way. In a sense, it's like data is considered the, the new oil, right?
We keep hearing that phrase, but it's also perhaps Achilles heel for a lot of companies, not just tech companies. They're gonna delve harder and harder into AI as they adopted. And as they do, they're gonna be gathering more information more quickly.
And, um, gi given what states are, are going to probably do in California, as, as Lisa mentioned, has one of the more aggressive privacy laws, it's, we're gonna see more of that. It's already happening in Europe. It's just gonna, it's gonna escalate.
Yeah. So, so John, yes, Texas was one of 1632 or all 50 states of that Google thing. I I wouldn't call it 10 pax than enough for, for being a maverick there.
No, I, Yeah. I, I, I was gonna get, And that's the thing, shades of Elizabeth Warren. Is it really Texas, the bastion of, of dereg you know, of, of doing this?
Or is reason Tesla? Or is it that just Tesla moved there and because I, I find it hard to believe that GM's the only company doing this. No, but to, to, and this is why I don't think we need, you know, the, the, again, with the Supreme Court, with the administrative use of administrative or the, or the extent the power of administrative agencies at the federal level, we're in a, we're in a bad place.
But this, this is something that shouldn't be state by state. This should be a nationwide state. Because what happens when I course from Texas, Oklahoma, is GM allowed to start collecting it again, right?
This, this is not a state by state. This screams for a consumer protection agency at a federal level. Totally.
Did I Right? But conceptually you agree with what the state of Texas is doing here? No, I don't.
No, I don't conceptually agree. 'cause I'm gonna tell you what Lisa, I think you hit it dead on. Let the marketing people talk.
For the most part, what GM and these companies are doing, I think actually serves a, a public good, right? I think it's, it's that information that underpins the OnStar emergency, uh, response team, right? When you've been in an accident and you're bleeding from your head and you can't talk so good, but you're able to hit that OnStar button, you want them to be able to gather some data to help you.
Good point. Yes. You want them to collect data that can make our car safer going forward.
This is, this is a public relations issue, not a regulatory issue. I think if gm, Ford, and even Tesla and with all, and let's face it, Tesla's software wrapped around a battery, okay? I'm sure they're collecting tons of stuff.
And so, but if the car companies can do a good job of saying why they're collecting this stuff, and it is somewhat anonymized. I'm gonna take, but you know, how often until a break failure happens, how often do we get blowouts? How often do the lights go on or off?
What speed do we usually drop? All of this data that goes into could be going into making us safer, making more, you know, safer vehicles that suggesting better legislation for car safety. Do we need the, the bump, uh, the airbags on the sides and, and what have you?
I think the car industry, the car manufacturers can, and, and by extent others can make a huge PR campaign here that they need this data to protect us. Are they selling it? I didn't see an allegation of them selling this data.
That, that's, that's my take, Mike. That's, that's the, yeah, that's what the rub is, right? If they're, if they're exploiting the data and as you said, They're selling it, that's another story story.
That's another story, right? If they're, if they're using the data to protect you in the case of an emergency, like through iPhone, I mean, you have that, you have those certain options. Sure, in case of emergency, you're incapacitated.
I'm all for that. Um, but yes, that's where you tip the line in Selling it. I think this, the subtle issue at work here is that they're buying data from third parties as well.
And there's this whole underbelly of data brokers out there, and no one quite knows what that data came from if they got permissions for, to use it in the first place. But Lisa, do we need more regulations around all this data brokering stuff that is, uh, feels to me very much like the wild, wild west out there. It does feel like the wild, wild west.
But Alan brought up some really good points there about thinking about the type of data that's being collected. How is it being used? Because you, you're right, Alan, we want our cars to be safer.
We wanna be safer, we wanna be more protected as we're traveling about wherever we're going. Um, we also wanna make sure that, that there is, um, and I'm not sure if regulations is the right word, Mike, but there has to be guardrails around misuse of information or Yeah. More information being sold.
Not just how I'm operating my vehicle, but information being, you know, sold by data brokers to determine if I, um, need my insurance hiked up. 'cause let's face it, they're not gonna go the opposite way and say, Lisa Martin is such a safe driver of her car, let's dial don her insurance premiums. But I think, um, no, no, I don't think it's regulation.
I think it's more guardrails. Lisa, let me go ahead, stop you there and, and ask your opinion. Have you guys ever done the progressive or Geico thing where they send you that plugin that plugs into your car and it monitors your driving and if you're a good boy or girl, you can get lowered rates?
I tried. I have not done that. They said, we're lucky you, we don't raise your rates, unplug it and send it back.
But, you know, I mean, technically who's driving, at least in the state of Florida, we yell at people who are driving at the speed limit, right? They're gonna cause accidents and they getting in the way. Yeah.
Say in California. Like California too. Yeah.
Point. No, but Lisa made a point to your point, Lisa, if the insurance company came to you and said, Hey, I'm gonna monitor your driving and I'm gonna see how fast you go and how, how quick you break, how hard you break, how much you change lanes, do you put your signal on before you change lights? And if you're a good person, we'll lower your rates.
If you're not, we may hire your rates. You wanna roll the dice? Yeah.
Right. Is that, are we okay with that? I don't know, but I will tell you about my early inventions of living in the state of Florida.
So, um, I was doing 80 and I pull, I saw a cop coming, so I went right down to 65 and then he sat on my bumper for about, I don't know, maybe five miles or so. And before he pulled me over and then he pulled me over to gimme a warning for quote unquote going too slow, even though I was at the speed limit. What, You know, Florida, the rule is you go 10 miles over speed limit, they won't pull you over if you're just 10 miles over.
And, and on the highway speed limit, that's kind of consistent Speed limit 70. That's kind consistent here. So 80 is the going rate.
Yeah. California, yeah. Lisa, I think right?
If you go on 1 0 1 or two 80, if you're going 70, you're fine. I agree. What, Where do, do you ever go 70 on 1 0 1 or two 80?
You guys have so much Traffic when you can't go faster. 'cause there's cars in front of you. Right?
Exactly. We, We put Traffic. That's how you get the speed Lan.
It's a it's a game. Yeah. It's, it's like a video game.
I, I But no, I mean look, they're, they're gathering this data, but, you know, all kidding aside, all kidding aside, the real issue here is, and then Lisa, you dead on, I think right off the, the bat on this one, we need to make it more explicit when companies, whether they be car companies or Amazon with Alexa or, or you know, any of these companies, we need to be more explicit when we're signing over permission for them to get in our shorts right. To, to just really collect a lot of data that we're not realizing that they're collecting what they're using it for, who they're sharing it with, et cetera. Right?
Is it going into the next version of chat, G-P-T-L-L-M or something? Right. And I, I think it would be good to have better transparency on, on, uh, disclosures around that.
That that's really the issue to Me. This should also be fairly simple to read. It shouldn't be like a thousand word document You sign, right?
Yeah. Can't legally Exactly. We just click, click the box at the bottom there can Read.
Right? And, and then that, look who said about going to pick up a new car, it takes it's minimum of two and a half hours. Yep.
Right? And yes, and, and by, by the time you are 45 minutes in, you are just, you know, looking for those yellow highlights that you gotta actually, the last couple times it's been an iPad they gave me and I just pit initial, initial, initial, initial, Initial, initial. It's a DocuSign.
Yes. I don't even know what I'm initialing and I don't understand the babble the guy talking about. I think this is a conspiracy to suck the joy outta driving.
So we'll all get Teslas and then nobody will be driving. Wow. Wow.
Musk just be, I hope not. I really don't. I'm sure is right.
He's done it again. Well, But, but, but seriously the amount of information that we knowingly or unknowingly, knowingly, so I can give people permission to collect from us. It's the same thing on your uli with your software licenses.
I, I had an issue on my Aura ring today. Uh, I've had it for about a week. Well, I've had my ordering for a long time, but for the last week, my nighttime heart rate's not being monitored and I I went on help and opened a ticket.
Well, it turns out they have all my, they have access to all of, and that's, that's health information, right? Yeah. It, I, I imagine.
And, and, um, you know, they've been collecting it and I, I guess I knew they were collecting it. How else do I see it in my reports in the app every day. But you think about it, they have a complete record of how often I exercise, what my heart rate is, what my REM sleep is, deep sleep, you know, all the things that aura collects your cardiac and all of that.
I I never really, you know, who reads those libs And what are they doing with that data? I don't know. Right.
You know, where does it end up too? Right? Right, Right.
I mean, they could, they monetize that 'cause times are tough. Yeah. Don't pay the 5 99 a month, uh, subscription for the Apple.
Just sell your data. I would love an app that just kind of told me who has my data and for what and maybe for what purpose? Just a little synopsis of the EULA agreement.
So, and then maybe, you know, like on your credit card where you can turn off services, I can turn off data access to various people. That's a brilliant idea. Mike, you should start a business.
There you go. You should. I'm I, I'm on way, I'm on the way to the Valley.
Get me some appointments with some tech bros. We'll get this going. Should come up on Safe Road.
You got it. Alright. Gosh, that trip shot Shot, I need 'em here.
Go easy. Okay. Um, anyway, or maybe, look, John wants to be the new chief content officer.
So Mike, go ahead. No, no, no. The escort of a plug.
No, no. Listen, I, I think on that note, we're gonna let you guys get on with your weekend. We do have a full text, strong TV lineup immediately following a text Strong gang today.
So do check out. It's a great way to end your week. There's so much, so much going on and we have such great content there.
Um, Lee, quick plug for your podcast, remind people about it and how they can get to it. Yeah, Absolutely. It's called Marketing, art and Science.
It's available on the feature in groups, uh, and six five media's YouTube pages. Uh, episode just dropped yesterday featuring the chief marketing officer at Dynatrace. And we talk about leveraging AI marketing councils, um, and how they can help organizations to really generate and prove marketing source business.
So really good stuff there. It's a biweekly show and you can find an on featuring group and Six Five Media, YouTube, and of course on Text On And a bird tells me it's soon gonna be available on Apple Podcast, Spotify, and all your favorite podcast channels. So stay tuned for that.
Alright, on that note, John, Lisa, thanks for joining us. Mitch had it jumped out early, but thanks to him as well. Mike, I will be back at the desk with you on Monday, Nick, we'll see you then, but we'll be on the show.
Are you gonna do the show tomorrow? Uh, no, I don't. I I'm in Texas.
I don't land well with through the magic of television. I will not be there tomorrow, today, but I'll be there tomorrow, Monday. Gotcha.
So for Tuesday show. All righty. See you Tuesday.
Until then, though, this is Alan Schal for Techstrong. Have a great weekend everyone. One.
I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research.


