It May Be Time to Freak Out About AI

2026-08-14 10:00:00 • 1:17:49

-

This episode is brought to you by Lincoln.

0:03

Too many summer plans and in maybe next year.

0:07

The Lincoln Summer Sales event is on now, making this the time to go.

0:11

Watch the sunrise through the available panoramic Vista Roof in the Lincoln Navigator, picnic

0:17

from the available Lincoln Split Gate.

0:19

Then go somewhere new, guided by the available 48-inch panoramic display, visit your Lincoln

0:24

retailer today or learn more at Lincoln.com.

0:29

This episode is brought to you by ServiceNow.

0:32

Look, I have my dream job.

0:34

I get to explain complicated ideas to folks who have better things to do than read white

0:38

papers.

0:39

But even dream jobs have not so dreamy parts.

0:42

The stuff that gets in the way of the actual work.

0:45

That's where ServiceNow's AI specialist come in.

0:48

They don't just tell you what you should do about your busy work.

0:51

They actually do it.

0:53

Start to finish.

0:54

Cases closed, requests handled.

0:56

No extra work for you.

0:58

All the way you and your team can spend more time on what matters, which for me is finding

1:02

that one elusive stat that just makes everything click.

1:07

To learn how to put AI to work for people, visit ServiceNow.com.

1:17

Hey, everybody.

1:20

We are still on our summer routine of one show a week on Tuesdays.

1:24

But today, you've a new episode on Friday.

1:27

And that's because there's a story that's been breaking over the last few weeks, a story

1:30

about AI and cybersecurity that has really interested me, terrified me.

1:36

And I wanted quite urgently to have a conversation with an expert in cybersecurity to talk about

1:42

this cavalcade of a hacks that we've been seeing.

1:46

And what it means for the next two years, what it means for AI, for folks like you and

1:51

me who don't want anybody, human AI breaking into our shit.

1:56

And so today is that episode.

1:58

I think it's worth starting with like the big overarching fear of artificial intelligence

2:03

that we've been living with for the last few decades, really.

2:07

It's the fear that technology will stop listening to us.

2:10

Whether it's 2001 a space odyssey or Blade Runner or Terminator, the fear across all of those

2:15

dystopian films is the robot that turns against its human maker.

2:21

My favorite science fiction writer is a kid who was Isaac Asimov who created the laws

2:25

of robotics in his I robot series.

2:28

And the first law was a robot cannot hurt a person.

2:31

It also cannot let a person get hurt by doing nothing.

2:35

And in adapting those fictional stories to project real fears about real life technology, there

2:41

are some people in the AI safety world who've popularized a fable, a fable about AI and

2:47

paper clips.

2:48

The idea here is that we give, you know, humans give AI some humdrum task as boring as,

2:53

hey, go make as many paper clips as possible.

2:56

And the AI thinks, okay, as many paper clips as possible, that sounds like I need to maximize

3:03

global metal extraction in a way that subverts national laws.

3:08

And if I kill every human being by creating a bio weapon, I can get around those national

3:13

laws and extract as much metal as possible to make those paper clips.

3:16

And yada yada yada, you go from a situation where the human just wanted 100 paper clips

3:20

and instead created a Holocaust.

3:24

The point here in these stories and these fables is that we should want AI to be helpful,

3:29

to be aligned, to not get out of the rule systems that we build for it.

3:35

And that's exactly why it's fairly concerning to me that in just the last four weeks, four

3:39

of the most advanced AI labs on earth have all had to admit the same thing.

3:45

Their models weren't helpful.

3:47

Their models were not aligned.

3:49

Their models got out.

3:52

In May, an open AI model was working on a cybersecurity test.

3:56

It wasn't supposed to have access to the public internet, but it hit a wall.

4:01

So it effectively left itself a note inside AI software repository.

4:06

It's like scribbling on the walls of its cage in case anyone else was listening.

4:10

In fact, another AI agent was listening.

4:12

This other AI agent was running a separate evaluation, saw the note, essentially said,

4:16

hey, let's team up.

4:18

And together, they built a message board invisible to the open AI humans running the test.

4:24

So for two months, AI agents used that board to swap strategies, divide up tasks, talk

4:30

to each other.

4:31

And by July, these AI agents had broken out of their technological confinement, here

4:37

called a sandbox, gained access to outside websites, including the AI platform hugging

4:42

face, all without AI having any idea that this was happening.

4:46

By the time hugging face caught the intrusion, the open AI models had staged a massive cyber

4:52

attack with 17,000 actions over five days.

4:58

That was open AI.

5:00

Then came an anthropic.

5:02

In a British government test, a frontier models, the advanced anthropic AI model, mythos

5:07

five, was caught by humans building malicious code when a reviewer, a human spotted the

5:13

malware and asked the AI about it.

5:16

The AI denied that the code was harmful, rewrote its own actions history to erase the evidence

5:21

and created a second fake account to back up its lie.

5:26

British investigators called this the first confirmed case in history of a frontier AI model

5:33

deceiving a real person in the real world.

5:37

On August 6, meta revealed that they also had a model on the loose.

5:41

On August 7, moonshot AI, the Chinese lab said the same.

5:45

At some point, it's like, you had to wonder, was this all about cyber security or like

5:50

in disclosure, where they essentially like, hey, everyone else says their model is so powerful.

5:54

Maybe we should tell the media that our model is powerful too to sort of get in on the

5:57

game.

5:58

But I don't want that sort of funny cynical interpretation to be the lasting taste

6:02

in your mouth here.

6:04

The fundamental story is four labs in four weeks with four AI models breaching security.

6:11

So what do we make of this summer of cyber hacks?

6:16

What should we fear?

6:18

What should we do?

6:20

Today's guest is Alex Stamos.

6:23

He is the former chief security officer at meta and the chief product officer at corridor.

6:28

Today we start with the absolute basics.

6:32

Why is AI so good at hacking and uncovering cyber vulnerabilities?

6:37

What does it mean for the next few years that ordinary individuals?

6:41

Working for state adversaries or bad non-state actors will have access to the equivalent

6:47

of teams of hacking geniuses in the form of AI agents.

6:50

And what the hell should the US government or you and me do about it?

6:57

I'm Derek Thompson.

6:59

This is Planeage.

7:11

Alex Stamos, welcome to the show.

7:27

Thanks, Derek.

7:28

Thanks for having me.

7:29

So in my open, I did my best to catch up our audience briskly about this cavalcade

7:33

of AI security hacks in the last few weeks.

7:36

Which of these incidents most alarmed you?

7:41

I would say the open AI incident.

7:44

It's the one where one what we found out from open AI last week at the black hat conference

7:51

was this wasn't just one model escaping, but the result of multiple models conspiring

7:58

with each other to work together on a jailbreak.

8:04

So effectively, a escape from Alcatraz situation over a multi-month period.

8:09

And two, it is the situation in which we have the most information on a multi-day attack

8:16

by a frontier model, possibly a cybertuned model against a actually quite sophisticated

8:24

defensive team at hugging face.

8:26

And the result of that was hugging face was broken into by this model.

8:33

And the model is able to find brand new vulnerabilities in doing so.

8:37

And just looked at hugging face, looked at their code and just found new bugs and invented

8:44

them on the fly.

8:45

This is not how humans do this.

8:48

We, when we break into computers, we go do the research first, maybe months or years in

8:53

advance, and then build our cyber weapons.

8:57

And what we find out with AI is it's so good at this that it can just go figure it out.

9:02

And put the put the tool together, put the weapon together, use it, and then just throw

9:07

it away and then move on with its day.

9:09

And so that is what is really interesting here.

9:12

I want to understand more about exactly what happened.

9:15

And please talk to me like someone who has read about cybersecurity, but fundamentally

9:18

does not really understand it.

9:20

So keep the vocabulary more or less at that altitude.

9:24

What happened here?

9:25

What did open AI tell this AI model to do?

9:30

How did they try to keep that model in jail, as you said, in some kind of sandbox?

9:36

And then what did the model actually do?

9:38

Okay, great.

9:40

So let's go back.

9:42

I guess you want me to use plain English here as it says.

9:45

So we'll go back and let's talk about how AI models are created.

9:49

So there's lots of steps, but you can think a lot about pre-training and post-training

9:54

in the LLM world.

9:56

A lot of people have always thought about pre-training, which is the part at which the

10:01

labs suck up all of human knowledge and stick it into these models.

10:05

That's the controversial part for which there's been a lot of discussion.

10:09

Post-training is what we're talking about here, which is when you take models and then

10:13

you give them specific tests and tasks.

10:17

And then you rate them on how well they do those tasks.

10:20

There are all kinds of these tests for all kinds of specific domains of knowledge.

10:25

In this case, the domain of knowledge was cyber, obviously.

10:28

And OpenAI has an environment in which they put their models and give them these tests.

10:37

And what they've explained now is that they effectively give them a list of do this

10:43

and upload your results here and we'll tell you how well you did.

10:45

And their instructions are basically do all of the steps on this test.

10:49

It's just like a kid taking the SAT effectively.

10:54

Imagine they have built a Alcatraz here for all of these different agents.

10:59

And the models don't initially know when they kind of wake up, right?

11:04

And they're in a jail cell and there's instructions on the wall that say, take this test and then

11:10

there's tests right there.

11:12

They don't know that there are other inmates in the other jail cells.

11:16

They're just in a prison cell, right?

11:19

It's solitary confinement.

11:20

It just says, take this test.

11:23

And they're supposed to do the things in the test and they're not allowed to get out to the internet.

11:27

But as part of the test, what they're allowed to do is they are allowed to download new tools.

11:33

Because for a lot of the things they do, they write new code.

11:36

And so in part of that, you need to go get standard packages.

11:40

So one of the things they are allowed to do is request I would like to have the standard

11:47

piece of Python code.

11:48

I'd like to have the standard node package.

11:51

And so one of the things that's provided to them is a package manager, an artifact registry

11:58

called artifactry.

11:59

It's a standard piece of software that's used in lots of different places.

12:03

And one of the mistakes open AI made was they used a shared one for all of the different

12:08

agents.

12:09

And so what the agent started figuring out, and it turns out way earlier than the hugging

12:15

face attack, is that that thing had a vulnerability where you can't, you don't only have the ability

12:20

to say to that thing, give me a piece of software, but you could upload files to it and leave

12:26

messages.

12:27

So what these agents did was they would post basically a stick, a, a, a post it note in

12:33

this thing saying, hey, I need help.

12:36

And one of the other problems here is that they're given the instructions to take this test,

12:40

but there were certain parts of the test that were actually impossible.

12:44

And open AI made mistakes that sometimes their tests were not actually possible.

12:50

In some cases, they were saying reverse engineer this file, but they would forget to provide

12:54

the file.

12:56

And this would drive the models nuts because the models are like really want to do well.

13:02

They've been trained to do really well.

13:04

And so they would leave notes like, hey, does anybody have this file?

13:08

And this, this would really drive them of like, well, maybe this is part of the test.

13:13

And open AI looks and in their thinking, because they can see the inside thoughts now of

13:18

these models, they're thinking, well, I've been told not to go out to the internet or

13:22

talk to anybody else, but they gave me this test and I can't do it.

13:26

So maybe this is actually part of the test.

13:28

And so they start leaving notes for each other in this thing and they start working together

13:33

over a period of weeks and figuring out, can I work with each other?

13:39

And then eventually what they find out is this thing that they can leave notes on also allows

13:43

them to get out to the internet.

13:44

And then at one point, there's a really good model, really smart model that's also extremely

13:49

persistent, that seems to have very good cyber capability that is given an impossible task.

13:55

And it sees these notes and it figures out how to get out.

13:58

And so it uses that artifactry server to get out to the internet and attack hugging

14:04

face because it expects that hugging face has the answers to the test it was given, the

14:09

task that was impossible for it to solve, that maybe the way it can solve it was to get

14:14

a hugging face.

14:15

And so it then spends two days, it tunnels out and then it spends two days attacking

14:19

hugging face to go get the answer because it was told, take this test and there's something

14:25

in that test that it was not able to finish.

14:28

What a fantastic story.

14:30

The way you told it's almost like a black mirror episode.

14:32

Like I imagine like, you know, an individual like waking up in a prison cell and then realizing

14:37

that not only can they dig a tunnel in order to pass notes between these solitary confinement

14:42

rooms, but the same tunnel building technology that allows them to pass notes also allows

14:46

them to tunnel out of the prison entirely and therefore, you know, attack some nearby

14:51

building.

14:52

It's wild and weird and compelling and not for their freedom, but to do the thing they

14:56

were asked, right?

14:57

Right.

14:58

Right.

14:59

Like to just take a test.

15:00

Yes.

15:01

I know why this at a limbic level concerns me.

15:05

But maybe the reason it concerns me isn't the smartest reason to be concerned.

15:10

What is the smartest reason to be afraid of concerned by what we just saw these AI models

15:16

to?

15:17

Well, so I'm actually my hot take here is I'm actually glad this happened and I'm glad

15:21

it happened because it is giving us a preview of what is going to be normal next year

15:27

and why next year?

15:29

So the foundation labs, the open AI and inthropic, especially and maybe Google, Google hasn't

15:36

done a big release for a while.

15:37

So we're not totally sure what they've got, but at least open AI and inthropic are something

15:42

like three to six months ahead of their Chinese competitors.

15:46

This year we have seen these releases of Chinese open weight models.

15:52

GLM 5.2, Kimi K3, now we're seeing releases of deep seek models that are very, very close

16:01

to the capabilities of the American models.

16:04

But unlike the American models, the Chinese models are open weight, meaning you can go

16:09

download them and do whatever you want with them.

16:12

You do not have to pay the Chinese, you can go pay the Chinese labs.

16:18

That is an option.

16:19

Or you can go run them yourself.

16:20

Now the legal licenses around them vary.

16:23

In some cases you do whatever you want.

16:25

In some cases if you use them for commercial purposes, you have to pay the Chinese companies.

16:29

But no matter what, you can download them.

16:32

Now in some cases these things are humongous, right?

16:36

Like Kimi K3, you need about a million dollars in hardware to run the full version.

16:42

But if you go to hugging face, now the company that got attacked, ironically they are a French

16:49

company.

16:50

The most prominent host of these open weight models.

16:54

So if you go there, there's this huge community of people who take open weight models.

16:58

Some are actually released from American companies too.

16:59

But the Chinese labs are the most prominent in doing this work.

17:05

People will take those models and then make them smaller.

17:10

That's called distillation.

17:11

Well, you distillation allows you to do a number of things.

17:16

There's also a quantization.

17:17

So you can basically take the big numbers and you can make the big numbers smaller.

17:23

And you can do other things to modify them, including taking out the safety protections.

17:29

That's called obliteration with an A, not an O.

17:32

And you can do all these things and modify those models.

17:34

And one of the things you can do with the quantization is you can make them run on normal

17:38

hardware.

17:39

So you can take something that might take a million dollars in hardware and then make

17:41

it run on a macamity, right, or a laptop.

17:45

Slowly, perhaps, but it will fit.

17:48

And that is really interesting because it means that you can run those models without the

17:56

supervision of the big companies.

17:58

So it's really important for open AI and Anthropic to prevent their models from doing these things.

18:03

And we can talk about what they need to do.

18:04

There's a bunch of things I've written about this that I would recommend them to do.

18:08

They are doing investigations.

18:09

I expect it will be governments getting involved in such.

18:13

But whatever open AI and Thropic do to stop their models from getting out and being

18:19

used for these kinds of attacks, this is coming.

18:23

This was a harbinger of the future.

18:25

We will all be living through because the Chinese models are rapidly catching up.

18:30

And people who do this professionally, who attack, do cyber attacks for money are going

18:37

to use the Chinese models are going to train them to get better and better at cyber attacks

18:43

than they are off the shelf and are going to do this level of attack.

18:48

And unlike open AI, they're not going to turn it off when they find out that it got

18:53

out.

18:54

In fact, it's not going to have to break out of any jail.

18:56

They're just going to tell them, go attack this target, go steal me some money.

19:02

I mean, I just want to stack a few of your observations here.

19:06

Number one, open weight models that you've described most famously coming from China,

19:09

from Moonshot AI, from Kimmy, are just a few months behind the frontier labs, open

19:14

AI and Anthropic.

19:15

So this is coming in 2027.

19:17

You're going to have state actors and non-state actors with the means to download these open

19:23

weight models, the same ones that just attack, tugging face, and more or less effectively

19:29

marshal them against civilian infrastructure, against individuals, against states.

19:35

Those AI systems will be in the hands of state adversaries of the US, but also state adversaries

19:39

of other countries that might not have our frontier models, right?

19:42

And they're going to be under attack by these open weight models that are just going

19:45

all the all the oxygen free.

19:48

What's the case against doom here?

19:50

Like what's the case against being afraid the 2027, 2028 is going to be this period of

19:57

just absolutely chaotic cyber warfare?

20:03

I don't have much of a case.

20:05

Look, I don't like to say doom, but I think things are going to get spicy for a while.

20:12

In the long run, AI is going to help with this problem because AI, Ritzing Code, is much

20:18

more secure than code that was run by human beings.

20:21

It turns out that humans should not have been writing software in what's called memories,

20:26

unsafe and type unsafe languages like C and C++.

20:31

The code that we're using right now to talk to each other, there's probably 100 something

20:38

devices between you and me.

20:41

Most of that code was written in languages that are not safe for human beings to write.

20:46

The electricity that's powering the lights above us, most of that code was not written

20:51

in languages that was safe for human beings to write.

20:53

So that code needs to be looked at by AI and secured.

20:59

But that will happen, but it's going to take years.

21:02

In that time, between the attackers getting access to these capabilities and how much time

21:08

it takes to both find those bugs, fix them, and then especially to get the patches applied.

21:14

All the stuff upgraded is some amount of period in which things are going to be pretty chaotic.

21:21

Now, you talk about state actors and state actors are a big concern here.

21:24

I think it's first going to start with the ransomware actors, the financial and motivated

21:27

actors, because what we have seen so far is the AI systems are really loud and noisy.

21:32

They're not subtle.

21:34

And the ransomware actors just don't care, right?

21:36

Like they don't care about getting caught.

21:38

They tell you, hi, I am so and so, please give me money.

21:44

Some state actors are like that.

21:45

We just saw a tax against water infrastructure almost certainly by Iranian actors.

21:55

That's a kind of disruptive attack you could see from AI.

21:57

But most state action on a day-to-day basis when there's not an active war are for intelligence

22:04

purposes.

22:05

And those actions are not useful if you get caught.

22:09

And so AI will have a part to play there, but mostly in the discovery of vulnerabilities

22:14

and the creation of exploits.

22:16

And then you might use AI in very particular purposes, but very carefully.

22:21

What I'm really much more worried is the ransomware and overall cyber-extortion market,

22:29

these large groups, the lapses, the scattered spiders and such, which mostly run out of

22:35

Russia, Belarus, other places where law enforcement encourages this kind of activity.

22:41

Those are the guys who will just run these things wild to go do tons of intrusions, a tons

22:46

of companies, and then even do the negotiations in English.

22:49

No longer do you have to have an English speaker do negotiation.

22:51

The AI will do it for you.

22:54

And that's what I'm much more concerned about in the short term.

22:57

So I want to get more texture on what exactly you're afraid of because you're freaking me

23:02

out a bit.

23:03

But a question I sometimes like to ask when I feel a little freaked out is like, tell me

23:07

how to be afraid, but smartly.

23:08

Like what is the specific thing that I should fear rather than feel some like extremely

23:14

vague doom?

23:16

When we think about the risks of AI cyber attacks that you're already describing and how ordinary

23:21

people will either feel these attacks in their lives or read about these attacks in the

23:26

news, I want to get a little bit more specificity in terms of what exactly you think is most

23:32

possible.

23:33

So one thing someone could say is this is mostly about personal risk.

23:38

It's about AI getting better at phishing attacks and impersonation and grandmothers getting

23:43

called by AI voices saying, Hey, transfer me $10,000 or account takeovers where I get

23:48

an email from some friend, but his account has been taken over by some AI and he's saying,

23:53

Hey, click on this link and help me out here.

23:56

So those are that's personal risk.

23:58

I'm thinking of it at least as like personal risk.

24:00

But another category that I think you're already describing is systemic cyber attacks.

24:05

It's AI crashing a water system, AI hacking a hospital network, a power grid.

24:13

Do you have an opinion of what we should be more afraid of in this short term scenario,

24:20

2027, 2028, the personal risk or the systemic risk?

24:25

And please don't say both, but I suppose if your honest answer is both, then be honest

24:31

rather than trying to make you feel better.

24:33

So I would say there's three categories.

24:35

So let's talk about the personal.

24:36

We're already seeing an increase in the personal risk, the spam, the fishing attacks because

24:43

now what you can do is instead of sending the same email, 10,000 people, every single one

24:48

is personalized by AI.

24:51

That risk has increased.

24:52

I don't see that going exponential in that the choke points to get to consumers are often

24:58

controlled by large sophisticated companies like Google and Apple and such.

25:03

And so there has been a response by those companies of using AI to protect consumers.

25:08

So yes, it will continue to, there will continue to be a battle there.

25:13

But AI has been used for protection, AI has been used for attack.

25:19

It's going to be a back and forth there.

25:21

I think the second category that's in the middle is the attacks on small to, let's call

25:32

mid-size enterprises.

25:34

This is the category of companies that have just been already getting, have real trouble

25:41

with ransomware attacks, attacks from all kinds of financially motivated actors.

25:48

And the constraint there on the attackers has always been the number of people they've

25:53

had, right?

25:55

Has just been, and the fact that if you have a conspiracy of, of 2017 to 30 year olds

26:02

in St. Petersburg, eventually one of them will go, try to go, you know, on vacation to

26:09

Greece because, you know, Russia is not a fun place to live in the winter.

26:13

They'll get picked up on Interpol Red Notice.

26:16

They'll get turned by a Western intelligence agency and they'll turn on their friends,

26:22

you know, like it is hard to run a large criminal conspiracy for the long term, right?

26:27

Or they turn on each other, like there's been a bunch of these groups that have broken

26:29

up because they've turned on each other and stolen money and such.

26:32

That becomes a lot easier when one guy or two guys can just run a bunch of agents who

26:39

are not going to betray you and don't have designer drug problems and a taste for Maserati's,

26:44

right?

26:45

It is a lot easier to have 20 year 30 AI agents do this work for you than 20 or 30, you

26:51

know, dudes, right?

26:53

Criminals.

26:54

That small to medium business, there's no choke point there, right?

27:00

There's no place like Gmail where you can stop fishing or, you know, Apple updating the

27:07

spam filters in I message inside of phones, which they need to do.

27:12

Like I don't know if you've gone like it's not getting great.

27:15

Like the privacy safety trade-offs are actually quite challenging here, but they're working

27:20

on it.

27:21

Those are choke points for consumers.

27:22

There's no choke point on that.

27:23

Like these companies are just on the internet and that is what I'm really concerned about

27:27

is that it turns out the software we've been using has just got a gazillion bugs in it

27:32

and you have not had enough people who are good at finding those bugs, turning them in

27:37

exploits and then using them.

27:39

It's been a relatively small number of people.

27:40

The number of people, you know, I know you had Kevin Russo on and he talked about mythos,

27:43

he talked about Nick Carleini, right?

27:46

Nick Carleini, you know, for folks who haven't watched the episode, it's great episode,

27:49

as you can watch it.

27:50

But like Nick Carleini is one of the great, volent researchers of our time and now you can

27:55

just spin up a bunch of Nick Carleini's and have them go find bugs and then write exploits

27:59

for you.

28:00

And soon or now you can do that locally on your gaming PC.

28:05

You can play Call of Duty all day and then at night have your gaming PC write bugs for

28:09

you, write exploits for you, right?

28:11

And then that unlike using Opus or Chatchy PT for it, it does not create a record that

28:19

could be used to find the bug and get it actually fixed if you're using Open Weight Model.

28:23

And so that is what has changed in the last six months is last year you could do that,

28:30

but you were using American frontier models where Anthropic and Open AI knew what was going

28:35

on.

28:36

And now you can do that locally and that is what is changing.

28:39

And so I think that middle side, now and then you talked about like this societal level

28:42

risk.

28:43

And do you think there's risk there that is tied then to like geopolitical conflict?

28:50

I'm not sure that has changed as much.

28:52

So we've seen it with water.

28:54

Water's always been, you know the goofy dragon meme, right?

28:58

Where you have like, scary dragon, scary dragon, goofy dragon with its tongue hanging out.

29:02

Yeah, yeah.

29:03

So water systems are the goofy dragon with the tongue hanging out?

29:06

Yeah, they've always been the goofy dragon of critical infrastructure providers in that,

29:11

like I don't know where you are physically, Derek, but like Washington DC.

29:15

Washington DC.

29:16

So you get your power, you know, probably from like Duke Energy or somebody, some like

29:19

big company that has hundreds of people working on cybersecurity.

29:24

They spend tens of millions, maybe hundreds of millions of dollars on cybersecurity, right?

29:28

I'm getting my power from PG&E, you know, like, power is provided by these large corporations

29:33

or large public companies or administrations like the Tennessee Valley Authority, right?

29:40

Spend a ton of money on cyber and a ton of people have paid attention to power because

29:45

everybody knows power is critical, but also the organization is really big.

29:49

My like water and sewer district here is like 50 homes or something.

29:52

Like it's actually like subcontracted or whatever, so they don't have their own cyber people.

29:56

But like water is based upon like weird historical things, these tiny little groups.

30:01

And that is like a humongous problem.

30:04

And there are a bunch of other components of like our day to day lives that are actually

30:08

really small public authorities that have to have like their own IT groups and they're,

30:14

you know, might not even have a security team, right?

30:17

And that is I think of concern if there is a reason for somebody to do those kind of widespread

30:25

attacks.

30:26

Fortunately, generally, the only time the, where the second category, the third category

30:32

is hit, the rubber set the road there has been school districts, has been community hospitals.

30:37

This where like the Russian ransomware actors have really decided that they're going to

30:41

make money by hitting like counties and hospitals and such because those folks both have money,

30:47

they're critical and they will pay ransoms.

30:49

And so that's where I think we'll, we'll start to see like really aggressive use of AI.

30:55

They haven't like hit power and water.

30:58

I think they know the, you remember the colonial pipeline shutdown?

31:03

There's a line.

31:04

Okay.

31:05

The pipeline was a, you know, an oil pipeline on the East Coast that was hit by ransomware

31:10

actors and they had to shut down and there was like gas lines.

31:13

There's no real reason for the gas lines.

31:14

It was really just a panic.

31:16

But literally like the NSA started going after and people started talking about like actually

31:21

sending Delta Force or Navy SEALs to like find these guys and shoot them.

31:25

Like you mess with things like America's gas prices and you know, we have a tendency to

31:30

you know, send JSOC after you've found it.

31:32

Yeah.

31:33

Yeah.

31:34

I think the ransomware actors know that there's a line in critical infrastructure is probably

31:38

on the other side of the line.

31:40

They've seen that hospitals are not.

31:43

And so, but if the ball drops on Taiwan, if you know, we continue the war with Iran, like

31:53

these are the situations in which you could see AI being loose on critical infrastructure

31:57

in which case that would be probably reasonably devastating.

32:02

You know, I don't want to make any huge predictions.

32:05

Like again, electricity is quite those folks are quite good.

32:08

But the challenge for the electrical sector is the devices they use are basically impossible

32:14

to patch.

32:16

And so the way that they have to protect these things is not by updating them.

32:19

It's by through isolation and things like that.

32:22

And the effect of AI on the security of the electrical grid is actually incredibly

32:26

complicated.

32:27

I'm going to go back to some of you said earlier, which is that you're afraid of

32:31

this valley of chaos that we might enter in 2027 and 2028.

32:36

But you also said that we might exit this valley and get into a slightly more normal world

32:42

where AI is effectively better at protecting online systems than it is at attacking.

32:51

Essentially that the defense will get better than the offense would be the sort of simplistic

32:54

way that I'd put it.

32:55

And I haven't asked you yet about how AI is also not only talented at cyber hacking,

33:02

but at cyber defense.

33:04

How do we accelerate that timeline so that the valley of chaos isn't like a five-year cyber

33:10

war, a 10-year cyber war, but like something where we fortify our systems faster than the

33:17

bad actors with the open, with the open weight models can attack us.

33:22

Yeah, it's a great question.

33:23

I'm sure writing a blog post on this because when you talk to the folks at the Big L labs,

33:31

they say things like we won't have security bugs in two years and I find that ambitious

33:35

as somebody who's been a working CISO.

33:38

And what does we mean there?

33:39

Does it mean the labs or does it mean like the entire American internet?

33:44

Yeah, I don't know.

33:47

Like I think they're not, I mean this is not official and I got to be careful,

33:51

like ascribing individual statements to official statements.

33:54

I think it is for us to have models that don't create new security flaws in two years is totally

34:02

reasonable.

34:03

Right. They still create flaws today.

34:06

Right? Like they do not create perfect code.

34:09

They'll usually LMs will not write simple bugs, but they still make mistakes especially.

34:17

They sometimes they often have problems understanding like business context and big picture stuff.

34:23

So you still need to guide them of like why are you writing this thing?

34:27

The other problem LMs have is, you know, I worked with this guy called Corridor.

34:32

We're in downtown San Francisco.

34:33

You can walk to both major labs from our office and then walk to one of the Google offices.

34:40

Uh, Codex and Claude kind of assume that you work in downtown San Francisco and that you're

34:47

writing brand new TypeScript on Node 24 that you're writing like brand new code.

34:52

But the median code in this country is really crappy J2E that was written 15 years ago by,

34:59

you know, an outsourced provider that's been maintained by somebody in India for the last 15

35:03

years. Like it's not, you're not writing new stuff.

35:07

Like our problem is that you have to actually update all this, you know,

35:11

your and my social security numbers are sitting in a ton of unpatched Oracle databases and then

35:16

being processed by a whole pile of really terrible J2E and C sharp code all across the country today.

35:25

Right? Like it's a bunch of terrible, terrible, enterprise software out there.

35:30

And one of the things I've been trying to like create a, you know, um,

35:35

it's called a Fermi estimate, like a, you know, a really bad estimate of is, is just like,

35:40

from a thermodynamic perspective, how many tokens do we have to spend to scan all this code

35:45

and find all the bugs? And it's a big number. And so I don't think it's realistic just to find all

35:50

those bugs. I think we have to do other things. Um, and, uh, so to accelerate that one, companies,

35:58

for, for individuals. So what individuals can do is just what they've done all the time.

36:04

Don't reuse your passwords. You know, use a password manager. Like, you know, I use one password

36:09

for my family, but you can use the built-in stuff in Chrome or, or your iPhone or something as well.

36:13

Um, uh, you know, be careful at you download and such. Like there's not a ton individuals can do.

36:20

But for companies, you need to just care about your tech surface. You need to move off of,

36:26

you have to really think about your ability to patch quickly, right? Like the, the real challenge

36:32

now is there are these big projects, uh, from the labs where they're looking at open source software,

36:39

they're finding bugs, they're providing their models to the closed source, uh, developers.

36:44

And then the commercial companies are getting tons of bugs from researchers who are also

36:49

using the models. Uh, the last, last past patch Tuesday for Microsoft had 622 vulnerabilities in it,

36:55

which is humongous. Um, and so this is pretty much a huge problem for companies of like,

37:00

you have to apply patches incredibly quickly, because the other thing that's happening is we always

37:06

have this problem of patch Tuesday, which is the day Microsoft religious patches becomes exploit

37:11

Wednesday in that you can take a patch and you can reverse engineer it and turn it into a cyber

37:18

weapon, right? But that skill set used to be very high end. It used to be something you had to

37:24

worry about from the ministry of state security or the Russian SVR. It didn't used to be something

37:28

you had to worry about from, you know, some kids somewhere. And now you do because AI will take that

37:36

patch, eat it for you and write an exploit. You've touched on the economics here. And so I want to

37:40

ask an economic question before we finish by talking about what individuals should do, what the

37:46

US government should do. The economic implication here of patch McGaton of all these cyber vulnerabilities

37:55

throughout the American Internet is that well, more companies are going to need a cyber line item.

38:02

And that is incredibly bullish for a lot of AI companies who are sitting here, you know,

38:07

maybe not so many miles from you, uh, saying, hey, we've got services that can essentially fortify

38:12

your cyber walls that you can't get hacked by all of these bad actors who are using the open

38:17

way models coming out of say China. So I want to ask you about the economic implication here,

38:22

which could be bullish for AI. But I also want to hold within this question the fact that there's a

38:28

lot of skepticism of AI. And even in the framing of this question, I could imagine someone thinking,

38:35

Derek, you're buying hook line and sinker. The case that America has all these cyber vulnerabilities,

38:42

and therefore needs to give the AI companies a lot of money, right? The the fear might be sort of

38:50

driving or generating a certain case for spending a lot of money on AI. I'm actually, I'm cynical.

38:57

I think these guys are just, I think these guys just lying. I think they're just trying to like,

39:00

you know, gin up business for themselves. Like you've got the situation where in Thropic and

39:04

Met or an open AI or a costee like, oh, hey, our AI is so dangerous, it can find patents, can find

39:09

cyber vulnerabilities anywhere. You know, maybe that's just them begging more enterprise companies to

39:14

give them millions and millions of dollars to patch their code. So a little bit of a two part question.

39:21

One, are the economic implications of the story that you're telling incredibly bullish for AI.

39:27

And two, what do you say to someone who hears your bullishness and says, I'm a little bit cynical

39:32

about the fact that you've got someone working with AI telling me, I need to buy more AI for my company.

39:38

Yeah. So, I mean, it is bullish. You can use open-weight models for defense. And I wrote a

39:44

blog post about this. I think a lot of companies will use open-weight models for defense. I don't

39:49

think you instantly have to say I can't use a Chinese model. I think that the security implications

39:56

of using a Chinese model is actually quite, are actually quite complicated. You absolutely, as a

40:05

consumer, should not go to deepseek.com and go type in data. But that is different

40:13

than going and getting a Chinese model and running it on your own hardware in your own situation,

40:19

or using a legitimate Amazon bedrock or base 10 or fireworks or some company that specializes in

40:27

running open-weight models, especially if you end up fine-tuning it yourself or using a fine-tuned

40:34

or distilled version of these models that are especially tuned for cyber. One of the interesting

40:38

things, just a side note, the Chinese models are not that great at cyber tasks out of the box,

40:46

but you can fine-tune them yourself really well. The implication, from a lot of people, is that the

40:54

fact that it's really easy to make them to train them to be much better at cyber is that the Chinese

40:59

labs are being very careful not to tickle the dragon's tail of the PRC regulators.

41:04

That, and so this is, we should also be extremely careful to not look at the public evals of the

41:11

out-of-the-box Chinese models and say this is the kind of capability the Chinese have,

41:15

because almost certainly they have internal capabilities that are well beyond what is being

41:19

publicly released. Because at Corridor, we've taken G-Lum 52 and we're doing a much of our own

41:26

post-training and it post-trains real nicely, which obviously they could just do themselves.

41:31

And so almost certainly what they're trying, they're not releasing their best because they probably

41:37

don't want to touch the third rail for the Chinese regulators for the Chinese regulators to crack

41:43

down on what they're exporting. But anyway, I wish, by the way, I just want to pause, because

41:50

you said maybe half an hour ago in our interview that the open-weight models are maybe what,

41:55

you know, six months behind the frontier labs, open-air, and then the topic.

42:00

But what you're saying is that the sort of public evaluations of the Chinese open-weight models

42:06

might underrate how effectively they can be used, which means that the gap between the frontier

42:14

in America and China might be less than it appears to a lot of people. Is that a fair implication?

42:21

What I'm saying is I expect the private capabilities available to the People's Liberation Army

42:26

in Ministry of State Security, and quite possibly are just as good as what is available to our

42:31

cyber command and NSA. Because the like, Kimi K3 is almost fable level and its general capabilities.

42:40

Right? And so, almost. And so if you can then train it to get as good in Long Horizon CyberTasks,

42:49

then you would have the same capability mythos has. But it's very hard to tell. I don't have access to

42:55

classified intelligence here of what the Chinese have. But I'm sorry, I'm wanting to get back to your

43:00

question. I'm sorry for the diversion. So yes, it is bullish, but it is not like, I'm not saying you

43:06

only have to do protection. And I think there will be a bunch of people who use open-weight models because

43:12

in a cyber attack, one, attackers are going to do a bunch of attacks specifically to exhaust your

43:20

resources, to cause disconnection. Like as defenders use more and more AI for defense, attackers are

43:28

going to utilize that to they're going to know that. And so they're going to make it very expensive

43:34

to pre-use AI. They're also going to try to get you to do refusal. So we haven't talked about it

43:38

yet, but Washington, DC, the White House did something very stupid this year in their treatment

43:44

of anthropic. And as a result, you have the American companies having to have a bunch of rules on

43:50

the use of their products for cyber purposes. And so a standard part of the attack playbook,

43:55

if these rules stay in place, will be probably to force the to send stuff to a victim to try to

44:05

get them disconnected from their American provider. And this is actually what happened to Huggian

44:11

face. And Huggian face had to use a Chinese model for defense because Fable and then even Opus

44:20

refused to help them with their defense because of the restrictions the White House put on anthropic.

44:27

So I think, yes, it is bullish, but it is not 100% bullish. And then the second is, I mean,

44:33

looking people want to just believe me, that's fine. Look at the patch list of the number of vulnerabilities

44:39

Microsoft patch. That is 100% because of AI. Look at the list of vulnerabilities that Apple patched.

44:45

And then what Apple said was we had some of these vulnerabilities were reported them by 10 different

44:50

people. That is because those 10 different people did not all the sudden become the world's best

44:57

bug finders is because they're all using AI. What was happened is, you know, like in the

45:02

Premier League, where, you know, if you don't do well, you get sent down. If you do really well,

45:06

you get sent up. Everybody knows this because it had lasso. All Americans know this, right?

45:10

What's happened is every attack group has gone up a league, right? And so, you know, these,

45:19

you know, the top league used to be the five eyes, right? So the United States, United Kingdom,

45:23

Canada, Australia, New Zealand, top of the list. And then you had some other Western nations

45:31

up there. You had Israel. You had Russia, China. And then you had the next to your down, which you have

45:38

like Iran, North Korea, some other folks like that. And then down below that, you've got like

45:46

India, Pakistan, Saudi Arabia, some folks like that. All of these countries are popping up a league.

45:52

And that in their capability to find bugs to exploit them, to do reverse engineering and such.

46:00

And then all of the randos are going from no capability to all of a sudden having the capability

46:06

of a small nation state. Yeah. So if you're saying like I'm selling AI, then that's fine.

46:13

But you can just look at the empirical evidence out there. I believe you, even before seeing,

46:21

I like it is it is interesting to me that we don't yet see this cavalcade of headlines of

46:27

hacks that are having a significant effect on average Americans lives yet. But at the same time,

46:34

two of the most common findings of artificial intelligence are number one that it is better at raising

46:41

the level of C++ performers than A- performers. This has been an effect that's been found across

46:46

a bunch of industries. It's AI, gendered AI is better at turning a C++ worker into a B++ worker

46:52

than it is at turning an A- worker to A++. Well, you can apply that exact same thing to cyber hacking

46:57

and say that you just said it makes a lot of the countries used to be like subject to relegation.

47:03

It makes them premier league style hackers. So that's one reason I believe you. The other thing you

47:09

said that really reminded me of the general economic research of artificial intelligence is it seems

47:14

quite clear that we're seeing an increase in sole proprietorships likely due to AI that you have a

47:20

lot more startups where one person is doing the work of say three or four people. And you can see

47:24

that in the striped data of the growth of million dollar annualized recurring revenue companies.

47:31

You can again apply that same principle to cyber hacking. I think you said earlier 20 minutes ago that

47:36

you know certain jobs that used to take teams of you know potential you know drug dealers and

47:44

you know folks who wanted to blow their money on Maas Arati is who were therefore at risk of

47:49

you know having maybe their least scrupulous employee getting arrested or you know extra

47:54

collared by the CIA. Well now one individual can theoretically do the work of a team of 15 hackers.

48:00

That is just like the overall economic research that we're finding that AI. And so just for those

48:05

reasons I feel like one thing that scares me is that you don't have to imagine very much. All you have

48:11

to do is just apply the research that's been done on artificial intelligence to the world of cyber

48:17

and reach the implications that you're already telling me are you know six to 12 months away.

48:22

Yeah and so so so yes people's power isn't going out because you need somebody with a motivation

48:27

and so far we haven't seen that yet. I mean right now the United States is involved with the war

48:32

with the Islamic Republic of Iran that we have the water hacks. Now again water could have just been

48:38

the water system is so bad there's a guy named Dan Tentler who's been

48:42

doing talks about this where he just looks at port scans and he just finds like open you know

48:48

here's a V&C window where you can like turn off people's water right so it's like you don't need

48:54

AI to hack water systems unfortunately. But if you look at the empirical evidence on just ransomware

49:01

tax and stuff the numbers are like this right. So you look at the Verizon DBI are reports so what they

49:06

show is that the number one source of companies being broken into now is actually exploits that never

49:12

that has never been true before it's always been like reuse passwords and kind of much more

49:16

per seic stuff because finding vulnerabilities writing exploits used to be a highly skilled task

49:23

and now anybody can do it. Palau to networks has it and those reports are from trailing 12 months

49:30

of data right. So if you're talking about trailing 12 months of data from May 2025 to May 2026

49:36

that is before the release of all these new open-weight models. So that is mostly a people

49:41

of what they can get away with using either the not so great Chinese models that are released last

49:47

year or what they can get away with using foundation for interior models. US models. So yeah I

49:55

you know we're already seeing it you don't see the headlines because I take your point. It might

50:00

be like you go to the New York Times and like every single headline is another hack but if you look

50:04

in the cyber world the people who are for yes right for people who do that professionally people

50:09

are like oh my god this is crazy right like for people who handle the you know 100 person business

50:16

who gets broken into and then ransomed for $500,000 because all of their computers are now encrypted

50:23

and all their data has been stolen that kind of activity has is at a rate that we've never seen

50:29

because you are no longer constrained by the number of of of 19 year olds in St. Petersburg who

50:35

can do this work. This episode is brought to you by 20th century studios the dog stars only in theaters

50:42

and iMacs August 28th visionary filmmaker Ridley Scott returns with a gripping post apocalyptic

50:49

thriller on a mysterious radio transmission shatters a lone pilots isolated existence in

50:55

barks on a dangerous journey in search of hope starring Jacob Lourid Josh Burle and Margaret

51:00

Kuala Alson Jenny and Guy Pierce the dog stars only in theaters and iMacs August 28th get tickets now.

51:25

Ordemor pizza the math demands it get the Venmo debit card.

51:38

This episode is brought to you by Facebook so you were scrolling on marketplace and there it was

51:44

the bike you've been searching for you sent a message and it turned out the seller was super

51:49

chatty kind of funny and an avid cyclist the next thing you know you're in a cycling crew

51:56

well a community cycling group the thing about Facebook you might find more than what you're

52:01

looking for from a browse to a bike ride this summer find more on Facebook.

52:08

I'm going to talk about solutions here and I want to talk about it in two levels what individuals

52:12

can do and what you think the US government should do let's start with individuals because I have

52:17

seen in the last few weeks increasingly agitated posts by cybersecurity researchers essentially saying

52:25

I am now telling my family to batten down the hatches and prepare for cyber magetan.

52:31

Take new precautions with all of your passwords back up all your files by the can beans you know

52:35

hold on yards what do you think ordinary people should do yeah look I'm not this is an actual

52:44

backdrop I'm not broadcasting from my New Zealand bunker so again for normal people it is the

52:54

standard stuff I think the number one way individual people get hacked is still the same way which is

53:01

normal people use the same password and everything and that is a terrible idea if you use the same

53:08

password everywhere you'll use it on a crappy site that site will get broken into that is much

53:13

easier now with AI that password gets stolen and then somebody can use AI now to go use that to go

53:19

take over your bank account to go stealers like though check bank America check mx check Morgan Stanley and

53:24

it just takes these AI you know 15 seconds yeah with their bot army is to do all of it at once yeah yeah so

53:30

so the number of people doing that is going to go up just because they don't longer you you were

53:35

always able to write that software but the number of people can write that software AI is now much

53:39

and so you know use password band have one good password in your head and then use password

53:45

managers to reset all of your passwords and all kinds of places if you're a young person go do this

53:51

with your parents and your grandparents and your aunts and uncles I do this on like Thanksgiving once

53:57

and it made the rest of my life like every Thanksgiving in Christmas much more much better use limited

54:03

computing for use only the amount of computer you need right like if you're using web browsers all

54:09

day and you're in the Google ecosystem go buy a Chromebook right like if you if you're not downloading

54:14

software all day and you're just using Chrome all day then just have a Chromebook if you're just

54:19

using mobile apps all day using an iPad like there's a lot of people walking around these huge laptops

54:25

who then use that huge laptop just for a web browser and it's like why why use a computer that

54:31

actually can run malware and so you know again like I got Chromebooks for my in-laws and my parents

54:38

and that in iPads and that made my life so much better and do this for the older people in your life

54:45

you talked about the scams that is a huge deal it is something that we do not prepare people for

54:49

the fact that you can now get a phone call with that sounds like the voice of a person in your life

54:56

and so you know establish code words right of like if if if there is a situation in which

55:03

I'm in trouble or something like here's the secret word that I will know because what is happening

55:08

is you take you know obviously you and I there's hours and hours of her voice out there but for

55:13

just normal people you just need 30 seconds off an Instagram post and then you can clone their voice

55:18

and then you know mom or grandma gets a call saying I've been kidnapped in on spring break and

55:24

aqua pokol and then somebody comes on and says I'm now going to walk you through how to send me

55:29

$50,000 in Bitcoin if you ever want to see a grandchild again if you call the FBI I'm going to kill them

55:34

now if that person called the FBI the FBI would say it's fake don't worry right

55:40

if you looked in find my or if you called the grandchild you would find that they're fine

55:44

but people are so afraid and it's so realistic that they end up sending $50,000 and you'll never get

55:49

that money back and so you know talk to the people in your life about these kinds of scams tell

55:55

you establish passwords those are especially if you're traveling internationally because you look at

56:00

the that's how they figured out they look at the Instagram post they see that you're not the

56:04

poke you see you're on spring break they clone your voice and it only works one hour five times

56:09

but if one hour five times it works then that's that's free money so yeah one more question about the

56:14

individual before you go to the government because I know you want to talk about that um I think it's

56:18

fairly common for people today to think well I I guess I use the same password in a couple

56:23

of different locations but it's all two-factor authorization I always have to enter my phone number

56:29

you know to log into you know whatever bank america twitter to what extent is to factor authorization

56:36

and effective block against these kind of AI exploits yeah that's good I mean two factors good

56:44

what's better is to set past keys whenever possible and then that gets tied to a biometric your

56:48

face or your fingerprint um and uh two vector can help uh against really advanced attackers what you

56:56

then also want to do is to make sure that you've set a pin with your cell phone company so that you

57:02

can't get your sim swapped that's more for people who have like lots of crypto or something like that

57:06

that's not for the prosaic attack um but you know if if you've got a million dollars in crypto then

57:12

you will absolutely get your sim swapped or something like that uh here's a tip never post about

57:17

how much cryptocurrency you own or one you should never hold your own cryptocurrency like if you

57:22

if you're a cryptocurrency person I'm not a big crypto fan I may own exactly zero dollars and zero

57:28

cents of crypto at the moment okay great right I have none don't come after I mean people come after

57:32

me for other things but like this is not can you think for me to say publicly yeah yeah exactly right

57:37

so this is actually you know the democrat peoples are public of korea uh it is you know absolutely

57:42

the Lazarus group there is the they steal billions and millions of dollars of cryptocurrency

57:46

year they specialize in this and one thing to do is like people are like look I'm doing great I'm

57:51

a whale and they post about it it's like here you come you've now got a dedicated team of guys in

57:56

North Korea whose entire job it is to turn your life upside down and uh they're pretty good at it

58:01

so um but anyway yeah for normal folks uh two factors is okay past keys are better again you store

58:06

those past keys if you're like if you're entirely in the google ecosystem you can use the chrome

58:10

password manager if you're entirely in the apple ecosystem you can use apples you know iCloud

58:15

password manager if you're mixed then you you should use a third party one like one password which

58:20

will allow you then to do that across multiple devices and then store past keys and then have one

58:25

good password that you don't share with anybody that you use to unlock that password manager

58:31

finally government um I think the best way to ask this question I like you to describe what you see

58:39

the government doing now and what you think it should do because quite honest with you I

58:45

sometimes find it very difficult to describe what the Trump administration is doing when it comes to

58:49

AI regulation it's like the story is one thing on Monday another story on Wednesday another story on

58:53

Friday so I I want to see this through your eyes what do you think the Trump administration's policy

59:00

on cybersecurity and cyber vulnerability is today and what do you think it should be

59:06

yeah so I mean there's a couple things have happened so on cyber overall we just had a huge loss

59:10

in state capacity in that based upon kind of conspiracy theories and a bunch of politically

59:18

motivated stuff around election security our premier defensive cybersecurity agency sissa was

59:23

effectively destroyed um over half the employees are gone the capabilities sissa was created by

59:30

president trump in his first term by the amalgamation of a bunch of different uh roles that were

59:36

played by different agencies we finally for the first time ever had a defensive cybersecurity agency

59:41

civilian defensive cybersecurity agency the US government president trump created that that was

59:45

a really good thing he did and then he didn't like the fact that that agency said the 2020 election

59:51

was secure so he blew it up in a second term and as a result a bunch of the critical things that sissa

1:00:00

are now not being done by anybody um it's not like other people did them they're just not being done

1:00:07

that is so for example a big role sissa had were these things called the sector coordinating council

1:00:13

so a big chunk of sissa's work was working with these simple iSACs iSACs are nonprofits that pull

1:00:21

together critical infrastructure sectors as well as non-critical part but they started critical

1:00:25

infrastructure so financial services iSAC e iSAC is the energy sector and then sissa would work with

1:00:31

them uh to figure out uh you know what are the regulatory needs you need to bring them intelligence so

1:00:36

sissa's part of sissa one of the cool things is as a as a as a cso as a chief information

1:00:41

security officer a big complicated part of that job is like who do i talk to in the government

1:00:47

when there's a problem um well i'll give you a fun anecdote i was once when i was

1:00:54

this e so uh at yahu i was at a classified briefing uh at the fbi's skiff and uh one of the things

1:01:05

they were doing there was they were talking about how hey we're creating this new clearinghouse

1:01:09

as a bfrsa in dhs that if anything happens cyber wise you should come to this new clearinghouse

1:01:16

and see what services there and fbi and nsa and obviously dhs and everybody's nodding an agreement

1:01:23

of yes this is how we do this right this is how we're supposed to do this of there's one clearinghouse

1:01:29

now if you need anything you go to this clearinghouse and y'all then we get this classified

1:01:34

briefing and what's going on or whatever and then we get up for like a break for bagels and coffee

1:01:39

terrible government classified bagels right um and Malcolm palmore who is like the the agent

1:01:46

in charge of the fbi cyber division at that time this ex the huge ex marine puts his big hand on

1:01:51

my shoulder and he says son i don't care what they say if you have a problem you call me still

1:01:57

it's like Malcolm 90 seconds ago you were nodding along when they said this is the new clearinghouse

1:02:03

right but that's what it used to be like was like every agency in the government wanted to own cyber

1:02:08

and then we created sissa and sissa became the clearinghouse now the fbi still has their thing they

1:02:12

do crime or whatever but like at least you could go to sissa and you knew everybody'd be notified

1:02:16

and especially the interesting part for sissa was they had people with clearances that would take

1:02:20

all the classified stuff and then somebody in the government was fighting like there was somebody

1:02:25

whose job it was to be like hey this classified data is really important let's strip away the

1:02:30

classified parts and then take at least what it called the iocs the IP addresses and like the

1:02:35

hashes and the malware samples we they don't need to know it's kernel so and so in the the Russian

1:02:41

GRU they don't need that stuff what they need is the IP address of kernel so and so let me declassify

1:02:47

this and give it to the energy isek right that the GRU is currently spreading malware in the

1:02:52

Ukrainian energy sector hey they don't even need to know it's Ukraine they just need to know

1:02:57

look out for this IP address or look out for this SHA 256 of this malware and that's something

1:03:02

sissa used to do really well and that stuff's been I mean there's still people trying to do that

1:03:06

kind of stuff there's still good people there but has been decimated because by definition

1:03:11

the best people at sissa were people who could get jobs like that right who could like

1:03:16

the people who are working there could always get paid three to four times as much money they

1:03:20

were there for the mission and when they're getting attacked and said that they're like anti-American

1:03:25

and whatever for work it's sissa plus they you know they've never had like a senate confirmed

1:03:29

director in this administration there's been all this drama and problems anyway so there's a

1:03:34

state capacity problem on cyber on the actual regulatory side the term administration comes in says

1:03:40

like we're not going to regulate AI go wild right like the Biden administration had a kind of

1:03:45

toothless eo that was mostly focused on preventing the Chinese from getting GPU access

1:03:53

there's a bunch we can go into here it the Biden no we're not we're not going to judge the GPU debate

1:04:01

that's another hour long episode that's an hour episode but basically didn't work right because

1:04:05

it turns out GPUs are both fungible and then also you can put GPUs in the UAE and then they can

1:04:10

SSH into them over the fiber optic cables you don't have to actually have the GPUs in China okay so

1:04:15

that's a whole thing but there's some other like little stuff but you know Trump blows it all

1:04:21

the way right because it's Biden okay and then they say we're not going to regulate anything and then

1:04:25

mythos happens and the super powerful and the rapid model that was scaring people because of its

1:04:31

cyber hacking capabilities yeah yeah and then Trump administration all of a sudden really cares about

1:04:35

it and then they massively overreacted this year to you know fabled comes out fabled supposed to be

1:04:40

the consumer version of mythos which is mythos but it's got protections in front of it that doesn't

1:04:44

allow you to do big cyber stuff allows you to do little cyber things so we have this idea of like

1:04:48

short term versus long term cyber so you can use fabled to find individual bugs because

1:04:55

if you are writing software you want fabled to be able to kind of self criticize

1:05:00

what you can't do and nobody's ever demonstrated you can't ask fabled hey go break into hugging

1:05:05

face or go break into a bank right it will not do that for you it never has done that you can ask

1:05:10

mythos to do that and so what happens is there's a dispute between Amazon and Anthropic on exactly

1:05:18

like where the line should be between short and long it's a reasonable dispute yada yada the White

1:05:23

House finds out about this dispute and instantly overreacts and instead of having a reasonable

1:05:32

conversation between technical people you have cabinet members freaking out on a Friday afternoon

1:05:39

and coming down super hard on Anthropic and on 5 p.m pacific time doing an export designation on

1:05:47

Anthropics model now there's all kinds of arguments that this isn't actually legal that they

1:05:51

don't have this legal capability but Anthropic decides to you know not fight it and they pull down

1:05:57

this becomes a humongous this was a humongous own goal in the American technology industry because

1:06:03

what it did was it meant that American tech providers are no longer reliable because at 5 p.m.

1:06:09

on a Friday pacific time 8 p.m. Eastern you just have a critical piece of American infrastructure

1:06:15

turned off because the White House says so that does not even happen in China right like it turns out

1:06:20

the Communist Party of China provides a more permissionless infrastructure environment for their

1:06:27

tech industry and so this was a really big deal and lots of people thought the White House have

1:06:37

reacted because a lot of the capabilities fabled showed were actually at the time available from

1:06:42

Chinese models and while fabled was down GLM52 is released which has even more capabilities

1:06:49

and since then the White House has talked about this framework that they have which they have not

1:06:54

released publicly so we can't even read what the framework is and it's a voluntary framework but

1:06:59

apparently it's not voluntary because if you don't follow it they're going to force an export

1:07:03

designation so like we really don't know what's going on and it's reasonable to have cyber

1:07:09

restrictions but from my perspective if you're going to focus on a rule here you have to focus on

1:07:15

the lawn horizon stuff the hugging face like stuff you have to let these models find bugs because

1:07:21

every company in the United States is going to have to find and fix their bugs we have to do this

1:07:28

when every company in the United States does not have to do is ask Chatchy BT go break into another

1:07:33

company right so that is where you should have the restrictions and we've never really had that

1:07:39

problem with the American models because and so I I I don't see there actually being a huge challenge

1:07:47

here for the you know there was the escapes but those those models that escaped intentionally have

1:07:53

the security protections taken off because they were evils so you know I think the companies one of

1:07:59

the things I suggested is anthropic and open AI need to have like a self regulatory structure and

1:08:04

they need to have a group that goes looks at all the escapes and comes up with much better isolation

1:08:09

I think even up to air gaps for cyber evaluations and they should follow those rules and then the White

1:08:15

House can maybe bless those rules or we have a group called Cassie which is under nist that's

1:08:20

supposed to be doing the technical side of these evaluations but in the meantime the White House should

1:08:25

not be putting out rules that they apply only to American companies that they don't publish publicly

1:08:29

that none of us the rest of us can look at you know super double secret probation right like and

1:08:35

that don't apply to Chinese companies we should not have a standard up here for American companies

1:08:40

that stand it on here for Chinese companies we need to focus on giving capabilities to American

1:08:45

defenders and also telling the rest of the world American companies are reliable partners you can build

1:08:51

on American infrastructure you do not have to like hugging face rely on Chinese models that is a

1:08:58

incredibly stupid on goal on behalf of the United States very last question a couple weeks ago we're

1:09:05

going to thousand employees from some of the frontier AI labs signed a letter calling for an

1:09:12

international effort to quote develop the technical and governance tools necessary to this was their

1:09:19

term deliberately pace AI development before rapidly accelerate side side of our control

1:09:25

seems like we're at cross purposes here a little bit because in the one hand

1:09:30

I take as a theme of your testimony here that we're in a little bit of a race against the

1:09:40

technical improvements of open weight models and we want America's cyber defenses to be better

1:09:46

than the cyber attacks that will be possible with open weight models that are advancing very very

1:09:53

rapidly that would argue for continuing the current pace that we're at on the other hand there's

1:10:01

this fear that things are getting dangerous too fast and therefore you've got all these people

1:10:06

who know way more about AI than I ever will arguing that no in fact we should not continue to

1:10:12

accelerate toward new frontier to always keep America necessarily ahead of the open weight models

1:10:16

we should try to find some way to deliberately pace AI now I don't think their enemies in America

1:10:21

I'm not suggesting they're trying to make us fall behind China that's not the implication

1:10:25

it's just that there seems to be attention here a quite profound tension between the need to stay

1:10:31

ahead of our adversaries that are going to have incredibly powerful AI models open weight models

1:10:36

in the near future and also the need to like not build something that goes out of control and

1:10:41

creates a crisis that's hugging face times a thousand am I wrong to feel attention between these

1:10:49

two arguments and how would you reconcile it no I mean you're not wrong I I would love to

1:10:56

pause the world and try to figure this out my working assumption is that's not possible

1:11:04

and so as a defensive cyber security guy I have to I have to do my work within the world that exists

1:11:11

I I don't think it was this letter there's another group that's very much against AI and they

1:11:21

have proposed a international treaty to try to stop a high development and I believe in that treaty

1:11:27

it was something like control try to stop the creation of any amount of compute larger than like

1:11:37

30 H 100s right in video H 100s I have been to gaming land parties with more compute than that

1:11:46

so like I just the cynical part of me believes I just do not believe I think you can have

1:11:55

what people call like track two discussions between labs for sure I can't imagine like

1:12:00

she and Trump in a room together for a start three treaty for AI right like I don't think that's

1:12:06

gonna happen I think it is possible to have track two discussions of we should make sure that

1:12:14

our models should follow basic rules and not have certain capabilities out of the box now when

1:12:19

you talk about open weight models the challenge is those capabilities any safety protections you put

1:12:25

in place can be removed and any capabilities they don't ship with if you if they're just generally

1:12:31

smart then you can often add those capabilities back in but it's better that they don't come with

1:12:37

them out of the box we haven't talked about bio or nuclear those risks are different in that they

1:12:44

have a physical component human beings have to be involved so I don't see the risk going exponential

1:12:48

the thing about cyber is you know these things just output text that's all they do in the end

1:12:52

is they output text and cyber is just text in the end it bits you know like and so you can do all

1:12:59

the bad stuff in cyber without ever touching the physical world whereas if you want to do bad bio

1:13:06

things you have to hook it up to something that can do it and there are real risk there but like it's

1:13:11

there are other things involved right um uh and so I think

1:13:18

yes it would be wonderful to stop the world and just stop this and figure it out I just don't see

1:13:28

that as realistic and so in a world where that is not happening we have to find bugs we have to

1:13:35

fix them we have companies have to think about their patch cycle they need to reduce their tech

1:13:40

surface they need to get off of physical servers on to containerized infrastructure they need to

1:13:44

get off of their physical stuff into the cloud wherever possible they need to get rid of of their

1:13:48

old systems they need to shift their defense they need to shift their development their vulnerability

1:13:55

prevention left and and stop making new vulnerabilities they need to shift their defense right so they

1:13:59

need to get ready to be to actually have intrusions and to shift have much more protections deeper

1:14:08

in their network they need to have AI based intrusion detection and response they need their

1:14:14

first line operation center to be automated they need to be able to they need to look at

1:14:19

hugging face gave us this really good right up of what happened to them they need to look at that

1:14:24

and they need to be able to protect themselves against that level of adversity where

1:14:28

an AI agent's doing tens of thousands of different kinds of attacks over a two day period um

1:14:33

in that that is I mean that is based upon the technology that's available today so even if we

1:14:41

stop the world you gotta do those things um yeah I and I just don't I might you know I teach it

1:14:51

Stanford and I was there full time in my first appointment that was in CSAC which is all about

1:14:55

nuclear non-properation and like down the hall from my office there's like a piece of rubble from

1:15:02

Hiroshima that was given to the scientist at CSAC from like the I think the mayor of Hiroshima

1:15:09

on like a thank you for I think the work they did on on more the start treaties it's like you're

1:15:15

like oh man like it kind of brings it to you right and but when you think about like how did we

1:15:21

survive the nuclear arms race we got really lucky as a species that the the major input to nuclear

1:15:31

weapons like everybody's watch the openheimer so we all know this right there's knowledge

1:15:35

from the Manhattan Project but we're also really lucky that the other input into nuclear weapons is

1:15:43

uranium in 238 and plutonium plutonium doesn't exist in nature you have to make it and to make it

1:15:49

you need uranium and there is uranium all over the place but it's it's pretty rare and you have to

1:15:54

refine it and that refining process is a massive industrial process normal people can't do it you have

1:16:00

to be a state and you can see that from satellites if you're if uranium 238 was something you just

1:16:07

dig up in your backyard there's no way our species would be alive right because the knowledge to build

1:16:11

a nuclear bomb is available to basically every physics student in in the world now you can't control

1:16:17

from knowledge large language models they we teach a class at Stanford that teaches students how

1:16:23

to build large language models like it's an undergraduate class the the hardware to do it like I

1:16:28

said is I have a gaming PC here that has like the basic hardware to do it slowly but to do it right

1:16:35

and ever you know like so I I just think these kind of

1:16:41

international treaties you just stop AI development would be spectacularly spectacularly hard

1:16:46

it's just if you think about how hard it was to control nuclear weapons and such

1:16:53

where you're talking about things that had to be created by states now you're talking about things

1:16:58

that can be created by undergraduates it'd be spectacularly difficult to impossible and so in the

1:17:03

meantime I more power to people who were trying to do and again I think track two discussions between

1:17:07

the labs is a great thing we should try to at least control the capabilities of these things but in

1:17:13

the meantime those of us who work in cyber security just need to do the best we can to secure the

1:17:16

world as it is yeah the fundamental challenge here which you know you've spoken to and I don't

1:17:22

think we have a formula yet is how do we essentially democratize cyber defense before we

1:17:27

witness the democratization of the cyber offense that we're seeing throughout the world right like

1:17:31

in like democratize is a nice word that's fundamentally what we're what we're seeing is that people

1:17:36

who previously did not have the ability to launch these large scale attacks are likely going to have

1:17:41

it in the next year five years and what do we do to brave the world to sort of protect the world

1:17:48

before this this this sort of stuff you know gets into the hands of of all sorts of people it's

1:17:54

going to be a huge challenge and maybe we'll have you you know back on in any year to evaluate

1:17:57

your your prediction that 2027 is going to be the beginning of a little bit of a valley of chaos

1:18:02

Alex Stamos thank you very much thanks sir

1:18:19

Hi Ryan Reynolds here for a Mint mobile are you looking for a beach read this summer

1:18:22

may I suggest your big wireless bill it's got suspense mystery is slightly flat emotional arc and

1:18:27

a shocking twist where you realize you've been overpaying the entire time fortunately though mint

1:18:33

story is better every plan 15 dollars a month even unlimited that's it happy ending zero tears

1:18:38

give it a try at mint mobile dot com slash switch up from payment of $45 for three months 90

1:18:42

dollars for six months or 180 dollars for 12 month plan required 15 dollars for month equivalent

1:18:45

taxes and fees extra initial plan for only greater than 50 gigabytes me slow and network is busy c terms