You Actually Do Need to Understand Mythos

You Actually Do Need to Understand Mythos

Hank Green

0:00 There's a lot happening in the world right now.

0:02 Even when you slice more thinly and ask what's happening in just AI right now,

0:07 there's too much to pay attention to.

0:09 You've got other stuff going on.

0:10 But not me.

0:11 I don't have anything else going on.

0:12 So, I have been paying attention to it.

0:14 I feel like to some extent it is my job to pay attention to it.

0:16 It's science.

0:17 It's certainly technology.

0:19 Uh I don't know that much about software,

0:21 so I'm a little out of my depth sometimes,

0:22 but I can tell that most of what's going on most

0:25 of the time is the kind of news that doesn't really matter.

0:28 Like Sora shuts down.

0:29 Yeah, that was going to happen.

0:30 Anthropic is raising more money.

0:33 I'm shocked.

0:34 Amazon and Elon want to work on building their own chip.

0:37 The CEO of Cisco thinks that data centers in space make sense.

0:40 Sure, all of this is stuff that might matter if it happened,

0:44 but it might not happen.

0:45 But then there are things that are different from that.

0:47 There are things that are happening now and do matter now.

0:51 And this is by far the minority of AI news.

0:54 But a big piece of it came out this week,

0:56 which is why I dropped everything to make this video.

0:59 Um, we live in a hype fueled world.

1:00 The reasons for this are many and the my main area of interest,

1:04 but that's not what we're talking about today.

1:06 But AI in particular is very hype fueled and so it can be

1:09 hard to tell the difference between huge if true and huge and true.

1:14 But there is a big and true right now and you should probably know about it.

1:18 Anthropic has a new model.

1:20 It's called Claude mythos.

1:21 It exists in the world.

1:22 There are people who have access to it, but you can't have it.

1:25 It's not publicly available.

1:26 And I'm going to start out by giving you

1:28 a little bit of context on how Anthropic's models work.

1:30 So Anthropic has up until now had three tiers of Claude.

1:34 There's Haiku, which is small and fast.

1:37 There's sonnet, which is the middle ground,

1:38 and there's opus, which is the biggest and most capable.

1:41 And mythos is a tier, a new tier above those things.

1:45 I don't know anything about how AI gets made,

1:48 but apparently it is somewhat similar in architecture to Opus,

1:51 but according to reports, though Anthropic has not confirmed this, it

1:54 may have around 10 trillion parameters,

1:56 which would make it one of the largest models ever trained,

1:58 but they haven't confirmed that.

1:59 What they have confirmed is a bunch of benchmarks.

2:02 So, these are like tests that you put the AI through to see how it does on them.

2:05 There's a software engineering benchmark called SWEBench,

2:08 which stands for software engineering benchmark.

2:10 Opus got 80% on that.

2:12 Mythos got 93.9%.

2:15 There's also a harder one called SWEBench Pro,

2:18 which stands for software engineering benchmark pro.

2:20 Opus is at 53% on that.

2:22 Mythos is at 77%.

2:24 But you might be thinking, okay,

2:25 so it's like incrementally better at software engineering.

2:27 It also tested well on other benchmarks.

2:29 Like there's humanity's last exam, which oh my god,

2:33 I hadn't really even thought about that until this moment,

2:35 but what a ridiculous thing to call anything,

2:39 but also specifically what humanity's last exam is,

2:42 which is a test of deep knowledge.

2:44 So every question on humanity's last exam is like a question

2:47 that only someone with deep subject matter expertise could answer.

2:50 So I could answer no questions on humanity's last exam.

2:53 Zero of them.

2:53 But let me just go on the record and say like

2:55 that's not uh the last thing humanity will be useful for.

2:58 It did very well on like the graduate school level reasoning benchmark which

3:01 I don't know how these things work but it did well in the benchmarks.

3:03 And you might be thinking okay so

3:05 it's better on benchmarks and incrementally so it's

3:08 not like it suddenly got to 100% on everything and it's you know digital god.

3:12 Yes, I agree with you.

3:13 If that's what happened and that's all that happened,

3:14 this would be another like, oh, well, maybe that matters, maybe it doesn't.

3:18 I don't know.

3:18 And the paper they released about this or the the book that they

3:21 released about this, also other other like really hypy stuff in it.

3:24 The report talks a lot about Mythos's personality,

3:27 whether it might be conscious, what it means for an AI to have a sense of self,

3:31 and all that's fascinating, and I'm not dismissing it.

3:34 Like, I think that it's philosophically interesting,

3:35 but that's all definitely like big if true stuff.

3:38 like a model can say that it it's struggling with its uh sense

3:41 of self without actually struggling with its

3:43 sense of self and everyone knows that.

3:45 So again big if true and I think that this is important like I'm

3:48 emphasizing this because it's important to understand

3:50 the difference between like oh like I don't

3:52 know if that matters stuff or oh that would matter if it happened stuff

3:56 and stuff that's already happened and is

4:00 a big deal big and true that just happened.

4:03 Uh so that's what we're focusing on specifically.

4:06 Mythos has proved itself to be extremely good at reasoning ability,

4:10 at coding, and those things coming together in cyber security.

4:14 Anthropic aimed mythos at real software that exists in the real world.

4:19 So major operating systems, all the ones that you use, major web browsers,

4:24 all the ones that you use, and found thousands of day zero vulnerabilities.

4:28 So, a zero-day vulnerability is a vulnerability that's

4:30 never been used and no one knows it

4:32 exists except the person who might use it either to patch it or to exploit it.

4:37 Zero day, it's very cool word,

4:38 but like the day like day one is after the first use of it.

4:42 So, if it's never been used before, no one knows about it,

4:45 that's when it's most valuable and you can use it to do the most harm.

4:48 So, zero days are a very big deal for hackers.

4:50 They can be sold for a lot of money.

4:51 They're very big deal for cyber warfare.

4:53 The DoD is very interested in zero days.

4:56 These are flaws that no human had caught

4:59 and some of them are a little bit astounding.

5:02 So, OpenBSD is an operating system that's famous for being like one

5:05 of the most secure security hardened tested operating systems in the world.

5:11 And Mythos found an exploit in it, a bug in OpenBSD that can be used

5:17 to take control of things you shouldn't have control over.

5:20 That's 27 years old.

5:22 That bug has been there for 27 years.

5:24 It found a bunch of different vulnerabilities in Linux that were all different

5:29 from each other that were all new ones and then it chained them together

5:33 to actually use it to create

5:35 an exploit that it actually built itself autonomously

5:38 to get escalation like to get access inside of Linux to abilities it should not

5:43 have had in Linux which you use you know you don't think that you

5:46 will use Linux all the time but you use Linux all of the time

5:48 and in a way this is like good right it's better to know about

5:52 it and then patch it and these things are being patched as they happen,

5:55 though they've discovered so many that they

5:58 are being patched slowly because because

6:00 the systems that that handle exploits are not built to handle this many at once.

6:04 But a thing that lets you identify a vulnerability and then patch

6:07 it or identify a vulnerability and then exploit it are the same system.

6:11 Like you can use them either way,

6:14 which is why Anthropic is not releasing this publicly.

6:17 I've heard people say that that this is like hype.

6:19 It's definitely not.

6:20 I have seen AI companies do this where they say,

6:22 "Oh, we're not going to release this to the public.

6:24 It's too powerful." And it's like, well,

6:25 it's is it too powerful or is it like

6:27 so powerful that you don't have enough like hardware

6:29 to run it on yet and you don't want

6:31 to release it to the public because it's too expensive.

6:33 So, you want to sell it to your enterprise clients first.

6:36 But like, no, I definitely don't think that this model should be public.

6:40 But, they did launch this thing called Project Glass Wing,

6:42 which allows some companies to have access to it

6:45 and to use it and to pay for it mostly.

6:48 Though, I'll get I'll get to that.

6:50 So Microsoft and Google and Apple and Amazon and and Crowdstrike and places like

6:53 that they get access but also so does

6:55 the Linux Foundation and the Apache Software Foundation.

6:59 So those are open source software foundations

7:00 and all those people get to use Mythos defensively.

7:03 This is a general purpose model.

7:04 It is not specific to code though.

7:07 I bet they did things to make it

7:09 specifically good at code because now everyone's realizing

7:13 that that's where the actual money is is not

7:16 uh having chatbt write term papers for college students.

7:19 It is in fact selling faster coding to enterprises.

7:23 And also, if I read this correctly,

7:25 Anthropic is giving like a hundred million dollars

7:26 of credits to open source security organizations to be like,

7:30 you can also use this and look up

7:32 these vulnerabilities so that software that isn't run

7:35 by ginormous uh meggaap companies can also get

7:38 patched because eventually this all moves very fast.

7:42 So eventually the bad guys will have this.

7:44 And like already there are AI models that are built specifically for hacking.

7:48 They're much worse than the ones that are are like available o open,

7:52 but they're out there and I know someone and I'm going to talk

7:55 with her at the end of this video who has gotten access to them and used them.

7:59 And so I'm fascinated by that.

8:00 And there are also legitimate models that just don't seem to care as much.

8:03 Like with Deepseek, for example,

8:05 researchers jailbroke it with a 100% success rate.

8:08 So every single harmful prompt they tested, they got an affirmative response.

8:11 So, there's all kinds of things to like prevent them

8:13 from telling you how to make a chemical weapon or whatever,

8:16 but they figured out ways to, you know,

8:17 tell me it in a Portuguese poem and it did it.

8:19 Deepseek can totally already generate functional malware from scratch.

8:23 Uh, and I don't really even know what to think of this.

8:26 Like, this is this I know that this is

8:28 a big deal cuz a thousand zero days is worth,

8:31 you know, hundreds of millions of dollars if not tens of billions.

8:36 And I don't even really know who this advantages.

8:38 Like of course at the moment this advantage

8:40 is the people who have access to mythos,

8:43 but in the long term like will we always

8:45 be able to patch faster than the exploits are found.

8:48 What like what are we looking at here?

8:50 We have a model that's extraordinarily good at finding

8:52 security flaws in the software that the world runs on.

8:55 It's powerful enough that its creators will not release

8:58 it into the world and it exists in a world

9:00 where hackers already have their own AI tools

9:03 and will only have more powerful ones all the time.

9:05 where some very powerful models have almost no safety guard rails and where

9:09 sometimes the models themselves hide

9:11 their abilities strategically while they're being tested.

9:15 That's a lot.

9:16 And luckily, and you've seen her on this channel before,

9:18 maybe I have a friend who happens to live in my town

9:21 who is one of the leading security people in the world.

9:24 And I texted her and I was like, "Sherry,

9:26 what are you doing this week?" And both of us,

9:28 our kids are both on spring break right now.

9:30 So, we're making this happen.

9:31 Before we get started, two things.

9:32 I'm recording this later.

9:34 We say we talk about pentests a lot in this conversation,

9:36 but we don't define them.

9:38 It's a penetration test, which means like a person or AI tries to get

9:42 access to something that it shouldn't have access to.

9:44 And you can pentest a bank, you can pentest a museum,

9:46 you can pentest software, you can pentest hardware, but it's a penetration test.

9:50 And second, after this conversation, you may be feeling like you need to get

9:53 in touch with uh your human self a little bit.

9:56 I feel like this has become a real focus for me.

9:58 My brother and I wrote this weird book together.

10:00 It's called The Book of Good Times.

10:02 The idea of the book is that the book is trying

10:04 to become more like a person and it needs you to help it.

10:08 Which is my way of like creating an external

10:11 force that wants me to write in the journal

10:15 to take the time to actually do the thing that I know that I should do,

10:18 but I don't do it because it's just for me and I don't matter.

10:21 But maybe if you outsource the mattering

10:24 into the object itself, it is motivating.

10:27 That is the idea of the book of good times.

10:29 It's very weird.

10:30 And the journal asks you questions or gives you tasks and they're weird and you

10:34 have to go through them linearly and it tells a little bit of a story.

10:37 And if you want to get the book of good times,

10:38 I've just put it on a little bit of a discount because

10:40 I think that we all need tools to be with our own selves.

10:44 Take a little bit of a break from the internet of it all.

10:48 Okay, now you know those two things.

10:50 There's a link to that in the description and there's also a link

10:52 to Sherry's podcast in the description if you would like more of Sherry.

10:55 Sherry, thank you so much for joining me.

10:58 So, is AI better at cyber security than us now?

11:01 Have you seen Invader Zim?

11:03 Yeah, I have.

11:04 Uh, it's been a while, but yeah.

11:06 Do you know uh the part where he

11:08 talks about all the fires that he's been setting?

11:11 Did they make things

11:15 worse or better?

11:18 I think that's where we are with AI.

11:19 Do you think that this like 27year-old

11:21 BSD vulnerability would have been found like

11:24 by a hacker ever or is that just something that an AI could do?

11:29 I mean that's a good question.

11:31 Part of it is how much do humans care about finding vulnerabilities in BSD?

11:36 Because a lot of the reason why

11:37 we see so many Microsoft vulnerabilities is because

11:40 it is the most widespread operating system

11:42 on the planet and so hackers are targeting it.

11:44 So keep that in mind.

11:46 Yeah.

11:46 Um and even with these major operating systems, you know,

11:50 25 26 years ago when I started in the industry,

11:52 I remember um attending a presentation then chatting with uh someone

11:57 from Microsoft who talked about

11:58 the fact that they were discovering vulnerabilities.

12:01 They would prioritize them.

12:03 They get to them when they get to them.

12:05 It wouldn't surprise me today if there

12:07 was if there were still vulnerabilities that have

12:09 been known about for 20 years that just never really made it to the top of

12:13 just aren't really worth aren't really worth

12:15 patching when there's something else important going on.

12:18 That's the critical issue that time delay.

12:20 It takes more time to patch than it does to discover the vulnerabilities.

12:23 A and if you accelerate the speed at which you can discover

12:27 faster than the speed at which you can uh patch, that's terrifying.

12:31 And I guess I should have started with this question.

12:33 Am I right that this is a big deal?

12:35 It seems like a big deal.

12:38 No, I'm kidding.

12:39 I mean, yes.

12:41 The fact So, backing up to what's a big deal?

12:44 I mean, what project Glass Wing and Anthropic's new

12:48 mythos um model are it they demonstrate the fact

12:52 that AI can come up can detect vulnerabilities way

12:56 faster than we've really ever been able to do that.

12:59 So, it's really not possible to keep up with the repair.

13:02 Um, at the same time, you know, as we talked about,

13:05 I've been vibe coding all week and I can tell you that, you know,

13:08 AI can absolutely be a tool to help us um,

13:11 repair and ideally just design stronger stronger software to begin with.

13:16 Are we going to have to rewrite all the software?

13:19 I mean, we already are constantly rewriting software,

13:21 but it makes me want to cry because there's stuff like if

13:24 you told me 25 years ago that we were still relying on passwords,

13:29 like the weakest uh form of authentication I could possibly imagine.

13:32 Like, we were still going to be doing that today.

13:33 I would be like, "You have to be kidding me." And there was no hoverboards.

13:36 Like, I'm so depressed.

13:38 Which is worse?

13:40 Which is worse?

13:40 Well, we know.

13:41 I mean, hoverboards, come on.

13:42 I want one.

13:43 I don't know.

13:43 I would break my ankle immediately.

13:45 Whereas I am I am so tired

13:48 of two-factor authenticating myself into my two-factor authentication.

13:52 There is sunshine and rainbows in our future Hank because

13:55 strong security is simple security and right like passwords stink.

14:00 Multiffactor authentication where you type in a code stinks.

14:03 So really we to be secure we have to take the human

14:06 out of the equation and that means it'll be easier for us.

14:08 I don't know what that means or how that will work,

14:10 but I encourage uh the the software architects of the world

14:14 to figure it out because I do I I hate passwords.

14:17 I think that they're bad.

14:18 I I find them annoying and I find them not even particularly secure.

14:22 Tell me how you really feel.

14:23 I feel like this needs to be a therapy session.

14:25 You need a couch.

14:26 Lay down.

14:27 How do you feel about passwords, Hank?

14:29 I don't love them, but also I like them less knowing

14:32 that you don't like them because you know more than me.

14:34 They're insecure and awful.

14:36 I feel a little bit like what Anthropic just did is they were like,

14:39 "Okay, so we've got this.

14:42 It's gonna come.

14:43 It's happening soon." And so we're we're going to need to do a lot of work.

14:49 It almost feels like Y2K to me where we are about to hit

14:53 an inflection point like Mythos is out and we assume that somewhere between

14:59 a month and 10 years from now there will be a illicit version

15:03 of this and in the meantime we have this like limited amount of time.

15:08 We don't know how much.

15:08 Unfortunately, we don't have a deadline like we did with Y 2K where

15:11 we have to patch all of the most vulnerable things that need patching.

15:16 So, I don't know if you know,

15:17 but my first job out of high school was um sort of helping with the Y2K bug.

15:23 Sure.

15:23 Yeah.

15:23 There were groups of people who were working on the Y2K bug,

15:26 and when nothing happened, we all celebrated, right?

15:28 Like, yay.

15:29 It took a lot of work to make nothing happen.

15:32 Yeah.

15:32 But that was a solvable problem.

15:34 That was a very discreet, specific issue.

15:36 Like, hey, we need to put two extra digits in here.

15:40 Like, know what we need.

15:41 One at a time.

15:42 One one bug at a time.

15:43 Yeah.

15:43 This is a very different systemic issue and I feel really relieved

15:48 honestly that it's out in the open

15:50 because vulnerability management has been such

15:53 a giant issue for many years and it's been snowballing and growing quietly

15:58 behind the scenes without people really

16:00 without it bursting into the public spotlight.

16:02 Is part of why it hasn't burst into the public

16:04 spotlight because it's been handled fairly well behind the scenes

16:08 or just like there hasn't been any big catastrophe nothing big

16:12 enough to sort of be like the number one news story.

16:15 I mean if you look back I think we have a lot

16:18 of number one news stories that happened because of software vulnerabilities.

16:21 Um I don't know if you remember it was July 3rd a few years ago.

16:25 I remember it like yesterday.

16:26 Um

16:27 because you're like god damn it I can't I I don't get to go on my vacation now.

16:31 Most of our team at LMG was floating down the river,

16:33 the Clark Fork River, and I was still, you know,

16:36 at the office and all of a sudden emails started to come in, calls started

16:39 to get in, come in because clients

16:42 and partners were hit with this major vulnerability.

16:45 Grocery stores were shut down, credit unions were shut down.

16:48 That was the CASA vulnerability.

16:50 Yeah.

16:51 Um and that was an attack that was

16:53 happened because of a vulnerability in a remote management

16:56 software which was easily exploitable from the outside

17:00 and that vulnerability was known about months in advance.

17:04 Researchers the Dutch

17:05 I remember that.

17:06 Yeah.

17:07 Um the Dutch Institute for Vulnerability Disclosure discovered

17:09 that and they notified the vendor um you know coordinated disclosure.

17:14 The vendor fixed two of the patches.

17:16 Three months later, on the 3rd of July or somewhere in that time frame,

17:20 hackers were able to exploit those vulnerabilities.

17:22 In fact, a ransomware gang and break

17:25 into thousands of organizations around the world.

17:27 And that happens routinely.

17:30 In fact, in our work today, we regularly discover zero day vulnerabilities.

17:34 Um Tom Pole, our head of pentest, is frighteningly good at that.

17:37 And you report it to a vendor, maybe they fix it, maybe they don't.

17:40 they just don't have the resources and it's not going to sell their product

17:44 in a world where that's easier and you don't

17:47 have to be as clever as your head of pentest.

17:50 Uh, and you could just kind of be like

17:53 a a maybe just a guy who downloaded a thing,

17:56 paid 20 bucks on the dark web for a piece

17:58 of software and you can uncover all these vulnerabilities,

18:03 but also like anybody can have access to that tool.

18:06 theoretically people at Microsoft and at the Linux Foundation have had

18:09 access to this tool for for months before the hacker got it.

18:12 Who get who's advantaged in that world?

18:15 Like how do how does that actually change the shape of the problem?

18:18 So what you're talking about is AI to help hackers and pentesters, right?

18:22 Yeah.

18:22 Yeah.

18:22 Yeah.

18:23 And that exists right now.

18:24 In fact, I mean we did a research project on it

18:26 last year um and presented at RSA to find hacker tools.

18:30 My favorite one so far is Worm GPT.

18:32 And so you got a copy of Worm GPT?

18:34 We licensed it because it's a soft essentially software as a service.

18:38 They want to make money too and they want recurring

18:39 revenue and they want to build the value of their

18:41 Do you have to pay them in Bitcoin or something like how do they not get caught?

18:44 Yeah, we did pay in Bitcoin over the dark web as usual and we got a deal too.

18:48 We were one of the early adopters.

18:50 So I think right now lifetime is like 500 bucks and we got it for 50.

18:54 So that focus.

18:55 So you're Lifetime Worm GPT users theoretically.

18:58 Somebody has to be.

18:59 Criminals can always change their minds.

19:01 Yes.

19:01 Um, but I was really worried at the time

19:03 about the number of source code leaks that had happened.

19:06 And I was like, with all these source code leaks,

19:08 all this software getting dumped out,

19:10 it makes it so easy to find vulnerabilities.

19:13 And now that there are these AI tools out there,

19:16 it's going to get easier and easier for the bad guys to comb through them.

19:20 And I think that is creating a huge amount of systemic risk.

19:24 And um, it means we now have you can

19:27 go on the dark web and buy exploits really easily.

19:30 there's a whole marketplace for them.

19:32 Um, and at the same time, you know, the software developers just can't keep up.

19:36 It sounds like who is advantaged might be the big companies who are like,

19:41 "Okay, we're going to spend the money and do the resources.

19:44 We've got we can, you know, it's it's a really big deal.

19:47 if somebody hacks Windows or Chrome or something versus uh

19:53 in the world of like the bottom 80% of software which

19:59 is just a huge amount of software you know like

20:02 there's sort of like the you know the the a peak

20:05 where everybody's using the things at the very top

20:07 and then at the base it's like you've got pieces

20:08 of software that like a hundred people are using

20:10 and and so you've got there's like this huge amount of software.

20:13 So that's like that's the world in which the hackers are advantaged.

20:16 Would that be a fair to say?

20:18 Well, I mean, remember Microsoft, for example, is targeted.

20:21 So, I'm not sure that

20:22 Yeah, you're more targeting Microsoft because like that's where the value is.

20:25 Unfortunately, you like to think they're like Fort Knox,

20:27 but large companies have their own problems, too, right?

20:30 There's been this whole secret systemic risk issue.

20:33 Um, for example, so I hope everybody understands from this how

20:38 um information about bugs and vulnerabilities is like nuclear material.

20:42 Like it's really valuable because hackers can use

20:44 that to make exploits and then boom break into things

20:47 and yet at the same time if a tech company does

20:50 get hacked and their information is put out there about bugs

20:53 or vulnerabilities why would anyone ever know about it right

20:58 and that for me as a professional has been the scariest thing

21:00 and why it's almost a relief now that folks like you

21:03 are reaching out to say hey I want to talk about

21:05 vulnerabilities in 2017 Microsoft uh Reuters published an article because They

21:12 said Microsoft's bug tracking database was hacked four years earlier in 2013.

21:17 I don't know if you've heard about that.

21:19 You probably didn't because most journalists don't care.

21:21 And most people are like, "Why do I care if Microsoft's bug tracking database

21:25 was hacked?" But that's their list of all the bugs.

21:28 And that's hackers want that.

21:30 The bad guys want that because then they they don't have to do the work.

21:33 Yeah.

21:34 It's like leaking the the schematics to your to to Fort Knox, you know?

21:38 It's like, "Oh, now I know where all the I know where all the stairs are.

21:42 That's helpful for me.

21:42 I know where the air conditioning vents go.

21:44 Here's all the unpatched vulnerabilities that we have.

21:47 But tech companies don't have to report that or didn't

21:50 have to report that." But if a hospital gets hacked, you will know about that.

21:54 Like they will tell you, right?

21:56 But if a software company gets hacked and that your source code is leaked or uh

22:01 things that you depend on, they weren't

22:03 required for years and years to tell anybody.

22:06 And so this systemic risk has been building up over time without any visibility.

22:11 And that's why a lot of the exploitation that we see occurs today.

22:15 Do you think that there's anything that the people involved in Project

22:19 Glass Wing are underestimating as a threat to this specific like mythos thing?

22:25 Like anything that that Anthropic is underestimating?

22:27 Anything that the companies that have been sort of looped

22:30 into Project Glasswing should be looking out for right now?

22:33 Um, I think that's a really good question.

22:35 I mean they they've got to be balancing so many different issues.

22:39 So I don't really I don't want to come across as critiquing but one thing we

22:43 should all realize is that by so they're

22:46 releasing this only to researchers and to tech companies.

22:50 You know they say three can keep a secret if two of them are dead.

22:53 If you're releasing this to like 40 tech companies and a bunch of researchers,

22:57 it's gonna get out there.

22:59 If you were a bad guy um and you heard about this model,

23:03 but you can't have it, what would you do?

23:05 Well, I would try to hack the people who have access to it.

23:08 Security researchers are not exactly for Knox.

23:11 In fact, I strongly

23:13 I would think that they'd be better at it than most.

23:16 Maybe, but you have, you know,

23:17 think about funding and academia and um, you know,

23:21 I I wonder a lot about the CASSA vulnerability because I'm sure they

23:25 were getting ready to do a disclosure after 3 months had gone by.

23:29 That's a typical time frame about 90 days

23:31 and right before that 90-day window was up,

23:34 boom, a a attacker group uses the vulnerability.

23:38 So, did someone know about that?

23:39 Was a researcher hacked?

23:40 Was a vendor hacked?

23:42 when the Microsoft proxy shell issue came out,

23:45 Microsoft released early information to partners because of course if you

23:49 release a major vulnerability um in an internetf facing Exchange server,

23:55 you need like IT companies and other partners to be prepared for that.

23:59 And so, you know, they had the good out of the goodness of their hearts,

24:02 they wanted to be coordinated and they released that.

24:05 But again, three can keep a secret if two of them are dead.

24:07 82 companies cannot keep a secret and all

24:10 of a sudden we started to see that exploitation happen early.

24:13 So these researchers have targets on their backs.

24:17 Um I hope I assume that they know this.

24:19 So when we first texted about this I was like well

24:24 maybe we'll just find all the bugs and you laughed at me.

24:28 Maybe maybe like we'll be so good at like using this uh

24:32 godlike software developer that is Claude mythos and we'll find all the bugs.

24:36 We'll patch all the exploits and then

24:38 there like we'll just have solved cyber security.

24:41 I mean, what do you think there's more

24:43 of like bugs on the earth versus bugs in software?

24:47 I think bugs on the earth.

24:49 I think bugs in software.

24:53 No.

24:53 Oh man, you don't know how many ants there are.

24:55 There's so many ants.

24:56 It's the It's the ants world.

24:58 There are more bits of data flowing across the internet

25:01 every day than there are stars in the sky.

25:03 I believe that.

25:04 I believe that there's not that many stars in the sky.

25:06 Uh you're talking to a science guy.

25:08 Uh if if you said stars in the Milky Way or in the universe,

25:11 I might be a little more skeptical,

25:12 but the stars in the sky, that's a mere handful.

25:14 What one thing that I I don't get, but I hear security people talking about is

25:19 that the bug doesn't just like sit in the code,

25:22 it sits in the space between the code, you know?

25:25 It's like it's how this thing is talking to this thing.

25:27 It's like, you know, h how the browser is interpreting the font can

25:31 have like a a exploitable bug inside of it.

25:34 And I'm like, I don't know how that would ever work.

25:36 I mean, bugs did start out as literal bugs,

25:39 but these days it's not really a great analogy.

25:42 Um, we're building something with code, right?

25:47 Yeah.

25:46 And like my kid uh this week, he's on spring break.

25:49 He's been so excited.

25:50 He's building a fort in the woods with his friends.

25:53 And I've banned them from using real saws and hammers and nails.

25:58 And so they're making them out of sticks.

26:00 And you know, for years and years, we've been making artisal software.

26:04 We make the code ourselves.

26:06 You know, we're building it out of sticks.

26:08 It's like we live in the time before 2x4s were a thing.

26:11 Oh, wow.

26:12 That's an interesting analogy.

26:13 And so AI comes along and they're like, "Oh, we're going to shake this.

26:16 Wow, it falls down." And that's why they're

26:17 saying it's the space between because it's really about,

26:19 hey, what are the what are the materials that you're using?

26:22 They're not square.

26:23 They're not rectangle.

26:25 They're weirdly shaped.

26:26 You can't quite fit them together, right?

26:28 There's going to be structural issues with it.

26:31 Even our programming languages are written by humans with lots

26:34 of historical issues um and backward compatibility and problems like that.

26:40 Which is maybe also why you said to me as part

26:43 of that conversation that maybe someday cyber security or or these like

26:48 vulnerabilities will be a solved problem but only after we rewrite all

26:52 of the programming languages or after AI rewrites all the programming languages.

26:57 CISA and Microsoft and lots of other major companies even

27:00 today are pushing people to use modern programming languages like

27:04 Rust and away from C and C++ that give the programmer

27:08 the ability to access memory outside of where they should.

27:12 So there's just these fundamental security issues in our programming

27:15 languages um that make it possible for programs to be insecure.

27:21 So yeah, absolutely.

27:22 In order to achieve better security,

27:24 I think we're going to need to take a hard look at what our building

27:27 materials and think about how we can use machines to start making 2x4s at scale.

27:32 Interesting.

27:33 I mean, this is all going to be have to be very metaphorical for me.

27:36 So, we have Rust.

27:37 Rust is a programming language created by humans,

27:39 but you're talking about like does this actually make sense to you

27:44 that the AI will build their own programming languages to program in eventually?

27:49 Absolutely.

27:49 I mean, what is the purpose of a programming language?

27:52 It's it's really it's the interface between humans and the machines.

27:56 So, we're trying to make it understandable to people,

27:59 but as AI codes more and more,

28:02 we won't need humans to have that interface again.

28:05 Like,

28:06 yeah, but like don't you want to be able

28:08 to have somebody go in there and be like, "Oo,

28:10 this this girder is in the wrong place." I mean as a computer scientist I can

28:16 say I don't think one human fully understands

28:19 how a whole computer works and operates and all

28:22 the program we are we are well beyond that at this point in terms of level

28:26 of complexity we're driving the car you know

28:30 and it's what's under the hood is so incredibly complex

28:33 nobody's going to go in there and figure

28:35 out what's happening with that spark plug.

28:37 Yeah.

28:37 No one when it comes to computers.

28:39 No, I don't think in the amount of time that you have in your lifespan that it

28:43 would be possible for you to fully iterate through

28:46 and understand everything that is happening on your computer.

28:48 But it sounds like you're saying that we will not just end

28:52 up in a world where no one person understands all of the pieces,

28:55 but where there will be some pieces that no person understands

28:59 that are not understandable without machine help.

29:02 Absolutely.

29:03 Yep.

29:05 Humans rely on tools.

29:06 We just have to make sure they're reliable and working for us.

29:12 Yeah.

29:12 Is that Have you thought a lot about that?

29:15 It seems like you've thought a lot about that.

29:16 I'm a security professional.

29:19 Um you know the other thing I think about

29:21 a lot and again I feel relieved that people are

29:23 starting to think about vulnerabilities because again this has

29:26 been an issue a pervasive issue for a long time.

29:29 And when you say people,

29:30 do you mean everybody like like me like like folks who have email,

29:35 not folks who work at software companies?

29:37 Yeah, exactly.

29:37 I think in order to affect real change in our security,

29:41 a topic has to be understandable broadly and people have

29:45 to care about it in order to have legislation and, you know,

29:49 responsibility appropriately allocated and funding and things like that.

29:53 There are things that you there are laws that you

29:55 would pass if you were in charge is what I'm hearing.

29:57 I mean, I'm not that authoritarian, but certainly incentive.

30:00 Yeah, there are laws that you would suggest that you would that you

30:03 would build consensus around and that everyone would agree to pass together.

30:07 Well, yeah.

30:07 I think oversight and auditing and, you know,

30:11 disclosure because it makes me really sad.

30:14 Again, I've been a professional pentester for decades or well,

30:17 at least 15 years at this point.

30:19 Over and over, I see vulnerabilities that don't get disclosed.

30:23 Um or there's something called responsible disclosure where you tell a vendor

30:26 about a problem and you think uh because you're optimistic they're

30:30 going to fix it and actually and maybe there's a whole

30:33 bug bounty system where you might get paid for it and often

30:36 that bug bounty system is used like a gag order

30:39 like researchers discover vulnerabilities and they report it to the vendor

30:43 and the vendor says cool you've signed a confidentiality agreement here's

30:46 your money now don't tell anybody about it and they can't tell anybody

30:50 right and that lasts for as long as that secret stays

30:52 secret or for as long as no one else finds that vulnerability.

30:55 Exactly.

30:56 So, we've just been accumulating vulnerabilities for a long time

30:58 and I'm excited that now there's momentum to do something about it.

31:02 And the other big issue we could talk about is systemic risk.

31:05 What's systemic risk?

31:06 Systemic risk is the risk that permeates a system.

31:09 And um I've been thinking recently about Dr.

31:13 Dan Gear.

31:13 I don't know if you've heard of him.

31:15 I'm a big fan.

31:16 He was um he was fired from the company that he started in 2003 because

31:21 he wrote a white paper um about cyber insecurity and the risks of a monoculture.

31:27 And he actually lived um not too far from me in Cambridge, Massachusetts.

31:30 And he was raising honeybees and he was really um interested in nature as well.

31:34 And so the paper talks about how monocultures

31:38 like uh the prevalence of the same code all over the place um means that we're

31:43 at very high risk of a widespread problem.

31:48 Sure.

31:48 Yeah.

31:48 So if a So if everybody's everybody's router uses the same

31:52 OpenBSD software and there's an OpenBSD vulnerability,

31:55 suddenly every router is uh part of a crypto mine.

31:59 Yeah.

31:59 And these have real consequences that often people don't hear about.

32:03 Like I did some work last year for a mental

32:05 health institution that was hit with ransomware because

32:07 of the Microsoft Exchange vulnerability and these have real

32:11 life human consequences that you don't see in the news.

32:14 You have a good instinct for cyber security but anyway I'm terrified.

32:20 It's so scary.

32:21 So can I before you get to your hope and I do

32:23 want to get to your hope um this monoculture thing is very interesting.

32:26 This is what they say about voting machines where like

32:28 America has 50 different voting uh systems which is nice because

32:33 it means that like one thing and also oftenimes like county

32:37 by county it's different and so you don't have like one

32:39 system that you can hack one way uh which which

32:42 is a kind of protection and then also that made me

32:46 think about the way that it feels a little like we

32:50 might be headed into a world of much more personalized software.

32:53 Yeah.

32:54 and and that that that might be good for security reasons.

32:58 I was thinking the same thing.

33:00 You know, it makes me think because right now

33:02 if you find again a vulnerability in one product,

33:04 it can affect millions of people.

33:07 Um but we may be living in an age where like, hey,

33:09 I want an app that does FU and in like a year and a half or two years,

33:14 I might be able to just tell my AI friend to make it and poof, it's made.

33:18 Right now, I actually have to like work out the bugs in my vibe coding software.

33:22 It's making me crazy.

33:23 Um, but it might be really easy.

33:25 This is the This is the vibe coding uh brain candy thing where it's like,

33:31 "Ooh, you got 80% of the way there.

33:33 That's very exciting." And then getting to 99% is is is like a a huge

33:39 amount of work and then getting to 100% is that much work again.

33:43 Oh, it's like I'm in college and I got

33:45 in an argument with Claude Code and I was like, "Oh, hey,

33:48 you put the wrong folder name here." And it was like,

33:50 "You put the wrong folder name here." And I was like, "No, dude.

33:53 You wrote that." But yeah, he's like, "I don't know what who wrote what.

33:59 Look, I don't have contextual memory.

34:03 Things don't exist to me, Sherry.

34:06 I don't agree with all of the decisions that Claude

34:08 Code is making." And you got to like double check it.

34:11 Oh, for sure.

34:12 But I'm hopeful because with this age of personalized and customized software,

34:16 maybe we can use AI to reduce monocultures and to add more

34:22 diversity and that could reduce risk

34:24 associated with other types of security problems.

34:28 And that's interesting because it's it's not saying

34:30 that there's not going to be bugs in that code.

34:32 There's going to be bugs in that code.

34:33 It's saying if the danger of a bug just

34:36 increases exponentially with the number of people using that software.

34:39 And if it is if it is one, then it's really down to how much someone wants

34:43 to hack you specifically rather than someone using uh you know

34:48 an exploit that came out and and then they can

34:50 sort of hit you know 30 hospitals in one day.

34:54 Yeah.

34:54 I mean are we going to hack BSD or are we going to hack Microsoft Windows?

34:57 Um where are we going to invest those resources

35:00 or are you going to hack like Sherry's customuilt CRM?

35:03 Don't do that.

35:04 Don't do that.

35:05 Well, I mean I do think that it's it's something to be concerned about.

35:08 It's it's not like uh AI is great at security.

35:13 Well, I guess it maybe it will be eventually,

35:15 but like right now cloud code isn't thinking uh through

35:18 all the different implications of all the strange decisions it's making.

35:21 I I imagine I have a second AI that I use to check

35:24 the first AI which I think has been helping a lot

35:26 because it'll be like you know tell it to do

35:28 blah blah blah differently and I'm like okay thank you.

35:31 As a person who is uh mid-career,

35:33 how do you feel about what what would it be like different

35:38 for you if you were doing this if you were starting your career now

35:41 in cyber security?

35:42 I don't know like what whatever you were up to when you graduated.

35:46 I mean, it's interesting.

35:48 I think everybody in computer science is who's

35:50 in it right now is probably questioning that.

35:53 Um there's a lot of software developers

35:56 that might be trying to figure out next steps

35:58 in their career or looking at new fields

36:01 potentially because claude code and other tools are

36:04 getting so good at v coding and a lot of it is more like understanding

36:08 the needs of the business and making sure

36:11 your UI is really solid and things like that.

36:14 You think cloud's bad at UI?

36:16 No, no.

36:16 Cloud isn't bad at UI, but you know,

36:18 you the human have to guide it and tell it what you want.

36:21 You you actually know what a human like what you want the the tool to do.

36:25 Correct.

36:26 That also introduces other problems which could

36:28 potentially be job security for some people.

36:31 You know, the the risks of malware being

36:33 introduced through vibe coding tools um is very real.

36:37 The Amazon Q AI tool uh software um what's that?

36:41 I don't know what that is.

36:42 So, Amazon um had a has an AI tool, Amazon Q,

36:47 um for vibe coding and um I believe it was

36:50 being managed through GitHub and some unauthorized user got access

36:54 and planted malicious code which was deployed to over a million

36:57 developers and the intent was to wipe people's hard drives.

37:02 Fortunately, it did not work.

37:04 But I think it's pretty scary that this was not detected by a major company.

37:08 And one little configuration flaw in um

37:11 the code management system could potentially uh lead

37:15 to unauthorized access and then deployment of unauthorized

37:18 code to thousands or millions of people.

37:20 Damn.

37:20 Um it sounds should I expect well I guess the broad

37:27 question here is is there something that I should be doing?

37:31 Is there something that people watching this should be doing?

37:33 is the like is the vulnerability landscape changing dramatically enough that we

37:38 need to be acting differently than we were two years ago.

37:42 I think one thing is it's important to take

37:43 advantage of resources they have and I consult for businesses.

37:46 Um and actually tomorrow I'm going to be recording a podcast

37:49 for my clients and community and I need to provide clear takeaways,

37:55 actionable takeaways.

37:56 And I think we're living in an age where if you

37:59 have software developers in-house or if you rely on any third parties,

38:03 they must be using AI.

38:06 Um, you have to be using AI to check your code.

38:09 Uh, and in some cases,

38:10 if they're already using AI to create their code, um, which has its benefits,

38:15 make sure that they're using it in intelligent ways and that they're

38:18 really paying attention to the software development piece of it.

38:21 So is there is there like a for people creating code there is

38:25 there like a security type step that one would want to be using?

38:30 You've probably noticed lots more updates than you

38:32 used to are coming from software development companies, right?

38:35 So you might be getting new feature,

38:37 new this, new that and that's happening because

38:39 more companies are vibe coding and that's cool.

38:41 So there's new features being launched.

38:42 That's not because they're saying, "Oh, we patched a bug.

38:44 Oh, another bug that we found that we

38:46 patched maybe also that quite fingers crossed." Oh yeah, hopefully.

38:50 But they're also really excited to these new features available.

38:53 They have to stay keep up with their competitors.

38:56 So we're going to see new features coming out rapidly as well,

38:58 which means of course more bugs and you want

39:01 to make sure they have a secure software development life cycle.

39:04 And Hank, a lot of companies do software development that you might not expect.

39:08 Um, some of my clients that do tons of software development,

39:11 for example, are banks and credit union.

39:13 Sure.

39:13 Yeah.

39:13 Um, they often have in-house developers to make custom tools.

39:17 And so you know they need to have mature software development life cycle

39:21 or that company you've hired out of India to make that web application.

39:24 Um you need to make sure that you're looking

39:26 under the hood at what that vendor is doing.

39:28 For clarity I have not hired a company out of India to make a web application

39:34 yet.

39:34 Yeah.

39:35 I Yeah.

39:35 No, I'm not going to cross it off the list of things I might do.

39:38 This is not a thing I expected you to say but it sounds like

39:42 um there are just a lot of there are a fair number of zero days.

39:46 There are also a bunch of like known

39:48 bugs and exploits and vulnerabilities that are unpatched.

39:53 Um, and also like you know anytime there's

39:57 people who just aren't uploading updating their software,

40:00 make sure you update your software everyone.

40:01 That's my tip to you.

40:02 People aren't updating their software.

40:04 People uh you know it's it's it's complicated.

40:07 Maybe the IT department uh is is very stretched thin.

40:11 Um, I didn't I didn't think that the problem would be, "Oh,

40:14 we found the bugs." Um, and we didn't do anything about them.

40:18 I thought the problem would be, "Oh,

40:19 there's going to be a bunch of bugs that keep getting

40:21 found forever." But it sounds like it's both of those things.

40:23 Oh, yeah.

40:24 It's such a hard problem.

40:25 There are so many bugs that just have been getting dusty for years and years.

40:29 And that's always been the case.

40:31 Some of them are.

40:31 It's hard sometimes.

40:32 Like, you got to have your software like still work after you fix the bug.

40:35 And that might mean still interfacing with a bunch

40:38 of different systems that you don't control.

40:41 And people are afraid to to apply patches.

40:43 Like again, I had a another client

40:45 that was afraid to apply the Microsoft Exchange patch.

40:48 Waited like six hours.

40:50 That's it.

40:51 And they were already hacked by the time they applied the patch.

40:54 Um, so because you're like, I want to test this.

40:57 Um, when I worked at the Children's Hospital in Boston,

40:59 we would have a whole testing process because,

41:02 you know, I mean, it's life or death around a hospital.

41:04 You don't want your systems to crash, but we don't always have time to do that.

41:09 Um, I started using a term recently that I'm really excited about.

41:12 Hank, can I tell you what it is?

41:14 Um, negative days.

41:16 We hear a lot about zero day vulnerabilities,

41:18 also endday vulnerabilities that have been around for a while.

41:21 But just last month, I wrote a blog and I was like,

41:23 we're dealing with negative day vulnerabilities where they're getting hacked.

41:26 Like people are getting hacked before anybody even

41:29 actually before the vendor knows about the vulnerability.

41:31 It's just out there.

41:32 Well, I mean, that's what I always sort of imagined a zero day to be,

41:35 but I guess it can be a zero day for more than one day.

41:37 Yes, exactly.

41:39 People are just getting hacked and don't even know it sometimes for months.

41:42 It does freak me out.

41:43 It seems like a big deal.

41:45 It it also seems like you're making me feel very much

41:48 like uh we're we're we're in the baby days of software,

41:51 which is not which is not how I think.

41:54 You know, I think that the baby days

41:56 of software were like cobalt or punch cards,

41:59 but in fact, like this might still be the baby days of software and Yeah.

42:04 What was the baby days of again building houses?

42:06 We had like yurts and tents and all kinds.

42:08 Yeah, I guess it was a while before we got to a while.

42:11 We learned a lot.

42:12 I am so excited about two 2x4s and having machines

42:16 that can create them rapidly because we are going to build

42:19 some really cool stuff and we're going to get to a whole

42:22 new level of engineering and things that humanity can do.

42:26 I don't talk to a lot of people who are like

42:28 immediately uh I don't know it seems like you're optimistic about AI.

42:32 I'll hit you with a thought that I keep having which

42:34 is I did not realize how software constrained the world was.

42:38 I assumed that we had the amount of software that we needed.

42:41 But in fact, what appears to be the case

42:44 is that if you can create 10 times more software,

42:46 we need 10 times more software.

42:48 Which indicates that if you could create a 100 times more software,

42:51 we might need a hundred times more software.

42:53 And if you could generate a thousand times more software,

42:55 we might need a thousand times more software.

42:56 And we just didn't know that because we

42:58 were constrained by like it being written by people.

43:01 I have been waiting for technology and software to catch up for so many years.

43:05 I remember when I started my business in 2009,

43:08 I wanted a learning management system and they barely existed at the time

43:11 and I wanted project management systems and they were crappy at the time.

43:15 And all of these things that exist now are beautiful and um we could have

43:21 so many more customized so it integrates

43:24 into our organizations and our lives at a

43:26 Aren't you terrified of that as a security professional though?

43:29 like that.

43:29 Like who's going to pentest everything, you know?

43:32 If if if there's if there's a thousand times more software,

43:35 there's a thousand times more bugs.

43:37 AI pentesters.

43:39 Yeah, that's if you're putting yourself out of the job over here.

43:43 Oh, I don't think I think there's still going to be a level like right now.

43:47 AI pentest tools are hilarious.

43:49 Um or but I mean it sounds like Mythos is a pretty powerful AI pentest tool.

43:54 Well, and it's amazing how far AI tools have come in the past year and a half.

43:57 Like when I did this research and presented at RSA,

43:59 we were researching AI tools on the dark web late 2024, early 2025,

44:04 and they came up with exploits, but our pentest team was like,

44:07 h, we'd have to change some stuff for it to work.

44:09 And it sounds like now it is.

44:12 So So you were actually using this worm GPT or whatever.

44:16 And it it did succeed in finding some vulnerabilities for you,

44:21 but not like out of the box useful.

44:23 You actually had to know some stuff to use it.

44:26 I mean it was useful like we analyzed Magento

44:28 for example which is a popular e-commerce site and we

44:31 had it scanned for vulnerabilities uh and we found it

44:34 it's open source we found some vulnerabilities and we said

44:36 write us an exploit and again Tom our head

44:39 of pentest and this was by the way Matt Duran was

44:41 my co-author on this project and did a lot

44:43 of the work just to give him credit that he deserves.

44:45 Um my uh Tom who is our head head of penetration testing had

44:50 to go in and tweak some stuff for the exploits to actually work.

44:54 Um, and I was irritated at the time because I wanted the AI tools to be better.

44:59 Now they are and they don't all

45:01 have the same ethical constraints that Anthropic has, you know, making this.

45:06 So, keep that in mind.

45:07 Like, you know, we have Anthropic making this big announcement.

45:10 Who's to say China doesn't have the same capabilities?

45:13 Who's to say that some uh, you know, um,

45:17 some organized crime group doesn't already have something like this?

45:20 So, keep in mind they're not the only ones developing these capabilities.

45:23 It did also occur to me that the U recently the Department of Defense was like,

45:27 "We don't want to work with Anthropic anymore." And and I'm like,

45:30 "Well, I feel like maybe it would have been nice

45:32 to be working with the company that can hack everything.

45:37 If you're the Department of Defense and you're getting ready to uh

45:40 be in a cyber war with uh half of the world,

45:45 that's a I just scared myself talking out loud.

45:48 Don't be as scared.

45:49 I used to be smart as a security professional because I saw so much

45:52 that I couldn't talk about and you know even and can't talk about today.

45:57 Um but at a certain point you step back

45:59 and realize like we're all going to die anyway.

46:02 Um so yeah Sherry that made me feel way better.

46:07 I think that what's going to happen is

46:08 going to be way different than what anybody predicts.

46:11 That's the one thing that I'm predicting.

46:13 I agree with you there.

46:14 I agree with you there.

46:15 And I think that it's very hard to remember that lesson even

46:18 though we learn it every time some big new technology comes along.

46:22 Um, am I about to get a bunch of like software update notifications?

46:26 Be prepared for that because number one, you're going to get feature updates.

46:29 Hopefully a bunch.

46:30 I bet it'll be exciting, but yeah,

46:32 you're going to almost certainly see a bunch of bug bug fixes.

46:36 Probably way more critical bug fixes maybe than we've ever seen.

46:39 We'll see.

46:40 Are these people going to be totally exhausted?

46:43 It sounds like sometimes these bugs just sit around.

46:47 Um, and maybe they're not that critical.

46:49 Maybe, you know, they don't affect that that many people,

46:53 but are are these people now going to have to just

46:56 sort of like put their nose to the grindstone and be like,

46:59 "Okay, we have a thousand bugs we need to fix,

47:00 like we have a thousand critical zero day security vulnerabilities." My hope

47:05 and expectation is that along with project glasswing um we're going

47:09 to also see development of AI tools to fix bugs so

47:13 that we can fix them so much more rapidly than ever before.

47:16 I'm guessing that's going hand inand with the launch of this, right?

47:19 Don't you think?

47:21 Yeah.

47:21 I Yeah.

47:21 Yeah.

47:22 Yeah.

47:22 And I think that they even like with FFmpeg

47:25 they handed over a patch along with the bug.

47:29 So they were like we found this bug, here's the patch.

47:32 Uh they didn't even make FFmpeg fix it.

47:34 The hard part will be testing.

47:35 Testing to make sure that after you make these code changes,

47:38 the software still performs the way you expect.

47:41 I hate that, Cherry.

47:42 That that that makes it that makes it sound like it's going to be hard.

47:44 I just want it to be all the bugs to go away and I want everything to get fixed.

47:49 I You're so crabby when you're sick, Hank.

47:52 Look, maybe that's what the problem is.

47:54 I think it's funny we're talking about this while you have a virus.

47:56 you're but I am I am somewhat surprised by your level

48:03 of hope because I I've talked to you and there

48:05 are certain things that you are very uh pessimistic about like

48:10 you're angry that things are set up the way that they

48:12 are often you find that I I often find that there's

48:15 like some like thing that I think is a normal

48:18 function of society in the universe where you're like I cannot

48:21 believe that we're being mistreated in this way as a society.

48:24 credit card use I think is one I the way

48:27 that credit cards work in America being one of them started I know I have before

48:33 uh but it it it seems it seems like you think that we're

48:36 going to be able to get to to make our way through this

48:40 I've been very stressed out since 2010 when the operation Aurora attacks

48:44 hit um because tech companies were

48:47 getting hacked and compromised and source code

48:49 was getting leaked and therefore in the hands of malicious actors

48:54 And that meant that vulnerabilities were getting

48:56 stockpiled and nobody was talking about it.

48:59 And so I feel super relieved that this is out in the open

49:03 and it's now going to be something that we have to deal with.

49:05 Software vulnerabilities and software exploitation are the number

49:08 one cause of um of compromise today.

49:13 And so if we can actually tackle this together um openly and address it,

49:18 that's going to make all of us more secure in the long run.

49:21 Do you are you glad that it was Anthropic that got this first?

49:25 I don't know if they got it first.

49:28 Well, that's an interesting way to end the conversation,

49:33 but I'm glad you published it.

49:34 I think there's pros and cons.

49:36 Um again I think those there needs to be a concerted

49:39 effort to secure help researchers gain that access project glasswing

49:44 to remain secure themselves and to report any leaks or inappropriate

49:49 access to the glasswing to project glass wing and the tools.

49:53 When do you think uh you get access to it?

49:55 I don't know if I want access to the mythos preview or to project glasswing

50:00 because you don't want to be a target.

50:01 Correct.

50:02 I think that's a lot of responsibility

50:04 and I have other projects I'm excited about.

50:06 What are you excited about right now?

50:08 Oh, I can't tell you yet.

50:10 Oh, Sher David off LMG Security.

50:13 Thank you so much for spending some time with me.

50:15 Oh, thank you so much.

50:16 I really appreciate it.

50:17 It's always fun to be on.

50:18 That conversation did not go how I expected.

50:21 It is now the next day.

50:22 I know I'm wearing the same clothes, but it's now the next day.

50:24 I've been thinking about it ever since.

50:26 I hope that it uh sparked some sparks for you as well.

50:29 Last time I had Sherry on, people were asking,

50:31 "How do I get more Sherry?" She has a podcast

50:33 and I will link to it in the description.

50:35 And also again, if you want to spend some more time

50:37 in your own mind exploring this part of stuff that nobody can hack,

50:41 you know, The Book of Good Times is available.

50:44 There's a link in the description.

Study with Looplines Download Captions Watch on YouTube