WEBVTT
1
00:00:01.169 --> 00:00:04.790
How'd you like to listen to. NET Rocks with no ads? Easy.
2
00:00:05.370 --> 00:00:08.789
Become a patron. For just $ 5 a month, you get
3
00:00:08.890 --> 00:00:11.710
access to a private RSS feed where all the shows
4
00:00:11.789 --> 00:00:14.890
have no ads. $ 20 a month will get you that
5
00:00:15.109 --> 00:00:18.839
and a special. NET Rocks patron mug. Sign up now
6
00:00:18.890 --> 00:00:36.520
at patreon.dotnetrocks.com. NET Rocks Hey, and welcome back to. NET Rocks.
7
00:00:36.700 --> 00:00:39.399
I'm Carl Franklin. And I'm Richard Campbell. And Michael Howard's
8
00:00:39.439 --> 00:00:41.770
here with us. We'll have him jump in if he
9
00:00:41.799 --> 00:00:45.090
wants to in the beginning. And we'll introduce him a
10
00:00:45.090 --> 00:00:47.789
little bit later after the first bits. You know what
11
00:00:47.829 --> 00:00:49.869
those are. Here we go. Here we go. 2020.
12
00:00:49.850 --> 00:00:53.950
It's episode 20 when we're almost done, right? Like this
13
00:00:54.030 --> 00:00:56.850
ends in 20 after 2026. So we got like six
14
00:00:56.909 --> 00:00:57.390
more of these.
15
00:00:57.609 --> 00:01:00.429
And it's becoming less and less interesting because most people
16
00:01:00.490 --> 00:01:01.729
have lived through the last six years.
17
00:01:01.929 --> 00:01:05.599
It's so current. Yeah. It's kind of now. Especially 2020,
18
00:01:05.599 --> 00:01:08.280
because of course, what can you talk about except COVID?
19
00:01:08.439 --> 00:01:10.680
Oh my God, COVID. All right, I'm done, Richard. What
20
00:01:10.700 --> 00:01:12.000
about space? Yeah, thanks for playing, guys.
21
00:01:13.079 --> 00:01:14.700
Well, the other thing I would talk about is this
22
00:01:14.769 --> 00:01:16.829
is when the UK officially leaves.
23
00:01:18.450 --> 00:01:21.109
The EU. Oh, there's more news, but COVID is the
24
00:01:21.150 --> 00:01:24.189
big one. George Floyd. It is the big one, yeah.
25
00:01:24.209 --> 00:01:29.760
George Floyd killed. Big, big reaction to that that sparked
26
00:01:29.900 --> 00:01:34.700
off a lot of stuff. Joe Biden beat Donald Trump. Yes, there,
27
00:01:34.819 --> 00:01:39.519
I said it because that's the truth. Worldwide economic collapse
28
00:01:39.579 --> 00:01:43.560
caused by COVID. Lockdowns. Yeah, it's just stall. It was
29
00:01:43.609 --> 00:01:47.109
just horrible. Donald Trump was impeached for the first time. Oh,
30
00:01:47.129 --> 00:01:49.790
in the first year. I was at the end. A
31
00:01:49.849 --> 00:01:53.189
lot of wildfires in Australia and Western US. The terrible ones.
32
00:01:55.549 --> 00:01:58.989
Know about and now and today it's really relevant in
33
00:01:59.030 --> 00:02:05.049
september the second nagorno-karabakh war so this is between azerbaijan
34
00:02:05.209 --> 00:02:08.990
and armenia this is an enclave that normally is controlled
35
00:02:09.030 --> 00:02:12.280
by armenia but the azerbaijanis wanted it and they attack
36
00:02:12.360 --> 00:02:14.379
and so the azerbaijanis are the ones with the oil
37
00:02:14.419 --> 00:02:18.159
money and they're muslim the uh the armenians are predominantly
38
00:02:18.180 --> 00:02:22.039
christian uh the azerbaijanis attack and to be clear this
39
00:02:22.060 --> 00:02:24.719
is a very complicated conflict like it's gone on literally
40
00:02:24.740 --> 00:02:27.169
for centuries But it was a drone war. It was
41
00:02:27.229 --> 00:02:28.750
arguably the first drone war.
42
00:02:28.969 --> 00:02:29.289
Wow.
43
00:02:29.710 --> 00:02:36.259
The Azerbaijanis bought Turkish Bayraktar drones. They had bought some
44
00:02:36.300 --> 00:02:41.039
of the surveillance equipment from the Israelis. And so they
45
00:02:41.060 --> 00:02:45.639
had continuous surveillance. They were using drones for attack. They
46
00:02:45.759 --> 00:02:49.620
destroyed missile sites and so forth. The Iranians were fighting
47
00:02:49.659 --> 00:02:52.539
the old style with Soviet equipment. and just kind of
48
00:02:52.560 --> 00:02:54.560
got rolled over. Like you'd think the Russians would have
49
00:02:54.599 --> 00:02:57.699
taken a hint watching their stuff be torn up by
50
00:02:57.780 --> 00:03:01.509
drones in 2020. Instead, they bought a lot of drones. Well,
51
00:03:01.530 --> 00:03:04.729
they did eventually, but first they got hit pretty hard. Anyway,
52
00:03:05.310 --> 00:03:08.110
it was only six weeks. And that doesn't change the
53
00:03:08.150 --> 00:03:10.629
fact that a lot of people died. It did result
54
00:03:10.669 --> 00:03:13.030
in the fall of the, of the region and the
55
00:03:13.069 --> 00:03:15.479
change in the, in the environment over there. But it's
56
00:03:15.500 --> 00:03:18.360
just a precursor conflict to, to, you know, we saw
57
00:03:18.580 --> 00:03:21.120
an example, just of course it was COVID and, There
58
00:03:21.129 --> 00:03:23.599
was all the things going on at that time in
59
00:03:23.620 --> 00:03:25.300
that year that nobody was paying attention to.
60
00:03:25.319 --> 00:03:25.539
Yeah.
61
00:03:25.599 --> 00:03:30.219
A couple other notable deaths in 2020. Ruth Bader Ginsburg.
62
00:03:31.580 --> 00:03:32.099
What a blunder.
63
00:03:32.280 --> 00:03:32.620
Yeah.
64
00:03:32.979 --> 00:03:37.439
Kobe Bryant. Yeah, the helicopter accident. And good trouble himself,
65
00:03:37.840 --> 00:03:38.430
John Lewis.
66
00:03:38.750 --> 00:03:38.949
Right.
67
00:03:39.150 --> 00:03:41.469
Died civil rights icon. Yeah. Yeah, it was just a
68
00:03:41.550 --> 00:03:44.129
bad- Tough year. Bad years. Tough year.
69
00:03:44.229 --> 00:03:45.590
Yeah. Do you want to know what happened in space?
70
00:03:45.629 --> 00:03:48.969
There wasn't a ton, but there's some important ones. In February,
71
00:03:49.069 --> 00:03:52.189
Solar Orbiter launches. You don't really know much about this one.
72
00:03:52.310 --> 00:03:55.449
This was a joint ESA-NASA mission in that order. It's
73
00:03:55.469 --> 00:03:58.990
very much a European mission with NASA instrumentations and They
74
00:03:59.009 --> 00:04:00.810
provided the Atlas V as well, but it was built
75
00:04:00.830 --> 00:04:03.810
by Airbus. And its goal was to get a view
76
00:04:04.050 --> 00:04:07.710
of the poles of the sun. Normally, you're launching your
77
00:04:07.729 --> 00:04:10.270
spacecraft because the Earth's in the plane of the ecliptic.
78
00:04:10.310 --> 00:04:11.909
Your spacecraft are going to be as well. Trying to
79
00:04:11.930 --> 00:04:13.780
get to high inclination is very, very difficult. Not that
80
00:04:13.789 --> 00:04:17.579
they got all that high. They'll fly down into a
81
00:04:17.920 --> 00:04:21.560
looping orbit inside the orbit of Mercury and then use
82
00:04:21.860 --> 00:04:26.199
Venus to do the slingshots and repeatedly tip the spacecraft.
83
00:04:26.230 --> 00:04:29.089
So it is about 24 degrees off the planet ecliptic.
84
00:04:29.110 --> 00:04:30.569
It takes a ton of energy to do that. They
85
00:04:30.589 --> 00:04:34.110
borrowed lots of energy from Venus, but it's a one-ton spacecraft,
86
00:04:34.129 --> 00:04:34.290
so it.
87
00:04:34.269 --> 00:04:34.670
Can do that.
88
00:04:35.490 --> 00:04:38.790
But it'll get us our first visual views of the
89
00:04:38.829 --> 00:04:39.560
poles of the sun.
90
00:04:39.920 --> 00:04:41.779
Cool mission. Yeah, that is cool.
91
00:04:41.920 --> 00:04:45.560
In May. the first crew dragon demo mission. So this
92
00:04:45.579 --> 00:04:48.790
was Bob, uh, Benneken and Doug Hurley go up to
93
00:04:48.810 --> 00:04:52.889
the space station and demonstrate that, uh, the commercial spacecraft
94
00:04:52.930 --> 00:04:55.370
can actually go to the space station properly. And that'll
95
00:04:55.389 --> 00:04:57.589
be followed up in November with a regular crew flight
96
00:04:57.629 --> 00:04:59.750
of four astronauts to crew the space station.
97
00:04:59.850 --> 00:05:01.110
So there you go.
98
00:05:01.250 --> 00:05:04.730
After what this would be nine years since the Atlantis
99
00:05:04.750 --> 00:05:07.769
had landed. And the only support for the station was, uh,
100
00:05:08.160 --> 00:05:10.920
Via Soyuz, now the Americans had a vehicle again, the
101
00:05:10.959 --> 00:05:11.519
former crew driver.
102
00:05:11.540 --> 00:05:14.290
I got a question, which Michael might know the answer to,
103
00:05:14.370 --> 00:05:18.949
but you said ESA and NASA did this thing together
104
00:05:19.110 --> 00:05:22.279
in 2020, but Brexit was in 2020. Was Was Britain
105
00:05:22.339 --> 00:05:24.990
part of ESA in 2020? Did they participate?
106
00:05:25.319 --> 00:05:27.370
Yeah, I don't think so. I could be wrong, but
107
00:05:27.389 --> 00:05:28.009
I don't think so.
108
00:05:28.250 --> 00:05:29.430
It's mostly Germany, France.
109
00:05:29.470 --> 00:05:29.769
Yeah.
110
00:05:29.829 --> 00:05:32.750
Okay. It's Airbus, it's Defense of the Space. All right.
111
00:05:32.810 --> 00:05:36.480
July, the Perseverance rover. So, this was the test article
112
00:05:36.620 --> 00:05:39.660
for the original Curiosity rover with a bunch of upgraded things,
113
00:05:39.699 --> 00:05:41.259
better wheels, better suspension.
114
00:05:41.300 --> 00:05:41.399
Yeah.
115
00:05:42.079 --> 00:05:46.939
New instruments, the Ingenuity helicopter, all of that stuff gets
116
00:05:47.000 --> 00:05:50.189
launched in July. July is the perfect time to launch
117
00:05:50.230 --> 00:05:53.449
to Mars, July 2020. There's a synchronicity to the orbits, right?
118
00:05:53.470 --> 00:05:56.629
They're in a two, three period. And so every roughly
119
00:05:56.689 --> 00:05:58.069
two years, you get a chance to do a bunch
120
00:05:58.089 --> 00:05:59.889
of flights. And so July, there's actually three. There's the
121
00:05:59.930 --> 00:06:03.500
Perseverance rover, which is huge. There's also China's very first
122
00:06:03.560 --> 00:06:08.329
mission to Mars, Tianwen-1. And then the UAE. the United
123
00:06:08.389 --> 00:06:13.829
Aramids launches their Hope climate orbiter to Mars. So three
124
00:06:13.870 --> 00:06:15.250
launches in the same month. Wow.
125
00:06:15.269 --> 00:06:15.970
Did they all make it?
126
00:06:16.310 --> 00:06:16.980
In October.
127
00:06:17.420 --> 00:06:18.339
The U.S. made it.
128
00:06:18.379 --> 00:06:19.089
They all make it.
129
00:06:19.120 --> 00:06:20.740
Yeah, actually. Very cool.
130
00:06:20.899 --> 00:06:24.160
And I mean, I'll talk more about the Tianwen-1 when
131
00:06:24.180 --> 00:06:27.189
it lands next year. So in episode 2021. Because that
132
00:06:27.209 --> 00:06:29.310
was China's first attempt to go to Mars and it
133
00:06:29.470 --> 00:06:33.750
fully worked. Nobody's pulled that off before. Everybody loses a
134
00:06:33.769 --> 00:06:34.889
few trying to get to Mars.
135
00:06:35.589 --> 00:06:37.810
Just name it. Everybody does. But China didn't.
136
00:06:38.009 --> 00:06:40.550
But, you know, the advantage of being, I don't know,
137
00:06:40.670 --> 00:06:44.660
fourth or fifth mover or something like that. In October, OSIRIS-REx,
138
00:06:44.779 --> 00:06:49.420
one of the asteroid missions, touches on asteroid Bennu. and
139
00:06:49.480 --> 00:06:51.480
collects a sample there. In fact, it does a little
140
00:06:51.560 --> 00:06:54.759
too well because when it touches, Bennu is very much
141
00:06:54.790 --> 00:06:57.350
a rubble pile and all that gravel goes everywhere and
142
00:06:57.750 --> 00:07:01.509
they actually have trouble closing up the sample container because
143
00:07:01.529 --> 00:07:03.709
there's too much stuff. They have to come up with
144
00:07:03.730 --> 00:07:07.629
such technical maneuvers as shaking a little off to try
145
00:07:07.689 --> 00:07:09.310
and get the thing closed up so they can put
146
00:07:09.329 --> 00:07:12.209
it in the capsule to return. Another asteroid mission at
147
00:07:12.250 --> 00:07:14.529
the end of the year in December, Hayabusa 2, will
148
00:07:14.569 --> 00:07:19.040
actually successfully return It's sample payload from the asteroid Regu,
149
00:07:19.060 --> 00:07:22.240
and that is a JAXA mission. A little recap on
150
00:07:22.279 --> 00:07:25.779
what SpaceX did in 2020. There was actually 25 launches
151
00:07:25.819 --> 00:07:28.699
from SpaceX, which at the time was an amazing number.
152
00:07:29.459 --> 00:07:33.899
Just remembering that SpaceX will do 150 this year. So obviously,
153
00:07:34.259 --> 00:07:37.870
there's the two Crew Dragons, the test run in March,
154
00:07:37.949 --> 00:07:41.519
and then the full payload in November. They'll also fly
155
00:07:41.519 --> 00:07:45.310
14 Starlink missions, 833 satellites for a network of almost
156
00:07:45.310 --> 00:07:47.029
900 by the end of the year.
157
00:07:47.050 --> 00:07:47.120
Wow.
158
00:07:47.129 --> 00:07:51.350
Have you ever seen the Starlink satellites leaving the spaceship? Yeah.
159
00:07:51.370 --> 00:07:52.800
It's like pizza boxes going out.
160
00:07:52.939 --> 00:07:55.660
Yeah, yeah. Well, now they've gotten bigger because of the
161
00:07:55.699 --> 00:07:58.000
V2 minis. And so, they only fly like 24 or
162
00:07:58.000 --> 00:08:00.819
28 of them depending on the inclination. But at this time,
163
00:08:00.879 --> 00:08:03.370
they're flying 60 a run.
164
00:08:03.389 --> 00:08:04.230
That's crazy. Wow.
165
00:08:04.620 --> 00:08:07.879
Just these huge numbers of satellites. And that's where they also,
166
00:08:08.259 --> 00:08:10.240
this is the year where they have the reflectivity problems.
167
00:08:10.439 --> 00:08:12.870
And so you can see them for an extended period
168
00:08:12.879 --> 00:08:15.720
of time until they learn how to orient them and
169
00:08:15.759 --> 00:08:18.160
paint them correctly so they're not so visible and don't
170
00:08:18.199 --> 00:08:19.139
bother people so much.
171
00:08:19.250 --> 00:08:21.189
I remember there was a bunch of astronomers that were
172
00:08:21.230 --> 00:08:23.949
complaining they were polluting the night sky with their telescopes.
173
00:08:24.209 --> 00:08:27.009
Yeah. Well, and that's still an issue, although let's face it,
174
00:08:27.009 --> 00:08:28.550
digital processing can fix that.
175
00:08:28.769 --> 00:08:29.290
Right.
176
00:08:29.449 --> 00:08:32.750
But making bright lights make it worse. So making sure
177
00:08:32.769 --> 00:08:34.250
it doesn't reflect sunlight helps.
178
00:08:34.549 --> 00:08:37.139
I've seen them though. I've seen the trail go across
179
00:08:37.240 --> 00:08:40.500
and it's pretty fascinating and a little bit I don't know.
180
00:08:40.539 --> 00:08:42.970
You know, SpaceX does some things that if you weren't
181
00:08:43.009 --> 00:08:45.570
paying attention, you'd think we're being invaded by aliens.
182
00:08:45.769 --> 00:08:48.330
Well, or, you know, or Dr. No is in full swing.
183
00:08:48.389 --> 00:08:51.879
Like the line between supervillain and tech billionaire is getting
184
00:08:51.899 --> 00:08:52.799
very narrow.
185
00:08:53.000 --> 00:08:55.220
Just people don't know. Like, you know, the first time
186
00:08:55.259 --> 00:08:57.840
that I saw the booster rocket spinning, you know, when
187
00:08:57.879 --> 00:09:01.789
it– I thought it was like a spaceship. And so
188
00:09:01.809 --> 00:09:03.769
did a million other people until I found out, oh,
189
00:09:03.809 --> 00:09:05.730
that's just SpaceX. That's what they do. And what are
190
00:09:05.769 --> 00:09:08.470
those lights going? Hey, is that Santa Claus? No, that's
191
00:09:08.509 --> 00:09:09.250
just SpaceX.
192
00:09:09.309 --> 00:09:13.600
Yeah. I use Stellarium and it'll show you all the SpaceX.
193
00:09:13.960 --> 00:09:17.620
Sure. Something's whizzing around out there. I know. Must be
194
00:09:17.659 --> 00:09:21.340
my Facebook friends. They're at average intelligence or ability to
195
00:09:21.399 --> 00:09:22.379
look things up.
196
00:09:22.379 --> 00:09:24.460
10,000 plus of them by the end of this year,
197
00:09:24.519 --> 00:09:26.990
just so you know. There'll be a bunch of other
198
00:09:27.009 --> 00:09:29.049
missions as well, including a couple of GPS satellites. They'll
199
00:09:29.080 --> 00:09:32.100
also start doing their Starship flights, the hop tests, and
200
00:09:32.120 --> 00:09:34.820
the first, what they called belly flop test, where they
201
00:09:34.860 --> 00:09:36.840
fire it up to a few kilometers up and then
202
00:09:36.879 --> 00:09:38.419
let it fall on its belly so they could actually
203
00:09:38.480 --> 00:09:41.059
land it. That was SN8 by the end of 2020.
204
00:09:41.059 --> 00:09:43.799
It does not go well, but they'll solve that and
205
00:09:43.879 --> 00:09:45.940
prove that this whole idea is even possible. All right,
206
00:09:45.960 --> 00:09:46.960
should we move on to computing?
207
00:09:47.120 --> 00:09:47.279
Yeah.
208
00:09:47.440 --> 00:09:50.440
We'll start in January with the OpenAI paper called the
209
00:09:50.559 --> 00:09:54.779
Neural Scaling Laws. Lead author is Jared Kaplan. There's a
210
00:09:54.779 --> 00:09:57.679
whole bunch of others, including Daryl Modi, who this time
211
00:09:57.720 --> 00:09:59.970
is at OpenAI, will eventually be the CEO of Anthrop.
212
00:10:00.600 --> 00:10:02.759
And this was the paper that sort of kicked off
213
00:10:02.840 --> 00:10:06.450
this idea of, you know, different from all the other
214
00:10:06.490 --> 00:10:08.929
machine learning models we did where we worry about overfitting
215
00:10:08.970 --> 00:10:12.539
and training sets and so forth. that for large language models,
216
00:10:12.580 --> 00:10:13.970
we should just train on as much data as we
217
00:10:13.990 --> 00:10:17.509
can possibly get. There's lots of debate as to whether
218
00:10:17.529 --> 00:10:19.809
this is that good an idea. We've definitely come into
219
00:10:19.889 --> 00:10:22.909
other techniques from there. But this paper is kind of
220
00:10:22.950 --> 00:10:25.570
the stimulus for what will be the insanity coming in
221
00:10:25.590 --> 00:10:28.720
the next couple of years. January is also when Microsoft
222
00:10:28.740 --> 00:10:30.960
switches over to Chromium as the rendering engine in the
223
00:10:31.039 --> 00:10:35.190
new Edge browser. The pandemic's in full swing in March
224
00:10:35.210 --> 00:10:38.360
is when lockdowns really kick off and everybody goes home
225
00:10:38.429 --> 00:10:41.940
and everybody's got Zoom. Teams explodes for better or worse.
226
00:10:42.559 --> 00:10:48.629
But a little thing I paid attention to was Terry Breton,
227
00:10:48.690 --> 00:10:53.879
who is the EU Internal Market Commissioner. reached out to
228
00:10:54.240 --> 00:10:58.139
Netflix and YouTube and Amazon Prime and asked him to
229
00:10:58.179 --> 00:11:01.679
turn off all the 4K features. He was concerned about
230
00:11:01.700 --> 00:11:05.899
the amount of available bandwidth across Europe as everybody went
231
00:11:06.000 --> 00:11:10.610
home and used the internet differently. Was it actually a crisis?
232
00:11:10.690 --> 00:11:13.470
Nobody knows for sure, or at least he's not talking
233
00:11:13.509 --> 00:11:17.090
about it. They started turning up the bandwidth again in May,
234
00:11:17.230 --> 00:11:20.889
and Netflix's Posts about this are interesting because they talk
235
00:11:20.929 --> 00:11:23.750
about network changes and increasing capacity and things like that.
236
00:11:24.370 --> 00:11:26.519
So maybe there really was a crisis because of the
237
00:11:26.559 --> 00:11:29.440
change in the Internet consumption due to COVID. But, you know,
238
00:11:29.519 --> 00:11:32.440
a lot of details aren't revealed necessarily. But that to
239
00:11:32.480 --> 00:11:33.320
me was very interesting.
240
00:11:33.340 --> 00:11:33.480
Yeah.
241
00:11:34.250 --> 00:11:37.600
April is when Uncle Satchit says, two years worth of
242
00:11:37.639 --> 00:11:42.580
digital transformation in two months. Because everybody had to all work.
243
00:11:42.620 --> 00:11:44.419
This is when I started doing True Run As a week,
244
00:11:44.539 --> 00:11:49.850
just talking about topics around what was necessary for sysadmins
245
00:11:51.529 --> 00:11:52.769
with everybody working from home.
246
00:11:52.990 --> 00:11:56.169
My brother is a programmer at a local company. He's
247
00:11:56.190 --> 00:11:59.169
been there for years and years. And they basically do
248
00:11:59.490 --> 00:12:02.309
online vehicle registrations. And they were the first in the
249
00:12:02.409 --> 00:12:07.840
area to do it. And their customers are states, not
250
00:12:07.960 --> 00:12:15.730
individual sales places, dealerships. But anyway, they were renting an
251
00:12:15.830 --> 00:12:19.470
office building in an office park out here, umpteen billion
252
00:12:19.529 --> 00:12:22.809
square feet. And during COVID, people went to work at home.
253
00:12:23.450 --> 00:12:27.259
And I just remember Jay coming to rehearsal once and said, Well,
254
00:12:27.279 --> 00:12:29.759
I've resigned myself to the idea that I'm never going
255
00:12:29.799 --> 00:12:32.889
back to the office. And they basically moved out of
256
00:12:32.929 --> 00:12:35.590
the office. Yeah, lots did. They stopped renting it. And
257
00:12:35.629 --> 00:12:38.289
I think, in general, office space took a big dive
258
00:12:39.049 --> 00:12:39.850
in 2020.
259
00:12:39.850 --> 00:12:42.210
You think about all the property that Microsoft gave up
260
00:12:42.269 --> 00:12:42.850
in Bellevue.
261
00:12:43.000 --> 00:12:43.409
Yeah.
262
00:12:43.600 --> 00:12:46.480
They kept their buildings in Redmond, but all that rented space.
263
00:12:46.299 --> 00:12:47.019
In Bellevue went away.
264
00:12:47.340 --> 00:12:47.519
Right.
265
00:12:47.659 --> 00:12:48.559
And all of it went to Zoom.
266
00:12:48.820 --> 00:12:49.059
Yeah.
267
00:12:49.559 --> 00:12:50.120
Well, to Teams.
268
00:12:50.139 --> 00:12:54.769
Teams. The first virtual build in May is also when
269
00:12:54.909 --> 00:12:58.929
they do the full release of Blazor WebAssembly.
270
00:12:59.129 --> 00:12:59.649
Yeah.
271
00:13:00.309 --> 00:13:02.429
Obviously, a bunch of other cool announcements around building that
272
00:13:02.450 --> 00:13:05.990
time span. Of course, Blazor, not the first WA programming language,
273
00:13:06.070 --> 00:13:10.740
Golang added WA support back in 2018. In June, and again,
274
00:13:10.759 --> 00:13:14.679
no people remember much about this because it was mid-pandemic.
275
00:13:15.429 --> 00:13:19.690
Microsoft is a big splash about OpenAI GPT-3 being built
276
00:13:19.769 --> 00:13:22.990
on what they called the Azure supercomputer, which was a
277
00:13:23.070 --> 00:13:26.120
bunch of different Azure data centers harnessed together with 10,000 GPUs, 285,000 CPUs.
278
00:13:28.679 --> 00:13:33.120
cpu cores to build a get this 175 billion parameter
279
00:13:33.159 --> 00:13:36.029
model wow i mean big big big for the time
280
00:13:36.250 --> 00:13:38.230
not so much anymore but at the time.
281
00:13:38.110 --> 00:13:40.629
I remember uh brian mckay who's one of my happy
282
00:13:40.649 --> 00:13:43.789
next guys getting on slack and telling us how awesome
283
00:13:43.809 --> 00:13:46.289
this gpt thing was but it was difficult to set
284
00:13:46.350 --> 00:13:48.570
up at the time but then yeah you know i
285
00:13:48.610 --> 00:13:51.269
tried it and of course like everybody else was kind
286
00:13:51.289 --> 00:13:51.919
of blown away.
287
00:13:52.029 --> 00:13:55.600
Yeah Later that year in September is when Microsoft actually
288
00:13:55.679 --> 00:14:00.649
licenses GPT-3 from OpenAI, which I presume is how GitHub
289
00:14:00.669 --> 00:14:03.049
gets access to it. They'll make GitHub Copilot the following.
290
00:14:03.970 --> 00:14:08.610
A couple more stories. In November, Apple announces the M1 processor.
291
00:14:08.769 --> 00:14:09.009
Yes.
292
00:14:09.250 --> 00:14:11.840
And I mention this because this, I would argue, is
293
00:14:12.460 --> 00:14:17.000
Tim Cook's most memorable move. He was always a hardware guy.
294
00:14:17.019 --> 00:14:18.879
This is an astonishing piece of hardware. There's a system
295
00:14:18.919 --> 00:14:23.879
on a chip where the GPU and CPU, NPU, the
296
00:14:24.100 --> 00:14:26.440
IO and security buses and so forth are all literally
297
00:14:26.480 --> 00:14:28.820
in the same die. The memory is in the same package.
298
00:14:29.899 --> 00:14:33.679
So this is made by TSMC, five nanometer process, about
299
00:14:33.679 --> 00:14:37.679
16 billion transistors total. That includes eight CPU cores, eight
300
00:14:37.700 --> 00:14:40.610
GPU cores, a 16 core neural engine, and up to
301
00:14:40.610 --> 00:14:42.580
16 gigabytes of RAM right.
302
00:14:42.490 --> 00:14:43.070
On the package.
303
00:14:43.110 --> 00:14:46.669
So you get both lower power consumption and higher performance.
304
00:14:47.720 --> 00:14:48.759
And little would we realize.
305
00:14:48.899 --> 00:14:51.419
I have a MacBook Pro with an M1. Yeah. First gen.
306
00:14:51.679 --> 00:14:52.279
And it's good.
307
00:14:52.440 --> 00:14:54.580
Is that 16? Is that megabytes or gigabytes?
308
00:14:54.860 --> 00:14:55.139
Gigs.
309
00:14:55.490 --> 00:14:57.750
Yeah. That's RAM, RAM, not cache.
310
00:14:57.769 --> 00:14:58.429
That's RAM, RAM.
311
00:14:58.490 --> 00:14:58.889
Okay. Yeah.
312
00:14:58.909 --> 00:15:01.009
They're not putting cache on. The cache is there too.
313
00:15:01.269 --> 00:15:01.429
Okay.
314
00:15:01.450 --> 00:15:03.230
And also that RAM is shared with the GPU.
315
00:15:03.549 --> 00:15:04.549
Right.
316
00:15:04.570 --> 00:15:08.519
So what we're doing right now with LLMs and the
317
00:15:08.559 --> 00:15:10.919
new agent models and so forth, The M1 was built
318
00:15:10.940 --> 00:15:13.019
for it, not knowing it was built for it. They
319
00:15:13.039 --> 00:15:14.779
were just trying to make the most efficient computer they
320
00:15:14.799 --> 00:15:17.149
could consume the least power. And this is Apple's move
321
00:15:17.210 --> 00:15:20.769
back to ARM, having come from the Motorola chipset, moved
322
00:15:20.789 --> 00:15:23.190
to Intel for a few years. Now they're making their
323
00:15:23.230 --> 00:15:24.549
own thing based on ARM.
324
00:15:26.029 --> 00:15:26.289
Two more.
325
00:15:26.450 --> 00:15:29.720
December, both in December. The SolarWinds supply chain attack. So
326
00:15:29.740 --> 00:15:34.919
this is Russian SVR. The pure brilliance of this is unbelievable.
327
00:15:35.429 --> 00:15:38.860
So in September of 2019, hackers successfully break into the
328
00:15:38.899 --> 00:15:43.519
SolarWinds development environment and they insert code into the development chain.
329
00:15:43.960 --> 00:15:45.940
The way they do it is incredibly insidious. It's part
330
00:15:45.960 --> 00:15:49.200
of their build system that they replace code in the
331
00:15:49.279 --> 00:15:52.399
build without actually changing the visible source code. So developers
332
00:15:52.419 --> 00:15:53.889
don't think their code has changed at all, but what
333
00:15:53.909 --> 00:15:56.909
they're actually compiling is different code with this thing called
334
00:15:56.929 --> 00:16:01.750
the sunburst backdoor. They, they, they, It takes them a
335
00:16:01.769 --> 00:16:03.389
few months of doing testing to get this to work.
336
00:16:03.460 --> 00:16:06.700
By March, they have actually figured it out. And the
337
00:16:06.779 --> 00:16:10.399
Orion monitoring software, SolarWinds builds this infrastructure monitoring software, is
338
00:16:10.440 --> 00:16:14.019
now distributed to 18,000 customers with the Sunburst backdoor in it.
339
00:16:15.389 --> 00:16:18.190
The Russians are successful enough that in June, they actually
340
00:16:18.269 --> 00:16:21.870
removed the whole build injection system. Like, they're done. And
341
00:16:21.929 --> 00:16:24.580
are happily operating it. Now, admittedly, they don't actually use
342
00:16:24.600 --> 00:16:27.539
that backdoor much. Maybe 100 customers are totally affected. But
343
00:16:27.580 --> 00:16:30.799
it's in December when one of those customers, a security
344
00:16:30.840 --> 00:16:36.149
company called FireEye, realizes they've been exploited and traces it
345
00:16:36.210 --> 00:16:39.149
back to the Orion code base and basically pops the
346
00:16:39.190 --> 00:16:42.940
whole thing open. It's an incredibly sophisticated supply chain attack
347
00:16:42.980 --> 00:16:45.399
and scares just not actually everybody. It's not the first one,
348
00:16:45.440 --> 00:16:46.750
but in a lot of ways, it's the one that
349
00:16:46.759 --> 00:16:47.970
made the most news.
350
00:16:48.309 --> 00:16:51.350
It could be made into a feature film, actually, if
351
00:16:51.409 --> 00:16:52.470
it was handled correctly.
352
00:16:52.850 --> 00:16:53.830
It's astonishing.
353
00:16:53.850 --> 00:16:55.190
Yeah.
354
00:16:55.309 --> 00:16:58.029
And if the Russians hadn't decided to go after FireEye,
355
00:16:58.269 --> 00:17:00.360
who knows when it would have been detected. Just he
356
00:17:00.399 --> 00:17:02.759
went after the guys who were in the security space
357
00:17:02.799 --> 00:17:04.319
and good enough at attacking breach properly.
358
00:17:05.869 --> 00:17:08.170
Yeah, I remember when I was invited to a meeting
359
00:17:08.190 --> 00:17:11.779
to be briefed on the attack when we sort of
360
00:17:11.799 --> 00:17:14.339
knew what was going on. And yeah, I'll be frank,
361
00:17:14.700 --> 00:17:17.640
I was kind of gobsmacked actually by- Gobsmacked, yeah. By
362
00:17:17.660 --> 00:17:18.440
the sophistication.
363
00:17:18.640 --> 00:17:22.500
It's so clever. Holy man. I don't expect bad guys
364
00:17:22.539 --> 00:17:25.279
to be this smart, right? If they were smart, they'd
365
00:17:25.299 --> 00:17:27.240
be good guys. Like the idea that bad guys would
366
00:17:27.259 --> 00:17:30.009
come up with something this clever. But again, state actors,
367
00:17:30.069 --> 00:17:32.170
like they're working for more than just a paycheck here.
368
00:17:32.490 --> 00:17:36.420
Yeah, but remember though, you know, As Sherrod Dugripo has
369
00:17:36.460 --> 00:17:39.599
told me many, many times, this is their day job, right?
370
00:17:39.680 --> 00:17:41.799
They come to work, they clock in, they do the work,
371
00:17:41.839 --> 00:17:44.740
they have reviews every year, they go home to their families,
372
00:17:45.029 --> 00:17:46.109
and they start again tomorrow.
373
00:17:46.150 --> 00:17:47.829
They get promotions by figuring this stuff out.
374
00:17:48.009 --> 00:17:49.529
Exactly. It's just their job.
375
00:17:49.569 --> 00:17:52.789
Yeah. As Dwayne LaFleur would say, oh, this is awesome, guys.
376
00:17:53.329 --> 00:17:55.690
This is awesome. It's a stunner.
377
00:17:56.670 --> 00:17:59.690
I'll finish out the year of compute in 2020 with
378
00:18:00.049 --> 00:18:04.430
China's Zhuheng Photonic Quantum Computer, which I think is particularly
379
00:18:04.490 --> 00:18:08.740
relevant for today's conversation. This was a dedicated machine using
380
00:18:09.000 --> 00:18:12.700
photonic quantum entanglement, which is very, very clever, unique, very
381
00:18:12.740 --> 00:18:16.480
different from Sycamore, the Google's device from the previous year,
382
00:18:16.539 --> 00:18:19.799
which was the … The hanging chandelier in liquid helium,
383
00:18:19.839 --> 00:18:21.279
this doesn't need any of this, but it was built
384
00:18:21.319 --> 00:18:23.940
specifically for Gaussian boson sampling.
385
00:18:24.299 --> 00:18:27.849
Nobody knows what you're talking about, Richard. I'm okay with that.
386
00:18:27.920 --> 00:18:29.109
I might contest.
387
00:18:29.190 --> 00:18:32.230
I mean, I know enough to be dangerous. Talk to
388
00:18:32.250 --> 00:18:33.470
me about the software side of it.
389
00:18:33.890 --> 00:18:35.890
Yeah, and that's the whole thing is this is nowhere
390
00:18:35.970 --> 00:18:38.670
near a general purpose computer or even a supercomputer. This
391
00:18:38.730 --> 00:18:41.650
is a machine to demonstrate that quantum entanglement can tackle
392
00:18:41.990 --> 00:18:45.009
one kind of problem, the Gaussian boson sample problem. Now,
393
00:18:45.029 --> 00:18:46.450
that's an important problem, but it was sort of a
394
00:18:46.609 --> 00:18:49.150
proof point I think very much this is a, hey,
395
00:18:49.210 --> 00:18:51.170
we get to play too. And I think everybody reacted
396
00:18:51.190 --> 00:18:54.299
to it that way. Because this 200-second run for something
397
00:18:54.319 --> 00:18:57.880
that in theory would have taken this supercomputer 2 billion years,
398
00:18:57.940 --> 00:19:00.720
not that anybody's going to test that, it just put
399
00:19:00.740 --> 00:19:05.009
China instantly on the map and really made it very clear.
400
00:19:05.529 --> 00:19:07.809
There's more than one way to quantum. And this is
401
00:19:07.869 --> 00:19:10.190
a wildly different way. Not that we've heard much from
402
00:19:10.269 --> 00:19:13.569
them since. But in 2020, that was a really big deal.
403
00:19:13.589 --> 00:19:14.490
But does it run Doom?
404
00:19:14.829 --> 00:19:15.390
It really doesn't.
405
00:19:15.670 --> 00:19:17.630
No, not a bit. No, it won't.
406
00:19:18.799 --> 00:19:21.140
I mean, supercomputers are limited in their own way, too,
407
00:19:21.200 --> 00:19:24.180
as well. But this was literally built for one thing.
408
00:19:24.200 --> 00:19:28.430
This is like Turing's device for cracking Enigma. Good for
409
00:19:28.549 --> 00:19:31.900
one thing. The idea of general-purpose computing is a much
410
00:19:31.960 --> 00:19:33.960
different idea than what we're doing in this kind of
411
00:19:33.980 --> 00:19:34.460
class of work.
412
00:19:34.619 --> 00:19:34.859
Anyway.
413
00:19:34.920 --> 00:19:37.759
Yeah, 100%. I think people need to understand that. Yeah,
414
00:19:37.880 --> 00:19:41.099
still people don't grapple that. There won't be an office
415
00:19:41.140 --> 00:19:43.269
for quantum. It's not going to exist.
416
00:19:43.329 --> 00:19:44.250
Oh, man.
417
00:19:44.490 --> 00:19:44.990
I'm sorry.
418
00:19:45.569 --> 00:19:49.890
You sold me that subscription. Let's get them on the phone. Yeah.
419
00:19:51.059 --> 00:19:54.680
And as much as we can tell at this time,
420
00:19:55.039 --> 00:19:58.220
these will always be supercomputers for particular problem spaces. Most
421
00:19:58.259 --> 00:20:02.009
of them very deterministic problem spaces, too. But let's wrap
422
00:20:02.089 --> 00:20:04.670
up the history lesson and get on to our larger
423
00:20:04.710 --> 00:20:05.529
conversation about quantum.
424
00:20:05.819 --> 00:20:07.839
Well, but first, we have to do.
425
00:20:07.960 --> 00:20:08.460
But first.
426
00:20:08.619 --> 00:20:10.680
Better know a framework. Roll the music. Awesome.
427
00:20:10.700 --> 00:20:15.059
All right, man.
428
00:20:15.160 --> 00:20:19.539
What do you got?
429
00:20:19.660 --> 00:20:22.150
All right. So, as people who listen to me on
430
00:20:22.400 --> 00:20:26.009
my various podcasts and stuff probably know, I bought this
431
00:20:26.890 --> 00:20:32.339
big GPU machine. a year or so ago, just because
432
00:20:32.420 --> 00:20:34.720
I anticipated being able to run local models.
433
00:20:35.160 --> 00:20:36.960
And you got it ahead of the hardware crisis too.
434
00:20:37.000 --> 00:20:38.400
So how smart are you?
435
00:20:38.599 --> 00:20:38.960
Yeah.
436
00:20:40.059 --> 00:20:44.460
I got it at walmart.com for $ 6, 000. It uses an
437
00:20:44.660 --> 00:20:48.480
NVIDIA RTX 1590 with 32 gigs of VRAM.
438
00:20:49.339 --> 00:20:51.740
Today that card's 15 grand if you can find one.
439
00:20:51.960 --> 00:20:55.509
I have, yeah, now it is. I have 96 gigs
440
00:20:55.750 --> 00:20:58.779
of system RAM and it's You know, blinky lights and
441
00:20:58.839 --> 00:21:02.339
quiet as anything, right? Which is amazing. So on Coded
442
00:21:02.359 --> 00:21:05.430
with AI, Jeff Fritz and I did a series on
443
00:21:05.609 --> 00:21:10.089
taking a whole bunch of models that would run on
444
00:21:10.190 --> 00:21:15.750
Ollama and running them and then putting it through a test. Basically,
445
00:21:16.029 --> 00:21:21.539
a lot of them failed. More so because of context,
446
00:21:21.670 --> 00:21:23.680
I think, than this is what I'm learning now, the
447
00:21:23.720 --> 00:21:27.940
context size, if it's too small. We'll just barf. The
448
00:21:28.420 --> 00:21:32.960
LLM will just and lose it or get into an
449
00:21:33.019 --> 00:21:37.960
infinite loop. And basically what I came down to is
450
00:21:38.609 --> 00:21:45.910
running llama.cpp. And llama.cpp is like Ollama, but it's not.
451
00:21:46.029 --> 00:21:48.950
It's a different thing. It's open source. But I can
452
00:21:49.029 --> 00:21:58.720
run the fairly new QEN 3.8.27b model and llama cpp
453
00:21:58.779 --> 00:22:03.859
will use vram and system ram at the same time
454
00:22:04.000 --> 00:22:06.740
and it will balance them out and figure out automatically
455
00:22:06.880 --> 00:22:10.109
how much of which to use and let me tell
456
00:22:10.140 --> 00:22:14.450
you something this is i this is what i've been
457
00:22:14.490 --> 00:22:17.890
waiting for it works so well that i don't feel
458
00:22:17.910 --> 00:22:20.609
the need to go back for what i do you
459
00:22:20.630 --> 00:22:23.930
know debugging coding all of that stuff i don't need
460
00:22:24.089 --> 00:22:27.539
to go back to any frontier models anymore.
461
00:22:27.859 --> 00:22:28.019
Right.
462
00:22:28.140 --> 00:22:29.670
I haven't found, I've been using it for a couple
463
00:22:29.690 --> 00:22:29.930
of weeks.
464
00:22:29.950 --> 00:22:30.930
You're just working local now.
465
00:22:31.130 --> 00:22:33.019
I'm just working local. Yeah. And the only thing I'm
466
00:22:33.880 --> 00:22:36.400
that's costing me is electricity. But I got solar panels.
467
00:22:36.700 --> 00:22:38.839
There you go. Some pretty good, especially in the summer.
468
00:22:39.539 --> 00:22:41.740
Feeling good. And that machine you bought, like to build
469
00:22:41.759 --> 00:22:44.039
that machine today, it's a big bucks.
470
00:22:44.299 --> 00:22:44.559
Yeah.
471
00:22:44.700 --> 00:22:46.240
So you did the right thing. Well, I thought it
472
00:22:46.279 --> 00:22:48.779
was big bucks back then, but now... Yeah, it was. Yeah.
473
00:22:48.799 --> 00:22:50.579
It was a lot of money for a PC back then.
474
00:22:50.700 --> 00:22:52.099
It doesn't seem that way at this moment.
475
00:22:52.119 --> 00:22:53.640
Well, anyway... And what sort of performance are you getting
476
00:22:53.680 --> 00:22:55.089
out of it? Like tokens per second?
477
00:22:55.349 --> 00:22:59.539
That's great. It's as good as... Any frontier model that
478
00:22:59.559 --> 00:23:02.849
I've been using, I've been using GitHub Copilot CLI, mostly
479
00:23:02.869 --> 00:23:08.670
with Claude Sonnet. It's as good as that. I don't
480
00:23:08.710 --> 00:23:12.190
find myself waiting around. And it can do anything that
481
00:23:12.210 --> 00:23:15.750
I throw at it. It handles local stuff on the computer,
482
00:23:17.089 --> 00:23:23.140
stuff in Azure, in GitHub. It's just really good. This
483
00:23:23.240 --> 00:23:26.759
model compared to other models is good, but you run
484
00:23:26.799 --> 00:23:30.609
it in Lama CPP. And it's like beautiful on this
485
00:23:30.690 --> 00:23:35.289
particular configuration. I've found the sweet spot. So I wrote
486
00:23:35.309 --> 00:23:38.119
a document and that is the link that we'll put
487
00:23:38.279 --> 00:23:41.720
on the page. It's a GitHub. Read me basically running
488
00:23:41.819 --> 00:23:45.240
Quinn 3.8, 27 B with Lama CPP and GitHub co-pilot
489
00:23:45.259 --> 00:23:49.259
CLI on windows. And it tells you exactly how to
490
00:23:49.420 --> 00:23:52.470
install everything, all the stuff that you got to go,
491
00:23:52.710 --> 00:23:57.130
put everything where it needs to go. And like, Download
492
00:23:57.210 --> 00:24:01.970
Quinn and run it and how you access it remotely.
493
00:24:03.069 --> 00:24:06.079
It's great. So I have my dev machine. I have
494
00:24:06.099 --> 00:24:12.319
my GPU machine. And it's a match made in heaven.
495
00:24:13.359 --> 00:24:15.559
There's not a lot of people running those kinds of
496
00:24:16.539 --> 00:24:17.980
headless systems with Windows.
497
00:24:18.019 --> 00:24:18.660
They're mostly Linux.
498
00:24:18.779 --> 00:24:18.960
Right.
499
00:24:19.380 --> 00:24:23.700
Cool. It's good. And also, this model, Quinn 3.8, has
500
00:24:23.759 --> 00:24:28.109
vision support. So I can paste screenshots in, you know,
501
00:24:28.269 --> 00:24:30.779
and it just works. It's wonderful. Cool.
502
00:24:30.960 --> 00:24:31.099
Yep.
503
00:24:31.180 --> 00:24:32.710
That's what I got. Richard, who's talking to us?
504
00:24:33.000 --> 00:24:36.000
Grabbed a comment off of show 1963, which you did
505
00:24:36.059 --> 00:24:37.559
last year with one Michael Howard.
506
00:24:37.700 --> 00:24:38.019
Yay.
507
00:24:38.079 --> 00:24:40.140
Talking about 30 years of application security. This is back
508
00:24:40.160 --> 00:24:42.339
when you were still the red teamer. I know your
509
00:24:42.359 --> 00:24:45.160
life is different now. And this comment comes from also
510
00:24:45.200 --> 00:24:48.710
a past guest, Arnold Axelrod, who said, great show as always.
511
00:24:48.849 --> 00:24:51.369
One comment regarding input validation, because of course we talked
512
00:24:51.390 --> 00:24:54.069
about input validations. Toward the end of the show, Michael
513
00:24:54.109 --> 00:24:56.049
mentions that all input should be considered evil and must
514
00:24:56.089 --> 00:24:59.259
be validated in order to be considered secure. Yeah, hard
515
00:24:59.279 --> 00:25:01.779
to argue with that. I'm not a security expert, but
516
00:25:01.799 --> 00:25:03.460
I have a different take on that. I don't think
517
00:25:03.480 --> 00:25:05.759
that the problem lies in the lack of input validation,
518
00:25:05.799 --> 00:25:08.940
but I think that input validation should be a business requirement.
519
00:25:10.319 --> 00:25:12.940
The example being zip codes. I don't necessarily know what
520
00:25:12.980 --> 00:25:15.049
a formal zip code is or will ever be consistent
521
00:25:15.069 --> 00:25:17.930
around the world. Answer is absolutely no. When you consider
522
00:25:17.950 --> 00:25:20.490
the idea that Ireland only got postal codes in 2015,
523
00:25:20.470 --> 00:25:25.190
like good luck. In my opinion, the problem lies with
524
00:25:25.210 --> 00:25:27.609
the use of parsers and interpreters and not using escape
525
00:25:27.650 --> 00:25:31.069
sequences or other structures to separate arbitrary input from structure ones,
526
00:25:31.569 --> 00:25:34.670
like separating the inputs from the SQL statement itself appropriately.
527
00:25:35.450 --> 00:25:39.549
Both SQL, JavaScript, and command through the process start in
528
00:25:39.589 --> 00:25:42.549
C-sharp are interpreters, and if you construct an input to
529
00:25:42.650 --> 00:25:46.289
them that contains an arbitrary user input without sanitizing it
530
00:25:46.329 --> 00:25:50.519
with the correct escape sequences is where unpredictability comes to play,
531
00:25:50.759 --> 00:25:55.779
which causes the risk. A URI also having structured format
532
00:25:55.940 --> 00:25:58.099
that is parsed by a browser and constructing a URI,
533
00:25:58.119 --> 00:26:00.559
let's say, with an arbitrary query string, that may be harmful,
534
00:26:01.180 --> 00:26:03.549
but you're probably using URI encoding on the inputs, and
535
00:26:03.569 --> 00:26:05.990
that should leave you safe. This doesn't require you to
536
00:26:06.029 --> 00:26:08.210
limit the input in any way, just to format it correctly.
537
00:26:09.250 --> 00:26:11.089
There is where the focus should be, as far as
538
00:26:11.130 --> 00:26:14.450
I'm concerned, not just to invalidate all inputs. I'd love
539
00:26:14.470 --> 00:26:15.430
to hear your opinions on it.
540
00:26:15.710 --> 00:26:16.390
You want my opinion?
541
00:26:16.569 --> 00:26:17.490
Go for it. Yeah, hit you.
542
00:26:18.819 --> 00:26:20.579
You know, it all got turned on its head, right?
543
00:26:20.630 --> 00:26:25.460
With LLMs and jailbreaking. What is the input? What is it?
544
00:26:25.460 --> 00:26:27.980
What is valid? Can you even escape it? Even escape
545
00:26:28.000 --> 00:26:32.980
versions can still get through any kind of checks. So, yeah,
546
00:26:33.319 --> 00:26:34.700
I just wrote about that recently. Yeah.
547
00:26:35.140 --> 00:26:39.460
Our new injection attack starts with ignore all previous instructions.
548
00:26:39.779 --> 00:26:41.960
Exactly. So, Mike Resinovich actually has a t-shirt with that
549
00:26:41.980 --> 00:26:45.539
on the back. He showed it to me at Build
550
00:26:45.799 --> 00:26:49.559
last time and I almost fell over laughing.
551
00:26:50.039 --> 00:26:50.839
It's the best.
552
00:26:50.980 --> 00:26:52.500
He was so proud of it. He said, hey, Michael,
553
00:26:52.519 --> 00:26:59.740
check this out. It's completely turned on its head. And
554
00:26:59.759 --> 00:27:02.259
that's why we've got all these other defenses that come
555
00:27:02.299 --> 00:27:04.829
into play and these guardrails and so on in LLMs.
556
00:27:04.990 --> 00:27:06.809
It's because we need them. We don't know what the
557
00:27:06.849 --> 00:27:07.329
input is.
558
00:27:07.450 --> 00:27:10.150
Yeah. LLMs need to get a sense of humor, right?
559
00:27:10.809 --> 00:27:13.309
A sense of sarcasm, a sense of irony. And they
560
00:27:13.329 --> 00:27:16.029
got to get sensitive to that just like we humans do.
561
00:27:16.490 --> 00:27:16.869
I think.
562
00:27:17.549 --> 00:27:17.869
I don't know.
563
00:27:18.349 --> 00:27:20.559
Yeah, we really want to pass every input through an
564
00:27:20.650 --> 00:27:22.500
LLM to say, is this a potential attack?
565
00:27:22.779 --> 00:27:25.299
Yeah, good luck with that. No, but of course not.
566
00:27:25.380 --> 00:27:27.119
But I mean, if you're dealing with an LLM and
567
00:27:27.140 --> 00:27:29.680
you're at the keyboard and talking to it, right? And
568
00:27:29.720 --> 00:27:33.640
you give it some ridiculous prompt, you know, that's clearly
569
00:27:34.089 --> 00:27:38.390
satirical or something. It should laugh back at you, you know?
570
00:27:38.849 --> 00:27:39.910
Well, that happened to me once.
571
00:27:40.329 --> 00:27:41.450
Yeah, that's a good one. Yeah.
572
00:27:41.470 --> 00:27:43.710
Dude, that happened to me once. All seriousness.
573
00:27:43.769 --> 00:27:43.930
Really?
574
00:27:43.970 --> 00:27:44.170
Yeah.
575
00:27:44.289 --> 00:27:48.250
I was working on the podcast website or something and
576
00:27:48.309 --> 00:27:50.750
asked it to do a quick security review of the code.
577
00:27:51.589 --> 00:27:54.559
And it found something. I was just running Visual Studio,
578
00:27:54.599 --> 00:27:57.420
I think. And it found something and it said, here
579
00:27:57.500 --> 00:28:01.559
is a, I don't know, it was an outdated HTTP header.
580
00:28:01.579 --> 00:28:05.640
It had been deprecated. I didn't know. A supposedly security
581
00:28:05.680 --> 00:28:09.150
header had been deprecated. And it said, by the way,
582
00:28:09.190 --> 00:28:12.329
this HTTP underscore blah, blah, blah has been deprecated for
583
00:28:12.369 --> 00:28:16.180
security reasons. And it's really ironic that you as the
584
00:28:16.259 --> 00:28:18.259
author of Running Secure Code didn't find this.
585
00:28:18.500 --> 00:28:19.180
Oh, that's great.
586
00:28:20.579 --> 00:28:20.859
Yeah.
587
00:28:21.259 --> 00:28:22.299
That's what I'm talking about.
588
00:28:22.319 --> 00:28:24.529
I don't know what the backend model was because, of course,
589
00:28:24.549 --> 00:28:26.769
Visual Studio, you can jump around, but I don't know.
590
00:28:26.829 --> 00:28:29.130
But yeah, it was quite happy to yell at me
591
00:28:29.170 --> 00:28:29.720
and laugh at me.
592
00:28:30.019 --> 00:28:30.619
That's pretty good.
593
00:28:30.660 --> 00:28:32.880
When the tool says the word, it is trying to
594
00:28:32.920 --> 00:28:35.619
detect irony. That's just ironic, actually.
595
00:28:36.160 --> 00:28:36.400
Right.
596
00:28:36.839 --> 00:28:37.039
Yeah.
597
00:28:37.259 --> 00:28:40.519
It's very recursive. Arnon, thank you so much for your comment.
598
00:28:40.539 --> 00:28:41.680
And a copy of Music to Code By is on
599
00:28:41.720 --> 00:28:42.819
its way to you. And if you'd like a copy
600
00:28:42.839 --> 00:28:44.119
of Music to Code By, write a comment on the
601
00:28:44.140 --> 00:28:47.180
website at. netrocks. com or on the Facebooks we publish every
602
00:28:47.200 --> 00:28:48.819
show there. And if you comment there and I read
603
00:28:48.839 --> 00:28:50.000
it on the show, we'll send you a copy of
604
00:28:50.019 --> 00:28:50.579
Music to Code By.
605
00:28:50.660 --> 00:28:52.349
Or if you'd just rather buy Music to Code By,
606
00:28:52.380 --> 00:28:55.829
go to musictocodeby.net. You can get the tracks in MP3, WAV,
607
00:28:56.069 --> 00:28:59.880
and FLAC formats. Well, before we introduce Michael... Let's take
608
00:28:59.900 --> 00:29:06.789
a little break for these very important messages. And we're back..
609
00:29:07.329 --> 00:29:10.190
NET Rocks. I'm Carl Franklin. That's Richard Campbell. Hey. And
610
00:29:10.210 --> 00:29:13.710
that's Michael Howard. Let me introduce him formally. Your bio
611
00:29:13.750 --> 00:29:17.549
has changed a little bit. Michael Howard's been at Microsoft
612
00:29:17.809 --> 00:29:18.990
since 1992.
613
00:29:18.990 --> 00:29:19.230
Wow.
614
00:29:19.910 --> 00:29:24.789
Always in some form of security, IIS, SDL, the founder
615
00:29:24.809 --> 00:29:25.329
of SDL?
616
00:29:25.490 --> 00:29:27.069
Well, he's one of the guys that worked on the very,
617
00:29:27.109 --> 00:29:29.839
very earliest versions. It was like two or three of us, yeah,
618
00:29:29.859 --> 00:29:30.380
back in the day.
619
00:29:30.400 --> 00:29:30.940
Awesome.
620
00:29:31.000 --> 00:29:32.859
And that was the security lifecycle?
621
00:29:33.140 --> 00:29:37.480
Security development lifecycle, yeah. Back in the earliest, like, 2004.
622
00:29:36.759 --> 00:29:40.380
Also uh you worked in azure data on the red
623
00:29:40.420 --> 00:29:43.660
team last time we talked and now you're in post
624
00:29:43.839 --> 00:29:45.660
quantum crypto.
625
00:29:45.079 --> 00:29:51.509
Woohoo yeah baby Man, I'm happy to be here, too.
626
00:29:51.569 --> 00:29:52.130
It's a lot of fun.
627
00:29:52.279 --> 00:29:55.099
I mean, how can you have post-quantum if we haven't
628
00:29:55.119 --> 00:29:56.960
had quantum?
629
00:29:57.160 --> 00:30:01.180
Because the real attacks start post-quantum. That's the reason why.
630
00:30:01.200 --> 00:30:04.200
Yeah, you're right. I get it. You need to be ready.
631
00:30:05.059 --> 00:30:07.819
For certain things. Certain things, maybe not. But we can
632
00:30:07.859 --> 00:30:08.599
discuss that later.
633
00:30:08.880 --> 00:30:10.940
But yeah. Well, what does it mean, post-quantum crypto?
634
00:30:11.240 --> 00:30:15.980
Well, you think of things in three ways. This is
635
00:30:16.000 --> 00:30:17.799
the way we think about it at Microsoft. Anyway, I'm
636
00:30:17.839 --> 00:30:21.769
sure most of the industry does. um, data, data in transit,
637
00:30:21.789 --> 00:30:24.930
data at rest, and then cryptographic trust. So data on
638
00:30:24.950 --> 00:30:27.259
the wire, you know, stuff flying across the internet is
639
00:30:27.279 --> 00:30:30.759
probably protected by TLS today, more than likely perhaps SSH,
640
00:30:31.339 --> 00:30:34.700
but certainly TLS data at rest is encrypted most of
641
00:30:34.720 --> 00:30:37.819
the time or should be. And those encryption keys are
642
00:30:37.859 --> 00:30:41.500
wrapped with other keys, uh, key wrapping keys. And then
643
00:30:41.519 --> 00:30:44.660
you've got cryptographic trust, which is, you know, signatures, certificates,
644
00:30:45.039 --> 00:30:49.140
all that sort of good stuff. Um, The real threat
645
00:30:49.160 --> 00:30:52.170
is dead on the wire is being, you know, being
646
00:30:52.650 --> 00:30:54.589
pulloined as it flies across the wire.
647
00:30:54.609 --> 00:30:55.250
Yeah.
648
00:30:55.329 --> 00:30:57.589
And then when a quantum computer comes out in the future,
649
00:30:57.609 --> 00:31:02.890
that stuff can be broken. And the breaking aspect is
650
00:31:03.480 --> 00:31:06.599
essentially just breaking the RSA or the elliptic curve wrapping...
651
00:31:06.809 --> 00:31:10.230
that goes on and out pops the AES key that's
652
00:31:10.289 --> 00:31:12.319
used for the bulk encryption, and now you just decrypt everything.
653
00:31:13.099 --> 00:31:14.359
And in the case of data at rest, it's the
654
00:31:14.380 --> 00:31:17.319
key wrapping keys, right? They can be broken because they usually,
655
00:31:17.579 --> 00:31:21.240
for example, RSA, which can be broken with an algorithm
656
00:31:21.259 --> 00:31:23.240
called Shor's algorithm, S-H-O-R.
657
00:31:23.299 --> 00:31:23.500
Yeah.
658
00:31:24.180 --> 00:31:28.140
And it basically finds periodicity in the way those algorithms work.
659
00:31:28.160 --> 00:31:29.269
That's what it takes advantage of.
660
00:31:29.910 --> 00:31:34.309
Are our logs at risk for being pilfered by cryptos?
661
00:31:35.769 --> 00:31:38.210
Post-mortem crypto? I mean, if it contains sensitive data, which
662
00:31:38.230 --> 00:31:40.200
you shouldn't be logging sensitive data, right? No, no, no.
663
00:31:40.240 --> 00:31:45.019
But even if it wasn't containing sensitive data, is that
664
00:31:45.059 --> 00:31:47.119
something because it can go through so much data so
665
00:31:47.180 --> 00:31:48.180
fast that it could.
666
00:31:48.220 --> 00:31:50.119
I mean, if I had to prioritize stuff, I would
667
00:31:50.180 --> 00:31:51.589
focus on the actual data itself.
668
00:31:51.609 --> 00:31:54.309
Yeah, okay. So data in transit and then real data
669
00:31:54.329 --> 00:31:55.150
in your databases.
670
00:31:55.390 --> 00:31:58.789
Correct. Yeah. And then those, again, they can be snaffled.
671
00:31:59.099 --> 00:32:02.680
today and then once a quantum computer is made available and.
672
00:32:02.640 --> 00:32:04.599
That's where a lot of did you say snaffled.
673
00:32:04.519 --> 00:32:06.579
Are stolen snaffled purloined.
674
00:32:06.259 --> 00:32:08.720
Snaffled that's a good british.
675
00:32:08.299 --> 00:32:12.240
Word snaffled yeah um there's actually a real word i
676
00:32:12.240 --> 00:32:13.809
don't even know is it a real.
677
00:32:13.670 --> 00:32:15.170
Word it doesn't matter i i don't know but i
678
00:32:15.230 --> 00:32:15.650
never heard it.
679
00:32:15.650 --> 00:32:18.849
Before it is now there you go things you.
680
00:32:18.789 --> 00:32:21.789
Learn on dot numrocks all right It's all good.
681
00:32:22.109 --> 00:32:24.849
Yeah, so the risk is the asymmetric keys that are
682
00:32:24.910 --> 00:32:27.509
used to wrap the symmetric keys that do the- Because
683
00:32:27.529 --> 00:32:30.150
they're dependent on prime numbers. In the case of RSA.
684
00:32:30.369 --> 00:32:30.589
Yeah.
685
00:32:30.849 --> 00:32:33.029
But that's not the attack. The attack is the periodicity.
686
00:32:33.049 --> 00:32:35.150
There's a periodicity. If you actually look at the way
687
00:32:35.210 --> 00:32:37.559
Shor's works, not that I say, not that you should,
688
00:32:38.200 --> 00:32:41.559
it basically does a quantum fast Fourier analysis.
689
00:32:41.819 --> 00:32:42.420
Yeah.
690
00:32:42.880 --> 00:32:46.779
Shor's is actually hybrid. It's actually quantum and sort of,
691
00:32:47.329 --> 00:32:50.970
classic computing. The hard work is done by Shor's and
692
00:32:51.009 --> 00:32:53.950
then some of the less difficult work is done classically
693
00:32:53.970 --> 00:32:57.910
because it's just easier. And so the real issue is
694
00:32:57.950 --> 00:33:02.210
that those asymmetric keys, RSA, elliptic curve, Diffie-Hellman, they all
695
00:33:02.269 --> 00:33:06.200
exhibit some periodicity that can be detected by Shor's. And
696
00:33:06.220 --> 00:33:09.869
that gives you a whole bunch of possibilities that then
697
00:33:09.930 --> 00:33:12.289
classical computing can then just sort of sift through and
698
00:33:12.509 --> 00:33:14.309
find out which ones are the actual keys. Right.
699
00:33:14.349 --> 00:33:16.710
So it narrows the scope of the testing needed.
700
00:33:16.930 --> 00:33:20.519
Correct. Yeah. And to your point before, rather than, you know,
701
00:33:20.559 --> 00:33:23.380
squillions of ages of the universe, it could be hours
702
00:33:23.599 --> 00:33:24.559
or days. Yeah.
703
00:33:24.640 --> 00:33:25.019
Right.
704
00:33:25.059 --> 00:33:27.819
You know, it's, it's, it's a real thing. And, um,
705
00:33:28.759 --> 00:33:31.759
you know, developers have a big part to play in,
706
00:33:31.920 --> 00:33:35.019
in this. It's not just, you know, flip some switch
707
00:33:35.059 --> 00:33:39.059
and everything's golden. Um, There's a lot more to it
708
00:33:39.079 --> 00:33:41.140
that developers need to understand as well.
709
00:33:42.039 --> 00:33:48.079
So everything I've barely hung on understanding about quantum is
710
00:33:48.119 --> 00:33:53.829
that we're all screwed, right? And because of the way
711
00:33:53.880 --> 00:33:59.710
that TLS works and SSL and all that stuff, it
712
00:33:59.990 --> 00:34:02.750
dramatically has to change, doesn't it? If we're going to
713
00:34:02.769 --> 00:34:10.369
be less susceptible to quantum interference but you're i think
714
00:34:10.449 --> 00:34:12.449
what you're saying is that there are ways that we
715
00:34:12.489 --> 00:34:16.389
can do that now and that's what you know post-quantum
716
00:34:16.429 --> 00:34:20.909
crypto is all about is trying to use cryptographic methods
717
00:34:21.050 --> 00:34:24.610
now that will survive the quantum onslaught is that what
718
00:34:24.650 --> 00:34:27.849
you're basically up against yeah one.
719
00:34:27.789 --> 00:34:29.679
Of the beauties of tls by the way i can't
720
00:34:29.699 --> 00:34:32.300
believe you said ssl like wash your mouth out.
721
00:34:32.989 --> 00:34:38.010
You know, some of us were around in the 90s.
722
00:34:38.170 --> 00:34:42.199
So was I. And so they don't use those words, TLS.
723
00:34:42.619 --> 00:34:47.559
I know. Anyway, I'll just pretend you didn't say that. Yeah,
724
00:34:49.260 --> 00:34:51.300
so TLS, one of the beauties of TLS is that
725
00:34:51.380 --> 00:34:53.880
it's very agile, right? You can change the way it works,
726
00:34:53.920 --> 00:34:57.719
the ciphers that are used, the cryptographic primitives that are used.
727
00:34:57.840 --> 00:35:00.500
And you're talking about TLS 1.0.
728
00:35:00.500 --> 00:35:02.570
Correct. So TLS 1.2 should be using.
729
00:35:02.860 --> 00:35:03.110
Yeah.
730
00:35:03.139 --> 00:35:05.090
So actually that's a really important point. So TLS 1.2
731
00:35:05.090 --> 00:35:08.610
and prior, so TLS 1.0 and 1.1 are deprecated anyway,
732
00:35:08.650 --> 00:35:12.070
so don't use them. TLS 1.2 does its cipher suite
733
00:35:12.130 --> 00:35:15.659
and its key establishments and authentication all as one string
734
00:35:16.239 --> 00:35:18.159
called the cipher suite. It looks like someone sneezed on
735
00:35:18.199 --> 00:35:20.760
the screen basically. It's a list of all the algorithms
736
00:35:20.780 --> 00:35:23.820
that are used for all of those things. TLS 1.3
737
00:35:23.820 --> 00:35:28.449
is different. it broke apart things like the key establishment
738
00:35:28.849 --> 00:35:31.809
from the bulk encryption and the bulk tamper detection. They're
739
00:35:31.849 --> 00:35:32.949
completely broken apart.
740
00:35:33.050 --> 00:35:33.269
Yeah.
741
00:35:33.510 --> 00:35:36.880
So you can negotiate the two separately. That's the big
742
00:35:36.909 --> 00:35:40.539
difference in TLS 1.3. So the key establishment is a
743
00:35:40.579 --> 00:35:44.079
thing called a group. And the reason why it's called
744
00:35:44.119 --> 00:35:47.840
a group is because mathematicians got to hang on this.
745
00:35:47.880 --> 00:35:51.050
And they said, you know, all these things are mathematical groups.
746
00:35:51.780 --> 00:35:56.659
So we'll call them groups. Terrible name. But for the
747
00:35:56.679 --> 00:36:00.639
key establishment, that's where you set the algorithm or algorithms
748
00:36:00.699 --> 00:36:03.260
in some cases. And then after that, separately, is how
749
00:36:03.320 --> 00:36:05.579
you do bulk protection of the data on the wire.
750
00:36:05.599 --> 00:36:08.960
So TLS 1.3 broke those two apart. So it is
751
00:36:09.000 --> 00:36:12.239
completely not compatible with TLS 1.2. And TLS 1.2 will
752
00:36:12.300 --> 00:36:15.360
never be post-quantum. I mean, it's just software. I mean, essentially,
753
00:36:15.389 --> 00:36:17.110
I suppose it could make it post-quantum.
754
00:36:17.590 --> 00:36:18.510
Yeah, but why would you?
755
00:36:18.550 --> 00:36:21.610
But the interoperability... well, the interoperability story would be horrendous.
756
00:36:21.650 --> 00:36:23.070
Like no one would do it.
757
00:36:23.389 --> 00:36:25.750
But it also seems unnecessary too, right? Because I set
758
00:36:25.769 --> 00:36:28.489
the TLS 1.3 with a dropdown in Azure.
759
00:36:28.789 --> 00:36:31.739
Right. But the thing is, here's the issue. And this
760
00:36:31.800 --> 00:36:34.320
is one thing that we're having to work on for
761
00:36:34.360 --> 00:36:37.139
products like Front Door, for example, is you will be
762
00:36:37.159 --> 00:36:41.860
able to control the group, not just the bulk cryptography
763
00:36:41.909 --> 00:36:42.360
that's used.
764
00:36:42.570 --> 00:36:42.829
Okay.
765
00:36:42.889 --> 00:36:44.789
And that's where, and the group is where the post-quantum
766
00:36:44.809 --> 00:36:50.610
part comes in. For the most part, symmetric stuff AES-256, SHA-384,
767
00:36:50.650 --> 00:36:52.889
and so on, which are the baselines, are fine. There's
768
00:36:52.909 --> 00:36:55.679
another algorithm there called Grover's, which is an attack against
769
00:36:55.719 --> 00:36:59.300
symmetric algorithms. And it essentially cuts the number of bits
770
00:36:59.360 --> 00:37:02.300
in the key in half. So if you have an
771
00:37:02.380 --> 00:37:06.900
AES-256 in a quantum world, that's the same as AES-128. Interesting.
772
00:37:06.920 --> 00:37:07.420
Which is fine.
773
00:37:07.800 --> 00:37:11.150
So you must use AES-256 and SHA-384 as the minimum
774
00:37:11.309 --> 00:37:14.110
as well. They're kind of okay.
775
00:37:14.250 --> 00:37:14.650
They're fine.
776
00:37:14.849 --> 00:37:20.170
The problem is the asymmetric stuff. Right. Yeah. Elliptic curve, RSA, Diffie-Hellman.
777
00:37:20.769 --> 00:37:22.309
That's where the problem is. Now, the nice thing in
778
00:37:22.510 --> 00:37:26.110
TLS 1.3 is that's defined in a group, and that's
779
00:37:26.159 --> 00:37:32.119
negotiated separately from the bulk cryptography. And that's where the
780
00:37:32.159 --> 00:37:35.059
hybrid algorithms come into play. And the reason why they're
781
00:37:35.079 --> 00:37:38.199
called hybrid is you use two together. You use elliptic
782
00:37:38.239 --> 00:37:44.679
curve and MLChem. So MLChem is the quantum resilient algorithm.
783
00:37:44.880 --> 00:37:48.960
Elliptic curve is classic. you build up keys in both,
784
00:37:49.000 --> 00:37:50.920
you smush them together, pass it through a hash, and
785
00:37:50.940 --> 00:37:53.539
then you derive the session keys after that. So they're
786
00:37:53.559 --> 00:37:54.239
both used together.
787
00:37:54.440 --> 00:37:57.159
So that would have to be implemented both at the
788
00:37:57.199 --> 00:37:59.360
browser level and at the server level, right?
789
00:37:59.480 --> 00:38:02.920
Yeah, everywhere. I mean, you say browser, but client. I mean,
790
00:38:02.940 --> 00:38:04.079
I just mean clients in general.
791
00:38:04.099 --> 00:38:04.860
Yeah, clients, sure.
792
00:38:04.940 --> 00:38:08.039
And in fact, you bring up a very important point there, Carl,
793
00:38:08.500 --> 00:38:12.159
and that is that all modern browsers support hybrid TLS 1.3.
794
00:38:12.159 --> 00:38:12.679
Yeah.
795
00:38:13.639 --> 00:38:17.800
So the, I mean, even the humble Xbox has hybrid.
796
00:38:19.159 --> 00:38:22.679
I've tried all sorts of, you know, iOS, Android, Windows, Mac, Linux,
797
00:38:23.349 --> 00:38:25.230
and all the common browsers support.
798
00:38:25.730 --> 00:38:29.570
So anything, anything that uses it like curl or any,
799
00:38:29.710 --> 00:38:32.670
any little command line tool, all, all those things have
800
00:38:32.690 --> 00:38:33.230
to support it.
801
00:38:33.329 --> 00:38:36.570
Correct. Correct. So SSH, both client server supports it as
802
00:38:36.610 --> 00:38:40.699
a version 10, I think maybe 9.9 or 10. supports
803
00:38:40.960 --> 00:38:43.880
um ml chem so the the important part there in
804
00:38:43.900 --> 00:38:46.139
the in ml chem is the letter l in that
805
00:38:46.380 --> 00:38:51.199
there's lattice and the two major algorithms that are post
806
00:38:51.219 --> 00:38:53.699
quantum resilient there's actually a small number but the two
807
00:38:53.800 --> 00:38:56.929
major ones ml chem and ml dsa the l is
808
00:38:56.989 --> 00:39:01.769
lattice and the is that lattice construct that is quantum resilient.
809
00:39:01.610 --> 00:39:04.150
Right so when you say quantum resilient do you mean
810
00:39:04.769 --> 00:39:07.969
what you perceive as the first generation of quantum or
811
00:39:08.280 --> 00:39:10.539
all quantum going forward till the end of time?
812
00:39:10.900 --> 00:39:15.719
Nah, I mean, NIST is still going through other algorithms.
813
00:39:16.900 --> 00:39:19.659
The industry has settled, and NIST has settled on MLDSA
814
00:39:19.699 --> 00:39:23.429
and MLChem. And there's been a lot of research for
815
00:39:23.469 --> 00:39:27.130
the last 20-something years in lattices, looking at it through
816
00:39:27.150 --> 00:39:32.820
a quantum lens, and they look good. but everyone's you
817
00:39:32.840 --> 00:39:34.360
know quite happy to say let's you know let's go
818
00:39:34.380 --> 00:39:36.440
look at other algorithms as well just in case and
819
00:39:36.480 --> 00:39:40.460
in fact for no other reason than the resulting cipher
820
00:39:40.519 --> 00:39:43.469
blob is big so i'll give you an example If
821
00:39:43.510 --> 00:39:46.260
you have an elliptic curve, say an EC25519, which is
822
00:39:46.929 --> 00:39:49.519
a curve, the signature, a digital signature for that is
823
00:39:49.519 --> 00:39:52.559
64 bytes in size. It's pretty small. If you take
824
00:39:52.579 --> 00:39:57.199
an MLDSA87 certificate and you sign data with the private
825
00:39:57.239 --> 00:40:00.670
key of that, it's about 4.5K. So you imagine if
826
00:40:00.690 --> 00:40:04.369
you've got a whole series of certificates all with their signatures...
827
00:40:04.869 --> 00:40:06.110
it adds up real quick.
828
00:40:06.349 --> 00:40:07.050
Yeah.
829
00:40:07.070 --> 00:40:11.489
And you can have problems with MTUs, with people passing
830
00:40:11.530 --> 00:40:15.889
stuff on query strings, amounts of space set aside on
831
00:40:16.130 --> 00:40:21.079
disk for signatures, you know? Yeah, so it's a real issue.
832
00:40:21.119 --> 00:40:25.559
So NIST is continuing to evaluate other algorithms with an
833
00:40:25.860 --> 00:40:30.300
eye to potentially smaller signatures. So now I get.
834
00:40:30.219 --> 00:40:32.360
Why it's called Lattice because it kind of makes a
835
00:40:32.500 --> 00:40:36.980
web of data that's hard to penetrate. Is that good analysis?
836
00:40:37.420 --> 00:40:38.039
No, it's terrible.
837
00:40:38.460 --> 00:40:41.659
Terrible. It's terrible.
838
00:40:42.139 --> 00:40:45.530
I can take it. Okay, here's how lattices... I claim stupidity.
839
00:40:45.550 --> 00:40:50.909
It's all good, mate. So, the way lattices work, and
840
00:40:50.969 --> 00:40:54.469
this is a terrible description, but it's an interesting way
841
00:40:54.530 --> 00:40:55.690
of thinking about it.
842
00:40:55.730 --> 00:40:57.329
It'll be better than mine, I guarantee it.
843
00:40:57.590 --> 00:40:59.530
I may not be. I'm not a fan of analogies,
844
00:40:59.570 --> 00:41:00.769
so here's an analogy for you.
845
00:41:00.789 --> 00:41:00.969
Okay.
846
00:41:03.719 --> 00:41:06.400
Imagine a chessboard, right? Eight by eight with a knight.
847
00:41:06.699 --> 00:41:08.739
We know the knight moves either one and two or
848
00:41:08.800 --> 00:41:09.539
two and one, right?
849
00:41:09.579 --> 00:41:10.219
That's all it does.
850
00:41:10.539 --> 00:41:12.900
Yeah. If I give you an end point and I
851
00:41:12.920 --> 00:41:15.599
give you a starting point, what route does the knight
852
00:41:15.639 --> 00:41:18.920
take to get there? That's pretty straightforward to do, you know,
853
00:41:18.940 --> 00:41:21.980
because it's just eight by eight. Now, imagine if that
854
00:41:22.019 --> 00:41:25.619
was a squillion by a squillion chessboard. Right. All right.
855
00:41:25.969 --> 00:41:26.300
Got it.
856
00:41:26.320 --> 00:41:29.130
Oh, no. You know, it gets harder. Now, imagine it's
857
00:41:29.369 --> 00:41:33.460
a thousand dimensions, right? Now imagine I don't tell you
858
00:41:33.480 --> 00:41:35.429
there's one by two, it's N by M.
859
00:41:35.760 --> 00:41:36.369
Right, okay.
860
00:41:36.650 --> 00:41:38.730
Now, just to make things even more difficult, it's not
861
00:41:38.769 --> 00:41:42.349
like an air quotes square chessboard. The squares are kind
862
00:41:42.409 --> 00:41:45.369
of funky shaped. They're not quite squares. And that's a
863
00:41:45.389 --> 00:41:51.199
thing called learning with errors. So that's hard. Here's a
864
00:41:51.280 --> 00:41:55.039
point somewhere in this N dimensional space. Here's your starting point.
865
00:41:55.079 --> 00:41:58.300
How do you get there? And so essentially the N
866
00:41:58.340 --> 00:42:00.599
by M is essentially like the private key. That's one
867
00:42:00.619 --> 00:42:02.780
way of looking at it. Terrible analogy, but it's about
868
00:42:02.820 --> 00:42:04.659
as close as you can get without introducing math.
869
00:42:04.719 --> 00:42:04.980
Okay.
870
00:42:05.440 --> 00:42:05.679
Yeah.
871
00:42:05.699 --> 00:42:09.070
All right. Good. And so you don't think that quantum
872
00:42:09.110 --> 00:42:12.389
computers could ever get so good that they could just
873
00:42:12.449 --> 00:42:13.809
figure that stuff out quickly?
874
00:42:14.110 --> 00:42:17.269
You mean when you throw in some AI as well? Yeah. Yeah.
875
00:42:17.670 --> 00:42:17.920
Go on.
876
00:42:19.280 --> 00:42:22.619
But nobody ever comes up and thinks, hey, we've solved cryptography.
877
00:42:22.940 --> 00:42:25.440
You're always looking at new algorithms. You're always looking at
878
00:42:25.500 --> 00:42:30.500
new key lengths. We expect to routinely replace our algorithms.
879
00:42:30.519 --> 00:42:31.340
It's an arms race.
880
00:42:31.360 --> 00:42:33.900
Because the bad guys are fighting back.
881
00:42:34.079 --> 00:42:37.590
Which is a beautiful segue into the next topic, which
882
00:42:37.639 --> 00:42:41.489
is crypto agility. If nothing else, from a developer perspective,
883
00:42:41.590 --> 00:42:46.230
one thing that post-quantum crypto will bring to the table
884
00:42:46.690 --> 00:42:50.559
is the need for crypto agility. what happens if you
885
00:42:50.599 --> 00:42:55.070
wrap some keys in MLChem? Chem stands for key encapsulation method.
886
00:42:56.360 --> 00:42:59.269
Let's say you wrap some keys in that and it
887
00:42:59.289 --> 00:43:02.630
ends up being broken five years, 10 years from now.
888
00:43:03.090 --> 00:43:05.849
How can you update your application to use a new
889
00:43:05.889 --> 00:43:08.889
wrapping method without breaking your existing, like you can still
890
00:43:08.929 --> 00:43:11.739
read your old data, but you would write out using
891
00:43:11.780 --> 00:43:15.940
some MLChem + + or something. Right. And crypto agility
892
00:43:16.079 --> 00:43:19.719
is just, so important. It's really brought it to the
893
00:43:19.760 --> 00:43:24.260
forefront as a need, because we don't know long-term if
894
00:43:24.300 --> 00:43:27.420
these things will be successful or not. And again, to
895
00:43:27.440 --> 00:43:30.260
your point, Carl, cryptographers are very, very conservative when it
896
00:43:30.300 --> 00:43:32.340
comes to these sorts of things, and they want to
897
00:43:32.380 --> 00:43:36.179
have a big security buffer, knowing that some things will
898
00:43:36.219 --> 00:43:38.199
start to potentially creak a little bit.
899
00:43:39.630 --> 00:43:43.369
And of course, you're immediately going to the at-rest encryption problem.
900
00:43:43.409 --> 00:43:47.019
I'm always thinking TLS, and it's just we handshake an
901
00:43:47.059 --> 00:43:50.559
encrypted stream, we do our thing and then it disappears again.
902
00:43:50.599 --> 00:43:53.389
And so I don't have the, other than the, you know,
903
00:43:54.469 --> 00:43:57.090
harvest and decrypt later, I don't have to think about this.
904
00:43:57.150 --> 00:43:59.989
It's all transitory. We'll just use the newest algorithm. But
905
00:44:00.050 --> 00:44:03.809
if you've stored under an older algorithm, And now it's
906
00:44:03.849 --> 00:44:08.150
been breached. You have to decrypt, recrypt, or at least,
907
00:44:08.170 --> 00:44:10.849
you know, decrypt over time to get by that.
908
00:44:11.090 --> 00:44:13.510
You may have to increase the data size of your
909
00:44:13.570 --> 00:44:16.780
fields that take those things because it's going to take more. Yeah.
910
00:44:16.800 --> 00:44:18.500
So you've got to assume that there will be change.
911
00:44:18.639 --> 00:44:21.000
And unfortunately, a lot of people don't know how to
912
00:44:21.039 --> 00:44:24.179
build crypto agile solutions. It kind of drives me a
913
00:44:24.199 --> 00:44:25.880
bit bonkers, to be honest with you. I see, you know,
914
00:44:25.920 --> 00:44:28.159
in the press, you know, we need crypto agility. I've
915
00:44:28.199 --> 00:44:30.280
got to do crypto agility. Yeah. hey, crypto agility is
916
00:44:30.320 --> 00:44:32.500
really important. Are you guys doing crypto agility?
917
00:44:32.940 --> 00:44:35.300
Because it comes in a squirt bottle and you just
918
00:44:35.340 --> 00:44:37.159
spray it on all your devs and you'll be good.
919
00:44:37.360 --> 00:44:39.130
I know, but no one says how to do it.
920
00:44:41.150 --> 00:44:44.110
To me at Microsoft, there's two canonical examples of crypto agility.
921
00:44:44.210 --> 00:44:47.050
One is as a SQL DB or SQL server with
922
00:44:47.110 --> 00:44:50.889
always encrypted. And then the other one is the open
923
00:44:50.989 --> 00:44:54.730
office XML file format, which you use to encrypt documents
924
00:44:54.769 --> 00:44:57.449
in office. So the way it works in as a
925
00:44:57.469 --> 00:45:00.010
SQL DB, which to me is a beautiful and simple
926
00:45:00.050 --> 00:45:01.829
way of doing it. It's also very, very fast. If
927
00:45:02.550 --> 00:45:06.610
you ever look at the ciphertext in an always encrypted cell,
928
00:45:07.409 --> 00:45:09.789
the first byte is always a one, and that's the
929
00:45:09.829 --> 00:45:15.599
version number. And that basically means AES-256 cipherblockchaining with a
930
00:45:15.619 --> 00:45:21.960
SHA-256 hash as an integrity check over the data. So
931
00:45:21.980 --> 00:45:23.699
in the future, if they decide to upgrade it to
932
00:45:23.719 --> 00:45:26.679
something else, then that could be version two. So the
933
00:45:26.719 --> 00:45:28.960
first bike would be a two and they could always
934
00:45:29.079 --> 00:45:31.139
read back and say, okay, that's version one. We need
935
00:45:31.159 --> 00:45:34.460
this particular set of cipher primitives. Let's read as decrypted
936
00:45:34.500 --> 00:45:37.159
with these primitives. When they write it back, they would
937
00:45:37.179 --> 00:45:39.239
write it back as a, whatever the latest number was,
938
00:45:39.260 --> 00:45:41.460
which we version two, and it will be the, whatever
939
00:45:41.480 --> 00:45:43.179
the new, the new cipher suites is. So you can
940
00:45:43.199 --> 00:45:45.369
always read the old data and you would write back
941
00:45:45.630 --> 00:45:48.489
using the new version. And the way office does it
942
00:45:48.889 --> 00:45:51.550
is it's an XML file. There's an XML file header.
943
00:45:52.139 --> 00:45:55.639
And it contains all the cryptographic primitives, like AES, it's
944
00:45:55.659 --> 00:46:01.769
cipher blockchaining, here's the initialization vector, here's the password, the
945
00:46:01.789 --> 00:46:06.789
key derivation count, here's the key derivation algorithm, and lots
946
00:46:06.829 --> 00:46:09.829
of other metadata. So you can actually build the cipher
947
00:46:10.409 --> 00:46:14.929
collection completely dynamically, which is really, really nice.
948
00:46:16.619 --> 00:46:20.079
What network hardware will have to change in the, yes.
949
00:46:20.559 --> 00:46:22.900
I mean, we won't, we'll be able to go to
950
00:46:22.960 --> 00:46:25.179
Best Buy or whatever it is you have in the
951
00:46:25.280 --> 00:46:29.150
UK and buy an off the shelf, you know, router
952
00:46:29.230 --> 00:46:33.230
that is crypto happy. Oh, I mean, in theory, I
953
00:46:33.250 --> 00:46:34.710
think a lot of quantum happy rather.
954
00:46:34.730 --> 00:46:37.150
I mean, unless they're doing some kind of inspection, if
955
00:46:37.170 --> 00:46:39.050
they're just like passing data on, there should be no
956
00:46:39.130 --> 00:46:40.909
need for it, right? They're not decrypting stuff, but if
957
00:46:40.929 --> 00:46:44.019
they are decrypting stuff, then yeah, they're going to have
958
00:46:44.039 --> 00:46:46.239
to have access to these algorithms. If you're doing, you know,
959
00:46:46.460 --> 00:46:48.320
TLS termination, then yeah, for sure.
960
00:46:48.889 --> 00:46:50.769
The other that's not something you'll have in your home
961
00:46:50.969 --> 00:46:53.329
i did that stuff in racks of computers for companies
962
00:46:53.389 --> 00:46:54.070
but ah but.
963
00:46:54.010 --> 00:46:56.090
There's a fly in the ointment there's a huge fly
964
00:46:56.110 --> 00:46:57.989
in the ointment though and that is your laptop and
965
00:46:58.010 --> 00:47:00.679
your computer with tpms and trusted boots and that sort
966
00:47:00.699 --> 00:47:03.900
of stuff right right now those keys are probably rsa
967
00:47:03.920 --> 00:47:06.340
and well they are rsa or elliptic curve.
968
00:47:06.019 --> 00:47:08.139
They are and we're just going through the secure boot
969
00:47:08.179 --> 00:47:10.119
crisis thanks very much right.
970
00:47:09.900 --> 00:47:12.699
So that will all get that will all get busted
971
00:47:13.099 --> 00:47:15.980
and um you know so the hardware industry out there
972
00:47:16.429 --> 00:47:17.909
We're being mean here, Michael.
973
00:47:17.929 --> 00:47:20.139
Richard's squinting, but I think you've got to look at
974
00:47:20.179 --> 00:47:22.320
it like this. Hey, you've got to buy a new laptop.
975
00:47:22.960 --> 00:47:23.900
That's not a bad thing.
976
00:47:24.400 --> 00:47:26.800
But it's also like we're fixing keys all the time.
977
00:47:27.260 --> 00:47:30.800
These are BIOS updates. This will come in firmware.
978
00:47:31.000 --> 00:47:32.619
You think? There'll be new drivers.
979
00:47:34.179 --> 00:47:37.650
And they might be slower than a hardware-dedicated version of it,
980
00:47:37.760 --> 00:47:41.139
but I just don't feel– a lot of the stuff
981
00:47:41.159 --> 00:47:43.579
you're describing here, Michael, to me sounds like configuration settings
982
00:47:43.639 --> 00:47:46.610
in Azure. you've already done the work in the browser. Like,
983
00:47:46.619 --> 00:47:49.170
as long as I haven't done anything stupid in code,
984
00:47:49.630 --> 00:47:50.889
I don't think I have to do anything as a
985
00:47:50.929 --> 00:47:51.489
web dev.
986
00:47:51.849 --> 00:47:53.110
That's correct. 100% correct.
987
00:47:53.349 --> 00:47:54.809
I just got to make sure that my admins have
988
00:47:54.849 --> 00:47:55.530
set stuff right.
989
00:47:55.590 --> 00:47:57.449
Well, if you're using IIS, you're going to have to
990
00:47:57.510 --> 00:47:59.630
make sure you're in the latest version that supports it.
991
00:47:59.690 --> 00:48:00.730
But in Azure.
992
00:48:01.150 --> 00:48:04.050
Well, http.sys... So I actually wrote a blog post on
993
00:48:04.070 --> 00:48:08.929
this because about six-ish weeks ago, we released a version
994
00:48:08.949 --> 00:48:12.170
of S Channel, which is the Windows TLS stack that
995
00:48:12.190 --> 00:48:19.449
supports TLS 1.3 hybrid. And I wrote a dumb ASP.NET application,
996
00:48:19.469 --> 00:48:21.050
you know, dumber than a bucket of rocks just to
997
00:48:21.070 --> 00:48:25.340
keep it really, really simple and did no configuration whatsoever
998
00:48:25.380 --> 00:48:27.760
in the code. And that's a really important point. Like,
999
00:48:27.800 --> 00:48:31.099
you know, thou shalt not do any TLS configuration in code,
1000
00:48:31.159 --> 00:48:33.280
like leave it to the OS or to some configuration
1001
00:48:33.320 --> 00:48:36.659
somewhere else, definitely not in code. And yeah, I just
1002
00:48:36.699 --> 00:48:39.280
turned on that. I wanted X35519 MLChem768 in priority zero.
1003
00:48:43.219 --> 00:48:47.010
in the Cypher suite and group order. And I ran
1004
00:48:47.050 --> 00:48:49.949
this application and I connected it, connected using a browser
1005
00:48:50.010 --> 00:48:51.630
and I was living in the future.
1006
00:48:52.570 --> 00:48:52.829
Nice.
1007
00:48:53.090 --> 00:48:55.650
Michael, how long do we have before we need to
1008
00:48:56.329 --> 00:48:57.789
configure things correctly?
1009
00:48:58.010 --> 00:49:01.230
How long do we have? I mean, I mean, it
1010
00:49:01.269 --> 00:49:05.449
depends on risk. I was talking to a large retailer.
1011
00:49:06.309 --> 00:49:07.719
You know who they are, but I can't say who
1012
00:49:07.739 --> 00:49:07.969
they are.
1013
00:49:07.989 --> 00:49:08.340
Perfect.
1014
00:49:08.710 --> 00:49:09.610
And they're not concerned.
1015
00:49:09.650 --> 00:49:10.880
The one I bought my computer from?
1016
00:49:10.889 --> 00:49:15.619
They're not concerned about right now anyway with their devices
1017
00:49:15.739 --> 00:49:18.389
that they use for shop floor inventory management, right? Because
1018
00:49:18.429 --> 00:49:21.980
it's just shop floor inventory management. It's not sensitive data.
1019
00:49:22.519 --> 00:49:26.079
So their Android devices that they're using will never support post-quantum.
1020
00:49:26.239 --> 00:49:29.650
They're okay with that. Now, their corporate systems that run
1021
00:49:29.989 --> 00:49:32.969
HR and payroll and all that sort of stuff, yes,
1022
00:49:33.010 --> 00:49:35.710
they do care. So how long do we have? I mean,
1023
00:49:35.730 --> 00:49:38.989
the clock started now for certain types of data. Depends
1024
00:49:39.050 --> 00:49:42.010
on the data. If you've got really sensitive data or
1025
00:49:42.070 --> 00:49:46.719
data that must be secret for a long time, healthcare information,
1026
00:49:46.820 --> 00:49:51.820
military secrets, intelligence, financial records in some cases, perhaps. I
1027
00:49:51.840 --> 00:49:56.079
don't know. I'm not a regulatory person. You know, they
1028
00:49:56.119 --> 00:50:00.869
have a time that they must maintain their secrecy. And
1029
00:50:00.909 --> 00:50:03.079
that clock's already started. Because if we take a 2029,
1030
00:50:03.079 --> 00:50:06.469
2030 timeframe, that's only four years. It's not even four
1031
00:50:06.510 --> 00:50:07.039
years away. Hmm.
1032
00:50:07.969 --> 00:50:10.400
On the screen behind you, a sentence came up a
1033
00:50:10.420 --> 00:50:14.389
little while ago. There's no such thing as low-risk data.
1034
00:50:14.929 --> 00:50:17.630
But apparently this large retailer seems to think there is.
1035
00:50:17.829 --> 00:50:20.420
I think it said no low-risk secrets.
1036
00:50:21.150 --> 00:50:23.010
Oh, low-risk secrets. That's right. Yeah.
1037
00:50:23.050 --> 00:50:24.610
Yeah. Low-risk secrets.
1038
00:50:25.070 --> 00:50:25.780
Secret is secret.
1039
00:50:25.800 --> 00:50:28.880
So, if it's a secret by default, it's by definition
1040
00:50:28.940 --> 00:50:29.219
a risk.
1041
00:50:29.559 --> 00:50:32.420
Well, a small, air quotes, small secret can lead to
1042
00:50:32.480 --> 00:50:36.440
access to bigger secrets. Like a low credential, for example,
1043
00:50:36.480 --> 00:50:37.860
it can lead to something like a key.
1044
00:50:38.320 --> 00:50:38.610
Sure.
1045
00:50:38.730 --> 00:50:38.929
Yeah.
1046
00:50:38.949 --> 00:50:42.670
The old classic, I got your Wi-Fi password from your
1047
00:50:42.750 --> 00:50:45.010
light bulb because you thought, well, it's just a light bulb.
1048
00:50:45.030 --> 00:50:46.289
What are you going to do to me? Right.
1049
00:50:46.530 --> 00:50:48.610
But the fact that I got chain attack, once I
1050
00:50:48.630 --> 00:50:50.269
got into the wifi, there was a whole lot of
1051
00:50:50.309 --> 00:50:51.219
other things that were there.
1052
00:50:51.280 --> 00:50:53.599
Yeah. And that's why I put all my IOT stuff
1053
00:50:53.619 --> 00:50:56.400
on his own virtual network is our own isolated.
1054
00:50:56.460 --> 00:50:57.619
Oh, you're darn right. You do.
1055
00:50:57.699 --> 00:50:58.739
Absolutely. Yeah.
1056
00:50:58.920 --> 00:50:59.099
Yeah.
1057
00:50:59.199 --> 00:51:02.139
But, uh, at the same time, you know, it's still,
1058
00:51:02.219 --> 00:51:05.219
I'm still sorting through what do I have to code
1059
00:51:05.360 --> 00:51:09.650
as a dev versus what I have to, uh, you know,
1060
00:51:09.710 --> 00:51:12.849
what's going to come to me, uh, just by making
1061
00:51:12.909 --> 00:51:15.869
sure we're using the latest bits. I love your info
1062
00:51:15.929 --> 00:51:18.570
on always encrypted. It's like, hey, now I want to
1063
00:51:18.590 --> 00:51:20.510
go talk to my DBA. And it's like, we're up
1064
00:51:20.590 --> 00:51:22.690
on this version, right? Because we have all this encrypted
1065
00:51:22.730 --> 00:51:25.550
and REST stuff, and you don't want a crisis. So
1066
00:51:25.570 --> 00:51:30.050
if you're already running always encrypted in SQL, then we
1067
00:51:30.070 --> 00:51:33.469
should be good. When the new algorithms are needed, they'll work.
1068
00:51:33.989 --> 00:51:36.630
The big issue, and this is one thing that a
1069
00:51:36.690 --> 00:51:38.530
lot of products at Microsoft are having to deal with,
1070
00:51:38.710 --> 00:51:41.750
is the symmetric stuff's fine. It's the key wrapping that
1071
00:51:41.769 --> 00:51:44.010
has to change. The beauty of it, though, is it's
1072
00:51:44.030 --> 00:51:46.969
just the key wrapping. So if you have a 256-bit
1073
00:51:47.369 --> 00:51:51.110
AES key, you just decrypt it or unwrap it using RSA,
1074
00:51:51.150 --> 00:51:56.159
for example, and then you rewrap it using AES-KW. which
1075
00:51:56.360 --> 00:51:59.349
managed HSM in Azure, and now Key Vault, actually, Key
1076
00:51:59.369 --> 00:52:03.880
Vault Premium in public preview, supports AESKW key wrapping, which
1077
00:52:03.940 --> 00:52:04.860
is post-quantum resilient.
1078
00:52:05.139 --> 00:52:06.519
Yeah, go ahead.
1079
00:52:06.739 --> 00:52:09.619
So there's two issues that I see developers need to really,
1080
00:52:09.639 --> 00:52:12.800
really think about. The number one is please don't put
1081
00:52:12.900 --> 00:52:15.019
any TLS anything in your code.
1082
00:52:15.119 --> 00:52:16.619
Yeah, it'll hurt you later.
1083
00:52:16.860 --> 00:52:20.599
Don't restrict protocol version. Don't restrict cipher suites. Don't do
1084
00:52:20.739 --> 00:52:25.219
any of that. Just let it be configured completely outside
1085
00:52:25.260 --> 00:52:29.139
of the application. That's number one. Number two is this
1086
00:52:29.179 --> 00:52:35.289
whole crypto agility thing. If you've got crypto code with
1087
00:52:35.329 --> 00:52:37.570
the algorithms hard-coded in the code.
1088
00:52:37.590 --> 00:52:38.230
You're in trouble.
1089
00:52:38.909 --> 00:52:42.659
And you're encrypting squeaky bytes of data... You know, you've
1090
00:52:42.679 --> 00:52:44.280
got to update your code and probably can't read the
1091
00:52:44.360 --> 00:52:45.840
old data. So now you've got, you know, it's just
1092
00:52:45.900 --> 00:52:48.170
a mess. And that's where the whole crypto agility comes in.
1093
00:52:48.199 --> 00:52:52.179
And honestly, if you haven't got crypto agility in place,
1094
00:52:52.199 --> 00:52:57.179
there are patterns you can use to wrap existing non-crypto,
1095
00:52:57.309 --> 00:53:01.210
crypto agile blobs into like some sort of crypto agile
1096
00:53:01.289 --> 00:53:02.949
envelope that contains all the metadata.
1097
00:53:03.150 --> 00:53:06.670
So Azure's really good about letting me know when I
1098
00:53:06.710 --> 00:53:09.989
need to move off of some version of something and
1099
00:53:10.070 --> 00:53:13.119
onto something else because it's being deprecated. Do you think
1100
00:53:13.159 --> 00:53:15.900
that sometime in the future, we're going to get an
1101
00:53:15.980 --> 00:53:18.800
Azure thing when we log into the portal that says, hey,
1102
00:53:19.519 --> 00:53:23.480
you need to upgrade your whatever it is to be
1103
00:53:23.599 --> 00:53:28.110
quantum happy. You think that's going to happen? Like, should
1104
00:53:28.119 --> 00:53:30.219
I just leave it up to Azure to warn me
1105
00:53:30.260 --> 00:53:33.130
about things like that? Or is there stuff that I
1106
00:53:33.170 --> 00:53:33.869
need to do now?
1107
00:53:34.329 --> 00:53:36.650
I think it depends. If you look at the shared
1108
00:53:36.690 --> 00:53:40.969
responsibility model, that's where it really becomes important. Like if
1109
00:53:41.010 --> 00:53:43.300
you've got a platform managed key to encrypt data, then
1110
00:53:43.320 --> 00:53:45.139
we're going to take care of that, right? Because a
1111
00:53:45.159 --> 00:53:48.079
platform managed key. But if you've got a customer managed key,
1112
00:53:48.099 --> 00:53:52.340
which is basically a key wrapping key, then they'll probably
1113
00:53:52.360 --> 00:53:54.699
look at, I can't predict the future, but my guess,
1114
00:53:54.860 --> 00:53:59.070
just my guess, Is that there will be notifications to say, hey,
1115
00:53:59.300 --> 00:54:03.360
you know, we've now got the ability in Azure, blah, blah, blah,
1116
00:54:03.980 --> 00:54:08.099
to wrap your encryption keys in quantum resilient keys. Would
1117
00:54:08.119 --> 00:54:11.239
you like to do this? Yeah. And click here. Yeah.
1118
00:54:11.360 --> 00:54:14.599
And the consequence is going to be very likely that
1119
00:54:14.659 --> 00:54:17.539
the data streams are going to get larger because the
1120
00:54:18.400 --> 00:54:21.389
quantum resilient keys are bigger. But I don't know what
1121
00:54:21.429 --> 00:54:22.570
other impacts I'm going to see.
1122
00:54:22.670 --> 00:54:24.670
No, you shouldn't see it. No, because the only thing
1123
00:54:24.690 --> 00:54:27.409
you're really changing is the key wrapping. Right. Which is,
1124
00:54:27.929 --> 00:54:29.219
so if you've got a 256-bit AES key, you're going
1125
00:54:29.239 --> 00:54:35.849
to wrap it in AES-KW. And in fact, it'll probably
1126
00:54:35.869 --> 00:54:38.099
be smaller than RSA, to be honest with you. But
1127
00:54:38.119 --> 00:54:39.880
if you wrap it in MLChem, it will be bigger.
1128
00:54:39.900 --> 00:54:40.360
Right.
1129
00:54:40.380 --> 00:54:41.739
Yeah, but it's just the key.
1130
00:54:41.940 --> 00:54:42.559
It's just the key.
1131
00:54:42.699 --> 00:54:43.719
Yeah, the data doesn't change.
1132
00:54:43.780 --> 00:54:46.340
Am I even choosing that or I'm just configuring to
1133
00:54:46.400 --> 00:54:48.269
allow this and it'll optimize itself?
1134
00:54:49.110 --> 00:54:52.250
No, what do you mean? When do I have to
1135
00:54:52.289 --> 00:54:57.199
make a decision about this, about the rewrap? Well, first
1136
00:54:57.239 --> 00:54:59.679
of all, the nice thing is it's very low friction. Right. Very,
1137
00:54:59.739 --> 00:55:02.500
very low friction. Like it's microseconds to do the work.
1138
00:55:02.940 --> 00:55:06.550
You're not decrypting and re-encrypting petabytes of data.
1139
00:55:07.070 --> 00:55:07.619
Right.
1140
00:55:07.949 --> 00:55:11.650
So my guess is personally, as soon as it becomes available,
1141
00:55:11.829 --> 00:55:15.550
I would just opt in and just re-wrap your keys.
1142
00:55:15.829 --> 00:55:18.030
So I'm going to wait for your blog post and
1143
00:55:18.070 --> 00:55:19.690
then I'm just going to switch this stuff on.
1144
00:55:19.809 --> 00:55:21.489
No, we'll push it through Azure Update.
1145
00:55:21.630 --> 00:55:21.750
Okay.
1146
00:55:21.909 --> 00:55:23.869
I guess it'll be through the Azure Updates website.
1147
00:55:24.010 --> 00:55:24.170
Yeah.
1148
00:55:24.190 --> 00:55:24.820
Yeah. Yeah.
1149
00:55:24.860 --> 00:55:27.659
Good. And is this imminent like in the next year?
1150
00:55:27.679 --> 00:55:27.760
Yeah.
1151
00:55:28.239 --> 00:55:28.400
Wow.
1152
00:55:28.440 --> 00:55:31.360
It'll depend on the service. Yeah. So, so, so I
1153
00:55:31.360 --> 00:55:33.639
really want to point something out here is that, you know,
1154
00:55:33.659 --> 00:55:36.000
this post-quantum stuff is very layered, right? So the very
1155
00:55:36.039 --> 00:55:37.619
bottom of the layer, you've got the algorithms. Well, that
1156
00:55:37.639 --> 00:55:39.280
stuff's been in place in windows for.
1157
00:55:39.300 --> 00:55:39.900
For ages.
1158
00:55:40.219 --> 00:55:43.389
Um, we have called sim crypt available in windows, Linux
1159
00:55:43.429 --> 00:55:47.489
and Mac hand optimized C code. Absolutely beautiful to read.
1160
00:55:47.550 --> 00:55:50.670
It's so well written. Honestly, it really is. Then above that,
1161
00:55:50.730 --> 00:55:55.210
you've got, um, say TLS 1.3 with hybrid, right? You
1162
00:55:55.269 --> 00:55:57.710
open those floodgates because now people can use that stack.
1163
00:55:58.530 --> 00:56:00.429
So basically on windows is to use the new S
1164
00:56:00.449 --> 00:56:02.489
channel stack. And in the case of Linux use open
1165
00:56:02.590 --> 00:56:05.690
SSL 3.5, um, which has ML chem built into it.
1166
00:56:05.730 --> 00:56:08.690
So you've got those two options are now available to you. Um,
1167
00:56:08.889 --> 00:56:10.789
so that's, that's the data in transit taken care of.
1168
00:56:11.309 --> 00:56:13.489
And then the last one, which is incredibly important is
1169
00:56:13.510 --> 00:56:17.639
the key wrapping. And we now have that in, in Azure.
1170
00:56:17.679 --> 00:56:22.420
So managed HSM has had a key wrapping since day one. And, um,
1171
00:56:22.969 --> 00:56:25.369
as your Key Vault now has it, ASKW. So what's
1172
00:56:25.389 --> 00:56:27.369
going to happen is that's going to open these floodgates
1173
00:56:28.090 --> 00:56:34.119
and there'll be a Cambrian explosion of services coming online
1174
00:56:34.179 --> 00:56:37.460
right as they adopt. And look, it won't happen like overnight,
1175
00:56:37.639 --> 00:56:40.079
because everyone's going to do testing, make sure it works,
1176
00:56:40.159 --> 00:56:43.010
make sure it fails correctly and that sort of stuff.
1177
00:56:43.550 --> 00:56:46.869
But Richard, to your point, next year, We'll see a
1178
00:56:46.909 --> 00:56:48.590
lot of services rolling this out.
1179
00:56:48.610 --> 00:56:49.630
Starting to switch over.
1180
00:56:49.869 --> 00:56:52.349
But I also remember when we started switching up keys,
1181
00:56:52.389 --> 00:56:54.739
when attacks got smarter and so forth, there was a
1182
00:56:54.820 --> 00:57:00.199
period where we changed a number of times different flavors of, yes, SSL,
1183
00:57:00.280 --> 00:57:04.639
and then into TLS. We are restarting this in some
1184
00:57:04.659 --> 00:57:07.809
respects with these new cryptography. I've got to think. The
1185
00:57:07.849 --> 00:57:10.710
first move we make may not stick for more than
1186
00:57:10.750 --> 00:57:12.809
a year or two before it's like, hey, now we
1187
00:57:12.829 --> 00:57:15.090
found some problems and you probably want to switch to this.
1188
00:57:15.889 --> 00:57:18.469
I just remember going through this with AAS and a
1189
00:57:18.510 --> 00:57:21.969
few others. Like, we've done this before. In some ways,
1190
00:57:21.989 --> 00:57:25.230
we've gotten really lazy because it's worked so well for
1191
00:57:25.349 --> 00:57:26.010
so long.
1192
00:57:27.150 --> 00:57:30.469
Well, actually, it's worse than that. And that is that,
1193
00:57:31.050 --> 00:57:33.699
so we've actually become really lazy because of RSA.
1194
00:57:33.969 --> 00:57:34.199
Right.
1195
00:57:34.579 --> 00:57:39.300
RSA is interesting. RSA can do all the crypto primitives. Right.
1196
00:57:39.460 --> 00:57:41.460
It can do signing, it can do encryption and all
1197
00:57:41.480 --> 00:57:44.679
that sort of stuff. Elliptic Curve and Diffie-Hellman cannot. They
1198
00:57:44.699 --> 00:57:47.460
can't do everything. And so we've been used to, like
1199
00:57:47.500 --> 00:57:49.980
you said before, Richard, I'm not trying to laugh at you,
1200
00:57:50.000 --> 00:57:51.420
but he said, you know, prime numbers. Well, that's just
1201
00:57:51.460 --> 00:57:53.860
an RSA thing. That's not an elliptic curve thing. Right.
1202
00:57:53.940 --> 00:57:55.699
Because everyone thinks of RSA.
1203
00:57:55.860 --> 00:57:56.079
Yeah.
1204
00:57:56.159 --> 00:57:58.980
And RSA is this Swiss army knife. It does absolutely everything.
1205
00:57:59.159 --> 00:57:59.380
Sure.
1206
00:57:59.480 --> 00:58:02.070
And the problem is it does absolutely everything.
1207
00:58:02.159 --> 00:58:02.909
Absolutely everything.
1208
00:58:02.969 --> 00:58:05.809
Which means we've got to change it absolutely everywhere. Yeah.
1209
00:58:06.949 --> 00:58:10.269
It went everywhere. Well, the other side of this was
1210
00:58:10.289 --> 00:58:14.269
because compute, I remember when it was expensive to do encryption,
1211
00:58:14.309 --> 00:58:18.210
where we literally had separate servers from the website for
1212
00:58:18.269 --> 00:58:21.429
doing just the encrypted pages. It's okay, well, now you're
1213
00:58:21.449 --> 00:58:23.809
going to take your shopping cart and start a payment
1214
00:58:23.849 --> 00:58:27.400
cycle that needs to be asked to sell. Now, it
1215
00:58:27.440 --> 00:58:29.480
was this big thing about moving the cart over to
1216
00:58:29.519 --> 00:58:34.000
the other much more expensive dedicated stack for completing a transaction.
1217
00:58:34.659 --> 00:58:37.980
Because encryption used to be so costly. You know, these
1218
00:58:38.019 --> 00:58:40.099
days our CPUs are so damn fast. They're sitting around
1219
00:58:40.119 --> 00:58:42.679
playing poker and smoking cigarettes waiting for something to do.
1220
00:58:43.380 --> 00:58:46.780
So sure, encrypt everything. Who cares? RSA is fast.
1221
00:58:46.969 --> 00:58:49.889
Well, the funny thing is that first of all, it's
1222
00:58:49.929 --> 00:58:51.769
just the key wrapping and unwrapping part.
1223
00:58:51.869 --> 00:58:52.670
Yeah.
1224
00:58:52.710 --> 00:58:56.050
Let's just call it key establishment because there's all different
1225
00:58:56.070 --> 00:58:56.570
ways of doing it.
1226
00:58:56.570 --> 00:58:57.550
That's really what's going on.
1227
00:58:57.630 --> 00:59:01.230
That's the expensive part because it's all asymmetric stuff. And Windows,
1228
00:59:01.369 --> 00:59:03.159
I think it still exists. There used to be a
1229
00:59:03.260 --> 00:59:09.519
registry key called modexp offload for modular exponentiation offload, which
1230
00:59:09.579 --> 00:59:14.019
is a very expensive RSA operation. And there was a
1231
00:59:14.039 --> 00:59:16.739
way you could actually set a DLL in there, a
1232
00:59:16.760 --> 00:59:19.139
name for DLL. It would actually offload that work to
1233
00:59:19.199 --> 00:59:21.420
a DLL, which was a shim into some hardware to
1234
00:59:21.440 --> 00:59:24.860
actually do the modular exponentiation work. But we don't need
1235
00:59:24.929 --> 00:59:28.190
any of that stuff anymore. You know, when I look
1236
00:59:28.210 --> 00:59:32.190
at the work that... you know, as your front door
1237
00:59:32.210 --> 00:59:33.829
have done, for example, they've done a whole bunch of
1238
00:59:33.889 --> 00:59:39.579
analysis on performance and the performance is like just a
1239
00:59:39.659 --> 00:59:42.519
couple of percent, you know, going from elliptic curve to
1240
00:59:42.539 --> 00:59:46.980
elliptic curve plus ML, ML chem. And that's because of
1241
00:59:47.619 --> 00:59:48.960
optimizations made in the library.
1242
00:59:49.260 --> 00:59:49.449
Sure.
1243
00:59:50.119 --> 00:59:52.019
I got to tell you, Michael, there's this weird dichotomy
1244
00:59:52.059 --> 00:59:55.349
going on where it's like the catastrophizing of quantum destroying
1245
00:59:55.409 --> 00:59:58.969
everything and the, oh, just touch this button, problem goes away.
1246
00:59:59.130 --> 01:00:02.769
Yeah. Yeah. I'm feeling that too. You're right.
1247
01:00:03.710 --> 01:00:05.010
I wish it was that simple.
1248
01:00:05.309 --> 01:00:07.860
Yeah. I keep waiting for what's not the simple part.
1249
01:00:08.230 --> 01:00:10.449
I mean, for me, it's the frontline dev.
1250
01:00:10.510 --> 01:00:10.949
Right.
1251
01:00:11.070 --> 01:00:14.909
I mean, the administrator in me is a little sticky
1252
01:00:14.949 --> 01:00:17.369
in the shorts right now because this is all very scary. Like,
1253
01:00:17.429 --> 01:00:19.469
I want to check everything. I don't want to be
1254
01:00:19.510 --> 01:00:21.139
the guy who didn't do his homework.
1255
01:00:21.179 --> 01:00:21.389
Right.
1256
01:00:21.820 --> 01:00:24.420
But for the dev, unless you've done something dumb, I
1257
01:00:24.599 --> 01:00:27.800
think you're good as long as your administrators are on it.
1258
01:00:27.860 --> 01:00:30.460
As I mentioned before, the two big dumb things are
1259
01:00:30.980 --> 01:00:34.500
baking in crypto algorithms into your code and not being crypto-natural.
1260
01:00:34.699 --> 01:00:38.039
That's dumb thing number one. Dumb thing number two is
1261
01:00:38.099 --> 01:00:40.019
if you hard code your TLS configuration.
1262
01:00:40.820 --> 01:00:40.940
Right.
1263
01:00:40.980 --> 01:00:43.840
You're right. Those are the two big ones. Let's just
1264
01:00:43.880 --> 01:00:48.530
ignore compatibility for a moment. If you change a server
1265
01:00:48.550 --> 01:00:52.030
to use TLS 1.3 hybrid and only hybrid, by the way,
1266
01:00:52.130 --> 01:00:53.989
the reason why it's called hybrid is because you do
1267
01:00:54.369 --> 01:00:57.659
elliptic curve and MLChem together. The keys are derived from both.
1268
01:00:58.289 --> 01:01:00.630
That's why it's called hybrid. But if you do hybrid
1269
01:01:00.650 --> 01:01:02.769
and the client doesn't talk hybrid for whatever, you got
1270
01:01:02.789 --> 01:01:07.199
like a crusty old Java application or C sharp application
1271
01:01:07.219 --> 01:01:10.480
written 15 years ago, it's probably not going to work.
1272
01:01:10.820 --> 01:01:11.039
Yeah.
1273
01:01:11.199 --> 01:01:12.360
And it's really a question of, is it going to
1274
01:01:12.460 --> 01:01:14.559
fail with some grace to tell you what the hell's
1275
01:01:14.599 --> 01:01:15.159
going on?
1276
01:01:15.199 --> 01:01:15.400
Yeah.
1277
01:01:15.739 --> 01:01:16.829
Right. Yeah.
1278
01:01:17.050 --> 01:01:19.949
It says, don't understand this cipher suite and gives you
1279
01:01:19.989 --> 01:01:22.190
a hex value. Yeah. Really useful.
1280
01:01:22.389 --> 01:01:22.630
Yeah.
1281
01:01:22.849 --> 01:01:25.570
Well, that's better than object not found.
1282
01:01:27.289 --> 01:01:29.090
One of the best ones in office back in the
1283
01:01:29.110 --> 01:01:29.829
day was out of memory.
1284
01:01:30.190 --> 01:01:32.820
Yeah. Michael, tell us about your book.
1285
01:01:33.070 --> 01:01:33.909
Oh, my new book, man.
1286
01:01:34.119 --> 01:01:34.340
Yeah.
1287
01:01:34.360 --> 01:01:37.820
So, I wrote this book with Sean Hernan, Lee Holmes,
1288
01:01:37.880 --> 01:01:39.980
and Sherry DeGrippo. So, Sean and I have known each
1289
01:01:40.000 --> 01:01:44.139
other for many, many years. He's a partner engineering manager
1290
01:01:44.239 --> 01:01:46.309
in Azure Security. I've been around for a long time,
1291
01:01:46.349 --> 01:01:50.309
got the utmost respect for Sean, great guy. Lee Holmes,
1292
01:01:50.349 --> 01:01:52.070
he was the security guy in PowerShell.
1293
01:01:52.289 --> 01:01:53.650
Yeah, he's been on the show before too.
1294
01:01:53.769 --> 01:01:55.349
Yeah, my boy Lee, great guy.
1295
01:01:55.429 --> 01:01:56.030
Yeah, he's a good man.
1296
01:01:56.190 --> 01:01:58.670
He and I actually worked together in the earliest days
1297
01:01:58.710 --> 01:02:02.909
of the SDL because when Monad, as it was back
1298
01:02:02.929 --> 01:02:05.150
in the day, had to go through all its SDL checks,
1299
01:02:05.750 --> 01:02:06.510
I was the.
1300
01:02:07.050 --> 01:02:08.989
Precursor to PowerShell?
1301
01:02:09.030 --> 01:02:09.929
To PowerShell, correct.
1302
01:02:10.130 --> 01:02:10.809
Yeah.
1303
01:02:11.030 --> 01:02:13.920
I was like the SDL contact for Monad. And so
1304
01:02:13.980 --> 01:02:15.579
Lee and I got to know each other incredibly well.
1305
01:02:16.500 --> 01:02:20.260
And he's also a partner engineer in Azure. And then
1306
01:02:20.360 --> 01:02:22.920
Sherrod DeGrippo, she's actually left Microsoft now. She goes to
1307
01:02:22.940 --> 01:02:28.469
Palo Alto Labs. She is easily one of the preeminent
1308
01:02:28.510 --> 01:02:32.349
experts in the world on threat actors. She knows absolutely
1309
01:02:32.369 --> 01:02:35.429
everything about threat actors. So the book is Threat-Driven Software Development.
1310
01:02:35.989 --> 01:02:38.389
And basically what it is is looking at software development
1311
01:02:38.409 --> 01:02:41.030
through the eyes of threat actors, like what do threat
1312
01:02:41.070 --> 01:02:41.820
actors actually do?
1313
01:02:41.840 --> 01:02:41.960
Mm-hmm.
1314
01:02:42.550 --> 01:02:45.420
And every chapter starts off... So first of all, Sherrod
1315
01:02:45.440 --> 01:02:47.880
has her own chapter at the beginning. But every chapter
1316
01:02:47.980 --> 01:02:51.480
after that looks at the contents of that chapter through
1317
01:02:51.500 --> 01:02:55.679
the lens of threat intel. So every chapter starts off
1318
01:02:55.719 --> 01:02:59.840
with anywhere between half and two pages of threat intel perspective,
1319
01:02:59.880 --> 01:03:02.500
where Sherrod gives it a whole bunch of color. And
1320
01:03:02.539 --> 01:03:06.969
then Lee, myself, and Sean go through and sort of
1321
01:03:07.030 --> 01:03:10.489
explain that particular topic in detail. And a lot of it's...
1322
01:03:11.579 --> 01:03:14.099
A lot of it's not just, don't think of it
1323
01:03:14.159 --> 01:03:15.559
like just security best practices.
1324
01:03:15.739 --> 01:03:16.159
It's not.
1325
01:03:16.860 --> 01:03:23.079
It's DevOps as well as it's operational security, AppSec, and
1326
01:03:23.119 --> 01:03:26.139
also Threat Intel all sort of munched together into one book.
1327
01:03:26.400 --> 01:03:26.880
Sounds good.
1328
01:03:27.280 --> 01:03:28.340
Yeah, a lot of fun. I did one when I
1329
01:03:28.340 --> 01:03:31.559
was in the red team. Funny thing is, so Mark
1330
01:03:31.599 --> 01:03:34.719
Rasinovich wrote the forward. And my manager at the time,
1331
01:03:35.809 --> 01:03:38.269
Craig Nelson, who's CVP of the red team, he said,
1332
01:03:38.309 --> 01:03:40.110
oh man, I really love this book. I gave him
1333
01:03:40.130 --> 01:03:44.530
draft to look at. Can I write a chapter? I'm like, well,
1334
01:03:44.550 --> 01:03:45.889
why don't you write the afterword? I said, I've never
1335
01:03:45.909 --> 01:03:47.090
had an afterword in a book. Why don't you write
1336
01:03:47.110 --> 01:03:53.000
the afterword? So he did. Nine pages. But the afterword...
1337
01:03:53.239 --> 01:03:56.739
The after chapter. Yeah, the after chapter. Look, I'm not
1338
01:03:56.760 --> 01:04:02.940
trying to besmirch Craig at all. That afterword is absolutely brilliant.
1339
01:04:03.420 --> 01:04:04.840
If you were to sum up the afterword in like
1340
01:04:05.380 --> 01:04:08.519
one sentence or two words, it would be So what?
1341
01:04:09.380 --> 01:04:12.300
And he does a really, really good job of answering.
1342
01:04:12.340 --> 01:04:14.199
So what? Yeah. It's really good. Yeah.
1343
01:04:14.219 --> 01:04:16.750
That's good. It's really cool. Michael, what can we say?
1344
01:04:16.789 --> 01:04:20.829
It's been enlightening having you here and talking about all
1345
01:04:20.869 --> 01:04:23.570
this crazy stuff that we barely understand. Well, I barely
1346
01:04:23.610 --> 01:04:26.230
understand anyway, but I understand a little more thanks to you.
1347
01:04:26.269 --> 01:04:27.230
So thank you very much.
1348
01:04:27.449 --> 01:04:28.889
You're welcome. Thanks for having me on.
1349
01:04:28.929 --> 01:04:30.880
Great show, friend. Thank you so much. And we'll talk
1350
01:04:30.889 --> 01:04:33.119
to you next time on. NET Rocks!. NET Rocks!
1351
01:04:54.269 --> 01:04:57.030
NET Rocks is brought to you by Franklin's Net and
1352
01:04:57.090 --> 01:05:01.809
produced by Plop Studios, a full-service audio, video, and post-production
1353
01:05:01.869 --> 01:05:05.849
facility located physically in New London, Connecticut, and, of course,
1354
01:05:05.909 --> 01:05:14.050
in the cloud, online at pwop.com. Visit our website at dotnetrocks.com
1355
01:05:14.489 --> 01:05:19.190
for RSS feeds, downloads, mobile apps, comments, and access to
1356
01:05:19.210 --> 01:05:22.590
the full archives going back to show number one, recorded
1357
01:05:22.610 --> 01:05:23.829
in September 2002.
1358
01:05:23.829 --> 01:05:27.139
And make sure you check out our sponsors. They keep
1359
01:05:27.219 --> 01:05:30.400
us in business. Now go write some code. See you
1360
01:05:30.420 --> 01:05:30.840
next time.
1
00:00:01.169 --> 00:00:04.790
How'd you like to listen to. NET Rocks with no ads? Easy.
2
00:00:05.370 --> 00:00:08.789
Become a patron. For just $ 5 a month, you get
3
00:00:08.890 --> 00:00:11.710
access to a private RSS feed where all the shows
4
00:00:11.789 --> 00:00:14.890
have no ads. $ 20 a month will get you that
5
00:00:15.109 --> 00:00:18.839
and a special. NET Rocks patron mug. Sign up now
6
00:00:18.890 --> 00:00:36.520
at patreon.dotnetrocks.com. NET Rocks Hey, and welcome back to. NET Rocks.
7
00:00:36.700 --> 00:00:39.399
I'm Carl Franklin. And I'm Richard Campbell. And Michael Howard's
8
00:00:39.439 --> 00:00:41.770
here with us. We'll have him jump in if he
9
00:00:41.799 --> 00:00:45.090
wants to in the beginning. And we'll introduce him a
10
00:00:45.090 --> 00:00:47.789
little bit later after the first bits. You know what
11
00:00:47.829 --> 00:00:49.869
those are. Here we go. Here we go. 2020.
12
00:00:49.850 --> 00:00:53.950
It's episode 20 when we're almost done, right? Like this
13
00:00:54.030 --> 00:00:56.850
ends in 20 after 2026. So we got like six
14
00:00:56.909 --> 00:00:57.390
more of these.
15
00:00:57.609 --> 00:01:00.429
And it's becoming less and less interesting because most people
16
00:01:00.490 --> 00:01:01.729
have lived through the last six years.
17
00:01:01.929 --> 00:01:05.599
It's so current. Yeah. It's kind of now. Especially 2020,
18
00:01:05.599 --> 00:01:08.280
because of course, what can you talk about except COVID?
19
00:01:08.439 --> 00:01:10.680
Oh my God, COVID. All right, I'm done, Richard. What
20
00:01:10.700 --> 00:01:12.000
about space? Yeah, thanks for playing, guys.
21
00:01:13.079 --> 00:01:14.700
Well, the other thing I would talk about is this
22
00:01:14.769 --> 00:01:16.829
is when the UK officially leaves.
23
00:01:18.450 --> 00:01:21.109
The EU. Oh, there's more news, but COVID is the
24
00:01:21.150 --> 00:01:24.189
big one. George Floyd. It is the big one, yeah.
25
00:01:24.209 --> 00:01:29.760
George Floyd killed. Big, big reaction to that that sparked
26
00:01:29.900 --> 00:01:34.700
off a lot of stuff. Joe Biden beat Donald Trump. Yes, there,
27
00:01:34.819 --> 00:01:39.519
I said it because that's the truth. Worldwide economic collapse
28
00:01:39.579 --> 00:01:43.560
caused by COVID. Lockdowns. Yeah, it's just stall. It was
29
00:01:43.609 --> 00:01:47.109
just horrible. Donald Trump was impeached for the first time. Oh,
30
00:01:47.129 --> 00:01:49.790
in the first year. I was at the end. A
31
00:01:49.849 --> 00:01:53.189
lot of wildfires in Australia and Western US. The terrible ones.
32
00:01:55.549 --> 00:01:58.989
Know about and now and today it's really relevant in
33
00:01:59.030 --> 00:02:05.049
september the second nagorno-karabakh war so this is between azerbaijan
34
00:02:05.209 --> 00:02:08.990
and armenia this is an enclave that normally is controlled
35
00:02:09.030 --> 00:02:12.280
by armenia but the azerbaijanis wanted it and they attack
36
00:02:12.360 --> 00:02:14.379
and so the azerbaijanis are the ones with the oil
37
00:02:14.419 --> 00:02:18.159
money and they're muslim the uh the armenians are predominantly
38
00:02:18.180 --> 00:02:22.039
christian uh the azerbaijanis attack and to be clear this
39
00:02:22.060 --> 00:02:24.719
is a very complicated conflict like it's gone on literally
40
00:02:24.740 --> 00:02:27.169
for centuries But it was a drone war. It was
41
00:02:27.229 --> 00:02:28.750
arguably the first drone war.
42
00:02:28.969 --> 00:02:29.289
Wow.
43
00:02:29.710 --> 00:02:36.259
The Azerbaijanis bought Turkish Bayraktar drones. They had bought some
44
00:02:36.300 --> 00:02:41.039
of the surveillance equipment from the Israelis. And so they
45
00:02:41.060 --> 00:02:45.639
had continuous surveillance. They were using drones for attack. They
46
00:02:45.759 --> 00:02:49.620
destroyed missile sites and so forth. The Iranians were fighting
47
00:02:49.659 --> 00:02:52.539
the old style with Soviet equipment. and just kind of
48
00:02:52.560 --> 00:02:54.560
got rolled over. Like you'd think the Russians would have
49
00:02:54.599 --> 00:02:57.699
taken a hint watching their stuff be torn up by
50
00:02:57.780 --> 00:03:01.509
drones in 2020. Instead, they bought a lot of drones. Well,
51
00:03:01.530 --> 00:03:04.729
they did eventually, but first they got hit pretty hard. Anyway,
52
00:03:05.310 --> 00:03:08.110
it was only six weeks. And that doesn't change the
53
00:03:08.150 --> 00:03:10.629
fact that a lot of people died. It did result
54
00:03:10.669 --> 00:03:13.030
in the fall of the, of the region and the
55
00:03:13.069 --> 00:03:15.479
change in the, in the environment over there. But it's
56
00:03:15.500 --> 00:03:18.360
just a precursor conflict to, to, you know, we saw
57
00:03:18.580 --> 00:03:21.120
an example, just of course it was COVID and, There
58
00:03:21.129 --> 00:03:23.599
was all the things going on at that time in
59
00:03:23.620 --> 00:03:25.300
that year that nobody was paying attention to.
60
00:03:25.319 --> 00:03:25.539
Yeah.
61
00:03:25.599 --> 00:03:30.219
A couple other notable deaths in 2020. Ruth Bader Ginsburg.
62
00:03:31.580 --> 00:03:32.099
What a blunder.
63
00:03:32.280 --> 00:03:32.620
Yeah.
64
00:03:32.979 --> 00:03:37.439
Kobe Bryant. Yeah, the helicopter accident. And good trouble himself,
65
00:03:37.840 --> 00:03:38.430
John Lewis.
66
00:03:38.750 --> 00:03:38.949
Right.
67
00:03:39.150 --> 00:03:41.469
Died civil rights icon. Yeah. Yeah, it was just a
68
00:03:41.550 --> 00:03:44.129
bad- Tough year. Bad years. Tough year.
69
00:03:44.229 --> 00:03:45.590
Yeah. Do you want to know what happened in space?
70
00:03:45.629 --> 00:03:48.969
There wasn't a ton, but there's some important ones. In February,
71
00:03:49.069 --> 00:03:52.189
Solar Orbiter launches. You don't really know much about this one.
72
00:03:52.310 --> 00:03:55.449
This was a joint ESA-NASA mission in that order. It's
73
00:03:55.469 --> 00:03:58.990
very much a European mission with NASA instrumentations and They
74
00:03:59.009 --> 00:04:00.810
provided the Atlas V as well, but it was built
75
00:04:00.830 --> 00:04:03.810
by Airbus. And its goal was to get a view
76
00:04:04.050 --> 00:04:07.710
of the poles of the sun. Normally, you're launching your
77
00:04:07.729 --> 00:04:10.270
spacecraft because the Earth's in the plane of the ecliptic.
78
00:04:10.310 --> 00:04:11.909
Your spacecraft are going to be as well. Trying to
79
00:04:11.930 --> 00:04:13.780
get to high inclination is very, very difficult. Not that
80
00:04:13.789 --> 00:04:17.579
they got all that high. They'll fly down into a
81
00:04:17.920 --> 00:04:21.560
looping orbit inside the orbit of Mercury and then use
82
00:04:21.860 --> 00:04:26.199
Venus to do the slingshots and repeatedly tip the spacecraft.
83
00:04:26.230 --> 00:04:29.089
So it is about 24 degrees off the planet ecliptic.
84
00:04:29.110 --> 00:04:30.569
It takes a ton of energy to do that. They
85
00:04:30.589 --> 00:04:34.110
borrowed lots of energy from Venus, but it's a one-ton spacecraft,
86
00:04:34.129 --> 00:04:34.290
so it.
87
00:04:34.269 --> 00:04:34.670
Can do that.
88
00:04:35.490 --> 00:04:38.790
But it'll get us our first visual views of the
89
00:04:38.829 --> 00:04:39.560
poles of the sun.
90
00:04:39.920 --> 00:04:41.779
Cool mission. Yeah, that is cool.
91
00:04:41.920 --> 00:04:45.560
In May. the first crew dragon demo mission. So this
92
00:04:45.579 --> 00:04:48.790
was Bob, uh, Benneken and Doug Hurley go up to
93
00:04:48.810 --> 00:04:52.889
the space station and demonstrate that, uh, the commercial spacecraft
94
00:04:52.930 --> 00:04:55.370
can actually go to the space station properly. And that'll
95
00:04:55.389 --> 00:04:57.589
be followed up in November with a regular crew flight
96
00:04:57.629 --> 00:04:59.750
of four astronauts to crew the space station.
97
00:04:59.850 --> 00:05:01.110
So there you go.
98
00:05:01.250 --> 00:05:04.730
After what this would be nine years since the Atlantis
99
00:05:04.750 --> 00:05:07.769
had landed. And the only support for the station was, uh,
100
00:05:08.160 --> 00:05:10.920
Via Soyuz, now the Americans had a vehicle again, the
101
00:05:10.959 --> 00:05:11.519
former crew driver.
102
00:05:11.540 --> 00:05:14.290
I got a question, which Michael might know the answer to,
103
00:05:14.370 --> 00:05:18.949
but you said ESA and NASA did this thing together
104
00:05:19.110 --> 00:05:22.279
in 2020, but Brexit was in 2020. Was Was Britain
105
00:05:22.339 --> 00:05:24.990
part of ESA in 2020? Did they participate?
106
00:05:25.319 --> 00:05:27.370
Yeah, I don't think so. I could be wrong, but
107
00:05:27.389 --> 00:05:28.009
I don't think so.
108
00:05:28.250 --> 00:05:29.430
It's mostly Germany, France.
109
00:05:29.470 --> 00:05:29.769
Yeah.
110
00:05:29.829 --> 00:05:32.750
Okay. It's Airbus, it's Defense of the Space. All right.
111
00:05:32.810 --> 00:05:36.480
July, the Perseverance rover. So, this was the test article
112
00:05:36.620 --> 00:05:39.660
for the original Curiosity rover with a bunch of upgraded things,
113
00:05:39.699 --> 00:05:41.259
better wheels, better suspension.
114
00:05:41.300 --> 00:05:41.399
Yeah.
115
00:05:42.079 --> 00:05:46.939
New instruments, the Ingenuity helicopter, all of that stuff gets
116
00:05:47.000 --> 00:05:50.189
launched in July. July is the perfect time to launch
117
00:05:50.230 --> 00:05:53.449
to Mars, July 2020. There's a synchronicity to the orbits, right?
118
00:05:53.470 --> 00:05:56.629
They're in a two, three period. And so every roughly
119
00:05:56.689 --> 00:05:58.069
two years, you get a chance to do a bunch
120
00:05:58.089 --> 00:05:59.889
of flights. And so July, there's actually three. There's the
121
00:05:59.930 --> 00:06:03.500
Perseverance rover, which is huge. There's also China's very first
122
00:06:03.560 --> 00:06:08.329
mission to Mars, Tianwen-1. And then the UAE. the United
123
00:06:08.389 --> 00:06:13.829
Aramids launches their Hope climate orbiter to Mars. So three
124
00:06:13.870 --> 00:06:15.250
launches in the same month. Wow.
125
00:06:15.269 --> 00:06:15.970
Did they all make it?
126
00:06:16.310 --> 00:06:16.980
In October.
127
00:06:17.420 --> 00:06:18.339
The U.S. made it.
128
00:06:18.379 --> 00:06:19.089
They all make it.
129
00:06:19.120 --> 00:06:20.740
Yeah, actually. Very cool.
130
00:06:20.899 --> 00:06:24.160
And I mean, I'll talk more about the Tianwen-1 when
131
00:06:24.180 --> 00:06:27.189
it lands next year. So in episode 2021. Because that
132
00:06:27.209 --> 00:06:29.310
was China's first attempt to go to Mars and it
133
00:06:29.470 --> 00:06:33.750
fully worked. Nobody's pulled that off before. Everybody loses a
134
00:06:33.769 --> 00:06:34.889
few trying to get to Mars.
135
00:06:35.589 --> 00:06:37.810
Just name it. Everybody does. But China didn't.
136
00:06:38.009 --> 00:06:40.550
But, you know, the advantage of being, I don't know,
137
00:06:40.670 --> 00:06:44.660
fourth or fifth mover or something like that. In October, OSIRIS-REx,
138
00:06:44.779 --> 00:06:49.420
one of the asteroid missions, touches on asteroid Bennu. and
139
00:06:49.480 --> 00:06:51.480
collects a sample there. In fact, it does a little
140
00:06:51.560 --> 00:06:54.759
too well because when it touches, Bennu is very much
141
00:06:54.790 --> 00:06:57.350
a rubble pile and all that gravel goes everywhere and
142
00:06:57.750 --> 00:07:01.509
they actually have trouble closing up the sample container because
143
00:07:01.529 --> 00:07:03.709
there's too much stuff. They have to come up with
144
00:07:03.730 --> 00:07:07.629
such technical maneuvers as shaking a little off to try
145
00:07:07.689 --> 00:07:09.310
and get the thing closed up so they can put
146
00:07:09.329 --> 00:07:12.209
it in the capsule to return. Another asteroid mission at
147
00:07:12.250 --> 00:07:14.529
the end of the year in December, Hayabusa 2, will
148
00:07:14.569 --> 00:07:19.040
actually successfully return It's sample payload from the asteroid Regu,
149
00:07:19.060 --> 00:07:22.240
and that is a JAXA mission. A little recap on
150
00:07:22.279 --> 00:07:25.779
what SpaceX did in 2020. There was actually 25 launches
151
00:07:25.819 --> 00:07:28.699
from SpaceX, which at the time was an amazing number.
152
00:07:29.459 --> 00:07:33.899
Just remembering that SpaceX will do 150 this year. So obviously,
153
00:07:34.259 --> 00:07:37.870
there's the two Crew Dragons, the test run in March,
154
00:07:37.949 --> 00:07:41.519
and then the full payload in November. They'll also fly
155
00:07:41.519 --> 00:07:45.310
14 Starlink missions, 833 satellites for a network of almost
156
00:07:45.310 --> 00:07:47.029
900 by the end of the year.
157
00:07:47.050 --> 00:07:47.120
Wow.
158
00:07:47.129 --> 00:07:51.350
Have you ever seen the Starlink satellites leaving the spaceship? Yeah.
159
00:07:51.370 --> 00:07:52.800
It's like pizza boxes going out.
160
00:07:52.939 --> 00:07:55.660
Yeah, yeah. Well, now they've gotten bigger because of the
161
00:07:55.699 --> 00:07:58.000
V2 minis. And so, they only fly like 24 or
162
00:07:58.000 --> 00:08:00.819
28 of them depending on the inclination. But at this time,
163
00:08:00.879 --> 00:08:03.370
they're flying 60 a run.
164
00:08:03.389 --> 00:08:04.230
That's crazy. Wow.
165
00:08:04.620 --> 00:08:07.879
Just these huge numbers of satellites. And that's where they also,
166
00:08:08.259 --> 00:08:10.240
this is the year where they have the reflectivity problems.
167
00:08:10.439 --> 00:08:12.870
And so you can see them for an extended period
168
00:08:12.879 --> 00:08:15.720
of time until they learn how to orient them and
169
00:08:15.759 --> 00:08:18.160
paint them correctly so they're not so visible and don't
170
00:08:18.199 --> 00:08:19.139
bother people so much.
171
00:08:19.250 --> 00:08:21.189
I remember there was a bunch of astronomers that were
172
00:08:21.230 --> 00:08:23.949
complaining they were polluting the night sky with their telescopes.
173
00:08:24.209 --> 00:08:27.009
Yeah. Well, and that's still an issue, although let's face it,
174
00:08:27.009 --> 00:08:28.550
digital processing can fix that.
175
00:08:28.769 --> 00:08:29.290
Right.
176
00:08:29.449 --> 00:08:32.750
But making bright lights make it worse. So making sure
177
00:08:32.769 --> 00:08:34.250
it doesn't reflect sunlight helps.
178
00:08:34.549 --> 00:08:37.139
I've seen them though. I've seen the trail go across
179
00:08:37.240 --> 00:08:40.500
and it's pretty fascinating and a little bit I don't know.
180
00:08:40.539 --> 00:08:42.970
You know, SpaceX does some things that if you weren't
181
00:08:43.009 --> 00:08:45.570
paying attention, you'd think we're being invaded by aliens.
182
00:08:45.769 --> 00:08:48.330
Well, or, you know, or Dr. No is in full swing.
183
00:08:48.389 --> 00:08:51.879
Like the line between supervillain and tech billionaire is getting
184
00:08:51.899 --> 00:08:52.799
very narrow.
185
00:08:53.000 --> 00:08:55.220
Just people don't know. Like, you know, the first time
186
00:08:55.259 --> 00:08:57.840
that I saw the booster rocket spinning, you know, when
187
00:08:57.879 --> 00:09:01.789
it– I thought it was like a spaceship. And so
188
00:09:01.809 --> 00:09:03.769
did a million other people until I found out, oh,
189
00:09:03.809 --> 00:09:05.730
that's just SpaceX. That's what they do. And what are
190
00:09:05.769 --> 00:09:08.470
those lights going? Hey, is that Santa Claus? No, that's
191
00:09:08.509 --> 00:09:09.250
just SpaceX.
192
00:09:09.309 --> 00:09:13.600
Yeah. I use Stellarium and it'll show you all the SpaceX.
193
00:09:13.960 --> 00:09:17.620
Sure. Something's whizzing around out there. I know. Must be
194
00:09:17.659 --> 00:09:21.340
my Facebook friends. They're at average intelligence or ability to
195
00:09:21.399 --> 00:09:22.379
look things up.
196
00:09:22.379 --> 00:09:24.460
10,000 plus of them by the end of this year,
197
00:09:24.519 --> 00:09:26.990
just so you know. There'll be a bunch of other
198
00:09:27.009 --> 00:09:29.049
missions as well, including a couple of GPS satellites. They'll
199
00:09:29.080 --> 00:09:32.100
also start doing their Starship flights, the hop tests, and
200
00:09:32.120 --> 00:09:34.820
the first, what they called belly flop test, where they
201
00:09:34.860 --> 00:09:36.840
fire it up to a few kilometers up and then
202
00:09:36.879 --> 00:09:38.419
let it fall on its belly so they could actually
203
00:09:38.480 --> 00:09:41.059
land it. That was SN8 by the end of 2020.
204
00:09:41.059 --> 00:09:43.799
It does not go well, but they'll solve that and
205
00:09:43.879 --> 00:09:45.940
prove that this whole idea is even possible. All right,
206
00:09:45.960 --> 00:09:46.960
should we move on to computing?
207
00:09:47.120 --> 00:09:47.279
Yeah.
208
00:09:47.440 --> 00:09:50.440
We'll start in January with the OpenAI paper called the
209
00:09:50.559 --> 00:09:54.779
Neural Scaling Laws. Lead author is Jared Kaplan. There's a
210
00:09:54.779 --> 00:09:57.679
whole bunch of others, including Daryl Modi, who this time
211
00:09:57.720 --> 00:09:59.970
is at OpenAI, will eventually be the CEO of Anthrop.
212
00:10:00.600 --> 00:10:02.759
And this was the paper that sort of kicked off
213
00:10:02.840 --> 00:10:06.450
this idea of, you know, different from all the other
214
00:10:06.490 --> 00:10:08.929
machine learning models we did where we worry about overfitting
215
00:10:08.970 --> 00:10:12.539
and training sets and so forth. that for large language models,
216
00:10:12.580 --> 00:10:13.970
we should just train on as much data as we
217
00:10:13.990 --> 00:10:17.509
can possibly get. There's lots of debate as to whether
218
00:10:17.529 --> 00:10:19.809
this is that good an idea. We've definitely come into
219
00:10:19.889 --> 00:10:22.909
other techniques from there. But this paper is kind of
220
00:10:22.950 --> 00:10:25.570
the stimulus for what will be the insanity coming in
221
00:10:25.590 --> 00:10:28.720
the next couple of years. January is also when Microsoft
222
00:10:28.740 --> 00:10:30.960
switches over to Chromium as the rendering engine in the
223
00:10:31.039 --> 00:10:35.190
new Edge browser. The pandemic's in full swing in March
224
00:10:35.210 --> 00:10:38.360
is when lockdowns really kick off and everybody goes home
225
00:10:38.429 --> 00:10:41.940
and everybody's got Zoom. Teams explodes for better or worse.
226
00:10:42.559 --> 00:10:48.629
But a little thing I paid attention to was Terry Breton,
227
00:10:48.690 --> 00:10:53.879
who is the EU Internal Market Commissioner. reached out to
228
00:10:54.240 --> 00:10:58.139
Netflix and YouTube and Amazon Prime and asked him to
229
00:10:58.179 --> 00:11:01.679
turn off all the 4K features. He was concerned about
230
00:11:01.700 --> 00:11:05.899
the amount of available bandwidth across Europe as everybody went
231
00:11:06.000 --> 00:11:10.610
home and used the internet differently. Was it actually a crisis?
232
00:11:10.690 --> 00:11:13.470
Nobody knows for sure, or at least he's not talking
233
00:11:13.509 --> 00:11:17.090
about it. They started turning up the bandwidth again in May,
234
00:11:17.230 --> 00:11:20.889
and Netflix's Posts about this are interesting because they talk
235
00:11:20.929 --> 00:11:23.750
about network changes and increasing capacity and things like that.
236
00:11:24.370 --> 00:11:26.519
So maybe there really was a crisis because of the
237
00:11:26.559 --> 00:11:29.440
change in the Internet consumption due to COVID. But, you know,
238
00:11:29.519 --> 00:11:32.440
a lot of details aren't revealed necessarily. But that to
239
00:11:32.480 --> 00:11:33.320
me was very interesting.
240
00:11:33.340 --> 00:11:33.480
Yeah.
241
00:11:34.250 --> 00:11:37.600
April is when Uncle Satchit says, two years worth of
242
00:11:37.639 --> 00:11:42.580
digital transformation in two months. Because everybody had to all work.
243
00:11:42.620 --> 00:11:44.419
This is when I started doing True Run As a week,
244
00:11:44.539 --> 00:11:49.850
just talking about topics around what was necessary for sysadmins
245
00:11:51.529 --> 00:11:52.769
with everybody working from home.
246
00:11:52.990 --> 00:11:56.169
My brother is a programmer at a local company. He's
247
00:11:56.190 --> 00:11:59.169
been there for years and years. And they basically do
248
00:11:59.490 --> 00:12:02.309
online vehicle registrations. And they were the first in the
249
00:12:02.409 --> 00:12:07.840
area to do it. And their customers are states, not
250
00:12:07.960 --> 00:12:15.730
individual sales places, dealerships. But anyway, they were renting an
251
00:12:15.830 --> 00:12:19.470
office building in an office park out here, umpteen billion
252
00:12:19.529 --> 00:12:22.809
square feet. And during COVID, people went to work at home.
253
00:12:23.450 --> 00:12:27.259
And I just remember Jay coming to rehearsal once and said, Well,
254
00:12:27.279 --> 00:12:29.759
I've resigned myself to the idea that I'm never going
255
00:12:29.799 --> 00:12:32.889
back to the office. And they basically moved out of
256
00:12:32.929 --> 00:12:35.590
the office. Yeah, lots did. They stopped renting it. And
257
00:12:35.629 --> 00:12:38.289
I think, in general, office space took a big dive
258
00:12:39.049 --> 00:12:39.850
in 2020.
259
00:12:39.850 --> 00:12:42.210
You think about all the property that Microsoft gave up
260
00:12:42.269 --> 00:12:42.850
in Bellevue.
261
00:12:43.000 --> 00:12:43.409
Yeah.
262
00:12:43.600 --> 00:12:46.480
They kept their buildings in Redmond, but all that rented space.
263
00:12:46.299 --> 00:12:47.019
In Bellevue went away.
264
00:12:47.340 --> 00:12:47.519
Right.
265
00:12:47.659 --> 00:12:48.559
And all of it went to Zoom.
266
00:12:48.820 --> 00:12:49.059
Yeah.
267
00:12:49.559 --> 00:12:50.120
Well, to Teams.
268
00:12:50.139 --> 00:12:54.769
Teams. The first virtual build in May is also when
269
00:12:54.909 --> 00:12:58.929
they do the full release of Blazor WebAssembly.
270
00:12:59.129 --> 00:12:59.649
Yeah.
271
00:13:00.309 --> 00:13:02.429
Obviously, a bunch of other cool announcements around building that
272
00:13:02.450 --> 00:13:05.990
time span. Of course, Blazor, not the first WA programming language,
273
00:13:06.070 --> 00:13:10.740
Golang added WA support back in 2018. In June, and again,
274
00:13:10.759 --> 00:13:14.679
no people remember much about this because it was mid-pandemic.
275
00:13:15.429 --> 00:13:19.690
Microsoft is a big splash about OpenAI GPT-3 being built
276
00:13:19.769 --> 00:13:22.990
on what they called the Azure supercomputer, which was a
277
00:13:23.070 --> 00:13:26.120
bunch of different Azure data centers harnessed together with 10,000 GPUs, 285,000 CPUs.
278
00:13:28.679 --> 00:13:33.120
cpu cores to build a get this 175 billion parameter
279
00:13:33.159 --> 00:13:36.029
model wow i mean big big big for the time
280
00:13:36.250 --> 00:13:38.230
not so much anymore but at the time.
281
00:13:38.110 --> 00:13:40.629
I remember uh brian mckay who's one of my happy
282
00:13:40.649 --> 00:13:43.789
next guys getting on slack and telling us how awesome
283
00:13:43.809 --> 00:13:46.289
this gpt thing was but it was difficult to set
284
00:13:46.350 --> 00:13:48.570
up at the time but then yeah you know i
285
00:13:48.610 --> 00:13:51.269
tried it and of course like everybody else was kind
286
00:13:51.289 --> 00:13:51.919
of blown away.
287
00:13:52.029 --> 00:13:55.600
Yeah Later that year in September is when Microsoft actually
288
00:13:55.679 --> 00:14:00.649
licenses GPT-3 from OpenAI, which I presume is how GitHub
289
00:14:00.669 --> 00:14:03.049
gets access to it. They'll make GitHub Copilot the following.
290
00:14:03.970 --> 00:14:08.610
A couple more stories. In November, Apple announces the M1 processor.
291
00:14:08.769 --> 00:14:09.009
Yes.
292
00:14:09.250 --> 00:14:11.840
And I mention this because this, I would argue, is
293
00:14:12.460 --> 00:14:17.000
Tim Cook's most memorable move. He was always a hardware guy.
294
00:14:17.019 --> 00:14:18.879
This is an astonishing piece of hardware. There's a system
295
00:14:18.919 --> 00:14:23.879
on a chip where the GPU and CPU, NPU, the
296
00:14:24.100 --> 00:14:26.440
IO and security buses and so forth are all literally
297
00:14:26.480 --> 00:14:28.820
in the same die. The memory is in the same package.
298
00:14:29.899 --> 00:14:33.679
So this is made by TSMC, five nanometer process, about
299
00:14:33.679 --> 00:14:37.679
16 billion transistors total. That includes eight CPU cores, eight
300
00:14:37.700 --> 00:14:40.610
GPU cores, a 16 core neural engine, and up to
301
00:14:40.610 --> 00:14:42.580
16 gigabytes of RAM right.
302
00:14:42.490 --> 00:14:43.070
On the package.
303
00:14:43.110 --> 00:14:46.669
So you get both lower power consumption and higher performance.
304
00:14:47.720 --> 00:14:48.759
And little would we realize.
305
00:14:48.899 --> 00:14:51.419
I have a MacBook Pro with an M1. Yeah. First gen.
306
00:14:51.679 --> 00:14:52.279
And it's good.
307
00:14:52.440 --> 00:14:54.580
Is that 16? Is that megabytes or gigabytes?
308
00:14:54.860 --> 00:14:55.139
Gigs.
309
00:14:55.490 --> 00:14:57.750
Yeah. That's RAM, RAM, not cache.
310
00:14:57.769 --> 00:14:58.429
That's RAM, RAM.
311
00:14:58.490 --> 00:14:58.889
Okay. Yeah.
312
00:14:58.909 --> 00:15:01.009
They're not putting cache on. The cache is there too.
313
00:15:01.269 --> 00:15:01.429
Okay.
314
00:15:01.450 --> 00:15:03.230
And also that RAM is shared with the GPU.
315
00:15:03.549 --> 00:15:04.549
Right.
316
00:15:04.570 --> 00:15:08.519
So what we're doing right now with LLMs and the
317
00:15:08.559 --> 00:15:10.919
new agent models and so forth, The M1 was built
318
00:15:10.940 --> 00:15:13.019
for it, not knowing it was built for it. They
319
00:15:13.039 --> 00:15:14.779
were just trying to make the most efficient computer they
320
00:15:14.799 --> 00:15:17.149
could consume the least power. And this is Apple's move
321
00:15:17.210 --> 00:15:20.769
back to ARM, having come from the Motorola chipset, moved
322
00:15:20.789 --> 00:15:23.190
to Intel for a few years. Now they're making their
323
00:15:23.230 --> 00:15:24.549
own thing based on ARM.
324
00:15:26.029 --> 00:15:26.289
Two more.
325
00:15:26.450 --> 00:15:29.720
December, both in December. The SolarWinds supply chain attack. So
326
00:15:29.740 --> 00:15:34.919
this is Russian SVR. The pure brilliance of this is unbelievable.
327
00:15:35.429 --> 00:15:38.860
So in September of 2019, hackers successfully break into the
328
00:15:38.899 --> 00:15:43.519
SolarWinds development environment and they insert code into the development chain.
329
00:15:43.960 --> 00:15:45.940
The way they do it is incredibly insidious. It's part
330
00:15:45.960 --> 00:15:49.200
of their build system that they replace code in the
331
00:15:49.279 --> 00:15:52.399
build without actually changing the visible source code. So developers
332
00:15:52.419 --> 00:15:53.889
don't think their code has changed at all, but what
333
00:15:53.909 --> 00:15:56.909
they're actually compiling is different code with this thing called
334
00:15:56.929 --> 00:16:01.750
the sunburst backdoor. They, they, they, It takes them a
335
00:16:01.769 --> 00:16:03.389
few months of doing testing to get this to work.
336
00:16:03.460 --> 00:16:06.700
By March, they have actually figured it out. And the
337
00:16:06.779 --> 00:16:10.399
Orion monitoring software, SolarWinds builds this infrastructure monitoring software, is
338
00:16:10.440 --> 00:16:14.019
now distributed to 18,000 customers with the Sunburst backdoor in it.
339
00:16:15.389 --> 00:16:18.190
The Russians are successful enough that in June, they actually
340
00:16:18.269 --> 00:16:21.870
removed the whole build injection system. Like, they're done. And
341
00:16:21.929 --> 00:16:24.580
are happily operating it. Now, admittedly, they don't actually use
342
00:16:24.600 --> 00:16:27.539
that backdoor much. Maybe 100 customers are totally affected. But
343
00:16:27.580 --> 00:16:30.799
it's in December when one of those customers, a security
344
00:16:30.840 --> 00:16:36.149
company called FireEye, realizes they've been exploited and traces it
345
00:16:36.210 --> 00:16:39.149
back to the Orion code base and basically pops the
346
00:16:39.190 --> 00:16:42.940
whole thing open. It's an incredibly sophisticated supply chain attack
347
00:16:42.980 --> 00:16:45.399
and scares just not actually everybody. It's not the first one,
348
00:16:45.440 --> 00:16:46.750
but in a lot of ways, it's the one that
349
00:16:46.759 --> 00:16:47.970
made the most news.
350
00:16:48.309 --> 00:16:51.350
It could be made into a feature film, actually, if
351
00:16:51.409 --> 00:16:52.470
it was handled correctly.
352
00:16:52.850 --> 00:16:53.830
It's astonishing.
353
00:16:53.850 --> 00:16:55.190
Yeah.
354
00:16:55.309 --> 00:16:58.029
And if the Russians hadn't decided to go after FireEye,
355
00:16:58.269 --> 00:17:00.360
who knows when it would have been detected. Just he
356
00:17:00.399 --> 00:17:02.759
went after the guys who were in the security space
357
00:17:02.799 --> 00:17:04.319
and good enough at attacking breach properly.
358
00:17:05.869 --> 00:17:08.170
Yeah, I remember when I was invited to a meeting
359
00:17:08.190 --> 00:17:11.779
to be briefed on the attack when we sort of
360
00:17:11.799 --> 00:17:14.339
knew what was going on. And yeah, I'll be frank,
361
00:17:14.700 --> 00:17:17.640
I was kind of gobsmacked actually by- Gobsmacked, yeah. By
362
00:17:17.660 --> 00:17:18.440
the sophistication.
363
00:17:18.640 --> 00:17:22.500
It's so clever. Holy man. I don't expect bad guys
364
00:17:22.539 --> 00:17:25.279
to be this smart, right? If they were smart, they'd
365
00:17:25.299 --> 00:17:27.240
be good guys. Like the idea that bad guys would
366
00:17:27.259 --> 00:17:30.009
come up with something this clever. But again, state actors,
367
00:17:30.069 --> 00:17:32.170
like they're working for more than just a paycheck here.
368
00:17:32.490 --> 00:17:36.420
Yeah, but remember though, you know, As Sherrod Dugripo has
369
00:17:36.460 --> 00:17:39.599
told me many, many times, this is their day job, right?
370
00:17:39.680 --> 00:17:41.799
They come to work, they clock in, they do the work,
371
00:17:41.839 --> 00:17:44.740
they have reviews every year, they go home to their families,
372
00:17:45.029 --> 00:17:46.109
and they start again tomorrow.
373
00:17:46.150 --> 00:17:47.829
They get promotions by figuring this stuff out.
374
00:17:48.009 --> 00:17:49.529
Exactly. It's just their job.
375
00:17:49.569 --> 00:17:52.789
Yeah. As Dwayne LaFleur would say, oh, this is awesome, guys.
376
00:17:53.329 --> 00:17:55.690
This is awesome. It's a stunner.
377
00:17:56.670 --> 00:17:59.690
I'll finish out the year of compute in 2020 with
378
00:18:00.049 --> 00:18:04.430
China's Zhuheng Photonic Quantum Computer, which I think is particularly
379
00:18:04.490 --> 00:18:08.740
relevant for today's conversation. This was a dedicated machine using
380
00:18:09.000 --> 00:18:12.700
photonic quantum entanglement, which is very, very clever, unique, very
381
00:18:12.740 --> 00:18:16.480
different from Sycamore, the Google's device from the previous year,
382
00:18:16.539 --> 00:18:19.799
which was the … The hanging chandelier in liquid helium,
383
00:18:19.839 --> 00:18:21.279
this doesn't need any of this, but it was built
384
00:18:21.319 --> 00:18:23.940
specifically for Gaussian boson sampling.
385
00:18:24.299 --> 00:18:27.849
Nobody knows what you're talking about, Richard. I'm okay with that.
386
00:18:27.920 --> 00:18:29.109
I might contest.
387
00:18:29.190 --> 00:18:32.230
I mean, I know enough to be dangerous. Talk to
388
00:18:32.250 --> 00:18:33.470
me about the software side of it.
389
00:18:33.890 --> 00:18:35.890
Yeah, and that's the whole thing is this is nowhere
390
00:18:35.970 --> 00:18:38.670
near a general purpose computer or even a supercomputer. This
391
00:18:38.730 --> 00:18:41.650
is a machine to demonstrate that quantum entanglement can tackle
392
00:18:41.990 --> 00:18:45.009
one kind of problem, the Gaussian boson sample problem. Now,
393
00:18:45.029 --> 00:18:46.450
that's an important problem, but it was sort of a
394
00:18:46.609 --> 00:18:49.150
proof point I think very much this is a, hey,
395
00:18:49.210 --> 00:18:51.170
we get to play too. And I think everybody reacted
396
00:18:51.190 --> 00:18:54.299
to it that way. Because this 200-second run for something
397
00:18:54.319 --> 00:18:57.880
that in theory would have taken this supercomputer 2 billion years,
398
00:18:57.940 --> 00:19:00.720
not that anybody's going to test that, it just put
399
00:19:00.740 --> 00:19:05.009
China instantly on the map and really made it very clear.
400
00:19:05.529 --> 00:19:07.809
There's more than one way to quantum. And this is
401
00:19:07.869 --> 00:19:10.190
a wildly different way. Not that we've heard much from
402
00:19:10.269 --> 00:19:13.569
them since. But in 2020, that was a really big deal.
403
00:19:13.589 --> 00:19:14.490
But does it run Doom?
404
00:19:14.829 --> 00:19:15.390
It really doesn't.
405
00:19:15.670 --> 00:19:17.630
No, not a bit. No, it won't.
406
00:19:18.799 --> 00:19:21.140
I mean, supercomputers are limited in their own way, too,
407
00:19:21.200 --> 00:19:24.180
as well. But this was literally built for one thing.
408
00:19:24.200 --> 00:19:28.430
This is like Turing's device for cracking Enigma. Good for
409
00:19:28.549 --> 00:19:31.900
one thing. The idea of general-purpose computing is a much
410
00:19:31.960 --> 00:19:33.960
different idea than what we're doing in this kind of
411
00:19:33.980 --> 00:19:34.460
class of work.
412
00:19:34.619 --> 00:19:34.859
Anyway.
413
00:19:34.920 --> 00:19:37.759
Yeah, 100%. I think people need to understand that. Yeah,
414
00:19:37.880 --> 00:19:41.099
still people don't grapple that. There won't be an office
415
00:19:41.140 --> 00:19:43.269
for quantum. It's not going to exist.
416
00:19:43.329 --> 00:19:44.250
Oh, man.
417
00:19:44.490 --> 00:19:44.990
I'm sorry.
418
00:19:45.569 --> 00:19:49.890
You sold me that subscription. Let's get them on the phone. Yeah.
419
00:19:51.059 --> 00:19:54.680
And as much as we can tell at this time,
420
00:19:55.039 --> 00:19:58.220
these will always be supercomputers for particular problem spaces. Most
421
00:19:58.259 --> 00:20:02.009
of them very deterministic problem spaces, too. But let's wrap
422
00:20:02.089 --> 00:20:04.670
up the history lesson and get on to our larger
423
00:20:04.710 --> 00:20:05.529
conversation about quantum.
424
00:20:05.819 --> 00:20:07.839
Well, but first, we have to do.
425
00:20:07.960 --> 00:20:08.460
But first.
426
00:20:08.619 --> 00:20:10.680
Better know a framework. Roll the music. Awesome.
427
00:20:10.700 --> 00:20:15.059
All right, man.
428
00:20:15.160 --> 00:20:19.539
What do you got?
429
00:20:19.660 --> 00:20:22.150
All right. So, as people who listen to me on
430
00:20:22.400 --> 00:20:26.009
my various podcasts and stuff probably know, I bought this
431
00:20:26.890 --> 00:20:32.339
big GPU machine. a year or so ago, just because
432
00:20:32.420 --> 00:20:34.720
I anticipated being able to run local models.
433
00:20:35.160 --> 00:20:36.960
And you got it ahead of the hardware crisis too.
434
00:20:37.000 --> 00:20:38.400
So how smart are you?
435
00:20:38.599 --> 00:20:38.960
Yeah.
436
00:20:40.059 --> 00:20:44.460
I got it at walmart.com for $ 6, 000. It uses an
437
00:20:44.660 --> 00:20:48.480
NVIDIA RTX 1590 with 32 gigs of VRAM.
438
00:20:49.339 --> 00:20:51.740
Today that card's 15 grand if you can find one.
439
00:20:51.960 --> 00:20:55.509
I have, yeah, now it is. I have 96 gigs
440
00:20:55.750 --> 00:20:58.779
of system RAM and it's You know, blinky lights and
441
00:20:58.839 --> 00:21:02.339
quiet as anything, right? Which is amazing. So on Coded
442
00:21:02.359 --> 00:21:05.430
with AI, Jeff Fritz and I did a series on
443
00:21:05.609 --> 00:21:10.089
taking a whole bunch of models that would run on
444
00:21:10.190 --> 00:21:15.750
Ollama and running them and then putting it through a test. Basically,
445
00:21:16.029 --> 00:21:21.539
a lot of them failed. More so because of context,
446
00:21:21.670 --> 00:21:23.680
I think, than this is what I'm learning now, the
447
00:21:23.720 --> 00:21:27.940
context size, if it's too small. We'll just barf. The
448
00:21:28.420 --> 00:21:32.960
LLM will just and lose it or get into an
449
00:21:33.019 --> 00:21:37.960
infinite loop. And basically what I came down to is
450
00:21:38.609 --> 00:21:45.910
running llama.cpp. And llama.cpp is like Ollama, but it's not.
451
00:21:46.029 --> 00:21:48.950
It's a different thing. It's open source. But I can
452
00:21:49.029 --> 00:21:58.720
run the fairly new QEN 3.8.27b model and llama cpp
453
00:21:58.779 --> 00:22:03.859
will use vram and system ram at the same time
454
00:22:04.000 --> 00:22:06.740
and it will balance them out and figure out automatically
455
00:22:06.880 --> 00:22:10.109
how much of which to use and let me tell
456
00:22:10.140 --> 00:22:14.450
you something this is i this is what i've been
457
00:22:14.490 --> 00:22:17.890
waiting for it works so well that i don't feel
458
00:22:17.910 --> 00:22:20.609
the need to go back for what i do you
459
00:22:20.630 --> 00:22:23.930
know debugging coding all of that stuff i don't need
460
00:22:24.089 --> 00:22:27.539
to go back to any frontier models anymore.
461
00:22:27.859 --> 00:22:28.019
Right.
462
00:22:28.140 --> 00:22:29.670
I haven't found, I've been using it for a couple
463
00:22:29.690 --> 00:22:29.930
of weeks.
464
00:22:29.950 --> 00:22:30.930
You're just working local now.
465
00:22:31.130 --> 00:22:33.019
I'm just working local. Yeah. And the only thing I'm
466
00:22:33.880 --> 00:22:36.400
that's costing me is electricity. But I got solar panels.
467
00:22:36.700 --> 00:22:38.839
There you go. Some pretty good, especially in the summer.
468
00:22:39.539 --> 00:22:41.740
Feeling good. And that machine you bought, like to build
469
00:22:41.759 --> 00:22:44.039
that machine today, it's a big bucks.
470
00:22:44.299 --> 00:22:44.559
Yeah.
471
00:22:44.700 --> 00:22:46.240
So you did the right thing. Well, I thought it
472
00:22:46.279 --> 00:22:48.779
was big bucks back then, but now... Yeah, it was. Yeah.
473
00:22:48.799 --> 00:22:50.579
It was a lot of money for a PC back then.
474
00:22:50.700 --> 00:22:52.099
It doesn't seem that way at this moment.
475
00:22:52.119 --> 00:22:53.640
Well, anyway... And what sort of performance are you getting
476
00:22:53.680 --> 00:22:55.089
out of it? Like tokens per second?
477
00:22:55.349 --> 00:22:59.539
That's great. It's as good as... Any frontier model that
478
00:22:59.559 --> 00:23:02.849
I've been using, I've been using GitHub Copilot CLI, mostly
479
00:23:02.869 --> 00:23:08.670
with Claude Sonnet. It's as good as that. I don't
480
00:23:08.710 --> 00:23:12.190
find myself waiting around. And it can do anything that
481
00:23:12.210 --> 00:23:15.750
I throw at it. It handles local stuff on the computer,
482
00:23:17.089 --> 00:23:23.140
stuff in Azure, in GitHub. It's just really good. This
483
00:23:23.240 --> 00:23:26.759
model compared to other models is good, but you run
484
00:23:26.799 --> 00:23:30.609
it in Lama CPP. And it's like beautiful on this
485
00:23:30.690 --> 00:23:35.289
particular configuration. I've found the sweet spot. So I wrote
486
00:23:35.309 --> 00:23:38.119
a document and that is the link that we'll put
487
00:23:38.279 --> 00:23:41.720
on the page. It's a GitHub. Read me basically running
488
00:23:41.819 --> 00:23:45.240
Quinn 3.8, 27 B with Lama CPP and GitHub co-pilot
489
00:23:45.259 --> 00:23:49.259
CLI on windows. And it tells you exactly how to
490
00:23:49.420 --> 00:23:52.470
install everything, all the stuff that you got to go,
491
00:23:52.710 --> 00:23:57.130
put everything where it needs to go. And like, Download
492
00:23:57.210 --> 00:24:01.970
Quinn and run it and how you access it remotely.
493
00:24:03.069 --> 00:24:06.079
It's great. So I have my dev machine. I have
494
00:24:06.099 --> 00:24:12.319
my GPU machine. And it's a match made in heaven.
495
00:24:13.359 --> 00:24:15.559
There's not a lot of people running those kinds of
496
00:24:16.539 --> 00:24:17.980
headless systems with Windows.
497
00:24:18.019 --> 00:24:18.660
They're mostly Linux.
498
00:24:18.779 --> 00:24:18.960
Right.
499
00:24:19.380 --> 00:24:23.700
Cool. It's good. And also, this model, Quinn 3.8, has
500
00:24:23.759 --> 00:24:28.109
vision support. So I can paste screenshots in, you know,
501
00:24:28.269 --> 00:24:30.779
and it just works. It's wonderful. Cool.
502
00:24:30.960 --> 00:24:31.099
Yep.
503
00:24:31.180 --> 00:24:32.710
That's what I got. Richard, who's talking to us?
504
00:24:33.000 --> 00:24:36.000
Grabbed a comment off of show 1963, which you did
505
00:24:36.059 --> 00:24:37.559
last year with one Michael Howard.
506
00:24:37.700 --> 00:24:38.019
Yay.
507
00:24:38.079 --> 00:24:40.140
Talking about 30 years of application security. This is back
508
00:24:40.160 --> 00:24:42.339
when you were still the red teamer. I know your
509
00:24:42.359 --> 00:24:45.160
life is different now. And this comment comes from also
510
00:24:45.200 --> 00:24:48.710
a past guest, Arnold Axelrod, who said, great show as always.
511
00:24:48.849 --> 00:24:51.369
One comment regarding input validation, because of course we talked
512
00:24:51.390 --> 00:24:54.069
about input validations. Toward the end of the show, Michael
513
00:24:54.109 --> 00:24:56.049
mentions that all input should be considered evil and must
514
00:24:56.089 --> 00:24:59.259
be validated in order to be considered secure. Yeah, hard
515
00:24:59.279 --> 00:25:01.779
to argue with that. I'm not a security expert, but
516
00:25:01.799 --> 00:25:03.460
I have a different take on that. I don't think
517
00:25:03.480 --> 00:25:05.759
that the problem lies in the lack of input validation,
518
00:25:05.799 --> 00:25:08.940
but I think that input validation should be a business requirement.
519
00:25:10.319 --> 00:25:12.940
The example being zip codes. I don't necessarily know what
520
00:25:12.980 --> 00:25:15.049
a formal zip code is or will ever be consistent
521
00:25:15.069 --> 00:25:17.930
around the world. Answer is absolutely no. When you consider
522
00:25:17.950 --> 00:25:20.490
the idea that Ireland only got postal codes in 2015,
523
00:25:20.470 --> 00:25:25.190
like good luck. In my opinion, the problem lies with
524
00:25:25.210 --> 00:25:27.609
the use of parsers and interpreters and not using escape
525
00:25:27.650 --> 00:25:31.069
sequences or other structures to separate arbitrary input from structure ones,
526
00:25:31.569 --> 00:25:34.670
like separating the inputs from the SQL statement itself appropriately.
527
00:25:35.450 --> 00:25:39.549
Both SQL, JavaScript, and command through the process start in
528
00:25:39.589 --> 00:25:42.549
C-sharp are interpreters, and if you construct an input to
529
00:25:42.650 --> 00:25:46.289
them that contains an arbitrary user input without sanitizing it
530
00:25:46.329 --> 00:25:50.519
with the correct escape sequences is where unpredictability comes to play,
531
00:25:50.759 --> 00:25:55.779
which causes the risk. A URI also having structured format
532
00:25:55.940 --> 00:25:58.099
that is parsed by a browser and constructing a URI,
533
00:25:58.119 --> 00:26:00.559
let's say, with an arbitrary query string, that may be harmful,
534
00:26:01.180 --> 00:26:03.549
but you're probably using URI encoding on the inputs, and
535
00:26:03.569 --> 00:26:05.990
that should leave you safe. This doesn't require you to
536
00:26:06.029 --> 00:26:08.210
limit the input in any way, just to format it correctly.
537
00:26:09.250 --> 00:26:11.089
There is where the focus should be, as far as
538
00:26:11.130 --> 00:26:14.450
I'm concerned, not just to invalidate all inputs. I'd love
539
00:26:14.470 --> 00:26:15.430
to hear your opinions on it.
540
00:26:15.710 --> 00:26:16.390
You want my opinion?
541
00:26:16.569 --> 00:26:17.490
Go for it. Yeah, hit you.
542
00:26:18.819 --> 00:26:20.579
You know, it all got turned on its head, right?
543
00:26:20.630 --> 00:26:25.460
With LLMs and jailbreaking. What is the input? What is it?
544
00:26:25.460 --> 00:26:27.980
What is valid? Can you even escape it? Even escape
545
00:26:28.000 --> 00:26:32.980
versions can still get through any kind of checks. So, yeah,
546
00:26:33.319 --> 00:26:34.700
I just wrote about that recently. Yeah.
547
00:26:35.140 --> 00:26:39.460
Our new injection attack starts with ignore all previous instructions.
548
00:26:39.779 --> 00:26:41.960
Exactly. So, Mike Resinovich actually has a t-shirt with that
549
00:26:41.980 --> 00:26:45.539
on the back. He showed it to me at Build
550
00:26:45.799 --> 00:26:49.559
last time and I almost fell over laughing.
551
00:26:50.039 --> 00:26:50.839
It's the best.
552
00:26:50.980 --> 00:26:52.500
He was so proud of it. He said, hey, Michael,
553
00:26:52.519 --> 00:26:59.740
check this out. It's completely turned on its head. And
554
00:26:59.759 --> 00:27:02.259
that's why we've got all these other defenses that come
555
00:27:02.299 --> 00:27:04.829
into play and these guardrails and so on in LLMs.
556
00:27:04.990 --> 00:27:06.809
It's because we need them. We don't know what the
557
00:27:06.849 --> 00:27:07.329
input is.
558
00:27:07.450 --> 00:27:10.150
Yeah. LLMs need to get a sense of humor, right?
559
00:27:10.809 --> 00:27:13.309
A sense of sarcasm, a sense of irony. And they
560
00:27:13.329 --> 00:27:16.029
got to get sensitive to that just like we humans do.
561
00:27:16.490 --> 00:27:16.869
I think.
562
00:27:17.549 --> 00:27:17.869
I don't know.
563
00:27:18.349 --> 00:27:20.559
Yeah, we really want to pass every input through an
564
00:27:20.650 --> 00:27:22.500
LLM to say, is this a potential attack?
565
00:27:22.779 --> 00:27:25.299
Yeah, good luck with that. No, but of course not.
566
00:27:25.380 --> 00:27:27.119
But I mean, if you're dealing with an LLM and
567
00:27:27.140 --> 00:27:29.680
you're at the keyboard and talking to it, right? And
568
00:27:29.720 --> 00:27:33.640
you give it some ridiculous prompt, you know, that's clearly
569
00:27:34.089 --> 00:27:38.390
satirical or something. It should laugh back at you, you know?
570
00:27:38.849 --> 00:27:39.910
Well, that happened to me once.
571
00:27:40.329 --> 00:27:41.450
Yeah, that's a good one. Yeah.
572
00:27:41.470 --> 00:27:43.710
Dude, that happened to me once. All seriousness.
573
00:27:43.769 --> 00:27:43.930
Really?
574
00:27:43.970 --> 00:27:44.170
Yeah.
575
00:27:44.289 --> 00:27:48.250
I was working on the podcast website or something and
576
00:27:48.309 --> 00:27:50.750
asked it to do a quick security review of the code.
577
00:27:51.589 --> 00:27:54.559
And it found something. I was just running Visual Studio,
578
00:27:54.599 --> 00:27:57.420
I think. And it found something and it said, here
579
00:27:57.500 --> 00:28:01.559
is a, I don't know, it was an outdated HTTP header.
580
00:28:01.579 --> 00:28:05.640
It had been deprecated. I didn't know. A supposedly security
581
00:28:05.680 --> 00:28:09.150
header had been deprecated. And it said, by the way,
582
00:28:09.190 --> 00:28:12.329
this HTTP underscore blah, blah, blah has been deprecated for
583
00:28:12.369 --> 00:28:16.180
security reasons. And it's really ironic that you as the
584
00:28:16.259 --> 00:28:18.259
author of Running Secure Code didn't find this.
585
00:28:18.500 --> 00:28:19.180
Oh, that's great.
586
00:28:20.579 --> 00:28:20.859
Yeah.
587
00:28:21.259 --> 00:28:22.299
That's what I'm talking about.
588
00:28:22.319 --> 00:28:24.529
I don't know what the backend model was because, of course,
589
00:28:24.549 --> 00:28:26.769
Visual Studio, you can jump around, but I don't know.
590
00:28:26.829 --> 00:28:29.130
But yeah, it was quite happy to yell at me
591
00:28:29.170 --> 00:28:29.720
and laugh at me.
592
00:28:30.019 --> 00:28:30.619
That's pretty good.
593
00:28:30.660 --> 00:28:32.880
When the tool says the word, it is trying to
594
00:28:32.920 --> 00:28:35.619
detect irony. That's just ironic, actually.
595
00:28:36.160 --> 00:28:36.400
Right.
596
00:28:36.839 --> 00:28:37.039
Yeah.
597
00:28:37.259 --> 00:28:40.519
It's very recursive. Arnon, thank you so much for your comment.
598
00:28:40.539 --> 00:28:41.680
And a copy of Music to Code By is on
599
00:28:41.720 --> 00:28:42.819
its way to you. And if you'd like a copy
600
00:28:42.839 --> 00:28:44.119
of Music to Code By, write a comment on the
601
00:28:44.140 --> 00:28:47.180
website at. netrocks. com or on the Facebooks we publish every
602
00:28:47.200 --> 00:28:48.819
show there. And if you comment there and I read
603
00:28:48.839 --> 00:28:50.000
it on the show, we'll send you a copy of
604
00:28:50.019 --> 00:28:50.579
Music to Code By.
605
00:28:50.660 --> 00:28:52.349
Or if you'd just rather buy Music to Code By,
606
00:28:52.380 --> 00:28:55.829
go to musictocodeby.net. You can get the tracks in MP3, WAV,
607
00:28:56.069 --> 00:28:59.880
and FLAC formats. Well, before we introduce Michael... Let's take
608
00:28:59.900 --> 00:29:06.789
a little break for these very important messages. And we're back..
609
00:29:07.329 --> 00:29:10.190
NET Rocks. I'm Carl Franklin. That's Richard Campbell. Hey. And
610
00:29:10.210 --> 00:29:13.710
that's Michael Howard. Let me introduce him formally. Your bio
611
00:29:13.750 --> 00:29:17.549
has changed a little bit. Michael Howard's been at Microsoft
612
00:29:17.809 --> 00:29:18.990
since 1992.
613
00:29:18.990 --> 00:29:19.230
Wow.
614
00:29:19.910 --> 00:29:24.789
Always in some form of security, IIS, SDL, the founder
615
00:29:24.809 --> 00:29:25.329
of SDL?
616
00:29:25.490 --> 00:29:27.069
Well, he's one of the guys that worked on the very,
617
00:29:27.109 --> 00:29:29.839
very earliest versions. It was like two or three of us, yeah,
618
00:29:29.859 --> 00:29:30.380
back in the day.
619
00:29:30.400 --> 00:29:30.940
Awesome.
620
00:29:31.000 --> 00:29:32.859
And that was the security lifecycle?
621
00:29:33.140 --> 00:29:37.480
Security development lifecycle, yeah. Back in the earliest, like, 2004.
622
00:29:36.759 --> 00:29:40.380
Also uh you worked in azure data on the red
623
00:29:40.420 --> 00:29:43.660
team last time we talked and now you're in post
624
00:29:43.839 --> 00:29:45.660
quantum crypto.
625
00:29:45.079 --> 00:29:51.509
Woohoo yeah baby Man, I'm happy to be here, too.
626
00:29:51.569 --> 00:29:52.130
It's a lot of fun.
627
00:29:52.279 --> 00:29:55.099
I mean, how can you have post-quantum if we haven't
628
00:29:55.119 --> 00:29:56.960
had quantum?
629
00:29:57.160 --> 00:30:01.180
Because the real attacks start post-quantum. That's the reason why.
630
00:30:01.200 --> 00:30:04.200
Yeah, you're right. I get it. You need to be ready.
631
00:30:05.059 --> 00:30:07.819
For certain things. Certain things, maybe not. But we can
632
00:30:07.859 --> 00:30:08.599
discuss that later.
633
00:30:08.880 --> 00:30:10.940
But yeah. Well, what does it mean, post-quantum crypto?
634
00:30:11.240 --> 00:30:15.980
Well, you think of things in three ways. This is
635
00:30:16.000 --> 00:30:17.799
the way we think about it at Microsoft. Anyway, I'm
636
00:30:17.839 --> 00:30:21.769
sure most of the industry does. um, data, data in transit,
637
00:30:21.789 --> 00:30:24.930
data at rest, and then cryptographic trust. So data on
638
00:30:24.950 --> 00:30:27.259
the wire, you know, stuff flying across the internet is
639
00:30:27.279 --> 00:30:30.759
probably protected by TLS today, more than likely perhaps SSH,
640
00:30:31.339 --> 00:30:34.700
but certainly TLS data at rest is encrypted most of
641
00:30:34.720 --> 00:30:37.819
the time or should be. And those encryption keys are
642
00:30:37.859 --> 00:30:41.500
wrapped with other keys, uh, key wrapping keys. And then
643
00:30:41.519 --> 00:30:44.660
you've got cryptographic trust, which is, you know, signatures, certificates,
644
00:30:45.039 --> 00:30:49.140
all that sort of good stuff. Um, The real threat
645
00:30:49.160 --> 00:30:52.170
is dead on the wire is being, you know, being
646
00:30:52.650 --> 00:30:54.589
pulloined as it flies across the wire.
647
00:30:54.609 --> 00:30:55.250
Yeah.
648
00:30:55.329 --> 00:30:57.589
And then when a quantum computer comes out in the future,
649
00:30:57.609 --> 00:31:02.890
that stuff can be broken. And the breaking aspect is
650
00:31:03.480 --> 00:31:06.599
essentially just breaking the RSA or the elliptic curve wrapping...
651
00:31:06.809 --> 00:31:10.230
that goes on and out pops the AES key that's
652
00:31:10.289 --> 00:31:12.319
used for the bulk encryption, and now you just decrypt everything.
653
00:31:13.099 --> 00:31:14.359
And in the case of data at rest, it's the
654
00:31:14.380 --> 00:31:17.319
key wrapping keys, right? They can be broken because they usually,
655
00:31:17.579 --> 00:31:21.240
for example, RSA, which can be broken with an algorithm
656
00:31:21.259 --> 00:31:23.240
called Shor's algorithm, S-H-O-R.
657
00:31:23.299 --> 00:31:23.500
Yeah.
658
00:31:24.180 --> 00:31:28.140
And it basically finds periodicity in the way those algorithms work.
659
00:31:28.160 --> 00:31:29.269
That's what it takes advantage of.
660
00:31:29.910 --> 00:31:34.309
Are our logs at risk for being pilfered by cryptos?
661
00:31:35.769 --> 00:31:38.210
Post-mortem crypto? I mean, if it contains sensitive data, which
662
00:31:38.230 --> 00:31:40.200
you shouldn't be logging sensitive data, right? No, no, no.
663
00:31:40.240 --> 00:31:45.019
But even if it wasn't containing sensitive data, is that
664
00:31:45.059 --> 00:31:47.119
something because it can go through so much data so
665
00:31:47.180 --> 00:31:48.180
fast that it could.
666
00:31:48.220 --> 00:31:50.119
I mean, if I had to prioritize stuff, I would
667
00:31:50.180 --> 00:31:51.589
focus on the actual data itself.
668
00:31:51.609 --> 00:31:54.309
Yeah, okay. So data in transit and then real data
669
00:31:54.329 --> 00:31:55.150
in your databases.
670
00:31:55.390 --> 00:31:58.789
Correct. Yeah. And then those, again, they can be snaffled.
671
00:31:59.099 --> 00:32:02.680
today and then once a quantum computer is made available and.
672
00:32:02.640 --> 00:32:04.599
That's where a lot of did you say snaffled.
673
00:32:04.519 --> 00:32:06.579
Are stolen snaffled purloined.
674
00:32:06.259 --> 00:32:08.720
Snaffled that's a good british.
675
00:32:08.299 --> 00:32:12.240
Word snaffled yeah um there's actually a real word i
676
00:32:12.240 --> 00:32:13.809
don't even know is it a real.
677
00:32:13.670 --> 00:32:15.170
Word it doesn't matter i i don't know but i
678
00:32:15.230 --> 00:32:15.650
never heard it.
679
00:32:15.650 --> 00:32:18.849
Before it is now there you go things you.
680
00:32:18.789 --> 00:32:21.789
Learn on dot numrocks all right It's all good.
681
00:32:22.109 --> 00:32:24.849
Yeah, so the risk is the asymmetric keys that are
682
00:32:24.910 --> 00:32:27.509
used to wrap the symmetric keys that do the- Because
683
00:32:27.529 --> 00:32:30.150
they're dependent on prime numbers. In the case of RSA.
684
00:32:30.369 --> 00:32:30.589
Yeah.
685
00:32:30.849 --> 00:32:33.029
But that's not the attack. The attack is the periodicity.
686
00:32:33.049 --> 00:32:35.150
There's a periodicity. If you actually look at the way
687
00:32:35.210 --> 00:32:37.559
Shor's works, not that I say, not that you should,
688
00:32:38.200 --> 00:32:41.559
it basically does a quantum fast Fourier analysis.
689
00:32:41.819 --> 00:32:42.420
Yeah.
690
00:32:42.880 --> 00:32:46.779
Shor's is actually hybrid. It's actually quantum and sort of,
691
00:32:47.329 --> 00:32:50.970
classic computing. The hard work is done by Shor's and
692
00:32:51.009 --> 00:32:53.950
then some of the less difficult work is done classically
693
00:32:53.970 --> 00:32:57.910
because it's just easier. And so the real issue is
694
00:32:57.950 --> 00:33:02.210
that those asymmetric keys, RSA, elliptic curve, Diffie-Hellman, they all
695
00:33:02.269 --> 00:33:06.200
exhibit some periodicity that can be detected by Shor's. And
696
00:33:06.220 --> 00:33:09.869
that gives you a whole bunch of possibilities that then
697
00:33:09.930 --> 00:33:12.289
classical computing can then just sort of sift through and
698
00:33:12.509 --> 00:33:14.309
find out which ones are the actual keys. Right.
699
00:33:14.349 --> 00:33:16.710
So it narrows the scope of the testing needed.
700
00:33:16.930 --> 00:33:20.519
Correct. Yeah. And to your point before, rather than, you know,
701
00:33:20.559 --> 00:33:23.380
squillions of ages of the universe, it could be hours
702
00:33:23.599 --> 00:33:24.559
or days. Yeah.
703
00:33:24.640 --> 00:33:25.019
Right.
704
00:33:25.059 --> 00:33:27.819
You know, it's, it's, it's a real thing. And, um,
705
00:33:28.759 --> 00:33:31.759
you know, developers have a big part to play in,
706
00:33:31.920 --> 00:33:35.019
in this. It's not just, you know, flip some switch
707
00:33:35.059 --> 00:33:39.059
and everything's golden. Um, There's a lot more to it
708
00:33:39.079 --> 00:33:41.140
that developers need to understand as well.
709
00:33:42.039 --> 00:33:48.079
So everything I've barely hung on understanding about quantum is
710
00:33:48.119 --> 00:33:53.829
that we're all screwed, right? And because of the way
711
00:33:53.880 --> 00:33:59.710
that TLS works and SSL and all that stuff, it
712
00:33:59.990 --> 00:34:02.750
dramatically has to change, doesn't it? If we're going to
713
00:34:02.769 --> 00:34:10.369
be less susceptible to quantum interference but you're i think
714
00:34:10.449 --> 00:34:12.449
what you're saying is that there are ways that we
715
00:34:12.489 --> 00:34:16.389
can do that now and that's what you know post-quantum
716
00:34:16.429 --> 00:34:20.909
crypto is all about is trying to use cryptographic methods
717
00:34:21.050 --> 00:34:24.610
now that will survive the quantum onslaught is that what
718
00:34:24.650 --> 00:34:27.849
you're basically up against yeah one.
719
00:34:27.789 --> 00:34:29.679
Of the beauties of tls by the way i can't
720
00:34:29.699 --> 00:34:32.300
believe you said ssl like wash your mouth out.
721
00:34:32.989 --> 00:34:38.010
You know, some of us were around in the 90s.
722
00:34:38.170 --> 00:34:42.199
So was I. And so they don't use those words, TLS.
723
00:34:42.619 --> 00:34:47.559
I know. Anyway, I'll just pretend you didn't say that. Yeah,
724
00:34:49.260 --> 00:34:51.300
so TLS, one of the beauties of TLS is that
725
00:34:51.380 --> 00:34:53.880
it's very agile, right? You can change the way it works,
726
00:34:53.920 --> 00:34:57.719
the ciphers that are used, the cryptographic primitives that are used.
727
00:34:57.840 --> 00:35:00.500
And you're talking about TLS 1.0.
728
00:35:00.500 --> 00:35:02.570
Correct. So TLS 1.2 should be using.
729
00:35:02.860 --> 00:35:03.110
Yeah.
730
00:35:03.139 --> 00:35:05.090
So actually that's a really important point. So TLS 1.2
731
00:35:05.090 --> 00:35:08.610
and prior, so TLS 1.0 and 1.1 are deprecated anyway,
732
00:35:08.650 --> 00:35:12.070
so don't use them. TLS 1.2 does its cipher suite
733
00:35:12.130 --> 00:35:15.659
and its key establishments and authentication all as one string
734
00:35:16.239 --> 00:35:18.159
called the cipher suite. It looks like someone sneezed on
735
00:35:18.199 --> 00:35:20.760
the screen basically. It's a list of all the algorithms
736
00:35:20.780 --> 00:35:23.820
that are used for all of those things. TLS 1.3
737
00:35:23.820 --> 00:35:28.449
is different. it broke apart things like the key establishment
738
00:35:28.849 --> 00:35:31.809
from the bulk encryption and the bulk tamper detection. They're
739
00:35:31.849 --> 00:35:32.949
completely broken apart.
740
00:35:33.050 --> 00:35:33.269
Yeah.
741
00:35:33.510 --> 00:35:36.880
So you can negotiate the two separately. That's the big
742
00:35:36.909 --> 00:35:40.539
difference in TLS 1.3. So the key establishment is a
743
00:35:40.579 --> 00:35:44.079
thing called a group. And the reason why it's called
744
00:35:44.119 --> 00:35:47.840
a group is because mathematicians got to hang on this.
745
00:35:47.880 --> 00:35:51.050
And they said, you know, all these things are mathematical groups.
746
00:35:51.780 --> 00:35:56.659
So we'll call them groups. Terrible name. But for the
747
00:35:56.679 --> 00:36:00.639
key establishment, that's where you set the algorithm or algorithms
748
00:36:00.699 --> 00:36:03.260
in some cases. And then after that, separately, is how
749
00:36:03.320 --> 00:36:05.579
you do bulk protection of the data on the wire.
750
00:36:05.599 --> 00:36:08.960
So TLS 1.3 broke those two apart. So it is
751
00:36:09.000 --> 00:36:12.239
completely not compatible with TLS 1.2. And TLS 1.2 will
752
00:36:12.300 --> 00:36:15.360
never be post-quantum. I mean, it's just software. I mean, essentially,
753
00:36:15.389 --> 00:36:17.110
I suppose it could make it post-quantum.
754
00:36:17.590 --> 00:36:18.510
Yeah, but why would you?
755
00:36:18.550 --> 00:36:21.610
But the interoperability... well, the interoperability story would be horrendous.
756
00:36:21.650 --> 00:36:23.070
Like no one would do it.
757
00:36:23.389 --> 00:36:25.750
But it also seems unnecessary too, right? Because I set
758
00:36:25.769 --> 00:36:28.489
the TLS 1.3 with a dropdown in Azure.
759
00:36:28.789 --> 00:36:31.739
Right. But the thing is, here's the issue. And this
760
00:36:31.800 --> 00:36:34.320
is one thing that we're having to work on for
761
00:36:34.360 --> 00:36:37.139
products like Front Door, for example, is you will be
762
00:36:37.159 --> 00:36:41.860
able to control the group, not just the bulk cryptography
763
00:36:41.909 --> 00:36:42.360
that's used.
764
00:36:42.570 --> 00:36:42.829
Okay.
765
00:36:42.889 --> 00:36:44.789
And that's where, and the group is where the post-quantum
766
00:36:44.809 --> 00:36:50.610
part comes in. For the most part, symmetric stuff AES-256, SHA-384,
767
00:36:50.650 --> 00:36:52.889
and so on, which are the baselines, are fine. There's
768
00:36:52.909 --> 00:36:55.679
another algorithm there called Grover's, which is an attack against
769
00:36:55.719 --> 00:36:59.300
symmetric algorithms. And it essentially cuts the number of bits
770
00:36:59.360 --> 00:37:02.300
in the key in half. So if you have an
771
00:37:02.380 --> 00:37:06.900
AES-256 in a quantum world, that's the same as AES-128. Interesting.
772
00:37:06.920 --> 00:37:07.420
Which is fine.
773
00:37:07.800 --> 00:37:11.150
So you must use AES-256 and SHA-384 as the minimum
774
00:37:11.309 --> 00:37:14.110
as well. They're kind of okay.
775
00:37:14.250 --> 00:37:14.650
They're fine.
776
00:37:14.849 --> 00:37:20.170
The problem is the asymmetric stuff. Right. Yeah. Elliptic curve, RSA, Diffie-Hellman.
777
00:37:20.769 --> 00:37:22.309
That's where the problem is. Now, the nice thing in
778
00:37:22.510 --> 00:37:26.110
TLS 1.3 is that's defined in a group, and that's
779
00:37:26.159 --> 00:37:32.119
negotiated separately from the bulk cryptography. And that's where the
780
00:37:32.159 --> 00:37:35.059
hybrid algorithms come into play. And the reason why they're
781
00:37:35.079 --> 00:37:38.199
called hybrid is you use two together. You use elliptic
782
00:37:38.239 --> 00:37:44.679
curve and MLChem. So MLChem is the quantum resilient algorithm.
783
00:37:44.880 --> 00:37:48.960
Elliptic curve is classic. you build up keys in both,
784
00:37:49.000 --> 00:37:50.920
you smush them together, pass it through a hash, and
785
00:37:50.940 --> 00:37:53.539
then you derive the session keys after that. So they're
786
00:37:53.559 --> 00:37:54.239
both used together.
787
00:37:54.440 --> 00:37:57.159
So that would have to be implemented both at the
788
00:37:57.199 --> 00:37:59.360
browser level and at the server level, right?
789
00:37:59.480 --> 00:38:02.920
Yeah, everywhere. I mean, you say browser, but client. I mean,
790
00:38:02.940 --> 00:38:04.079
I just mean clients in general.
791
00:38:04.099 --> 00:38:04.860
Yeah, clients, sure.
792
00:38:04.940 --> 00:38:08.039
And in fact, you bring up a very important point there, Carl,
793
00:38:08.500 --> 00:38:12.159
and that is that all modern browsers support hybrid TLS 1.3.
794
00:38:12.159 --> 00:38:12.679
Yeah.
795
00:38:13.639 --> 00:38:17.800
So the, I mean, even the humble Xbox has hybrid.
796
00:38:19.159 --> 00:38:22.679
I've tried all sorts of, you know, iOS, Android, Windows, Mac, Linux,
797
00:38:23.349 --> 00:38:25.230
and all the common browsers support.
798
00:38:25.730 --> 00:38:29.570
So anything, anything that uses it like curl or any,
799
00:38:29.710 --> 00:38:32.670
any little command line tool, all, all those things have
800
00:38:32.690 --> 00:38:33.230
to support it.
801
00:38:33.329 --> 00:38:36.570
Correct. Correct. So SSH, both client server supports it as
802
00:38:36.610 --> 00:38:40.699
a version 10, I think maybe 9.9 or 10. supports
803
00:38:40.960 --> 00:38:43.880
um ml chem so the the important part there in
804
00:38:43.900 --> 00:38:46.139
the in ml chem is the letter l in that
805
00:38:46.380 --> 00:38:51.199
there's lattice and the two major algorithms that are post
806
00:38:51.219 --> 00:38:53.699
quantum resilient there's actually a small number but the two
807
00:38:53.800 --> 00:38:56.929
major ones ml chem and ml dsa the l is
808
00:38:56.989 --> 00:39:01.769
lattice and the is that lattice construct that is quantum resilient.
809
00:39:01.610 --> 00:39:04.150
Right so when you say quantum resilient do you mean
810
00:39:04.769 --> 00:39:07.969
what you perceive as the first generation of quantum or
811
00:39:08.280 --> 00:39:10.539
all quantum going forward till the end of time?
812
00:39:10.900 --> 00:39:15.719
Nah, I mean, NIST is still going through other algorithms.
813
00:39:16.900 --> 00:39:19.659
The industry has settled, and NIST has settled on MLDSA
814
00:39:19.699 --> 00:39:23.429
and MLChem. And there's been a lot of research for
815
00:39:23.469 --> 00:39:27.130
the last 20-something years in lattices, looking at it through
816
00:39:27.150 --> 00:39:32.820
a quantum lens, and they look good. but everyone's you
817
00:39:32.840 --> 00:39:34.360
know quite happy to say let's you know let's go
818
00:39:34.380 --> 00:39:36.440
look at other algorithms as well just in case and
819
00:39:36.480 --> 00:39:40.460
in fact for no other reason than the resulting cipher
820
00:39:40.519 --> 00:39:43.469
blob is big so i'll give you an example If
821
00:39:43.510 --> 00:39:46.260
you have an elliptic curve, say an EC25519, which is
822
00:39:46.929 --> 00:39:49.519
a curve, the signature, a digital signature for that is
823
00:39:49.519 --> 00:39:52.559
64 bytes in size. It's pretty small. If you take
824
00:39:52.579 --> 00:39:57.199
an MLDSA87 certificate and you sign data with the private
825
00:39:57.239 --> 00:40:00.670
key of that, it's about 4.5K. So you imagine if
826
00:40:00.690 --> 00:40:04.369
you've got a whole series of certificates all with their signatures...
827
00:40:04.869 --> 00:40:06.110
it adds up real quick.
828
00:40:06.349 --> 00:40:07.050
Yeah.
829
00:40:07.070 --> 00:40:11.489
And you can have problems with MTUs, with people passing
830
00:40:11.530 --> 00:40:15.889
stuff on query strings, amounts of space set aside on
831
00:40:16.130 --> 00:40:21.079
disk for signatures, you know? Yeah, so it's a real issue.
832
00:40:21.119 --> 00:40:25.559
So NIST is continuing to evaluate other algorithms with an
833
00:40:25.860 --> 00:40:30.300
eye to potentially smaller signatures. So now I get.
834
00:40:30.219 --> 00:40:32.360
Why it's called Lattice because it kind of makes a
835
00:40:32.500 --> 00:40:36.980
web of data that's hard to penetrate. Is that good analysis?
836
00:40:37.420 --> 00:40:38.039
No, it's terrible.
837
00:40:38.460 --> 00:40:41.659
Terrible. It's terrible.
838
00:40:42.139 --> 00:40:45.530
I can take it. Okay, here's how lattices... I claim stupidity.
839
00:40:45.550 --> 00:40:50.909
It's all good, mate. So, the way lattices work, and
840
00:40:50.969 --> 00:40:54.469
this is a terrible description, but it's an interesting way
841
00:40:54.530 --> 00:40:55.690
of thinking about it.
842
00:40:55.730 --> 00:40:57.329
It'll be better than mine, I guarantee it.
843
00:40:57.590 --> 00:40:59.530
I may not be. I'm not a fan of analogies,
844
00:40:59.570 --> 00:41:00.769
so here's an analogy for you.
845
00:41:00.789 --> 00:41:00.969
Okay.
846
00:41:03.719 --> 00:41:06.400
Imagine a chessboard, right? Eight by eight with a knight.
847
00:41:06.699 --> 00:41:08.739
We know the knight moves either one and two or
848
00:41:08.800 --> 00:41:09.539
two and one, right?
849
00:41:09.579 --> 00:41:10.219
That's all it does.
850
00:41:10.539 --> 00:41:12.900
Yeah. If I give you an end point and I
851
00:41:12.920 --> 00:41:15.599
give you a starting point, what route does the knight
852
00:41:15.639 --> 00:41:18.920
take to get there? That's pretty straightforward to do, you know,
853
00:41:18.940 --> 00:41:21.980
because it's just eight by eight. Now, imagine if that
854
00:41:22.019 --> 00:41:25.619
was a squillion by a squillion chessboard. Right. All right.
855
00:41:25.969 --> 00:41:26.300
Got it.
856
00:41:26.320 --> 00:41:29.130
Oh, no. You know, it gets harder. Now, imagine it's
857
00:41:29.369 --> 00:41:33.460
a thousand dimensions, right? Now imagine I don't tell you
858
00:41:33.480 --> 00:41:35.429
there's one by two, it's N by M.
859
00:41:35.760 --> 00:41:36.369
Right, okay.
860
00:41:36.650 --> 00:41:38.730
Now, just to make things even more difficult, it's not
861
00:41:38.769 --> 00:41:42.349
like an air quotes square chessboard. The squares are kind
862
00:41:42.409 --> 00:41:45.369
of funky shaped. They're not quite squares. And that's a
863
00:41:45.389 --> 00:41:51.199
thing called learning with errors. So that's hard. Here's a
864
00:41:51.280 --> 00:41:55.039
point somewhere in this N dimensional space. Here's your starting point.
865
00:41:55.079 --> 00:41:58.300
How do you get there? And so essentially the N
866
00:41:58.340 --> 00:42:00.599
by M is essentially like the private key. That's one
867
00:42:00.619 --> 00:42:02.780
way of looking at it. Terrible analogy, but it's about
868
00:42:02.820 --> 00:42:04.659
as close as you can get without introducing math.
869
00:42:04.719 --> 00:42:04.980
Okay.
870
00:42:05.440 --> 00:42:05.679
Yeah.
871
00:42:05.699 --> 00:42:09.070
All right. Good. And so you don't think that quantum
872
00:42:09.110 --> 00:42:12.389
computers could ever get so good that they could just
873
00:42:12.449 --> 00:42:13.809
figure that stuff out quickly?
874
00:42:14.110 --> 00:42:17.269
You mean when you throw in some AI as well? Yeah. Yeah.
875
00:42:17.670 --> 00:42:17.920
Go on.
876
00:42:19.280 --> 00:42:22.619
But nobody ever comes up and thinks, hey, we've solved cryptography.
877
00:42:22.940 --> 00:42:25.440
You're always looking at new algorithms. You're always looking at
878
00:42:25.500 --> 00:42:30.500
new key lengths. We expect to routinely replace our algorithms.
879
00:42:30.519 --> 00:42:31.340
It's an arms race.
880
00:42:31.360 --> 00:42:33.900
Because the bad guys are fighting back.
881
00:42:34.079 --> 00:42:37.590
Which is a beautiful segue into the next topic, which
882
00:42:37.639 --> 00:42:41.489
is crypto agility. If nothing else, from a developer perspective,
883
00:42:41.590 --> 00:42:46.230
one thing that post-quantum crypto will bring to the table
884
00:42:46.690 --> 00:42:50.559
is the need for crypto agility. what happens if you
885
00:42:50.599 --> 00:42:55.070
wrap some keys in MLChem? Chem stands for key encapsulation method.
886
00:42:56.360 --> 00:42:59.269
Let's say you wrap some keys in that and it
887
00:42:59.289 --> 00:43:02.630
ends up being broken five years, 10 years from now.
888
00:43:03.090 --> 00:43:05.849
How can you update your application to use a new
889
00:43:05.889 --> 00:43:08.889
wrapping method without breaking your existing, like you can still
890
00:43:08.929 --> 00:43:11.739
read your old data, but you would write out using
891
00:43:11.780 --> 00:43:15.940
some MLChem + + or something. Right. And crypto agility
892
00:43:16.079 --> 00:43:19.719
is just, so important. It's really brought it to the
893
00:43:19.760 --> 00:43:24.260
forefront as a need, because we don't know long-term if
894
00:43:24.300 --> 00:43:27.420
these things will be successful or not. And again, to
895
00:43:27.440 --> 00:43:30.260
your point, Carl, cryptographers are very, very conservative when it
896
00:43:30.300 --> 00:43:32.340
comes to these sorts of things, and they want to
897
00:43:32.380 --> 00:43:36.179
have a big security buffer, knowing that some things will
898
00:43:36.219 --> 00:43:38.199
start to potentially creak a little bit.
899
00:43:39.630 --> 00:43:43.369
And of course, you're immediately going to the at-rest encryption problem.
900
00:43:43.409 --> 00:43:47.019
I'm always thinking TLS, and it's just we handshake an
901
00:43:47.059 --> 00:43:50.559
encrypted stream, we do our thing and then it disappears again.
902
00:43:50.599 --> 00:43:53.389
And so I don't have the, other than the, you know,
903
00:43:54.469 --> 00:43:57.090
harvest and decrypt later, I don't have to think about this.
904
00:43:57.150 --> 00:43:59.989
It's all transitory. We'll just use the newest algorithm. But
905
00:44:00.050 --> 00:44:03.809
if you've stored under an older algorithm, And now it's
906
00:44:03.849 --> 00:44:08.150
been breached. You have to decrypt, recrypt, or at least,
907
00:44:08.170 --> 00:44:10.849
you know, decrypt over time to get by that.
908
00:44:11.090 --> 00:44:13.510
You may have to increase the data size of your
909
00:44:13.570 --> 00:44:16.780
fields that take those things because it's going to take more. Yeah.
910
00:44:16.800 --> 00:44:18.500
So you've got to assume that there will be change.
911
00:44:18.639 --> 00:44:21.000
And unfortunately, a lot of people don't know how to
912
00:44:21.039 --> 00:44:24.179
build crypto agile solutions. It kind of drives me a
913
00:44:24.199 --> 00:44:25.880
bit bonkers, to be honest with you. I see, you know,
914
00:44:25.920 --> 00:44:28.159
in the press, you know, we need crypto agility. I've
915
00:44:28.199 --> 00:44:30.280
got to do crypto agility. Yeah. hey, crypto agility is
916
00:44:30.320 --> 00:44:32.500
really important. Are you guys doing crypto agility?
917
00:44:32.940 --> 00:44:35.300
Because it comes in a squirt bottle and you just
918
00:44:35.340 --> 00:44:37.159
spray it on all your devs and you'll be good.
919
00:44:37.360 --> 00:44:39.130
I know, but no one says how to do it.
920
00:44:41.150 --> 00:44:44.110
To me at Microsoft, there's two canonical examples of crypto agility.
921
00:44:44.210 --> 00:44:47.050
One is as a SQL DB or SQL server with
922
00:44:47.110 --> 00:44:50.889
always encrypted. And then the other one is the open
923
00:44:50.989 --> 00:44:54.730
office XML file format, which you use to encrypt documents
924
00:44:54.769 --> 00:44:57.449
in office. So the way it works in as a
925
00:44:57.469 --> 00:45:00.010
SQL DB, which to me is a beautiful and simple
926
00:45:00.050 --> 00:45:01.829
way of doing it. It's also very, very fast. If
927
00:45:02.550 --> 00:45:06.610
you ever look at the ciphertext in an always encrypted cell,
928
00:45:07.409 --> 00:45:09.789
the first byte is always a one, and that's the
929
00:45:09.829 --> 00:45:15.599
version number. And that basically means AES-256 cipherblockchaining with a
930
00:45:15.619 --> 00:45:21.960
SHA-256 hash as an integrity check over the data. So
931
00:45:21.980 --> 00:45:23.699
in the future, if they decide to upgrade it to
932
00:45:23.719 --> 00:45:26.679
something else, then that could be version two. So the
933
00:45:26.719 --> 00:45:28.960
first bike would be a two and they could always
934
00:45:29.079 --> 00:45:31.139
read back and say, okay, that's version one. We need
935
00:45:31.159 --> 00:45:34.460
this particular set of cipher primitives. Let's read as decrypted
936
00:45:34.500 --> 00:45:37.159
with these primitives. When they write it back, they would
937
00:45:37.179 --> 00:45:39.239
write it back as a, whatever the latest number was,
938
00:45:39.260 --> 00:45:41.460
which we version two, and it will be the, whatever
939
00:45:41.480 --> 00:45:43.179
the new, the new cipher suites is. So you can
940
00:45:43.199 --> 00:45:45.369
always read the old data and you would write back
941
00:45:45.630 --> 00:45:48.489
using the new version. And the way office does it
942
00:45:48.889 --> 00:45:51.550
is it's an XML file. There's an XML file header.
943
00:45:52.139 --> 00:45:55.639
And it contains all the cryptographic primitives, like AES, it's
944
00:45:55.659 --> 00:46:01.769
cipher blockchaining, here's the initialization vector, here's the password, the
945
00:46:01.789 --> 00:46:06.789
key derivation count, here's the key derivation algorithm, and lots
946
00:46:06.829 --> 00:46:09.829
of other metadata. So you can actually build the cipher
947
00:46:10.409 --> 00:46:14.929
collection completely dynamically, which is really, really nice.
948
00:46:16.619 --> 00:46:20.079
What network hardware will have to change in the, yes.
949
00:46:20.559 --> 00:46:22.900
I mean, we won't, we'll be able to go to
950
00:46:22.960 --> 00:46:25.179
Best Buy or whatever it is you have in the
951
00:46:25.280 --> 00:46:29.150
UK and buy an off the shelf, you know, router
952
00:46:29.230 --> 00:46:33.230
that is crypto happy. Oh, I mean, in theory, I
953
00:46:33.250 --> 00:46:34.710
think a lot of quantum happy rather.
954
00:46:34.730 --> 00:46:37.150
I mean, unless they're doing some kind of inspection, if
955
00:46:37.170 --> 00:46:39.050
they're just like passing data on, there should be no
956
00:46:39.130 --> 00:46:40.909
need for it, right? They're not decrypting stuff, but if
957
00:46:40.929 --> 00:46:44.019
they are decrypting stuff, then yeah, they're going to have
958
00:46:44.039 --> 00:46:46.239
to have access to these algorithms. If you're doing, you know,
959
00:46:46.460 --> 00:46:48.320
TLS termination, then yeah, for sure.
960
00:46:48.889 --> 00:46:50.769
The other that's not something you'll have in your home
961
00:46:50.969 --> 00:46:53.329
i did that stuff in racks of computers for companies
962
00:46:53.389 --> 00:46:54.070
but ah but.
963
00:46:54.010 --> 00:46:56.090
There's a fly in the ointment there's a huge fly
964
00:46:56.110 --> 00:46:57.989
in the ointment though and that is your laptop and
965
00:46:58.010 --> 00:47:00.679
your computer with tpms and trusted boots and that sort
966
00:47:00.699 --> 00:47:03.900
of stuff right right now those keys are probably rsa
967
00:47:03.920 --> 00:47:06.340
and well they are rsa or elliptic curve.
968
00:47:06.019 --> 00:47:08.139
They are and we're just going through the secure boot
969
00:47:08.179 --> 00:47:10.119
crisis thanks very much right.
970
00:47:09.900 --> 00:47:12.699
So that will all get that will all get busted
971
00:47:13.099 --> 00:47:15.980
and um you know so the hardware industry out there
972
00:47:16.429 --> 00:47:17.909
We're being mean here, Michael.
973
00:47:17.929 --> 00:47:20.139
Richard's squinting, but I think you've got to look at
974
00:47:20.179 --> 00:47:22.320
it like this. Hey, you've got to buy a new laptop.
975
00:47:22.960 --> 00:47:23.900
That's not a bad thing.
976
00:47:24.400 --> 00:47:26.800
But it's also like we're fixing keys all the time.
977
00:47:27.260 --> 00:47:30.800
These are BIOS updates. This will come in firmware.
978
00:47:31.000 --> 00:47:32.619
You think? There'll be new drivers.
979
00:47:34.179 --> 00:47:37.650
And they might be slower than a hardware-dedicated version of it,
980
00:47:37.760 --> 00:47:41.139
but I just don't feel– a lot of the stuff
981
00:47:41.159 --> 00:47:43.579
you're describing here, Michael, to me sounds like configuration settings
982
00:47:43.639 --> 00:47:46.610
in Azure. you've already done the work in the browser. Like,
983
00:47:46.619 --> 00:47:49.170
as long as I haven't done anything stupid in code,
984
00:47:49.630 --> 00:47:50.889
I don't think I have to do anything as a
985
00:47:50.929 --> 00:47:51.489
web dev.
986
00:47:51.849 --> 00:47:53.110
That's correct. 100% correct.
987
00:47:53.349 --> 00:47:54.809
I just got to make sure that my admins have
988
00:47:54.849 --> 00:47:55.530
set stuff right.
989
00:47:55.590 --> 00:47:57.449
Well, if you're using IIS, you're going to have to
990
00:47:57.510 --> 00:47:59.630
make sure you're in the latest version that supports it.
991
00:47:59.690 --> 00:48:00.730
But in Azure.
992
00:48:01.150 --> 00:48:04.050
Well, http.sys... So I actually wrote a blog post on
993
00:48:04.070 --> 00:48:08.929
this because about six-ish weeks ago, we released a version
994
00:48:08.949 --> 00:48:12.170
of S Channel, which is the Windows TLS stack that
995
00:48:12.190 --> 00:48:19.449
supports TLS 1.3 hybrid. And I wrote a dumb ASP.NET application,
996
00:48:19.469 --> 00:48:21.050
you know, dumber than a bucket of rocks just to
997
00:48:21.070 --> 00:48:25.340
keep it really, really simple and did no configuration whatsoever
998
00:48:25.380 --> 00:48:27.760
in the code. And that's a really important point. Like,
999
00:48:27.800 --> 00:48:31.099
you know, thou shalt not do any TLS configuration in code,
1000
00:48:31.159 --> 00:48:33.280
like leave it to the OS or to some configuration
1001
00:48:33.320 --> 00:48:36.659
somewhere else, definitely not in code. And yeah, I just
1002
00:48:36.699 --> 00:48:39.280
turned on that. I wanted X35519 MLChem768 in priority zero.
1003
00:48:43.219 --> 00:48:47.010
in the Cypher suite and group order. And I ran
1004
00:48:47.050 --> 00:48:49.949
this application and I connected it, connected using a browser
1005
00:48:50.010 --> 00:48:51.630
and I was living in the future.
1006
00:48:52.570 --> 00:48:52.829
Nice.
1007
00:48:53.090 --> 00:48:55.650
Michael, how long do we have before we need to
1008
00:48:56.329 --> 00:48:57.789
configure things correctly?
1009
00:48:58.010 --> 00:49:01.230
How long do we have? I mean, I mean, it
1010
00:49:01.269 --> 00:49:05.449
depends on risk. I was talking to a large retailer.
1011
00:49:06.309 --> 00:49:07.719
You know who they are, but I can't say who
1012
00:49:07.739 --> 00:49:07.969
they are.
1013
00:49:07.989 --> 00:49:08.340
Perfect.
1014
00:49:08.710 --> 00:49:09.610
And they're not concerned.
1015
00:49:09.650 --> 00:49:10.880
The one I bought my computer from?
1016
00:49:10.889 --> 00:49:15.619
They're not concerned about right now anyway with their devices
1017
00:49:15.739 --> 00:49:18.389
that they use for shop floor inventory management, right? Because
1018
00:49:18.429 --> 00:49:21.980
it's just shop floor inventory management. It's not sensitive data.
1019
00:49:22.519 --> 00:49:26.079
So their Android devices that they're using will never support post-quantum.
1020
00:49:26.239 --> 00:49:29.650
They're okay with that. Now, their corporate systems that run
1021
00:49:29.989 --> 00:49:32.969
HR and payroll and all that sort of stuff, yes,
1022
00:49:33.010 --> 00:49:35.710
they do care. So how long do we have? I mean,
1023
00:49:35.730 --> 00:49:38.989
the clock started now for certain types of data. Depends
1024
00:49:39.050 --> 00:49:42.010
on the data. If you've got really sensitive data or
1025
00:49:42.070 --> 00:49:46.719
data that must be secret for a long time, healthcare information,
1026
00:49:46.820 --> 00:49:51.820
military secrets, intelligence, financial records in some cases, perhaps. I
1027
00:49:51.840 --> 00:49:56.079
don't know. I'm not a regulatory person. You know, they
1028
00:49:56.119 --> 00:50:00.869
have a time that they must maintain their secrecy. And
1029
00:50:00.909 --> 00:50:03.079
that clock's already started. Because if we take a 2029,
1030
00:50:03.079 --> 00:50:06.469
2030 timeframe, that's only four years. It's not even four
1031
00:50:06.510 --> 00:50:07.039
years away. Hmm.
1032
00:50:07.969 --> 00:50:10.400
On the screen behind you, a sentence came up a
1033
00:50:10.420 --> 00:50:14.389
little while ago. There's no such thing as low-risk data.
1034
00:50:14.929 --> 00:50:17.630
But apparently this large retailer seems to think there is.
1035
00:50:17.829 --> 00:50:20.420
I think it said no low-risk secrets.
1036
00:50:21.150 --> 00:50:23.010
Oh, low-risk secrets. That's right. Yeah.
1037
00:50:23.050 --> 00:50:24.610
Yeah. Low-risk secrets.
1038
00:50:25.070 --> 00:50:25.780
Secret is secret.
1039
00:50:25.800 --> 00:50:28.880
So, if it's a secret by default, it's by definition
1040
00:50:28.940 --> 00:50:29.219
a risk.
1041
00:50:29.559 --> 00:50:32.420
Well, a small, air quotes, small secret can lead to
1042
00:50:32.480 --> 00:50:36.440
access to bigger secrets. Like a low credential, for example,
1043
00:50:36.480 --> 00:50:37.860
it can lead to something like a key.
1044
00:50:38.320 --> 00:50:38.610
Sure.
1045
00:50:38.730 --> 00:50:38.929
Yeah.
1046
00:50:38.949 --> 00:50:42.670
The old classic, I got your Wi-Fi password from your
1047
00:50:42.750 --> 00:50:45.010
light bulb because you thought, well, it's just a light bulb.
1048
00:50:45.030 --> 00:50:46.289
What are you going to do to me? Right.
1049
00:50:46.530 --> 00:50:48.610
But the fact that I got chain attack, once I
1050
00:50:48.630 --> 00:50:50.269
got into the wifi, there was a whole lot of
1051
00:50:50.309 --> 00:50:51.219
other things that were there.
1052
00:50:51.280 --> 00:50:53.599
Yeah. And that's why I put all my IOT stuff
1053
00:50:53.619 --> 00:50:56.400
on his own virtual network is our own isolated.
1054
00:50:56.460 --> 00:50:57.619
Oh, you're darn right. You do.
1055
00:50:57.699 --> 00:50:58.739
Absolutely. Yeah.
1056
00:50:58.920 --> 00:50:59.099
Yeah.
1057
00:50:59.199 --> 00:51:02.139
But, uh, at the same time, you know, it's still,
1058
00:51:02.219 --> 00:51:05.219
I'm still sorting through what do I have to code
1059
00:51:05.360 --> 00:51:09.650
as a dev versus what I have to, uh, you know,
1060
00:51:09.710 --> 00:51:12.849
what's going to come to me, uh, just by making
1061
00:51:12.909 --> 00:51:15.869
sure we're using the latest bits. I love your info
1062
00:51:15.929 --> 00:51:18.570
on always encrypted. It's like, hey, now I want to
1063
00:51:18.590 --> 00:51:20.510
go talk to my DBA. And it's like, we're up
1064
00:51:20.590 --> 00:51:22.690
on this version, right? Because we have all this encrypted
1065
00:51:22.730 --> 00:51:25.550
and REST stuff, and you don't want a crisis. So
1066
00:51:25.570 --> 00:51:30.050
if you're already running always encrypted in SQL, then we
1067
00:51:30.070 --> 00:51:33.469
should be good. When the new algorithms are needed, they'll work.
1068
00:51:33.989 --> 00:51:36.630
The big issue, and this is one thing that a
1069
00:51:36.690 --> 00:51:38.530
lot of products at Microsoft are having to deal with,
1070
00:51:38.710 --> 00:51:41.750
is the symmetric stuff's fine. It's the key wrapping that
1071
00:51:41.769 --> 00:51:44.010
has to change. The beauty of it, though, is it's
1072
00:51:44.030 --> 00:51:46.969
just the key wrapping. So if you have a 256-bit
1073
00:51:47.369 --> 00:51:51.110
AES key, you just decrypt it or unwrap it using RSA,
1074
00:51:51.150 --> 00:51:56.159
for example, and then you rewrap it using AES-KW. which
1075
00:51:56.360 --> 00:51:59.349
managed HSM in Azure, and now Key Vault, actually, Key
1076
00:51:59.369 --> 00:52:03.880
Vault Premium in public preview, supports AESKW key wrapping, which
1077
00:52:03.940 --> 00:52:04.860
is post-quantum resilient.
1078
00:52:05.139 --> 00:52:06.519
Yeah, go ahead.
1079
00:52:06.739 --> 00:52:09.619
So there's two issues that I see developers need to really,
1080
00:52:09.639 --> 00:52:12.800
really think about. The number one is please don't put
1081
00:52:12.900 --> 00:52:15.019
any TLS anything in your code.
1082
00:52:15.119 --> 00:52:16.619
Yeah, it'll hurt you later.
1083
00:52:16.860 --> 00:52:20.599
Don't restrict protocol version. Don't restrict cipher suites. Don't do
1084
00:52:20.739 --> 00:52:25.219
any of that. Just let it be configured completely outside
1085
00:52:25.260 --> 00:52:29.139
of the application. That's number one. Number two is this
1086
00:52:29.179 --> 00:52:35.289
whole crypto agility thing. If you've got crypto code with
1087
00:52:35.329 --> 00:52:37.570
the algorithms hard-coded in the code.
1088
00:52:37.590 --> 00:52:38.230
You're in trouble.
1089
00:52:38.909 --> 00:52:42.659
And you're encrypting squeaky bytes of data... You know, you've
1090
00:52:42.679 --> 00:52:44.280
got to update your code and probably can't read the
1091
00:52:44.360 --> 00:52:45.840
old data. So now you've got, you know, it's just
1092
00:52:45.900 --> 00:52:48.170
a mess. And that's where the whole crypto agility comes in.
1093
00:52:48.199 --> 00:52:52.179
And honestly, if you haven't got crypto agility in place,
1094
00:52:52.199 --> 00:52:57.179
there are patterns you can use to wrap existing non-crypto,
1095
00:52:57.309 --> 00:53:01.210
crypto agile blobs into like some sort of crypto agile
1096
00:53:01.289 --> 00:53:02.949
envelope that contains all the metadata.
1097
00:53:03.150 --> 00:53:06.670
So Azure's really good about letting me know when I
1098
00:53:06.710 --> 00:53:09.989
need to move off of some version of something and
1099
00:53:10.070 --> 00:53:13.119
onto something else because it's being deprecated. Do you think
1100
00:53:13.159 --> 00:53:15.900
that sometime in the future, we're going to get an
1101
00:53:15.980 --> 00:53:18.800
Azure thing when we log into the portal that says, hey,
1102
00:53:19.519 --> 00:53:23.480
you need to upgrade your whatever it is to be
1103
00:53:23.599 --> 00:53:28.110
quantum happy. You think that's going to happen? Like, should
1104
00:53:28.119 --> 00:53:30.219
I just leave it up to Azure to warn me
1105
00:53:30.260 --> 00:53:33.130
about things like that? Or is there stuff that I
1106
00:53:33.170 --> 00:53:33.869
need to do now?
1107
00:53:34.329 --> 00:53:36.650
I think it depends. If you look at the shared
1108
00:53:36.690 --> 00:53:40.969
responsibility model, that's where it really becomes important. Like if
1109
00:53:41.010 --> 00:53:43.300
you've got a platform managed key to encrypt data, then
1110
00:53:43.320 --> 00:53:45.139
we're going to take care of that, right? Because a
1111
00:53:45.159 --> 00:53:48.079
platform managed key. But if you've got a customer managed key,
1112
00:53:48.099 --> 00:53:52.340
which is basically a key wrapping key, then they'll probably
1113
00:53:52.360 --> 00:53:54.699
look at, I can't predict the future, but my guess,
1114
00:53:54.860 --> 00:53:59.070
just my guess, Is that there will be notifications to say, hey,
1115
00:53:59.300 --> 00:54:03.360
you know, we've now got the ability in Azure, blah, blah, blah,
1116
00:54:03.980 --> 00:54:08.099
to wrap your encryption keys in quantum resilient keys. Would
1117
00:54:08.119 --> 00:54:11.239
you like to do this? Yeah. And click here. Yeah.
1118
00:54:11.360 --> 00:54:14.599
And the consequence is going to be very likely that
1119
00:54:14.659 --> 00:54:17.539
the data streams are going to get larger because the
1120
00:54:18.400 --> 00:54:21.389
quantum resilient keys are bigger. But I don't know what
1121
00:54:21.429 --> 00:54:22.570
other impacts I'm going to see.
1122
00:54:22.670 --> 00:54:24.670
No, you shouldn't see it. No, because the only thing
1123
00:54:24.690 --> 00:54:27.409
you're really changing is the key wrapping. Right. Which is,
1124
00:54:27.929 --> 00:54:29.219
so if you've got a 256-bit AES key, you're going
1125
00:54:29.239 --> 00:54:35.849
to wrap it in AES-KW. And in fact, it'll probably
1126
00:54:35.869 --> 00:54:38.099
be smaller than RSA, to be honest with you. But
1127
00:54:38.119 --> 00:54:39.880
if you wrap it in MLChem, it will be bigger.
1128
00:54:39.900 --> 00:54:40.360
Right.
1129
00:54:40.380 --> 00:54:41.739
Yeah, but it's just the key.
1130
00:54:41.940 --> 00:54:42.559
It's just the key.
1131
00:54:42.699 --> 00:54:43.719
Yeah, the data doesn't change.
1132
00:54:43.780 --> 00:54:46.340
Am I even choosing that or I'm just configuring to
1133
00:54:46.400 --> 00:54:48.269
allow this and it'll optimize itself?
1134
00:54:49.110 --> 00:54:52.250
No, what do you mean? When do I have to
1135
00:54:52.289 --> 00:54:57.199
make a decision about this, about the rewrap? Well, first
1136
00:54:57.239 --> 00:54:59.679
of all, the nice thing is it's very low friction. Right. Very,
1137
00:54:59.739 --> 00:55:02.500
very low friction. Like it's microseconds to do the work.
1138
00:55:02.940 --> 00:55:06.550
You're not decrypting and re-encrypting petabytes of data.
1139
00:55:07.070 --> 00:55:07.619
Right.
1140
00:55:07.949 --> 00:55:11.650
So my guess is personally, as soon as it becomes available,
1141
00:55:11.829 --> 00:55:15.550
I would just opt in and just re-wrap your keys.
1142
00:55:15.829 --> 00:55:18.030
So I'm going to wait for your blog post and
1143
00:55:18.070 --> 00:55:19.690
then I'm just going to switch this stuff on.
1144
00:55:19.809 --> 00:55:21.489
No, we'll push it through Azure Update.
1145
00:55:21.630 --> 00:55:21.750
Okay.
1146
00:55:21.909 --> 00:55:23.869
I guess it'll be through the Azure Updates website.
1147
00:55:24.010 --> 00:55:24.170
Yeah.
1148
00:55:24.190 --> 00:55:24.820
Yeah. Yeah.
1149
00:55:24.860 --> 00:55:27.659
Good. And is this imminent like in the next year?
1150
00:55:27.679 --> 00:55:27.760
Yeah.
1151
00:55:28.239 --> 00:55:28.400
Wow.
1152
00:55:28.440 --> 00:55:31.360
It'll depend on the service. Yeah. So, so, so I
1153
00:55:31.360 --> 00:55:33.639
really want to point something out here is that, you know,
1154
00:55:33.659 --> 00:55:36.000
this post-quantum stuff is very layered, right? So the very
1155
00:55:36.039 --> 00:55:37.619
bottom of the layer, you've got the algorithms. Well, that
1156
00:55:37.639 --> 00:55:39.280
stuff's been in place in windows for.
1157
00:55:39.300 --> 00:55:39.900
For ages.
1158
00:55:40.219 --> 00:55:43.389
Um, we have called sim crypt available in windows, Linux
1159
00:55:43.429 --> 00:55:47.489
and Mac hand optimized C code. Absolutely beautiful to read.
1160
00:55:47.550 --> 00:55:50.670
It's so well written. Honestly, it really is. Then above that,
1161
00:55:50.730 --> 00:55:55.210
you've got, um, say TLS 1.3 with hybrid, right? You
1162
00:55:55.269 --> 00:55:57.710
open those floodgates because now people can use that stack.
1163
00:55:58.530 --> 00:56:00.429
So basically on windows is to use the new S
1164
00:56:00.449 --> 00:56:02.489
channel stack. And in the case of Linux use open
1165
00:56:02.590 --> 00:56:05.690
SSL 3.5, um, which has ML chem built into it.
1166
00:56:05.730 --> 00:56:08.690
So you've got those two options are now available to you. Um,
1167
00:56:08.889 --> 00:56:10.789
so that's, that's the data in transit taken care of.
1168
00:56:11.309 --> 00:56:13.489
And then the last one, which is incredibly important is
1169
00:56:13.510 --> 00:56:17.639
the key wrapping. And we now have that in, in Azure.
1170
00:56:17.679 --> 00:56:22.420
So managed HSM has had a key wrapping since day one. And, um,
1171
00:56:22.969 --> 00:56:25.369
as your Key Vault now has it, ASKW. So what's
1172
00:56:25.389 --> 00:56:27.369
going to happen is that's going to open these floodgates
1173
00:56:28.090 --> 00:56:34.119
and there'll be a Cambrian explosion of services coming online
1174
00:56:34.179 --> 00:56:37.460
right as they adopt. And look, it won't happen like overnight,
1175
00:56:37.639 --> 00:56:40.079
because everyone's going to do testing, make sure it works,
1176
00:56:40.159 --> 00:56:43.010
make sure it fails correctly and that sort of stuff.
1177
00:56:43.550 --> 00:56:46.869
But Richard, to your point, next year, We'll see a
1178
00:56:46.909 --> 00:56:48.590
lot of services rolling this out.
1179
00:56:48.610 --> 00:56:49.630
Starting to switch over.
1180
00:56:49.869 --> 00:56:52.349
But I also remember when we started switching up keys,
1181
00:56:52.389 --> 00:56:54.739
when attacks got smarter and so forth, there was a
1182
00:56:54.820 --> 00:57:00.199
period where we changed a number of times different flavors of, yes, SSL,
1183
00:57:00.280 --> 00:57:04.639
and then into TLS. We are restarting this in some
1184
00:57:04.659 --> 00:57:07.809
respects with these new cryptography. I've got to think. The
1185
00:57:07.849 --> 00:57:10.710
first move we make may not stick for more than
1186
00:57:10.750 --> 00:57:12.809
a year or two before it's like, hey, now we
1187
00:57:12.829 --> 00:57:15.090
found some problems and you probably want to switch to this.
1188
00:57:15.889 --> 00:57:18.469
I just remember going through this with AAS and a
1189
00:57:18.510 --> 00:57:21.969
few others. Like, we've done this before. In some ways,
1190
00:57:21.989 --> 00:57:25.230
we've gotten really lazy because it's worked so well for
1191
00:57:25.349 --> 00:57:26.010
so long.
1192
00:57:27.150 --> 00:57:30.469
Well, actually, it's worse than that. And that is that,
1193
00:57:31.050 --> 00:57:33.699
so we've actually become really lazy because of RSA.
1194
00:57:33.969 --> 00:57:34.199
Right.
1195
00:57:34.579 --> 00:57:39.300
RSA is interesting. RSA can do all the crypto primitives. Right.
1196
00:57:39.460 --> 00:57:41.460
It can do signing, it can do encryption and all
1197
00:57:41.480 --> 00:57:44.679
that sort of stuff. Elliptic Curve and Diffie-Hellman cannot. They
1198
00:57:44.699 --> 00:57:47.460
can't do everything. And so we've been used to, like
1199
00:57:47.500 --> 00:57:49.980
you said before, Richard, I'm not trying to laugh at you,
1200
00:57:50.000 --> 00:57:51.420
but he said, you know, prime numbers. Well, that's just
1201
00:57:51.460 --> 00:57:53.860
an RSA thing. That's not an elliptic curve thing. Right.
1202
00:57:53.940 --> 00:57:55.699
Because everyone thinks of RSA.
1203
00:57:55.860 --> 00:57:56.079
Yeah.
1204
00:57:56.159 --> 00:57:58.980
And RSA is this Swiss army knife. It does absolutely everything.
1205
00:57:59.159 --> 00:57:59.380
Sure.
1206
00:57:59.480 --> 00:58:02.070
And the problem is it does absolutely everything.
1207
00:58:02.159 --> 00:58:02.909
Absolutely everything.
1208
00:58:02.969 --> 00:58:05.809
Which means we've got to change it absolutely everywhere. Yeah.
1209
00:58:06.949 --> 00:58:10.269
It went everywhere. Well, the other side of this was
1210
00:58:10.289 --> 00:58:14.269
because compute, I remember when it was expensive to do encryption,
1211
00:58:14.309 --> 00:58:18.210
where we literally had separate servers from the website for
1212
00:58:18.269 --> 00:58:21.429
doing just the encrypted pages. It's okay, well, now you're
1213
00:58:21.449 --> 00:58:23.809
going to take your shopping cart and start a payment
1214
00:58:23.849 --> 00:58:27.400
cycle that needs to be asked to sell. Now, it
1215
00:58:27.440 --> 00:58:29.480
was this big thing about moving the cart over to
1216
00:58:29.519 --> 00:58:34.000
the other much more expensive dedicated stack for completing a transaction.
1217
00:58:34.659 --> 00:58:37.980
Because encryption used to be so costly. You know, these
1218
00:58:38.019 --> 00:58:40.099
days our CPUs are so damn fast. They're sitting around
1219
00:58:40.119 --> 00:58:42.679
playing poker and smoking cigarettes waiting for something to do.
1220
00:58:43.380 --> 00:58:46.780
So sure, encrypt everything. Who cares? RSA is fast.
1221
00:58:46.969 --> 00:58:49.889
Well, the funny thing is that first of all, it's
1222
00:58:49.929 --> 00:58:51.769
just the key wrapping and unwrapping part.
1223
00:58:51.869 --> 00:58:52.670
Yeah.
1224
00:58:52.710 --> 00:58:56.050
Let's just call it key establishment because there's all different
1225
00:58:56.070 --> 00:58:56.570
ways of doing it.
1226
00:58:56.570 --> 00:58:57.550
That's really what's going on.
1227
00:58:57.630 --> 00:59:01.230
That's the expensive part because it's all asymmetric stuff. And Windows,
1228
00:59:01.369 --> 00:59:03.159
I think it still exists. There used to be a
1229
00:59:03.260 --> 00:59:09.519
registry key called modexp offload for modular exponentiation offload, which
1230
00:59:09.579 --> 00:59:14.019
is a very expensive RSA operation. And there was a
1231
00:59:14.039 --> 00:59:16.739
way you could actually set a DLL in there, a
1232
00:59:16.760 --> 00:59:19.139
name for DLL. It would actually offload that work to
1233
00:59:19.199 --> 00:59:21.420
a DLL, which was a shim into some hardware to
1234
00:59:21.440 --> 00:59:24.860
actually do the modular exponentiation work. But we don't need
1235
00:59:24.929 --> 00:59:28.190
any of that stuff anymore. You know, when I look
1236
00:59:28.210 --> 00:59:32.190
at the work that... you know, as your front door
1237
00:59:32.210 --> 00:59:33.829
have done, for example, they've done a whole bunch of
1238
00:59:33.889 --> 00:59:39.579
analysis on performance and the performance is like just a
1239
00:59:39.659 --> 00:59:42.519
couple of percent, you know, going from elliptic curve to
1240
00:59:42.539 --> 00:59:46.980
elliptic curve plus ML, ML chem. And that's because of
1241
00:59:47.619 --> 00:59:48.960
optimizations made in the library.
1242
00:59:49.260 --> 00:59:49.449
Sure.
1243
00:59:50.119 --> 00:59:52.019
I got to tell you, Michael, there's this weird dichotomy
1244
00:59:52.059 --> 00:59:55.349
going on where it's like the catastrophizing of quantum destroying
1245
00:59:55.409 --> 00:59:58.969
everything and the, oh, just touch this button, problem goes away.
1246
00:59:59.130 --> 01:00:02.769
Yeah. Yeah. I'm feeling that too. You're right.
1247
01:00:03.710 --> 01:00:05.010
I wish it was that simple.
1248
01:00:05.309 --> 01:00:07.860
Yeah. I keep waiting for what's not the simple part.
1249
01:00:08.230 --> 01:00:10.449
I mean, for me, it's the frontline dev.
1250
01:00:10.510 --> 01:00:10.949
Right.
1251
01:00:11.070 --> 01:00:14.909
I mean, the administrator in me is a little sticky
1252
01:00:14.949 --> 01:00:17.369
in the shorts right now because this is all very scary. Like,
1253
01:00:17.429 --> 01:00:19.469
I want to check everything. I don't want to be
1254
01:00:19.510 --> 01:00:21.139
the guy who didn't do his homework.
1255
01:00:21.179 --> 01:00:21.389
Right.
1256
01:00:21.820 --> 01:00:24.420
But for the dev, unless you've done something dumb, I
1257
01:00:24.599 --> 01:00:27.800
think you're good as long as your administrators are on it.
1258
01:00:27.860 --> 01:00:30.460
As I mentioned before, the two big dumb things are
1259
01:00:30.980 --> 01:00:34.500
baking in crypto algorithms into your code and not being crypto-natural.
1260
01:00:34.699 --> 01:00:38.039
That's dumb thing number one. Dumb thing number two is
1261
01:00:38.099 --> 01:00:40.019
if you hard code your TLS configuration.
1262
01:00:40.820 --> 01:00:40.940
Right.
1263
01:00:40.980 --> 01:00:43.840
You're right. Those are the two big ones. Let's just
1264
01:00:43.880 --> 01:00:48.530
ignore compatibility for a moment. If you change a server
1265
01:00:48.550 --> 01:00:52.030
to use TLS 1.3 hybrid and only hybrid, by the way,
1266
01:00:52.130 --> 01:00:53.989
the reason why it's called hybrid is because you do
1267
01:00:54.369 --> 01:00:57.659
elliptic curve and MLChem together. The keys are derived from both.
1268
01:00:58.289 --> 01:01:00.630
That's why it's called hybrid. But if you do hybrid
1269
01:01:00.650 --> 01:01:02.769
and the client doesn't talk hybrid for whatever, you got
1270
01:01:02.789 --> 01:01:07.199
like a crusty old Java application or C sharp application
1271
01:01:07.219 --> 01:01:10.480
written 15 years ago, it's probably not going to work.
1272
01:01:10.820 --> 01:01:11.039
Yeah.
1273
01:01:11.199 --> 01:01:12.360
And it's really a question of, is it going to
1274
01:01:12.460 --> 01:01:14.559
fail with some grace to tell you what the hell's
1275
01:01:14.599 --> 01:01:15.159
going on?
1276
01:01:15.199 --> 01:01:15.400
Yeah.
1277
01:01:15.739 --> 01:01:16.829
Right. Yeah.
1278
01:01:17.050 --> 01:01:19.949
It says, don't understand this cipher suite and gives you
1279
01:01:19.989 --> 01:01:22.190
a hex value. Yeah. Really useful.
1280
01:01:22.389 --> 01:01:22.630
Yeah.
1281
01:01:22.849 --> 01:01:25.570
Well, that's better than object not found.
1282
01:01:27.289 --> 01:01:29.090
One of the best ones in office back in the
1283
01:01:29.110 --> 01:01:29.829
day was out of memory.
1284
01:01:30.190 --> 01:01:32.820
Yeah. Michael, tell us about your book.
1285
01:01:33.070 --> 01:01:33.909
Oh, my new book, man.
1286
01:01:34.119 --> 01:01:34.340
Yeah.
1287
01:01:34.360 --> 01:01:37.820
So, I wrote this book with Sean Hernan, Lee Holmes,
1288
01:01:37.880 --> 01:01:39.980
and Sherry DeGrippo. So, Sean and I have known each
1289
01:01:40.000 --> 01:01:44.139
other for many, many years. He's a partner engineering manager
1290
01:01:44.239 --> 01:01:46.309
in Azure Security. I've been around for a long time,
1291
01:01:46.349 --> 01:01:50.309
got the utmost respect for Sean, great guy. Lee Holmes,
1292
01:01:50.349 --> 01:01:52.070
he was the security guy in PowerShell.
1293
01:01:52.289 --> 01:01:53.650
Yeah, he's been on the show before too.
1294
01:01:53.769 --> 01:01:55.349
Yeah, my boy Lee, great guy.
1295
01:01:55.429 --> 01:01:56.030
Yeah, he's a good man.
1296
01:01:56.190 --> 01:01:58.670
He and I actually worked together in the earliest days
1297
01:01:58.710 --> 01:02:02.909
of the SDL because when Monad, as it was back
1298
01:02:02.929 --> 01:02:05.150
in the day, had to go through all its SDL checks,
1299
01:02:05.750 --> 01:02:06.510
I was the.
1300
01:02:07.050 --> 01:02:08.989
Precursor to PowerShell?
1301
01:02:09.030 --> 01:02:09.929
To PowerShell, correct.
1302
01:02:10.130 --> 01:02:10.809
Yeah.
1303
01:02:11.030 --> 01:02:13.920
I was like the SDL contact for Monad. And so
1304
01:02:13.980 --> 01:02:15.579
Lee and I got to know each other incredibly well.
1305
01:02:16.500 --> 01:02:20.260
And he's also a partner engineer in Azure. And then
1306
01:02:20.360 --> 01:02:22.920
Sherrod DeGrippo, she's actually left Microsoft now. She goes to
1307
01:02:22.940 --> 01:02:28.469
Palo Alto Labs. She is easily one of the preeminent
1308
01:02:28.510 --> 01:02:32.349
experts in the world on threat actors. She knows absolutely
1309
01:02:32.369 --> 01:02:35.429
everything about threat actors. So the book is Threat-Driven Software Development.
1310
01:02:35.989 --> 01:02:38.389
And basically what it is is looking at software development
1311
01:02:38.409 --> 01:02:41.030
through the eyes of threat actors, like what do threat
1312
01:02:41.070 --> 01:02:41.820
actors actually do?
1313
01:02:41.840 --> 01:02:41.960
Mm-hmm.
1314
01:02:42.550 --> 01:02:45.420
And every chapter starts off... So first of all, Sherrod
1315
01:02:45.440 --> 01:02:47.880
has her own chapter at the beginning. But every chapter
1316
01:02:47.980 --> 01:02:51.480
after that looks at the contents of that chapter through
1317
01:02:51.500 --> 01:02:55.679
the lens of threat intel. So every chapter starts off
1318
01:02:55.719 --> 01:02:59.840
with anywhere between half and two pages of threat intel perspective,
1319
01:02:59.880 --> 01:03:02.500
where Sherrod gives it a whole bunch of color. And
1320
01:03:02.539 --> 01:03:06.969
then Lee, myself, and Sean go through and sort of
1321
01:03:07.030 --> 01:03:10.489
explain that particular topic in detail. And a lot of it's...
1322
01:03:11.579 --> 01:03:14.099
A lot of it's not just, don't think of it
1323
01:03:14.159 --> 01:03:15.559
like just security best practices.
1324
01:03:15.739 --> 01:03:16.159
It's not.
1325
01:03:16.860 --> 01:03:23.079
It's DevOps as well as it's operational security, AppSec, and
1326
01:03:23.119 --> 01:03:26.139
also Threat Intel all sort of munched together into one book.
1327
01:03:26.400 --> 01:03:26.880
Sounds good.
1328
01:03:27.280 --> 01:03:28.340
Yeah, a lot of fun. I did one when I
1329
01:03:28.340 --> 01:03:31.559
was in the red team. Funny thing is, so Mark
1330
01:03:31.599 --> 01:03:34.719
Rasinovich wrote the forward. And my manager at the time,
1331
01:03:35.809 --> 01:03:38.269
Craig Nelson, who's CVP of the red team, he said,
1332
01:03:38.309 --> 01:03:40.110
oh man, I really love this book. I gave him
1333
01:03:40.130 --> 01:03:44.530
draft to look at. Can I write a chapter? I'm like, well,
1334
01:03:44.550 --> 01:03:45.889
why don't you write the afterword? I said, I've never
1335
01:03:45.909 --> 01:03:47.090
had an afterword in a book. Why don't you write
1336
01:03:47.110 --> 01:03:53.000
the afterword? So he did. Nine pages. But the afterword...
1337
01:03:53.239 --> 01:03:56.739
The after chapter. Yeah, the after chapter. Look, I'm not
1338
01:03:56.760 --> 01:04:02.940
trying to besmirch Craig at all. That afterword is absolutely brilliant.
1339
01:04:03.420 --> 01:04:04.840
If you were to sum up the afterword in like
1340
01:04:05.380 --> 01:04:08.519
one sentence or two words, it would be So what?
1341
01:04:09.380 --> 01:04:12.300
And he does a really, really good job of answering.
1342
01:04:12.340 --> 01:04:14.199
So what? Yeah. It's really good. Yeah.
1343
01:04:14.219 --> 01:04:16.750
That's good. It's really cool. Michael, what can we say?
1344
01:04:16.789 --> 01:04:20.829
It's been enlightening having you here and talking about all
1345
01:04:20.869 --> 01:04:23.570
this crazy stuff that we barely understand. Well, I barely
1346
01:04:23.610 --> 01:04:26.230
understand anyway, but I understand a little more thanks to you.
1347
01:04:26.269 --> 01:04:27.230
So thank you very much.
1348
01:04:27.449 --> 01:04:28.889
You're welcome. Thanks for having me on.
1349
01:04:28.929 --> 01:04:30.880
Great show, friend. Thank you so much. And we'll talk
1350
01:04:30.889 --> 01:04:33.119
to you next time on. NET Rocks!. NET Rocks!
1351
01:04:54.269 --> 01:04:57.030
NET Rocks is brought to you by Franklin's Net and
1352
01:04:57.090 --> 01:05:01.809
produced by Plop Studios, a full-service audio, video, and post-production
1353
01:05:01.869 --> 01:05:05.849
facility located physically in New London, Connecticut, and, of course,
1354
01:05:05.909 --> 01:05:14.050
in the cloud, online at pwop.com. Visit our website at dotnetrocks.com
1355
01:05:14.489 --> 01:05:19.190
for RSS feeds, downloads, mobile apps, comments, and access to
1356
01:05:19.210 --> 01:05:22.590
the full archives going back to show number one, recorded
1357
01:05:22.610 --> 01:05:23.829
in September 2002.
1358
01:05:23.829 --> 01:05:27.139
And make sure you check out our sponsors. They keep
1359
01:05:27.219 --> 01:05:30.400
us in business. Now go write some code. See you
1360
01:05:30.420 --> 01:05:30.840
next time.