The AI Security Window Is Closing
AI-enabled cyberattacks are already here, and the window for defenders to respond is short. That's the claim in the OpenAI open letter signed by hundreds of organizations, including direct competitors. Max, Seth, and Cody get into why you should treat this as a capital-I Incident, why technical debt bites first, whether the defender's window is real or a very good sales frame, and what Dario Amodei's subsequent pacing essay changes. Read the open letter
WATCH / LISTENA round-table on the security stories everyone's talking around. The panel takes the position most people won't say out loud, then argues it out. Part of Galactic's Threat Aware.
Transcript
Auto-generated transcript, apologies for any errors. Download as text
Cold open
We haven't had the blip yet. The one big event, and it's coming, I think. The one big event that touches the entire world.
Narrator
This is Unauthorized Opinions, part of the Threat Aware Podcast Network, where the Galactic Security Team says exactly what's on their minds. Unfiltered takes on the cybersecurity threats, trends, and stories that matter most to the people defending real organizations. Here's your host, Max Kurek.
Max Kurek
Welcome in. We're glad you're here. I'm joined as always by Seth Loe, Galactic's President and Chief Security Officer and Director of Security Research, Cody Kretsinger, here for another episode of Unauthorized Opinions. Guys, how are we feeling today? Cody, how's everything going? How's your week been?
Cody Kretsinger
Yeah, it's been crazy already. I'll be honest. For it we're recording this on a Monday morning. It has been a crazy Monday morning already. And that's okay. It's just that's the way that it usually ends up being. And I am excited for this particular episode because I know Max, there's a lot here to talk about, a lot to unpack. And if you want to talk about just being relevant in the news right this second, I can't wait to unpack this.
Max Kurek
Seth, probably not a position that you're unfamiliar with. And I know that there's a lot, like Cody said, that we have to unpack today and I know you're you've got some strong opinions on what we're gonna be discussing.
Seth Loe
I had a family member turn eighty years old this weekend and we went to they had an organized party in a big barn sized garage, chairs around the perimeter, food, the whole bit, and just octagenarians as far as the eye could see, Septuaginarians leaning up b next to them. And guess what I had to talk about for four hours at an eightieth birthday party with every little group. I encountered.
Max Kurek
Yeah. Why my computer won't turn on.
Seth Loe
Yeah, it's Seth is AI gonna kill us in the next six months. I had that conversation like s no less than six times on Saturday afternoon, and you know, that's what I wanted to talk about, but let's see how it goes.
Max Kurek
Yeah, not the way all the eighty year olds were thinking they would go out getting
Seth Loe
Something to me that 70 and 80 year olds have heard this, they want to know. They still had a very you know, we have had some very technical, some very cybersecurity governed conversations with the folks that we work with in week and week, you know, week in and week out. We're having problem solving style discussions around this issue. How can we secure things and do all that? They the I guess I would say the zeitgeist, if you can use that term with 70 and 80 year They are still very much in the sci fi reality side of this.
They went back and forth between different degrees of panic of like, what is this real? Are we in trouble? Tell me please, are we in trouble? Or ha, that somebody's been watching too many movies and not taking it seriously enough. Striking that sort of middle balance this weekend was a little difficult.
Max Kurek
Overwhelming majority of people, when they read the news headlines and they're thinking about subjects like AI extinguishing them from this earth, they're thinking truly in like Terminator context, right? Like that's how they envision this. But to your point, and we're not gonna get super deep into this side of it, but I think I want to mention this really quickly, because I've been reading a lot and hearing a lot about just overall sentiment around AI. There have been some research firms that have put out numbers that indicate AI has risen up the importance ladder faster than any other issue they track when it comes to surveying people, ahead of things like climate change and childcare and a lot of the social issues that you hear about in the political discourse.
Like AI and what it means for our world is an issue that in the last year has exploded in terms of people's awareness. And clearly that's not im limited to any single age group as it sounds like you learned very well this weekend. And the
Seth Loe
The flip side of that is that their children, their great grandchildren, their grandchildren in those conversations. And I'm speaking specifically to Gen Z and Gen Alpha here, where very much, I'm not going to get in this. I'm not going to trust AI. I'm not going to use it. I don't like it. I want it out of everything, which is such an unusual flip-the-script kind of reaction on what the younger generations tend to do with technology. Because our generation saw pocket cell phones, smartphones, internet service, and we're like, Gimme more, give me more, give me more.
I think that to your point, Max, talks about like what happens when a rocket of an issue like this takes off. I would have thought it would have been the older generation saying, Stop, not gonna do it, too fancy, don't understand it. And the younger generation's going, Give me more, give me more. And that is not what I saw this weekend.
Max Kurek
We're going to be very AI focused on today's episode. And there's a couple of reasons for that. There's obviously been a ton of stuff in the news, and even over just the past three to four weeks, some of the developments from AI adoption and AI security perspective are really, really significant. And we need to talk about them. We've been talking about them with our Galactic Partner base for a couple of weeks now. Seth published a blog last week around on this topic and what this topic is guys is at the end of August OpenAI published an open letter and it went on to be signed by hundreds of different organizations.
Galactic is one of those organizations, but Anthropic, Microsoft, Google, a lot of the big security providers, Cisco, CrowdStrike, Sentinel One, have all signed on to this open letter. And I think Right off the bat, that's very telling 'cause you've got a lot of competitors that are in that mix. You've got a lot of companies actively participating in this AI arms race, right? It was a authored by OpenAI, signed by Anthropic, signed by Perplexity, a lot of these other businesses. And at its core, what the open letter claims, and we'll include a link to the open letter in the description notes for the show today.
So if anyone hasn't read it, Homework assignment number one from listening here today is to go read the letter. But it basically amounts to saying that in the coming months, AI enabled cyber attacks are going to become far more widespread, far more sophisticated, and that's going to happen in a matter of months, not years. Critical infrastructure is going to be particularly susceptible. And this really what it boils down to is a collective call to action. On the part of every business and every organization that is protecting their critical assets and needing to prepare for this moment.
The three basic principles status quo security, while important, are not going to be enough. More defenders need cyber capable AI, but the most important thing is, and this is the point to stress, the response has to be collective, right? There's a reason this was published as an open letter. There's a reason all these companies signed on to it so far, is because doing this in silos or doing only pieces of this defensive security work is not going to have the impact that it needs to have. And this really needs to be collective action. And so what I want to start with, guys, and Seth, I'm-I want to come to you first on this question, is you've read the letter, you've digested it, you've put out, again, a couple of different you put out a blog on this.
You recorded an episode of the risky bit. If you guys haven't listened to episode two of the risky bit, just subscribe to Threat Aware. You'll get access to it. It's really, really compelling. But I guess what I want to ask you on this front, Seth, is why is it so critical for folks to read and understand this letter? And what from your perspective is the most important thing? If I'm a business leader listening to this, if I'm an IT person or a technology person, or if I'm just somebody who cares about the safety of my personal information online.
Why do I need to read and understand this letter? And what's the most important thing or two for me to do in response to this?
Seth Loe
I think the single most important reason for everybody to read this letter is to get a sense of why this is a collective action moment. There are periods of time in the world where you can say, wow, that's a big problem, but I think the government's gonna take care of that one. Or, wow, that's a big problem, but it's on that side of the world. And that company should take care of it. Every once in a while, issues come up that are so big, have the potential to have so much impact. That they generate the amount of discussion.
You know, the level of discourse that we're seeing on this issue right now is through the roof. I haven't seen anything talked about this consistently since I think maybe Facebook launched. And you could be in a restaurant and you could hear the table next to you talking about have you been on Facebook yet? So find out why it is that this isn't a let somebody else worry about it problem. You know, you you'll see three groups addressed in there. You're gonna see government. Cybersecurity defenders and then this everyone category that says what everybody should do about that.
And what everybody should be doing about that is talking to the people who represent you. Talk in your businesses. I mean you don't have to be the owner of the company or the CEO to raise this issue in your meetings. You know, I think 2020 to 2030 is the decade of meetings. We meet all day long everywhere. Bring it up. Ask what are we doing about this? How are we taking this seriously? What are the things that we expect to see change? Because when you look at this call for collective action, one of the things it says in there and one of the things we subscribe to, one of the reasons why we signed it, is that this moment in time should be treated as an active incident.
I'm currently sitting under a boil order right now that was due to a pressure problem. And I'm sitting here like trying to find out everything I can about whether my local municipality had their PLCs out there on the web. And have I am I right now boiling water on my stove to drink because somebody got hacked? Ask the questions what are we doing about this? How are we responding to this?
Max Kurek
If the people that you're expecting to be asking you questions about this stuff and bring it to you haven't been doing that yet, that's definitely something I would take note of. That's a bit of a red flag. But just to emphasize, like raise these points on your own because you if you've if your head's not been buried in the sand, and we're gonna talk about some of the noteworthy happenings, especially over the past couple of weeks. You're hearing about the risk in real time. You're hearing about it from folks on the AI side of the aisle, if you will, or maybe folks that were at one point on that side of the aisle and have since either voluntarily, mostly voluntarily chosen to move away from that side of the aisle.
But the stories are only going to become more and more prevalent. And the conversations need to be had. And if the folks that you're expecting to bring those conversations forward are not. Take it upon yourself and then think critically about whether the people that you're expecting to bring this stuff forward are not holding up their end of the bargain and what you need to do about that. Cody, coming over to you. A lot to unpack from what Seth just said, but what's your kind of take overall on the open AI letter and why folks need to read and understand it and some of the things they need to consider doing in the aftermath.
Cody Kretsinger
The importance of actually treating this like a an incident. And anybody that's been through incident response classes with me understands that I put it in three different categories, right? There's the event which is something that is treated on a day-to-day basis. There's the lowercase I incident that it's priority, but it's not you know, it's not a big deal. Then there's the capital I incident, the capital I incident being the one where the organization needs to stop. Needs to understand exactly what's going on, needs to take this very seriously. We usually reserve the capital I incidents for like big ransomware outbreaks, things along those lines.
This is a capital I incident and it needs to be treated as such. The organization needs to pump the brakes and figure out what they're going to do when it comes to the this letter. And we'll get into more about this, but The letter actually outlines a few things that you can do that really aren't all that forward thinking. And what I mean by that is they are things that every organization should already be doing. And there's a very specific reason why if you're not already doing some of those things where it might come back and burn you a little bit.
So my big one takeaway is treat this like a capital I incident. Make sure the organization prioritizes this, make sure that you're following the basics, which we'll get into in a little bit, and then also understand the organization's role and everybody's position within the organization as it relates back to AI itself. So those are just quick high level observations from this particular letters.
Max Kurek
And to add some color to what you're talking about with getting back to the basics, the letter is pretty prescriptive in this regard, if not super specific from a high level, lots of good back to basics things for everybody to keep in mind. Longstanding bugs that have been sitting in the environment, places where you have excess excessive permissions, misconfigurations, unpatched software, any tech debt sitting in your environment. Like these are the basics. And here's the thing, guys, everybody listening, when I just said that and when Cody said that. Everybody listening to this podcast, I bet you had one thing pop into their head right away.
A thing that they've been thinking about from a security perspective that's been living inside of their environment that their security advisor or security vendor has been talking to them about for a couple of months that's still sitting there, that still hasn't gotten addressed. There has never been a stronger call to action to go address those things. There's also never really been, certainly in the past, gosh, past number of months or years, A more compelling reason for you as a security advisor or somebody who's providing security to a business either internally or externally to go back and revisit a lot of the security conversations that have gotten stale, the things that you've been pushing on for months and haven't gotten movement on for one reason or another.
It we're too busy. We don't have the budget for it. Like this is a critical moment, just an inflection point in the security landscape generally, and it's a perfect reason. To go back and revisit those conversations because you have new evidence as to why this has to happen now. And this defender's window that the letter talks about being months rather than years ascribes urgency to it that you don't even have to take on as your own.
Seth Loe
To talk in some real terms about a phrase that you dropped there that I think maybe have sped past some people, and it is the phrase technical debt. What is technical debt? And code developers, you know tech debt, you use this word all the time. When you're talking about code that you needed to fix a long time ago, it's limping along, and you just never have had the motivation to go fix it or things you were thinking about improving. Tech debt. Is the argument you've been trying to make on replacing old versions of Windows server operating systems that are laying around with critical data on them?
It is that piece of network security equipment that you bought six years ago, threw it into the rack, and forgot about it. That is your tech debt. It is those desktop operating systems that are still floating around the network, that are still sitting in key locations, that are running Windows 10. Dare I say it, Windows XP, Windows seven
Max Kurek
I was gonna say I don't know if you went far enough Windows ten.
Seth Loe
Because it runs one of those pieces of software that somebody bought a lot of years ago. It can't run on upgraded operating systems. They kept it around on Windows seven so that they could continue to use it. That old software that cannot be updated, that old software that you just have never gotten the budget together to replace, this is such a key place where this tech debt is going to bite you. It is the insecure system that you have defended, that you've made excuses for why you want to keep it. You've made excuses why not to budget to replace it, because it just keeps working, right?
Tech debt sounds a lot like it ain't broke, don't fix it. If you've said that about any of your systems, and now I'm talking to the executives, if you've said this about your tech systems, if you've been in budget meetings where you've been talking about security upgrades and you use the word, if it ain't broke, don't fix it, my friend, you have tech debt. That needs to be addressed immediately.
Cody Kretsinger
And there's another piece here, Max, and I don't want to derail this too early on, but there was a phrase that you used that you didn't have time for. Here's the thing. AI works at machine speed, which means that it has a lot of time very quickly, to find these things compared to humans. So the I don't have time to fix this is not an excuse anymore. And it's a shame that it's not an excuse anymore. Because it's a poor excuse to begin with. We should all try to strive to be secure to begin with.
That's just me, my opinion. But that being said, it is so easy for AI to find these things so, so quickly that the adage if it ain't broke, don't fix it, and I didn't have time for that, are n they're not in this discussion anymore. And I want to flip that back around. If a incident And I don't mean w you know, this particular letter incident. If an incident pops off in your organization and it comes to light that the reason why a particular thing was not resolved prior to that incident and it was I didn't have time to fix it, and or it wasn't broke, so I just let it go, those are gonna cast a really bad light on whoever is maintaining and doing the administrative components of that organization.
Max Kurek
What a good transition, because we're about to talk about that right now. But yes, tech debt is going to be AI driven cyber attack's best friend. So do with that what you will. And I think you've gotten some great insights on why just now. Okay, guys, really quickly just to wrap up the letter conversation, then we're gonna kind of get into what's happened since the letter was published. Seth alluded to three groups of people that are responsible for doing things. There's actually four mentioned in the letter. And I just really quickly want to highlight the letter calls out every organization to take the actions we just described, right?
Make cyber defense a leadership priority, fix your highest risk weaknesses, get rid of all your tech debt, all of those things that we just mentioned. It also calls on cybersecurity companies and technology partners to test defenses continuously. Against frontier and AI capabilities, strengthen existing tools, et cetera, and measure progress by how many of the organizations that you serve are actually protected. It also calls out governments to coordinate locally, nationally, internationally, fund cyber defense, starting with essential services, but then also frontier AI companies. So calling out themselves in a certain way with re with calls for things like responsible model access, significant funding training and hands on support for under resourced critical infrastructure defenders.
That's kind of a big point to make that's a common thread throughout all of this. But guys, I have a couple of questions specifically on this idea of who's holding up their end of the bargain and all of these different groups that folks that the letter calls out. Is there any one of those groups that you think has weaker incentive to deliver on what's being asked of them than others and like what the impact of that might be? Or are we feeling pretty confident that everyone's gonna heed this warning and the collective call to action is going to be taken with the response that we're all hoping it does?
Cody Kretsinger
The fact that just the last couple of years we've been talking about privacy in technology, which is something we've been talking about in the industry for like 15 years. And that stinks because those conversations should have happened 15 years ago when this was all starting to, you know, become a thing. But instead, government took long time in order to do thing. And we're going to see that again with AI. And there's I can give another I can give another example of this. The C V S score, right? The one that we all know and love.
The one on you know, how bad is a particular vulnerability that is released to the public. That's
Seth Loe
This is that metric about how long your receipt gets at the pharmacy, right? Yeah.
Cody Kretsinger
Yes, actually that is it.
Seth Loe
No. Okay, sorry, no, wrong one. Sorry, my bad.
Cody Kretsinger
Actually MITRE prints all of those for you so you can anyway. The C V S score was based on or this that system was essentially the way for the public for consumers to judge whether or not a particular product was vulnerable. So therefore they would potentially change their opinion on whether or not that they would buy that product. So the It was essentially self regulation. It was basically the security industry saying, and if we highlight that this company is always vulnerable, consumers probably won't buy their product. Well, that didn't happen, right? It literally did not change anybody's way of purchasing.
So what did we do next? We shifted that to cyber liability insurance, where it said, okay, if an organization needs to be responsible. Let's make sure that they have insurance. And insurance will regulate this market. And surely that will fix all of the problems. Well, that hasn't fixed any of the problems. There's still vulnerabilities in software. There's still going to continue to be vulnerabilities and in all of that stuff. So where is the logical next step going to be? It's going to be with government regulation. And I want to highlight how long it's taken For vulnerabilities, which is a thing that has existed or essentially vulnerability management, a thing that has existed for years and years.
And finally, the consensus is well, maybe there should be some government regulation around how organizations release code into the public and whether or not it should be as secure or up to certain standards like the vehicle standards, you know, or the aircraft standards for safety and things along those lines. It's gonna be the same way with AI. It's I mean there's we can't convince ourselves otherwise. It's going to happen this way. The last point that I'll make is not the governments but municipalities need to take this so incredibly serious. And I don't think that there's enough weight that was put in the letter focused on them.
That is, as Seth kind of alluded to a little bit earlier, was your water, but also wastewater, and it's your natural gas and it's your local energy sources and it's things along those lines. What AI has got potential to do on the bad side is highlight these security weaknesses in these particular platforms. So incredibly fast. So incredibly fast. And if those organizations aren't on the flip side using AI to at least address some of the things to narrow the scope, they're going to be in a position that is very, very, very bad. And this whole idea of is AI can gonna kill us all, I mean, that's a bit ridiculous.
But Is AI going to potentially expose some security weaknesses that we didn't want to be exposed is the bigger question, and I think that one is a resounding yes.
Max Kurek
This is purely anecdotal, but to your last point there, golly, it feels like the number of stories you're seeing where local governments, municipalities, infrastructure, utilities are the victims in the headlines. It's almost like I feel like I'm reading more of those stories than just your average run of the mill businesses being victimized by attackers and by AI driven attacks and things. So I that's such an important call out and something I sadly expect we can kinda expect to continue. There
Cody Kretsinger
There's one more thing that I want to highlight about that specifically, and it's that every year I go to DEF CON and Black Hat, and there's this conversation that happens every single year. And one of the things that struck me that resonated with me years ago was in on a panel discussion with some of the biggest cybersecurity leaders in the nation, in the world, there was the statement being made that all critical infrastructure In the United States, all critical infrastructure was already compromised to a certain degree. And that was just a given. It was a known.
They just said it plainly as fact and they moved on. I think most folks do not understand that isn't an assumption. It is a known, and people are working from that known. And it's not well known outside of the security industry. And Max, to point, these headlines are going to continue to pop up if people do not take security seriously, even more so now than previously.
Max Kurek
And it's gonna be a lot easier. This I'm gonna put my Seth Loe hat on here for this analogy. It's gonna be a lot easier for it to continue to happen than like in Batman Begins where Dr. Crane has all the convicts pouring the like the stuff directly into like the broken pipe, and then atomizing it and everyone has that hallucinogen and then you know the apocalypse happens. It's gonna be a lot easier than that.
Seth Loe
Max, so bravo on the analogy. But what I want to extract from that is the reason why when audiences watched that movie, they found it compelling. And it dovetails so perfectly with something that Cody just said because it hits at a change in tactics. It's a completely different outcome that they're searching for there. It's a completely different group that they're targeting. Because it's one thing, Max, and it got your attention too. It's one thing if you hear that, you know, Kuber Nasties Incorporated got hacked for three million dollars and you're not a consumer of their product.
You kind of go, ha, Faceless Corporation got what they deserved because they weren't secure. What's compelling about insane people pouring poison in the Gotham water system is they're going after the people. These are not faceless multinational conglomerates with billions of dollars in their pockets, golden parachutes waiting for them when their company fails. That's not what that is. Crane, man, the sand man, he was trying to create chaos at the human personal level. And I think that's why the level of discourse has been raised, because it's no longer is AI gonna crash my favorite company. It's is it AI going to wipe out my retirement savings?
Is it going to bring my bank to its knees and I'm not going to have access to cash when I need to buy grocery supplies? Is it going to mess with the c the supply chain so that the groceries never even make it to my town? Is it going to turn down the pressure in my local water municipality so I can't even use the water that comes out of the tap? And, you know, those are real questions that affect real people. Not that the business stuff didn't. But it's a little hard harder for it to seem faceless now.
Max Kurek
Yeah, the victim is the person you see when you look in the mirror. We guys, we have a lot of folks listening to this podcast that are security professionals, that are security advisors in to some degree. They might work internally inside a company from a security perspective. And I just want to ask you one quick question and try and do a little bit of a kind of a rapid fire thing. The letter asks these folks to make AI powered defense deployable for critical infrastructure, for the businesses that they serve. What should the customers or the audiences of these security advisors or technology partners or third party security advisors, what should their customers expect from them in this age of, you know, AI powered attack and AI powered defense.
Like if I'm somebody who works with a security advisor or with a th a cer third party security company, obviously I want them to read and understand this letter, but what should I ultimately be expecting from them as this conversation continues to move forward? Cody, kind of cu I'll start with you and kind of curious for your perspective on that.
Cody Kretsinger
Yeah. So there's no hiding it anymore. You either need to adopt AI or you need to get out of the lane. And that's if there's one thing that clients or customers are probably going to be looking to, it's gonna be being able for that individual, for the listener, obviously, to have a good understanding of the landscape, where we are headed, and what you are doing about it. And you can only do that if you adopt AI to some degree. That means not only from a defensive standpoint, but also a daily, you know, a daily function and being able to understand its capabilities and all of those things.
So if you're putting your head in the sand and not adopting AI to some degree and understanding it, understanding its capabilities, then somebody else is going to and is going to answer those questions for you.
Seth Loe
Cody, I would love to continue talking about what you started with, but I will talk about the four things because what they did is they laid out a cycle and let me see if I can match Max's question with Cody's question and put these things together. You should see, and if you're the cybersecurity professional, your clients, those people who trust you, those people who deserve to feel safe, deserve to feel like something important is being done. Should be seeing you do the following things. And I want to add a front load task that is here for those people.
First of all, you should be leveraging this opportunity. You have been crying to us for decades about how nobody is listening. You've been talking about cybersecurity. You've been, you know, you went into a meeting and you talked about FIPS and you talked about firewalls and you talked about MITRE and you talked about IDS and IPS and shocker, nobody listened. They're listening now. So they should see you seizing on this opportunity and you should be doing four things. You should be leveraging low cost AI models. And what I'm talking about in here is the AI solutions that are already built into the security services that you consume now.
Everything's getting an AI sticker added to it, folks. You need to find out of the sub of the security tools that you've got in place now. Why did they put the AI sticker on it? What features, what capabilities is it that you have not chosen to leverage yet? A lot of times there's a switch you got to flip. A lot of times there's changes to your configurations you need to make to be able to leverage that machine speed that Cody was talking about. At machine speed, you should be finding. Where you are weak, fixing those weaknesses.
That's a big mouthful to say, just fixing those weaknesses. It is about replacing outdated systems. It is about patching systems. It is about taking systems that cannot be fixed and putting compensating controls around them, isolating them so they cannot be reached from attackers. It is about verifying that you actually fixed the things, right? The patches are in place, they're doing what they're supposed to. The new software that's been purchased. Is secure and updated. The systems that you had to isolate with compensating controls, that they're actually protected. A lot of times, both finding where you are weak and verifying that you have fixed them requires a third-party set of eyes.
Somebody who is not you, who is not affected by the assumption that the job was done right, to get in there, penetration testing, vulnerability scanning, all of those things, putting those tools in play to test on that verify stage, did you actually fix it? And then last but not least, repeat. This isn't a one and done. This is a new cycle of opportunity or excuse me, a new cycle of activity to get into if you're not already in that cycle. A lot of the people that we work with are in that cycle already, have been for years, get into it.
Cody Kretsinger
The
Max Kurek
The machine speed component that Cody was talking about earlier means if you're only conducting the find, fix, verify process once a year, man, you're in for a rude awakening, I think very, very soon. Yeah. Absolutely. Okay, guys. Some stuff has happened since OpenAI published the letter at the end of August. And one of the things that happened is Our old pal, Dario Amadei, CEO of Anthropic, published a thirty eight hundred word essay. And in case there's any college students listening to the podcast, that's about fifteen double spaced Times New Roman twelve point pages of an essay.
Golly. Hope has an assignment for that. Yeah.
Cody Kretsinger
Amen. What version of citations did he use? Was it L A or what's the other
Max Kurek
What are
Seth Loe
Strictly Chicago.
Max Kurek
Okay. I don't still have it on I bet I could find it if I dug down, but my stu the style guide, I don't even remember what the like standard style guide was. But there was one book that had all the different options, and the professor would tell you, okay, this is the one I expect. It came out less than two weeks after the open AI letter was published, and it was called We Must Pace the Frontier. And it basically called on AI companies to slow down.
Cody Kretsinger
Yeah.
Max Kurek
The rate at which models gain capability so that safety work can catch up. And there was basically three proposals in the essay. Embedded third-party evaluators with access inside AI companies. Like think of regulatory supervisors in like banking. That really worked out great in 2008. Sorry, sorry, excuse me. Safety standards and pacing limits agreed among countries. So here's the government component country agreement. That is boy, pie in the sky, maybe. And then attempted coordination with authoritarian governments as well. So some of these proposals a little bit more realistic than others, but in general, if we take if we bring pull out the main takeaway of calling on AI companies to slow the rate at which the model gains capability and all of that.
Interestingly, like Sam Altman, Elon, they were all like, Yeah, that's a great proposal. And I'm sure they weren't angry at all that AI stocks plummeted in the immediate aftermath of the essay being published. But what I wanna ask you guys in terms of how thank you. Right. Yes.
Seth Loe
The market self corrected. It might have been a little inflated, little injection of reality, the market self corrected.
Max Kurek
You're being so diplomatic today, Seth, with your terminology.
Seth Loe
Look, I came ready to actually show up on camera today.
Max Kurek
What I want to ask you guys, given the timing of this as it relates to the open AI letter we just discussed, the letter's kind of central premise, right, was this defender's window. We've talked about the defender's window being months to take action. That framing of that defender's window came from companies that build AI and was signed by companies that sell defensive AI. Is that is there any reason To be skeptical, and Seth kind of got into this a little bit, or to say that maybe it's the most effective sales frame the industry has produced in a decade.
I know that's being super, super cynical. But especially in light of this kind of corollary, I guess, that Dario's throwing out in his essay of, yeah, we're gonna eat our own dog food too, and here's how we do it. How much skepticism should we have? I guess is the def do we agree that the defender's window is real and legit, first and foremost, I think is the most important question. I think we've kind of already alluded to that a little bit, but just to get it all out on the table. But is there any reason to be suspect?
Is this all just like a big PR move?
Seth Loe
Well, I mean, as a card carrying cynic, be cynical. You know, understand that all every single writer, every single author has their own individual motives on this. And you can certainly be cynical about their motives, but you've got to kind of examine too, they are even billionaire organizations who are in these corporations that have been funded by speculative investment. Have to have a long term strategy, especially these companies that are talking about IPOs. You could not build an IPO off of a claim that we have months to respond. Follow that up by a big nothing burger and expect to continue to grow that investment base.
Be cynical, have your conspiracy theories about this kind of disclosure, but there's some realities here you can't ignore.
Max Kurek
I And there's still people that you can be angry at if you want to be. Like and you can still be angry at Dario and Sam and Elon if that's easy to do. But Jensen Huang, the Palantir CEO Carp, Alex Carp, they're firmly on you know, the other side of this is that any like voluntary slow slowdown would benefit our geopolitical rivals or we should just Move as fast as possible because we'll be able to use it for good too. And that'll all outweigh any of the risks. So there's still people that you can get mad at.
If you need
Seth Loe
You had to say Palantir, didn't you? I may or may not know a custom knife maker who will give you a free custom made Damascus knife if you bring him a flock camera.
Max Kurek
I know.
Cody Kretsinger
Good.
Max Kurek
Man, man, my marketing brain is running wild now with possibilities. My gosh.
Seth Loe
So there's plenty of villains to be found here. Yeah.
Max Kurek
There are Cody, I want to ask you a slightly different question here. 'cause I mean Dario, this we're basically talking about pacing, right? And taking time to slow down and make sure that controls and security catch up with risk potential in a year or two years or however long these guys agree that they can stretch this out. What would evidence of real pacing look like? Like what controls would it include? What would the AI landscape look in like in a year or a year and a half if they actually ascribed to the things that Dario is setting out in this essay?
And if every one of these companies keeps shipping on the same schedule, is there a version of this pacing that isn't just like marketing and theater and lip service? And is there actual tangible change that could occur and what might that look like from like a controls perspective or a policy perspective, I guess? I'm curious if you have any thoughts there.
Cody Kretsinger
Y yeah, I've got some thoughts and I don't think anybody's gonna slow down. I think ultimately at the end of the day, this is a nuclear arms race to a certain degree. And one half of an organization can say, yes, we're going to participate in some sort of public way of slowing things down, but the other half is going to continue to develop at whatever speed that they're going to do it because If i here's the thing, for this to work, this means every single AI company has to be on board. And every single AI company is not going to be on board with it because they're going to figure out that well, if I don't slow down, then I'm definitely going to have the advantage over somebody else.
And that might be worth their risk. The it might their investors might enjoy that risk a little bit more than other organizations. And I'll also tell you who isn't slowing down. And that's anybody who is building a private model and leveraging it for bad things illegally. The T one thousand is gonna start showing up and we're gonna go, now this makes complete sense now because it's just where we were headed in some kind of fashion. I don't know. I have no idea. I have no idea where any of this is going. I'm just along for the ride.
Seth Loe
Cody says T one thousand and I have to look over my shoulder immediately. It's involuntary. Yeah. I do agree with you on the scale of the problem. And I so I you used the metaphor here of a nuclear arms race. Can you imagine if the nuclear arms race of the nineteen forties and fifties had been driven by speculative investment? Instead of under the control of government and military entities who were looking at this as a wor on the heels of a world war that they wanted the whole world to be able to recover from. I mean, even the warmongers, even the eagles were like, okay, we had enough of this.
This all went too far. Let's slow things down. Imagine if there had been a consortium of hedge funds. Driving innovation in the nuclear arms race if it had maybe had gone a little differently. Yeah.
Cody Kretsinger
I think private companies owning this is weird. We are in a weird era and I because of that, I have no idea where this is gonna go and how bad it's gonna be.
Max Kurek
If you had to put it at a I don't know on a like a one to ten scale or 'cause cause the solution to these issues that we're talking about here, in theory, right, is regulation on to some degree. Like that's and I know if you're not watching us on YouTube, you saw Cody just take a big old deep breath. And Dario, if he was listening to this, would say, well, that's why I mentioned in my essay embedded third-party evaluators, right? That have access inside AI companies. And it might not happen in the current landscape given some of the things Seth has described.
But can we, is there any hope for us guys? Is there any hope for humanity that regulation can occur effectively enough to mitigate some, maybe not all, but some of The concerns that Cody just laid out, and certainly not on the bad guy side, right? Because bad guys are gonna bad guys. So let's keep that in a separate bucket and we need to get t shirts and we need to get thread aware t-shirts that say bad guy gonna get bad guys are gonna bad guy. But let's just keep let's keep it focused just on the I I'm not gonna say good guy, because we're talking about AI companies here, but just on that side of things are Can we maintain any hope that a world in which effective regulation exists and can actually mitigate some of these concerns and give people some level of peace of mind?
Like is there a world in which that happens?
Seth Loe
Yeah, I think so. And here's why I think so. First of all, we haven't had the blip yet. The one big event, and it's coming, I think. The one big event that touches the entire world. W now we hope that it's not rolling blackouts in the middle of a heat wave. We hope it's not the shutting down of every financial market in the system. I hope personally that AI and if AI, if you're watching, watches the movie Fight Club, and the big blip is they wipe out everybody's credit scores. You know? Right. So AI, if you're listening, watch Fight Club.
Great movie. Stands on its own. We can talk about the cinematics of it if you want. We can also talk about the writing if you want. But let's also talk about the end, right? When all everybody's credit card scores get wiped out, right? So If AI is gonna come after, and we're all concerned because we're having these discussions about how AI comes after the little guy, if it goes after infrastructure, if it goes after food supply, supply chain and all those kinds of things, there's also a chance that AI goes, well, maybe I will become the champion of the little guy, but whatever the big event that we are they're predicting we're going to have, it won't be one big earth shattering, undoes us all event.
It will be one big gets all of our attention events. And I think you are going to see people say, you know, we talked about regulation. We talked about government. This is not unique to our, to our country. There are democratic institutions all over the world. They're going to say to their representatives, you did not protect us. You did not meet us in this event. You are not doing enough. They're going to fear for losing their base of support. They're fear going to fear for losing the power. Because they've breached the trust. And I think you will have that room full of septugenarians and octogenarians that I talked about at the beginning of this podcast get radicalized, mobilized.
They write freaking letters. They pick up the phone and call. You're going to see those Gen Zs and Gen Alphas that I talked about before going, okay, old folks, you had your shot. Now we're going to take it over. We're going to get loud about it. I think that we will have we'll have a blip. That hasn't had yet happened yet. Even if it's even if things swing towards the bad side and we don't curb it and people don't self regulate, I think there'll be a blip that helps us self regulate.
Max Kurek
There's one thing we gotta do, guys, before we wrap. And it's t it's about time, and I think we've got a lot of good candidates based on our discussion today, to do some Hall of Fame inductions and some Hall of Shame inductions. I don't think we've done this since episode one of Unauthorized Opinions. So I wanna see if anybody has a nominee to throw out. Let's start, let's start with Hall of Fame, because we just had a little bit cynicism, so let's get some positivity in the mix. And does anybody have a nominee this week to throw out for the Security Hall of Fame?
Seth Loe
I have a nominee, but they cannot be named.
Max Kurek
Okay. Okay. All right. So Seth's abstract unknown nominee. Here we go.
Seth Loe
And it is not my local, but a regional municipality who saw the podcast on water systems and all of that. I got confirmation this week that they made changes to an overly permissive remote access system that could have been exploited in order to grant access to the PLCs in that water treatment facility. Got a little message on the side about how they saw the podcast. They talked to their IT team. The IT team told them, hey, buddy, you were the one that wanted this overly permiss permissive remote access system so that you could check on us on the weekends from home.
They shut it down, they took steps, they looked at it. So I can't name them obviously, but I've got ties because of my previous MSP relationships to some miss municipalities who happened to see it and take some action and I want to add them to that.
Max Kurek
That's an awesome one. Go ahead.
Cody Kretsinger
And I I'll save it for later because here's the thing. It isn't this specific municipality. It's gonna be any municipality who takes this to heart and actually does any of the good in it. And I want to highlight real fast what Seth just said. This isn't a time to say it's useless to defend against these things, put your head in the sand and just pretend like it's it nothing's gonna change and all of that. As wonderful as that idea would be, we still are going to be here tomorrow, next month, next year, ten years from now, a hundred years from now.
All of those things. The big AI thing isn't going to end humanity. Therefore, we do need to do these things. And there are very small things you can do right this second in order to help defend against those things. And it's the basics. It's making sure the basics are met. Everybody understands what the basics are. If you're you know what, if you're in a municipality and you're taking this news seriously, that's my vote. Make good positive change.
Max Kurek
That sounds like a motion which I would second to forego the rest of our nomination process and immediately enshrine local municipalities doing the right thing and taking action as this week's Hall of Fame inductee, all those in favour say aye.
Seth Loe
I
Max Kurek
All right. Really quickly, we gotta get a hall of shame nominee in here, and I've got one to throw out, and then I'm curious if you guys have any others. I won't say OpenAI is my Hall of Shame nominee, but their disclosure record certainly is my Hall of Shame nominee. Everyone has heard about kind of the hugging face incident and now a open AI portfolio company hugging face, but everyone has heard about the hugging face incident as kind of the first, you know, the first case of completely AI driven attack with no human behind it.
And there's a really good episode that Aidan did of Beyond Intelligence talking about did your AI actually go rogue? And so I'm not going to say that it went rogue because Aidan might ha take issue with me. So go listen to episode one of Beyond Intelligence if you haven't heard it. But since all of that has come to light, there's been another at least six incidents that have been clearly documented about with the same issue tracing back to open AI models. And some of these I think there was one in particular around a like a German like wiki or something like this that got compromised that happened back in the spring and it just came to light I don't know, less than a couple of weeks ago.
So I I'm throwing this out there because we're talking a lot about and some of the folks who are more like gung ho about No regulation, say, these companies will self regulate and it'll all be fine. Look at their history when it comes to disclosure notifications and incident notifications and ask yourself if you really truly believe that. So OpenAI's disclosure record is my Hall of Shame nominee for today. Does anybody else have anything else to throw out on Hall of Shame?
Seth Loe
Yeah, I've got a Hall of Shamer here and I hate to make it personal, but it's Andrew Yang. And this is why. So I don't know if you saw this or not, and I know we didn't get a chance to talk about it. Andrew Yang goes on the news Friday, Thursday or Friday, and says, Hey, I have insider knowledge that during the hugging face incident, and I'm gonna do my best hugging face emoji. That's during the hugging face incident. The agents that broke out of their sandbox created self-replicating versions of themselves all over the internet.
And if you understand the implications of if that is true, that is huge. For him to drop a, he says, I'm breaking this news without sourceable information, without being able to port directly to a source that other people can verify. First of all, we hope that he's all wrong and he's all full of it, but to drop it that way is irresponsible. So I think he needed to come if he wants to break that news, if he wants to be the face of the story, if he wants to be the person who's credit for exposing this, he needs to come with some real sourceable information because whatever he revealed there, if it can be true, if it is true and can be verified, is bigger than the story about how somebody told him a secret that he decided to share.
Cody Kretsinger
Since we did our last episode where we did Hall of Shame, there has been one vendor who has something like another I have to double check the actual number. It's triple figures. It's in the hundreds. Hundreds of vulnerabilities have been disclosed, many of which were pretty significant remote code execution and or like privileged bypasses. Does anybody here take want to take a guess as to what firewall vendor has had that many vulnerabilities released just within the last couple of months? It starts with an F and ends in Ortigate.
Max Kurek
I was gonna say there's only two I could potentially think of and that would be number one on the list.
Cody Kretsinger
So these there's three really good ones here and I th I'll just leave it there.
Max Kurek
Voting for a company that starts with F and ends in Ortigate for Hall of Shame this week.
Seth Loe
I want to hold my vote to find out what their response is to it because everybody's vulnerable somehow. They have that many exposures. If their response is meh, this is the price of admission, folks. This is how it goes. Versus, hey, we're taking a heartfelt look at what we do and we're going to redesign and rethink what we do, then my vote is one farty thumbs down.
Cody Kretsinger
There's not been an official statement that they're gonna take it more seriously or anything. And this is very much unfortunately, it's so bad that it's just it's generated memes. Like, yeah, another vulnerability by this company. So I don't know if that sways you at all.
Seth Loe
Do the memes have that one lady who's been like super prevalent right now where like she's smiling with her mouth but not with her eyes and everybody's creeped out about it?
Cody Kretsinger
Th Yes.
Seth Loe
Can we find any evidence that they're finding their vulnerabilities? They're fixing them. They're verifying that they fixed them. And then they're on a repeat cycle because it doesn't sound like it.
Cody Kretsinger
It doesn't sound like it at all.
Max Kurek
It doesn't, but there's a good note for everybody who wants to potentially be considered for future Hall of Fame induction. Find, fix, verify, repeat. If you can go and get that implemented, which is the takeaway from today's episode. Every single person, every single company listening, go read the open letter, find, fix, verify, repeat. And we will see you back here to enshrine you into the Hall of Fame for Cody Kretsinger and Seth Loe. I'm Max Kurek reminding you to stay threat aware. We will see you next time.