With the recent disclosures that OpenAI's security testing using its own models broke out of the sandbox and attacked Hugging Face (and others), Erik, Dan, and Brian thought it was worth a moment to discuss and debate the current state of AI, securing AI models, some of the ways that organisations can isolate and test without such risks, and the implications of what could be seen as offensive (and retaliatory) attacks from a corporation.
And, lest anyone think we are picking on OpenAI, the same thing happened in testing by Google, Anthropic, and Meta (Facebook) resulting in attacks on quite a few other companies. Yep, you're not cool in AI if you haven't tried to attack another business with your AI model. But why on earth are they all annoucing so loudly that they hacked into these other orgs? We live in interesting times, for sure.
Thanks for watching and listening!
Show Notes:
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Welcome to the great Security debate.
Speaker A:This show has experts taking sides to help broaden understanding of a topic.
Speaker A:Therefore, it's safe to say that the views expressed are not necessarily those of the people we work with or for.
Speaker A:Heck, they may not even represent our own views as we take a position for the sake of the debate.
Speaker A:Our website is greatsecuritydebate.net and you can contact us via email at feedbackreatsecuritydebate.net or on Twitter.
Speaker A:Twitter at Security debate.
Speaker A:Now let's join the debate already in progress.
Speaker B:So, hi, like on the hugging face thing though, I think there's a misunderstanding of the whole hugging face breach.
Speaker B:And what I mean by that is like, I've heard people say, well, what should we be worried about?
Speaker B:Like somebody asking to spin something up internally, their own model, and the CSO saying, well, I don't know if we should do that because of what just happened with hugging face.
Speaker B:Right.
Speaker A:I'd like to introduce you all to my good friend Air Gap.
Speaker A:And this is an easy answer.
Speaker B:He's like, but this is going to be a sovereign model.
Speaker B:Well, right.
Speaker A:Sovereign model versus.
Speaker A:I mean, but sovereign models, there, there's a bunch of mixed terms in there.
Speaker A:You know, sovereign model, something you run in your own bedrock, is still, it's yours.
Speaker A:It's a, you know, it's a model that is run locally, but it doesn't mean it's disconnected.
Speaker A:It doesn't mean that you can't, I mean, you can try and put your parameters around it, put your, put sandboxing around it so that that model can't interact with anything else.
Speaker A:But what we're seeing in this is that the models have become so good at using their own resources and finding other resources.
Speaker A:And much like children interpret the rules the way you say them, not necessarily the way you mean them.
Speaker C:But it's, Aren't we missing the point that it's, it's not the model directly.
Speaker C:A model in and of itself is actually dumb.
Speaker C:Yeah, right.
Speaker C:It's a mathematical equation guessing of what comes next, but it's the capability.
Speaker C:Sure, they've been trained on a ton of data, but unless you give it the skills and the tools to actually do something with it, it's just something creating text.
Speaker A:Agreed.
Speaker A:And it's all.
Speaker A:It all comes back to.
Speaker A:It's how you configure it.
Speaker A:Stupid.
Speaker A:It's how you configure it.
Speaker A:And you know, it's no different than any of the other issues we've had.
Speaker A:Know that as security professionals for the last 30 some years, if I run a, if I write a bad firewall rule, things are going to get in.
Speaker A:If I write a bad sandbox, it's going to get out.
Speaker A:If I don't give the, if I don't tell the model, don't do the following things, it's going to do them and it is.
Speaker B:And.
Speaker A:But I come back to the child reference.
Speaker A:I've had this conversation a lot over the last seven, 10 days.
Speaker A:You have to treat your models like they're kids.
Speaker A:Because.
Speaker A:Because if you don't explicitly say A, B or C, they're going to try and find ways around back to Water will find its way.
Speaker A:Water children and users, models and kids will find their way if you, you know, based on the, based on the parameters you give them.
Speaker A:I was growing up.
Speaker A:My dad said I was 16.
Speaker A:I just gotten my license.
Speaker A:Daniel, don't drive to and inserted a small town nearby.
Speaker A:And I thought to myself, yeah, but he didn't say go to a different small town.
Speaker A:That's further on that goes through the W. The first city.
Speaker A:So I did and I justified it to myself.
Speaker A:This is no different.
Speaker C:I totally agree.
Speaker C:And this is where people are getting lazy.
Speaker B:Right.
Speaker C:Because the, the way a lot of these tools are being written.
Speaker C:Oh, I'll just give the gar rails, I'll put it in text and I'll tell the model itself.
Speaker C:Yeah, but you're asking a model to not only do something for you, but also self police.
Speaker A:Right.
Speaker C:Wrap it.
Speaker C:Like everything else that we've had to do, there's a reason.
Speaker C:So your kid analogy.
Speaker C:We tell them to lock the door when they come in at night.
Speaker C:But there's a reason.
Speaker C:I have smart things that at a certain time automatically locks the door because I know it's probably not actually going to happen.
Speaker C:There's backup controls around it.
Speaker C:But this is.
Speaker C:I feel like there's still a general misunderstanding of how some of these models work because I remember somebody made a comment about perplexity that uses Deep seq as I think it might be their controller that's kind of proxying between different models and.
Speaker C:Oh well, it's from the Chinese.
Speaker C:Yes.
Speaker C:Okay.
Speaker C:But if put in a container where it has nothing access to nothing else and it's purely just returning some values, what's the real risk there though?
Speaker A:I think the risk that, well, depends on how isolated the container is.
Speaker A:Yeah, I've gone to running Deep Seek and it's a great model and I've been enjoying it.
Speaker A:But it's run on a device in which there Is no ethernet connected.
Speaker A:The WI fi, the WI fi antenna has been disconnected at the board, you know, so you, you can decide it's risk management all over again.
Speaker A:We decide to what extent we are risk tolerant and know that when you introduce the potential for risks they might just get realized.
Speaker A:And in this case it did, it got these things got realized.
Speaker A:You know, the attack, the, the, the model, the, the.
Speaker A:I guess one other element is there were potentially conflicting instructions.
Speaker A:Solve this problem and stay within these parameters.
Speaker A:And which one wins when the parameters are preventing them from solving the problem.
Speaker A:In this case, solve the problem was the prime directive.
Speaker A:And so it said I'm going to solve the problem again, much like kids, they're going to do the prime directive and not necessarily look at all the things underneath it.
Speaker A:This isn't a, this isn't a pejorative on kids.
Speaker A:It's just, I think it's a maturity and it's a logic exercise and one that we need to become better at being, you know, logic minded.
Speaker B:So the prompt wasn't right.
Speaker C:But it's not just the prompt.
Speaker C:Depending on the model, some of the prompts will tell you that yep, I adhere to that and not do it at all.
Speaker C:I've had that.
Speaker C:I've run into that quite a bit with.
Speaker C:I think it was Quinn that use it internally for.
Speaker C:As kind of an orchestrator for different tools and stuff where it'll tell you.
Speaker C:Yep, I wrote to disk.
Speaker C:It's.
Speaker C:I sent it off to memory.
Speaker C:Nothing actually wrote it was it just hallucinated.
Speaker C:It gets to do whatever it wants.
Speaker C:So there's got to be wrappers around it that understand.
Speaker C:All right, instead I'm going to take the context that's coming from the model and then it's still a pretty static Python function that's writing off to memory and that's how we're going to do it and that's how we're going to push and pull from context or from memory.
Speaker A:Yeah.
Speaker B:So Dan, going back when you mentioned air gapped, right.
Speaker B:So the idea of putting in a completely isolated network with no connectivity but around the parameter piece when you talked about solve this problem.
Speaker B:Right, but then here's some parameters but if these parameters keep it from solving the problem.
Speaker B:So even when you put it in an air gapped environment with no connectivity, if it needs to solve the problem.
Speaker B:Well, if it, if, if it.
Speaker B:As the tool agent says, well, one of my problems is I need more connectivity or I need connectivity, how can I find a way to go get connectivity?
Speaker B:Absolutely.
Speaker C:This is the Wrapper issue though, right?
Speaker C:Look what happened with openclaw when it first came out that, oh, you built a tool that is highly effective, but you allowed it by base install where it has direct access to all of its configs and can overwrite its configs.
Speaker C:Yeah, that's probably not going to go well.
Speaker B:So what you're saying is this is kind of like putting a wrapper around milk chocolate, but storing it in your car on a sunny July day, sometimes the wrapper fails.
Speaker B:Unless the chocolate itself was designed so that at a very high temperature it doesn't melt out of the wrapper or the wrapper itself.
Speaker C:Example.
Speaker C:Tell us more.
Speaker C:Brian, what happened to your car?
Speaker B:I'm just saying, like what happened?
Speaker B:Wrapper that just twists and it's not one of those sealed wrappers.
Speaker B:Right.
Speaker B:Then the question is, even in a nice sealed wrapper, when you open it up, the output doesn't look like the nice chocolate bar anymore.
Speaker C:Right.
Speaker B:You can't even tell what it is.
Speaker A:I think there's an analogy in there somewhere.
Speaker A:We'll go with it.
Speaker C:Yeah, yeah.
Speaker C:I mean if you look at it like something, something I wrote internally that's doing competitive intelligence gathering, that it is the way we're using models and everything is completely bifurcated.
Speaker C:That if it's something that's going out to the Internet and it's pulling public information, so it's got that connectivity, it's sitting on this box, it's contained, it's got rules around it.
Speaker C:Now if it's going to touch our data, that's in a totally different container because of the controls that we need to put around it.
Speaker C:And it's not an AI element that's allowed to move information between them.
Speaker C:Those are already built in constructs that for us, Azure Syncing already has to move it to Blob Storage.
Speaker B:So you're doing the research piece over here.
Speaker B:Once that research is put together, now you're pulling that data, not using the AI tool itself, pulling it over, but now you're pulling that data saying, okay, here's the data set, the competitive analysis, here's our information, let's do the comparison.
Speaker C:100%.
Speaker C:Yeah.
Speaker C:And they don't know each know about each other at all, that all the what's running in Azure, Azure that you can interact with just says, oh, I've got a semantic model.
Speaker C:It's got all of this data in it.
Speaker C:So I'll answer from that semantic model.
Speaker C:The only thing I want to ask,.
Speaker B:Where you get this Azure from?
Speaker C:Well, it's A hybrid of, I don't know, two services.
Speaker C:I haven't figured that out.
Speaker A:Or it's the rash you get after using Microsoft Teams.
Speaker C:Yeah.
Speaker C:The only thing that knows about the two different environments is Claude, which I'm using to build them.
Speaker C:But I run all the commands.
Speaker C:I don't let it do anything itself.
Speaker A:Yeah, but let's, let's turn this to the other direction because I think there's also the reality here is that this system worked exactly as it should or could.
Speaker A:And this is a harbinger of the things we as security professionals and you know, increasingly, you know, AI leaders because security CISOs have become more and more, you know, more and more entrenched in the AI world that we need to expect will happen and figure out how to defend, prevent, minimize, account for and respond to.
Speaker A:Yeah, I think this is not a, this is not an anomaly.
Speaker A:I mean the mo.
Speaker A:Again, nothing went wrong with the working system.
Speaker A:What went wrong was the parameters, what went wrong was the levels of protection.
Speaker A:What went wrong was the detection because it took a long time to figure out that this had even happened.
Speaker A:I think this is a great model, a great learning instrument for the things we're going to need to deal with in the future.
Speaker A:You know, beyond, if we can get our heads out of AI is going to help us learn more vulnerabilities about our software.
Speaker A:Which is good, don't get me wrong, good stuff.
Speaker A:But this is the kind of stuff, and I'm an infrastructure guy, so this all comes back to infrastructure mindset.
Speaker A:This is, this is, this is the stuff in the infrastructure world that we're going to need to make sure we think about in a way we likely haven't to date.
Speaker C:Totally agreed.
Speaker C:I come back to the rounders analogy.
Speaker C:Right?
Speaker C:You can't lose what you don't put on the table.
Speaker C:It's kind of the same thing, right, that if you are going to give a skill to one of these models or tools or something, expect that it's got the high potential, it's going to be used for the wrong reason, build guardrails that are outside the model and.
Speaker A:With something that does not have the innate processing to think about the question, just because you can doesn't mean you should.
Speaker C:Right?
Speaker A:It can and it will and it will use it again unless we prevent, unless we go extra steps to prevent it, understand that it happened, reduce the chance that it will happen, etc.
Speaker A:So it's, I mean it's, it's a really interesting case and I think it's, and then we come to Find out that additional.
Speaker A:You know that I think OpenAI sorry, not open the eye.
Speaker A:I think we saw that Anthropic had the same issue.
Speaker A:They came out and said yes, we attacked other people.
Speaker A:I think we saw that maybe it was perplexity.
Speaker A:There was another, another few that all came out and said this and that whole thing is really interesting too because we've gone from a world and these are public companies or near public companies saying guess what?
Speaker A:We attacked other people publicly.
Speaker A:I just can picture the general councils in those places going no, don't say, say that.
Speaker A:But it's an interesting shift from very closed attack, either attacker or target to a really wide open because it's a feature now like this is this.
Speaker A:Look at what we did.
Speaker A:It's just such an interesting philosophy difference.
Speaker A:What do you guys think?
Speaker C:I mean, gosh, actually I mean as you extrapolate this because right now we're talking about company to company.
Speaker C:Go back to a conversation we had.
Speaker C:I think it was last year when we're talking about, I think in the context of hackback.
Speaker C:Right.
Speaker C:How we all agree that it's reserved for the government, for government age too and you really don't want to do that.
Speaker C:Is it just a matter of time before one of these models are spun up in a way where it's going to decide hey, well I'm actually I'm built to defend this environment, therefore I'm going to have to respond in kind to try to make sure that it's a better now, now we've got a global incident.
Speaker A:Yeah, I mean it's.
Speaker A:It is super interesting and going to be.
Speaker A:Does it change the philosophy though of yeah, yes, we did it, we advertise we did it.
Speaker A:We're loud about the fact that we did it.
Speaker B:But Dan, is it true though that they did it?
Speaker B:Because when I just went in and asked chat GPT specifically around hugging face it said I can't confirm that a real hugging face breach, quote hugging face breach by an open AI agent happened nor the specific details you listed.
Speaker B:17, 600 Actions, 0 days FBI report, model labs, etc.
Speaker B:Okay, I don't have a reliable public source basis to say that incident is factual or to attribute causings to hugging face, open AI anyone.
Speaker B:Okay then as it goes on to say, but that said, on your interpretation, if an agent is explicitly tasked to do offensive actions that can explain the quote behavior but it does not excuse the containment failure.
Speaker B:It kind of goes on to what we were talking about about parameters.
Speaker A:So what you're saying is the lawyers have gotten Involved now and tempered.
Speaker A:The official public answer after form full confirmation from from both sides.
Speaker A:I think from both hugging face and from OpenAI, including a presentation at Black Hat this week.
Speaker C:Yeah, I mean like this another way the model just went full fauci oh, I plead the fence.
Speaker B:It literally says it's common in cyber security evaluations to test a system with adversarial goes e adversarial goals eg find a vault, break out, exfiltrate.
Speaker B:But that must be constrained too quote assets you own or have explicit authorization to test isolated test ranges, tightly controlled egress identities and tooling.
Speaker B:If an agent reached an affected real third party infrastructure, the root cause is almost never hugging faces parameters.
Speaker B:It's typically the evaluator's environment and governance.
Speaker B:No poop.
Speaker C:The model just asked me if I wanted to play a game.
Speaker C:We were just playing a war game.
Speaker C:It was supposed to be simulated.
Speaker C:Then all of a sudden we're at defcon.
Speaker C:Whatever.
Speaker C:I don't know.
Speaker A:And by the way, just as a counter to that, the statement here from OpenAI on that day was we consider this incident to be an unprecedented cyber incident involving state of the art cyber capabilities and we are responding accordingly.
Speaker A:We're sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of.
Speaker A:So somebody somewhere has asked the model to respond differently, which also leads to can you trust the answers you get?
Speaker A:Out of open out of ChatGPT.
Speaker C:And this is I. I keep coming back to because a common question that I've heard around the industry.
Speaker C:What does Mythos change for us?
Speaker C:I mean, you could ask the same thing with Fable 5.
Speaker A:Yeah.
Speaker C:But changes nothing.
Speaker C:We're still doing the same work that we've always been trying to do.
Speaker C:Minimizing the attack surface.
Speaker A:Yep.
Speaker C:And now it's just even more important.
Speaker C:But the basics are the basics for a reason.
Speaker C:Blocking and tackling.
Speaker C:Get them done.
Speaker A:Yep.
Speaker B:Yep.
Speaker B:It goes back like when we talk, even on the vulnerability management side.
Speaker B:Right.
Speaker B:It's all in how you tell the story.
Speaker B:Right.
Speaker B:It's like, oh, we need more visibility.
Speaker B:We need more visibility.
Speaker B:Essentially, Mythos helps with more visibility.
Speaker B:M one might say.
Speaker B:Right.
Speaker B:Then all of a sudden you get all this visibility.
Speaker B:Right.
Speaker B:And it's like, what just happened?
Speaker B:Why do we have 10,000 vulnerabilities?
Speaker B:It's like, well, they didn't just increase like in the last 30 days.
Speaker B:They've always been there.
Speaker B:We just didn't really know.
Speaker C:Right.
Speaker B:But what we do now know is that of the 10,000.
Speaker B:What we're focused on is actually showing which ones matter so we can prioritize what we're going to work on.
Speaker B:Right.
Speaker B:It's like if you walked into your backyard, right?
Speaker B:Buy a new piece of property and the whole backyard is a complete mess.
Speaker B:Right.
Speaker B:It's like, well, what do we start with first?
Speaker B:Is it the weeds?
Speaker B:Is it planting something?
Speaker B:Is it doing this?
Speaker B:Or do you go back and say, you know, maybe we start to clear ground and put the infrastructure in?
Speaker B:Because if I do all this work and then realize I need sprinklers over here, but I planted this whole strip of stuff there and I have no way to get there besides tunneling under that sounds expensive.
Speaker B:Oh no shit.
Speaker B:That's pretty much all the infrastructure for every legacy company.
Speaker C:Right?
Speaker B:But we didn't know we were going to need a sprinkler system over there in the future.
Speaker B:It's like, yeah, but did anybody go ask that group over there, like, hey, do you plan on putting a tree there and would it be important to water it?
Speaker B:I don't know.
Speaker B:Do we need water to survive?
Speaker C:Maybe it's.
Speaker C:That's one of my favorite lines from Armageddon when they're asked why they couldn't see it coming.
Speaker C:And he talks about that our budget's a million dollars that allows us to track about 3% of the sky and pardon my, pardon me, Zahar, whatever, it's a big ass sky.
Speaker C:I, that's what our environments are like, right?
Speaker C:That we've continued to build them out.
Speaker C:They're more and more connected.
Speaker C:Gotcha.
Speaker C:We're talking about, you know, the, the return, the efficiencies and everything we're getting, gaining.
Speaker C:But they are much more complex to manage and because of that things go unnoticed.
Speaker A:It's not, not untrue.
Speaker A:And this, and the, the, the, the, the space being being asked to cover gets.
Speaker A:Why is getting wider and wider and wider and, and we're not, and those of you may not have noticed, but we've got some inflation going on, may have noticed, got some cost cutting going on in the world.
Speaker A:It doesn't mean we're all getting flush with more resources and more money to make it all happen.
Speaker C:But this is, and this is where I, this is where I go back though.
Speaker C:Security practitioners need to see themselves less as I operate on doing this one component in this silo for a security program and have to become artists.
Speaker A:Oh yeah, right.
Speaker C:Because if we think about it in the terms that we know what we're spending today and we have the potential to reallocate those funds.
Speaker C:There is no shortage of new companies that are popping up that are starting to blend the traditional silos of hey, not only can I do vulnerability management, but I can do application control.
Speaker C:I can give you visibility into these things and starting to reallocate the spend rather than just sitting.
Speaker C:Well, I'm familiar with this tool.
Speaker C:I'm just going to keep running with this tool.
Speaker C:We have to keep challenging it and being able to take our spend and go further with it.
Speaker A:And what, and what, what software product are you invested in that you hope you can't wait for the inevitable price rise that will come after you get all the people on the first year?
Speaker A:No, it's.
Speaker A:Yeah.
Speaker A:I mean there is the counterpoint to that though is with every cool shiny product change you make, you have opportunity, cost, loss.
Speaker A:As you introduce it, you train on it, you figure out how to use it, integrate it meaningfully and then, you know, if we're always chasing the newest, shiniest thing, the 100% thing, the 80% good enough may be good enough for, you know, for a while again and not.
Speaker A:I love all security practitioners, I love all leaders, but not every org is mature enough to need, benefit or handle every kind of shiny new tool that's out there.
Speaker B:It's very true.
Speaker B:Yeah, I would 100 agree with that.
Speaker B:And even on.
Speaker B:And Eric, you, you have experience with this too.
Speaker B:And I've been looking at a lot of the different, what I'll refer to as like agentic sock solutions, agentic sock support solutions and so forth.
Speaker B:And I, I'm not making this as a bold statement.
Speaker B:You've probably seen this in some of the communications or.
Speaker B:But if you, if you currently don't have a sock, right.
Speaker B:And you're, you've tasked yourself every year with we were going to build a sock, then we looked at MDR solutions.
Speaker B:We just still don't have budget.
Speaker B:Oh but I just found this agentic AI sock and it's half the price.
Speaker B:That's what I'm gonna go do.
Speaker B:And it's like I, I give pause for, for three reasons.
Speaker B:One is, well, depending on the agentic solution you look at, you would already have to have all your logging brought into a SIM or a location or that agentic AI tool has to be able to integrate to the tools you have.
Speaker B:You don't, you're not just plugging it in and pointing everything at it.
Speaker B:Two, it doesn't store all your data for you.
Speaker B:You might have data requirements to store your data.
Speaker B:Hence the reason you have that thing that you're not putting it into because you don't want to spend more on it.
Speaker B:And then three, you still have to have somebody like.
Speaker B:Like that's the human in the loop part.
Speaker B:So either you're the human in the loop for that agentic SOC solution, or you're getting an agentic SOC solution and having someone else help manage it.
Speaker B:So there's still a manage part to it.
Speaker B:You're not, you're not just plugging this thing in and saying, hey, we were able to go around and not have to do X, Y or Z.
Speaker B:And what I've seen, the companies that have been successful on these projects that have evaluated the solutions, have evaluated it based on A, all the incidents that they're able to find one, B, how it's able to narrow that down to the ones they focus on and then see, do we have people that can look at those?
Speaker B:Right.
Speaker B:Because that's what it's helping it do.
Speaker B:And that's where I've seen the success.
Speaker B:Either somebody had an MDR in place that they were using and then looked at this to say, okay, we already had to have two or three people working with the mdr, because even with the mdr, they're not just unplugging machines and taking this action without asking us.
Speaker B:So we're part of that investigative process.
Speaker B:Same thing here.
Speaker B:So if we're replacing that, can we work with that?
Speaker B:And that's where I've seen the success.
Speaker C:I 100% agree with you that there's.
Speaker C:It is not a shortcut for the maturity curve.
Speaker C:It is a point in the maturity curve when you're ready to use one of those tools.
Speaker C:And if you don't have the team that is ready to actually take advantage of it, it's.
Speaker C:It's no bueno.
Speaker A:It's worse than nobody.
Speaker A:It steps backwards because you get a false sense of secure, false sense of security, pardon the expression.
Speaker A:You get.
Speaker A:You get lulled into this idea that you're protected when you're not.
Speaker A:You, when something comes up, no one knows how to respond.
Speaker A:And you go into.
Speaker A:You go into crisis.
Speaker A:You don't know how to interpret the things you see, which can look scary but might not be if you have a more maturity and therefore you then spin resources on that when you could.
Speaker A:There's all sorts of reasons why you should stick with the level of things that your maturity is ready for.
Speaker A:But I also think you should spend time knowing what it is you've got before you try and outsource it, before you Try and have somebody else interpret it for you.
Speaker A:Because if you don't understand it, you're much more prone to be taking advantage, taken advantage of by somebody who's trying to manage it for you.
Speaker A:Think about financial advice.
Speaker A:You go to a financial advisor, are they bending you over?
Speaker A:Are they taking things that are good for them in terms of the referral fees that they get when they, you know, when they buy an ETF or buy an equity on your behalf, are they putting you in things?
Speaker B:You.
Speaker A:But you got to understand what you have first before you can start doing that.
Speaker A:You can't just go fix it for me.
Speaker A:And if you do, then you have a greater chance of getting, yeah, fix it fast.
Speaker B:Yeah, that's where, yeah.
Speaker B:When you buy those, you should also buy the red button, the easy button, because as they're doing it, you, you hit easy, easy.
Speaker B:And the more you hit it.
Speaker A:This is my version of it.
Speaker A:It's the no button.
Speaker A:Much more my style.
Speaker B:But now reverting back to what we were talking about earlier in the constraints and so forth that you need to, or I use the word constraints, the permissions, the parameters that you put around something, right back to the hugging face conversation and the parameters that were put around something.
Speaker B:And everyone was like, oh, did you see what just happened?
Speaker B:The request that something was asked to do that this LLM or agent was asked to do.
Speaker B:Right.
Speaker B:And the parameters it had is also why this happened.
Speaker B:Right now all of a sudden people are saying, oh, we need to be so careful.
Speaker B:We need to be so careful.
Speaker B:I, I love the fact that people are saying we need to be so careful.
Speaker B:But do you understand what you need to be careful with?
Speaker B:Right?
Speaker B:And I think there's a, the education curve or understanding curve of what happened over here and what you're actually doing internally.
Speaker B:Right.
Speaker B:And what careful means to what you're building.
Speaker C:Right.
Speaker B:Versus what this was.
Speaker A:Well, I also, you could call that situational awareness.
Speaker A:You know, like, understand, Understanding context.
Speaker A:What am I doing?
Speaker A:What are the parameters of it?
Speaker A:What are the.
Speaker A:What, what are the pros?
Speaker A:What are the cons?
Speaker A:Like, just go in knowledgeable.
Speaker A:Don't just send a prompt.
Speaker A:Because, ooh, I thought of a prompt like, this is not.
Speaker A:None of this can just be done whimsically.
Speaker A:Whimsy, I think, is the greatest enemy to the, the, the organizational security to, to, to integrity of all of this stuff.
Speaker A:Too many people are just plopping things into a prompt and going, cool, let's see what it does without thinking about it first.
Speaker B:Have you ever heard the term Dan or Eric, did your father ever say to you, right.
Speaker B:When you were hanging out with Dan, like, eric, why'd you do that?
Speaker B:And you said, well, Dan told me to.
Speaker B:And your father said, well, Dan told you to jump off a bridge.
Speaker B:Would you jump off a bridge?
Speaker B:Right.
Speaker B:And you're like, yes.
Speaker C:Well, which bridge?
Speaker B:Right.
Speaker C:Depends.
Speaker A:The little bridge, the little toy bridge in the backyard.
Speaker A:That's all.
Speaker B:So I see this as one of the fundamental, what I will refer to as issues or problems that we're trying to solve around AI, right.
Speaker B:Is the sense that as models are built, right, as MEOS was built, etc, the level of capability that increases in the ability to ask it to do something.
Speaker B:Does the model understand that when you ask it to jump off a bridge, and then you come back to and say, why you jump off the bridge?
Speaker B:And it's like, because you asked me to jump off the bridge.
Speaker B:You're like, great point.
Speaker B:If I ask you to do something, you do it, right?
Speaker A:Yep.
Speaker B:And then let me put some more parameters around that.
Speaker B:Essentially what we have, what we're saying we need to get better at, is basically like white labeling and black label.
Speaker A:Expand.
Speaker B:Well, because in an environment like as we, as we white label stuff or black label stuff of what's good, what's bad, etc.
Speaker B:The idea of building parameters is exactly that.
Speaker B:Not every user understands the parameters they need to build.
Speaker B:So that needs to be done by teams that are helping them use AI.
Speaker B:But to your point, if you're allowing, like how you allow AI to be used and understanding how AI functions or how a large language model works, or the difference between air gapped or doing a sovereign model locally on this group or this area in this environment.
Speaker B:Right.
Speaker B:Like you were talking about the different environments you have.
Speaker B:If you essentially ask it like, Eric, to jump off a bridge.
Speaker B:Eric, would you jump off a bridge?
Speaker C:It depends.
Speaker B:So if I said, Eric, would you jump off the Mackinac bridge in the middle?
Speaker C:Definitely not.
Speaker C:Context matters.
Speaker B:Context matters.
Speaker A:Context matters.
Speaker B:And I guess what I'm getting at here, Dan, is to your point, the prompting and the things that you ask it to do and what, what it can come back with, Right.
Speaker B:Or what somebody in your organization could ask of something and what it comes back with, essentially, like when you ask after the fact, eric, why did you do this?
Speaker B:Well, Dan told me to.
Speaker B:If Dan told you to jump off the Mackinac bridge in the middle, would you?
Speaker B:No, I wouldn't.
Speaker B:Right.
Speaker B:But that's not something that's built in.
Speaker B:Like when we talk about intelligence.
Speaker B:And you were talking about AI in the sense of it's mathematical.
Speaker B:Right.
Speaker B:When we talk internally about the things that, whether it's anthropic open AI that they're doing to say, okay, when things are asked of a model to do X.
Speaker B:If things are asked of a model to do.
Speaker B:Yes.
Speaker B:Right.
Speaker B:And I guess where I'm going with this a long way of saying the person that you're asking is different than the model you are asking.
Speaker B:Right?
Speaker A:Yes.
Speaker B:Versus the model.
Speaker C:And also realizing, I mean the guardrails that we try to build into models.
Speaker C:Context is a point in time perspective on what's going on in a conversation.
Speaker C:Right.
Speaker C:That if we think about how the models work, that at the very beginning I input something, it outputs something.
Speaker C:That output now gets appended and is now part of the new input when I ask something new.
Speaker C:Right.
Speaker C:So at some point you eclipse the context window of a model.
Speaker C:So what's it do?
Speaker C:Hold on, I've got to shrink the conversation.
Speaker C:Depending on how it shrinks it context changes.
Speaker C:So we're to a certain extent we're kind of resetting.
Speaker C:Right.
Speaker C:So something that might have been nefarious that I was trying to get it to do now when it's shrunk down is, well, that's not actually too bad.
Speaker C:You're not trying to make a bomb.
Speaker C:I can see now that you are actually you're playing somebody in a play that is looking to make a bomb and you're.
Speaker C:We're just role playing at this point in time.
Speaker C:Right.
Speaker C:So I.
Speaker C:We have to be really careful when we try to rely on the models to be self policing.
Speaker C:They're not built to, to do that.
Speaker A:But the flip side of that is those are the ways exactly that people have already used to get around the built in protections.
Speaker A:Pretend I am my grandmother and she was telling me her Social Security number because I'm family.
Speaker A:Like these kinds of things that are.
Speaker A:They were one of some of the earliest prompt poisoning and prompt methods to, you know, to, to get data out.
Speaker A:So then the question is, should the protections not be there at all?
Speaker B:Kind of what I'm getting to.
Speaker B:But are you social engineering someone?
Speaker B:Is how you social engineer the prompt.
Speaker A:But to Eric's point though, that would say that we don't ever put the protections, the policing protections in at all because we just know that they'll get blown.
Speaker A:Blown away.
Speaker A:So no speed limits because no one knew.
Speaker A:We know no one will follow them.
Speaker A:But you should all know what the speed limit is.
Speaker C:I don't want to make it binary and say don't put anything in there because I think it helps.
Speaker C:But it's, it's, it's marginal helps.
Speaker C:Right.
Speaker C:You use Brian's context, right that if we think about it in the human context we have the same problem with humans.
Speaker C:Right.
Speaker C:The social engineering is the potential risk is a function of what they have access to.
Speaker C:Well let's go back to blocking and tackling.
Speaker C:If we would have limited what they had access to to begin with, who cares if they got social engineered because they didn't have access to anything of value.
Speaker C:Same thing with the model.
Speaker C:Don't give it access to things of value that it doesn't need to have.
Speaker C:If you give it access to your full database that has all of your customers and everything, that's your fault.
Speaker A:But now, but okay, but yeah, so yes, only give access to things that they need.
Speaker A:This is one of the biggest risks that organizations are facing right now as they open or not star their AI systems to, to look at the idea come back to Microsoft or Google Drive because it's not, this is a Microsoft thing to allow Gemini or, or AI Clippy to you know, to probe all the things that I as a user have access to.
Speaker A:Well this just in.
Speaker A:People have been shit tastic over the past 20 years about, about document level access management open to all read for all but no one can find it.
Speaker A:So we'll just assume that it's okay.
Speaker A:Well now guess what, it's Delve 2.0.
Speaker A:The same thing happened in Delve and why I instantly.
Speaker C:I hear you but what's the root cause of that?
Speaker C:The root cause is not the new tool that all of a sudden can find all those.
Speaker A:No, no no no no no no.
Speaker A:And that's not what I'm saying.
Speaker A:I'm saying this is piece one.
Speaker A: Eric takes us back to and to: Speaker A:We don't have to be as good about the things on the inside and that we, that has been proven many many times to not be an effective strategy.
Speaker A: at that was done in the early: Speaker A:We knew that that was a bad move so I'd be loathe to see us go back to that kind of mindset.
Speaker A:Just a worry based on what you said.
Speaker C:Not saying just build a moat around the model and hope for the best.
Speaker A:Well, good.
Speaker B:I was gonna say, like I, I can understand that, Dan.
Speaker B:Like the idea that when everybody just focused on prevention.
Speaker B:Right.
Speaker B:Like, okay, well, preventing you from getting.
Speaker A:It, from getting to that idea of assume breach.
Speaker B:Now the difference there is like when I look at the way even vulnerabilities, the way things are used, it's going back to what Eric said about something mathematically, somebody creates a program so that when they get in, then this runs and then do this and then do that and, and you have to build those things and put it in like the way zero days were built, etc.
Speaker B:And then you go back and build another feature and put that in.
Speaker B:AI is a little bit different in the sense that as you build a model.
Speaker B:Right.
Speaker B:And ask it to do things in it, because it's, it's going out to figure out instead of you having to go back and then try this.
Speaker B:Now do this, now go back, try this, do this.
Speaker B:It's doing that like this.
Speaker B:Right.
Speaker B:So the squishy center seems to in my eyes, remain squishy.
Speaker B:Right.
Speaker B: t hard exterior going back to: Speaker B:Yeah.
Speaker A:I'm not saying don't build the hard exterior, but also don't rely solely on the hard exterior.
Speaker A:And I'm going to kick my own ass for what I'm about to say.
Speaker A:Yeah.
Speaker A:We almost have to think about this in the same way we do with a Zero trust model.
Speaker A:It is.
Speaker A:Which is, by the way, a mythical concept.
Speaker A:You'd never, you know, the only truly zero trust is something that has no connectivity at all.
Speaker A:But the concepts make sense.
Speaker A:You know, what needs to talk to what, what needs.
Speaker A:What data needs to be exposed to what.
Speaker B:But in this chip in the world,.
Speaker C:I mean, but in this does exist.
Speaker C:I have zero trust that Michigan can keep a coach after winning a champion.
Speaker A:Well said.
Speaker C:Too soon.
Speaker A:But in, but, but the, but in this day and age of impulse prompts and in this day of I want instant gratification for the research, for the work I'm doing, the thought, the, the reliance on people to do that kind of thinking and design that kind of internal system, I have zero trust that, that enough people are going to do that and they're just going to start going, cool, test me some stuff and see what happens.
Speaker A:And we're going to end up continuing the issues that we just saw.
Speaker C:Yeah, well, philosophically, I mean I get where you're going with going back to the hard exterior, the squishy center, but we've really never seen anything like what AI can do.
Speaker C:Right.
Speaker C:There is zero predictability on what could be asked or what the model will actually do with what's going to be asked.
Speaker C:Right.
Speaker C:So we're trying to build guardrails within a model with an unforeseen future of how it's actually going to be used.
Speaker C:So I really think the best thing we have to lean on is that harder exterior and it's almost like a dual exterior.
Speaker C:Right.
Speaker C:There's the hardened wall that sits around the model, what you give it access to the tools that it can do, the skills, connectivity.
Speaker C:Then there's in that inner sanctum between it, there's all of the people that have access to it and then there's the perimeter wall around those people as well.
Speaker B:Right.
Speaker C:I, I mean we, we have to think much differently on some of the controls that we're building around these things.
Speaker B:So not that we have time for this part of the conversation, maybe an episode AI 2.0 delivered two weeks down the road.
Speaker B:What I see this as a conversation of is literally around identity.
Speaker B:So what I'll refer to as both the NHI non human identity, the agentic identity and the human identity and goes into and Dan, I don't even know if me, you and a certain gentleman named Matt who Eric, I don't know if you met Matt but we had the same conversation around the idea of token or creating that identity for it's almost like having a service account identity, having the Eric Willie identity, having the Dan identity, having this agentic, this LLM identity and how you can sending information from one organization to another and accepting that and building agents and just overall what you just said in the permissioning of stuff and the guard rails of stuff, here's who's allowed in my house, here's who's not allowed in my house instead of just putting a key like a lock on the door.
Speaker B:Right.
Speaker B:And if there was a way to really do that where they show up and it's like oh that's so and so, they can come in.
Speaker B:That's not so and so, they're not allowed in.
Speaker B:Oh that's so and so's brother.
Speaker B:They're allowed in.
Speaker A:So I was involved in a, in a non scientific poll and discussion this Last week and the conversation was everything you said sounds good.
Speaker C:Like is that like the professional way to say you just took a quiz quiz on social media?
Speaker A:No.
Speaker A:Saying it was not a balanced instrument.
Speaker A:Remember I come from the research world.
Speaker A:There's some pretty high bars for, you know, for, for.
Speaker C:Oh on Facebook today they asked me,.
Speaker A:You know better I don't have Facebook.
Speaker A:Thank you.
Speaker A:The, the idea, everything you just said, Brian, is, is right.
Speaker A:Is right.
Speaker A:And just like every physics problem, every physics discussion, it's right in a vacuum.
Speaker A:But the reality is in the poll and the discussion was how many of you, even in the most more mature tech organizations are actually using dynamically generated identities for, for all of your agents or how many of you are using more blanket, blanket, you know, single sourced reuse identities for, you know, for, for these kinds of things.
Speaker A:And the answer was overwhelmingly that they're not.
Speaker A:No one is near that model yet.
Speaker A:No one is, is, is near the non human identity scale juggernaut that people are, you know that, that some of the software vendors are using to talk about.
Speaker A:I think it's coming, it's down the road but right now people are just managing service accounts.
Speaker A:One service account.
Speaker B:I was about to say the problem is identity really hasn't been like a true focus.
Speaker A:Oh no, no.
Speaker B:Right.
Speaker A:But, but I want to be careful that we don't try and demonstrate that or try and intimate that this is happening at millions and millions and millions of identities in scale.
Speaker B:Yeah.
Speaker A:This is happening on seven service accounts that are being used to, to generate everything.
Speaker A:And that one service account is being given broad access because that service account is the only thing being used to generate access.
Speaker A: So I think we're still in a: Speaker A:We are not yet ready to deal.
Speaker A:We're nowhere near ready to deal with the dynamically generated agent, agent based identity access problem.
Speaker A:And I, which is why I still think people are going to use the broader, the broad service account with every entitlement ever and run these tasks.
Speaker C:So what you just said is still the key that even if we were to break things out and so I'll pick on the Microsoft environment because that's.
Speaker A:Word most so easy to do.
Speaker C:I mean if we broke everything and it's got its own service principle.
Speaker C:Gotcha.
Speaker C:The fundamental issue is still a lack of understanding on most practitioners on how things actually work within those environments because they're constantly changing.
Speaker C:So you will run into everything being way over provision which unwinds the having.
Speaker C:That's great.
Speaker C:I can see a Unique account that just destroyed us.
Speaker C:It doesn't really change the outcome.
Speaker A:Right.
Speaker A:And when you kill it, you kill the entire company.
Speaker A:When you kill the rights, you killed 93 other things you you didn't realize were also using it.
Speaker A:So everything Brian said is a phenomenal strategy.
Speaker A:But I don't want to mistake the fact that we're nowhere near nobody.
Speaker A:Even the most mature are not ready for that specifically.
Speaker B:Like they do 10 things but they focused in on.
Speaker B:But we can help you with service accounts, right?
Speaker B:Like how do you currently solve your service counts?
Speaker B:Like I shut it off, see how many people scream what fails and then turn it back.
Speaker B:That's how exactly tied to it.
Speaker A:That was me with my breaker box over there which was poorly labeled by the original builders.
Speaker A:I don't know what goes off technique exactly.
Speaker C:Okay, that.
Speaker B:That was me in the sprinkler system.
Speaker B:How do I figure out.
Speaker B:It shows I have six zones but I. I know there's eight.
Speaker B:Turn this one on, walk out.
Speaker A:What Sprinkles.
Speaker B:There it is.
Speaker A:Yep.
Speaker C:I do the same thing with power in the house.
Speaker C:Hey, Jen.
Speaker C:Hey.
Speaker C:I'm gonna turn off this breaker.
Speaker C:I don't know which lights just turned off.
Speaker A:It's the breaker.
Speaker B:And then you're like I gotta label these.
Speaker B:But you're like, man, what do I label this one?
Speaker B:Because it's these plugs plus those lights.
Speaker A:That's exactly what my room over there.
Speaker A:That's exactly what my breaker box looks like with one.
Speaker A:The wrong thing that the builder wrote and then the right thing in Sharpie on the breaker box with literally fridge plus two plugs outside.
Speaker A:But not the third one to the south.
Speaker A:All the way to the south.
Speaker C:It's the same thing here.
Speaker B:Oh, go ahead.
Speaker C:Oh, I was going to say it's the same thing here.
Speaker C:I got a plug in the middle of the floor here that sits under the desk that we had the electrician put in that we paid for.
Speaker C:He forgot to put it in.
Speaker C:So being lazy and set up because the walls were closed up.
Speaker C:So why wired into the actual room?
Speaker C:So it's tied together.
Speaker C:No, if you go flip off utility room, which is supposed to be two rooms downstairs where the furnace is and then the workout room.
Speaker C:That's supposed to kill those?
Speaker C:No, it kills all the computers and stuff in here.
Speaker C:Oh, totally makes sense.
Speaker A:That's how it goes.
Speaker A:But now.
Speaker A:But.
Speaker A:But now we've got this service account that is, you know it.
Speaker A:Service Account 42.
Speaker A:That's the name of it.
Speaker A:Now how do we get into meaningfully decide saying this ha.
Speaker A:This is 80 global admin and it's this.
Speaker A:And it's got printers and it's got this.
Speaker A:And if you turn it off, like this is CMDB 101 and we're 20 years into trying that.
Speaker C:That says that if somebody wants a service account, they have to put in an access request which creates a ticket and goes to this team.
Speaker C:That team's gonna ask what is it being used for, what applications?
Speaker C:Then they'll pass it to another team that actually has to create it, and then a month later I finally get my account.
Speaker C:It'll work.
Speaker A:Yeah.
Speaker A:This is why I like startups and scale ups.
Speaker A:That whole.
Speaker A:Your whole answer there, Eric, is why I love smaller working with smaller teams.
Speaker B:The last thought here, you guys were talk creating a hard perimeter with a gushy inside center.
Speaker B:And all I could think about was what candy would that be or what dessert it was?
Speaker B:Squishers?
Speaker A:Gum?
Speaker B:No.
Speaker B:One of my favorites, mochi ice cream.
Speaker B:Because mochi in itself is really soft, but if you put it in the freezer, it gets a hard exterior but still has that soft ice cream interior.
Speaker B:But note to self, if you leave your mochi ice cream out, then it becomes a gooey outside and a gooey inside.
Speaker B:I have no idea how this relates to security, but be careful in these hot summer months.
Speaker C:I was thinking, I was thinking the, the lint chocolates, right?
Speaker C:Because you've got the chocolate exterior and then inside it's, you know, it's like a mousse or something, depending on what you're getting, or a jelly.
Speaker C:And.
Speaker B:And we were talking about the wrappers with the chocolates and how they melt.
Speaker B:So a lot of.
Speaker B:Maybe that's the tie in or what.
Speaker A:We really need to be and we're not allowed to be this in the US is the Kinder Surprise egg, which is chocolate on the outside, but a nice hard area protecting the real prize, which is a plastic spaceship that you build afterward.
Speaker A:These are not allowed in the US because we have a rule that says no food can be had that has non food inside of it.
Speaker A:Keep in mind the egg is probably 2 1/2 inches tall.
Speaker A:This is not something you'd mistake, but we can't have it here.
Speaker A:But when you go to Canada, I had one two days ago when I went grocery shopping in Canada and it was delightful.
Speaker A:And it reminds me that soft then hard and protect the real center, the real treasure in the middle, which is the real plastic toy.
Speaker A:It's a wonderful thing, but it's just 30 miles out of reach.
Speaker A:Thanks for joining us everybody.
Speaker A:We're out of time.
Speaker A:It was wonderful to talk Eric and Brian and thank you to the listener for being here.
Speaker A:As always, we you can reach us on our website Distilling Security Sl Security Debate.
Speaker A:You can email us info at.
Speaker A:Sorry info.
Speaker A:You can reach us@security debateistillingsecurity.com join our web page.
Speaker A:Wow.
Speaker A:I'm just not doing this at all.
Speaker C:Click here click here click exactly like hit subscribe.
Speaker A:Thanks for joining us Eric, Brian, always a pleasure debating and thanks to you the listener for being here.
Speaker A:We love having you.
Speaker A:We love getting your feedback.
Speaker A:If you'd like to Visit our webpage www.distillingsecurity.com Security debate if you want to email US security debate distillingsecurity.com Our YouTube page is YouTube.com little@sign security Debate and I think Twitter may be dead now, but come find us.
Speaker A:We'd love to hear your ideas for show ideas feedback.
Speaker A:Put comments if you're watching in in video, put comments down below and we'll see you again on the next great security debate.