
Microsoft Threat Intelligence Podcast · 2026-07-01 · 1h 3m
Key moments - from our scoring
Substance score
49 / 100
Five dimensions, 20 points each
Casey Ellis, founder of Bugcrowd and co-founder of Disclose.io, argues that we're already in a 'vulnpocalypse' driven by AI-assisted vulnerability research, a flood of new researchers entering the field, and breakdowns in coordinated disclosure practices. The conversation covers how LLMs are amplifying both elite researchers - who gain 'super say' capabilities - and mediocre ones, creating signal and noise simultaneously. Ellis and host Sharad Agrippa discuss the tension between publishing vulnerabilities for accountability and exposing users to risk, the importance of clear vendor timelines and researcher communication, and how altruism is waning among bounty hunters worried about AI commoditizing their skills. Key themes include vulnerability disclosure standards (Google Project Zero's 90+30 model), safety-critical systems like pacemakers that need longer patch windows, and how enterprise attack surface management emerged when bounty hunters exposed forgotten internet assets. Ellis emphasizes that aligning expectations before disclosure conversations begin is the most reliable practice in 15 years of coordinating vulnerability research at scale.
Both. Elite researchers like Pwn2own's Chompy use AI to automate tedious tasks and gain 'super say' capabilities while preserving their creativity, while mediocre researchers are also becoming more effective, creating a simultaneous increase in signal and noise across vulnerability discovery.
Tell the vendor explicitly that you plan to disclose and set a specific timeline (e.g., 90 days), then check in at intervals like day 45. This creates accountability and back-pressure for the vendor to act without immediately exposing users to greater risk.
Safety-critical systems like implanted cardiac defibrillators or satellites cannot be patched across entire fleets within 90 days, so vendors should communicate their realistic patch windows upfront based on their product type, customer base, and ecosystem risk.
In the 1990s-2000s, security researchers had to educate that offensive research existed; now the conversation is easier to have after things go public, but the pace of the entire system has accelerated - everyone's doing stupid things faster with more energy and tools.
Increase the reward further to maintain velocity and activate researchers who weren't motivated by lower amounts, creating a balancing act where researchers get paid better for increasingly difficult work to find.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains genuine practitioner insights - the fireproof-safe reward-adjustment model, the 2026 triage-trash-fire prediction, AI atrophy for skilled writers, and the bug-bounty-to-ASM origin story - but roughly half the runtime is consumed by personal tangents on party planning, sci-fi movies, eye candy bars, and general mental-health discussion that adds zero operational value.
I actually kind of went on record predicting that back in Q4 of last year. Just saying, yeah, 2026 is going to be a triage trash fire for basically the entire Internet
your fireproof safe is now rated to 2700 Fahrenheit instead of 2200 Fahrenheit. It's time to actually increase that reward
A handful of fresh framings land - 'vibe crime,' the fireproof-safe bounty-scaling model, and AI-induced skill atrophy - but the episode leans heavily on stock security-community consensus (AI lowers barriers for both sides, community matters, transparency is good) without first-principles argument or genuine contrarianism.
I think vibe crime is, is definitely...we've seen like a rise in like sloppy but effective, you know, cyber criminal campaigns
the thing that was a tell was like, when I went to write on my own, it was hard...what had happened was there was, like, a degree of atrophy that had kicked in
Casey Ellis is a genuine practitioner - Bugcrowd founder, Disclose.io co-founder, 15 years running coordinated disclosure at scale - not a career podcast guest, and he draws on real operational experience; however the conversational format prevents him from going deep enough to fully showcase that expertise.
in 15 years of like coordinating hacking the Internet at scale like that is the one thing that works reliably
from what I've seen through bug crowds, through working with security researchers, all that other stuff, there's a lot more vulnerabilities out there than I think people care to admit
The episode offers a respectable cluster of named references - Project Zero's 90+30 standard, Pwn to Own researcher 'Chompy,' implanted cardiac defibrillators as a patching edge case, Japan's hackback legislation, Scattered Spider, the Comm - but is largely devoid of hard numbers, CVEs, actual bounty payout figures, or breach data that would make claims verifiable.
Google Project Zero have done a lot around this whole kind of 90 plus 30 standardization
you can't patch an entire fleet of you know, internal cardiac defibrillators that are implanted inside humans within 90 plus 30 days
The host lands one genuinely sharp binary framing ('Is AI mostly making the elite great researchers faster, or is it making mediocre researchers more effective?') and surfaces a good listener question on disclosure timelines, but the interview drifts badly into mutual validation, personal AI-tool anecdotes, and a sci-fi movie segment, with zero meaningful pushback on any claim Ellis makes.
Is AI mostly making the elite great researchers faster, or is it making mediocre researchers more effective?
What's your favorite sci fi movie?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo sits down with Casey Ellis, founder of Bugcrowd and co-founder of disclose.io, to explore how AI is reshaping vulnerability research, bug bounty programs, and the future of cyber defense. They discuss the growing volume of vulnerabilities, the challenges of responsible disclosure, the rise of AI-assisted hacking, and what happens when increasingly powerful tools are placed in the hands of both defenders and attackers. The conversation also dives into the human side of cybersecurity, from community and creativity to maintaining optimism and connection in an AI-driven world. In this episode you’ll learn: How AI is changing vulnerability research for both defenders and threat actors The challenges of responsible disclosure in an age of rapid software development Why cybersecurity experts believe vulnerability volume is growing faster than ever Some questions we ask: How will AI affect individual threat actors, hacktivists, and cybercriminals? What tasks should humans continue doing instead of outsourcing AI? When does publishing vulnerability research help defenders versus help threat actors?
Transcribed and scored by The B2B Podcast Index.
Speaker A: For years, vulnerability disclosure operated on like a weird, uneasy social contract. Researchers found vulnerabilities, vendors patched them, threat actors tried to move faster than everyone else. Things were pretty weird. I come from a time of what we called anti disclosure, which was keep it for yourself and do something crazy with it. So today on the Microsoft Threat Intelligence podcast, we're going to talk to my guest, Casey John Ellis, founder of Buckcrowd, co founder of Disclose IO and one of the pioneers, really on the forefront of the modern bug bounty programs and how we do coordinated vulnerability disclosure. So Kasey spent decades doing this, and we are going to go deep into all of those things that everyone is talking about on the Internet, which is things like AI assisted vuln discovery. What is the future of disclosure? What does ethical hacking mean? Does it mean anything? And special for this episode, this is my first video episode of the Microsoft Threat Intelligence podcast. So for those of you who didn't know what I look like, this is my face, this is Casey's face, and we're trying video for the first time. Casey, welcome to the show.
Speaker B: Thank you for having me, Sherrod. It's great to be on.
Speaker A: I'm Sharad Agrippa with Microsoft, and let's just like, go right into it for sure. What is happening right now? Are we in vulmpocalypse or is vulmpocalypse coming later? Because it hasn't happened yet.
Speaker B: Yeah, I mean, look, I tend to think that we were already in vulnpocalypse. Um, you know, the fact that writing software is hard and there's vulnerabilities everywhere already. Um, you know, this is before you kind of consider all the. Net new code that we're creating at a rapid rate of knots right now. Uh, from what I've seen through bug crowds, through working with security researchers, all that other stuff, there's a lot m more vulnerabilities out there than I think people care to admit or talk about kind of openly in that sense. And what's happening at the moment is that the whole idea of you must be this tall to ride in order to find some sort of issue, um, create a report for it, get it into, uh, the vendor, um, that's dropped a lot. So you've got a whole bunch of new people kind of joining the fun, so to speak, on the good guy side and the bad guy side, um, as well as all of this new tooling that's kind of popped up and dropped itself on the Internet over the past couple of years in the form of LLMs and AI and all that other stuff, it is a lot easier to get to some, uh, sort of outcome. Um, so you put all those things together and there's just a whole lot of crap all happening at the one time. And, and that's, I think, what a lot of us are experiencing right now. So is it volume apocalypse yet? Like, we haven't really seen the Internet can, you know, spontaneously combust, um, just yet. But it's definitely showed signs of wanting to try to do that at the very least over the past couple of months.
Speaker A: I feel like the system is being stress tested. Like, I, I just feel the pressure in all of these institutional systems that we have had for such a long time. Um, let me ask you, you mentioned you must be this tall to ride. So let me frame it this way.
Speaker B: Sure.
Speaker A: Is AI mostly making the elite great researchers faster, or is it making mediocre researchers more effective?
Speaker B: Both, uh, 100% both. Like, there was a really good thread, uh, off the back of, uh, pwn to own Chompy talking about, um, because she's a phenomenal vuln researcher. And what she's gone out and tried to kind of communicate to everyone is that she hasn't kind of replaced her own creativity or process with AI, but the parts of the types of vulner search that she does that are like, tedious or arduous or require just a ton of automation harness, create just all the boring stuff. Um, and she's using AI to get herself to a point of success way more quickly. And she's a phenomenal researcher. So that to me is an example of someone who's already pretty elite. Um, I think she, um, she referred to it last night on Twitter as like, you know, good researchers, ah, now have like, super say on capabilities if they're using lms.
Speaker A: Yeah, she did say that, which I
Speaker B: think is a pretty good way of framing it because the folks that are really paying attention to this stuff and leaning into it, like, they're just, they're just getting more and more efficient and more and more effective, which is really cool on the, on the elite research side, when you've got them working in your corner, um, it's reasonable to assume that the same benefits apply to the bad guys as well, which is the scary part, but that is what it is. Um, but yeah, to your point as like, there's a whole bunch of folk, you know, we've seen this in Bug Bounty. Um, like a lot of the patterns to me are very, very familiar. Uh, because when we first started, like Encouraging bounty hunters, uh, and started really kind of building out this sort of bounty community as a subset of the existing security research community. Back in like 2013, 2014, you have this phenomena of people that get like 12 out of 10 for enthusiasm, but maybe a 3 out of 10 for usefulness, if that makes sense.
Speaker A: I mean, that can apply to a lot parts of life, really.
Speaker B: Yeah, it's honestly, it's not like, uh, I think the, the challenge with it is that they create noise and you have to deal with that noise. And if you're already struggling with vulnerability intake and triage and like fixing and all those different things and, and suddenly you've got this sort of bum rush of really like excited people showing up. Try trying to help you. Um, it's not necessarily their fault and they're not necessarily like malicious or doing a bad thing, but it does create load. So, like, going back to what you just said before about the stress on the system, you know, I kind predicted that back in. I actually kind of went on record predicting that back in Q4 of last year. Just saying, yeah, 2026 is going to be a triage trash fire for basically the entire Internet and pretty much everyone in security because it's just the noise level's gone up right across the board. So, yeah, the signal's going up, but the noise has gone up at the same time is the shorter answer to that.
Speaker A: Okay, so then kind of going back to what you were saying about more stuff coming out.
Speaker B: Yeah.
Speaker A: Where are we? And like, at, uh, what point does publishing the research become simply enabling threat actors? Like, like we're standing on this razor's edge, quite frankly, of are we still doing good or are we doing harm? And that's been a question for a long time, but it's at a velocity now that you cannot ignore.
Speaker B: Yeah, and this is a lot of, like, a lot of what, what we do with Disclose IO is kind of trying to speak in both directions. So trying to actually like, talk to researchers, especially kind of the newer ones on the playing field and help them understand the equities of, of decision making around stuff like that. Because it's to me, like full disclosure. It's, it's like, it's like death and taxes. Do you know what I mean? Like, you can hate it all you like, it doesn't care. It's not actually listening. It doesn't really matter. Like to me, that's like the lowest energy failure state of when vulnerability coordination fails. Um, and it ends up being the option of last resort for researchers that's just kind of there as the default state. So you can't really tell it to not exist anymore because it's just going to happen as a thing. Um, but in the meantime, for companies, the way that they get better at avoiding that is to actually have a good vulnerability disclosure policy. They've got, um, the ability to find where their intake points are. Those are, uh, clear and out there and all other stuff. And then you've got, obviously, a good coordination and management process on the back end of things. Some companies are really good at that. Others suck. Others haven't even really thought of it yet. So, like, when you think about it at a system level, you've got all these, like, like I said before, like, enthusiastic people that, you know, they read a Tavis Ormandy tweet from, you know, 2015 and think, yeah, but this is the thing. Same as what we were saying before. You get, you know, especially kind of younger players jumping in. They just think that that's how you get things done. And in a lot of ways, they aren't wrong. Like, if you've got a vendor that's not responsive, or you, like, really do believe that there's a risk, um, that needs to get addressed, and they're not listening to you for whatever reason. Creating public accountability around that is actually a pretty effective way to get the ball rolling in that sense. But to your point, it does create additional risk for users. There's all sorts of equities that people don't necessarily think through in the mix as well.
Speaker A: Speaking of, of Tavis and 2015, and me even thinking back to, like, full disclosure mailing list, which was one of, you know, we were talking, um, you know, I am talking a lot and thinking a lot about fun on the Internet, which we will bring. Perfect. We will bring fun to the Internet. We will have it.
Speaker B: I love that, by the way.
Speaker A: Yeah, I'm very committed to having fun on the Internet. Um, thinking back, there has always been this disclosure debate. It is something that has raged since the 90s, very publicly. Yeah, everyone's got a point. Everyone's got a feeling, um, what is the difference between disclosure debates from 15 or 20 years ago versus today and what we're looking at coming at us?
Speaker B: Yeah, I think probably two things. One is that, you know, in the 90s and the 2000s, kind of when I grew up hacking the Internet as well. So we both came up in an environment that didn't really understand offensive security research, um, but also was pretty much just afraid of people that could do the kinds of things that we could do by default. And we had to put a lot of work into actually educating the fact that locksmiths exist as well. We're not just burglars here. Um, so I think when you think about how it's all playing out at this point in time, um, it is easier, I think, to have the conversation after things blow up. It's like, no, I was trying to help. Like, this is something that you need to get better at. Like, if you're not thinking about appsec and risk management, all those different things. Like, if your initial introduction to the need to do that is someone kind of coming in through the front door and saying, hey, your baby's ugly, um, that's not an ideal way to start that conversation, but it does get things moving. Right? Um. Um, so I think, like, that's one part because it's. It is. It is a conversation that you can have now. And it's like you're not explaining everything from scratch. Which is, which is good. That's a good thing. I think on the downside to it, like, just collectively, we're all doing stupid things faster, with more energy at this point in time. Right? So, like, everyone's jumping in, trying to help out. Like, the bad guys are trying to figure out how to, how to be more effective. You know, they're seeing, um, opportunities get created in how technology gets deployed that they can exploit for whatever reason. Um, and just in general, like, there's a lot. Like, the overall kind of system that we're dealing with is way more dynamic and way more chaotic and like, like, chaos is a ladder, um, when it comes to, you know, bad guys doing bad things. So I think, you know, again, it's like a confidence. It's not, to me, any one thing, it's the fact that, like, we're already pretty bad at this and we've just turned up the heat on the whole system and we're kind of experiencing that right now.
Speaker A: I put on my social media, which I only use right Now, Twitter and LinkedIn. LinkedIn, whatever. The. The ones. Those are, the ones that I use.
Speaker B: It's always going to be Twitter. It will never be X. I'm with you.
Speaker A: I'm tweeting on Twitter. Um, I put out a call for questions for you, so I want to pull one of those in now.
Speaker B: Yeah, sure.
Speaker A: And this is a spicy one, so I like it a lot. How long should you wait if a vendor is ignoring you before disclosing a vulnerability? What is your opinion? Like, yeah, what, what Is your like, philosophical point of view on that?
Speaker B: Um, my, my philosophical on that is probably not a bad starting point. I think the big thing with disclosure, uh, publishing. So let's start for a sec at the beginning. Vulnerability, disclosure, you've got researcher finds bug, researcher reports the bug, and then at some point in the future, researcher publishes what they found, an advisory comes out. There's some sort of public version of that initial private interaction. And I think I'm clarifying that because calling it all disclosure can get kind of confusing. Um, there are like multiple steps to the process. Right? Um, I think the thing from a publishing standpoint that's most important for researchers to consider is whether or not they've actually told the vendor that they're planning to disclose to publish in that sense. Because to me, that's actually the most important part of that particular piece of the process. Because all of a sudden you started a counter, right? Like you created accountability. Um, the vendor knows that like, when this date comes, you're going to push this stuff out onto the Internet and it's going to become a matter of public record, of public opinion, all other stuff. So to me that's the most important part. And it's honestly one of the things I see a lot of researchers missing because they'll, they'll like fire off a submission, um, they'll, you know, not get a response or they'll get a response that they're not happy with, like whatever might be happening in that, uh, kind of initial reporting interaction. And they just kind of hit the fuck it button and publish it online to kind of move things along, which again is effective in moving things along because all of a sudden you're creating more attention around the problem. But going back to what you said before, at that point you've generally exposed the users to a greater level of risk at that point in time. And for what? If you could have just told them, I'm planning on publishing this in 90 days. Check in day 45. Hey, how's that going? Can you hear me? Are you dealing with this thing or not? Just so you know, I'm still working to this timeline and this is the plan. Um, you get what I mean? I think that that back pressure of the timeline is a really important part of it. The other side of it as well is that like, you know, it's, it's, I think, um, like Google Project Zero have done a lot around this whole kind of 90 plus 30 standardization that they have around software and libraries and hosted systems in particular. I know, like the MSRC has kind of one of the bigger, uh, like let's look at these guys and see what they're doing entities around how this whole thing kind of plays out. Um, the reality is that like, you know, if I'm, if I found a vulnerability in a, ah, in a pacemaker for example. So if you're familiar with you know, the work that Barnes and those folk did, um, you know, may he rest in peace, like all, all the while ago, um, you can't patch an entire fleet of you know, internal cardiac defibrillators that are implanted inside humans within 90 plus 30 days. Like that's, that's not going to work out. So there are I think a lot of different um, particularly safety critical systems and things that involve hardware, especially like satellites are another crazy one. Um, to think about like 90 days is not going to cut it. So you've got to figure out on the researcher side what is a reasonable thing to do. And I think the ideal scenario is when the vendor has actually said this is how long we're going, um, if we get things fixed before this date rolls around, then we'll tell you and we can do a joint publication advisory, blah, blah, blah, but like just based off our products, based off our customers, based off the kind of risk that we assess this whole thing kind of introducing into, into that ecosystem, this is roughly how long we're going to need. I think there is an opportunity for vendors to say that if it's got to be a year, it's got to be a year. Sometimes that's going to be true, other times and I think more often it's actually probably less than 90 days because we are in a position where we can patch like hosted code on the Internet way faster than that. So it's going to be your mileage may vary thing. But I think aligning those expectations before the conversation starts is, you know, in 15 years of like coordinating hacking the Internet at scale like that is the one thing that works reliably. The more, the more kind of aligned people can be on the expectations of the conversation before it kicks off. Nine times out of 10, the smoother it goes.
Speaker A: In your experience, you talk to a lot of bug bounty researchers, that many of them, you probably talk to some, that this is their job, this is their source of income, this is what they do with their time.
Speaker B: Yep.
Speaker A: What is the kind of like mood and temperature out there in terms of like AI timelines? How does that sharpen things? Is there uh, is the altruism waning? And when I Say that. What I mean is, are researchers getting to the point where they're like, you know what? I don't really care anymore. I'm doing what I'm gonna do. Like, what's the vibe out there? Give me a vibe check.
Speaker B: Yeah, Uh, I think, yes, definitely. Like, I think the, like, the altruism is waning in certain areas, especially like, amongst the folks that are, that are doing this for a living, if that makes sense. I think that applies to folks doing vulnerability research, pen tests. Uh, I think that's actually kind of more of a general workforce phenomena right now because everyone's twitchy around how AI is going to affect the kind of value that they can bring that they're getting paid for. I think a lot of people have that question on their mind, and the bounty community is no exception to that. Probably the difference is it's full of people that break things, um, including the systems and the conversations that are going on. So when they get pissed off, they do tend to get kind of noisy all at once. Uh, and you kind of see that on Twitter when you suddenly see this flashpoint, like, oh, my God, why is everyone screaming about that particular issue? It's because there's some version of a thing that's affected one person that everyone else is worried about, and then they just all kind of jump on and start screaming on Twitter. Um, there's a lot more of that that's more frequent at the moment is the, is the thing that I've observed. Um, and I think in a lot of ways that's good because we get to round off the sharp edges of this and figure out how we go forward. Right. Um, but in the meantime, it is like, it is a thing that people can look at and get concerned. You know, I think hunters, just in general, they're definitely the folks that kind of drag their heels a little bit on figuring out how to use AI to make themselves more effective. They're kind of regretting probably not getting into it sooner at this point and playing like, crazy catch up. But yeah, I mean, to me, this is no, like the, there's like the, the version of this that's really familiar is when the bounty hunting community, um, started to cotton onto the fact that, like, people don't know where their is on the Internet. Back in, like 2015, 2016, right. There was this whole kind of phenomena of people getting paid a couple of million bucks a year because they go looking for publicly, um, targetable assets that everyone else has probably forgotten about because they're often some weird Part of the Internet or it's an acquisition that's gotten forgotten or whatever else. Right. For us in the industry, we already knew that was a problem, but it took the bounty community coming along and pretty much setting it on fire to create kind of awareness around it. And yeah, off the back of that what ended up happening was a bunch of people creating tooling and basically the enterprise attack surface management category was kind of born out of that. So at that point in time, a whole bunch of people that were using that strategy to, to make their money, you know, ended up kind of having to compete with the platforms and the different automations and all the other people kind of jumping in and doing a similar thing. This is kind of like that in some ways. I think it's, it's affecting a lot more people in a lot more, different ways all at once. Maybe more than the example I just gave did. But to me the phenomena is pretty much the same.
Speaker A: I've seen a lot of that discourse I think, um, where somebody is like this is my full time career now and then they see things improve in security and say that entire class or that entire category of my financial future just got taken away from me because this became more secure. And it's a bit sour grapes but it's also so like that's what we're here for.
Speaker B: That's why we're doing this in the first place. Yeah, I uh, I spend a lot of time explaining that to people and it can get, I mean it's, it's, it's a weird one because I think again with like the, the history and the experience that people like us have kind of step stepping back from the whole thing. It's like, duh, like why, why we're not doing this because being vulnerable is fun. It's because we want to know where we are so we can fix that. Like that's the entire point. So if you're helping us do that then logically the, the byproduct of it, if you're doing it right, is better resilience and you end up having a harder time finding vulnerabilities in whatever you're hitting up. Right. Um, not everyone thinks that part through because they just come in, they're like, oh cool, it's a gold rush. Like I can do crazy hackery stuff and get paid for it. And as it gets harder there can definitely be sense of sour grapes around that. But yeah, I think it's an important thing to remind folk. It's like we're not doing this for the lulls necessarily we're doing. I mean, there are definitely lulls involved, but that's not really the point. The point is to try to figure out how to make things safer. Um, so, yeah, it's a weird one, I do think, for folks that are running bounty programs in particular, um, as distinct from just a straight vulnerability disclosure program. One of the things, um, that I've always tried to encourage people to do in context of bug crap, but just in general as well. It's like your fireproof safe rating, um, that's like your top kind of reward, uh, offer, if that makes sense. Oh, cool, you're offering ten grand. You started getting a whole bunch of P1s um, in that category with that level of incentive, and now you've made that harder. So that velocity of P1s that are coming in is reducing. Congratulations, your fireproof safe is now rated to 2700 Fahrenheit instead of 2200 Fahrenheit. It's time to actually increase that reward. Um, so that you're encouraging more attention, you're encouraging, you're activating people that might not have been, um, too excited about the reward that you were offering before. And you just kind of keep on iterating on that. And in the meantime, the folks that are doing the work, they actually end up getting paid better for what is going to be more difficult for them in terms of achieving an outcome. So there's a balancing act to it that I think, uh, again, in the middle of this AI slopdemic, I think is the part that we're not necessarily the vulmpocalypse just yet. Um, but everyone's kind of backing off a little bit because it's so noisy. I expect that to pass or to at least normalize at some point in the future. At which point we can start coming back to stuff like what we were just talking about around. How do we reward these folk, how do we actually engage them, treat them like a strategic asset instead of a pain in the ass, because ultimately they can be both. Right? But if we get better at, uh, dealing with the pain in the ass aspects of the process itself, then all of a sudden we can focus back on the strategic asset.
Speaker A: But it's an interesting place to be, especially for, I think, um, you know, I have always been in like network security. I've always been in like detection engineering and threat intelligence, right? Like, watch what the threat actors are doing on the wire. Talk about it, Stop it. So, like a lot of the bug bounty stuff is very, actually New for me since coming to Microsoft over the past couple of years.
Speaker B: Right. Um,
Speaker A: and what the whole new like advent of AI has shown me. First, apparently I'm a software developer now, which is a terrible thing. But oh yes, oh my gosh, I am out there and I am causing trouble and I am telling Claude, you know, build me a million dollar, uh, startup, make no mistakes, do it now.
Speaker B: Yep. Yeah. Uh, and also the trick there is to say Codex is going to check your work once you're done. So look, it sits up a little bit straighter just as a, as a hot tip.
Speaker A: That is a hot T tip. Another hot tip that I have found is to make sure that you have MD files referencing Gemini or one of the other. Yeah, you know, one of the other LLMs while you're having it check your code. I believe. Yes. Everything is based on my weird intuitive myths. I do believe that they are checking that and they are feeling competitive about it. So put them all in there and name them with the competitors names and you probably will get all in a
Speaker B: jar, Just shake it up and see
Speaker A: what happens, you know, and drink it, um, hallucinate it. What? Machine hallucinations are nothing compared to human ones. Um, so, so what I'm finding is that one, um, these capabilities, the, the LLMs are able to write code really well when it comes to things that are not, um, when it comes to things that are public. So it's great at making HTML, it's great at making web apps, it's great at making things that it's probably been trained on that are open source. It's not great at mobile apps because most mobile apps are not available for uh, code review. They're very closed. So I am kind of wondering where you see the potential for the mobile app space to become even more dangerous because these elements are not writing good mobile apps. They're writing things that even I, as a non traditional, um, background person in terms of development, I'm looking at it and going, even as a security nerd, I can see the unchecked input.
Speaker B: Hang on. Yeah, yeah, yeah. Um, yeah, look, that's a fun one because I've always kind of worked off this principle that vulnerabilities exist as a function of lines of code and it's a probability game. Um, a lot of the frontier labs are working really hard. A lot of the reason why you've got stuff like Mythos and Aardvark or Daybreak out of um, OpenAI. They're not necessarily trying to create these master hacking machines. They're actually trying to figure out how to create code that's more secure. Um, and they're learning offense in a model context in order to be able to do that. So you know what that should net out to over time is like LLMs getting better at definitely writing code that's technically more perfect and technically more secure. Um, the bit that I think gets missed there, and this is definitely informed by watching people break the Internet at scale for the last 15 years, is it's not just the code that creates, um, risks and vulnerabilities in these systems, right? You've got implementation issues, you've got your classic kind of developer, ah, working with a really secure framework that makes a particular thing that they want from a feature standpoint, difficult, so they figure out some clutch to get around it and that clutch turns out to be stupidly vulnerable. That happens all the time and that's a function of human incentive. Do you know what I mean? So for as long as people are the ones actually building stuff, to me that's always going to be a thing, um, just because security is hard. So in the short term we're in this place where you know a lot of. I know I'm not speaking specifically to mobile apps here, but I do think it like applies right across the board. Like you've just got a whole lot of people building crap, um, in a real hurry and not necessarily thinking through security because their main motivation is just to get the damn thing to work in the first place and get it out there and you know, have passive, passive income and retire to the Cayman Islands or whatever it is. That's, that's m, motivating them, right?
Speaker A: I'm ready, I'm going to do it.
Speaker B: I mean that sounds pretty great, right? You can understand why this is going on, but it is, you know, like speed is the natural enemy of quality and to me, like security is ultimately quality's child. So like if you've got this acceleration of LOC getting released out into the wild, then logically you're going to end up with more vulnerabilities as a part of that. To me, I guess the thing that'll sort of flush that out over time is figuring out if the bad guys identify that like, oh crap, we've got a whole bunch of really bad mobile apps now. And like as a financially motivated criminal, as a nation state actor, as a, like whatever it is that's motivating me as a, as an adversary, like I can achieve my outcome through that particular kind of net new attack surface, I haven't seen that happen yet. But you know, it's not to say that it won't at some point in the future.
Speaker A: I think, um, there's, there's this idea and it's expressed really well in the Rocky Horror Picture show final Song. And the line is, don't dream it, just be it. And, and I do think that we are in a place right now where as, uh, security professional, if we can dream it, the threat actors can be it. And so every crazy, wild, horrible idea that you have, the threat actors had it first and they're going to implement it.
Speaker B: Yep. Yeah. And this is, I mean honestly, this is what got me into crowdsourcing and bounty and just the whole kind of general concept that became bug crowd, um, in the first place. It's like, you know, white hats or ethical researchers like preloading that question at some point. Um, oh, it's coming. Like folks, yeah, I know folks that uh, are uh, doing this in good faith for the benefit of my glorious beautiful nation of Internet security. Um, they're a reflection from a creativity and a skill standpoint of what their adversaries are capable of. So what you kind of see bounty hunters doing, you can reasonably expect that there's at least some version of that happening in bad guy land. Um, and yeah, to me they do tend to learn from each other, um, either directly or through seeing breaches or seeing threat behavior that gets written up or whatever else. People get ideas and they just kind of cross pollinate. So yeah, if you can dream it, you can build it. Um, I think vibe crime is, is definitely, you know, we've seen, I mean, honestly, we've seen like a rise in like sloppy but effective, you know, cyber criminal campaigns, especially ones that are financially motivated. Like that's been steadily ramping up over the past year. Um, I don't think that'll slow down because, you know, even if the frontier models put really good guard rails on, on not letting their systems be a part of stuff like that, you've got all of the open weight models that are coming out now. You've got the ability to just ask it nicely like 10 times and it'll do it anyway. Um, all these tools are in everyone's hands at this point in time. So that's sort of the world that we're living in now and kind of the world that we're moving into.
Speaker A: And I think, yeah, and I think that I can feel in the general discourse and in the technological releases that are coming out, which are rapid fire anthropic in particular. Is a, a juggernaut machine of releasing products at Velocity.
Speaker B: I mean, and educating their entire dev role base on that too. Like that's the thing that I think they've really taken ownership of over the past period. Sorry to get you off there.
Speaker A: Yeah, so, so I, I see that as well. Like they're not just releasing the products, they're releasing full video, full tutorial, full. This is how you do, this is
Speaker B: how you do the thing. Yeah.
Speaker A: And I have really benefited from that because, you know, I've never built anything before. I have, I have always made this really clear distinction between the makers and the breakers and insecurity. We have a real breaker mentality. And I want to be clear to those of you who are like deep security hard, you know, die hard in your DNA that are listening, spend an hour talking to a software developer and it's like meeting somebody from another planet. They have light in their eyes still. They're excited.
Speaker B: Um,
Speaker A: they want to build features and they want people to use those features.
Speaker B: They're generally grizzled, but like a different kind of grizzled. I think that's probably the way that I'd find it.
Speaker A: They want to do stuff like they want, they want to get, they want to change people's lives. Like they just come from such a different mindset. And I spend a lot of time with developers at Microsoft. I'm leaving next week in fact to go teach a six hour workshop on threat driven software development which I've done 600 now. Developers at Microsoft, they have to come sit in the room with me the entire day. We do give them an open bar at the end but um, they have to sit and learn what threat actors are doing. And so you talking about vibe crime and all of this stuff. Let me ask you, we've always talked about nation sponsored, financially motivated. What's going to happen in the social, the hacktivism, um, the disgruntled individual. What's going to happen with one person now being fully enabled by all these new tools?
Speaker B: Yeah, um, that honestly is the, the wild card that's been keeping up at night probably the most in all of this. And that's been for the last couple of years. I predicted kind of a return of the chaotic threat actor back in 22. I think it was um, just in time for Scattered Spider to show up. You got the comm, you've got all of these different groups that uh, their motivations. I think there's an aspect of cyber defense, particularly when it's threat informed, that does in some ways kind of rely on this idea of understanding what the, what the adversary wants because it's like, okay, if they want to deny service so they can do ransomware, I can predict that and I can start to mitigate the blast radius of that being successful. Like if they're a nation state, they want pre positioning or they want secrets or blah blah, blah, like I'm going to increase detections or whatever else it might be. You know, you do have this, this scenario now where like a bunch of pissed off kids can just destroy stuff because they feel like it's um, or because, you know, they've got someone kind of prompting them in a certain direction. Like the comm was definitely like that. You've got, you know, the hacking games is a group that I'm pretty involved with. Um, and I got involved with that because they kind of stumbled across this fact that like kids are getting recruited on gaming platforms like Roblox and whatever else, um, and basically brought into, you know, either economically driven cybercrime or into groups like the con that are just out there to cause major mayhem. Right. So like, we can't necessarily, like, it goes back to the whole like, you must be this tall to ride problem. Um, it's a pretty low bar at this point in time, which means you've got folks that can just sort of sit at home and say, you know what, I'm pissed off about this thing, I'm going to go try to break into it. Um, that's pretty easy to do at this point. So yeah, it's, it's a, it's an interesting time because I do think, you know, LUL's motivated hacking, like chaotic threat actors. Like, you know, the, the kind of you think about stuff even at the international relations level, um, you know, the, the cyber army of Ukraine, uh, when that kicked off and it's like, cool, let's like crowdsource a whole bunch of people on a telegram channel to go like, mess up Russia. Um, interesting. Um, probably like illegal in a lot of ways, but given the conflict and given all of the things, it's like, yeah, that's just, we're just gonna let that fly. You know, watching that play out, it's like that cat's out of the bag now. So if you've got like nation on nation disagreements, all of a sudden you've got this entire corpus of people that can get kind of swept up into that and basically put to work for the sake of the fight. A lot of the historical Title 50 and Title 10 assumptions, we've had around cyber warfare, I think are in the process of going out the window. Um, and yeah, like all of these different things, again, it's like everything's sort of moving around really quickly. I think the cool thing going back to what we were just talking about with, if you can dream it, you can do it. Um, one of the things I've loved about this whole AI thing is seeing hackers, seeing people that aren't, uh, platform builders. They can build stuff that breaks other stuff, but they're not necessarily a solution or a product builder in that sense. But they have such deep understanding of what the problems actually are that if you put the ability to code in their hands, they can just go off and start to build things that might be a part of the solution in the future. And I've seen that at hackathons. I've seen that through like different offensive AI conferences I'm, um, part of and stuff like that. That particular trend to me is like the bright spot in all of this. But yeah, there's a lot of pretty crazy that's sort of bubbling up at this point in time. And I don't see it getting any less crazy, um, just because there's so much energy in the system at this point in time, like international conflict, plus all of this capability, plus all these different reasons to do it, plus I'm not sure if AI is going to take my job or not, blah, blah, blah, blah, blah. You've got like a whole bunch of like, heat under the pot that I think creates some pretty unpredictable, you know, actions. As a byproduct of that, I'm, um,
Speaker A: really, I feel like, anxiously awaiting what the shape of the future is going to be.
Speaker B: I think just about everyone's in that boat right now.
Speaker A: But yeah, and as I think I am discovering, I am trying to have fun with it. I, uh, you know, I, I think security professionals, if you have a security personality, which, it is a controversial hot take, but I do believe that there is something inborn. I do believe that there is a psychological, uh, profile of people who are in Infosac. Um, if you have that profile, you are prone at times to modeling, to the malaise, to the ennui, uh, to, to being bummed out. Um, yep. Uh, to, to go even deeper on that. I think that stress, uh, and anxiety has a rebound effect of depression. So like, if you're constantly in firefighting and incident response mode, once things kind of calm down, a lot of those people go into a deep depression. And if you're not careful it can really eat you up.
Speaker B: Yeah, adrenaline. Adrenaline is super useful, but it's a bad diet. Um, and I think the same goes for cortisol, and we're all kind of junkies for that if we've been around this space for long enough. So, yeah, I think that's, that's. Honestly, it's one of the things I've, I've really enjoyed about watching your whole, like, let's make the Internet fun thing. Because, yeah, I've always said this. Like, I take the problems that I get involved in solving, like, really seriously and really personally. Um, but I also believe, like, if you, if you can't, if they can't at least be some sort of sense of gallows humor. Um, especially if you've, like, stared all the way into the abyss and had it blinked back, which is the position that a lot of us that have been around for a while now now find ourselves in. Like, you've got to be able to laugh about stuff. You got to be able to take yourself seriously, but not too seriously. Um, I actually think that that's a really important. I mean, I just enjoy being like that more than not anyway. Right. But I actually think it is a, is a really important resilience strategy.
Speaker A: Yeah. And, like, for me, I think I take the work super seriously. I take the threat landscape super seriously. But I try not to take myself too seriously. I try to kind of what I am calling whimsy maxing. Um, I try to have a, A sense of, uh, levity about it because ultimately, a lot of what we do is truly absurd, uh, insecurity. There are people whose jobs are to, like, break into things and wreck things and make the world worse.
Speaker B: Yep.
Speaker A: Our job is to just stop them from doing their job. It's a, It's a weird place. It's a weird place.
Speaker B: Yeah, I, I, I mean, I fully agree. Like, my, you know, some of my favorite people in the world are, uh, cybersecurity entrepreneurs. Um, you know, and it's partly because I just, I love inventing stuff and helping people build things and growing and all that kind of, like, that's something that I just get a lot of joy from and, and do pretty well at. But the other side of it is that, like, you know, these are people that can, like, look some pretty dark stuff in the face, um, and kind of stare at it until it blinks first and then decide, okay, I'm going to do something about that. Um, let's, let's go, you know, have, like, let's go, like, Deliberately engage this sense of optimism around the fact that there might be solutions for stuff. Go pursue that. Then bring people around that can have fun along the way. Um, they're awesome because, like, we're all a bit nuts, right? It's like, oh, no, we've seen some really, really dark. Yeah, that's. That is. That is a part of, like, the job. Um, and I think people outside of it don't necessarily, uh, grasp, you know, how dark it can. It can get sometimes. But, like, someone's got to do it. So there's that, and that's mission and purpose and the cortisol and the adrenaline stuff, which we're just talking about before. But then in the middle of that, there's opportunities to actually, like, make things better and, like, deliberately engage optimism and humor and just. And, you know, staying up until 3am at the Mandalay, you know, every August, like, all that kind of stuff is just all a, uh, really fun part of, I guess, the community and really important to just, you know, see it continue to be resilient as we go forward. Because going back to what we said before, we're just going to need more of this. Like, this is not going away. Um, and I love that because I love working on these problems. I love the people I get to do it with. Um, you know, these are some of the things that I think actually make that possible.
Speaker A: I agree. I think shout, um, out to eye candy at 3:00am Um, I think, um,
Speaker B: if, you know, you know, if you
Speaker A: know, you know, um, what's funny about Eye Candy to me is that you're probably not getting a drink. It's not coming. Like, whatever you ordered is not coming. So it's not exactly one of those places.
Speaker B: It comes from the person that goes over to the, like, the little mini mall thing.
Speaker A: Yeah. It's like I brought these back. Um, yeah, they're not the service there. Um, but I think what you're saying too, is that ultimately community is so important and having, um, the support of people who are in that same fight with you and are experiencing the same, um, bewilderment. I joke frequently. Is it a joke? Is it true? I don't know. I joke frequently that I have the AI psychosis. Um, I don't feel that I'm being, like, tricked by an AI chatbot. I feel like I am entering a psychological space of like, wow, this is a lot like this. This is big. And it is almost too big to behold in some ways.
Speaker B: Yeah. Um, I mean, the community thing, like, that's. That's something that I actually get. Like, I've always been huge on that. Um, duh, like Bug Crowd is like literally a gigantic community that we're trying to put to work. So I've definitely got some biases in this area, but the whole idea of community as the thing that one can go fast, but many can go far, that whole kind of management and leadership principle, I think community is the thing that ultimately powers that when you're doing the kind of stuff that we do. Because, yeah, you get to share the dark stuff and the gallows humor. It's the same thing with doing startups, having other founders around you that are going through. Through the same like really difficult set of things that like most other people don't actually understand because they don't, they don't do this. Like, that's not their fault. But to be able to have your peers together, to be able to just have that support network, I think is critical. But then the other side of it is that like, everyone's smarter than, you know, the sum of the parts, I think. Yeah, like the, like the opportunities to actually. Oh, I hadn't thought of that. Um, or, oh, you've just challenged my worldview around a particular problem in a way that I probably wouldn't have gotten to myself. But because I'm in community, um, and we're talking about this, or having like a robust 3am eye candy conversation or whatever it might be, it's like I actually learn and grow from that and hopefully the other people do as well. Um, you can't do that on your own. And yeah, like, AI is definitely. A lot of this stuff's public now. But in terms of the early days of training these models up, they would have basically mandatory breaks from models, um, for that exact reason that you just called out this whole idea of I've tripped over down the Alice in Wonderland hole. Um, and I actually need to reset what my sense of reality is. Um, the Internet's been like that the entire time. I think AI is a particularly. It's a version of that that has a lot more gravity to it than I think anything we've sort of dealt with on the Internet before. Um, save May, maybe social media. Um, yeah, so community is like an antidote to that. And I think it's the thing that takes us all forward at the same time. It's like, yeah, we're playing with this stuff and actually digging into it and seeing it how, seeing how it can help us, seeing how we can use it, seeing how it grows. What is the Shape of the future, that's another good one. No individual person, I think, is going to figure that out. Everyone's going to have their own thesis, and then you kind of bump those thesises off each other and all of a sudden you come up with something that's a little bit more accurate towards where the future actually goes.
Speaker A: I think too, something I've been thinking about a lot is that I want to preserve humanity. I want to preserve our humanness. And computers can't have fun. We can have fun, we can care about things, we can have emotional responses to things, but ultimately creativity, innovation, new thoughts, new directions, all of those things are going to come from humans. You can't, you know, say, oh, we've trained on everything that's been published in the past and think you're going to come up with something new. And so I really want to encourage that. And people that are listening and people that I meet that like, yeah, we have uniquely human characteristics and those are ever more in desperate need.
Speaker B: Yes, yeah, yeah, 100%. Like, we're going to end up with this layer of beige right across everything. And I think it's really important to, um, to acknowledge that, uh, you know, just in terms of how things accelerate, like, the role that AI plays in, like, humans interacting with each other, with the world, like, those are all things that are going to happen over time. Um, but it doesn't mean that as the human, you become a part of that. Like, we should be staying on the wire, not, not in the wire in that sense. Um, I love the fact that, like, there's, there's almost an antithecal, like, element to security research. Everyone's like, oh, we can use AI to, like, make all the security problems go away. It's like, well, the bad guys are still people. Um, and ostensibly we're here doing what we do because of them. Um, they're not about to pack up and go home. And if we make everything that they're using to be successful today impossible for them, it's not like they're going to stop innovating and applying creativity offense. So it's like that's kind of the opposing force that we're here to basically balance out. Um, creativity is like a core component to that. And like you said, you can't replace it. You can accelerate it with AI for sure. Um, computers are great at pretending to have fun or creating some sort of counterfeit version of fun, and that's fine every now and then, I think, but, um, choosing consciously not to fully get sucked into that Wire. I think it's a really important thing. It's something that I think about a lot and actually try to be really deliberate with because I can definitely go down a C hole and. And like, you know, all of a sudden it's 5am and I'm completely detached from reality. Like, that is a thing that happens
Speaker A: from time to time.
Speaker B: So it's like, all right, what are we going to do about that?
Speaker A: I want, I just want everyone to understand. Casey's experiencing it. I am also experiencing it. You are not alone. We are falling down into AI um, never ending pit on occasion at 5am and. And I would say one of the great things that I'm trying to do to combat that. Conscious about where I want to employ connection.
Speaker B: Yeah.
Speaker A: And where I don't. So I'm thinking about, like, putting together, I don't know, like a party M. Do I want to immediately go to chat GPT and start planning a party or do I want to send. Yeah, like. Or do I want to send unhinged texts to my friends and be like, what if we had a party and everyone had to dress as their favorite? What? Like, where are your opportunities to have human connection that will fulfill you and fill you up and, and motivate you, empower you and, and give you the courage to face another day? And where do you just need utilitarian immediacy?
Speaker B: Yeah. So Dan, Dan Meisler has a really fun way of framing this. Um, no robots in the gym. Right. So it's like, like the idea that, like, if you're a factory worker, then, you know, your job is to like, move the thing around and whatever you can use from a technology standpoint to reduce the cost of doing that and to make yourself more efficient is a good idea. Um, on the other hand, if you go to the gym, like, the whole reason that you're doing that is because you want the resistance. You want like your own kind of personal interaction with, with weights or whatever it is that you're doing. Um, and to get a robot in to do that for you would completely miss the point. So this idea that is this factory work or is this me going to the gym, kind of applying that kind of mental model to it, I think is a really fun thing. I found that with writing. Um, I definitely had a period a little while back where I was leaning on AI I think in hindsight a little bit too heavily to help me with idea creation and getting things together and all that kind of stuff. It's super useful for that. But the thing that was a tell was like, when I went to write on my own, it was hard. It's like, what, uh, hang on. What happened? I'm good at this. Like, and. And what had happened was there was, like, a degree of atrophy that had kicked in.
Speaker A: Yeah.
Speaker B: I'm m. Like, oh, man. Okay, that's not good. So I kind of pulled back from that. And same with party planning. Like, chat GPT, like, how to party.
Speaker A: Good.
Speaker B: Um, I think the unhinged text version is probably going to net out to a better party at the end of the day anyway. So it's like, all right, I'm deliberately engaging, engaging in. In that kind of process just to, like, set some markers up and create some boundaries and do all that kind of stuff and still take advantage of all this because it's powerful and it's super useful. But, like, using it for what it's good at and then maintaining your engagement with the things that give you joy and that you're good at. I think that that sort of separation is a really. It's a good thing to think about and not something that people are talking about enough right now, I think.
Speaker A: Yeah. I think about it a lot. Like, using that party example again, like, I'm happy to let it do the labor of, like, making me a grocery list list or me saying, okay, I'm gonna have 30 people at my house. How much food do I need to get? Sure. But what crazy things are we doing? How wild can we make it? What weird things should I ask people to bring? That's a group chat conversation with my human friends.
Speaker B: Yep. Agreed. Agreed.
Speaker A: Um, so.
Speaker B: So I feel like we solved that. That's good.
Speaker A: We solved it. Oh, we're making progress. The humans against the machines. We're gonna win. Um, what's your favorite sci fi movie?
Speaker B: Oh, uh, Children of Men.
Speaker A: Oh, no, that's your favorite. Are you okay?
Speaker B: I had to think about that, and I nearly caught myself saying it. But, um, just as a. It's dark and all that kind of stuff, but it's just such a beautifully constructed film.
Speaker A: Yeah.
Speaker B: Um, and I kind of appreciate that. Like, there's a bunch, um, in the mix, but I do love that one. Probably Matrix. Matrix would be. Would be the other one, which is, like, age appropriate and all that other stuff. But I still remember the feeling of sitting in a cinema, um, like, skipping school to go and watch it, uh, back in the day in Australia. And it still hits me kind of the same.
Speaker A: Um, I am a huge Kubrick fan and I always have been, and 2001 has just been. I think about it all the time. I'm doing, um, spoiler alert. I'll be giving the keynote at RBA SAC at the beginning of June, and I'm going to heavily kind of make some parallels between where we are with 2001 and reality today. Um, tell me. We have a lot of questions that came in. I want to ask one of these before we have to wrap up.
Speaker B: Sure.
Speaker A: This is from a former guest on this podcast, Greg Lesnowicz. Uh, for those of you listening, go check out the episode between two Gregs. It's a DPRK focused, um, expertise episode. It's real fun.
Speaker B: Oh, that's fun.
Speaker A: Asks. Yeah, the bringing on two DPRK experts is very wild, especially asking them all these cryptocurrency questions. And they're like, yeah, we just, we don't do that. And I'm like, but shouldn't you know about cryptocurrency? Like, yeah, we probably should, but we don't. And I'm like, okay. So, Greg, a, um, great friend of mine asked for Casey. What do you wish that the future of threat intelligence could be? What do you think would be kind of the ultimate form in the future that we could have?
Speaker B: Yeah, um, I think. As much sharing and as much transparency as possible. Um, just as a default kind of design state. Right. Like, I've always been big on this idea. Um, you know, Kirchhoff's principle in cryptography, like, the enemy knows the system. System. Uh, so if you're keeping things secret, that secrecy is inherently fragile, and when it fails, it fails catastrophically at some point in the future. Like, the antithesis and the antidote to that, the antifragile version of that is transparency and openness. Um, in ti. That's really hard to do sometimes, because sometimes you got to keep stuff under your hat. Uh, but I think trying to get to a point where there's as much sharing and kind of goes back to the community stuff we're talking about as well. Like, there's group think that can be applied to, to defense and to counter operations, to all that kind of stuff. Um, I think that's, that's a utopian kind of picture of things, but definitely something that I believe in and I think is really important. Um, I think threat informed design is going to get more important. Um, just this idea that, like, we can't get around to fixing all the vulnerabilities that we've got, and we need to just assume that a bad guy is going to be successful. So how do we design around that instead of just assuming that we can keep them out 100% of the time? Um, using threat intelligence to actually inform that and to have it more tightly integrated with design, architecture, build engineering, all that kind of stuff is a utopian version of mine, um, or a utopian outcome that I quite like. Um, probably the other is. And this is less of a utopian ideal state, but I do think that there's a lot of policy and legislative shifting going on at the moment to, uh, enable, you know, things like hackback and disruption. Um, I'm not necessarily a fan of that because it's messy. Um, but. But we do seem to collectively be heading in that direction. Like, Japan passed laws, Australia is looking at it, a bunch of EU countries are looking at it, the White House is saying stuff about it. You know, we are going to get to a position where it's like, all right, we're actually going to take the fight back to the bad guys. Um, from a threat response standpoint, um, there's a part of me that's terrified of that, but a part of me that really likes it, because I do think we've been sort of sitting on our hands in terms of being able to actually deal with a lot of this stuff. In a lot of ways, it has been very reactive. I think it becoming more proactive in the future. I'd love to see a productive version of that. I guess
Speaker A: it will be interesting, I think, if there is one. When one policymaker, whether that's a nation or an organization or what, when one policymaker goes, I think the others are going to come very quickly behind.
Speaker B: Yeah, Um, I mean, Japan. Japan broke rank on. On. On that 12 months ago, 15 months ago. And like, you think about their geography, um, you think about some of the stuff that's slated to happen next year. The timing kind of makes sense. Um, I think that definitely triggered a whole bunch of policymaking in other parts of the world. Like, there's been a version of this, like a letters of mark law in Congress for a, um, couple of years now. And there's, like, revs of that happening. There's work on this type of thing happening inside the White House. Like, it's. It's heading in that direction, I think.
Speaker A: Final question.
Speaker B: Shoot.
Speaker A: What still gives you optimism?
Speaker B: Uh, people. People. Honestly, people.
Speaker A: Humans.
Speaker B: Come on.
Speaker A: Humans.
Speaker B: You know, I love technology. I love criminal creativity. I love, like, peering into some of the. Some of the, you know, the dark edges of the stuff that we were talking about. Um, like, I enjoy, like, intellectually And I enjoy kind of at a, like an outcome level, all that stuff. But I think the thing that I always come back to, um, that makes me smile and makes me optimistic is just the fact that I get to do this stuff with incredible people, um, that are all like a little bit unhinged and all super motivated and all completely imperfect but wonderful, Um, I think that makes me optimistic and even looking at the next generation that's coming through and the opportunity for our generation to actually help them with some of the rough edges that they're going to experience. Um, but at the same time getting to learn from the things that they see that we don't. Because, like, we're not like, native to the technology environment they're growing up in. Like, it's all community, it's all people. Um, yeah, I love that. I think computers on their own would be kind of lonely and boring at the end of the day. So the fact that we get to sprinkle like awesome humans on top of all this stuff and do it all together, I think that's something that I love about it and something that definitely gives me hope.
Speaker A: I love that. I agree. I really, um. One of the things about this new AI enabled feature is that I hope it does have a return to how people feel, where intuition comes from. These very unique things of warmth and humor and hunger and feelings and being able to kind of wrap ourselves around that instead of cold, hard silicon.
Speaker B: Like, yeah, I think that there is a, uh, there's an opportunity in all of this to just be a lot more deliberate. Do you know what I mean? Like, I do. I do feel like there's almost like an analog kind of renaissance coming at some point in the future where everyone's like, oh my God, we've been sucked all the way into this thing and it's kind of annoying. So, like, let's not rebel and burn the whole thing down, but like, just be deliberate about disengaging and connecting with each other and, you know, doing things that feel good and that make other people happy and all that kind of stuff. Stuff. Um, I don't feel like we're quite there yet. I feel like we're still in the, like the vortex part of it. But. But I do see a point in time coming where that becomes like something that folk are a lot more deliberate about. And I like that idea.
Speaker A: I like it too. I. I encourage everyone to be intentional. Set your intentions before you start anything.
Speaker B: Um, also a recipe for a good vulnerable disclosure or bug bounty program going right back to the start.
Speaker A: So to set your intention, Set your intentions. Okay.
Speaker B: Y.
Speaker A: That's a good tip. Kasey, this is fantastic. Thank you so much for coming on the Microsoft Threat Intelligence podcast and helping us figure out kind of what is strange and important and what we're doing and where the industry is going. Really appreciate talking to you.
Speaker B: It's been a really fun chat. Sherrod, thanks for having me on.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.