Sean McMillan: If you've been at Black Hat and DEF CON this year, you have heard a lot of opinions. You've heard a lot of AI opinions. AI this, AI that. It's everywhere, right? And some of that is real, some of that is hype. We call that noise. So our theme this year has been block out the noise. And to kind of wrap that up, we decided to do a live version of initial access with w we have this is the most smart people I've seen in a room together. In a very long time. so it's it's a great opportunity to kind of get to what's actually important and what the future may hold for security. So you'll see some familiar faces. We got some new ones today, too. I'm very excited to get started on this. first let me let me introduce a couple of these folks. We've got some longtime friends of the show: John Unts, senior security engineer, exploit development. We have Richard Brown, senior managing operator. And then new to the program, we have Billy Giles, managing senior consultant here with Bishop Fox as well. And joining us from OpenAI, he is a member of the technical staff. he's a red team expert at OpenAI. So a lot of interesting, different perspectives. And I'm excited to get into this. We only have two microphones, so it's gonna be a second between questions where we pass things along. Be patient. I'm Sean McMillan. Community manager here at Bishop Fox, and this is initial access. So, first question, I guess, is what has everyone been attending? What have you seen so far? Did it sounds like none of you really did Black Hat. That was just me in a booth for three days. It was really fun though. We we talked to a lot of people. We'll be releasing clips if you're watching this on YouTube or listening to the podcast version. you'll be able to see a lot of our clips on YouTube and LinkedIn, et cetera, of the people we talked to there. Got some good perspectives. But I'd like to hear from you guys. DEF CON has just started. This was the first day of DEF CON. I think most of you were there in some format. how's how's the con been so far?
John Untz: Well go like this is so this is actually my first year since the move over to the convention center. last year I the last year I was here was twenty twenty three. so that aspect's totally new to me as far as like having it all under one roof, and not having to go between, you know, different buildings and whatnot for everything. so Richard and I were actually talking about that on the way over. there there's some pros and cons to that I think still. I'm I I definitely like while I don't I don't miss the walking back and forth between, you know, the different hotels and whatnot. but some of the villages that are out on like the main floor, I felt like it's a lot less intimate as far as like getting to getting into the activities, getting to talk to people. And the
Sean McMillan: That's one of the big things at DEF CON, right? Is that it's that that differentiates it from a black hat or an RSA or some other big format.
John Untz: Yeah, yeah. And and and like it's not all of them, right? There were they do still have villages, up in private rooms, up on like the second floor. but there is to me, there's like a notable disparity between, say, like the I think it like the payment processing village was one of them that like I walked in, it was immediately like you could you could just like immediately start learning something as soon as you stepped in, there's an expert in there talking Yeah. You know, ab about the about the process and whatnot. Not to say that there's not experts d at at at any of the other, you know, villages. It just it was just something I picked up on immediately was like, I'm I'm already in the conversation. and I I think that that also just could be like just not as many people up in like the second and third floor as there is like out on the main floor, right? Yeah.
Richard Brown: And one thing to note too, this year we did see them have headphones in some of the other booths. So it's nice that in the loud convention area they were able to have a more intimate setting, but it still was. Now I see the talker up there and I'm four rows back without headphones and I can't hear what he's saying. yeah.
Billy Giles: Yeah.
Richard Brown: It was good all it it was good for the most part.
John Untz: Right, right, right, yeah. Yeah, I'm curious Billy from like from you like being like active in like the the Red Team village area, like how how that experience is as far as like
Sean McMillan: I sh I should have said that. Billy is like Mr. Red Team Village. on the board, you're you're the master of coin, as so to speak, the treasurer.
Billy Giles: fortunate enough that they let me hang out.
Sean McMillan: Yeah, very very involved in DEF CON. So yeah, what's your experience been so far?
Billy Giles: As they say it takes a village, right? So yeah, definitely definitely credit to
Sean McMillan: Sometimes it takes
John Untz: Yeah.
Billy Giles: Credit to the 30 or so people that do this year round to prepare. And then the army of volunteers that we get every year, just amazing. So you know, we show up and the art the volunteers show up and I do nothing. It's amazing. I love it. But yeah, to get back to what you're talking about. So we were on the floor last year, yeah, and it was absolutely awful because there were some vendors down there that had microphones. Right, right. So was very loud. Yeah. And then they told all the villages that we couldn't use microphones last year. Yeah. Right. So we were like trying to yell and use megaphones and we did the keynote panel so there There's you know a couple hundred people standing around and we're trying to use a megaphone and pass it back and forth. Right, right. So the the headsets are a fantastic up there. Like we had we had probably two hundred people in the keynote this morning as well, everyone with a headset on and you know they could all hear us directly from the microphone. So it was it was fantastic this morning.
John Untz: Yeah. Yeah. Something we were yeah, thanks. We something we we noted was I I I I can't recall exactly which villa village it was on the top of my head, but there there was a village that w they didn't have the headphone. They were on the main floor but there you know was it IoT or yeah.
Richard Brown: Game hacking.
John Untz: Or game hacking, yeah, yeah. And so so there was somebody doing a talk there and they just like they like that, right? They didn't even have a a megaphone, they had to like kinda like shout over the crowd and so we were starting to talk about like, you know How could we or or how could anybody like like fix something like this? And wondering if you know everybody has to have the hacker tracker app now to like do any like merch sales. I'm wondering if they can incorporate something like that into the app itself to where you know, like the different speakers, they just you know, they they they basically talk into a microphone and then all you have to do is just like get on the app and and your dial into it. And
Sean McMillan: Yeah.
John Untz: like you can just not even be in the audience. You could be out in the hall or whatever and still listening in like a p like a podcast.
Sean McMillan: Yeah. Right.
John Untz: So
Sean McMillan: Interesting. Interesting. Matthew, have you had a chance to hit the floor at all yet?
Matthew Bryant: Yeah, I mean my my my main experience with DEF CON is definitely you sort of get out of it what you put into it and so like some of the best times I've ever had at the conference have always been like, I'm gonna participate and like do this this event or you help either it's help out or it's like do you know what they have planned and also just one of the nice things is it tends to be like my friends from all over the world usually end up at DEF CON, at the very least you're gonna meet people that you're like, I haven't seen this person in forever. I'm super happy to catch up and like you know, what have you been doing over the past years or some you know, especially with all the all the changes that have happened, so I've always enjoyed them.
John Untz: Yeah. Have you d done anything as far you so you mentioned like you know like the participation stuff. Is there anything like you've you've you've like gone around to to like today and like participated in?
Matthew Bryant: Not yet for this time, although well, my my wife is actually doing quite a few quite a bit of talking, so helping assisting more with that. But in prior years it's been like, you know, pla playing in Hack Fortress and stuff like that, which has always been enjoyable and stuff that nature, so
John Untz: I was trying to explain Hack Fortress to to Richard actually. I so like in in the pa I'd done ShmooCon, for back when they were around. and that was where I did like a lot of Hack Fortress stuff and so I was trying to ex show him like 'cause they didn't have it like actively going when we were over there. but yeah, trying to explain to him like how this whole thing works. I think that's like another like one of those like great things that you know, yeah, like it's like you need to get ten people together to make a team. But it's such a cool competition as far as like It's f so for those that don't know, right? Hack Fortress is historically it was Team Fortress 2, now they just moved to Quake 3. but the way it works is yeah, I keep forget about the mic situation. I mean I'm so used to the webcam stuff.
Sean McMillan: Ha ha.
John Untz: the the the way it works is you get a team of ten, six of them are playing the like the first person shooter, four of them are playing are are are doing like capture the flag hacker challenges, right? the the the hacker challenges are like unlocking, you know, buffs and stuff like that for the team that's playing the the side of the team that's playing the first person shooter and then vice versa as they're getting kills, it's getting like hint unlocks and stuff like that for the the hacker team. And there's like there there's all sorts of like jump in challenges. Like it's a at I think at one one point the last time I we played it, there was one of our team members had to like get up and do like karaoke to something. I could
Sean McMillan: I could get a black bat. See this is what I could do that.
John Untz: That's what I That's th that that's what I mean. That's like one of those like cool challenges that's like there's something for everybody. Right? Like you don't have to just come in and just be a hacker. Like you don't have to be a reverse engineer. You don't have to be a an AI guy. You can do anything on these teams and like everybody can contribute. So yeah, so I just wanted like kudos to the Hack Fortress team, by the way. Like that's such a cool idea. I'm glad that it
Sean McMillan: Yeah, it's back again this year. That's very cool. Yeah. so one of the things I mentioned Bishop Fox's theme this year, like for we had a booth for the first time. That's very cool. and our our theme was block out the noise. And w w we talk about it a lot on the podcast. That's kind of like the the seed that started the podcast was like there's so much hype everywhere and it's it's hard to read the news and know what is what you should actually be worried about. What's gonna affect you, even if other people are worried about that kind of stuff. so we've been asking people in the booth, I did a lot of videos this week, what's the noise in the industry? And so I figured instead of doing individual interviews with you, we can just kinda go down the line, like what's your take? What what do you see in the headlines or or people in in the industry talking about a lot that just gets a little eye roll? Yeah, yeah. We we need to sh it
Billy Giles: I got I get start. Okay.
Sean McMillan: off.
Richard Brown: I mean, as always, AI is the first headline, whether it's good or bad, AI is first headline. But from me, from my vulnerability research, it's always the CVEs that drop that people keep promoting and making worse than actually are until you dig into it. And as a company, you don't know what's going on. And that happens even more around DEF CON time. People hype up their talks and hype up everything. And not saying that some of these aren't worthy of that, but a lot of them aren't. And and
Sean McMillan: I'm not saying they
John Untz: Yeah, no.
Richard Brown: Yeah, no, no. I they're worthy of the talk, but not of all the hype. And I think when you dig into the nitty-gritty, we as hackers love when we hear these crazy exploit chains. We love when you hear these cr but the reality of them are not as easy as we all make out to be. Like we were we were talking about the CTFs, for instance, they always divulge into it they not divulge, but they always end up being cryptographic challenges at the end. Right. And that's not my specialty. So I'm helping out early on, I'm finding flags, I'm hacking web apps, and then it's like, Okay, I'm done. Hand it over to you
Sean McMillan: Yeah.
Richard Brown: Right. but but yeah, as far as as as far as hype training goes, I think it it it's always gonna be the vulnerabilities that I hear talks about. and I haven't heard as many this year as I used to. Used to be big on the ATM hacks. I used to love those. Right. I didn't even see one this year I don't think so.
Billy Giles: Right. Matt Birch is giving a talk. Is he? Also explodes too. Yeah. I love this question because and I'm gonna be very careful in how I answer it. Not because I'm a politician.
Sean McMillan: Do it live.
Richard Brown: Yeah.
Billy Giles: Not because I'm a politician, just because I want to make sure that I say this clearly and don't give the wrong impression. But the way that the the two conferences have gone, right, Black Hat is is very heavily sales focused. Yeah. Yeah. And when you have sales driving discussion, often there's fear mongering. And I think that's what we're seeing a lot of. Like we're seeing this people telling stories like, this this fourteen year old took AI and hacked all these companies and he didn't know anything about hacking. Not true, right? When you when you dig into it, he knew a lot about hacking and he augmented his skills. so I think the the difference in the message that I'm hearing at at Defcon is like at least to the Red Team Village from this morning, that the key the keynote panel, all the things that we've done, it's been this is happening. We need to figure out how to do it responsibly and we need to identify the problems we're gonna have along the way and mitigate those now. Right. So one of the the big thing is always like client data, like that's a big challenge in consulting, something we're all facing, we're trying to work through. My biggest fear honorally, and I don't want to fearmonger, but my biggest fear is the the career pathing that we've traditionally had, right? So you you get an entry level pen tester and you let really get some experience that way. Yeah. And then you maybe grow into a red teamer or maybe they come an IoT hacker or whatever whatever they want to do, right? Yeah. But when you take away those entry level jobs and start replacing them with AI, I fear what do we have that path? Yeah, what's the career path for a red teamer? Yeah. So I mean, I'm trying to look at like go back to the the older way of thinking, which is what alternate, you know, kind of tech jobs have the requisite core knowledge that we could recruit from, like you know, like network engineers and things like that. So instead of having a bunch of, you know, experienced pen testers to to choose from when you're trying to grow a red team, then you can, you know, start to look at these other areas and and still continue to have success. But definitely a challenge I'm worried about. Yeah.
Sean McMillan: Yeah.
John Untz: Yeah. So like f firstly like I just wanna like like to touch on that last point you said about like you know pulling from like you know more disparate like career fields and stuff like that. Like I think that's a good point because like like in my case, like my my I my my background in the military was initially in like ground radio, right? That has like nothing relatively nothing to do with like cyber. but like there's a ton of people that came out of backgrounds like that that we ended up taking and were able to like build into really good like cyber operators. So I think that's a good point to make that like There's a lot of those more for lack of a better way to say, like almost hand more hands-on types of career fields that can build into that. the one of the things that I picked up on or that that I want to go back to on the on the main DEF CON floor was the there's a the the phone freaking challenge. going back to like old school kind of tactics and stuff like that. I thought it was really cool that some that they they've brought back like, you know, like what I consider like the original hacking. Right. and like but like to your point like yeah, right, like being able to like like like reteach those like old kind of skill sets that have kind of been like a forgotten art, right?
Richard Brown: For for the younger viewers. Freaking is the old payphones you just have a dial tone.
Sean McMillan: Yeah.
John Untz: Medicine.
Sean McMillan: Yeah, yeah, yeah. Very different from modern yeah.
Richard Brown: Don't Google that. But yeah, you
John Untz: Yeah, yeah. Yeah, yeah. Crunch.
Sean McMillan: Yeah, I kept
Richard Brown: send signals to mimic the phone tones and it would make the call for you. That's a little pivot. A payphone is a thing that's the mouth.
Sean McMillan: Ha ha ha.
Matthew Bryant: Yeah.
John Untz: Yeah. but no it's like like to get back to like your qu original question, Sean. I think that I think that's one thing I did pick up on like like walking around the DEF CON floor was whereas like the like you were saying, like like the black at kind of side of things was a lot more pitching the fear of of AI. I've actually seen a lot of people around the DEF CON floor more so like getting to what it actually is, which is a tool, right? AI is just a tool to get your job done. every time we see these big hacks, right, they o the the headlines always say, you know, AI hacked whatever, whatever. You open the article and it's the same thing. Not AI hacked something. Somebody using AI hacked this in this way, right? because that's the reality. And I think it's cool that, you know, the the the hacker community is, you know, they're responding in a in a healthy manner as far as like, yeah, we recognize this as like a big new technology and embracing it in such a way that it's not It it it's we're we're we're not we're not fearful of it. We're we're bending it to our free will, right?
Sean McMillan: Yeah.
Matthew Bryant: Yeah, I guess going back to like the core point about like the noise and everything, I think I think we're all to the point where we're like, okay, this like obviously serious, it's not gonna go away. Again, imagine going back to before this, yeah. Right. I I think one of the things that I will note is at every part of like this whole AI thing, there's always people who are like, this is the correct way to do it. And if you look back six months ago or a year ago, yeah, all of that stuff that they're saying is like completely irrelevant now. So like the rapid change I think it's it throws a lot of people 'cause they're like, I'm not not up to date with all this, but all I've got to say is like, you know, the environment's changing, like we see the models just keep getting better. There's stuff we had we had to do previously that are not even relevant factors anymore. So, you know, I I would say I would never say like, you it's too late for all I haven't got enough into AI. It's definitely a tool. It's something that you can get into and a hundred percent. So
Sean McMillan: A lot of Conversation over the last few years, obviously, AI being as as new as it is as far as the adoption rate. The talk at Black Hat and DEF CON and just in the industry has been AI, AI, AI, AI. And I'm curious how you guys see. Do you think do you see the conversations around AI actually getting nuanced enough to like matter more now? I mean, like we we talk about the fear-mongering and the AI did it or something. But like that's something we strive for in the podcast. I hope we deliver it somewhere. But like, do you think that people are starting to look at it as more of not like AI is this magic thing, but it's like here's what we're actually able to do with it. Here's what we're, you know, not how how big the model is or something, but like how we actually surround it with our knowledge and our methodologies.
Matthew Bryant: Yeah, I th I think so there's obviously like nobody has any doubt about the level of AI marketing and all the stuff that comes out and like, well, you know, now d they'll all this crazy stuff is true. And there's that, but there is some level of like, listen, there are practical things that are changing. The time from like there's a C V that came out with a broad description to like I have a working exploit is like greatly, greatly reduced and it's only gonna get closer. So there's a lot of like there there's a lot of noise and stuff out then there's like the practicals of like, you know, there's real stuff and I think internal security teams everywhere are almost certainly talking about this. They're like What what are we gonna do in this world where the time between this bug report gets disclosed and suddenly people are trying to use it against us is like a very real discussion then? Yeah. Yeah. So
John Untz: Right. And and and I think honestly like it's I like I know we've talked about this before, like the like the time to patch and and like that timeline is is in my opinion has always been like way like grossly too long. you know, we've we we talked a lot about like companies that would, you know, hold like you know, change review boards and stuff like that, which like understand that like there's business logic decisions that have to get made and and and you know, I I totally understand those things. But Even before AI, we still had those same problems of we're holding back a patch because somebody's not in the office to sign off on updating this database that, you know, might bring the whole company to a halt for five minutes. Right. so I do think it's good that like essentially that we're we we're we're at a heightened threat level, right? because it it it's kind of forcing those functions of, okay, we do need to take these security patches more seriously. We do need to get ahead of the curve now. Right.
Matthew Bryant: I th I think there's also like some supreme irony in the fact that it's like, okay, well you know, we it's like sure these bugs are like gonna be exploited much quicker, but like, we we have a tool that can help us fix stuff quicker and so there's like these both sides of the aisle where it's like, okay, well both are gonna involve like looking at it with new lens.
John Untz: Yeah, yeah, yeah, yeah, exactly.
Matthew Bryant: So
Sean McMillan: Every CISO I have seen at at Black Hat is th they all have grey hair now. Except ours. Ours does not, though.
Billy Giles: So I was gonna add I was gonna add that there's a there's a really interesting kind of two sides of the same coin thing that's happening, right? Because yes, AI is gonna help us solve some security problems. That's inevitable. It already is, right? Yeah. But it's also creating security problems of its own. Yeah. Right? Based on implementations and things. So
Sean McMillan: Attacker is even doing anything.
John Untz: No, right just use it.
Billy Giles: Just implementing a a product it increases the attack surface. And now, you know, as a as a profession, as a career field, we're looking at ways to exploit AI to you know to enable attack. So I did bring up the thing about the training because I do worry about, you know, entry level, but like you're still gonna need humans testing AI because again, there's implementations that have to happen, right? There's there's builds and and things go wrong and people make mistakes. So
Sean McMillan: Headlines we see the more organizations are getting on board with like okay, we have to like do it right and not just do it fast.
Billy Giles: Yep. And as long as people are there to make mistakes, there are gonna be ways to exploit them.
John Untz: Yeah.
Richard Brown: Yeah. Yeah. And and I I will say just I like bringing the podcast out of security sometimes because I feel like we do need to remember security is the juiciness of AI right now. But there are other things going on the AI. They're curing things. They're solving problems. Right. So it's easy to see, well, AI is bad because it's hacking things. AI's bad because it's breaking things, right? Yes, but it's also doing good in other areas too. Yeah. Right? So we can't just keep lumping it into security research and vulnerabilities when there are other practical uses outside of that. Yes, it's helping us speed up our time from discovery to remediation, but it's also doing other good things in the world besides just fixing water.
Sean McMillan: Yeah. Yeah, I think that's that's interesting. Like, you know, you hear some of these like tech giants talking about how AI is if could cure cancer. Right. It could do like all these things. And I think it's it's easy to get caught up in the the fear of it and the cybersecurity aspect of it and forget like what the nuts and bolts of it actually are and and what's possible. And yes, it hasn't cured cancer, but like these these things these Victories are happening down the line, they just don't make headlines. Like has anyone asked about I haven't tried that. I literally have not tried that.
Richard Brown: Yeah, yeah.
John Untz: You have to solve the riddles three.
Richard Brown: Yeah. But
Sean McMillan: I love it.
Richard Brown: I do think and not get too philosophical, I do think it'll be a hacker though that solves these things. Right? We see the biohacking village becoming bigger now. We see people getting implants in their hands to do fun things and open doors. And like the the more that grows and the more hackers get into the mindset of doctors and that kind of thing, I think we will see this eventuality where hackers become this crazy amalgamation of skill sets that aren't just
Sean McMillan: Hackers will inherit the earth. Yeah.
Richard Brown: Rise up, yeah.
Sean McMillan: I love it. Well be kind to me when that happens to me. all right. I wanna I wanna talk for a moment here. Billy, I mentioned you're very heavily involved in Red Team Village on the board. and that is kind of a big deal at DEF CON. It's one of the better known villages, better attended. I'm I'm curious what like how you see Red Team Village as like maybe a model for other villages or like what what is it that sets it apart and and that that draws the kind of crowds that it does?
Billy Giles: Yeah, so interestingly, you know, I I don't get a l spend a lot of time in other villages, but what I do every single time I go, I'm amazed by what they do. Yeah. Right. So it's easy to get caught up in Red Team Village, but I think like all of the villages at DEF CON bring something unique and they're all fantastic. So I just wanna start with that. Yeah. Red Team Village, you know, I got lucky, I just had a friend that said, Hey, come and volunteer and then they liked the way I volunteered, so I I stayed
Sean McMillan: Hey, you did a great job. Would you like more responsibility?
Billy Giles: That was basically what happened to it. But you know, I feel really lucky that they they asked me to be part of the team 'cause it's an incredible group of individuals that just really care about the community. Right. They just want to spend time and effort and put on something that they know the community will enjoy and something they'll get something out of. Like 'cause that's that's our mission. A lot of people don't know we have a a mission behind the scenes and that's to provide offensive security education to the community through conferences, right? So the primary one being DEF CON.
Sean McMillan: I was gonna say this is not just a DEF CON thing. You guys are all over the place, yeah.
Billy Giles: Yep. And we you know, this year I I'm really proud of the team and I wanna hit that point that you were talking about because we had an identity issue kind of a couple of years ago and we were struggling with like how to set the village up to be the most productive because we two years, three years ago, something like that, we said, Hey, we're gonna hand out these poker chips, right? If you wanna come to a talk, come get a poker chip and then you come back at talk time and otherwise you can't even come in the room. Right, right? Mm-hmm. Which basically like Said, hey, if you're if you're in the front of the line, you can come to Red Team Village, but if you're the back line, you're never getting in here. And yeah, that was a horrible thing for us to do it. We didn't realize it when we were planning it. We thought this is gonna be great. It was a fantastic idea. but we got the backlash and and we learned from that. So this year, you know, the village is open, anybody can walk through. We have six tactics stations ongoing the entire time. So you can just sit down and work on something. some of those are tied to workshops. So y you might attend an hour workshop and then you can go over and just do the hands-on portion of the tactic. Yeah. and I think that's so much better than just talks. We used to just do talks. Yeah. It's like you said about payment village, right? It's being able to learn and get your hands on and do stuff. and and and the model of like, you know, I learn and somebody shows me and then I get to practice it, like that is remembering.
Sean McMillan: That's how you actually do
John Untz: human right that's that's human learning, right? You see monkey do, right? That is that is a hundred percent like that's at least for me, that's how I learn.
Billy Giles: Yeah, yeah, yeah. Yep. So because of that, that's you know, where where we set our vision a couple of years ago that we wanted to go with the village. And I I'll just say that like this year is the best I've ever seen and I absolutely love the layout that we have and I think it's it's very inviting and and the noise problem that ha last year down there because it was all the microphones, that that silent headphones system has has really, you know, helped right with that. So yeah, I'm really, really enjoying the village this year.
Sean McMillan: I was gonna ask like how it's evolved over the last couple of years and I figured it would be this big AI answer and you're like, It's headphones, you know? Honestly. Yeah.
Billy Giles: Ha ha.
Sean McMillan: Game changer. Yeah. Sometimes
Richard Brown: Yeah, not the noise.
Sean McMillan: it's a simple thing.
Billy Giles: Turns out if people can hear you?
Richard Brown: Yeah.
Sean McMillan: Yes, yeah, that's actually that's step one of for sure. That's awesome. you're also involved in the Noob Village this year. You're not not running it, but you're you're giving a a presentation there, yeah? Yep.
Billy Giles: So last year an individual, Josh Mason, started the Nuke Village. I when I heard the idea, I was like, How has somebody not done this before?
Sean McMillan: Noob village is itself a noob.
Billy Giles: Yeah, second time. And it this village was created for first timers at DEF CON who don't really know what to go see, right? W where should I go? this I'll start here at the Noob Village. Sure. and they have a lot of talks ongoing there that are geared at at newer people who are interested in cybersecurity or, you know, maybe are in one one role and want to move to another. so I'm giving a talk tomorrow. No, I'm giving a talk on Sunday.
Sean McMillan: I I couldn't tell you what day it is.
Billy Giles: at New Village that's called it's it's basically so you want to be a red teamer, right? I'm just gonna talk about what being a red teamer really is. I think it'll resonate, but unfortunately it's like at you know, twelve forty five on Sunday. So, you know, some folks are already headed out, it's at the end. I'll probably be a zombie by that point, but I'll be there. Yeah. It'll it
Sean McMillan: It'll it'll maybe be a different flavor. You're saying, you know, so you wanna be a red teamer, let me tell you about being a red teamer. At it with red teamer.
Billy Giles: I I just I wanna I wanna cut the noise, right? Because there's a lot of noise about red team as I think it's all just hacking.
Sean McMillan: I curious about like what you my perception of like people you know, people message me on LinkedIn trying to get a job at Bishop Fox all the time and I'm like, Thank you. I don't that's not my area, but I'll I'll do my best, you know? and I I feel like the the vibe behind red teaming is like you can't just become a red teamer. You have to do your time. You have you need the experience. Obviously you need some experience, but like this seems like an accessible for someone newer to the field, newer to DEF CON, like Here's maybe a roadmap. Yep. Something like that.
Billy Giles: Essentially. Yeah. I it exists. I actually made a slide with AI that is a roadmap.
Sean McMillan: Nice.
Billy Giles: That will be part of it. But yeah, I think it's gonna be a lot of fun. to your point though, we have just a a vocabulary problem with red teaming, right? Because we call a lot of people just call including the red team village, we're guilty of this, right? It we mean offensive security village, right? We call it the red team village because it's cooler. but within offensive security, there's a bunch of different disciplines and types of engagements, right? And one of those being a red team. So Technically you can if you look at it in the broader sense, you can go directly into being a red team or an offensive security person, right? A junior pen tester. Well, as long as those jobs are still around. You walk in the door
Sean McMillan: You could be a red teamer.
John Untz: Yeah.
Billy Giles: And then yeah, so the challenge is is keeping the the the vocabulary straight.
Sean McMillan: Yeah. I mean it's the same tactics, same stuff, just kinda different objective. Different different defined goals on you know.
Billy Giles: I always say that red teaming is pen testing with stealth and C two. Yeah.
Sean McMillan: Sure. Yeah. I like that.
John Untz: You guys so so the red team this year, right, you guys are doing the village of villages with a couple of the other right, blue team. I can't remember whichever whichever one's it is off the top of my head.
Billy Giles: I'm gonna apologize because I have no idea.
Sean McMillan: So I do my big No, he's telling you that's what you're doing.
John Untz: Yeah, by the way, if you didn't know, you are dead.
Billy Giles: Yeah. So here's what really happens. like a lot of other organizations just want to be involved with villages, right? So literally on Friday morning, like thirty or forty people will wander in the village and say, Hey, can we put this in your village or can we do this? Right. And the person that they talk to is probably the only person that knows about it at all. yeah, we don't miss. So I'm sure maybe Mike's work in the village of villages. I haven't thought about it.
John Untz: Yeah. Well so so the the so the question I was gonna ask you was like beyond like the 'cause I I off the top of my head I know it's blue team but I I can't wear the other ones. What are some like good or what what would what do you think would be some cool like overlapping villages between like you know like I like in my head I'm thinking like you know red team and IoT or something like that that has like you know some shared some shared skill sets that you could like apply to like a shared CTF or something.
Billy Giles: Yeah, yeah. So there's the pro the biggest overlap that I can see is probably between the red team village and the adversary village. Okay, yeah. Right, 'cause you got it's they're focused on adversary emulation simulation, which is
Richard Brown: Thanks.
Billy Giles: types of red teaming. Yeah. Right. So there's a lot of overlap, a lot of similar talks, a lot of people that, you know, submit talks to both villages. And I think it's great though. the the individual that runs that village has been doing it for years. He teaches at Black Hat, teaches at DEF CON, right? just a a outstanding member of the community. So definitely like that village and support as well. I actually submitted a talk to them as well this year and just shows you the quality 'cause I I didn't make
Sean McMillan: Not that you didn't make it. You just had so many other talks at other villages. I had to turn it down. Awesome. Well, I think I think talking about red teaming, let's kind of take that into, as we said, everything's AI now, right? Matthew, I'd love to pick your brain a little bit about Like how people think of red teaming as this traditional, like it's a phishing thing or it's a network access thing. And you, like, for your job, you kind of have to think about that differently, I'm I'm guessing. what what how how has being an AI red team expert sort of changed your your view of what red teaming means? Or has it?
Matthew Bryant: Yeah, so one thing is I I'll say that I think maybe our perspective is a little biased just because there the parts of it that are easy to us are probably not the easiest for everybody. For example, when it comes to like, you know, we need this initial bug, we need this stuff, it's like we've done this a lot, so that's for us that's a little bit more trivial. What the what the thing that's really enables us to do a lot quicker, which has been a little bit s surprising for us, is like, you know, oftentimes when you first breach into a company, you're like there's this vast engineering creation that's like all of production, all of the internal stuff. And it takes you a while, even if you have the access you need to figure out like the data that you want to steal and and do it end to end, right? But now with these models, instead of like you going through like some huge like multiple code bases and like piecing together forensically where this stuff actually sits, like you can just sort of ask a model in plain English, like, where's the prod database for this? You know, you know, stuff like this. And so it's very helpful in that regard, which is kind of an unexpected ch thing. And then I also think like it's also very useful to like Like when we talk about like building up infrastructure to do something like a a phishing campaign or whatever it is, previously it's like, okay, well now we gotta build all this now, we gotta get domains, we gotta do all this stuff. And now it's like sort of like, okay, so web server to do this is like very we can spin that code up very quickly and get operations moving much more, you know, efficiently. So that's definitely a big change as well. And, you know, it probably speaks widely to the other side too, which is like other offensive on the other side of the you know, of the coin is like, you know Real world APTs are probably going to be able to do that too. So it's interesting to consider. Yeah.
Sean McMillan: I'm curious we because we see so many stories about, you know, AI attacks and and and various whether it's you know people manipulating organizations in more of a traditional way or even their their AI assets or something like that. the floor kind of barrier to entry on on doing a lot of this has lowered definitely. I'm curious like what someone who you know, works at OpenAI, thinks about reading some of these things. like you have a a level of expertise that these kind of vibe code folks maybe don't. do you read these things and think like we're in trouble or you think these these are like kids playing?
Matthew Bryant: You know, listen, I I think that like when it comes to like people who are on the I don't want to say like junior, but you know, the earlier stage in their career, like they can they can definitely do a lot more because, you know, they can it's a it's abstracted, they can like some of the when it comes to like the reverse engineering stuff, for example, like that's very complex, very nitty gritty, and a lot of that has been completely changed by the addition of all these AI models, right? Like you can do just not even just like it's even if you know what you're doing with the reversing, the scale of like analysis you can do and
John Untz: At a speed at which you
Matthew Bryant: and this and the iteration speed hundred percent is like very different. So like That 100% exists. you know, I w I wouldn't say it in I wouldn't state it any other way. but you know, to me, like even on the other side, it it's kind of interesting how work has changed a little bit. There's some things I miss. I miss like being in the zone and like really grinding through code, trying to find yes of the stuff right. But it's also very interesting because now we can sort of move a lot more conceptually. Like before, a lot of times we're like, okay. I know that this is roughly how this is gonna work and how I'm gonna do this and now you can almost move a lot more conceptually where you're like, Okay, I know I need to do this, write the code to do this, execute it, you know, as opposed to you spending many hours doing something that the kind of grunt work that you know you can do, it's just sort of, you know.
Sean McMillan: Yeah. I think you know, as as we've kind of talked about how so many people think of AI, and and no one in this room, but maybe think about AI as like this magic solution to all these things, right? And and it is like sometimes you see it do something and it blows your mind, you're like, wow. I mean, whether that's security related or a really great recipe that it just dropped on you. Or so you know, I there's so many so many different ways that it can that it can surprise you. Do you find working with it so closely that it still surprises you at all, or are you like desensitized to the whole thing?
Matthew Bryant: No, I mean I listen, everybody everybody's surprised even at work, just 'cause like you'll you'll like new I mean, like you'll have like small like model revision changes and you're suddenly like, whoa, this is like way better than before because you'd have these things where you're like, well it just can't do this right, but then you know, they come out with a a new model release and you're like, wow, so all of the stuff that we thought was a problem is apparently solvable and is solved, so we don't to worry about it. So and I've I've noticed like I even in the past couple I want to say like a couple of months, like the you can see a lot more of like I don't wanna say thinking 'cause it's like a complicated what tha what does that mean topic, but you can see it being a lot less like the the traditional like, the AI's being dumb and going down this weird whatever has kinda gone away quite a bit. So
Sean McMillan: Yeah. Yeah. Yeah.
Billy Giles: I I wanted to add one point about something that that he mentioned there. I think we often forget about the human element, right? Yes, AI is magic, right? But hacking a company, whether it's a kid using AI or whatever, right, is still a crime. So that person is still admitting to commit a crime. Just because that crime is is more accessible doesn't make it any less of a crime, right? So I I don't I don't have again, I don't like to fear monger because I don't think we're just gonna have this mass, you know, you know Wave of of criminals, there's people new criminals are
Sean McMillan: Have I been pwned? Absolutely you have.
Billy Giles: But so all the people that are already criminal leaning, right? Are when you read like reports that have come out from the big tech folks like Mandy and et cetera, you know, you you get into these reports and you really look at how they're using AI and it's it's the same way that that we're using it. They're using it to, you know, enable workflows and help write code because writing code sucks. I hate it. Yeah. Like I'm so glad I don't have to do that anymore, you know? Don't
Sean McMillan: Ease you.
Billy Giles: write code anymore and I don't get haircuts anymore. That's I'm done.
Sean McMillan: Me neither.
Richard Brown: Yeah.
Sean McMillan: yeah, I'm I'm also a little bit curious to get sort of all of your perspective, and maybe this could be like our our wrap up. We can kind of just dwell on this for a bit. When you think about what has happened in the industry over the last few years, like AI has disrupted things in in huge ways, right? If we may just kind of say like we think back on what we were talking about just a couple years ago at DEF CON and AI was new and it was exciting. where do you what do you think what kind of conversations do you think we're gonna be having in say two or three years? And you are you're being recorded. We will replay this in two years and we will see.
Richard Brown: Yeah. I think the conversations we'll be having is did we do it effectively? Right? And what I mean by that is companies nowadays who specialize in AI are doing things. Companies who don't specialize in AI just throw AI at the solution and think it's working great. Right? And when that happens, and you see that people who are proper practitioners of AI mess up and make mistakes, and now people who aren't doing it. Right. And w and we we have the the big breach that happened with AI escaping its its, you know. if that happens with someone who's practitioned in AI, that's probably happened in other areas that we don't know about yet. Sure. Because whatever it happened that I have the logs that other companies do. Right. So I mean I I think in the next couple of years we'll see this like we have this like dead internet theory going on already, where at the internet's bots, right? Maybe it's not theory anymore. Maybe in a couple years we're talking to nothing but AI chat bots. So I don't know. My my biggest fear, I guess, in the future is it's gonna be it's already hard to distinguish real people from bots. I'm pretty sure I called to get my oil changed and it was a bot. right just the the the they were talking to me, I was like, they're like, okay, Thursday works. And I was like, I can't tell if you're real Thursday
Sean McMillan: Right now.
Richard Brown: works for me too. Thanks. Thank you.
Sean McMillan: No one's this nice, come on.
Richard Brown: yeah, so I think yeah, i the the conversation will be like did
John Untz: Yeah.
Richard Brown: we take enough precautions before we release this into non again, non cyber fields too. Mm-hmm. So
Sean McMillan: Yeah.
Billy Giles: that's a tough question. That's a really tough question.
Sean McMillan: I have no idea.
Billy Giles: Well, because I I listened to you and you say the models have moving so fast, right? Like like I I think we we it's very possible that we don't even know what conversations we'll be having in two years. Because it's you know there'll be another evolution of the the technology and we'll have gaps and we'll have new problems that have emerged and that's what we'll be talking about is how do we solve those. But I think some of these hopefully in you know, in two years or so, some of these initial problems that we're kinda thinking about and starting to work through. We'll be beyond those and beyond, you know, the the next layer of problems.
John Untz: Right. Yeah. No, I think first of all that's yeah, that's that's a that is a great point that like we are moving at breakneck speed. We have been moving at breakneck speed, right, with with development. so that's a good point. I'm I'm I'm very curious as far as like from like a lawmaker's perspective and like politicians' perspective, there's that that's obviously like a big deal right now. Yeah. There's
Sean McMillan: Yeah.
John Untz: a lot of regulatory mo motions happening right now.
Sean McMillan: Yeah, I was gonna say there's not much regulatory No, there's not. There's not
John Untz: There but there's a lot of talk around it and and I think I mean, you know, the speed of politics is probably around two years on something like that, right?
Sean McMillan: Sure.
John Untz: on top of that, a couple of years we're in another election year, right? So
Richard Brown: Some AI. Right.
John Untz: we'll have what was the the Fallout Three president, John John John Henry Adams or whatever. Yeah. that'll be our next candidate. but no, I th those are things that that I'm that are like at the forefront of like what what a next couple of years look like in the AI space is like, you know We had like in the past I guess the last decade, politics has changed a lot around technology. there's been a lot of misinformation and disinformation campaigns that were pre AI, right? And then now we've come into the AI age and those are just kind of an amplified so I'm I'm I'm definitely curious to see like the like the policy at DEF CON talks that are gonna be t taking place over the next two years for for stuff like that.
Matthew Bryant: Yeah, so th there's like I think a couple of sides for it. First off I wanna say like I actually agree with what you said, which is funny 'cause even listen I'm at like at the Frontier Labs and I'm I'm still like if you ask me two years out, what what do I know what it's gonna look like? I really could not tell you Cause you know, I I when I originally came into the company I was the security skeptic that I think a lot of people were you I'm like I'm like, Yeah, you know, it's interesting, we'll sort of see where it goes. I'd love to see like if this can really 'cause you never know, it's like okay, are are the innovations gonna continue? Are we still gonna see this, right?
John Untz: So at some point, right.
Matthew Bryant: And so like, you and and I think now, you know, i one of the things that is the best is we you get you're wrong a number of times and then you're kinda like, all right, well, clearly there's something here, you know. Now I'm a little bit more on the other side of the fence where I'm like, okay, clearly. I think in the short term, some of the things that excite me are like, you know, I feel like the way that we've used computers up till now has been very much sort of like, you know, in the nineties, it's like, Okay, we got a keyboard and a mouse and like no, we don't get touch screens and I feel I watch pe watch people interact with computers a lot more naturally when it comes to like I could talk to it, gives me accurate information. I don't have to like you know, instead of like looking something up on a search engine and clicking stuff and reading articles, it can just be like, you know, ask the question I want, get the answer I want. Seems a lot more so I think that stuff is is exciting and with their s with the nuance with some of complications there. But you know again, looking out in like looking at six months ago versus now and seeing the complexity changes Pretty crazy. a part of me wants to think as well, you know, there'll be the short term stuff where we'll have automation, but it in the history of computing it's it's rare that we have some big innovation and everybody's just like, well, nobody wants computers and you know, like we finished all the like it tends to be people like, well, let's get more of that in here. So I think on the very long term I could see something like that happening. But again, if I knew, you know, I would be probably making stock market better.
Sean McMillan: That's fair. Well, I I really appreciate everyone taking the time out of their day to to join us here. I think these are interesting conversations and we will see in two years how much of this is true. One thing I will say, I spoke with with a CISO earlier who was talking about one inspiring thing on the the kind of AI front where every organization needs to figure out how to implement it, how to con yeah kind of control it. and they were saying there's a great community of CISOs that are all just kind of Competitor doesn't matter. We are all on board in figuring this out and sharing information and doing whatever we can to make sure that we all get this right. Right. And I think that that kind of summed up to me, like, it's gonna be okay. I think maybe I don't know. Yeah. I think there's there's a lot of a lot of good people sharing information and working really hard to to to get this all right. And I think that that's that's a best case scenario. So
Matthew Bryant: Well best parts about security I think is like, you know, as the security teams we're not like listen, I know we're like competitors or whatever, but we all want the same thing, so just not get hacked, not have these things happen, right?
Sean McMillan: Right.
John Untz: Yeah, it is it is definitely I feel I do feel like that yeah, we're we're one of the few industries that like works together as best as we can along certain better.
Sean McMillan: Sure. Yeah. Yeah. I think I always like to try and wrap our podcast because we usually talk about these terrible attacks and like I like to try and wrap it on something positive. So that's that's what I got. So thank you so much, you guys. Matthew, thanks for for joining. Billy, also a first timer. Great having you on. We'll be in touch next week and we'll have you back on. actually we're gonna have a special episode next week. I will not be on. It's actually gonna be more of like a threat sort of like deep dive episode coming up. So I'm really excited about that. Yeah. but till next time, maybe we'll all be out on these couches again next year. Who knows? Be awesome. Stay safe, and we'll see you next week.
John Untz: Well go like this is so this is actually my first year since the move over to the convention center. last year I the last year I was here was twenty twenty three. so that aspect's totally new to me as far as like having it all under one roof, and not having to go between, you know, different buildings and whatnot for everything. so Richard and I were actually talking about that on the way over. there there's some pros and cons to that I think still. I'm I I definitely like while I don't I don't miss the walking back and forth between, you know, the different hotels and whatnot. but some of the villages that are out on like the main floor, I felt like it's a lot less intimate as far as like getting to getting into the activities, getting to talk to people. And the
Sean McMillan: That's one of the big things at DEF CON, right? Is that it's that that differentiates it from a black hat or an RSA or some other big format.
John Untz: Yeah, yeah. And and and like it's not all of them, right? There were they do still have villages, up in private rooms, up on like the second floor. but there is to me, there's like a notable disparity between, say, like the I think it like the payment processing village was one of them that like I walked in, it was immediately like you could you could just like immediately start learning something as soon as you stepped in, there's an expert in there talking Yeah. You know, ab about the about the process and whatnot. Not to say that there's not experts d at at at any of the other, you know, villages. It just it was just something I picked up on immediately was like, I'm I'm already in the conversation. and I I think that that also just could be like just not as many people up in like the second and third floor as there is like out on the main floor, right? Yeah.
Richard Brown: And one thing to note too, this year we did see them have headphones in some of the other booths. So it's nice that in the loud convention area they were able to have a more intimate setting, but it still was. Now I see the talker up there and I'm four rows back without headphones and I can't hear what he's saying. yeah.
Billy Giles: Yeah.
Richard Brown: It was good all it it was good for the most part.
John Untz: Right, right, right, yeah. Yeah, I'm curious Billy from like from you like being like active in like the the Red Team village area, like how how that experience is as far as like
Sean McMillan: I sh I should have said that. Billy is like Mr. Red Team Village. on the board, you're you're the master of coin, as so to speak, the treasurer.
Billy Giles: fortunate enough that they let me hang out.
Sean McMillan: Yeah, very very involved in DEF CON. So yeah, what's your experience been so far?
Billy Giles: As they say it takes a village, right? So yeah, definitely definitely credit to
Sean McMillan: Sometimes it takes
John Untz: Yeah.
Billy Giles: Credit to the 30 or so people that do this year round to prepare. And then the army of volunteers that we get every year, just amazing. So you know, we show up and the art the volunteers show up and I do nothing. It's amazing. I love it. But yeah, to get back to what you're talking about. So we were on the floor last year, yeah, and it was absolutely awful because there were some vendors down there that had microphones. Right, right. So was very loud. Yeah. And then they told all the villages that we couldn't use microphones last year. Yeah. Right. So we were like trying to yell and use megaphones and we did the keynote panel so there There's you know a couple hundred people standing around and we're trying to use a megaphone and pass it back and forth. Right, right. So the the headsets are a fantastic up there. Like we had we had probably two hundred people in the keynote this morning as well, everyone with a headset on and you know they could all hear us directly from the microphone. So it was it was fantastic this morning.
John Untz: Yeah. Yeah. Something we were yeah, thanks. We something we we noted was I I I I can't recall exactly which villa village it was on the top of my head, but there there was a village that w they didn't have the headphone. They were on the main floor but there you know was it IoT or yeah.
Richard Brown: Game hacking.
John Untz: Or game hacking, yeah, yeah. And so so there was somebody doing a talk there and they just like they like that, right? They didn't even have a a megaphone, they had to like kinda like shout over the crowd and so we were starting to talk about like, you know How could we or or how could anybody like like fix something like this? And wondering if you know everybody has to have the hacker tracker app now to like do any like merch sales. I'm wondering if they can incorporate something like that into the app itself to where you know, like the different speakers, they just you know, they they they basically talk into a microphone and then all you have to do is just like get on the app and and your dial into it. And
Sean McMillan: Yeah.
John Untz: like you can just not even be in the audience. You could be out in the hall or whatever and still listening in like a p like a podcast.
Sean McMillan: Yeah. Right.
John Untz: So
Sean McMillan: Interesting. Interesting. Matthew, have you had a chance to hit the floor at all yet?
Matthew Bryant: Yeah, I mean my my my main experience with DEF CON is definitely you sort of get out of it what you put into it and so like some of the best times I've ever had at the conference have always been like, I'm gonna participate and like do this this event or you help either it's help out or it's like do you know what they have planned and also just one of the nice things is it tends to be like my friends from all over the world usually end up at DEF CON, at the very least you're gonna meet people that you're like, I haven't seen this person in forever. I'm super happy to catch up and like you know, what have you been doing over the past years or some you know, especially with all the all the changes that have happened, so I've always enjoyed them.
John Untz: Yeah. Have you d done anything as far you so you mentioned like you know like the participation stuff. Is there anything like you've you've you've like gone around to to like today and like participated in?
Matthew Bryant: Not yet for this time, although well, my my wife is actually doing quite a few quite a bit of talking, so helping assisting more with that. But in prior years it's been like, you know, pla playing in Hack Fortress and stuff like that, which has always been enjoyable and stuff that nature, so
John Untz: I was trying to explain Hack Fortress to to Richard actually. I so like in in the pa I'd done ShmooCon, for back when they were around. and that was where I did like a lot of Hack Fortress stuff and so I was trying to ex show him like 'cause they didn't have it like actively going when we were over there. but yeah, trying to explain to him like how this whole thing works. I think that's like another like one of those like great things that you know, yeah, like it's like you need to get ten people together to make a team. But it's such a cool competition as far as like It's f so for those that don't know, right? Hack Fortress is historically it was Team Fortress 2, now they just moved to Quake 3. but the way it works is yeah, I keep forget about the mic situation. I mean I'm so used to the webcam stuff.
Sean McMillan: Ha ha.
John Untz: the the the way it works is you get a team of ten, six of them are playing the like the first person shooter, four of them are playing are are are doing like capture the flag hacker challenges, right? the the the hacker challenges are like unlocking, you know, buffs and stuff like that for the team that's playing the the side of the team that's playing the first person shooter and then vice versa as they're getting kills, it's getting like hint unlocks and stuff like that for the the hacker team. And there's like there there's all sorts of like jump in challenges. Like it's a at I think at one one point the last time I we played it, there was one of our team members had to like get up and do like karaoke to something. I could
Sean McMillan: I could get a black bat. See this is what I could do that.
John Untz: That's what I That's th that that's what I mean. That's like one of those like cool challenges that's like there's something for everybody. Right? Like you don't have to just come in and just be a hacker. Like you don't have to be a reverse engineer. You don't have to be a an AI guy. You can do anything on these teams and like everybody can contribute. So yeah, so I just wanted like kudos to the Hack Fortress team, by the way. Like that's such a cool idea. I'm glad that it
Sean McMillan: Yeah, it's back again this year. That's very cool. Yeah. so one of the things I mentioned Bishop Fox's theme this year, like for we had a booth for the first time. That's very cool. and our our theme was block out the noise. And w w we talk about it a lot on the podcast. That's kind of like the the seed that started the podcast was like there's so much hype everywhere and it's it's hard to read the news and know what is what you should actually be worried about. What's gonna affect you, even if other people are worried about that kind of stuff. so we've been asking people in the booth, I did a lot of videos this week, what's the noise in the industry? And so I figured instead of doing individual interviews with you, we can just kinda go down the line, like what's your take? What what do you see in the headlines or or people in in the industry talking about a lot that just gets a little eye roll? Yeah, yeah. We we need to sh it
Billy Giles: I got I get start. Okay.
Sean McMillan: off.
Richard Brown: I mean, as always, AI is the first headline, whether it's good or bad, AI is first headline. But from me, from my vulnerability research, it's always the CVEs that drop that people keep promoting and making worse than actually are until you dig into it. And as a company, you don't know what's going on. And that happens even more around DEF CON time. People hype up their talks and hype up everything. And not saying that some of these aren't worthy of that, but a lot of them aren't. And and
Sean McMillan: I'm not saying they
John Untz: Yeah, no.
Richard Brown: Yeah, no, no. I they're worthy of the talk, but not of all the hype. And I think when you dig into the nitty-gritty, we as hackers love when we hear these crazy exploit chains. We love when you hear these cr but the reality of them are not as easy as we all make out to be. Like we were we were talking about the CTFs, for instance, they always divulge into it they not divulge, but they always end up being cryptographic challenges at the end. Right. And that's not my specialty. So I'm helping out early on, I'm finding flags, I'm hacking web apps, and then it's like, Okay, I'm done. Hand it over to you
Sean McMillan: Yeah.
Richard Brown: Right. but but yeah, as far as as as far as hype training goes, I think it it it's always gonna be the vulnerabilities that I hear talks about. and I haven't heard as many this year as I used to. Used to be big on the ATM hacks. I used to love those. Right. I didn't even see one this year I don't think so.
Billy Giles: Right. Matt Birch is giving a talk. Is he? Also explodes too. Yeah. I love this question because and I'm gonna be very careful in how I answer it. Not because I'm a politician.
Sean McMillan: Do it live.
Richard Brown: Yeah.
Billy Giles: Not because I'm a politician, just because I want to make sure that I say this clearly and don't give the wrong impression. But the way that the the two conferences have gone, right, Black Hat is is very heavily sales focused. Yeah. Yeah. And when you have sales driving discussion, often there's fear mongering. And I think that's what we're seeing a lot of. Like we're seeing this people telling stories like, this this fourteen year old took AI and hacked all these companies and he didn't know anything about hacking. Not true, right? When you when you dig into it, he knew a lot about hacking and he augmented his skills. so I think the the difference in the message that I'm hearing at at Defcon is like at least to the Red Team Village from this morning, that the key the keynote panel, all the things that we've done, it's been this is happening. We need to figure out how to do it responsibly and we need to identify the problems we're gonna have along the way and mitigate those now. Right. So one of the the big thing is always like client data, like that's a big challenge in consulting, something we're all facing, we're trying to work through. My biggest fear honorally, and I don't want to fearmonger, but my biggest fear is the the career pathing that we've traditionally had, right? So you you get an entry level pen tester and you let really get some experience that way. Yeah. And then you maybe grow into a red teamer or maybe they come an IoT hacker or whatever whatever they want to do, right? Yeah. But when you take away those entry level jobs and start replacing them with AI, I fear what do we have that path? Yeah, what's the career path for a red teamer? Yeah. So I mean, I'm trying to look at like go back to the the older way of thinking, which is what alternate, you know, kind of tech jobs have the requisite core knowledge that we could recruit from, like you know, like network engineers and things like that. So instead of having a bunch of, you know, experienced pen testers to to choose from when you're trying to grow a red team, then you can, you know, start to look at these other areas and and still continue to have success. But definitely a challenge I'm worried about. Yeah.
Sean McMillan: Yeah.
John Untz: Yeah. So like f firstly like I just wanna like like to touch on that last point you said about like you know pulling from like you know more disparate like career fields and stuff like that. Like I think that's a good point because like like in my case, like my my I my my background in the military was initially in like ground radio, right? That has like nothing relatively nothing to do with like cyber. but like there's a ton of people that came out of backgrounds like that that we ended up taking and were able to like build into really good like cyber operators. So I think that's a good point to make that like There's a lot of those more for lack of a better way to say, like almost hand more hands-on types of career fields that can build into that. the one of the things that I picked up on or that that I want to go back to on the on the main DEF CON floor was the there's a the the phone freaking challenge. going back to like old school kind of tactics and stuff like that. I thought it was really cool that some that they they've brought back like, you know, like what I consider like the original hacking. Right. and like but like to your point like yeah, right, like being able to like like like reteach those like old kind of skill sets that have kind of been like a forgotten art, right?
Richard Brown: For for the younger viewers. Freaking is the old payphones you just have a dial tone.
Sean McMillan: Yeah.
John Untz: Medicine.
Sean McMillan: Yeah, yeah, yeah. Very different from modern yeah.
Richard Brown: Don't Google that. But yeah, you
John Untz: Yeah, yeah. Yeah, yeah. Crunch.
Sean McMillan: Yeah, I kept
Richard Brown: send signals to mimic the phone tones and it would make the call for you. That's a little pivot. A payphone is a thing that's the mouth.
Sean McMillan: Ha ha ha.
Matthew Bryant: Yeah.
John Untz: Yeah. but no it's like like to get back to like your qu original question, Sean. I think that I think that's one thing I did pick up on like like walking around the DEF CON floor was whereas like the like you were saying, like like the black at kind of side of things was a lot more pitching the fear of of AI. I've actually seen a lot of people around the DEF CON floor more so like getting to what it actually is, which is a tool, right? AI is just a tool to get your job done. every time we see these big hacks, right, they o the the headlines always say, you know, AI hacked whatever, whatever. You open the article and it's the same thing. Not AI hacked something. Somebody using AI hacked this in this way, right? because that's the reality. And I think it's cool that, you know, the the the hacker community is, you know, they're responding in a in a healthy manner as far as like, yeah, we recognize this as like a big new technology and embracing it in such a way that it's not It it it's we're we're we're not we're not fearful of it. We're we're bending it to our free will, right?
Sean McMillan: Yeah.
Matthew Bryant: Yeah, I guess going back to like the core point about like the noise and everything, I think I think we're all to the point where we're like, okay, this like obviously serious, it's not gonna go away. Again, imagine going back to before this, yeah. Right. I I think one of the things that I will note is at every part of like this whole AI thing, there's always people who are like, this is the correct way to do it. And if you look back six months ago or a year ago, yeah, all of that stuff that they're saying is like completely irrelevant now. So like the rapid change I think it's it throws a lot of people 'cause they're like, I'm not not up to date with all this, but all I've got to say is like, you know, the environment's changing, like we see the models just keep getting better. There's stuff we had we had to do previously that are not even relevant factors anymore. So, you know, I I would say I would never say like, you it's too late for all I haven't got enough into AI. It's definitely a tool. It's something that you can get into and a hundred percent. So
Sean McMillan: A lot of Conversation over the last few years, obviously, AI being as as new as it is as far as the adoption rate. The talk at Black Hat and DEF CON and just in the industry has been AI, AI, AI, AI. And I'm curious how you guys see. Do you think do you see the conversations around AI actually getting nuanced enough to like matter more now? I mean, like we we talk about the fear-mongering and the AI did it or something. But like that's something we strive for in the podcast. I hope we deliver it somewhere. But like, do you think that people are starting to look at it as more of not like AI is this magic thing, but it's like here's what we're actually able to do with it. Here's what we're, you know, not how how big the model is or something, but like how we actually surround it with our knowledge and our methodologies.
Matthew Bryant: Yeah, I th I think so there's obviously like nobody has any doubt about the level of AI marketing and all the stuff that comes out and like, well, you know, now d they'll all this crazy stuff is true. And there's that, but there is some level of like, listen, there are practical things that are changing. The time from like there's a C V that came out with a broad description to like I have a working exploit is like greatly, greatly reduced and it's only gonna get closer. So there's a lot of like there there's a lot of noise and stuff out then there's like the practicals of like, you know, there's real stuff and I think internal security teams everywhere are almost certainly talking about this. They're like What what are we gonna do in this world where the time between this bug report gets disclosed and suddenly people are trying to use it against us is like a very real discussion then? Yeah. Yeah. So
John Untz: Right. And and and I think honestly like it's I like I know we've talked about this before, like the like the time to patch and and like that timeline is is in my opinion has always been like way like grossly too long. you know, we've we we talked a lot about like companies that would, you know, hold like you know, change review boards and stuff like that, which like understand that like there's business logic decisions that have to get made and and and you know, I I totally understand those things. But Even before AI, we still had those same problems of we're holding back a patch because somebody's not in the office to sign off on updating this database that, you know, might bring the whole company to a halt for five minutes. Right. so I do think it's good that like essentially that we're we we're we're at a heightened threat level, right? because it it it's kind of forcing those functions of, okay, we do need to take these security patches more seriously. We do need to get ahead of the curve now. Right.
Matthew Bryant: I th I think there's also like some supreme irony in the fact that it's like, okay, well you know, we it's like sure these bugs are like gonna be exploited much quicker, but like, we we have a tool that can help us fix stuff quicker and so there's like these both sides of the aisle where it's like, okay, well both are gonna involve like looking at it with new lens.
John Untz: Yeah, yeah, yeah, yeah, exactly.
Matthew Bryant: So
Sean McMillan: Every CISO I have seen at at Black Hat is th they all have grey hair now. Except ours. Ours does not, though.
Billy Giles: So I was gonna add I was gonna add that there's a there's a really interesting kind of two sides of the same coin thing that's happening, right? Because yes, AI is gonna help us solve some security problems. That's inevitable. It already is, right? Yeah. But it's also creating security problems of its own. Yeah. Right? Based on implementations and things. So
Sean McMillan: Attacker is even doing anything.
John Untz: No, right just use it.
Billy Giles: Just implementing a a product it increases the attack surface. And now, you know, as a as a profession, as a career field, we're looking at ways to exploit AI to you know to enable attack. So I did bring up the thing about the training because I do worry about, you know, entry level, but like you're still gonna need humans testing AI because again, there's implementations that have to happen, right? There's there's builds and and things go wrong and people make mistakes. So
Sean McMillan: Headlines we see the more organizations are getting on board with like okay, we have to like do it right and not just do it fast.
Billy Giles: Yep. And as long as people are there to make mistakes, there are gonna be ways to exploit them.
John Untz: Yeah.
Richard Brown: Yeah. Yeah. And and I I will say just I like bringing the podcast out of security sometimes because I feel like we do need to remember security is the juiciness of AI right now. But there are other things going on the AI. They're curing things. They're solving problems. Right. So it's easy to see, well, AI is bad because it's hacking things. AI's bad because it's breaking things, right? Yes, but it's also doing good in other areas too. Yeah. Right? So we can't just keep lumping it into security research and vulnerabilities when there are other practical uses outside of that. Yes, it's helping us speed up our time from discovery to remediation, but it's also doing other good things in the world besides just fixing water.
Sean McMillan: Yeah. Yeah, I think that's that's interesting. Like, you know, you hear some of these like tech giants talking about how AI is if could cure cancer. Right. It could do like all these things. And I think it's it's easy to get caught up in the the fear of it and the cybersecurity aspect of it and forget like what the nuts and bolts of it actually are and and what's possible. And yes, it hasn't cured cancer, but like these these things these Victories are happening down the line, they just don't make headlines. Like has anyone asked about I haven't tried that. I literally have not tried that.
Richard Brown: Yeah, yeah.
John Untz: You have to solve the riddles three.
Richard Brown: Yeah. But
Sean McMillan: I love it.
Richard Brown: I do think and not get too philosophical, I do think it'll be a hacker though that solves these things. Right? We see the biohacking village becoming bigger now. We see people getting implants in their hands to do fun things and open doors. And like the the more that grows and the more hackers get into the mindset of doctors and that kind of thing, I think we will see this eventuality where hackers become this crazy amalgamation of skill sets that aren't just
Sean McMillan: Hackers will inherit the earth. Yeah.
Richard Brown: Rise up, yeah.
Sean McMillan: I love it. Well be kind to me when that happens to me. all right. I wanna I wanna talk for a moment here. Billy, I mentioned you're very heavily involved in Red Team Village on the board. and that is kind of a big deal at DEF CON. It's one of the better known villages, better attended. I'm I'm curious what like how you see Red Team Village as like maybe a model for other villages or like what what is it that sets it apart and and that that draws the kind of crowds that it does?
Billy Giles: Yeah, so interestingly, you know, I I don't get a l spend a lot of time in other villages, but what I do every single time I go, I'm amazed by what they do. Yeah. Right. So it's easy to get caught up in Red Team Village, but I think like all of the villages at DEF CON bring something unique and they're all fantastic. So I just wanna start with that. Yeah. Red Team Village, you know, I got lucky, I just had a friend that said, Hey, come and volunteer and then they liked the way I volunteered, so I I stayed
Sean McMillan: Hey, you did a great job. Would you like more responsibility?
Billy Giles: That was basically what happened to it. But you know, I feel really lucky that they they asked me to be part of the team 'cause it's an incredible group of individuals that just really care about the community. Right. They just want to spend time and effort and put on something that they know the community will enjoy and something they'll get something out of. Like 'cause that's that's our mission. A lot of people don't know we have a a mission behind the scenes and that's to provide offensive security education to the community through conferences, right? So the primary one being DEF CON.
Sean McMillan: I was gonna say this is not just a DEF CON thing. You guys are all over the place, yeah.
Billy Giles: Yep. And we you know, this year I I'm really proud of the team and I wanna hit that point that you were talking about because we had an identity issue kind of a couple of years ago and we were struggling with like how to set the village up to be the most productive because we two years, three years ago, something like that, we said, Hey, we're gonna hand out these poker chips, right? If you wanna come to a talk, come get a poker chip and then you come back at talk time and otherwise you can't even come in the room. Right, right? Mm-hmm. Which basically like Said, hey, if you're if you're in the front of the line, you can come to Red Team Village, but if you're the back line, you're never getting in here. And yeah, that was a horrible thing for us to do it. We didn't realize it when we were planning it. We thought this is gonna be great. It was a fantastic idea. but we got the backlash and and we learned from that. So this year, you know, the village is open, anybody can walk through. We have six tactics stations ongoing the entire time. So you can just sit down and work on something. some of those are tied to workshops. So y you might attend an hour workshop and then you can go over and just do the hands-on portion of the tactic. Yeah. and I think that's so much better than just talks. We used to just do talks. Yeah. It's like you said about payment village, right? It's being able to learn and get your hands on and do stuff. and and and the model of like, you know, I learn and somebody shows me and then I get to practice it, like that is remembering.
Sean McMillan: That's how you actually do
John Untz: human right that's that's human learning, right? You see monkey do, right? That is that is a hundred percent like that's at least for me, that's how I learn.
Billy Giles: Yeah, yeah, yeah. Yep. So because of that, that's you know, where where we set our vision a couple of years ago that we wanted to go with the village. And I I'll just say that like this year is the best I've ever seen and I absolutely love the layout that we have and I think it's it's very inviting and and the noise problem that ha last year down there because it was all the microphones, that that silent headphones system has has really, you know, helped right with that. So yeah, I'm really, really enjoying the village this year.
Sean McMillan: I was gonna ask like how it's evolved over the last couple of years and I figured it would be this big AI answer and you're like, It's headphones, you know? Honestly. Yeah.
Billy Giles: Ha ha.
Sean McMillan: Game changer. Yeah. Sometimes
Richard Brown: Yeah, not the noise.
Sean McMillan: it's a simple thing.
Billy Giles: Turns out if people can hear you?
Richard Brown: Yeah.
Sean McMillan: Yes, yeah, that's actually that's step one of for sure. That's awesome. you're also involved in the Noob Village this year. You're not not running it, but you're you're giving a a presentation there, yeah? Yep.
Billy Giles: So last year an individual, Josh Mason, started the Nuke Village. I when I heard the idea, I was like, How has somebody not done this before?
Sean McMillan: Noob village is itself a noob.
Billy Giles: Yeah, second time. And it this village was created for first timers at DEF CON who don't really know what to go see, right? W where should I go? this I'll start here at the Noob Village. Sure. and they have a lot of talks ongoing there that are geared at at newer people who are interested in cybersecurity or, you know, maybe are in one one role and want to move to another. so I'm giving a talk tomorrow. No, I'm giving a talk on Sunday.
Sean McMillan: I I couldn't tell you what day it is.
Billy Giles: at New Village that's called it's it's basically so you want to be a red teamer, right? I'm just gonna talk about what being a red teamer really is. I think it'll resonate, but unfortunately it's like at you know, twelve forty five on Sunday. So, you know, some folks are already headed out, it's at the end. I'll probably be a zombie by that point, but I'll be there. Yeah. It'll it
Sean McMillan: It'll it'll maybe be a different flavor. You're saying, you know, so you wanna be a red teamer, let me tell you about being a red teamer. At it with red teamer.
Billy Giles: I I just I wanna I wanna cut the noise, right? Because there's a lot of noise about red team as I think it's all just hacking.
Sean McMillan: I curious about like what you my perception of like people you know, people message me on LinkedIn trying to get a job at Bishop Fox all the time and I'm like, Thank you. I don't that's not my area, but I'll I'll do my best, you know? and I I feel like the the vibe behind red teaming is like you can't just become a red teamer. You have to do your time. You have you need the experience. Obviously you need some experience, but like this seems like an accessible for someone newer to the field, newer to DEF CON, like Here's maybe a roadmap. Yep. Something like that.
Billy Giles: Essentially. Yeah. I it exists. I actually made a slide with AI that is a roadmap.
Sean McMillan: Nice.
Billy Giles: That will be part of it. But yeah, I think it's gonna be a lot of fun. to your point though, we have just a a vocabulary problem with red teaming, right? Because we call a lot of people just call including the red team village, we're guilty of this, right? It we mean offensive security village, right? We call it the red team village because it's cooler. but within offensive security, there's a bunch of different disciplines and types of engagements, right? And one of those being a red team. So Technically you can if you look at it in the broader sense, you can go directly into being a red team or an offensive security person, right? A junior pen tester. Well, as long as those jobs are still around. You walk in the door
Sean McMillan: You could be a red teamer.
John Untz: Yeah.
Billy Giles: And then yeah, so the challenge is is keeping the the the vocabulary straight.
Sean McMillan: Yeah. I mean it's the same tactics, same stuff, just kinda different objective. Different different defined goals on you know.
Billy Giles: I always say that red teaming is pen testing with stealth and C two. Yeah.
Sean McMillan: Sure. Yeah. I like that.
John Untz: You guys so so the red team this year, right, you guys are doing the village of villages with a couple of the other right, blue team. I can't remember whichever whichever one's it is off the top of my head.
Billy Giles: I'm gonna apologize because I have no idea.
Sean McMillan: So I do my big No, he's telling you that's what you're doing.
John Untz: Yeah, by the way, if you didn't know, you are dead.
Billy Giles: Yeah. So here's what really happens. like a lot of other organizations just want to be involved with villages, right? So literally on Friday morning, like thirty or forty people will wander in the village and say, Hey, can we put this in your village or can we do this? Right. And the person that they talk to is probably the only person that knows about it at all. yeah, we don't miss. So I'm sure maybe Mike's work in the village of villages. I haven't thought about it.
John Untz: Yeah. Well so so the the so the question I was gonna ask you was like beyond like the 'cause I I off the top of my head I know it's blue team but I I can't wear the other ones. What are some like good or what what would what do you think would be some cool like overlapping villages between like you know like I like in my head I'm thinking like you know red team and IoT or something like that that has like you know some shared some shared skill sets that you could like apply to like a shared CTF or something.
Billy Giles: Yeah, yeah. So there's the pro the biggest overlap that I can see is probably between the red team village and the adversary village. Okay, yeah. Right, 'cause you got it's they're focused on adversary emulation simulation, which is
Richard Brown: Thanks.
Billy Giles: types of red teaming. Yeah. Right. So there's a lot of overlap, a lot of similar talks, a lot of people that, you know, submit talks to both villages. And I think it's great though. the the individual that runs that village has been doing it for years. He teaches at Black Hat, teaches at DEF CON, right? just a a outstanding member of the community. So definitely like that village and support as well. I actually submitted a talk to them as well this year and just shows you the quality 'cause I I didn't make
Sean McMillan: Not that you didn't make it. You just had so many other talks at other villages. I had to turn it down. Awesome. Well, I think I think talking about red teaming, let's kind of take that into, as we said, everything's AI now, right? Matthew, I'd love to pick your brain a little bit about Like how people think of red teaming as this traditional, like it's a phishing thing or it's a network access thing. And you, like, for your job, you kind of have to think about that differently, I'm I'm guessing. what what how how has being an AI red team expert sort of changed your your view of what red teaming means? Or has it?
Matthew Bryant: Yeah, so one thing is I I'll say that I think maybe our perspective is a little biased just because there the parts of it that are easy to us are probably not the easiest for everybody. For example, when it comes to like, you know, we need this initial bug, we need this stuff, it's like we've done this a lot, so that's for us that's a little bit more trivial. What the what the thing that's really enables us to do a lot quicker, which has been a little bit s surprising for us, is like, you know, oftentimes when you first breach into a company, you're like there's this vast engineering creation that's like all of production, all of the internal stuff. And it takes you a while, even if you have the access you need to figure out like the data that you want to steal and and do it end to end, right? But now with these models, instead of like you going through like some huge like multiple code bases and like piecing together forensically where this stuff actually sits, like you can just sort of ask a model in plain English, like, where's the prod database for this? You know, you know, stuff like this. And so it's very helpful in that regard, which is kind of an unexpected ch thing. And then I also think like it's also very useful to like Like when we talk about like building up infrastructure to do something like a a phishing campaign or whatever it is, previously it's like, okay, well now we gotta build all this now, we gotta get domains, we gotta do all this stuff. And now it's like sort of like, okay, so web server to do this is like very we can spin that code up very quickly and get operations moving much more, you know, efficiently. So that's definitely a big change as well. And, you know, it probably speaks widely to the other side too, which is like other offensive on the other side of the you know, of the coin is like, you know Real world APTs are probably going to be able to do that too. So it's interesting to consider. Yeah.
Sean McMillan: I'm curious we because we see so many stories about, you know, AI attacks and and and various whether it's you know people manipulating organizations in more of a traditional way or even their their AI assets or something like that. the floor kind of barrier to entry on on doing a lot of this has lowered definitely. I'm curious like what someone who you know, works at OpenAI, thinks about reading some of these things. like you have a a level of expertise that these kind of vibe code folks maybe don't. do you read these things and think like we're in trouble or you think these these are like kids playing?
Matthew Bryant: You know, listen, I I think that like when it comes to like people who are on the I don't want to say like junior, but you know, the earlier stage in their career, like they can they can definitely do a lot more because, you know, they can it's a it's abstracted, they can like some of the when it comes to like the reverse engineering stuff, for example, like that's very complex, very nitty gritty, and a lot of that has been completely changed by the addition of all these AI models, right? Like you can do just not even just like it's even if you know what you're doing with the reversing, the scale of like analysis you can do and
John Untz: At a speed at which you
Matthew Bryant: and this and the iteration speed hundred percent is like very different. So like That 100% exists. you know, I w I wouldn't say it in I wouldn't state it any other way. but you know, to me, like even on the other side, it it's kind of interesting how work has changed a little bit. There's some things I miss. I miss like being in the zone and like really grinding through code, trying to find yes of the stuff right. But it's also very interesting because now we can sort of move a lot more conceptually. Like before, a lot of times we're like, okay. I know that this is roughly how this is gonna work and how I'm gonna do this and now you can almost move a lot more conceptually where you're like, Okay, I know I need to do this, write the code to do this, execute it, you know, as opposed to you spending many hours doing something that the kind of grunt work that you know you can do, it's just sort of, you know.
Sean McMillan: Yeah. I think you know, as as we've kind of talked about how so many people think of AI, and and no one in this room, but maybe think about AI as like this magic solution to all these things, right? And and it is like sometimes you see it do something and it blows your mind, you're like, wow. I mean, whether that's security related or a really great recipe that it just dropped on you. Or so you know, I there's so many so many different ways that it can that it can surprise you. Do you find working with it so closely that it still surprises you at all, or are you like desensitized to the whole thing?
Matthew Bryant: No, I mean I listen, everybody everybody's surprised even at work, just 'cause like you'll you'll like new I mean, like you'll have like small like model revision changes and you're suddenly like, whoa, this is like way better than before because you'd have these things where you're like, well it just can't do this right, but then you know, they come out with a a new model release and you're like, wow, so all of the stuff that we thought was a problem is apparently solvable and is solved, so we don't to worry about it. So and I've I've noticed like I even in the past couple I want to say like a couple of months, like the you can see a lot more of like I don't wanna say thinking 'cause it's like a complicated what tha what does that mean topic, but you can see it being a lot less like the the traditional like, the AI's being dumb and going down this weird whatever has kinda gone away quite a bit. So
Sean McMillan: Yeah. Yeah. Yeah.
Billy Giles: I I wanted to add one point about something that that he mentioned there. I think we often forget about the human element, right? Yes, AI is magic, right? But hacking a company, whether it's a kid using AI or whatever, right, is still a crime. So that person is still admitting to commit a crime. Just because that crime is is more accessible doesn't make it any less of a crime, right? So I I don't I don't have again, I don't like to fear monger because I don't think we're just gonna have this mass, you know, you know Wave of of criminals, there's people new criminals are
Sean McMillan: Have I been pwned? Absolutely you have.
Billy Giles: But so all the people that are already criminal leaning, right? Are when you read like reports that have come out from the big tech folks like Mandy and et cetera, you know, you you get into these reports and you really look at how they're using AI and it's it's the same way that that we're using it. They're using it to, you know, enable workflows and help write code because writing code sucks. I hate it. Yeah. Like I'm so glad I don't have to do that anymore, you know? Don't
Sean McMillan: Ease you.
Billy Giles: write code anymore and I don't get haircuts anymore. That's I'm done.
Sean McMillan: Me neither.
Richard Brown: Yeah.
Sean McMillan: yeah, I'm I'm also a little bit curious to get sort of all of your perspective, and maybe this could be like our our wrap up. We can kind of just dwell on this for a bit. When you think about what has happened in the industry over the last few years, like AI has disrupted things in in huge ways, right? If we may just kind of say like we think back on what we were talking about just a couple years ago at DEF CON and AI was new and it was exciting. where do you what do you think what kind of conversations do you think we're gonna be having in say two or three years? And you are you're being recorded. We will replay this in two years and we will see.
Richard Brown: Yeah. I think the conversations we'll be having is did we do it effectively? Right? And what I mean by that is companies nowadays who specialize in AI are doing things. Companies who don't specialize in AI just throw AI at the solution and think it's working great. Right? And when that happens, and you see that people who are proper practitioners of AI mess up and make mistakes, and now people who aren't doing it. Right. And w and we we have the the big breach that happened with AI escaping its its, you know. if that happens with someone who's practitioned in AI, that's probably happened in other areas that we don't know about yet. Sure. Because whatever it happened that I have the logs that other companies do. Right. So I mean I I think in the next couple of years we'll see this like we have this like dead internet theory going on already, where at the internet's bots, right? Maybe it's not theory anymore. Maybe in a couple years we're talking to nothing but AI chat bots. So I don't know. My my biggest fear, I guess, in the future is it's gonna be it's already hard to distinguish real people from bots. I'm pretty sure I called to get my oil changed and it was a bot. right just the the the they were talking to me, I was like, they're like, okay, Thursday works. And I was like, I can't tell if you're real Thursday
Sean McMillan: Right now.
Richard Brown: works for me too. Thanks. Thank you.
Sean McMillan: No one's this nice, come on.
Richard Brown: yeah, so I think yeah, i the the conversation will be like did
John Untz: Yeah.
Richard Brown: we take enough precautions before we release this into non again, non cyber fields too. Mm-hmm. So
Sean McMillan: Yeah.
Billy Giles: that's a tough question. That's a really tough question.
Sean McMillan: I have no idea.
Billy Giles: Well, because I I listened to you and you say the models have moving so fast, right? Like like I I think we we it's very possible that we don't even know what conversations we'll be having in two years. Because it's you know there'll be another evolution of the the technology and we'll have gaps and we'll have new problems that have emerged and that's what we'll be talking about is how do we solve those. But I think some of these hopefully in you know, in two years or so, some of these initial problems that we're kinda thinking about and starting to work through. We'll be beyond those and beyond, you know, the the next layer of problems.
John Untz: Right. Yeah. No, I think first of all that's yeah, that's that's a that is a great point that like we are moving at breakneck speed. We have been moving at breakneck speed, right, with with development. so that's a good point. I'm I'm I'm very curious as far as like from like a lawmaker's perspective and like politicians' perspective, there's that that's obviously like a big deal right now. Yeah. There's
Sean McMillan: Yeah.
John Untz: a lot of regulatory mo motions happening right now.
Sean McMillan: Yeah, I was gonna say there's not much regulatory No, there's not. There's not
John Untz: There but there's a lot of talk around it and and I think I mean, you know, the speed of politics is probably around two years on something like that, right?
Sean McMillan: Sure.
John Untz: on top of that, a couple of years we're in another election year, right? So
Richard Brown: Some AI. Right.
John Untz: we'll have what was the the Fallout Three president, John John John Henry Adams or whatever. Yeah. that'll be our next candidate. but no, I th those are things that that I'm that are like at the forefront of like what what a next couple of years look like in the AI space is like, you know We had like in the past I guess the last decade, politics has changed a lot around technology. there's been a lot of misinformation and disinformation campaigns that were pre AI, right? And then now we've come into the AI age and those are just kind of an amplified so I'm I'm I'm definitely curious to see like the like the policy at DEF CON talks that are gonna be t taking place over the next two years for for stuff like that.
Matthew Bryant: Yeah, so th there's like I think a couple of sides for it. First off I wanna say like I actually agree with what you said, which is funny 'cause even listen I'm at like at the Frontier Labs and I'm I'm still like if you ask me two years out, what what do I know what it's gonna look like? I really could not tell you Cause you know, I I when I originally came into the company I was the security skeptic that I think a lot of people were you I'm like I'm like, Yeah, you know, it's interesting, we'll sort of see where it goes. I'd love to see like if this can really 'cause you never know, it's like okay, are are the innovations gonna continue? Are we still gonna see this, right?
John Untz: So at some point, right.
Matthew Bryant: And so like, you and and I think now, you know, i one of the things that is the best is we you get you're wrong a number of times and then you're kinda like, all right, well, clearly there's something here, you know. Now I'm a little bit more on the other side of the fence where I'm like, okay, clearly. I think in the short term, some of the things that excite me are like, you know, I feel like the way that we've used computers up till now has been very much sort of like, you know, in the nineties, it's like, Okay, we got a keyboard and a mouse and like no, we don't get touch screens and I feel I watch pe watch people interact with computers a lot more naturally when it comes to like I could talk to it, gives me accurate information. I don't have to like you know, instead of like looking something up on a search engine and clicking stuff and reading articles, it can just be like, you know, ask the question I want, get the answer I want. Seems a lot more so I think that stuff is is exciting and with their s with the nuance with some of complications there. But you know again, looking out in like looking at six months ago versus now and seeing the complexity changes Pretty crazy. a part of me wants to think as well, you know, there'll be the short term stuff where we'll have automation, but it in the history of computing it's it's rare that we have some big innovation and everybody's just like, well, nobody wants computers and you know, like we finished all the like it tends to be people like, well, let's get more of that in here. So I think on the very long term I could see something like that happening. But again, if I knew, you know, I would be probably making stock market better.
Sean McMillan: That's fair. Well, I I really appreciate everyone taking the time out of their day to to join us here. I think these are interesting conversations and we will see in two years how much of this is true. One thing I will say, I spoke with with a CISO earlier who was talking about one inspiring thing on the the kind of AI front where every organization needs to figure out how to implement it, how to con yeah kind of control it. and they were saying there's a great community of CISOs that are all just kind of Competitor doesn't matter. We are all on board in figuring this out and sharing information and doing whatever we can to make sure that we all get this right. Right. And I think that that kind of summed up to me, like, it's gonna be okay. I think maybe I don't know. Yeah. I think there's there's a lot of a lot of good people sharing information and working really hard to to to get this all right. And I think that that's that's a best case scenario. So
Matthew Bryant: Well best parts about security I think is like, you know, as the security teams we're not like listen, I know we're like competitors or whatever, but we all want the same thing, so just not get hacked, not have these things happen, right?
Sean McMillan: Right.
John Untz: Yeah, it is it is definitely I feel I do feel like that yeah, we're we're one of the few industries that like works together as best as we can along certain better.
Sean McMillan: Sure. Yeah. Yeah. I think I always like to try and wrap our podcast because we usually talk about these terrible attacks and like I like to try and wrap it on something positive. So that's that's what I got. So thank you so much, you guys. Matthew, thanks for for joining. Billy, also a first timer. Great having you on. We'll be in touch next week and we'll have you back on. actually we're gonna have a special episode next week. I will not be on. It's actually gonna be more of like a threat sort of like deep dive episode coming up. So I'm really excited about that. Yeah. but till next time, maybe we'll all be out on these couches again next year. Who knows? Be awesome. Stay safe, and we'll see you next week.