Bending Towards Visibility – The Inevitability Curve EP16
Host Chris Blask and guest Blaine McNutt delve into the evolution of cybersecurity, discussing their experiences in the field and the changes they’ve witnessed over the decades. They begin by reflecting on their early careers in network security, focusing on military-grade security and the inception of early firewalls. As they explore the transformation of security measures from traditional models to modern approaches, they touch on concepts such as zero trust, non-repudiation, and the impact of cloud technologies on current security paradigms.
They examine the significance of visibility and contextual understanding in managing security in an increasingly complex digital landscape, the challenges posed by too many alerts, and the potential of AI and quantum computing to reshape the field. They underscore the importance of a proactive approach to security, emphasizing the need for foundational hardening, clarity in policies, and a return to core tenants that have stood the test of time.
Transcript
This is Textron tv. Hello, my name is Chris Blak. Welcome to another episode of The Inevitability Curve.
And every week we try to take an interesting topic. We certainly take an interesting person, and we look at where we've been on this path, where we are right now, and perhaps, you know, uh, intuitive a little bit about where we're going in the future. So with me today is the good friend, Blaine McNutt.
Hi Blaine, how are you? Hey, Chris. Great.
It's good to see you. Good to see you too. Where in the world are you?
Uh, round Rock, Texas, actually. Round Rock, rowdy Rock or Round Rock, Texas. I'm actually in Ontario, Canada.
I've been spending a lot of time on solar power boats and so forth, but like the Sparrows returning to Capistrano when I start, uh, showing up in the north, it's a sure sign in spring. So it's, uh, it is good to see. And we worked together at Cisco, uh, uh, a billion and a half years ago, I think, around the term of the century.
And, you know, and now, now you're working at Wizz. Um, I'm working at sobes. I'm doing a thing for Techstrong.
We're both involved with all sorts of industry activities, and we can riff on all of those. And as we're talking about in the green room, um, we'll sort of follow your lead on this. So how we want to take it, you know, looking back as you got involved in, in the security space, you say we, you know, as you were say with the military background, you're take taking a really structured approach to security, then merging that into this chaos wild west of the internet.
Wrap around to where we're now. So what did it look like to you as you are entering the field at large? Sure.
When, when I first started, we were working on military grade, uh, network security. So started off with, uh, out of band Authe authentication and authorization, full encryption across the network. It was our, you know, our customers were, uh, the NSA Swiss Bank and, um, the Scientology group at, at that point in time.
So we had very small group, right? It was very small group people, but we were really focused on security. We got purchased early on, uh, because we had license of the Microsoft stack.
Uh, we were building Windows in T 3 51, then six compliance content. And then they had us turn around and build the first Windows in T Firewall. So we started with really heavy network security and moved into perimeter security very quickly.
And this was just at the buring. We were trying to get into that, you know, new businesses were trying to get online. We didn't know how to do it.
So they, everybody needed a firewall, and we thought we could build a commercial firewall that would be viable. Um, and we were doing a lot of stuff also around audit management systems, which were kind of the early sim correlations across Windows NT. We were trying to build that.
So that's, that's where we started. And then we got sold to Cisco, well, in, sent the Century firewall, right? Uh, I think about this, uh, this conversation, you know, in my odd history, you know, I was border aware you in, in, in the early nineties.
Then I spent some time with, uh, uh, with the gauntlet of folks I ended up at Cisco and, and where picks, and they all firewall ended up being the big thing. But I was hired to be the product manager for Century, which last meetings until the end of life, you know? So I had this brief time to, to get to know that, and, and I'm, and in the interview process and thinking about the job, that's the job I was lying for.
Can I sit here with a Windows NT firewall? And if given everything else I've said in my career, say, yes, this is a good idea too, right? And, and, uh, yes.
So let's, let's, let's, let's dwell on that for one for a second, because Windows NT still exists out in operational technology, industrial control systems, and it's this sort of, you know, cliche is Windows 11, right? I mean, that's the core, right? We shifted from, uh, XP to Windows NT and then on the, on the core, right?
Right. Yeah. So, and we, and but with your background, you know, that hardcore security, military grade security, you know, making a Windows NT firewall, what is that would've been, that would've been 95, 96 Yes.
Kind of thing. Yep. 95 9 6.
Exactly. We got bought in 97, but we were building out all this technology in nine five, started in nine four, the, the audit management system, which was really meant to be an early intrusion detection system. If we reframe, rename it to what it would be today, that was Scott Wiggles brainchild very early, right?
He can't come outta Harris. And the, uh, the, the, he built a trusted system database for Soliris. Uh, so we had, you know, a lot of background in cybersecurity, which was in just called trusted systems, right?
I mean, I think, I can't remember what you called it before, uh, uh, but I've heard some of these earlier conversations, and we didn't really have a name for it, right? It was just we were trying to build a way to do things securely. The number of attackers who were out there were, were limited.
Um, and certainly not at scale like they're today, and they didn't have the toolkits off the shelf. I mean, there's so many things today that make it different. Uh, but all the tendency we had around cybersecurity at the time, like confidentiality, integrity, uh, least privilege, which, you know, we now call zero trust or whatever.
But it was really trusted untrusted and defense in depth at the time. But it was focused on, you know, at the network stack layer enforcing did you have permission to talk to this box? And it wasn't, it, the stack enforced it, like, it, it wasn't a policy, you know, I mean, it was a policy that you distributed, but it was all manual, uh, distribution.
We had a lot of, uh, uptake problems for that. And no one allowed encryption across their networks. So when Cisco bought us, they had us, you know, divest ourselves of that product.
It went back to, you know, a military, uh, focused company, a DD focused company. Um, and we went on with, with Century, but we did build in some of the tenants of that, you know, um, we still, uh, had encryption between the distributed components in Century, which was one of the early attempts at, at distributed systems. I would say that, um, that was also, if we look at cybersecurity and the tenants, we did some things great.
And they managed to survive, and we did some things that we did that just didn't make it right. It really took microservices architecture to drive the, the distribution that we needed today. And all cybersecurity back then was really limited based on, um, the compute power and the expense of that.
So, distributed systems were too expensive because they required more than one box, and Cisco knew how to sell boxes. They didn't know how to sell a distributed system or software, right? It was really, it took them a while to get to that point, probably around 2010 before they actually started doing licensing around software, right?
In a, in a, in a at scale way. Uh, but we also really wanted early on to do attestation of code at the, at the code level, make an algorithmic proof that this is secure. So that's something that we wanted to do early or haven't been able to do yet to date, but we're probably getting closer to that model, right?
Um, so, you know, I think I've, we had a, a limited application of the trust and untrust it, it, we ended up being that to do that, well, we had to just basically have internal and external perimeters, as you'll remember from the, from the picks, right? So, depends in depth where we were trying to build perimeters within perimeters per, within perimeters, was, was really difficult. Um, because those policy distribution systems that we generated later with CSPM, the Cisco Secure Policy Manager, uh, those really didn't take off.
Uh, well, either we fell back to the, you know, I'm sitting at the box level looking out at the rest of the world. Um, and now if we look at where we are today with, with the cloud, I think that these are the models that will come back again. So over time and over history, what I keep seeing is a pattern of us trying to take the same thing that we applied earlier and, and rebuild that in the new world.
You know, with, with new, with a better intersection of technology in marketplace, right? People are aware of the problems, they understand and trust technology much more. I mean, it was so much about untrust and distrust back, um, back then we couldn't get anything done.
Like we couldn't even discover the networks, right? To be able to build auto policies, right? Nobody would like, oh, no, you can't, you can't probe the network.
That's not allowed. Um, so, and it was really, because all processing was so expensive, even at the, the gateway link lever, right? Well, and everything was so expensive and expensive in time, you know, is the most recurring theme and everything I'm talking about today, maybe it always has been.
And I, as, as, as you're talking, I'm putting together what you're saying right now and what we're talking about in the Green Room. I think I finally know what the theme of this episode is, right? Because this is, you know, it's not the arc of authentication or anything else.
It's everything. Right? Right, right.
Because I keep saying, you're saying the same sort of things already, um, that in a lot of the work I'm working on today in supply chain and software build material and so forth, a lot of these working groups, I, I find a, you know, I fear that I'm repeating myself a bit too much. Um, but I keep saying, this isn't really new, and this is, who knows, this is what we're doing, right? We're filling in this part right here, which is really important.
But we knew about this decades ago, right? And, and I think we're coming at a time where, because a lot of factors, we can do the things we had meant to do all along for the first time. Yes.
And that may be changing entire paradigms of how we not just do security, but how we use these networks. So lemme let me see if I can follow the, the thread a little. You mentioned CSPM, the Cisco Secure Policy Manager, which what's what the Century Firewall code base turned into?
Correct. In 99, yeah. 99 2000.
Uh, correct. There was a, we were in the cts office, but Judy Estrin and built that as a SKUNKWORK project. Right, exactly.
And all that came out, I, I had to say this one 'cause that came out of the internet access and Appliance Business Unit. The I-A-I-A-A-B-U is the original business. You, you, and you and I, uh, ti and I just broke, I think the last or the next to last IAB wine glass.
I've had just on the boats a month ago. I was like, oh, oh, no. Yeah, yeah, right.
We're at the, at that point. But, you know, the Cisco Secure Network, right? And, you know, and I left with a couple friends shortly thereafter, we, uh, started a sim company sold to Cisco, and it didn't really go up a, a long way after the acquisition, right.
And that, that, that team actually originated with CSPM. Well, that was Partha Iman, I mean, so they actually went over and created, uh, forgo came back. I, I worked on Mars extensively as well.
So these are all things that we've attempted, and that was just a frustration that they wouldn't let us generate logs or correlate, uh, detections from other companies. That sort of distrust has also gone away. I think that companies and their partnerships view, you know, the open APIs and rest APIs that we have, allowing access to monitoring events pretty freely now, and that, so these sorts of visibility problems across your environment have, have, have gotten much better, right?
It's just that now at scale, they're, they're problematic. So I think that, um, if we look at today, you know, what we really are doing much better, and what Wiz absolutely crushed is the visibility in correlation of context across multiple domains. So we've seen multiple iterations of this consolidation to a single platform.
We saw it on, on Palo Alto Networks firewall, which was amazing, where they correlated all the different detection types, whether it was IPS and DNS and, and URL filtering all the things that we had done, even, even early actually on, uh, century Firewall. We actually had URL filtering and cash filtering and, and load balancing, all these things built in. But now they, they, they built it on the next generation firewall got much faster than that.
And Wiz did the same thing around CSPM, KSPM and identity and secrets, and malware and vulnerability management. Because at cloud scale, the problem has become that it, that there's so much moving. It is so fast.
There's so many new technologies coming in, and there's so many new teams that are actually involved in what could be security. So from the development and the, and the DevOps and the, and, and the SREs and all of these folks all the way into the SOC still, we have all of this new context that they need to understand what's happening, what's, what's on a box, what's the business context, what's the, the data that's on it, is it valuable? Because the number of alerts, this really hasn't changed, right?
Like, we still have too many alerts and not enough actionable insights. And that, and that's where R really came in, right? So I think that full context of the cloud environment and shifting onto on-prem is really where we're trying to go today.
Like, this is the problem we're trying to solve today. Give us the insights and visibility, but we still have this overwhelming, uh, sense of too many alerts in actionable. So I think we're gonna fall back to some of these older tenets again, right?
Let's focus on hardening OSS and container images. Let's use those as deployments and redeploy every night if we need to, to try to solve and harden what we're doing, right? How do we get the SBOs right?
This is this validation in, in non-repudiation, not only of users, but of the, the supply chain has become really difficult, right? And this is, I know where you focus, you love this stuff, right? Uh, but shifting left into development and how do we engage those folks to proactively, you know, use the same information that we have from the cloud to help focus on, on preemptive hardening.
And that still just goes back to let's preemptively harden and, and not ever get it into production environment. So I think we're, we're moving toward things. I think we've had real success, you know, like obviously point to point encryption from the old days, from the t and t days, which was not the, the D six product just didn't work.
We have it everywhere. That's ubiquitous. I, you know, when I was at Palo Alto, I think we said there was 70% of all traffic on the enterprise networks were encrypted.
And I would say almost all traffic on the Internet's encrypted. It's pretty rare you hit an A CTP with, without a TLS connection, right? I think we've made great services with, uh, zero trust, so that we at least the concept and that that's nothing new.
Again, nothing new. How, how, uh, we got that term patented, I'm not sure. But it was the untrust, you know, it was the same.
We, we all saw this, we all saw the, uh, you know, like trust sec, Cisco was really Dix. We kept seeing these patterns over time come back. Um, but we also have, we've really made great strides in the, in the monitoring and auditing, which I think is I important because of the ability of, of opening up these APIs, we have made amazing, uh, progress with the computational and storage expenses, right?
Like memory with virtualization and the cloud platforms, the ability to do microservice architectures where everything is isolated. This is foundationally different, not to mention. And I, I, I go back to, there was a conversation you had earlier with someone, uh, um, where you were talking about building your own CRM.
And I was laughing because we had to build our own databases. We had to build our own object-oriented databases. You know, we had to build our own, uh, protocols around, you know, uh, RCP type protocols.
We had to build all of our own queue systems. We had to build everything that that wiz came and took off the shelf, right? Like Neptune, uh, custo, we have a whole, whole lot of stuff that we just leveraged the very best technology out there that somebody else maintains, and we can focus on our mission.
So I think that's been a big benefit to security today. Um, but it's also exacerbated our problems because now our attack surface is multi-cloud, multi environment, and the technologies are coming up by hundreds a day, it feels like, right? New technologies, new versions, new it iterations.
How does anybody supposed to keep up with this? And this is why I say we have to fall back to those old tenets, right? And this is so many points on there to touch on, right?
You just, the, the, the, the quantity of alerts topic, right? And you and I both been around long enough. You know, we can go back to the, I got an alert today and it's freaking me out to, I gonna get alerts all the time to what you, where we are right now, where, you know, as you're saying, we've got an alert management infrastructure in general terms, it's good enough now that we can say we can't actually tune this much.
Maybe it's time to actually secure the hosts, right? So general being someone, the alert, cutting out the noise from the gate, from the get go, like, we do that, right? And I think that that is a real opportunity for us in the future.
I would say, I think we still failed on the concept of trusted operating systems today, but we're making improvements, right? We have some really good, uh, container images that are getting hardened proactively. But Linux is new, right?
I mean, we, we hardened DNS over decades to get it to where it is today. Um, and that, you know, that's, I remember talking to Scott about that stuff early on. How do we get, how do we make these things better?
He's like, it's just time, right? Like, it's just time. There's no way to plan it out in advance.
But algorithmically, you know, in the future we have a chance, right? Well, and time and scale, right? You know, the, the, the, you know, the recurrent themes that I, that I keep talking about all the time, you know, come down to time to visibility, right?
I don't know if that's a real term or I just, you know, think of that, but it's, it's the, you know, securing the host. Like, you know, go back to the days, the eighties and nineties and so forth. We're saying you need to secure the host.
And people are saying they don't seem to be they falling apart. They, and I don't have the time. And then we get to, you know, actually doing some logging and alerting and finding out that yes, they're having problems all the time, right?
And it takes periods of, you know, decade or two or three until the drivers are there to allow the time and the capability of actually making secure, secure host, as you say, you can redeploy them overnight all the time because they're now cloud containers, and it's not a sheet orchestrator problem. Yeah. Orchestrators solve this problem for us.
They, they can do it on, you know, as a new image is detected in, in the registry, it just comes back up. It's amazing, right? This is, there's some amazing, uh, improvements that we've made over time, but we still have a few, like the non-repudiation is tough.
I think that, um, you know, you spoke about this in an earlier, an earlier, uh, episode as well about the bespoke, uh, attacks, right? So there's a risk in the immediate environment, and that is, you know, a lot of the really great technologies like wildfire from Palo Alto, they, they're based on anomaly detection. So if everything is unique, there are no anomalies, right?
And so I think that that is one of the things that we have to think about. And again, that is why we have to fall back to these earlier tenants around, like, how do we validate, how do we get non-repudiation in and how do we harden the OSS in a way and harden everything, all the infrastructure in a way that we can get to that? And then we'll go back to the policy generation where we deploy at a service microservice and application level, and then infrastructure level as a defense and dev strategy, and monitor that.
We'll finally be able to do policy audit, which was also something we could never do before, right? Validate that what we think is in place is actually in place. And that there is nothing that's creeping around that violates the policy.
So, you know, that we finally have the compute power to do that. And all we really need is a better logging system, which is what, you know, syslog has always been terrible. How do we, how do we solve for that?
I think we're making progress. We have the LSM modules in Linux also that should help with some of the trust stuff coming in the future as well. Right?
Well, and a lot of that, you know, takes us, you know, you know, right in, right into the present, right? And these are the things that, that I'm, you know, rolling right in my head all the time, pondering on, because we take a lot of things, you know, a lot of, a lot of pushback in the past. And this is where my whole inevitability curve thing, you know, kind of, you know, starts.
Because if right now, at any given value of now we're saying there's too much of a and a is increasing, then at some point there'll, you know, there'll be more a than than air molecules, right? And we had to address this somehow at some point in the future. Anything that's increasing, you know, um, continually has to at some point stop or be dealt with.
And, and a couple cases just what we're talking about here. Um, but, you know, the, the, sometimes you actually go back to the host, you'll, you know, get back to the foundations, actually stop producing as many of those, uh, alerts and, and, and things to deal with. And sometimes you just, you just throw more horsepower at it.
And everything we're about today, computational power, quantum computing, ai, LOM, you know, A, B, C, a bunch of great acronyms, and the keep going back. And last, one of the last things you said, you know, I, I, I love because we have never been able to understand policy, our policy environments at all, right? Right.
I've been sailing these boats up and down the Florida coast for the last three years. And one of the things I find fascinating is even at two knots, I can't google fast enough to figure out what laws apply to me as I move across the water, because you, I'm looking for the three words that tell me the county name, the municipality, the word anchor boat. You get a bunch of, and now just for this little chat TPT thing, I can just say, what are the anchoring laws in the next three miles at, you know, northeast of here?
And it just lists them out, right? And it may not even be entirely accurate, but oh my God, it's so much closer, right? Yeah.
We're direction, we're heading directionally the right the way, right? I mean, the, the full context thing from the, you know, like the Wiz provided, I, it's amazing when, when you see what you can do at that, and you think about that, think about that use case. We know that we're in a certain region, we know the laws that are associated with that.
We can start to correlate data all across. And now we don't run outta space. We don't have, we're not trying to consume a limited piece of, of infrastructure that a customer has.
We, it's almost infinite. Like it's not, but it's not, you know, obviously it's not infinite, but it's almost infinite in terms of the application's perspective. Well, it, it collapses these, these impossibilities, right?
You know, and it's, and it's anybody who's watched the Moore's Law of Complication, you know, as, as, as seen this happen. But you get people saying experts, world experts who know exactly what they're talking about. It's not possible to do this because it would take too long, right?
And this whole policy thing of all hacking and physical hacking and cyber hacking and policy hacking is my favorite topic because it's all policy hacking at the end of the day. How are things being used and our ability to understand policy, a again, in every context has been about zero, right? You don't know if you're breaking a law, you don't know the laws, right?
And we're getting to the point where even in these, these sort of, you know, common popular going to the store, driving to the street, uh, context, we can see everyone being able to see all the policy impacted all the time. And in our little world of, of information flows, and cybersecurity wasn't even me. And, you know, just if I could say, I know the rules and regulations that apply to me in this action right now, I know what I have committed to, but the company I work, I know what I've committed to my employer, that policy in the contracts, I know what they have committed to the supplier and supply chain contact, what's in the con, what's in that contract?
What's the contract language that applies to what I'm doing right now? I know the regulations and the laws and the jurisdictions are every step along the way all at once. In none of the time it took me to say this, what does it even mean, right?
As opposed to the same thing where you go, I'll bet I could. I'm not really sure. And you don't, right?
Yeah. Yeah. That, which is still like one of the places, places that we're just really, we, we, everyone suffers under that.
It's, uh, it's under the overwhelming, right? It's under the overwhelming Yes. Like in the, in the supply chain, you know, world like, and a couple of things you said, you know, lead up all of this, like in the, you know, in around the turn of the century, we hadn't enhanced threat intelligence and information sharing and ISACs, you know, really doing anything and so forth.
But now we have a couple decades of to that in supply chain, you know, we're building on top of that plus, you know, the massive global legacy of logistics and supply chain organizations that may not have been doing security, but gosh, if they aren't tracking things all the time and really good at it, right? We're starting to bolt these things together with, you know, and I, again, I was gonna say my, you know, looking into the future, are we in time, 25 minutes looking into the future, right? I think we're moving into the space where we can do a bunch of stuff that folks about our age, you know, have been working on all our careers to this point and inching towards, and just, you know, looking at it from the supply chain side where I can literally do that.
I can say that, you know, we bought this, you know, it's a company asset, and I am the authorized user of this, so I'm allowed to see certain levels of information about it, but I have a problem with it. My help desk is responding to right now, and there's a new firmware update. There's three seven layers back in, in the supply chain, but everybody has a contract language in place.
And I get that software bill and material or that at attestation about whatever it is that I need to know right now. I, I think we'll automate a lot of this. I think this is, I think that we could do this for users.
I think we can do this for service accounts or the, the non-human identities. And I think we can do it for the software images themselves and, and, and then generate that into the sbo. So like, I think that non-repudiation at the, at the, I'll call it file level and, and in the user or operator level.
So the principle and the file level will be, we'll be able to get this right? Like this is just, and it's, this has been the inevitable piece getting here, right? Like, it's taken so, so, so long to get here.
But we do have blockchaining, uh, you know, which was originally what it was designed for. It wasn't designed for crypto coins, right? It was designed for this sort of this, uh, how do we keep track of everything and have the chain of custody that we really understand and can validate, and it's, and it's transparent, right?
How do we do that? So I think the technology is here, we're just, we're still trying to bolt together these older systems rather than scratching it and starting over, right? I think it, it, and it, and it is hard to do that.
I think that, you know, short term, we're gonna get to the algorithmic attestation at the microservice application level, right? So we'll start there, and then we'll just rely on like hardened oss and, and container images in the meantime. But those will also, uh, you know, in the longer term, we'll use AI to help us refactor and, and, and validate those, right?
And so as we do that, that will be really, really valuable. Um, I think that, you know, this, that we are the next near term future, I believe is this automatic deploy end-to-end policies across the infrastructure layer at the application microservice layer, so that we get zero trust and defense in depth at the same time, right? So we'll have smaller nested perimeters, um, that are, you know, based on the guardrails around the microservices at, at multiple layers in the supply chain.
So the CICD pipeline, the developer pipeline, the deployments, um, at deactivation activation, we'll get to see all this data and it'll all be logged in a way that is much easier to interpret than like a cis log, right? Um, they're trying to correlate all these events together to the same object, right? This is really hard, uh, Wiz does this, but it's really, really hard to do, right?
And I think that's one of the things that's been tough. I think we're also gonna shift, you know, one of the things we do today is we use enterprise browsers, which is moving us back to the dumb terminal mainframe type model. But I think that this is the answer in the future, because we can't harden all the endpoints in a distributed fashion.
And I started thinking about this when you guys were talking about the medical devices, right? What we will move to is that the medical devices and these IOCs will just be dumb terminals, hardened dumb terminals into microservices, that, that will just collect data and distribute it back up, right? All they're gonna do is push data up.
Uh, and so it's not gonna be, and they'll read from the microservice, and then we can harden the microservices. And, and that's how we solve for this long, long-term upgradability problem that we have with all these devices. You know, you, you said attestation three times and, you know, uh, uh, like, like Beetlejuice, you know, that just caused me, causes me to, you know, appear.
And that it, it's, it's interesting to watch that work. It's 2019, February 20th, 2019, February, March, that, uh, Maria and Dari and I came up with this idea for what's turned out to be an open source attestation ecosystem, but the, the Debo project, the Debo io. So now, and it started at, just as you said, it started as a conversation about blockchain and security.
And once we realized, you know, what we're talking about, we, we tried to see if we could talk about it without saying the word blockchain, because that's been so spoiled by cryptocurrency. And, but it's just distributed ledges. It just means that more than one person has a ledger and whoever touches it, it magically replicates you can't fool anybody.
A neat feature. And in the, at attestation world, and, and it's funny, y you know, I think immediately after that call, somebody said, that's an attestation system. I was like, attestation.
I know that word. I hadn't really heard it. Right?
Right. Now we hear it all the time. And we literally had in the supply chain world, you know, the idea of attestation forms, which sounded almost as bad to me as blockchain, but, uh, uh, but, but it's because of what it sounds like is someone's just gonna say, say, oh yeah, I'll sign a P two C.
Well, yeah, we did that wink wink. Now, when I say attestation, I mean the systems in real time are attesting to what they're doing. And that is transparent to everyone.
You know, who, who has a policy around having that information, like, you know, the customer. And if the analogies I like to use is a shrink wrap machine, if you're packaging my, my product for me, um, and I'm selling it downstream, and one of the requirements is it does not go above a certain temperature in the shrink wrap machine, I would like that shrink wrap machine to attest to some repository, some channel, um, maybe a distributed ledger, maybe a d on channel, or I'll know if it broke that. I mean, I'm not gonna get a customer a complaint, right?
I'm not gonna see my product looking weird before I ship it. I know for a fact that it hasn't been spoiled because I ha have already gotten all the attestations in real time forever for the last seven years. And I know if it, if I see an attestation that it went over, I know that I'm not gonna get that box.
Okay? Because I know, you know, I know, you know, everybody has, and that sort of visibility just makes things easy, makes, you know, it saves a lot of time, it saves a lot of concern. It, God help me for saying this keeps businesses honest.
Well, and it keeps the, the contributors to like open source projects, honest. Like how do we, how do we attest to, or, or have the non-repudiation visibility into who these people are who are making contributions? Like I think this is really important to be able to tie it back.
Is, is, is the, that's gonna be the biggest problem to solve, I think, is how do we, that's still the biggest problem. How do we solve that? Uh, I think we'll get to that realtime policy validation and, and audit along the way.
And so I think that is it, as you said, not only the, the pipeline and, and the supply chain, but understanding the operational changes and the operation thereof, you know, should be something that we have a un uh, that, uh, ledger that's not gonna be able to be manipulated, right? I mean, 'cause, 'cause now data poisoning is one of the biggest problems that we have. O overall, like this is overall.
And if we don't move to a logging system other than sis log, we're not gonna get around it. Right? I, I think that's a big part.
So, you know, long term we'll have the AI hardening of the images, the refactoring of legacy code. We should be able to get the non-repudiation, you know, in there as well. I think we will move back to, um, out of band authentication and authorization, because how do you get rid of these, uh, attackers coming in?
I got, I can't quite envision how that was coming, but I feel like that's, that that old then six stack model where you had this completely different session fire up to say, Hey, are you really who you say you are? Like this is the kind of thing that we, we need. 'cause the internet has opened it up and made it really hard, right?
Um, and I think we'll see that almost everything goes back to using those little trusted systems. The, the, the, the lens of security modules is as a core of what we're doing. Um, it's sure, you know, our risks are really like, as you said around quantum computing, um, AI making.
It's super easy to get, you know, everything else. And I, I think another big risk is the lack of historical context. You said these are the problems that we've been working on all of our time, all of our lives, right?
The, the Brian Riches or, or, or, and the kerrigans and, and the, the er balls are, are really rare people. And so I was thinking about this problem in particular. I'm like, how do we get around this?
And my son loves history, and I'm like, it's historians. They're the people who are gonna, they're gonna move. They're gonna shift into a much more distinctive role that leads us in technology because new people are coming in, they're using this technology, they're not really good at it because it didn't solve their problems.
We are much better at using the technology they than our kids, even though, even though they've had it their entire lives, they just, they don't even know what problem it was created to solve. And we are like, oh, this is, you know, like microservices and containers. This is amazing.
We're no longer building Norton Ghost images and to solve for the problem of putting in 35 floppies, right? I mean, this is, this is, uh, we, we've solved all these problems for ourselves and this is like what they get outta the gate, right? Yeah.
That's a really good point. And, and maybe that's kind of what I'm trying to do with this series in general, because I find myself saying this awful a lot because, oh, it helps me a lot. It helped me a lot in my early career learn more about Bletchley Park and, you know, to learn from folks, you know, like John Tipt, Fred Cohen and all these, you know, when, and people have been that longer than I have because for a couple things, you, you, you, you can see the pieces that are already done.
You know, components you may not have been aware of and maybe apply to whatever it's you're working on. And you know, I, I have a tendency to think, you have to look ahead and say, oh, this is gonna happen inevitably, and think it's gonna happen sooner. 'cause I don't understand perhaps how long it took to get to this point.
Right. And at the same time though, I I, I have been correct a couple times in my life, you know, when, when people are saying, oh, you don't understand, it takes a long time for these to, to happen. Sometimes that's changing.
And I think the kind of things that we're seeing now with oh, on every level, you know, content creation for, you know, sharing the history, I think right? People like that, I, we all watch a lot of, you know, small little pieces of content. This is interesting stuff I keep saying to, to all us, you know, uh, folks already, you know, that they, you know, pretty well, all of us in the, in coming centuries, maybe forever will show up as characters in movies because seriously there whether was a dozen or a couple dozen, or even a couple hundred, couple thousand people doing cybersecurity.
It's fascinating stuff. It is. And we have a story to tell and it, and it matters.
And say, yeah, combine all that with, you know, Moore's law. And, and I, again, I hate to just to say AI or LOM because it's, it's more than just the little tools we're seeing. It's the fact that there's all this behind them right now, get these emergent properties and we're already seeing the ent ai application to small aspects of cybersecurity.
We, you know, it's gonna be, that'll be huge, right? Just to take the burden off. But I still think that even at that, we're not gonna haveis go back and, uh, make the decisions around policy yet.
And we're not gonna have it, we're not gonna have it like break, bring down production environments because there's seen next place. So we're still gonna have humans in the chain. And I, I think this is very much like, um, you know, how the FINRA regulated groups have to be, if you're using any of these technology, you have to have a human in the loop.
'cause you have to validate what we're doing, uh, before the decisions are allowed to go forward. And that's it. Just like the nuclear, uh, conversations you had earlier.
Like, you're gonna have a human in the loop and, and we're g but we're gonna get a lot less context. We're gonna cut down the noise and then we're gonna take that information that we gain from that. We'll make some, some manual correlations, and then let the AI go refactor the code so that we don't have these sorts of things happen again.
I think, I think that's, that we'll be in this loop where that's where cybersecurity goes in the future. It's gonna be all about proactive harm. Today.
We focus so much on, uh, how do we capture somebody in the act? It's, it's too much, right? Like, as we're scaling up hundred thousands of resources that are, that are alive for 20 or 30 seconds.
I mean, this seems like how, how are you gonna catch that? Right? And they, they're really good at cleaning up their trail.
And that's why that audit log has to be, we have to have the logs in a way that they can't clean them out. We're only as good as our audit trail. That was one of Scott's tenant, you're only as good as your, you're only as secure as your audit trail.
That's what he would say. Well, he, and you mentioned the nuclear stuff, operational technology, industrial control systems always love this. Right?
And, and, you know, 'cause as you say, you can cyber the heck out of it, but at the end of the day, you know, people have been building this system for a long time. My favorite example that I've seen in my personally, in my career was, uh, was acting as, uh, chief security officer for EPM, the Columbian National Grid. And they asked me, what's the first thing you wanna do?
And I said, I wanna physically see an example of everything, right? And the, and the water treatment, uh, plant, uh, up on the side of the, the, the valley, uh, in Meine had a, a great old guy, you know, he'd been doing the job for decades. And it says, you know, fifties, sixties era concrete wa a water treatment plant, drinking water treatment plant.
But they had gotten a lot of love and, and, and money in more recent years and had upgraded with all the good toys. But it's the same rooms. This concrete room, um, uh, that Freddy was in, uh, who ran the place, had, uh, all these scada you know, high-end toys and big screens and everything else, sensors, and we're looking at all that.
And just outside his office is a fish tank. And the fish tank has fish in it, and it's plumbed into the third, the next to last stage of the water, uh, purification process. And the SCADA systems can say whatever they like, but if the fish die, die freddy's turning off the water period.
I love that. Yeah. And that's right.
Yeah. We can overthink our risk here. You know, we, we're not gonna replace humans.
You know, systems may crash, you know, uh, you, uh, uh, infrastructure can go down and it can hurt people. Um, right. Which has always happened.
That's right. I think we generally, we'll keep it trending less. As long as we keep following these paths.
I think we're living in a good direction. I've found this series to be very inspirational. As you keep calling back to the younger culture, the younger generations are gonna be able to do great things.
And I, I'm super hopeful that that's the case. I, you know, quantum computing is a risk, but it's also a, a, it'll help solve a lot of the problems, right? If, if, if we can get there.
And so then it, and how do you avoid, you know, quantum computing, AI based attack generation? You have to go back to hardening. You can't, this detecting in real time is gonna be almost impossible, right?
So we have to go back to that core tenet of like, let's build it right the first time. Let's keep hardening it. Well, I, I can't think of a better note to end on, you know, um, and I, my, one of my favorite movies is a terrible beat movie, but, uh, undercover Blues, right?
And the, the, the, the, the, the lead character is, uh, saying to his little baby, you know, at a zoo, you know, reading the Endangered Tiger, um, plaque and saying, don't worry, honey. We'll make sure there's plenty of tigers in the future for you. So I think it'll have plenty of challenges.
You know, I think like our generations, they'll been fine. They'll work their way through it. And, uh, and it'll all work out.
It will just, I'm hopeful, I'm hopeful, but it took a good, it took a good show to convince me that this was it. So Chris, I appreciate that. Well, my work here is done.
That's if I do nothing else in my life, you make, make, uh, anybody feel hopeful and, and move forward a little bit, then, then I couldn't ask for anymore. That's right. I couldn't ask more for you either.
Bla thanks for being a good friend, colleague, all the good work we've done and your time today. Thank you. And, and thank you for everything you've done in the industry all these years.
I, I know that taxi and sticks were a big part of your, your early work too. So like, you've done so much for us. It's been amazing.
Thank you. Thank you. Collaboration.
Thank you, all of you for spending your time with us today. Keep up the good work. We will see you again.


