
Enterprise Security Weekly · 2026-06-29 · 1h 41m
Adriel Desautels from Netraguard joins Adrian Sanabria and Tyler Shields to dissect the fundamental problems plaguing penetration testing as an industry. The core issue: compliance-focused pen testing creates a false sense of security by delivering vulnerability inventories rather than threat-led assessments that simulate real attack paths. Desautels argues that PCI compliance in 2003 - 2004 inadvertently commoditized pen testing, enabling vendors like Nessus to flood the market with checkbox assessments priced per IP address, divorcing testing from actual threat actor behavior. The conversation contrasts the "compliance industry" (90% of engagements) with genuine penetration testing, where knowledge transfer, kill chain analysis, and purple team collaboration deliver real defensibility. Both Desautels and Sanabria reference Haroon Mir's "Pen Testing Considered Harmful" (2011) thesis - that pen testers emulate other pen testers, not attackers - showing how ransomware crews later adopted pen test methodology because organizations failed to act on findings. The episode closes with skepticism toward AI-driven pen testing automation, positioning it as fundamentally misaligned with threat-realistic assessment.
Compliance-focused testing delivers a vulnerability inventory to satisfy regulations (like PCI) but establishes false security. Threat-led testing emulates actual threat actors by mapping the kill chain - how attackers got in, why it was possible, and behavioral patterns - enabling organizations to build defenses rather than just patch vulnerabilities.
PCI created a regulatory requirement for pen testing without defining threat levels or standards, enabling any vendor running Nessus to market themselves as pen testers. This triggered a race-to-the-bottom pricing model priced per IP, divorcing testing from actual complexity and enabling checkbox compliance over genuine security improvement.
Ask how the vendor calculated the cost and can they justify the workload. Real pen tests price based on complexity and understanding your environment; checkbox assessments use flat rates per IP or endpoint, which cannot account for varying service complexity and typically indicate low-value compliance work.
Purple teaming involves collaborative, ongoing work between testers and the organization's security team throughout the engagement, compressing months of threat intelligence gathering into real-time knowledge transfer. Traditional pen testing ends with a report; purple teaming uses findings as the starting point for remediation and defense building.
AI hallucinates and lacks comprehension, making it unsuitable for threat-realistic assessment; it may automate vulnerability scanning but cannot replicate the behavioral intelligence and adaptive thinking required to simulate actual threat actor TTPs and deliver actionable defense strategy.
Computed from the transcript - who did the talking, and the words that came up most.
Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: Topic: Why Meta is destroying its engineering organization The titular essay: A very interesting analysis of what's going on inside big tech companies as they try to dogfood their own AI hype and tokenmaxx themselves into oblivion. There have been a LOT of stories on this, but this is the most comprehensive and enlightening. A few more are linked below. This is relevant to security, because heavier AI use appears to be linked to a much higher occurrence of availability and security issues.
Transcribed and scored by The B2B Podcast Index.
Speaker A: This week, Adriel Desotels from Netraguard is with us to discuss the state of pen testing and AI. Then in this week's topic segment, we discuss why Meta is destroying its engineering organization. And finally, in the Enterprise security news, an AI vibe check. An AI SoC vendor shuts down. Cybersecurity vendor layoffs, funding and acquisitions, Cascading breaches, Digital estate management. Criminals don't trust AI either. Some devs won't code without AI even if you pay them to. And Midjourney is now a healthcare company. All that and more on this episode of Enterprise Security Weekly.
Speaker B: Mhm.
Speaker A: It's the show where we talk security vendors and aren't afraid to name names. It's Enterprise Security Weekly. Welcome to Enterprise Security Weekly and Happy National Waffle Iron Day. This is episode 465 and will be released on Monday, June 29, 2026. I'm your host, Adrian Sanabria, and joining me is the master of marketing, the mayor of mayhem, Tyler Shields. How you doing, Tyler?
Speaker C: Good, good. I have a question for you. Do you prefer waffles or pancakes?
Speaker B: Waffles. Okay. Waffles.
Speaker C: Oh, yeah. You got waffles across the board. Okay.
Speaker A: Just, just, just more exciting like. So, uh, my, my partner urged me to ask, uh, have any of you ever cooked anything in a waffle iron that wasn't waffles?
Speaker C: I've never owned a waffle iron.
Speaker A: Really?
Speaker C: No. Right now, uh, I can imagine it makes good paninis though.
Speaker A: Yeah, right. Like you can make omelets in it. You can do all kinds of stuff. I. Same thing with a rice cooker. I've only ever cooked rice in the rice cooker. I know you can do like the full meal in the rice cooker, but I, I don't know. I don't mind getting dishes at the end.
Speaker C: At the end of the day, anything that tastes as good as a waffle and has little holes for the syrup to fill. That's a win. Yeah, that's a win.
Speaker B: Yeah.
Speaker A: See, and that's, that's why waffles are better than pancakes. Is that the little. The little cups to hold the peanut butter, the syrup, whatever you want to put on them?
Speaker C: Yeah, absolutely.
Speaker A: You nailed it. That is the value prop. That's why he is the master of marketing.
Speaker B: Right there.
Speaker C: There we go. There we go.
Speaker A: Found the value prop. All right, quick announcement, then we'll jump into our interview. Uh, security leaders, your vulnerability program is overloaded. Thousands of findings. Try millions of findings. Limited resources and no clear way to prioritize what actually matters to the business. Meanwhile, regulators and boards expect measurable risk reduction, not just scan results. Join the Vulnerability Management Virtual CyberSecurity Summit on July 29 to learn how leading organizations are shifting from volume to risk based prioritization and turning exposure into actionable strategy. Security Weekly listeners can register for free at securityweekly.com vuln management using the promo code CSS26-SW. All right. And with that we are talking about the state of penetration testing, particularly with regards to AI. We're excited to have Adriel Desotels with us today. He's the CEO and founder at Netraguard where he has done a lot of penetration testing over the past 20 years. Welcome to the show, Adriel.
Speaker B: Hey, thank you so much. I'm excited to talk about this stuff and I think it's important and we
Speaker A: have done a little work together in the past.
Speaker B: We have, we have, yeah. Monks like that and interactions through LinkedIn and share a lot of similar opinions I think on things. Yeah, yeah.
Speaker A: I, I did a pen test for you once as a uh.
Speaker B: I remember this a while. Yeah, I remember that. A long time ago. That's right. So you know our inner workings in our culture to some degree still.
Speaker A: I do, I do.
Speaker B: Yep, yep. Yeah, I've been around for a while. It's amazing. It doesn't seem like 20 years has gone by. Actually it seems like it's been about two, but uh. Hot damn.
Speaker A: Yeah, well I, I think so. I was looking at 2006 to 20. 26 should actually be 21. Right? Yeah. If, if you count both, both sixes on, on either end.
Speaker B: Yeah, that's right. Yeah. And then I mean you can go back farther and talk about the snow soft days because kind of incorporated the same philosophies in Natural Guard. That was like 1998 to present. So kind of dating myself now.
Speaker A: Yeah, yeah, yeah. It's uh. I started pen testing in, in 2008. Like, like formally started pen testing. So uh, I was doing internal pen testing at the company before that, before I uh, set out to do it contract. Um, wise. But, but yeah, so it's um. That's part of what I want to talk about today is how it's evolved over the years. Like I remember there was this very uh, memorable talk that Harun mir gave at 44 con back in, in uh, 2011, um, in London. Uh, pen testing considered harmful.
Speaker B: Right.
Speaker A: Uh, he's always been very good at uh, spicy titles, uh, spicy topics, contrary stuff. But um, but yeah, made a lot of really good points in that. And one of them was that pen testers emulate other pen testers, not attackers. You know, back in those days, um, the way you would get popped is like, like web browsers were a mess, they weren't very secure. And we, we were all using Flash and we had Java plugins and we had Shockwave and we had Silverlight and they all had vulnerabilities in them. And just like drive by infections were super common. You just visit a website and boom, you got malware. Yeah. Um, and of course no pen testers were doing that because it's like super unethical, uh, to do some of this stuff. But yeah, I find it interesting that like just six years later, the average ransomware case looked exactly like a pen test from 2011.
Speaker B: Right.
Speaker A: In fact, we suspect pen testers are engaging in some of the stuff. Like they're using the same tools as pen testers. The process is the same. So just wanted to get your thoughts on that. Is that how you remember this progressing as well? What did you think?
Speaker B: Yeah, ah, I mean, I, I look at the penetration testing industry and there's actually, there's something kind of parallels what you were talking about that I see. And it, it's really, I guess the infosec industry as a whole, right. Um, if you look at the companies that are building defensive technology, right, Stuff that actually is supposed to block attacks, their attacks work really well or, sorry, the defenses work really well against the commercial off the shelf tools because they can ingest those tools and the, the data from those tools, the attacks from those tools easily and block them. But if you work outside of the boundaries of where those tools actually exist and you launch attacks that are unknown, you bypass things. Right? So when you said pen testing is making things more vulnerable or I guess it was a quote from somebody else. Um, I agree. When you talk about things like compliance focused pen testing versus, uh, you know, realistic threat or threat led penetration testing, which I consider to be what a pen test is, Right. You should emulate a threat actor, not emulate what other pen testers do. Uh, and the reason I agree with that also is because, um, if you're doing the bare minimum required to satisfy regulations, uh, you're not doing what's required to sort of build defenses or advance defenses against real world threat actors yet people. And Greg Steinhoffel, right, Target CEO is a great example where he effectively said, hey, you know, we were just certified as being PCI compliant. We suffered a breach anyways. Right. So these pen tests do Damage by establishing a false sense of security. And I don't feel like we can blame the consumer like the buyer of these pen tests on this all the time, or maybe even most of the time, because they shouldn't have to be experts in what penetration testers do. Right. So their job becomes very difficult. Finding a real tester that'll deliver a real report that has impactful value versus something that delivers just a vulnerability inventory. Um, that's kind of a roundabout way of talking about what you mentioned, I think, but I, uh, hope it makes sense.
Speaker A: Zero trust is clearly the future as threats get faster, quieter, and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable and optimization operationally clean. Unknown software is stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. See why CISOs are adopting it@securityweekly.com ThreatLocker yeah, I mean, the thing that really kills me is that ransomware crews started doing exactly what pen testers have been doing for decades. And we've all had those pen tests, so we should have been super prepared for it. Right. You know, but everybody gets a pen test. The pen tester gets DA in like six minutes. And we're like, there it is. Check the pilot. Done.
Speaker B: Yeah.
Speaker A: Like, I don't think it's even occurring to some companies that, oh, maybe it shouldn't be super easy for the pen tester to come in and just like walk all over us.
Speaker B: Yeah. And, you know, I think that comes to, um, I think it comes to how the test is delivered after it's delivered, how the report is presented in knowledge transfer. Right.
Speaker A: Um, if the report is even presented, sometimes it just shows up in their email and nobody, they're on to the next thing.
Speaker B: Yeah. So there are a couple of things that we see. I mean, almost every new customer that comes in, every sales call is people anticipate getting that inventory of vulnerabilities. And so they don't initially take it seriously.
Speaker A: It's not a vulnerability scan.
Speaker B: Yeah. Right. So they're like, oh, we have, I mean, deprecated ssl. Come on, everybody. You know, it's like, you know, and, and what they don't, what they're not in the habit of getting is sort of, uh, the kill chain or the path to compromise. You know, this is how we got in. This is why it was possible. These are the behavioral things we had to do. And here, how you build your defenses, not how you patch vulnerabilities, but, but here, here's how you actually establish defenses within the context of your organization. And during sales calls, when we begin talking about that, you can see a shift. I mean it's almost visible in the way people hold themselves and speak between. This is going to be boring to. Wow, this is kind of exciting. Maybe we'll get something out of it. And that carries through the engagement up to the point, uh, of delivery. And we find that when we deliver the final report, um, our customers end up being really interactive. They really want the knowledge, you know, they kind of crave that. And that knowledge transfer, uh, is where the real value comes in. I mean, if you can talk to threat actors, which is exactly what we are sort of in a legitimate way. Right? So if you can talk to threat actors and pick their brains, you can use that intelligence to build defenses that are going to work. Um, so it's a huge difference between. And I do think there are two industries. I think there's the compliance industry that makes up like 90% of everything, and then there's the industry that does the real thing, you know, um, I call it the genuine penetration testing industry. Right,
Speaker A: yeah. And that's um, so I guess you need a customer that actually cares, uh, to start with, that actually wants to improve things. And then, you know, so I've seen different definitions of what uh, and we should have defined this upfront. So one of the things I found, I delivered a Talk@ uh, 2018 RSA called It's Time to kill the pen test. You know, that was again around this kind of thing of like it's not delivering very much value. Like the actual penetration testing is like this little 30 minute sliver, uh, in the middle of what? Of the paid engagement. And like there's this huge chunk of vulnerability scanning on the front end and this huge chunk of writing the report on the back end. Uh, that is the bulk of what you're paying for in this little bit in the middle where they're like, yeah, can, can you get any exploits working on the, these things that the vulnerability scan found? Yeah, so, um, so yeah, defining one of the things I found when I gave that talk, I did a survey and I found when you say penetration test, most people think of what I would call a web app assessment. They don't think like black box, ah, you know, external, uh, trying to break in to the, like the whole enterprise is in scope. Like that's not what they're Thinking when they hear this term. So sorry, I should have defined that up front.
Speaker B: So it's interesting you say that. Actually. Um, I used to spend a lot of time working on definitions and I found that there's a pretty general, uh, description. Right. So a penetration test is a test that determines whether something can make its way into or through something else. And penetration testing isn't unique to it. Security, of course. You have soil penetration testing, materials penetration testing, ballistics testing. Right. The difference between our industry though and those other industries, like if you look at ballistics testing, there are different standards, I think is V0 and V90 talks about how many strikes and they're very well defined standards. If you look at our industry, we don't have any standards that really take the threat into consideration. It's just like you have to do these specific things. So you. Yeah, okay. I can pressure test my sub. Right. In a bathtub or I can pressure test at a 3,000ft. Which one are you going to get into? Well, most people are choosing the bathtub sub and then get surprised when it implodes at 3,000ft, you know, so, so
Speaker A: the definition is definitely a little Ocean Gate reference there.
Speaker B: Hey, I was just watching say about it me. That's why it came into my mind. But, but I mean it's, you know, this is why standards and realistic standards are so important. But you're. I think you're right and I think that the definition goes even farther. Right. People think penetration test and they think zero day vulnerability research or they think exploit dev. You know, uh, they don't ever think. Well, I'm trying to determine, you know, if X can get into Y. And so this will be a web application penetration test. An external or internal infrastructure or maybe human social engineering. Right.
Speaker C: Yeah.
Speaker B: And, and social engineering doesn't just mean phishing, which a lot of companies seem
Speaker A: to think that that's what it means.
Speaker B: You know, uh, look at anything with Shiny Hunter and you know the voice call, they were crafty with calling people up and getting what they wanted. Right. Um, I think definitions are critical. Uh, and I actually think there's another point of failing for industry. I think our industry kind of bastardizes these terms and definitions. Just like they say things are solutions or they prevent all breaches. You know, definitions are important and clarity is important. You know, integrity.
Speaker A: So, yeah, so, so like what we're talking about here, like, I um, was very interested. So when I gave that it's time to kill the pen test talk, of course I recognize that, um, compliance still demands it that it's still going to exist. And I tried to build a replacement. And, uh, I never found again a common definition for red team or for purple team. But what I was suggesting, uh, did look somewhat like what some people call purple team, where a traditional pen test, like once the pen tester has all their findings, puts it in the report, that's where it ends. Whereas my understanding of how most people did purple teaming like that, that's where, uh, a lot of the work begins. Like, you're actually going to sit alongside that person. Because I found in a lot of cases, people knew, like, they weren't going to do well in a pen test before the pen tester showed up. Like, ah, they didn't need somebody to come in, slap them in the face and tell them that they sucked. They needed somebody to tell them, uh, where do we start? How do we prioritize? What should we do first? How do we fix this?
Speaker B: Yeah, so, um, I guess to touch on. Right. So for us, um, I guess we stick with traditional definitions. Right. Red teaming is sort of militaristic. It's objective driven, and the report is more of a narrative as opposed to a real report. But in terms of the purple team concept, we almost started doing that accidentally from the very beginning with the way we deal with our customers. So we make sure throughout the entire process, unless it's supposed to be, you know, a bona fide red team, where we're isolated and we're really trying to attack, you know, idir capabilities and things like that. Right. Um, we tend to work pretty closely with the team. Uh, and one of the things that we like doing is getting as much insider intelligence information as we can. And the philosophy there is because, yeah, pen tests happen over a finite period of time. Unless you're offering, you know, a continual service, which, you know, depending on how that's delivered, has some value, you know. Right. Maybe. Um, but when you, when you operate in that kind of collaborative, like, deep purple teaming method, you compress time because the threat actors are going to spend their time collecting all this intelligence about you. And it might take them months. I can just say, hey, Adrian, tell me about these things. Like, okay, here you go. All of a sudden I can build a threat that is probably more substantial than. Right. What a threat actor can do. And then we can see if you can stand up against it. And if you can't, we can help you get there. And if you can, well, that's awesome, you know, um, but I agree, purple teaming is, I think that's where the real magic sauce happens.
Speaker A: Uh, Tyler, you look very introspective. Share your thoughts.
Speaker C: Yeah, you know, it's just kind of. I, too, have been a pen tester. I did my first pen test. Uh, you guys were talking about this earlier. I did my first pen test in, I think, like, 1995 or something. Right. Like, way, way, way back. And I feel like in many cases, today's version of pen test has really drifted from what it really was intended to be, which was exercising of real life threat models. Right.
Speaker B: Yes.
Speaker C: And now it feels like oftentimes we get into a situation where it has nothing to do with real life threat models that are actively being exploited. It has to do with, you know, who can give us the best zero day. And you kind of got to this a little bit, uh, a second ago. Who can give us the best zero day or find every vulnerability or every single thing and exploit it all the way through. And it makes me both disappointed for the term pen testing. And it's, you know, uh, the travesty that it started from and what it's become. But also, you know, maybe we shouldn't even be using the term, and we should just be focused on what the goal is, which is exercising threat scenarios to determine our resilience. Right. And yeah, yeah, okay, sure. Let's. Let's trim it down to two words. Pen test. Right. But I don't know that that's kind of. That. That was my introspective luck, Adrian.
Speaker B: I think. I mean, I think you're exactly right. And I. I distinctly remember the divergence. Um, I think it was 2003 or 4 was whenever the credit card companies got together and actually established pci.
Speaker A: Pci, yeah.
Speaker B: Right. Like, I mean, sure, it was done with good intention, but the road to hell was paved with good intention. Right. What they ended up doing was they created a standard that became a requirement for all these companies, but they failed to define any level of threat. They didn't. They just said, you have to go through these things. So, you know, NESSUS became a big thing. Everybody and their grandmother could become a pen tester by running NESSUS and producing a report. Uh, and that took over because the demand for a pen test was regulated. And so now businesses, there is a need to, you know, to go out to get that check in the box. And unfortunately, a lot of them were competing on low price. And the businesses who were doing the buying, some of them very likely had the intention of buying a quality pen test. But when everybody is using the same language and the same you know, the same marking, the whole nine yards. It's really hard to tell the difference, um, unless you look at pricing. Right. So there are still two industries. But if you're going to be pricing a real penetration test, you can't do it by number of IP addresses, number of clicks, number of API endpoints. Right. You need to actually have an understanding of complexity and do diagnostics. Right. Like, 10 IPs can be offering no services, or they can be offering, you know, some super complex web applications. Theoretically, if 10 IPS have 40 hours per this, 400 hours. If I'm charging somebody five grand, 500 bucks per IP, I'm working for 1250 an hour, I'm clearly not doing a real pen test. Right. And then the inverse is what happens if none of them have any services. All of a sudden I'm making five grand for zero minutes of work, you know, so when people are buying pen tests, the question that they really should ask themselves are, how do these guys know it's going to cost this much? What do they know about my workload and can they justify the workload to me so I understand what I'm paying for? Right. Um, I think, I think that is one of the most powerful ways to tell the difference between getting the type of pen test that we're almost embarrassed to call a pen test today, and then, you know, getting the real deal.
Speaker A: And again, if the expectation is, uh, I give you 40 grand, you give me a checkbox, um, then. Then those folks don't even care about that. Right.
Speaker B: Yeah. Yep.
Speaker A: If you care about outcomes, you know, maybe you should pay for outcomes.
Speaker B: That's right. Yeah. Um, you know, it's. It is true a lot of them, uh, when given the choice between doing the real deal or doing that check in the box, uh, they'll go for the checkbox because it's cheaper, knowing full well what they're getting to, um, you know, of course, is it really cheaper because you suffer a breach down the road, you know, so.
Speaker A: So, uh, speaking of the road to hell and good intentions and, um, the commoditization of things, um, I, I think it's a good segue into talking about AI pen testing. Right. This is something that comes up every year. You know, I think the first time I saw, uh, my buddy, um, Adam Compton, uh, try to automate most of a pen test or most of the automatable stuff, I think it was like 2011 or something like that. 2010, 2011. He's given like, uh, a dozen talks on it over the years. Uh, he's built it, thrown away, rebuilt it I think five or six times. So now when I hear generative AI is going to automate the pen test, I'm like, wait a minute, I know people have been automating 98% of the pen test for, or at least the low hanging fruit, the stuff that's really time consuming for decades, right? So how do you look at AI? What do you think? What is the impact right now? And what do you think about the. I'm going to sell you AI pen testing. You don't need humans anymore.
Speaker B: I think it's like testing a bulletproof vest with a squirt gun. Um, I mean AI hallucinates, it doesn't have any comprehension at all. You know, it might be able to pick up some context, but who knows if it's really going to understand the context. I, I really think that these AI penetration testing solutions are glorified vulnerability scanners. And they are most certainly not going to give you a test that at all resembles anything realistic because they don't have the same kind of, well, they don't deploy the same types of ttps. Realistically, you know, a real threat actor is going to want to breach and they're going to want to be focused and they're going to try to move laterally until they can get your data. Uh, and AI is going to be like, let me test everything under the sun all at once and see what happens and get busted. Real threat actor doesn't want to get busted because you don't get the real depth. Right. So if you're using an AI, even if it can do, I mean realistically, there is no AI tool that I've seen that does true chaining and all uses like pre, pre scripted or deterministic change, change in the symbol thing. But um, using AI, you're not going to get that creative chaining. You're not going to say, hey, I remember seeing this file with this text in it and I remember talking to this guy and he mentioned something, let me put these, oh, look, there's a password near. You know, um, I think it's the next step in automated vulnerability scanning. Now in terms of threat to the industry, I think genuine penetration testing is actually going to grow and become busier with AI. Uh, I think compliance, penetration testing is going to get clobbered because what they are doing right now can be automated better by AI. I mean they're just running tools like Nessus and Qualis and you know, next pose or whatever it might be.
Speaker A: So, so the Cheap human services go away entirely and just get replaced by AI?
Speaker B: I think so. I think that that's not unrealistic, but it's only because those cheap human services are built around repetitiveness and automation and not a deep dive. Not thinking. Right. So I, I do think that that's, I think that's realistic. Um, and honestly, it might make things easier for the buyers too, because now they know.
Speaker A: Okay.
Speaker B: And I do think, here's an example, I think AI is great for maintenance. So buyers can say, well, I want to use this company to do my annual maintenance and checkups because they have this really cool AI engine that has a harness like we talked about previously. It has really powerful harness with good knowledge built into it. That's what matters a lot. Right? Use that for your maintenance and then, you know, hire a team that delivers realistic threat penetration testing. Right. To actually come in and do a deep dive. Find the things that matter, identify the areas where, you know, an attacker's behavior has to align with specific aspects of your organization and build defenses that matter based on that intelligence. Right. Um, I think it'll help people differentiate between the two types of vendors.
Speaker A: Gotcha.
Speaker B: Consolidation.
Speaker A: And for the rest of it, I want to shift to something a little bit more, more fun, a little bit more light hearted. I curious, you've been doing it 20 years. What do you run across that you're just like, oh, uh, please don't make this basic mistake. Yeah, please, that should have been gone like forever ago that you find every single time. That's.
Speaker B: I mean, honestly, it's still just the really simple things like default configurations, default passwords, password1. I kid you not. Um, you know, uh, honestly, like, we get so many hits with that.
Speaker A: That's a code on my luggage. There you go.
Speaker B: You know, uh, or password 1234. Some variant of those. Yeah. You know, I think, I think that the majority of things, if we were to go through and look at our reports, um, the majority of things that, that we see that make us have that kind of reaction are repetitive configuration issues across the board with different customers. And these are really simple issues that come to play because, you know, people who are managing cloud environments, for example, have, uh, a lot on their plate and they can't think about every single little thing. Right. They hire us to come in and we find that little thing. We're like, well, you know, and this kind of popped everything. So. So I don't think it's one thing, but I think it's one class of things, you know, gotcha. I Think it's like that. Yeah.
Speaker A: And then, you know, what. What's, uh. What's one of the most surprising things, uh, that you found? Maybe some of the most unique and. And, I don't know, fun to share.
Speaker B: Yeah. Uh, so in engagement, I. Where patch management didn't seem to exist anywhere, uh, where we found systems that were deployed. Uh, well, I mean, there were protocols that were as old as, like, 1986 or so that were in operation. We found, you know, checkpoint, firewall one, a version that was deployed in, like, 2010, completely unpatched. I mean, just. I think the most surprising thing to me was just this enterprise infrastructure that was. That. Was that open and that misconfigured, you know? Um, I mean, yeah, you name the misconfiguration, you name the issue is there. And the challenge, of course, uh, for them was, well, we did it because we had to get access to things. We had to make things easier. Right. So it's the whole argument of security makes things hard. Um, yeah, but that was probably the most. That was probably one of the most shocking things we had come across recently. I mean, sort of finding, you know, your Russian threat actors and infrastructure.
Speaker A: Yeah, you go to do a pen test and you find out you're the fourth or fifth one in there.
Speaker B: Yeah, that happens. This company actually was like that, too, but more shocking was the state of affairs, you know, uh, do you.
Speaker A: Do you ever come to, like. Like, do you ever do a pen test on, like, Uncle Vinnie's sandwich shop, and you're like, damn, this is rock solid?
Speaker B: Like, yes, yes, I see you not. Uh, when we were first starting, um. I don't want to say first, probably around 2008 or 7, we got this lead from a. A company in New York, and we go to see the company. It was this Irish pub, and, you know, and they had. They had, uh, uh, these points of sale cash registers, and they're all worried about, you know, themselves getting hacked and so on. So, you know, we did work with them, but there was so little work to actually do. We didn't bill them for it, you know?
Speaker D: Uh.
Speaker B: Oh, yeah, they didn't actually have that many issues. Their paranoia did them. Well, you know, they actually. They configured things, right? They were. They were even segmenting things, which was amazing, for, like, three cash registers. You know, it was. It was really. It was something else, you know, and they paid us. You know, they paid us well with beer. Nice. Yeah. Yeah. But I do think. I think that, um. I think that they're probably one of the Ones that surprised me the most because small companies like that typically don't have that kind of knowledge, you know, and then m. In terms of most challenging, honestly, the most challenging infrastructures to get into and move and achieve a specific objective are the ones that have even your basic honey pots deployed properly. Because you don't know it's a honey pot until you trip it. Right. I mean, even if you have an infrastructure that you know is not particularly well managed from a patch perspective and you have vulnerabilities, if we breach your infrastructure, the first thing we have to do upon entry is do discovery. If you have honeyput deployed within proximity of that and we ping that, you
Speaker A: know, we're busted immediately.
Speaker B: Yeah, it's like, honestly I. We recommend to people that they deploy them and it's the bane of our existence, but they're that good. So.
Speaker A: Yeah, well, it's good to hear because they're stupid, simple to deploy. I talk them up all the time and uh. Yeah, glad to hear that works.
Speaker B: Yeah. Honeypots, canary tokens, all of it. Yeah.
Speaker A: All right. And with that, Adriel, thank you so much for joining us today. This was a lot of fun going down memory lane and, and coming some of this.
Speaker B: Definitely. Thank you. Thank you for having us. For having me, I guess, on the channel. Uh, yeah, it was great. I enjoyed it.
Speaker A: All right, uh, we've got some, uh, some interesting stuff that Adriel has written, uh, in the show notes here. So go check out those, uh, couple of them are blog posts, couple of them are op eds. Uh, very interesting. Go check those out and stay tuned. When we come back, we're going to talk about Meta and what they're doing to their engineering organization. You're probably sick of the word agent, but here's the problem. Your dev team is handing every new agent in your cloud way more permissions than it needs. And when one goes rogue, you've got four minutes before your data's gone. You need a default deny button that doesn't break every workload. That's Sunree's cloud permissions Firewall native IAM controls, not Newfoundland. Default deny on every agent and human identity automatically. Learn more@securityweekly.com Sonrai welcome back to Enterprise Security Weekly. For this week's topic segment, we're discussing why Meta is destroying its engineering organization. So that's not my opinion. That's the name of the article that, ah, inspired this topic segment, uh, Pragmatic Engineer. So if you go to newsletter.pragmaticengineer.com uh, he's got a write up entitled why Meta? Why is Meta destroying its engineering organization? And um, it's, it's interesting because it's, it's both connected to the whole token maxing thing with requiring employees to use AI. Um, but Meta has gone so many steps further here, right where they are. They took a bunch of their engineers didn't really consider. I guess when you have an organization that large, you don't have time to do considerations on who you move to a different project. But in some cases it was totally random. They might take the best engineers off the project you're working on and put them over into the AI organization where they're doing nothing but teaching, uh, AI to do stuff, right? Like they have to come up with uh, things to train AI on and they just do that day in, day out. They're not building any products, they're not doing anything that has any kind of sense of um, accomplishment or anything. They're still getting paid the same. So good news, they still get paid the same. Um, but they've been very vocal about how awful this is, you know, So I guess like they really want to replace employees with AI, but AI wasn't good enough. So now they're using the employees that are going to replace with AI to help it replace them better. And so you now have, and the reason, uh, it's titled Destroying the Engineering Organization because you're really just on two sides here. You're either, uh, still working in your old job, doing more rewarding stuff, building product, uh, things like that, building resilience, uh, whatever those engineers were normally doing, or you got moved over to the AI organization. Uh, but even if you're over here, you haven't been laid off, you haven't been moved to the, to the, you know, the, the dreadful job. You're wondering, is it inevitable? Am I going to be moved over there? So basically the article makes the point that 100% of Meta's engineers are actively looking for new jobs.
Speaker C: There is so much to this article and so many different vantage points on how to think about this. Literally. I can argue both sides of the argument, both sides of the coin, and actually be right on. Both sides of the argument isn't. All right, let's just take the moving of engineers. Well, let's just take the uh, the tracking of engineering activity. Massive mistake, right? Like, you know, you don't sit there and you track every click, everything you do and, and expect people to be creative and do interesting things and like that's just not how the the human, the human works. So obviously there was a lot of screw ups throughout the entire uh, concept of that. Um, but if you take the idea of, and I'm going to argue against kind of this guy's point, if you take the idea of that the AI work was meaningless and worthless, uh, I'm not entirely sure that that's true. What I mean by that is there is a lot of very meaningful and powerful work that has been done inside of Meta for a decade or more, building the scaffolding that allows them to execute at the scale that they execute. Meta is one of those companies that has to create things from scratch because nobody else in the world has to deal with the scale that they have to deal with. Right? So the concept of like engineering without writing code can be very powerful. Now if you're just going in and tagging activities, right, maybe that's some rote, um, boring stuff for a period of time, but there was even a comment in the articles about somebody saying, no, this is how I view it. And I've spun this into a, a powerful, useful story of how I'm creating scaffolding that, uh, scaffolding that allows AI to become its most powerful self. So I think there's just a lot to this thing, much more than like they completely screwed it up. Although if you're looking at it from a cultural lens, I agree with you 110% culturally, how they approached it and how they rolled it off, uh, rolled it out very much, met, uh, significant pushback from lots and lots of people. And it's caused the problem with a cultural mistake like that is it can domino effect throughout the entire company. Right. And so, you know, one, two, ten, a dozen, 100, a thousand get affected with something, be it a layoff or a move to a group that they don't want to move, or even just the concept of forced movement between groups, which was very unique and new inside of Facebook, although it's, or Meta, although it's been done in many companies for hundreds of years. Um, you know, just the culture is changing. And so what does this mean for Facebook? Are they the next IBM in the sense of, you know, you can go there and get a great paycheck for a long period of time, but you're just going to be doing click the box kind of work and you know, have it be a different level of meaningful. I feel very rambly at the moment, but it's because I think that, that it is not as clear and as cut and dry as Zuckerberg's A shithead. Therefore the culture's gone awful. It's not that clear cut and dry. And I'll stop rambling there because I felt like that was all over the
Speaker B: place
Speaker C: and it was clearly because nobody has a retort.
Speaker A: Yeah. So. Well, uh, I, I was going to let Eamon go, but, uh, just to interject real quick here, like, uh, from my perspective, like, there's not that many companies in the world with tens of thousands of software engineers. Right. Meta is one. This is a, I don't know, like a dozen companies worldwide that have that many software engineers and they built up such a culture, like they even share this book, uh, that they put out and gave scale scaling employees internally. The way you run an organization when you have tens of thousands of engineers is very different from any organization that has a dozen. Right. If they're wrong and this all goes wrong, how long does it take to rebuild that? Like they've only built it once. Right. And it was over the last 20 years, over the company's entire lifetime.
Speaker C: When, uh, you say it, uh, you mean the culture, do you mean the culture of the engineering?
Speaker A: The culture and the tens of thousands of employees and everything that goes on
Speaker C: going into an era where tens of thousands of employees are no longer needed from an execution capacity.
Speaker B: Right.
Speaker A: That's the bet. And if the bet's wrong, that's what I'm saying. Like, I don't know.
Speaker C: Zuckerberg's really good at, Zuckerberg's really good at making these bets. Look how accurate he was with the Metaverse. And yes, I'm being sarcastic.
Speaker A: I was really hoping you're, you're going
Speaker C: down, uh, the, the sarcasm, the sarcasm line. I think, I think the key, the key to the point though is like, are we going through a paradigm shift, an era paradigm shift where less employees makes more sense and it's okay to try to get rid of people now, again, culture. I'm not going to defend the HR decisions and the process side of it. Right. Like, I think that could have been handled a, uh, bajillion times better. Right. I'm not going to defend that. But is it the right decision? If we want to, if we want to kind of beat that up a little bit? You know, we're in a, we're in a world now where it's far less about writing lines of code. And basically what we're asking these people to do is essentially get into the code review process, the post coding process, where we're going to start to see multipliers of required humans Growth. Right. If you compress the day to day coding that needs to be done and it shrinks significantly, where does the bottleneck move to? It moves to two places. Code review, which is post, or it moves to ideation, and product management, which is creating more specs for the, for the AI to write. Right. And so I think what's happening here, again, not talking about the HR part of it, but I think what's happening here is, look, we don't need the coders anymore. Let's squeeze them, squish and move them to post code review or move them to product management. And we don't have a world in which we can just allow people to make decisions anymore about what group they want to be in because we have to move them out. Right. And so yes, it could have been, could have been handled better, but it feels like what might be right for the company.
Speaker A: Well, and there's, I think one of the myths there is that programmers, that software engineers write code. Right? Like, like it's, it's a lot have told me that it's maybe 10% of the job. Right. Like there's, there's a lot of other work going on there that you can't necessarily offload to, to an AI at this point. So, um, I think we got Eamon back and I think he's stable. So I'll turn it over to you.
Speaker C: Welcome back, Eamon.
Speaker D: Yeah, thanks. Yeah, there's a lot to unpack here. I mean, if you take a look at the article and the supporting articles, I think there's a lot of threads here. One, we should probably talk about the security issues, like the, you know, the vulns that I've introduced from, from, from this, uh, which is an observation I've noticed is that like, people are pushing code and people are reviewing code, but it's the agents that are doing the pushing and the reviewing and nobody's actually like looking at the code. You know, one, one guy on some slack was like, if you have, if you're, if you're not even looking at the code and approving it, you should be fired. You know, it was a very snarky, uh, response. Uh, but there could be some truth to it. The other side is, um, you know, thinking that, uh, AI is going to replace engineers. And I love what Jensen Huang says. Like, he goes, it's not, uh, in fact, it's going to make engineers, uh, busier than ever. Which, um, could lead to an interesting observation of Jevin's Paradox. Right. If we have something that's Going to make our lives easier, but in actuality it's making our lives busier.
Speaker A: Right. What I was commenting earlier, Eamon, is that writing code is not the full job. Right?
Speaker D: Yeah. And you know, uh, people have been talking about like, how product, um, managers. Now, the job of the product manager is changing where that they can actually ship proof of concepts for code and things like that, right. Without even talking to engineering and say, hey, engineering, this is what I want. Help me build this in reality, make this production. Uh, and that's also going to force engineers to have more of a product manager mindset as well. Um, I gotta tell you, almost every day somebody asks me, how has AI changed your job? And I'm like, man, that's a big question. Like, yeah, you know, I, I think what they're hoping to hear or wanting to hear is like, are you going to be jobless with AI? And the, the reality is one, it's made my personal job easier where I can actually do, I could push proof of concepts, I could fix code issues. Right. I could review code. But also I have way more PRs to review as well now, so it's making my job even harder. You know, I'm busier than ever.
Speaker A: Um, yeah. You started a dozen new projects that you now have to manage through an AI.
Speaker D: Yeah, yeah.
Speaker C: I want to talk through this a little bit of the data labeling discussion in the article, right? Because they're talking about moving people off of writing code to data labeling. And that's what I was trying to figure out exactly what is data labeling?
Speaker B: Right.
Speaker C: And so in this piece here it says data labeling is more involved work, even though it is a bit repetitive. Right. There's labeling tasks like where you create a website, look at it and decide if it looks good or not. But, you know, uh, but then there are more involved AI training tests which looks like this, come up with a task that AI should do, write the tests that will confirm the result. Right. So kind of the, the, um, the acceptance measurement, uh, of acceptance criteria, did it deliver what it was supposed to deliver, Packaged all of it up into a Docker container, then read the code that the AI writes, often doing this based on feedback from several models and give it feedback. So that's what a big chunk of these developers are being moved to. And this feels a lot like, I don't want to embrace AI. This feels a lot like I want to keep writing code. But the reality of the future is code will not be written by these guys. And so I'm sure I'll get A backlash from engineers who hear this clip and go, wow, Tyler's like, you know, very, uh, anti writing code. But the reality is I feel like code will be written less, which moves people to the confirmation of the validation of code, which in this stake is called data labeling, which is where engineers need to learn to go. They either need to learn to go there or they need to learn to become product managers, because there's just not going to be a need for them to write for loops anymore. And they don't want it. They're yelling at the cloud.
Speaker A: I got the impression that the data labeling was going to be very temporary. Like this was just a stopgap to get the AI where it needs to go. Not that this is a new thing that they would then do indefinitely. Um, yeah, that they would do this for like three or six months until it was good enough, and then they would also get laid off, was the impression that I got from reading all this.
Speaker C: Yeah. And, and it's possible that that's the case. Um, but why is that possible? Because the creation of the test cases will become AI. The adjudification of the, the correctness of the code could potentially become AI driven, in which case they then would have to move into product creation ideation on the front end of that, of that pipeline. Right. So I don't know what the next phase is, but this feels very much like, hey, I'm angry that you're telling me that my job doesn't exist anymore because railroads, um, you know, I'm a railroad engineer and the car was just invented. Right. Like, I'm sorry, but there's just not the need for the quantity of developers anymore at Meta, and they hired a bajillion of them and they only need a half a bajillion, so they got to do something with them. And yes, I'm not going to sit here and say that how they did it was right, because I think that was a massive failure of colossal portions, you know, culturally. But the why they did it doesn't really seem that wild to me.
Speaker A: Meta doesn't have a ton of wins, you know, So I have to admit I've been reading all this through a biased lens of, oh, they are screwing this up. Uh, like, we've already seen a couple cases where companies had to hire back after laying off because of AI. So, um, yeah, I don't know. They have 6,500 people doing data labeling out of their 25,000 engineers, which is already quite a bit less than I think what they had when all this kicked off.
Speaker C: So they've moved 6,500 people to code review instead of writing code review to data labeling. Small. Yeah, but like, I just read. Like, to me, the way I'm reading this article is data labeling is code review. Right. It's creating the test to validate that the creation of the, of the AI code is accurate.
Speaker A: It's basically like you're now a teacher. You're coming up with problems for the student, which is the AI to do, and when it gets it wrong, you correct it and you do that in a loop forever.
Speaker D: Yeah.
Speaker C: I'm not saying it's a fun job, but.
Speaker D: Yeah. Are we referring to, like, the reinforcement? Learning from human feedback? R.L.H. yeah, yeah, yeah. I mean, it's similar to, I think. Adrian, was it you that posted this? Where, like, um, companies are. They have cameras on people's heads, uh, where they're like in sewing machines and capturing their movements so that they can train models. Um, I mean, I think it's. It's, um, a long tail. I don't know when done is done, that's. That's going to be an interesting. I don't know.
Speaker A: So the camera on the head, that's all meta employees and they cannot opt out of that. That's. Everyone is having every click, everything they do tracked all the time.
Speaker D: Right, right, right. But it's.
Speaker A: Yeah, this is, this is. You are no longer doing any real work that contributes to anything that will be released. Like, this is. You're just coming up with sample problems. You're making workbooks, uh, to train the AI to get better at, uh, doing what you used to do.
Speaker D: Yeah. I mean, you know, the whole token maxing, I don't know if it's like really tracking the right metrics. Right. Because it's not, you know, people could be, you know, wasting tokens on a whole lot of things, but the output is not really that great. The quality cannot be that great. So.
Speaker A: Yeah, yeah. I mean, that's a skill within itself.
Speaker C: Token maxing at isolation is stupid. It's stupid. Spend as much as money can to write our code. Well, token minimizing, while output maximizing is the ideal. Right. That's what efficiency is. Yeah. We don't want to just spew tokens and really, by measuring only the input to that mathematical equation is stupid because people will just spew input. Right. They'll just, oh, I can ask this seven different ways and maximize my tokens. Like, that whole thing is dumb.
Speaker A: I. I'm so a year from now, maybe six months from now, uh, we'll revisit this, we'll do another topic segment, and, uh, and we'll see how things turned out. All right, that's all the time we have for this week's topic segment. Uh, stick around. We'll be right back with the news. Enterprises are adopting AI tools such as AI agents, MCPs, LLMs, and skills. At 10x speed, these agents have access to business critical workflows, applications, tools, and sensitive data. But access without governance and control isn't acceleration. It's exposure and critical risk. The question isn't whether to build or use AI agents. It's whether security teams can govern the AI environment. Akto is the leading AI agent security platform, helping enterprises solve this gap. With continuous agent discovery, automated AI red teaming, agentic guardrails, AI security posture management, and runtime protection, OCTO helps enterprises secure AI adoption across the entire AI lifecycle. Learn more at securityweekly.com October welcome back to Enterprise Security Weekly. Now for the Enterprise Security Weekly news. You can check out securityweekly.com esw465 if you want to follow along as we go through the news or for links to any of the articles that we're covering. All right. Eamonn. I never introduced you, but Eamon Elsa joined us in the last segment, and I'm an asshole and I forgot to introduce him.
Speaker C: You're good.
Speaker B: You're good. How you doing?
Speaker D: I kind of just snuck in there.
Speaker A: Yeah. All right, so we actually. We have some interesting stuff in story number one here, which is where we cover the vibe. Uh, funding, acquisitions. We have two extra sections we normally don't have. Uh, it's not often we get to talk about a cybersecurity company shutting down. Uh, not asset acquisition, not acqui hire. Like nothing's going anywhere. They're just done. Um, and we've got a layoff section, so the layoffs is the easiest to talk about. Snyk is laying off 90 employees. Uh, it's not their first layoff. I don't even think it's their second layoff. Uh, they've done a few rounds over the last three or four years.
Speaker C: Yeah, fourth round.
Speaker A: Uh, um, not a lot of details on that. Like, uh, the. The. That's less than 24 hours old as of the time that we're recording this. Uh, a lot of people were still looking for some more information, but, um. But yeah, already on LinkedIn, people are offering to hire people. You know, the usual, uh, thing that you see out there. So hopefully they. They, uh. Uh, most of Them find a chair, uh, as the musical chairs go on. Uh, but the other one, Salem Cyber, uh, was one of the AI SoC AI assistant startups, uh, formally submitted the paperwork to shut down operations. So I guess chapter seven, maybe. Um, I had not heard of them. But in my defense, there are like 60 of these companies.
Speaker C: So, uh, I'm intimate with that company. I was an advisor with that company, uh, since well before they positioned as a soc AI company.
Speaker A: Oh, so they pivoted into the soc AI.
Speaker C: They pivoted into SOC AI, that's correct. Uh, and the team, the founding team there are just great, great human beings. And so I've been kind of, uh, involved tangentially mostly as like CEO asking me, like, how should I handle this situation? Kind of, uh, support over the last year and a half. Uh, and yeah, it's just sad to see that they didn't make it. But, um, you know, it was just one of those situations where I think they had, they were too early to market and pivoted into it and you know, had, had already burned off enough at that point that it was hard for them to remain competitive. And look, they're in North Carolina. It's hard. It's twice as hard, 10 times as hard when you're not in the Valley or Boston or New York. And so it was a difficult, uh, road for them all the way through the process. So, uh, I have a lot of empathy for those guys. I feel for those guys. They gave it everything they had and they're great human beings. That's a bummer to see them shut down, but they literally just shut the doors.
Speaker A: Yeah, it's super crowded space. Um, like the, you know, there's not a lot of feature parody. People are going in different directions with this thing on, on how they're doing. Sock AI. So, um, yeah, I mean we've been predicting this, right? Like, not everybody's gonna have the chair when the music stops, you know, which is probably the same with, uh, sneakier. But I wonder, you know, like. Yeah, talking about, you know, one of the things I think about when doors are closed, like all these people leaving Meta, uh, I, I think, uh, Oracle in the last four months has laid off like 55,000 people now. Like they had 30,000 and then another 25,000 or something like that. Like, I wonder how many doors open, right? Like, and I wonder if some of those doors, you know, like the replacement for Meta M, I wonder if that's going to come from one of these people that were forced to do data labeling. Uh, for sure.
Speaker C: I do think it will be. I 100% think it will be. Look, I lived through the dot com doors all closing. Right. I was there as we were watching high tech collapse and pets.com go under because you know, they couldn't ever achieve what they had, uh, you know, set out to achieve. And yeah, all that stuff closes. But you know, out of the ashes, out of the ashes of a high tech collapse rises the phoenix. Right. And we will see that again. Uh, I would argue that probably the next 12 to 24 months, 12 to 18 months is probably going to be one of the best investment vintages you can get your hands on.
Speaker B: Right.
Speaker C: Like when, when everybody's getting smacked is when you put the money to work and find that next, uh, the next bird to come out of the ashes. And I think you will, you will see that if we look back 10 years from now.
Speaker A: Yeah, a lot of good talent has severance and time to think about what they're going to do next.
Speaker C: Yeah, yeah. And they're sitting in a world now where the technology and the ability to create has never been faster and we can create more with less. And where it would take, you know, a million dollar investment and six people 24 months to get something off the ground takes, you know, my, my six months of severance money and me and a buddy in a coffee shop like literally to achieve the exact same thing in six months what took two years before. So that's what I'm saying. I think you're just going to see a massive explosion of AI driven technologies coming out of the, out of the collapse of uh, you know, whatever this is, we're seeing the collapse occur.
Speaker A: Amen. Sounded like you were starting to say something.
Speaker D: No, no, no, no, nothing. I mean, you know, it's um, yeah, you know, being laid off is, is not easy, um, or can, can be tough. But I think what people need to understand, uh, and I've said this a little bit before, but the employment, employment in the future is not going to be the same. Right. You're going to have to have multiple sources of income. Right. Uh, little bit entrepreneurial, all that kind of stuff. And so, um, what's going to be difficult is those that don't have that muscle and don't know, you know, how to exercise that muscle.
Speaker A: Uh, well, it's so interesting here. I've been in Europe for the last two weeks and uh, and this is still a place where like joining IBM in the 70s, like you can spend your whole career in one place still, you know, so there's still, there's a very different mindset over here, and I guess that's why they don't have an AWS or a gcp, uh, over here. Like, like they don't have a hyperscaler, um, because, uh, you know, the, the goals. And just, just the goals of employment is, is different over here. You know, like, like there are people just, uh, on a weekday just out there playing in the fountains in the, uh, you know, the hotel where I'm staying. You know, like, like they're just not working for the whole summer.
Speaker D: They, they enjoy life. I mean, they know how to. Like, I mean, you know, they take off in August, so, I mean, there is that. I mean, we definitely are not known for that here. So.
Speaker C: Yeah, cultural differences, for sure.
Speaker A: Uh, so the vibe check, uh, last week Mike Prevet asked, uh, uh, so the US government effectively forced Anthropic to pull Fable 5 and Mythos 5 for every customer overnight. Does your model can vanish on a policy whim, change what you actually run? And so 50% of people said that they're staying put. Um, without Mythos or Fable, they're just gonna drop down to Opus 4.8 or, uh, whatever the latest Opus is. And so 50% said they're staying put, 25%, uh, a quarter said they're building the exit, and 25% said they're already moving. So I thought that was interesting. Basically talking about, you know, when your model of choice gets rug pulled, what do you do?
Speaker D: I mean, there's so many models these days, so, you know, it's.
Speaker A: I mean, right when this happened, I got an email from tinfoil, which is like a, um, the whole idea behind tinfoil is it's like imagine chatgpt if it was, uh, uh, what's the term they use where they even encrypt data? Ah, in memory only. You have the key. Not, uh, confidential, uh, computing. Um, I forget the term for it, but yeah, like confidential computing. So basically like you're running in the cloud, but the cloud provider can't see your workload. So like Proton. Yeah, I'm blanking on the term for it.
Speaker D: It's been a long end to end encryption, like, so there's no, like, there's no insight into it. Yeah, I can't, I don't remember the
Speaker A: technical term, but yeah, it's like confidential computing. It's something computing. But, um, but yeah, I got an email from them and they're like, yeah, we're deprecating these three models. So make sure by the end of the week you're off of those models. And it just reminded me that, like, this is a pretty normal thing. Like, I remember people getting upset with OpenAI for deprecating certain models. Um, I guess like one of the things that these providers think about is like, how powerful is the model versus how much inference costs us. And if it's not efficient, like they're gonna, they're gonna ax it, right? You know, like they can make a lot more model or a lot more money off a more efficient model. So, um, so yeah, I wonder how many of these people are gonna be pushing to local. Uh, because that seems to be. That's what Apple's pushing for. That's what Microsoft is pushing for. They just released a bunch of local models during their last big event. Uh, so we're going to see a lot more hardware in the near future that's designed to run AI locally. So I wonder how much of that eats that up.
Speaker C: The good in theory, porn execution is my answer to that, Adrian. Um, because I think last week when we were talking, I kind of brought up that idea. But maybe it's going to push pretty significantly. I thought maybe it would. The more I've researched this topic, the less I believe that, um, for a couple reasons. And for what it's worth, I was one of the staying poet. Claude is my ride or die. Uh, that's what my answer to this was. Um, but look, humans, developers, building is in essence all about efficiency and uh, cost versus, uh, revenue. And at the end of the day, if it costs less to run a service version of it, we're going to use a service version of it. Regardless of the risks, within reason, Regardless of the risk to the business. Because at the end of the day, look, I don't think Anthropic wanted to pull it. Right. Clearly this was, uh, a government situation of forcing the rug pull to occur. And so who do we have to blame here? The provider that we're hooked with. That can literally happen to any of them or the government. In this case, I believe it's somewhat politically motivated because they have beef with Dario, um, from Anthropic. Like Dario and Trump are at each other's throats. So this is in my opinion, very politically motivated. But at the end of the day, okay, so you go to Opus. Uh, I don't think it makes that much difference.
Speaker B: Right.
Speaker C: It's not like we're talking about. So, uh, ride or die, stay with them. In my opinion, I think bulk of people will just take the lazy route out and just stick with them and not switch more. I've been thinking about this, but into
Speaker A: the point that there's so many other models out there. Story number 13, which I added, uh, pretty late. So if you haven't refreshed, like maybe I didn't get it into the notes on Slack. But story number three, China's, uh, 360 says that it has developed tools that match Anthropic's Mythos, uh, which is not surprising. Right. Like OpenAI was there like a month and a half, two. Two months after with GPT 5.5, which came pretty close in a lot of benchmarks. Uh, we've seen that some benchmarks, uh, um, uh, smaller models actually do better than the large, larger models. It just depends on what you're doing. Like some of the reasoning tasks, smaller, cheaper models just do better. Um, so yeah, yeah, I feel like we're at a point where, um, open models, Chinese models, uh, like there's now Canadian models. Yeah, like, like we're, we're kind of spoiled for choice at this point. And I, I don't think it's a huge impact if one of them gets pulled for most people.
Speaker C: No, I don't, I don't think so either. And I think actually what, what the long answer to that is is model commoditization. What is it really going to mean when. And this is, this is. I've been saying this for a year and a half now that everybody's been complaining that 2026 is the year that everybody complains about the cost of tokens now. 2026, oh my God, we can't afford how many tokens we're spending on everything we do. Well, guess what? It will come down. The market will make that number, that cost per token come down. And what's going to drive it is model commoditization. Oh, look, I can switch to 360 out of China for one third of the price. I'll go over there for a while. Oh, look, I can go over to Gemini at a, uh, even more discounted price. I'm going to go over there because when the, when the products are on parity, that's a commoditized market where cost is all that matters. Right. And I think at some point we will see that the models will commoditize down. It may not happen in 2026. Maybe it's 2028. You know, I don't know when. But just like cloud computing, Cloud computing has come down too. What's that, Eamon?
Speaker D: You don't think the prices are going to go up because they're so all subsidized right now.
Speaker C: Maybe in the short term. Maybe in the short term. But I'm saying in the long term that it's, uh, a, you know, all markets commoditize, all markets drop in price, all markets are superseded by other markets. And I don't think tokens in the AI era are any different. It's just a matter of when. And so for me, you know, I think could make a ton of money. And I know there's some companies out there doing it. It's just a routing company where your whole job is to be the middleman that routes between all of the different. So you don't have to change anything in your open router.
Speaker B: There you go.
Speaker C: Yeah. And that, that company is going to crush it because people are just like, you know what? I'll solve this problem by being an open router. So Fable gets rug pulled, a flip to some other one that's relatively close in value.
Speaker D: And you know what happens? The good thing, I mean, you know, it's a bad event, but it's the good thing that at least it happened quickly because, uh, you know, it didn't. It's not like Fable was out for six months and then it got pulled. That would have been way more catastrophic. Yeah. Because, I mean, it takes time for providers, for companies to. They do a lot of testing before they release a model or integrate it into their tooling.
Speaker B: Uh,
Speaker D: so, you know, like, typically a model comes out, they'll get a preview of it actually before, like a beta preview, and then they'll release it in their product maybe, you know, on the day of the public release or, uh, a couple weeks after.
Speaker A: So, yeah, I think they knew there was a chance it was going to get pulled. Right. Because White, uh, House put out that executive order. It says, you're not allowed to do this without our say so, and they did it anyway. So I, I think they knew there was a good chance of it. And, uh, it only helps their marketing and their prep for their, uh, ipo Even better.
Speaker C: If you really want to dig into the drama of it, go listen to. I don't think it's the most recent, but it might be the one back from the most recent of the all in podcast. Uh, they got into the drama where, uh, they talk about how the actual communication about the rug pull occurred between the White House and Dario and they sent him. Basically, there was. Yes. Yeah. And Jassy essentially, uh, his. It's presumed to be somebody on his research team. On his cyber team basically said that there was a real risk of breaking out of jailbreaking fable and told the White House that. And the White House said, that's a national security issue. And they contacted Dario at Anthropic and Dario basically gave him the middle finger and published a blog post saying every
Speaker A: single model is jailbroken. There are no unjailbroken, um, models.
Speaker C: He got defensive and basically said like, you know, this type of jailbreak as defined by your team actually didn't matter and it's not important. And he might be right, but at the end of the day, I think it's a political pissing match that caused it to be pulled more than anything else. Yeah, but it doesn't change the fact that you still have to have some kind of resilience to swap models. And I think that's where like the open router approach is probably your best bet.
Speaker A: All right, moving on here. Uh, we've got some funding, um, Sandbox aq, which is real big, um, Quantum, uh, company. Uh, they do a lot of stuff post, uh, quantum cryptography is just one of the many things that they do. Uh, they got a big grant from the Chips and Science Act. Half, uh, a billion dollars. Um, so a few other interesting ones in there. Dream security, Operational technology and critical infrastructure Security platform. I don't know much about them, but they got a 260 million dollar round and are now a valued, uh, as a unicorn. So over a billion dollar valuation. Uh, we're starting to see that every month again now. Tyler. Uh, we've got at least one unicorn
Speaker C: every month now, so that's uh, bubble territory.
Speaker A: Interesting.
Speaker B: Yeah.
Speaker A: Um, there's a couple other big rounds in there. Nothing that I just haven't had it. One of them. 20 Technologies, a US based offensive cyber warfare operations platform, raised 100 million Series B 20 technologies offensive cyber warfare platform. Okay.
Speaker C: Not sure what that means, but okay,
Speaker A: me neither. Um, M. Yeah, it was just, you know what, I was talking about this with my partner the other day. Like, because of AI and a lot of things, it's not just AI, you know, politics also. Um, there's just so much going on. I'm just. I can't get excited about funding and acquisitions like I used to be able to. Like, it's just all a blur at this point. I don't have any time to really look into these, to read like. And just the desire to do so is gone.
Speaker B: It's.
Speaker A: Yeah, yeah, there's just too much going on all the time.
Speaker C: What I struggle with and I Think, uh, it's a function of being around as long as we have Adrian is how is this different than any other iteration before? And then immediately you jump to, okay, there's got to be some kind of AI derived cyber, whatever they called it, Offensive cyber warfare operations platform. Okay, so AI, but then you have to really mentally make the leap of can AI reinvent this market and reinvent that space. And that's where you and I probably, at least I know I struggle pretty heavily, is like, can it. But here's the thing. Every time I say that to myself, I find out that I'm wrong. Like, literally, I've probably said that three times on investment opportunities in the last 24 months. And then fast forward 24 months, it's like, holy shit, they're now at 100 million in AR. What just happened? How'd they do that? So, I, uh, don't know, man. That's my struggle is just trying to grasp how AI is truly impacting the day to day from the startup scene.
Speaker A: Yeah. So apparently the mission of this company is to transform cyber warfare by encoding elite operator knowledge into autonomous AI agents that operate at machine speed and global scale, allowing human operators to focus on strategy. I'm not sure anybody in the military is ready to pull that trigger because it sounds a lot like AI making military decisions, like AI pulling triggers.
Speaker C: We're back to the Terminator discussion of like four years ago.
Speaker A: Very Skynetty.
Speaker C: Talking about this.
Speaker A: Very Skynetty. Um, okay, there's one. Password. Main acquisition. Sailpoint. Main acquisition. Acquisition Cisco. Main acquisition. Let's move on.
Speaker C: You can tell he gets excited over acquisitions, guys.
Speaker B: Yeah.
Speaker A: Uh, so interesting new tool here. Uh, one of the engineers at thinkst introduced, uh, a tool called package proxy. Uh, Eamon. I don't know if you got a chance to look at this, but I thought it was pretty interesting. Supply chain safety checks without client side software.
Speaker D: Oh, I did not get to look at this. No, no, but it is something interested in.
Speaker A: It requires you to set up, uh, some cloud flare, um, um, scaffolding, uh, for it to work. Uh, but, but yeah, it looks pretty cool. It looks like, uh, basically they, they're looking for a way to address this, um, you know, install scripts, post install scripts, uh, tool, you know, packages getting backdoored, that kind of issue, catching it early, catching it programmatically automatically. So looks, looks pretty cool. And it's, it's open source. You can just go grab it.
Speaker C: Yeah. So it's basically a proxy that, that, that sets up and does some of these really from what I can tell, does one of these, um, you know, require the package to be a certain age check, uh, whether the package was uploaded to the repo incorrectly, look at email domains, you know, et cetera, et cetera? Yeah, it's like a freeware proxy. Eamon.
Speaker D: Yeah, yeah, yeah, go ahead. No, I just, I mean my approach to this, towards this now is kind of uh, really have your own repos internally and just have engineers pull from there and not allow anyone to pull directly from the Internet. So that applies to VS Code, that applies to you know, npm, all the packages, um, and extensions. So um, I would, you know, if I didn't have that, I would probably. Yeah, but that's, that's kind of like my path is like, hey, you're not allowed to go out to the public, pull it from our repo. It's vetted. Maybe I would run this obviously on my own repo, like on the internal repo.
Speaker A: Yeah, it's the same thing Apple and Google did uh, with uh, their smartphone, uh, ecosystems to protect them. Right. You can still sideload on the Android side of things. Uh, but that's the reason why nobody's getting compromised through their smartphones these days is because there's a proxy there. You know, like they are doing some security work to make sure people aren't putting malware in there. Of course there's a lot of hardening, sandboxing on the OS itself.
Speaker C: But, but let's be clear there. They didn't do that to be altruistic. They do that to take 30% of the cut of buying apps. Right. That's, that's why they do that.
Speaker A: Yeah, yeah, there, there's, it's, it's a side benefit. It's the same thing with DevOps. Like DevOps. DevOps didn't create uh, ephemeral infrastructure and all this, uh, speed and scale to help security. Like they did it for performance. But we benefited, uh, we benefited from a lot of that work.
Speaker C: But so my concern about this is what's going to get people to adopt this now, this freeware package now as opposed to having adopted it six years ago when JFrog and Sonatype Nexus were basically saying the same thing. You know, because we're going to put a repo on your, on your site. You're going to point everybody to the repo, the repo is going to go outbound, you're going to have a gold confirmed safe package that comes in, gets scanned, gets checked.
Speaker A: People look because they've all had incidents now that's the difference.
Speaker C: That's the difference.
Speaker A: Now it's so. Well, uh, everyone has experienced it firsthand. Yeah.
Speaker C: Well, let's hope that the uh, you know, shock and awe makes the adoption of this.
Speaker A: Uh, I mean it's the thing we always said in pen testing, like we need breach as a service because, uh, you know, after the breach, now they take it seriously. Right?
Speaker C: Yeah, yeah, yep.
Speaker A: Uh, let's see. So CISA came out with their bod, uh, 2604. Um, I would have chosen a different name personally, but uh, it's basically vulnerability prioritization. Uh, and it's a decent framework for it, even if you're not required to. Obviously this is for government agencies. Um, but yeah, it's a pretty reasonable set of um, framework for determining. Hey, is this vulnerability serious enough to fix super fast or can I wait? Can I afford to wait? And it's based off of, ah, a couple things like if it's on the KEV or not. That's not ideal. If it's on Kev, it's already being actively exploited. That's a late indicator. But, uh, is it automatable? Is there technical impact? Um, I don't see any federal agencies fixing stuff in three days, which is the top, top level that they're expected to do stuff in. And this applies to Fedramp now as well. Um, nobody's doing stuff in three days. Like, I, I talk to companies day in, day out who are like, we can't do it in seven, we can't do it in five. Like, and the government's going to do it in three. I don't think so. So I don't know. Yeah, why not? Three hours? Three minutes. Patch it in in three minutes. That's the requirement.
Speaker C: Sounds good to me. Make it happen.
Speaker A: As long as we're going to throw out something unrealistic, sure.
Speaker C: Faster the better.
Speaker A: So the um, Eamon, let's, let's jump to one of yours. Let, let's skip away from some of mine.
Speaker D: Mine, I had some. Oh, okay. Yeah, here we go.
Speaker A: Yeah. So you've got two amd, uh, stripping memory crypto, which I didn't even realize was happening from its consumer CPUs without any press release or anything like that. And then the other one, we may be living through the Most consequential, consequential 100 days in cyber history and almost nobody has noticed because we are just being, uh, hit over the head with everything so often. Yeah, I feel like I just. Yeah, yeah.
Speaker D: The second one was actually from I, uh, Think the same person that published the dvd, uh, article. So when I. Yeah, yeah, that's how I found it. Yeah, yeah, the long read. So that was, that was pretty interesting. Um, and you know, I, the, the author takes a. Take that like, you know, there's all these like big cybersecurity events that happen and we're like not really paying attention to them. So it's, it's worth a read.
Speaker A: I mean it's not that we're not. We just don't have any time to talk about it before the next one happens.
Speaker D: Yeah, I think that's the. I mean, you know, I, I think we're all experiencing um, squirrel. Right. Like, you know, attention just being led in different directions.
Speaker A: But yeah, like, like affordably, like overnight we find out that like. And I, I keep seeing different amounts. Like uh, some are reporting 30,000 Fortinet devices hacked, some are reporting over 70,000, some are reporting hundreds of thousands. Some were also reporting that a bunch of Ms. SQL also got hit and Sophos devices also got hit. But like overnight somebody hit tens of thousands of firewalls and compromised them without a zero day with uh, credential theft. And, and like, like we're not like we should be spending the whole news thing just talking about that. Like, like if that happened three years ago, like I would have just wiped everything off else off the news list and we'd just be talking about that. But there are other insane things happening at the same time.
Speaker C: I mean it's a volume thing, man. It's a volume of noise thing. And it's not even that we don't want to talk about them as you mentioned Adrian, like we do M. But when you're hit with so many at some point you just like all right, whatever. Like you know, and it doesn't affect the day to day too much because it's usually some big company that you know, massive European aviation breach or you know, something, something huge or you know, uh, you know, some of these articles, some of the things Rockstar Games gets hacked, like super big interesting articles but they're happening with so much frequency and it doesn't really affect the day to day of most of us or most of our companies. It's kind of like eh.
Speaker A: Okay, so the other aspect of it that, that we have to mention is uh, like, like Strykers mentioned on here. They got 200,000 devices wiped via intune. Right. Um, and then they posted their best quarter ever like a month after that. It's just not hurting companies all that much, you know. I think that's one of the reasons why this isn't a big deal. Like Jaguar Land Rover was a big deal. Like they couldn't produce cars for like a month and a half. 4,000 other companies were impacted. But like the rest of these, a lot of companies are just shrugging these attacks off.
Speaker D: What's interesting about some of these attacks is that it's kind of like a lot of ip, um, all over the place. So it's maybe it's like a quiet, um, how do I say, this skirmish, you know, that's happening on the Internet between different, you know, private companies and governments that just everybody's trying to grab everybody else's IP and just, uh, you know, go around. I don't know, maybe it's a little too esoteric or fringe.
Speaker C: But he. Yeah, sorry to interrupt there. I mean, go ahead and finish.
Speaker D: No, no, no, yeah, you go for it.
Speaker C: I mean, he, he distills it to a few different things. Right. Um, which I find interesting. Right. One possibility is that the attribution to a state actor is professionally expensive. Meaning it's hard to, um, you know, hard to kind of get to the point where you can actually have true data. Okay. A second possibility is that the SaaS supply chain story is uncomfortable for the security industry to even dwell on because we can't fix it. Right. And the industry sells fixes that aren't working. Okay, maybe, but this is the one I find to be the most interesting. Right. Is this kind of what we were talking about? A third possibility is that much simpler and possibly the most powerful. The news cycle has trained the public to bounce off of cyber stories. The audience has already absorbed Equifax, OPM, Yahoo, SolarWinds, MPD, Snowflake, and the marginal shock of, uh, to quote DJ Khaled, another one has flattened. Right. Like at the end of the day, it just doesn't matter and nobody cares. Um, um, you know, the, it's just. And then he, he even goes on to say the fourth possibility is the acceleration of AI on the side of industry is just overpowering from a volume perspective. And in cybersecurity, it's the only thing anybody talks about anymore. And when you pile all this together, breaches don't matter, nobody cares, move on. Right. The noise is just there.
Speaker A: I didn't even hear about the Lockheed Martin thing. Apparently 28 engineers got doxed and 375 terabytes were stolen. F35 blueprints. I thought the F35 blueprints got stolen a long time ago. I don't. So I. I didn't even hear about that one. Like, it's. It's, uh. There's a lot of stuff in here that, uh, didn't even make it. Somebody who does a weekly podcast with a 45 minute news segment did not even hit my radar.
Speaker C: Yeah, Honda. I didn't hear about the Honda breach.
Speaker D: Honda, yeah, Honda. He also claims that China NS breach, though, maybe the largest single exfiltration event. And he goes. He's not sure if it's true.
Speaker A: Oh, is that the supercomputer one? Yeah, yeah, we're not sure if that's true. That is. Yeah, I did look at. I did hear about that when I looked into it.
Speaker D: Okay.
Speaker C: Yeah, I don't know, man. It's just a noise thing, you know, It's a. It's a, uh, it's. I think personally, it's a situation of, you know, you cry wolf enough. It's not really a cry wolf analogy in the sense of they're lying, but if they're just so much noise, you just get desensitized to the volume of it and to the point where, like, you, Adrian, I'm supposed to be keeping up on this stuff, and I see another breach news report, I take a quick glance and I'm like, yeah, okay, so what, it's just another one?
Speaker D: Yeah, we have been really desensitized. And then these are all the ones that we hear about. Right? There's so many ones that don't happen. We all know that. I mean, sorry that we don't know about that happen. Um, and I try to tell folks, you know, a lot of companies feel like, oh, if they get breached, yes, that's not a good thing. Um. Um, but you know, historically, we know that they just forget. The public just forgets about it right now if it happens more than once. Like, I see LastPass again in here. Like, why are we people using LastPass? Like, come on, you know, please learn your lesson.
Speaker A: Uh, Clue. What was it called? Yeah, Clue.
Speaker C: The clue breach.
Speaker D: Yeah, I didn't even know who Clue was, so I didn't either.
Speaker C: Sales. It's a Salesforce plugin or something, I think.
Speaker D: I don't have a clue.
Speaker A: Yeah, yeah, it is well, uh, played. I missed that.
Speaker C: He doesn't have a clue.
Speaker B: Ah.
Speaker A: Uh, I got. Got it.
Speaker C: Apparently, neither does Adrian, so it's fine,
Speaker A: y'.
Speaker B: All.
Speaker A: It is 10:30pm Where I'm at.
Speaker B: You gotta.
Speaker A: You gotta cut me a break.
Speaker C: You get all the breaks you want, buddy. All the breaks you want.
Speaker D: I. I love the $60 laptop story though I have to say that was.
Speaker A: Well before we get to that, since you mentioned clue, um, I, and this is related to just being inundated with breaches, uh, I came up with a term that I call cascading breaches which uh, we've seen happen a couple times now. Like trivia. Trivia was an example of that. Aqua's trivia got breached and then check marks got breached and then uh, two of their projects got breached and then light LLM got breached and then two companies got breached because light LLM got breached. So you just have this cascading effect where one thing that everybody uses gets breached like cloon, uh, or the other example here is the fortinet devices getting compromised and then there's a whole bunch of other breaches that happen as a result, uh, trailing from that because it's a supply chain component or because credentials are stolen in mass.
Speaker C: Yeah, I've been calling that hack amplification. Right. You're basically as an attacker, why would you rather attack one company and be successful when you can attack a hack amplification style attack and you hack one thing that results in hack the company that's everybody's supplier. Yeah, yeah, yeah. And that, that has always been the foundational argument of why software supply chain, or supply chain in general attacks are so risky and so dangerous. Uh, and why they're so hard to handle. Right. Like how do you eliminate them? Because every single one of our companies lives off of 50 or 100 or 200 or 500 different software packages that we're using every day. And you know, sure, we send the requirements. Oh, you have to be SOC2 and you have to be this and you have to have a pen test in the last X. But no, that's all theater. At the end of the day, none of that's really going to protect you. It's not going to protect them either. It's just, it's a minimal level of due diligence. So the insurance people get off your back and you know, at the end so you, so you're not negligent. You at least asked. Right. And at the end of the day that's why those attacks, the uh, hack amplification attacks are so powerful.
Speaker A: Yeah. So Eamon, let's go to Digital estate management. What'd you think of that article?
Speaker D: It was fun. It was a fun read. Like uh, kudos to the. So uh, the summary of the story is like someone bought a laptop, uh, from an estate sale for $60 and you know they're hoping to get some sort of friction but they turn on the computer and it goes straight to the desktop windows computer uh, and goes straight to the desktop login. And the author goes and explores the computer and finds a very meticulously uh, well maintained computer. Um, so much so that uh, the original owner who has uh, passed away um put a registry key to prevent it from updating to Windows 11. Right. So just like kind of like really want, knew what, what they wanted. Uh but you know it, it does have the security of the 1990s where all, all the original uh, owners uh, information, I mean m, I mean like Social Security numbers, client account passwords, right. Medicare, um, login everything were just in like several text files. Well organized. Well I organized text files but um, yeah it's pretty scary and it might be related but I am seeing a large, there's a lot of people reaching out to me like parent friends. Right. Um, people my parents age that are being hit with scams right now. Um, so it's a little later but they don't know about good password hygiene and MFA and all that kind of stuff. Um, but this was ah, an amazing treasure trove of information.
Speaker A: Yeah, it's, it's um, it's a rough area where um, even a decade ago, uh, one of the, when I started a consulting startup, uh, we did some pro bono services and one of those was trying to recover data from uh, family members who had passed away and didn't leave their passwords behind. Nobody knew how to get into their devices. Uh, they wanted to get rid of the devices or sell them but didn't know how to wipe them properly, that kind of stuff. So we would help with those kinds of things and there's not really good great resources out there for these people to figure out how to do that. Um, so. And there's not good resources built into the devices either. Like the number of services I've seen out there was some way to turn your automatically turn your account over to somebody else if you pass away. Like a lot of services just don't have that. Uh, a couple out there have deadman switches where if you don't log in for three months, uh Gmail does have this where if you don't log in for a certain amount of time it will give access to your email account to somebody else. It will offer for them to set up an account. I think it's like three months or something like that. But um, but most services don't like you just have to have your affairs in order you know, make sure that uh, those, that account information is somewhere where people can get to it. And uh, and it's usually a giant mess for whoever's behind after you're gone.
Speaker C: Well, if it wasn't such a horribly insecure piece of software, I would argue that LastPass is probably best suited to offer this as a service. Uh, not kidding. I, I'm kidding, but not kidding. Right? Like I'm kidding about the LastPass part of it. But.
Speaker A: So yeah. 1Password. When you set up a 1Password account, it encourages you to print out the emergency kit and put it in a safe or a safety deposit box and that has your uh, your key and you write down your master password on it and you file it away in some place that's physically safe. And that's how you know, because it's your password manager. Uh, that, that's how I'm sure, I'm sure um, LastPass has something similar there last time I used it, I don't, I don't recall it. But uh, 1Password does have a uh, uh, and it's literally something that you just print out uh, onto physical paper, uh, where you put your credentials on there so somebody can get in, in there if they need to. So I've done that for mine. But um, I, I'm not the, the typical person like most of these people, uh, from my, my parents generation and maybe the age of this guy here. They do store their passwords and text files.
Speaker C: Mhm.
Speaker D: Yeah.
Speaker C: Along with everything else that, that was compromised here. Software licenses, upgrade histories, invoices, billing records for clients, medical records, everything.
Speaker A: No disk encryption, no password when you boot the thing up.
Speaker B: Yeah.
Speaker C: Why nobody else is touching that computer but him. Why?
Speaker A: So speaking of people being unaware, I'm just going to cover this real quick and we can move on. Number uh, 10 is just somebody posting on blue Sky. They're like hey, this is a really weird captcha and it's click fix, right? It's one of these where it's trying to get you to paste a command that will get you infected with an info stealer into your terminal. Um, but this is just legitimately somebody who doesn't know what click fix is, who doesn't understand this social engineering technique. Uh, just posting a screenshot and being like uh, this is weird what's going on with this captcha? And of course there's, there's typical ah, responses with people like you some kind of hear you, you don't know, you know, attacker in the responses. But um, but it's, it's um, it's a reminder that, you know, as these things evolve, like Click Fix has been around for a couple years, but I think only in the last six months did I understand what the term click fix meant. Right. So it's going to take even longer for, you know, the. Just the ordinary folks to become familiar with this attack type. And it like, forget your antivirus. Like this. This was the solution for Endpoint Security. Like just have you execute the command on purpose and it bypasses all your security tools for now.
Speaker D: That's crazy.
Speaker B: Yep.
Speaker A: There have been so many breaches where, um, like that Axios, ah, NPM package. It was Click Fix. They got him to pay something into his terminal.
Speaker C: I mean, this goes back to the discussion we had around pen testing and why pen testing is not, you know, that important of a technique anymore because it doesn't really emulate the reality of what's happening on the ground, which is, yeah, Click Fix style, cut and paste my way to your heart kind of attacks. Right. Like, it's just a different. This is so much more common than anything you'll find in a zero day pen test. I mean, come on.
Speaker A: Yeah.
Speaker B: Yeah. All right.
Speaker A: For our squirrel stories, um, this one blew me away. Mid Journey is making, uh, like, like, uh, uh, what do you call it? Uh, the machine that takes, uh, an image of your body you climb into. My brain is really an mri. Mri, yeah. So this is basically like there's some kind of fluid, you go in a chamber. They, uh, make it look like a spa. Like it looks really relaxing and inviting and they use ultrasonic to image your body. Um, and this is Mid Journey, the company that didn't even build a front end for their image generator. You had to get a Discord account, uh, to produce AI generated images. Like the jankiest company out there never built a front end, is now in healthcare and building medical devices. I did not expect this at all. This caught me, uh, completely out of the blue.
Speaker C: Oh my gosh, this is weird. After you step on a platform, Mid Journey scanner will submerge you in water at a rate of 2 inches per second. And your body passes through a ring made up of a half a million squares, the sign of the size of a grain of sand. With each one of them capable of emitting ultrasonic waves and recording the ripples that bounce off your body and back to it. Bizarre.
Speaker D: Yeah.
Speaker A: The demo videos are, are very cool looking. They're. It's worth watching the videos. Oh, there's a video M. Yeah, there's several videos.
Speaker C: The Right. The writing of this, the Engadget article author, is just brilliant. The company compares them to dolphins that use echolocation. So going through a scan is like being surrounded by half a million tiny dolphins from every angle.
Speaker A: Sure, sure.
Speaker C: The result of the 3D map of your body down to a fraction of a millimeter. That looks a lot like MRIs, but nearly 100 times the speed. All those tiny dolphins.
Speaker A: Dolphins are assholes, by the way. Like that. That does not comfort me at all.
Speaker C: Could you imagine being surrounded by a million tiny dolphins that are echolocating your body down to the millimeter?
Speaker A: If they're tiny, it's better.
Speaker D: Adrian, have you not had a good experience with dolphins or something?
Speaker A: No, I've just read a lot about them, and I'm not going to ruin dolphins and other cute animals for anybody listening to this podcast. But if you wanted to, you could do just a tiny bit of research on dolphins and you'll be like, oh, my God, they are assholes. Wow.
Speaker D: Huh? Huh? Are they, like, bullies or something? Okay, I gotta look this up.
Speaker C: We're gonna have to Google it. We're gonna have to look it up. I mean.
Speaker A: Yeah, yeah, I'll tell you after we stop recording.
Speaker D: Yeah. It sounds like Adrian had a bad experience with the dolphin, though. It's kind of.
Speaker A: No, not personally. I've just read.
Speaker C: I think he's just prejudiced against dolphins. I think he's just prejudiced against Dolphins.
Speaker D: Went to SeaWorld or something and just had a, you know, not a good experience, so.
Speaker A: And the other squirrel story, if all else fails, um, this is a website that allows you to, um, get rid of your angst and just empty yourself of all your problems by screaming at your computer. So it actually invites you to switch to voice mode and scream at your computer. And it's like an animated black hole. And, uh.
Speaker B: Wow.
Speaker C: Yeah, that's pretty awesome.
Speaker D: That's kind of cool.
Speaker A: So, yeah, somebody had some fun vite coding.
Speaker D: Yeah. Yeah, that's cool.
Speaker A: So that's a lot of fun. And with that, that's all the time we have, uh, for this episode of Enterprise Security Weekly. Thank you so much, Eamon and Tyler, for joining me today. It's been a blast. All right, big thanks to everyone watching or listening to this week's episode of Enterprise Security Weekly. Next week we'll be talking to Sandy Bird from Sun Re Security about IAM controls for AI agents.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.