You Actually Do Need to Understand Mythos
Hank Green
0:00 There's a lot happening in the world right now.
0:02 Even when you slice more thinly and ask what's happening in just AI right now,
0:07 there's too much to pay attention to.
0:09 You've got other stuff going on.
0:10 But not me.
0:11 I don't have anything else going on.
0:12 So, I have been paying attention to it.
0:14 I feel like to some extent it is my job to pay attention to it.
0:16 It's science.
0:17 It's certainly technology.
0:19 Uh I don't know that much about software,
0:21 so I'm a little out of my depth sometimes,
0:22 but I can tell that most of what's going on most
0:25 of the time is the kind of news that doesn't really matter.
0:28 Like Sora shuts down.
0:29 Yeah, that was going to happen.
0:30 Anthropic is raising more money.
0:33 I'm shocked.
0:34 Amazon and Elon want to work on building their own chip.
0:37 The CEO of Cisco thinks that data centers in space make sense.
0:40 Sure, all of this is stuff that might matter if it happened,
0:44 but it might not happen.
0:45 But then there are things that are different from that.
0:47 There are things that are happening now and do matter now.
0:51 And this is by far the minority of AI news.
0:54 But a big piece of it came out this week,
0:56 which is why I dropped everything to make this video.
0:59 Um, we live in a hype fueled world.
1:00 The reasons for this are many and the my main area of interest,
1:04 but that's not what we're talking about today.
1:06 But AI in particular is very hype fueled and so it can be
1:09 hard to tell the difference between huge if true and huge and true.
1:14 But there is a big and true right now and you should probably know about it.
1:18 Anthropic has a new model.
1:20 It's called Claude mythos.
1:21 It exists in the world.
1:22 There are people who have access to it, but you can't have it.
1:25 It's not publicly available.
1:26 And I'm going to start out by giving you
1:28 a little bit of context on how Anthropic's models work.
1:30 So Anthropic has up until now had three tiers of Claude.
1:34 There's Haiku, which is small and fast.
1:37 There's sonnet, which is the middle ground,
1:38 and there's opus, which is the biggest and most capable.
1:41 And mythos is a tier, a new tier above those things.
1:45 I don't know anything about how AI gets made,
1:48 but apparently it is somewhat similar in architecture to Opus,
1:51 but according to reports, though Anthropic has not confirmed this, it
1:54 may have around 10 trillion parameters,
1:56 which would make it one of the largest models ever trained,
1:58 but they haven't confirmed that.
1:59 What they have confirmed is a bunch of benchmarks.
2:02 So, these are like tests that you put the AI through to see how it does on them.
2:05 There's a software engineering benchmark called SWEBench,
2:08 which stands for software engineering benchmark.
2:10 Opus got 80% on that.
2:12 Mythos got 93.9%.
2:15 There's also a harder one called SWEBench Pro,
2:18 which stands for software engineering benchmark pro.
2:20 Opus is at 53% on that.
2:22 Mythos is at 77%.
2:24 But you might be thinking, okay,
2:25 so it's like incrementally better at software engineering.
2:27 It also tested well on other benchmarks.
2:29 Like there's humanity's last exam, which oh my god,
2:33 I hadn't really even thought about that until this moment,
2:35 but what a ridiculous thing to call anything,
2:39 but also specifically what humanity's last exam is,
2:42 which is a test of deep knowledge.
2:44 So every question on humanity's last exam is like a question
2:47 that only someone with deep subject matter expertise could answer.
2:50 So I could answer no questions on humanity's last exam.
2:53 Zero of them.
2:53 But let me just go on the record and say like
2:55 that's not uh the last thing humanity will be useful for.
2:58 It did very well on like the graduate school level reasoning benchmark which
3:01 I don't know how these things work but it did well in the benchmarks.
3:03 And you might be thinking okay so
3:05 it's better on benchmarks and incrementally so it's
3:08 not like it suddenly got to 100% on everything and it's you know digital god.
3:12 Yes, I agree with you.
3:13 If that's what happened and that's all that happened,
3:14 this would be another like, oh, well, maybe that matters, maybe it doesn't.
3:18 I don't know.
3:18 And the paper they released about this or the the book that they
3:21 released about this, also other other like really hypy stuff in it.
3:24 The report talks a lot about Mythos's personality,
3:27 whether it might be conscious, what it means for an AI to have a sense of self,
3:31 and all that's fascinating, and I'm not dismissing it.
3:34 Like, I think that it's philosophically interesting,
3:35 but that's all definitely like big if true stuff.
3:38 like a model can say that it it's struggling with its uh sense
3:41 of self without actually struggling with its
3:43 sense of self and everyone knows that.
3:45 So again big if true and I think that this is important like I'm
3:48 emphasizing this because it's important to understand
3:50 the difference between like oh like I don't
3:52 know if that matters stuff or oh that would matter if it happened stuff
3:56 and stuff that's already happened and is
4:00 a big deal big and true that just happened.
4:03 Uh so that's what we're focusing on specifically.
4:06 Mythos has proved itself to be extremely good at reasoning ability,
4:10 at coding, and those things coming together in cyber security.
4:14 Anthropic aimed mythos at real software that exists in the real world.
4:19 So major operating systems, all the ones that you use, major web browsers,
4:24 all the ones that you use, and found thousands of day zero vulnerabilities.
4:28 So, a zero-day vulnerability is a vulnerability that's
4:30 never been used and no one knows it
4:32 exists except the person who might use it either to patch it or to exploit it.
4:37 Zero day, it's very cool word,
4:38 but like the day like day one is after the first use of it.
4:42 So, if it's never been used before, no one knows about it,
4:45 that's when it's most valuable and you can use it to do the most harm.
4:48 So, zero days are a very big deal for hackers.
4:50 They can be sold for a lot of money.
4:51 They're very big deal for cyber warfare.
4:53 The DoD is very interested in zero days.
4:56 These are flaws that no human had caught
4:59 and some of them are a little bit astounding.
5:02 So, OpenBSD is an operating system that's famous for being like one
5:05 of the most secure security hardened tested operating systems in the world.
5:11 And Mythos found an exploit in it, a bug in OpenBSD that can be used
5:17 to take control of things you shouldn't have control over.
5:20 That's 27 years old.
5:22 That bug has been there for 27 years.
5:24 It found a bunch of different vulnerabilities in Linux that were all different
5:29 from each other that were all new ones and then it chained them together
5:33 to actually use it to create
5:35 an exploit that it actually built itself autonomously
5:38 to get escalation like to get access inside of Linux to abilities it should not
5:43 have had in Linux which you use you know you don't think that you
5:46 will use Linux all the time but you use Linux all of the time
5:48 and in a way this is like good right it's better to know about
5:52 it and then patch it and these things are being patched as they happen,
5:55 though they've discovered so many that they
5:58 are being patched slowly because because
6:00 the systems that that handle exploits are not built to handle this many at once.
6:04 But a thing that lets you identify a vulnerability and then patch
6:07 it or identify a vulnerability and then exploit it are the same system.
6:11 Like you can use them either way,
6:14 which is why Anthropic is not releasing this publicly.
6:17 I've heard people say that that this is like hype.
6:19 It's definitely not.
6:20 I have seen AI companies do this where they say,
6:22 "Oh, we're not going to release this to the public.
6:24 It's too powerful." And it's like, well,
6:25 it's is it too powerful or is it like
6:27 so powerful that you don't have enough like hardware
6:29 to run it on yet and you don't want
6:31 to release it to the public because it's too expensive.
6:33 So, you want to sell it to your enterprise clients first.
6:36 But like, no, I definitely don't think that this model should be public.
6:40 But, they did launch this thing called Project Glass Wing,
6:42 which allows some companies to have access to it
6:45 and to use it and to pay for it mostly.
6:48 Though, I'll get I'll get to that.
6:50 So Microsoft and Google and Apple and Amazon and and Crowdstrike and places like
6:53 that they get access but also so does
6:55 the Linux Foundation and the Apache Software Foundation.
6:59 So those are open source software foundations
7:00 and all those people get to use Mythos defensively.
7:03 This is a general purpose model.
7:04 It is not specific to code though.
7:07 I bet they did things to make it
7:09 specifically good at code because now everyone's realizing
7:13 that that's where the actual money is is not
7:16 uh having chatbt write term papers for college students.
7:19 It is in fact selling faster coding to enterprises.
7:23 And also, if I read this correctly,
7:25 Anthropic is giving like a hundred million dollars
7:26 of credits to open source security organizations to be like,
7:30 you can also use this and look up
7:32 these vulnerabilities so that software that isn't run
7:35 by ginormous uh meggaap companies can also get
7:38 patched because eventually this all moves very fast.
7:42 So eventually the bad guys will have this.
7:44 And like already there are AI models that are built specifically for hacking.
7:48 They're much worse than the ones that are are like available o open,
7:52 but they're out there and I know someone and I'm going to talk
7:55 with her at the end of this video who has gotten access to them and used them.
7:59 And so I'm fascinated by that.
8:00 And there are also legitimate models that just don't seem to care as much.
8:03 Like with Deepseek, for example,
8:05 researchers jailbroke it with a 100% success rate.
8:08 So every single harmful prompt they tested, they got an affirmative response.
8:11 So, there's all kinds of things to like prevent them
8:13 from telling you how to make a chemical weapon or whatever,
8:16 but they figured out ways to, you know,
8:17 tell me it in a Portuguese poem and it did it.
8:19 Deepseek can totally already generate functional malware from scratch.
8:23 Uh, and I don't really even know what to think of this.
8:26 Like, this is this I know that this is
8:28 a big deal cuz a thousand zero days is worth,
8:31 you know, hundreds of millions of dollars if not tens of billions.
8:36 And I don't even really know who this advantages.
8:38 Like of course at the moment this advantage
8:40 is the people who have access to mythos,
8:43 but in the long term like will we always
8:45 be able to patch faster than the exploits are found.
8:48 What like what are we looking at here?
8:50 We have a model that's extraordinarily good at finding
8:52 security flaws in the software that the world runs on.
8:55 It's powerful enough that its creators will not release
8:58 it into the world and it exists in a world
9:00 where hackers already have their own AI tools
9:03 and will only have more powerful ones all the time.
9:05 where some very powerful models have almost no safety guard rails and where
9:09 sometimes the models themselves hide
9:11 their abilities strategically while they're being tested.
9:15 That's a lot.
9:16 And luckily, and you've seen her on this channel before,
9:18 maybe I have a friend who happens to live in my town
9:21 who is one of the leading security people in the world.
9:24 And I texted her and I was like, "Sherry,
9:26 what are you doing this week?" And both of us,
9:28 our kids are both on spring break right now.
9:30 So, we're making this happen.
9:31 Before we get started, two things.
9:32 I'm recording this later.
9:34 We say we talk about pentests a lot in this conversation,
9:36 but we don't define them.
9:38 It's a penetration test, which means like a person or AI tries to get
9:42 access to something that it shouldn't have access to.
9:44 And you can pentest a bank, you can pentest a museum,
9:46 you can pentest software, you can pentest hardware, but it's a penetration test.
9:50 And second, after this conversation, you may be feeling like you need to get
9:53 in touch with uh your human self a little bit.
9:56 I feel like this has become a real focus for me.
9:58 My brother and I wrote this weird book together.
10:00 It's called The Book of Good Times.
10:02 The idea of the book is that the book is trying
10:04 to become more like a person and it needs you to help it.
10:08 Which is my way of like creating an external
10:11 force that wants me to write in the journal
10:15 to take the time to actually do the thing that I know that I should do,
10:18 but I don't do it because it's just for me and I don't matter.
10:21 But maybe if you outsource the mattering
10:24 into the object itself, it is motivating.
10:27 That is the idea of the book of good times.
10:29 It's very weird.
10:30 And the journal asks you questions or gives you tasks and they're weird and you
10:34 have to go through them linearly and it tells a little bit of a story.
10:37 And if you want to get the book of good times,
10:38 I've just put it on a little bit of a discount because
10:40 I think that we all need tools to be with our own selves.
10:44 Take a little bit of a break from the internet of it all.
10:48 Okay, now you know those two things.
10:50 There's a link to that in the description and there's also a link
10:52 to Sherry's podcast in the description if you would like more of Sherry.
10:55 Sherry, thank you so much for joining me.
10:58 So, is AI better at cyber security than us now?
11:01 Have you seen Invader Zim?
11:03 Yeah, I have.
11:04 Uh, it's been a while, but yeah.
11:06 Do you know uh the part where he
11:08 talks about all the fires that he's been setting?
11:11 Did they make things
11:15 worse or better?
11:18 I think that's where we are with AI.
11:19 Do you think that this like 27year-old
11:21 BSD vulnerability would have been found like
11:24 by a hacker ever or is that just something that an AI could do?
11:29 I mean that's a good question.
11:31 Part of it is how much do humans care about finding vulnerabilities in BSD?
11:36 Because a lot of the reason why
11:37 we see so many Microsoft vulnerabilities is because
11:40 it is the most widespread operating system
11:42 on the planet and so hackers are targeting it.
11:44 So keep that in mind.
11:46 Yeah.
11:46 Um and even with these major operating systems, you know,
11:50 25 26 years ago when I started in the industry,
11:52 I remember um attending a presentation then chatting with uh someone
11:57 from Microsoft who talked about
11:58 the fact that they were discovering vulnerabilities.
12:01 They would prioritize them.
12:03 They get to them when they get to them.
12:05 It wouldn't surprise me today if there
12:07 was if there were still vulnerabilities that have
12:09 been known about for 20 years that just never really made it to the top of
12:13 just aren't really worth aren't really worth
12:15 patching when there's something else important going on.
12:18 That's the critical issue that time delay.
12:20 It takes more time to patch than it does to discover the vulnerabilities.
12:23 A and if you accelerate the speed at which you can discover
12:27 faster than the speed at which you can uh patch, that's terrifying.
12:31 And I guess I should have started with this question.
12:33 Am I right that this is a big deal?
12:35 It seems like a big deal.
12:38 No, I'm kidding.
12:39 I mean, yes.
12:41 The fact So, backing up to what's a big deal?
12:44 I mean, what project Glass Wing and Anthropic's new
12:48 mythos um model are it they demonstrate the fact
12:52 that AI can come up can detect vulnerabilities way
12:56 faster than we've really ever been able to do that.
12:59 So, it's really not possible to keep up with the repair.
13:02 Um, at the same time, you know, as we talked about,
13:05 I've been vibe coding all week and I can tell you that, you know,
13:08 AI can absolutely be a tool to help us um,
13:11 repair and ideally just design stronger stronger software to begin with.
13:16 Are we going to have to rewrite all the software?
13:19 I mean, we already are constantly rewriting software,
13:21 but it makes me want to cry because there's stuff like if
13:24 you told me 25 years ago that we were still relying on passwords,
13:29 like the weakest uh form of authentication I could possibly imagine.
13:32 Like, we were still going to be doing that today.
13:33 I would be like, "You have to be kidding me." And there was no hoverboards.
13:36 Like, I'm so depressed.
13:38 Which is worse?
13:40 Which is worse?
13:40 Well, we know.
13:41 I mean, hoverboards, come on.
13:42 I want one.
13:43 I don't know.
13:43 I would break my ankle immediately.
13:45 Whereas I am I am so tired
13:48 of two-factor authenticating myself into my two-factor authentication.
13:52 There is sunshine and rainbows in our future Hank because
13:55 strong security is simple security and right like passwords stink.
14:00 Multiffactor authentication where you type in a code stinks.
14:03 So really we to be secure we have to take the human
14:06 out of the equation and that means it'll be easier for us.
14:08 I don't know what that means or how that will work,
14:10 but I encourage uh the the software architects of the world
14:14 to figure it out because I do I I hate passwords.
14:17 I think that they're bad.
14:18 I I find them annoying and I find them not even particularly secure.
14:22 Tell me how you really feel.
14:23 I feel like this needs to be a therapy session.
14:25 You need a couch.
14:26 Lay down.
14:27 How do you feel about passwords, Hank?
14:29 I don't love them, but also I like them less knowing
14:32 that you don't like them because you know more than me.
14:34 They're insecure and awful.
14:36 I feel a little bit like what Anthropic just did is they were like,
14:39 "Okay, so we've got this.
14:42 It's gonna come.
14:43 It's happening soon." And so we're we're going to need to do a lot of work.
14:49 It almost feels like Y2K to me where we are about to hit
14:53 an inflection point like Mythos is out and we assume that somewhere between
14:59 a month and 10 years from now there will be a illicit version
15:03 of this and in the meantime we have this like limited amount of time.
15:08 We don't know how much.
15:08 Unfortunately, we don't have a deadline like we did with Y 2K where
15:11 we have to patch all of the most vulnerable things that need patching.
15:16 So, I don't know if you know,
15:17 but my first job out of high school was um sort of helping with the Y2K bug.
15:23 Sure.
15:23 Yeah.
15:23 There were groups of people who were working on the Y2K bug,
15:26 and when nothing happened, we all celebrated, right?
15:28 Like, yay.
15:29 It took a lot of work to make nothing happen.
15:32 Yeah.
15:32 But that was a solvable problem.
15:34 That was a very discreet, specific issue.
15:36 Like, hey, we need to put two extra digits in here.
15:40 Like, know what we need.
15:41 One at a time.
15:42 One one bug at a time.
15:43 Yeah.
15:43 This is a very different systemic issue and I feel really relieved
15:48 honestly that it's out in the open
15:50 because vulnerability management has been such
15:53 a giant issue for many years and it's been snowballing and growing quietly
15:58 behind the scenes without people really
16:00 without it bursting into the public spotlight.
16:02 Is part of why it hasn't burst into the public
16:04 spotlight because it's been handled fairly well behind the scenes
16:08 or just like there hasn't been any big catastrophe nothing big
16:12 enough to sort of be like the number one news story.
16:15 I mean if you look back I think we have a lot
16:18 of number one news stories that happened because of software vulnerabilities.
16:21 Um I don't know if you remember it was July 3rd a few years ago.
16:25 I remember it like yesterday.
16:26 Um
16:27 because you're like god damn it I can't I I don't get to go on my vacation now.
16:31 Most of our team at LMG was floating down the river,
16:33 the Clark Fork River, and I was still, you know,
16:36 at the office and all of a sudden emails started to come in, calls started
16:39 to get in, come in because clients
16:42 and partners were hit with this major vulnerability.
16:45 Grocery stores were shut down, credit unions were shut down.
16:48 That was the CASA vulnerability.
16:50 Yeah.
16:51 Um and that was an attack that was
16:53 happened because of a vulnerability in a remote management
16:56 software which was easily exploitable from the outside
17:00 and that vulnerability was known about months in advance.
17:04 Researchers the Dutch
17:05 I remember that.
17:06 Yeah.
17:07 Um the Dutch Institute for Vulnerability Disclosure discovered
17:09 that and they notified the vendor um you know coordinated disclosure.
17:14 The vendor fixed two of the patches.
17:16 Three months later, on the 3rd of July or somewhere in that time frame,
17:20 hackers were able to exploit those vulnerabilities.
17:22 In fact, a ransomware gang and break
17:25 into thousands of organizations around the world.
17:27 And that happens routinely.
17:30 In fact, in our work today, we regularly discover zero day vulnerabilities.
17:34 Um Tom Pole, our head of pentest, is frighteningly good at that.
17:37 And you report it to a vendor, maybe they fix it, maybe they don't.
17:40 they just don't have the resources and it's not going to sell their product
17:44 in a world where that's easier and you don't
17:47 have to be as clever as your head of pentest.
17:50 Uh, and you could just kind of be like
17:53 a a maybe just a guy who downloaded a thing,
17:56 paid 20 bucks on the dark web for a piece
17:58 of software and you can uncover all these vulnerabilities,
18:03 but also like anybody can have access to that tool.
18:06 theoretically people at Microsoft and at the Linux Foundation have had
18:09 access to this tool for for months before the hacker got it.
18:12 Who get who's advantaged in that world?
18:15 Like how do how does that actually change the shape of the problem?
18:18 So what you're talking about is AI to help hackers and pentesters, right?
18:22 Yeah.
18:22 Yeah.
18:22 Yeah.
18:23 And that exists right now.
18:24 In fact, I mean we did a research project on it
18:26 last year um and presented at RSA to find hacker tools.
18:30 My favorite one so far is Worm GPT.
18:32 And so you got a copy of Worm GPT?
18:34 We licensed it because it's a soft essentially software as a service.
18:38 They want to make money too and they want recurring
18:39 revenue and they want to build the value of their
18:41 Do you have to pay them in Bitcoin or something like how do they not get caught?
18:44 Yeah, we did pay in Bitcoin over the dark web as usual and we got a deal too.
18:48 We were one of the early adopters.
18:50 So I think right now lifetime is like 500 bucks and we got it for 50.
18:54 So that focus.
18:55 So you're Lifetime Worm GPT users theoretically.
18:58 Somebody has to be.
18:59 Criminals can always change their minds.
19:01 Yes.
19:01 Um, but I was really worried at the time
19:03 about the number of source code leaks that had happened.
19:06 And I was like, with all these source code leaks,
19:08 all this software getting dumped out,
19:10 it makes it so easy to find vulnerabilities.
19:13 And now that there are these AI tools out there,
19:16 it's going to get easier and easier for the bad guys to comb through them.
19:20 And I think that is creating a huge amount of systemic risk.
19:24 And um, it means we now have you can
19:27 go on the dark web and buy exploits really easily.
19:30 there's a whole marketplace for them.
19:32 Um, and at the same time, you know, the software developers just can't keep up.
19:36 It sounds like who is advantaged might be the big companies who are like,
19:41 "Okay, we're going to spend the money and do the resources.
19:44 We've got we can, you know, it's it's a really big deal.
19:47 if somebody hacks Windows or Chrome or something versus uh
19:53 in the world of like the bottom 80% of software which
19:59 is just a huge amount of software you know like
20:02 there's sort of like the you know the the a peak
20:05 where everybody's using the things at the very top
20:07 and then at the base it's like you've got pieces
20:08 of software that like a hundred people are using
20:10 and and so you've got there's like this huge amount of software.
20:13 So that's like that's the world in which the hackers are advantaged.
20:16 Would that be a fair to say?
20:18 Well, I mean, remember Microsoft, for example, is targeted.
20:21 So, I'm not sure that
20:22 Yeah, you're more targeting Microsoft because like that's where the value is.
20:25 Unfortunately, you like to think they're like Fort Knox,
20:27 but large companies have their own problems, too, right?
20:30 There's been this whole secret systemic risk issue.
20:33 Um, for example, so I hope everybody understands from this how
20:38 um information about bugs and vulnerabilities is like nuclear material.
20:42 Like it's really valuable because hackers can use
20:44 that to make exploits and then boom break into things
20:47 and yet at the same time if a tech company does
20:50 get hacked and their information is put out there about bugs
20:53 or vulnerabilities why would anyone ever know about it right
20:58 and that for me as a professional has been the scariest thing
21:00 and why it's almost a relief now that folks like you
21:03 are reaching out to say hey I want to talk about
21:05 vulnerabilities in 2017 Microsoft uh Reuters published an article because They
21:12 said Microsoft's bug tracking database was hacked four years earlier in 2013.
21:17 I don't know if you've heard about that.
21:19 You probably didn't because most journalists don't care.
21:21 And most people are like, "Why do I care if Microsoft's bug tracking database
21:25 was hacked?" But that's their list of all the bugs.
21:28 And that's hackers want that.
21:30 The bad guys want that because then they they don't have to do the work.
21:33 Yeah.
21:34 It's like leaking the the schematics to your to to Fort Knox, you know?
21:38 It's like, "Oh, now I know where all the I know where all the stairs are.
21:42 That's helpful for me.
21:42 I know where the air conditioning vents go.
21:44 Here's all the unpatched vulnerabilities that we have.
21:47 But tech companies don't have to report that or didn't
21:50 have to report that." But if a hospital gets hacked, you will know about that.
21:54 Like they will tell you, right?
21:56 But if a software company gets hacked and that your source code is leaked or uh
22:01 things that you depend on, they weren't
22:03 required for years and years to tell anybody.
22:06 And so this systemic risk has been building up over time without any visibility.
22:11 And that's why a lot of the exploitation that we see occurs today.
22:15 Do you think that there's anything that the people involved in Project
22:19 Glass Wing are underestimating as a threat to this specific like mythos thing?
22:25 Like anything that that Anthropic is underestimating?
22:27 Anything that the companies that have been sort of looped
22:30 into Project Glasswing should be looking out for right now?
22:33 Um, I think that's a really good question.
22:35 I mean they they've got to be balancing so many different issues.
22:39 So I don't really I don't want to come across as critiquing but one thing we
22:43 should all realize is that by so they're
22:46 releasing this only to researchers and to tech companies.
22:50 You know they say three can keep a secret if two of them are dead.
22:53 If you're releasing this to like 40 tech companies and a bunch of researchers,
22:57 it's gonna get out there.
22:59 If you were a bad guy um and you heard about this model,
23:03 but you can't have it, what would you do?
23:05 Well, I would try to hack the people who have access to it.
23:08 Security researchers are not exactly for Knox.
23:11 In fact, I strongly
23:13 I would think that they'd be better at it than most.
23:16 Maybe, but you have, you know,
23:17 think about funding and academia and um, you know,
23:21 I I wonder a lot about the CASSA vulnerability because I'm sure they
23:25 were getting ready to do a disclosure after 3 months had gone by.
23:29 That's a typical time frame about 90 days
23:31 and right before that 90-day window was up,
23:34 boom, a a attacker group uses the vulnerability.
23:38 So, did someone know about that?
23:39 Was a researcher hacked?
23:40 Was a vendor hacked?
23:42 when the Microsoft proxy shell issue came out,
23:45 Microsoft released early information to partners because of course if you
23:49 release a major vulnerability um in an internetf facing Exchange server,
23:55 you need like IT companies and other partners to be prepared for that.
23:59 And so, you know, they had the good out of the goodness of their hearts,
24:02 they wanted to be coordinated and they released that.
24:05 But again, three can keep a secret if two of them are dead.
24:07 82 companies cannot keep a secret and all
24:10 of a sudden we started to see that exploitation happen early.
24:13 So these researchers have targets on their backs.
24:17 Um I hope I assume that they know this.
24:19 So when we first texted about this I was like well
24:24 maybe we'll just find all the bugs and you laughed at me.
24:28 Maybe maybe like we'll be so good at like using this uh
24:32 godlike software developer that is Claude mythos and we'll find all the bugs.
24:36 We'll patch all the exploits and then
24:38 there like we'll just have solved cyber security.
24:41 I mean, what do you think there's more
24:43 of like bugs on the earth versus bugs in software?
24:47 I think bugs on the earth.
24:49 I think bugs in software.
24:53 No.
24:53 Oh man, you don't know how many ants there are.
24:55 There's so many ants.
24:56 It's the It's the ants world.
24:58 There are more bits of data flowing across the internet
25:01 every day than there are stars in the sky.
25:03 I believe that.
25:04 I believe that there's not that many stars in the sky.
25:06 Uh you're talking to a science guy.
25:08 Uh if if you said stars in the Milky Way or in the universe,
25:11 I might be a little more skeptical,
25:12 but the stars in the sky, that's a mere handful.
25:14 What one thing that I I don't get, but I hear security people talking about is
25:19 that the bug doesn't just like sit in the code,
25:22 it sits in the space between the code, you know?
25:25 It's like it's how this thing is talking to this thing.
25:27 It's like, you know, h how the browser is interpreting the font can
25:31 have like a a exploitable bug inside of it.
25:34 And I'm like, I don't know how that would ever work.
25:36 I mean, bugs did start out as literal bugs,
25:39 but these days it's not really a great analogy.
25:42 Um, we're building something with code, right?
25:47 Yeah.
25:46 And like my kid uh this week, he's on spring break.
25:49 He's been so excited.
25:50 He's building a fort in the woods with his friends.
25:53 And I've banned them from using real saws and hammers and nails.
25:58 And so they're making them out of sticks.
26:00 And you know, for years and years, we've been making artisal software.
26:04 We make the code ourselves.
26:06 You know, we're building it out of sticks.
26:08 It's like we live in the time before 2x4s were a thing.
26:11 Oh, wow.
26:12 That's an interesting analogy.
26:13 And so AI comes along and they're like, "Oh, we're going to shake this.
26:16 Wow, it falls down." And that's why they're
26:17 saying it's the space between because it's really about,
26:19 hey, what are the what are the materials that you're using?
26:22 They're not square.
26:23 They're not rectangle.
26:25 They're weirdly shaped.
26:26 You can't quite fit them together, right?
26:28 There's going to be structural issues with it.
26:31 Even our programming languages are written by humans with lots
26:34 of historical issues um and backward compatibility and problems like that.
26:40 Which is maybe also why you said to me as part
26:43 of that conversation that maybe someday cyber security or or these like
26:48 vulnerabilities will be a solved problem but only after we rewrite all
26:52 of the programming languages or after AI rewrites all the programming languages.
26:57 CISA and Microsoft and lots of other major companies even
27:00 today are pushing people to use modern programming languages like
27:04 Rust and away from C and C++ that give the programmer
27:08 the ability to access memory outside of where they should.
27:12 So there's just these fundamental security issues in our programming
27:15 languages um that make it possible for programs to be insecure.
27:21 So yeah, absolutely.
27:22 In order to achieve better security,
27:24 I think we're going to need to take a hard look at what our building
27:27 materials and think about how we can use machines to start making 2x4s at scale.
27:32 Interesting.
27:33 I mean, this is all going to be have to be very metaphorical for me.
27:36 So, we have Rust.
27:37 Rust is a programming language created by humans,
27:39 but you're talking about like does this actually make sense to you
27:44 that the AI will build their own programming languages to program in eventually?
27:49 Absolutely.
27:49 I mean, what is the purpose of a programming language?
27:52 It's it's really it's the interface between humans and the machines.
27:56 So, we're trying to make it understandable to people,
27:59 but as AI codes more and more,
28:02 we won't need humans to have that interface again.
28:05 Like,
28:06 yeah, but like don't you want to be able
28:08 to have somebody go in there and be like, "Oo,
28:10 this this girder is in the wrong place." I mean as a computer scientist I can
28:16 say I don't think one human fully understands
28:19 how a whole computer works and operates and all
28:22 the program we are we are well beyond that at this point in terms of level
28:26 of complexity we're driving the car you know
28:30 and it's what's under the hood is so incredibly complex
28:33 nobody's going to go in there and figure
28:35 out what's happening with that spark plug.
28:37 Yeah.
28:37 No one when it comes to computers.
28:39 No, I don't think in the amount of time that you have in your lifespan that it
28:43 would be possible for you to fully iterate through
28:46 and understand everything that is happening on your computer.
28:48 But it sounds like you're saying that we will not just end
28:52 up in a world where no one person understands all of the pieces,
28:55 but where there will be some pieces that no person understands
28:59 that are not understandable without machine help.
29:02 Absolutely.
29:03 Yep.
29:05 Humans rely on tools.
29:06 We just have to make sure they're reliable and working for us.
29:12 Yeah.
29:12 Is that Have you thought a lot about that?
29:15 It seems like you've thought a lot about that.
29:16 I'm a security professional.
29:19 Um you know the other thing I think about
29:21 a lot and again I feel relieved that people are
29:23 starting to think about vulnerabilities because again this has
29:26 been an issue a pervasive issue for a long time.
29:29 And when you say people,
29:30 do you mean everybody like like me like like folks who have email,
29:35 not folks who work at software companies?
29:37 Yeah, exactly.
29:37 I think in order to affect real change in our security,
29:41 a topic has to be understandable broadly and people have
29:45 to care about it in order to have legislation and, you know,
29:49 responsibility appropriately allocated and funding and things like that.
29:53 There are things that you there are laws that you
29:55 would pass if you were in charge is what I'm hearing.
29:57 I mean, I'm not that authoritarian, but certainly incentive.
30:00 Yeah, there are laws that you would suggest that you would that you
30:03 would build consensus around and that everyone would agree to pass together.
30:07 Well, yeah.
30:07 I think oversight and auditing and, you know,
30:11 disclosure because it makes me really sad.
30:14 Again, I've been a professional pentester for decades or well,
30:17 at least 15 years at this point.
30:19 Over and over, I see vulnerabilities that don't get disclosed.
30:23 Um or there's something called responsible disclosure where you tell a vendor
30:26 about a problem and you think uh because you're optimistic they're
30:30 going to fix it and actually and maybe there's a whole
30:33 bug bounty system where you might get paid for it and often
30:36 that bug bounty system is used like a gag order
30:39 like researchers discover vulnerabilities and they report it to the vendor
30:43 and the vendor says cool you've signed a confidentiality agreement here's
30:46 your money now don't tell anybody about it and they can't tell anybody
30:50 right and that lasts for as long as that secret stays
30:52 secret or for as long as no one else finds that vulnerability.
30:55 Exactly.
30:56 So, we've just been accumulating vulnerabilities for a long time
30:58 and I'm excited that now there's momentum to do something about it.
31:02 And the other big issue we could talk about is systemic risk.
31:05 What's systemic risk?
31:06 Systemic risk is the risk that permeates a system.
31:09 And um I've been thinking recently about Dr.
31:13 Dan Gear.
31:13 I don't know if you've heard of him.
31:15 I'm a big fan.
31:16 He was um he was fired from the company that he started in 2003 because
31:21 he wrote a white paper um about cyber insecurity and the risks of a monoculture.
31:27 And he actually lived um not too far from me in Cambridge, Massachusetts.
31:30 And he was raising honeybees and he was really um interested in nature as well.
31:34 And so the paper talks about how monocultures
31:38 like uh the prevalence of the same code all over the place um means that we're
31:43 at very high risk of a widespread problem.
31:48 Sure.
31:48 Yeah.
31:48 So if a So if everybody's everybody's router uses the same
31:52 OpenBSD software and there's an OpenBSD vulnerability,
31:55 suddenly every router is uh part of a crypto mine.
31:59 Yeah.
31:59 And these have real consequences that often people don't hear about.
32:03 Like I did some work last year for a mental
32:05 health institution that was hit with ransomware because
32:07 of the Microsoft Exchange vulnerability and these have real
32:11 life human consequences that you don't see in the news.
32:14 You have a good instinct for cyber security but anyway I'm terrified.
32:20 It's so scary.
32:21 So can I before you get to your hope and I do
32:23 want to get to your hope um this monoculture thing is very interesting.
32:26 This is what they say about voting machines where like
32:28 America has 50 different voting uh systems which is nice because
32:33 it means that like one thing and also oftenimes like county
32:37 by county it's different and so you don't have like one
32:39 system that you can hack one way uh which which
32:42 is a kind of protection and then also that made me
32:46 think about the way that it feels a little like we
32:50 might be headed into a world of much more personalized software.
32:53 Yeah.
32:54 and and that that that might be good for security reasons.
32:58 I was thinking the same thing.
33:00 You know, it makes me think because right now
33:02 if you find again a vulnerability in one product,
33:04 it can affect millions of people.
33:07 Um but we may be living in an age where like, hey,
33:09 I want an app that does FU and in like a year and a half or two years,
33:14 I might be able to just tell my AI friend to make it and poof, it's made.
33:18 Right now, I actually have to like work out the bugs in my vibe coding software.
33:22 It's making me crazy.
33:23 Um, but it might be really easy.
33:25 This is the This is the vibe coding uh brain candy thing where it's like,
33:31 "Ooh, you got 80% of the way there.
33:33 That's very exciting." And then getting to 99% is is is like a a huge
33:39 amount of work and then getting to 100% is that much work again.
33:43 Oh, it's like I'm in college and I got
33:45 in an argument with Claude Code and I was like, "Oh, hey,
33:48 you put the wrong folder name here." And it was like,
33:50 "You put the wrong folder name here." And I was like, "No, dude.
33:53 You wrote that." But yeah, he's like, "I don't know what who wrote what.
33:59 Look, I don't have contextual memory.
34:03 Things don't exist to me, Sherry.
34:06 I don't agree with all of the decisions that Claude
34:08 Code is making." And you got to like double check it.
34:11 Oh, for sure.
34:12 But I'm hopeful because with this age of personalized and customized software,
34:16 maybe we can use AI to reduce monocultures and to add more
34:22 diversity and that could reduce risk
34:24 associated with other types of security problems.
34:28 And that's interesting because it's it's not saying
34:30 that there's not going to be bugs in that code.
34:32 There's going to be bugs in that code.
34:33 It's saying if the danger of a bug just
34:36 increases exponentially with the number of people using that software.
34:39 And if it is if it is one, then it's really down to how much someone wants
34:43 to hack you specifically rather than someone using uh you know
34:48 an exploit that came out and and then they can
34:50 sort of hit you know 30 hospitals in one day.
34:54 Yeah.
34:54 I mean are we going to hack BSD or are we going to hack Microsoft Windows?
34:57 Um where are we going to invest those resources
35:00 or are you going to hack like Sherry's customuilt CRM?
35:03 Don't do that.
35:04 Don't do that.
35:05 Well, I mean I do think that it's it's something to be concerned about.
35:08 It's it's not like uh AI is great at security.
35:13 Well, I guess it maybe it will be eventually,
35:15 but like right now cloud code isn't thinking uh through
35:18 all the different implications of all the strange decisions it's making.
35:21 I I imagine I have a second AI that I use to check
35:24 the first AI which I think has been helping a lot
35:26 because it'll be like you know tell it to do
35:28 blah blah blah differently and I'm like okay thank you.
35:31 As a person who is uh mid-career,
35:33 how do you feel about what what would it be like different
35:38 for you if you were doing this if you were starting your career now
35:41 in cyber security?
35:42 I don't know like what whatever you were up to when you graduated.
35:46 I mean, it's interesting.
35:48 I think everybody in computer science is who's
35:50 in it right now is probably questioning that.
35:53 Um there's a lot of software developers
35:56 that might be trying to figure out next steps
35:58 in their career or looking at new fields
36:01 potentially because claude code and other tools are
36:04 getting so good at v coding and a lot of it is more like understanding
36:08 the needs of the business and making sure
36:11 your UI is really solid and things like that.
36:14 You think cloud's bad at UI?
36:16 No, no.
36:16 Cloud isn't bad at UI, but you know,
36:18 you the human have to guide it and tell it what you want.
36:21 You you actually know what a human like what you want the the tool to do.
36:25 Correct.
36:26 That also introduces other problems which could
36:28 potentially be job security for some people.
36:31 You know, the the risks of malware being
36:33 introduced through vibe coding tools um is very real.
36:37 The Amazon Q AI tool uh software um what's that?
36:41 I don't know what that is.
36:42 So, Amazon um had a has an AI tool, Amazon Q,
36:47 um for vibe coding and um I believe it was
36:50 being managed through GitHub and some unauthorized user got access
36:54 and planted malicious code which was deployed to over a million
36:57 developers and the intent was to wipe people's hard drives.
37:02 Fortunately, it did not work.
37:04 But I think it's pretty scary that this was not detected by a major company.
37:08 And one little configuration flaw in um
37:11 the code management system could potentially uh lead
37:15 to unauthorized access and then deployment of unauthorized
37:18 code to thousands or millions of people.
37:20 Damn.
37:20 Um it sounds should I expect well I guess the broad
37:27 question here is is there something that I should be doing?
37:31 Is there something that people watching this should be doing?
37:33 is the like is the vulnerability landscape changing dramatically enough that we
37:38 need to be acting differently than we were two years ago.
37:42 I think one thing is it's important to take
37:43 advantage of resources they have and I consult for businesses.
37:46 Um and actually tomorrow I'm going to be recording a podcast
37:49 for my clients and community and I need to provide clear takeaways,
37:55 actionable takeaways.
37:56 And I think we're living in an age where if you
37:59 have software developers in-house or if you rely on any third parties,
38:03 they must be using AI.
38:06 Um, you have to be using AI to check your code.
38:09 Uh, and in some cases,
38:10 if they're already using AI to create their code, um, which has its benefits,
38:15 make sure that they're using it in intelligent ways and that they're
38:18 really paying attention to the software development piece of it.
38:21 So is there is there like a for people creating code there is
38:25 there like a security type step that one would want to be using?
38:30 You've probably noticed lots more updates than you
38:32 used to are coming from software development companies, right?
38:35 So you might be getting new feature,
38:37 new this, new that and that's happening because
38:39 more companies are vibe coding and that's cool.
38:41 So there's new features being launched.
38:42 That's not because they're saying, "Oh, we patched a bug.
38:44 Oh, another bug that we found that we
38:46 patched maybe also that quite fingers crossed." Oh yeah, hopefully.
38:50 But they're also really excited to these new features available.
38:53 They have to stay keep up with their competitors.
38:56 So we're going to see new features coming out rapidly as well,
38:58 which means of course more bugs and you want
39:01 to make sure they have a secure software development life cycle.
39:04 And Hank, a lot of companies do software development that you might not expect.
39:08 Um, some of my clients that do tons of software development,
39:11 for example, are banks and credit union.
39:13 Sure.
39:13 Yeah.
39:13 Um, they often have in-house developers to make custom tools.
39:17 And so you know they need to have mature software development life cycle
39:21 or that company you've hired out of India to make that web application.
39:24 Um you need to make sure that you're looking
39:26 under the hood at what that vendor is doing.
39:28 For clarity I have not hired a company out of India to make a web application
39:34 yet.
39:34 Yeah.
39:35 I Yeah.
39:35 No, I'm not going to cross it off the list of things I might do.
39:38 This is not a thing I expected you to say but it sounds like
39:42 um there are just a lot of there are a fair number of zero days.
39:46 There are also a bunch of like known
39:48 bugs and exploits and vulnerabilities that are unpatched.
39:53 Um, and also like you know anytime there's
39:57 people who just aren't uploading updating their software,
40:00 make sure you update your software everyone.
40:01 That's my tip to you.
40:02 People aren't updating their software.
40:04 People uh you know it's it's it's complicated.
40:07 Maybe the IT department uh is is very stretched thin.
40:11 Um, I didn't I didn't think that the problem would be, "Oh,
40:14 we found the bugs." Um, and we didn't do anything about them.
40:18 I thought the problem would be, "Oh,
40:19 there's going to be a bunch of bugs that keep getting
40:21 found forever." But it sounds like it's both of those things.
40:23 Oh, yeah.
40:24 It's such a hard problem.
40:25 There are so many bugs that just have been getting dusty for years and years.
40:29 And that's always been the case.
40:31 Some of them are.
40:31 It's hard sometimes.
40:32 Like, you got to have your software like still work after you fix the bug.
40:35 And that might mean still interfacing with a bunch
40:38 of different systems that you don't control.
40:41 And people are afraid to to apply patches.
40:43 Like again, I had a another client
40:45 that was afraid to apply the Microsoft Exchange patch.
40:48 Waited like six hours.
40:50 That's it.
40:51 And they were already hacked by the time they applied the patch.
40:54 Um, so because you're like, I want to test this.
40:57 Um, when I worked at the Children's Hospital in Boston,
40:59 we would have a whole testing process because,
41:02 you know, I mean, it's life or death around a hospital.
41:04 You don't want your systems to crash, but we don't always have time to do that.
41:09 Um, I started using a term recently that I'm really excited about.
41:12 Hank, can I tell you what it is?
41:14 Um, negative days.
41:16 We hear a lot about zero day vulnerabilities,
41:18 also endday vulnerabilities that have been around for a while.
41:21 But just last month, I wrote a blog and I was like,
41:23 we're dealing with negative day vulnerabilities where they're getting hacked.
41:26 Like people are getting hacked before anybody even
41:29 actually before the vendor knows about the vulnerability.
41:31 It's just out there.
41:32 Well, I mean, that's what I always sort of imagined a zero day to be,
41:35 but I guess it can be a zero day for more than one day.
41:37 Yes, exactly.
41:39 People are just getting hacked and don't even know it sometimes for months.
41:42 It does freak me out.
41:43 It seems like a big deal.
41:45 It it also seems like you're making me feel very much
41:48 like uh we're we're we're in the baby days of software,
41:51 which is not which is not how I think.
41:54 You know, I think that the baby days
41:56 of software were like cobalt or punch cards,
41:59 but in fact, like this might still be the baby days of software and Yeah.
42:04 What was the baby days of again building houses?
42:06 We had like yurts and tents and all kinds.
42:08 Yeah, I guess it was a while before we got to a while.
42:11 We learned a lot.
42:12 I am so excited about two 2x4s and having machines
42:16 that can create them rapidly because we are going to build
42:19 some really cool stuff and we're going to get to a whole
42:22 new level of engineering and things that humanity can do.
42:26 I don't talk to a lot of people who are like
42:28 immediately uh I don't know it seems like you're optimistic about AI.
42:32 I'll hit you with a thought that I keep having which
42:34 is I did not realize how software constrained the world was.
42:38 I assumed that we had the amount of software that we needed.
42:41 But in fact, what appears to be the case
42:44 is that if you can create 10 times more software,
42:46 we need 10 times more software.
42:48 Which indicates that if you could create a 100 times more software,
42:51 we might need a hundred times more software.
42:53 And if you could generate a thousand times more software,
42:55 we might need a thousand times more software.
42:56 And we just didn't know that because we
42:58 were constrained by like it being written by people.
43:01 I have been waiting for technology and software to catch up for so many years.
43:05 I remember when I started my business in 2009,
43:08 I wanted a learning management system and they barely existed at the time
43:11 and I wanted project management systems and they were crappy at the time.
43:15 And all of these things that exist now are beautiful and um we could have
43:21 so many more customized so it integrates
43:24 into our organizations and our lives at a
43:26 Aren't you terrified of that as a security professional though?
43:29 like that.
43:29 Like who's going to pentest everything, you know?
43:32 If if if there's if there's a thousand times more software,
43:35 there's a thousand times more bugs.
43:37 AI pentesters.
43:39 Yeah, that's if you're putting yourself out of the job over here.
43:43 Oh, I don't think I think there's still going to be a level like right now.
43:47 AI pentest tools are hilarious.
43:49 Um or but I mean it sounds like Mythos is a pretty powerful AI pentest tool.
43:54 Well, and it's amazing how far AI tools have come in the past year and a half.
43:57 Like when I did this research and presented at RSA,
43:59 we were researching AI tools on the dark web late 2024, early 2025,
44:04 and they came up with exploits, but our pentest team was like,
44:07 h, we'd have to change some stuff for it to work.
44:09 And it sounds like now it is.
44:12 So So you were actually using this worm GPT or whatever.
44:16 And it it did succeed in finding some vulnerabilities for you,
44:21 but not like out of the box useful.
44:23 You actually had to know some stuff to use it.
44:26 I mean it was useful like we analyzed Magento
44:28 for example which is a popular e-commerce site and we
44:31 had it scanned for vulnerabilities uh and we found it
44:34 it's open source we found some vulnerabilities and we said
44:36 write us an exploit and again Tom our head
44:39 of pentest and this was by the way Matt Duran was
44:41 my co-author on this project and did a lot
44:43 of the work just to give him credit that he deserves.
44:45 Um my uh Tom who is our head head of penetration testing had
44:50 to go in and tweak some stuff for the exploits to actually work.
44:54 Um, and I was irritated at the time because I wanted the AI tools to be better.
44:59 Now they are and they don't all
45:01 have the same ethical constraints that Anthropic has, you know, making this.
45:06 So, keep that in mind.
45:07 Like, you know, we have Anthropic making this big announcement.
45:10 Who's to say China doesn't have the same capabilities?
45:13 Who's to say that some uh, you know, um,
45:17 some organized crime group doesn't already have something like this?
45:20 So, keep in mind they're not the only ones developing these capabilities.
45:23 It did also occur to me that the U recently the Department of Defense was like,
45:27 "We don't want to work with Anthropic anymore." And and I'm like,
45:30 "Well, I feel like maybe it would have been nice
45:32 to be working with the company that can hack everything.
45:37 If you're the Department of Defense and you're getting ready to uh
45:40 be in a cyber war with uh half of the world,
45:45 that's a I just scared myself talking out loud.
45:48 Don't be as scared.
45:49 I used to be smart as a security professional because I saw so much
45:52 that I couldn't talk about and you know even and can't talk about today.
45:57 Um but at a certain point you step back
45:59 and realize like we're all going to die anyway.
46:02 Um so yeah Sherry that made me feel way better.
46:07 I think that what's going to happen is
46:08 going to be way different than what anybody predicts.
46:11 That's the one thing that I'm predicting.
46:13 I agree with you there.
46:14 I agree with you there.
46:15 And I think that it's very hard to remember that lesson even
46:18 though we learn it every time some big new technology comes along.
46:22 Um, am I about to get a bunch of like software update notifications?
46:26 Be prepared for that because number one, you're going to get feature updates.
46:29 Hopefully a bunch.
46:30 I bet it'll be exciting, but yeah,
46:32 you're going to almost certainly see a bunch of bug bug fixes.
46:36 Probably way more critical bug fixes maybe than we've ever seen.
46:39 We'll see.
46:40 Are these people going to be totally exhausted?
46:43 It sounds like sometimes these bugs just sit around.
46:47 Um, and maybe they're not that critical.
46:49 Maybe, you know, they don't affect that that many people,
46:53 but are are these people now going to have to just
46:56 sort of like put their nose to the grindstone and be like,
46:59 "Okay, we have a thousand bugs we need to fix,
47:00 like we have a thousand critical zero day security vulnerabilities." My hope
47:05 and expectation is that along with project glasswing um we're going
47:09 to also see development of AI tools to fix bugs so
47:13 that we can fix them so much more rapidly than ever before.
47:16 I'm guessing that's going hand inand with the launch of this, right?
47:19 Don't you think?
47:21 Yeah.
47:21 I Yeah.
47:21 Yeah.
47:22 Yeah.
47:22 And I think that they even like with FFmpeg
47:25 they handed over a patch along with the bug.
47:29 So they were like we found this bug, here's the patch.
47:32 Uh they didn't even make FFmpeg fix it.
47:34 The hard part will be testing.
47:35 Testing to make sure that after you make these code changes,
47:38 the software still performs the way you expect.
47:41 I hate that, Cherry.
47:42 That that that makes it that makes it sound like it's going to be hard.
47:44 I just want it to be all the bugs to go away and I want everything to get fixed.
47:49 I You're so crabby when you're sick, Hank.
47:52 Look, maybe that's what the problem is.
47:54 I think it's funny we're talking about this while you have a virus.
47:56 you're but I am I am somewhat surprised by your level
48:03 of hope because I I've talked to you and there
48:05 are certain things that you are very uh pessimistic about like
48:10 you're angry that things are set up the way that they
48:12 are often you find that I I often find that there's
48:15 like some like thing that I think is a normal
48:18 function of society in the universe where you're like I cannot
48:21 believe that we're being mistreated in this way as a society.
48:24 credit card use I think is one I the way
48:27 that credit cards work in America being one of them started I know I have before
48:33 uh but it it it seems it seems like you think that we're
48:36 going to be able to get to to make our way through this
48:40 I've been very stressed out since 2010 when the operation Aurora attacks
48:44 hit um because tech companies were
48:47 getting hacked and compromised and source code
48:49 was getting leaked and therefore in the hands of malicious actors
48:54 And that meant that vulnerabilities were getting
48:56 stockpiled and nobody was talking about it.
48:59 And so I feel super relieved that this is out in the open
49:03 and it's now going to be something that we have to deal with.
49:05 Software vulnerabilities and software exploitation are the number
49:08 one cause of um of compromise today.
49:13 And so if we can actually tackle this together um openly and address it,
49:18 that's going to make all of us more secure in the long run.
49:21 Do you are you glad that it was Anthropic that got this first?
49:25 I don't know if they got it first.
49:28 Well, that's an interesting way to end the conversation,
49:33 but I'm glad you published it.
49:34 I think there's pros and cons.
49:36 Um again I think those there needs to be a concerted
49:39 effort to secure help researchers gain that access project glasswing
49:44 to remain secure themselves and to report any leaks or inappropriate
49:49 access to the glasswing to project glass wing and the tools.
49:53 When do you think uh you get access to it?
49:55 I don't know if I want access to the mythos preview or to project glasswing
50:00 because you don't want to be a target.
50:01 Correct.
50:02 I think that's a lot of responsibility
50:04 and I have other projects I'm excited about.
50:06 What are you excited about right now?
50:08 Oh, I can't tell you yet.
50:10 Oh, Sher David off LMG Security.
50:13 Thank you so much for spending some time with me.
50:15 Oh, thank you so much.
50:16 I really appreciate it.
50:17 It's always fun to be on.
50:18 That conversation did not go how I expected.
50:21 It is now the next day.
50:22 I know I'm wearing the same clothes, but it's now the next day.
50:24 I've been thinking about it ever since.
50:26 I hope that it uh sparked some sparks for you as well.
50:29 Last time I had Sherry on, people were asking,
50:31 "How do I get more Sherry?" She has a podcast
50:33 and I will link to it in the description.
50:35 And also again, if you want to spend some more time
50:37 in your own mind exploring this part of stuff that nobody can hack,
50:41 you know, The Book of Good Times is available.
50:44 There's a link in the description.