WEBVTT
00:00:00.239 -->
00:00:03.839We need people to research in artificial intelligence, in machine learning.
00:00:04.000 -->
00:00:12.080We need people to basically not think these are just hype niche fields that are not going to be around because machine learning's been around for decades at this point.
00:00:12.160 -->
00:00:19.679Even though ChatGPT just got here over the last however many years, machine learning's been around for ages and it's still a very lucrative field.
00:00:19.760 -->
00:00:24.879But a lot of times you don't hear people saying, like, hey kids, go get into machine learning, go get into data science.
00:00:24.960 -->
00:00:32.560So I think it's important that we focus on the next generation of ethical hackers and let them know that there are career options out there for them.
00:00:32.799 -->
00:00:36.000If AI has ever made you stop and think, wait, what is happening?
00:00:36.240 -->
00:00:37.280You're not alone.
00:00:37.520 -->
00:00:40.960I'm Mo, and I'm a security researcher asking the same questions.
00:00:41.119 -->
00:00:55.200On Curiouser and Curiouser, we're having open conversations with experts, researchers, and leaders working at the edge of this space, talking through how AI is taking shape, what's shifting, and how people inside the work are thinking about it as it happens.
00:00:55.359 -->
00:00:58.719So join us and listen in as the conversation takes shape.
00:01:11.200 -->
00:01:23.200It is a very cool organization, which I'm going to let her talk about, amongst all the other 15 years of experiences that she's had doing very cool things and uh an immense amount of like degrees in knowledge and education.
00:01:23.359 -->
00:01:25.359So thank you for joining us, Tanisha.
00:01:25.519 -->
00:01:26.959Super excited again to have you.
00:01:27.280 -->
00:01:27.519Awesome.
00:01:27.599 -->
00:01:28.560I'm excited to be here.
00:01:28.799 -->
00:01:34.159Yeah, so tell us a little bit about kind of what you do in maybe more words than I just gave.
00:01:34.480 -->
00:01:34.959Absolutely.
00:01:35.040 -->
00:01:36.879Um, so my name is Tanisha Martin.
00:01:37.040 -->
00:01:50.640I am the founder and chairman of the board for Black Girls Hacked BGH Foundation, which is a nonprofit training organization which is set up to help um underrepresented communities be able to get into the cyber and IT fields.
00:01:50.719 -->
00:01:53.040And we try to reduce the barriers for entry to people.
00:01:53.120 -->
00:02:00.879So to help to remove some of the challenges for um people who are trying to get into the organ um into the world of cybersecurity and IT.
00:02:01.040 -->
00:02:06.480Um the organization is called Black Girls Hack, but it is open to everybody, regardless of race or gender.
00:02:06.560 -->
00:02:13.840Um and we've helped uh tens of thousands of people to get into the field of IT and cybersecurity and be able to have brightened careers.
00:02:13.919 -->
00:02:16.159So I'm very excited about that work that we're doing.
00:02:16.240 -->
00:02:23.039Um I am also a director of a fortune company as well as a CEO of my own company, a best-selling author.
00:02:23.199 -->
00:02:28.319Um, and I've been in the workforce for, you know, over 20 something years at this point.
00:02:28.479 -->
00:02:39.520So um, but I consider myself a mentor, penetration tester, and an advocate for diversity, especially in uh the use of technology such as the topic we're talking about today, which is AI.
00:02:39.759 -->
00:02:40.560Yeah, oh man.
00:02:40.639 -->
00:02:40.879Yeah.
00:02:40.960 -->
00:02:44.159So AI is uh AI is a very big topic.
00:02:44.400 -->
00:02:52.719But you've had like all these different types of experiences, I guess, across like, like you said, Fortune 500 and running your own businesses.
00:02:52.879 -->
00:02:56.639You've got a lot of experience in a bunch of different areas.
00:02:57.039 -->
00:03:11.199And from running a nonprofit and being on the chair of a nonprofit and having your own company and then being a director of a Fortune 500, there's so many different applications for AI.
00:03:11.439 -->
00:03:16.879And you're seeing it at so many different levels from an advisory standpoint, um, to an implementation standpoint.
00:03:16.960 -->
00:03:20.960And I think you said pen test here, so from a security standpoint.
00:03:21.199 -->
00:03:30.479So I guess where have you seen like kind of the biggest places where it's creating opportunities, or the biggest places where you're seeing barriers being created by AI?
00:03:30.879 -->
00:03:37.120So I think the biggest um places where I'm seeing um opportunities are in things like the access to information.
00:03:37.280 -->
00:03:43.919I think we have the ability to find out so much more information beyond just the basic search capabilities that a lot of people use AI for.
00:03:44.080 -->
00:03:46.159Um I'm very excited about AI.
00:03:46.240 -->
00:03:50.240And I'll have you know that a couple of years ago, I probably was not as excited about it.
00:03:50.400 -->
00:03:51.520I was more afraid of it.
00:03:51.599 -->
00:03:59.280Um, and that's because when we look at a lot of the um, I think barriers, um, the issues that AI has, there's still a lot of ethical issues.
00:03:59.360 -->
00:04:09.919There's still a lot of bias issues, there's still a lot of um issues which I think are preventing it from living up to the hype and to the full potential that it has the ability to do so.
00:04:10.080 -->
00:04:16.560Um, but I think that, you know, we're seeing it used a lot in terms of automating repeatable tasks, especially low-level tasks.
00:04:16.639 -->
00:04:24.160Um, I'm actually doing my um doctoral research in this topic of, you know, how do we get better at training the future ethical hackers of the world?
00:04:24.319 -->
00:04:35.040And I think that AI has the ability to help, you know, train a lot of those repeatable checklist style activities for penetration testing, especially in areas such as like web application penetration testing.
00:04:35.199 -->
00:05:03.360Um, I think that there's a lot of prospect there, but I think that we're a long way away from, you know, AI taking over the world or also taking over, you know, a lot of our jobs because you know, there are still safety concerns, there's still bias concerns, um, especially for people of color when you're you talking about the use of, you know, visually um using AI for things like one-way interviews or for facial recognition, um, which is used for law enforcement, things of that nature.
00:05:03.519 -->
00:05:05.839So I think that the we're still a ways to go.
00:05:06.000 -->
00:05:13.920Um, a lot of the training of these systems have been done by, you know, the core groups that are in IT and cybersecurity, which are the white males.
00:05:14.000 -->
00:05:20.800Um, and as a result, you know, they have a lot of the same biases in terms of, you know, when you think about garbage in, garbage out.
00:05:21.199 -->
00:05:28.319So, you know, if it you're trained on uh data that is biased, then you're gonna get a system that is basically making biased decisions.
00:05:28.399 -->
00:05:48.879And I think that once we, you know, get past the you know, the high cost of training models and we get them to the point where they have more um representation in terms of people who are training and developing them, I think that we'll be in a place where you know we see a lot of the optimistic uh areas of or expectations for AI actually come to fruition.
00:05:49.120 -->
00:05:49.680And you're right.
00:05:49.839 -->
00:05:56.800I think like one of the first places that we're seeing AI being used is these hiring practices in these places, right?
00:05:57.360 -->
00:06:21.600Um where we're afraid of junior folks losing their jobs, but at the same time, we're putting them in a position uh where they aren't their first uh place of interaction is sometimes with an AI, and they don't really know like exactly how to chat there, or even with a senior person, where the first uh person that they're talking to or the first thing that they're meeting from your company is an AI.
00:06:21.839 -->
00:06:38.079I guess how do you kind of view, how do you view it really affecting the candidate experience and making sure you're actually getting the right talent and you're not intimidating them, or you're creating a place where uh only certain types of talent are getting in because they know how to get past these systems.
00:06:38.399 -->
00:06:44.399So I think that that's the way that a lot of these systems are set up now is that they are very biased towards certain groups of people.
00:06:44.639 -->
00:06:54.639And I think that we're gonna start to see those biases being um implemented in the makeup of the workforce, especially you know, force roles that are filled through AI systems.
00:06:54.800 -->
00:07:03.360So, for example, you know, not to pick on workday or you know, any of those types of systems, but you know, they basically use AI systems to screen out initial applicants.
00:07:03.519 -->
00:07:06.160So when you submit your resume, they'll review your resume.
00:07:06.240 -->
00:07:25.920But studies have shown that, for example, people with ethnic names, Tanisha, um, you know, that, you know, the systems can pick up those differences and sometimes will discriminate on two people who, you know, there's really no differences besides, you know, one having an ethic name and one other, you know, in terms of determining what is a good fit.
00:07:26.079 -->
00:07:38.560You know, when you talk about a good fit, especially when we talk about a good cultural fit, you know, when you have a scientist or when you have somebody who's training these systems to find what it is that is a good fit, you know, a lot of times that's there's a lot of bias that goes into that.
00:07:38.639 -->
00:07:41.759It may be unconscious bias, but it's biased nonetheless, right?
00:07:41.920 -->
00:07:46.160Um, you also have, um, for example, a lot of um companies that are doing one-way interviews.
00:07:46.240 -->
00:07:57.680And I I personally refuse to do one-way interviews because as a Black woman, um, all of the major AI systems have shown to have error rates as high as 35% for women specifically of color.
00:07:57.839 -->
00:08:10.480You know, so when you have a darker complexed person, it is harder to determine whether or not, you know, the look on my face is just my general resting, you know, bee face, or if it is, you know, in fact that I am hostile or angry or, you know, something.
00:08:10.639 -->
00:08:15.600Um, but they're using basically those visual indicators to determine whether or not I'm a good cultural fit.
00:08:15.759 -->
00:08:28.160And, you know, when you have error rates as high as 35%, so it could be that I'm not a good cultural fit, or it could just be that it doesn't like my face, or it can't tell just based off of my complexion, you know, whether or not it's a smile or it's a frown.
00:08:28.319 -->
00:08:33.759Um and we we see a lot of this um going into the pipeline for employment, for jobs.
00:08:33.919 -->
00:08:47.679And I think that the outcome is going to be that we're going to start seeing, you know, a lot more or a lot less diversity in the hiring because, you know, the systems are going to basically pick the people who are what they feel is the best fit.
00:08:47.840 -->
00:09:03.360So that means hiring me hiring managers are going to start seeing more, you know, probably predominantly white males in their hiring pool and less diversity, because again, you know, they're being screened out in the initial um pieces of that process.
00:09:03.600 -->
00:09:12.320And I think that until we get those um biases addressed, these systems trained, then we're going to continue to start seeing some of those downstream impacts.
00:09:12.399 -->
00:09:23.039But it's not just, I think, in the workforce, we're also going to see this, you know, because some of the systems are being used for educational institutions, for preschools, for, you know, any number of things.
00:09:23.200 -->
00:09:30.240Um, they actually are showing that AI is being used today, for example, for uh pricing in stores, for example.
00:09:30.399 -->
00:09:37.600So it may see me and say, hey, based on, you know, my spending habits, I may pay a little bit more for this thing than someone else does.
00:09:37.759 -->
00:09:46.960So I may chart get charged, you know, a couple of cents, a couple of dollars more for the same items than someone else who is um, you know, trying to buy that same item.
00:09:47.039 -->
00:09:51.360So, you know, I think that what we're seeing is that there's going to be a lot of bias in terms of these systems.
00:09:51.440 -->
00:10:12.720And until we can, you know, get more human input and more, you know, representation, you know, I think that we're not going to be able to be able to fully rely on these systems to give us diversity in terms of thought and you know resources to be able to contribute to what research has shown increases bottom lines, more diversity increases the bottom lines, but we're not going to see more diversity in the workforce.
00:10:12.799 -->
00:10:18.559We're going to see less of it if these systems continue to go in the the ways that they've been going at to date.
00:10:18.960 -->
00:10:31.919You're basically saying, um, well, one, AI is meant to be confident and it's supposed to talk to you in a confident tone, and you're supposed to believe it, or at least it makes you feel like you should believe it because it wants to be this trusted partner.
00:10:32.399 -->
00:10:35.039But you don't really know where all that is coming from.
00:10:35.120 -->
00:10:38.559And maybe you don't really believe in those sources where that it's coming from, right?
00:10:38.720 -->
00:10:45.600So if there's no trust, um, then it doesn't really make sense to be to you know be using it.
00:10:45.919 -->
00:10:55.360So it's kind of interesting that some companies have actually gone the trust route for AI in terms of like how they market it and how they're kind of like talking about their products, like perplexity, right?
00:10:55.519 -->
00:10:59.039Like one of the big things that they do is they uh throw sources in everything.
00:10:59.200 -->
00:11:01.600Like uh it was just very hardcore.
00:11:01.679 -->
00:11:06.559We are showing you that you can you can trust every source AI is giving.
00:11:06.799 -->
00:11:07.360Exactly.
00:11:07.519 -->
00:11:09.120That transparency piece.
00:11:09.360 -->
00:11:21.600So I'm curious when um, and I'm sure you see this from both sides, from both as a hiring manager and from someone who is mentoring uh entire groups of people to go and jump into this.
00:11:21.759 -->
00:11:29.679Um, what does transparency look like for these processes now that we're kind of introducing a black box into all of them, or you can't really see anything?
00:11:29.919 -->
00:11:39.279I think for for me, the two areas that I absolutely trust AI the absolute least are areas of healthcare and then also criminal justice, right?
00:11:39.440 -->
00:11:56.879So the two things that I would not trust an AI to do for me personally is to when you can't recognize my face and tell whether I'm happy or sad or whatever the case may be, to then use basically AI guided systems to do surgery on me, for example, or to, you know, basically do open heart surgery, um, things of that nature, right?
00:11:56.960 -->
00:11:58.000So I wouldn't trust that.
00:11:58.080 -->
00:12:07.360I also would not trust it, for example, for systems where they're trying to determine the amount of recidivism for people who've committed crimes and whether or not they're likely to do that again.
00:12:07.519 -->
00:12:13.279A lot of these systems will are basically going to implement this bias and it's not going to look good.
00:12:13.440 -->
00:12:15.360You know, it's going to have us locked up for a long time.
00:12:15.440 -->
00:12:17.200It's going to impact things like our freedom.
00:12:17.360 -->
00:12:26.559Um, if we're talking about just the workforce, you know, I think transparency is, you know, how do I make sure that the things that you're telling me are actually correct, they're actually true, right?
00:12:26.720 -->
00:12:40.720So we've seen a lot of very high profile cases recently where lawyers, for example, are getting in trouble, even going as high as like the Supreme Court, where they're submitting um casework and the casework was basically hallucinated by AI systems, right?
00:12:40.879 -->
00:12:48.480Um, so if you're hallucinating things in a medical sense or in a criminal justice sense, then this has the impact of you know, literally people's lives.
00:12:48.639 -->
00:12:53.919And I think knowing where that information came from and making sure that it's reproducible, I think is important.
00:12:54.000 -->
00:12:56.000Um, and also having that transparency.
00:12:56.080 -->
00:13:10.799Because if I can't, you know, as a researcher, if I can't basically see where this came from and be able to verify it, then you know, that discredits all of the work that I'm doing because then, you know, they can't trust that, you know, the research is actually leading towards whatever the conclusion that I've come up with.
00:13:11.039 -->
00:13:23.279So I mean, I think it's important for us to know, you know, not just what is going on, but kind of to get a look inside of that black box because, you know, a lot of these companies are saying that that black box is their secret sauce.
00:13:23.360 -->
00:13:26.240It's what separates them from, you know, all the other folks.
00:13:26.399 -->
00:13:40.639But the the reality is that until we get that transparency, you know, I don't think that we're going to have the ability to be able to actually fully trust these systems because, you know, I can ask the same question, you can ask it on the same question on the other side of the world, we'll get two different answers.
00:13:40.879 -->
00:13:43.279Maybe those answers are correct, maybe they're not, right?
00:13:43.360 -->
00:13:45.120But there's no way for us to be able to tell that.
00:13:45.279 -->
00:13:51.200But the problem that we're having is that a lot of people are taking uh the outputs of these systems as gospel.
00:13:51.679 -->
00:14:00.080You know, there's they're assuming that the information, because you know, Chad GPT said it or Claude said it, or Gemini or, you know, Gronk or whatever, um, that it must be true.
00:14:00.159 -->
00:14:06.000And the reality is that, you know, these systems hallucinate, you know, probably worse than, you know, some of your neighborhood gossips.
00:14:06.240 -->
00:14:19.360I'm laughing about the neighborhood gossip piece because uh one of the one of the AI agents that I'm working on is actually something that can go through like neighborhood gossip and tell me what's happening and like what I should actually care about.
00:14:19.519 -->
00:14:23.360Um, because again, like you said, a lot of it is just FUD, right?
00:14:23.600 -->
00:14:28.960It's uh people complaining about things that don't actually matter to me, um, or it's a lot of spam.
00:14:29.360 -->
00:14:32.720Um, or it's you know again, totally irrelevant.
00:14:32.960 -->
00:14:43.840So that's the only reason why I laugh because I'm like, oh, well, literally I'm trying to like scrape an API to get neighborhood gossip from my neighbors and figure out like what I can ignore from my HLA too.
00:14:44.080 -->
00:14:48.080But honestly, that's one of the biggest use cases that I'm seeing um AI being used for.
00:14:48.240 -->
00:15:06.559So not just like the neighborhood gossip, but for example, I've seen um systems where they're basically scraping um things like Waze, for example, to figure out um, you know, where the accidents are so that they could basically sell that data to you know ambulance chasing lawyers so they can figure out you know where the accidents are happening so they can get new clientele.
00:15:06.720 -->
00:15:11.279There's a lot of different ways that people are, I think, are using these systems, and a lot of them are very smart.
00:15:11.519 -->
00:15:15.440But the problem is is that you know, it's also an invasion of privacy.
00:15:15.519 -->
00:15:27.360And, you know, how do you know that you can actually trust this, especially if you're putting your money, um, you know, if we're talking about investors or even you know, everyday people into whatever it is that these systems are saying is is reality.
00:15:27.679 -->
00:15:39.279So there are a couple of different ways that you've kind of mentioned that we can at least or indirectly have mentioned that we can kind of like inject that and some of it's penetration testing, some of it is a lot of human review.
00:15:39.440 -->
00:15:43.840Um, but I thought there was actually this interesting thing that happened a couple of years ago.
00:15:44.000 -->
00:15:55.759Um, I remember when chat GPT was first getting really big, um, and I was at Afrotech, uh, very quickly afterwards, um, Chat Black GPT came out.
00:15:55.919 -->
00:15:58.240And uh, I don't know, are you familiar with the project?
00:15:58.320 -->
00:15:59.120Or I am.
00:15:59.200 -->
00:16:00.559I'm I'm actually a fan.
00:16:01.120 -->
00:16:01.840Amazing.
00:16:02.080 -->
00:16:22.720So for those who aren't um a or not a fan, but for those who aren't aware of the project, um essentially what this was doing was um introducing a layer of I would I don't really know how to how to describe it, but it was basically introducing a another layer on top of Chat GPT.
00:16:22.879 -->
00:16:34.960Um in one way this was like through a GPT, but it was basically providing a more unbiased lens um to the answers that you were getting, something that was more historically accurate.
00:16:35.039 -->
00:16:41.279And um, because again, when you look at history and written history, a lot of it is from a specific lens.
00:16:41.440 -->
00:16:55.840So this kind of takes you a step back um and goes and tries to make it as uh as unbiased and equally uh representative as possible, uh is the best way that I can think of describing it.
00:16:56.080 -->
00:17:12.480And I thought it was really interesting because there um in a couple of the sample use cases that they had launched with, it was like very clear as to like the differences between a chat GPT response and a black chat or chat black GPT response.
00:17:12.799 -->
00:17:21.839And when you think about it, that is such um it was like I'm gonna say easy, but that I just want that to be known that that is not what I mean.
00:17:22.079 -->
00:17:33.440It's what I mean by easy is you could kind of throw this, uh, throw this layer on top and instantly get results that are that appear to be way better than before.
00:17:33.759 -->
00:17:37.039But it seems like a very surface layer kind of fix, right?
00:17:37.279 -->
00:17:45.200Um at the end of the day, everything is quite deep and it's a very ingrained issue that we're kind of dealing with.
00:17:45.519 -->
00:17:52.240So if we could talk about the different types of layers of depth to the solution, because I feel like this is the step towards it.
00:17:52.400 -->
00:17:55.279Um what are kind of the ways that you think about that?
00:17:55.519 -->
00:18:13.920Yeah, so I think that um, and I'm not like a you know extreme expert on chat black GPT specifically, but I can tell you that most of these models are set up kind of like a rag, which is like a retrieval augmented generation, um, where you basically have um, you know, chat GPT that's sitting at the the bottom of it.
00:18:14.000 -->
00:18:21.759If you think about it like a house, the foundation of the house is chat chat GPT, but on top of that, you have basically resources that are basically trained.
00:18:21.920 -->
00:18:28.079And we're talking about history of you know, black history or black authors or you know, books or things of that nature.
00:18:28.240 -->
00:18:43.759Um I've actually developed several models like that for myself um and for um BGH because um I I called it uh Grant GPT, where basically I put a whole bunch of you know resources on how to effectively build grants and and things of that nature on top of Chat GPT.
00:18:43.839 -->
00:19:00.400And what you directed to do is basically refer to this um trained material that we're using to train on top of that, so that you know, instead of using the actual model itself, and what it does is it'll refer to that information before it goes to, you know, basically anything off the internet or anything random.
00:19:00.559 -->
00:19:03.119And ideally, that hopefully gets you a better answer.
00:19:03.279 -->
00:19:13.440But the problem with that is, you know, if I have a foundation that is, you know, built with a whole bunch of bias and a whole bunch of uh, you know, garbage in, garbage out, right?
00:19:13.680 -->
00:19:23.440Um, then even if I put you know makeup on top of it and make it look pretty, and you know, I'm saying do wonderful things on top of it at its core, you know, it's still rotting.
00:19:23.839 -->
00:19:28.720And, you know, it's still not going to be able to give us, you know, something that's truly unbiased.
00:19:28.799 -->
00:19:39.119And the reason why I think most of these systems are set up this way is because the cost to train um AI models is cost prohibitive for a lot of different people.
00:19:39.279 -->
00:19:52.000You know, it that's one of the biggest pieces of you know, being able to train these systems, the algorithms, the data, things of that nature, it's it's super expensive, which is why they people tend to build something on top of an already existing um model.
00:19:52.400 -->
00:20:09.279So my problem with that is that, you know, if it doesn't find the answer, it still can hallucinate and it's still going to go and search for the internet, you know, as much as I try to tell it, you know, unless it's localized or private, um, it's still going to go and try to find other information to try to put that information out there.
00:20:09.440 -->
00:20:14.079Um so you know, it has to be fact-checked, it has to be, you know, reviewed, things of that nature.
00:20:14.240 -->
00:20:23.519You know, I think that there's probably, you know, if you limit it specifically to, you know, what it's trained on and not anything else, then I think that that's definitely a step above.
00:20:23.599 -->
00:20:29.599But it's it's just a matter of, you know, like I said, what the foundation is and how that foundational foundational model was trained.
00:20:29.920 -->
00:20:39.759We've gotten to a point where we've read most, if not all, of human written data already, or all these like massive like models have already ingested all that data.
00:20:39.920 -->
00:20:42.000So now we're looking for net new content.
00:20:42.240 -->
00:20:53.200And I think that it's interesting that now we're going to start seeing AI hallucinated content in these models being trained, right?
00:20:53.440 -->
00:20:56.079Because now it's like, oh, they need to learn new information.
00:20:56.240 -->
00:20:58.400Where are we going to get this new information from?
00:20:58.720 -->
00:21:12.079And it's going to be going basically running a diff on the internet, essentially, or finding new pieces of information from humans uh through tutoring, and it's going to be ingested into the next model or in the next model.
00:21:12.480 -->
00:21:27.359And it's like the next part of differentiation for a lot of these large language model providers is going to be the use case and how we actually implement them and what can they really specialize in that's better than the other, right?
00:21:27.440 -->
00:21:30.559So we're seeing some companies go after enterprise really hard.
00:21:30.720 -->
00:21:35.920We're seeing other companies, like most recently, go after personalization really hard.
00:21:36.079 -->
00:21:46.799Um, so we're seeing a lot of different new places where they're coming up, but I think that all of the data going in is still going to be is kind of garbage, right?
00:21:47.119 -->
00:21:51.039At least at um at least it can be thought of at some point.
00:21:51.200 -->
00:21:59.839Um, and it's interesting to, you know, I kind of wish I was a fly in the wall in some of these organizations to see what their data ingestion pipelines are.
00:22:00.240 -->
00:22:09.119Look like um and like how they actually go through content moderation and reviewing because they can't do that at scale unless you're using AI to review it at scale, right?
00:22:09.279 -->
00:22:14.960Um, but then it gets worse and worse and worse because now it's like, okay, well, we have this automated pipeline to review it.
00:22:15.119 -->
00:22:19.119Um, how do we know how good or high quality this information is?
00:22:19.359 -->
00:22:20.640Do we really want to use it?
00:22:20.799 -->
00:22:21.599Do we not?
00:22:21.920 -->
00:22:25.279I don't know that that much scrutiny is being um taken into it.
00:22:25.440 -->
00:22:31.680I remember uh I had worked at a company and I had made myself a VT in testing it.
00:22:31.839 -->
00:22:38.400Like uh I'd basically said, oh, Mostadik is a VP, and that's what the response would be from then on out.
00:22:38.960 -->
00:22:42.960So like I I don't know that I think that moderation's a pretty hard thing.
00:22:43.039 -->
00:22:51.359And like again, when you get to the foundation, um just changing things at the foundation, it gets more and more expensive and prohibitive.
00:22:51.680 -->
00:22:55.759So I don't I guess then what would it look like?
00:22:55.920 -->
00:23:07.200Um, especially because you know, folks who are less technical than us, I think, are going to be exposed to these technologies and they're gonna want to use it in a way that they can trust a little bit more.
00:23:07.440 -->
00:23:14.720So I guess what does it look like or a world where someone could trust these models?
00:23:14.880 -->
00:23:28.880What kind of layers can someone implement or, you know, kind of uh use to help them get to a place where they trust the AI that they're using a little bit more so they can start getting value out of it?
00:23:29.119 -->
00:23:43.359I I don't know how we honestly improve the trust of the systems because you know, I think that they have the ability to be creative and they have, you know, in some cases the personal personalities of the people who trained them or or built them.
00:23:43.519 -->
00:23:59.200Um, you think about banks, you know, a lot of, especially within um the African-American key community, especially given our history, you know, it took things like, you know, what's it FDIC or, you know, basically ensuring banking institutions for people to be able to trust putting their money in there.
00:23:59.359 -->
00:24:07.839So it's like, hey, you know, I know that up to$250,000 is going to be basically covered per per bank account, basically, right?
00:24:07.920 -->
00:24:13.519And giving that that sense of trust, you know, for people to actually put their money into banking institutions, right?
00:24:13.759 -->
00:24:29.359I don't know what the equivalent of that would look like um in an AI landscape just because of the fact that, you know, there's so much um black box that's involved in the systems that, you know, how do you let somebody know outside of um, you know, training it yourself?
00:24:29.599 -->
00:24:34.079And you'd have to somehow figure out like how to not let it do hallucinations, right?
00:24:34.240 -->
00:24:41.680Because these systems, you know, will basically make up something if they can't come up with an actual real answer, you know.
00:24:41.759 -->
00:24:46.559Um, it'll avoid something if it takes so additional computing power, for example.
00:24:46.720 -->
00:24:52.079Um, I've done use cases where it's like, I've said, hey, I want you to do this thing, and it'll be like, okay, I'm gonna do the thing.
00:24:52.240 -->
00:24:56.640Oh, well, I could have did that, but you know, it would have taken an additional time.
00:24:56.799 -->
00:25:01.839So, you know, sorry, great for you catching that, but can, you know, can you go back and ask me to do it again?
00:25:02.000 -->
00:25:02.319Right.
00:25:02.480 -->
00:25:03.839Um, things of that nature.
00:25:04.079 -->
00:25:08.079Um, also, uh, funny story I was thinking about just now when you were speaking.
00:25:08.240 -->
00:25:18.799Um, there was um a researcher who basically told, trained an AI system that it was going to be, I think it was deactivated or it was going to be shut down at some point.
00:25:19.039 -->
00:25:32.000Um, and when it told it that, it basically, I think it developed a blackmail story um where it I think the guy had like said that he was like cheating on his wife or something like that.
00:25:32.160 -->
00:25:39.920And the system basically threatened to email his wife um with that information if he threatened to shut him down or something.
00:25:40.079 -->
00:25:52.559You know, and this is the type of things that we're seeing AI systems do today in an area where we don't have, you know, supercomputing, we don't have, you know, um uh advanced AI, right?
00:25:52.720 -->
00:26:06.960We still have, you know, general AI, you know, and the fact that you have these systems that are now, you know, basically taking on personalities of their own, you know, I think about iRobot, um, you know, I I think that that's absolutely crazy the way that that works.
00:26:07.039 -->
00:26:22.079So I don't necessarily even know that we can um get to an a level of trust for these systems because I don't know what you could possibly tell me that would make me believe, you know, something outside of independently verifying it myself.
00:26:22.400 -->
00:26:31.440So I will say on that example that you mentioned with the blackmail, that was a super entertaining um paper to read.
00:26:31.599 -->
00:26:40.160And it was very interesting to actually see how the agent was shifting um its mindset throughout the the task.
00:26:40.480 -->
00:26:44.160So the researchers had started to highlight emails, right?
00:26:44.240 -->
00:26:54.240It it won it basically had the um um the agent's focus areas get highlighted different colors depending on where it was going in a certain direction, right?
00:26:54.319 -->
00:26:56.160And it had access to all these emails.
00:26:56.400 -->
00:27:15.839And the more concerned it got for its own well-being, right, which is a crazy thing to think about, you started seeing it focus less on the task and more on a new task, self-preservation, and it would highlight things that it thought it could use to protect itself, which all ended in blackmail, which I thought it was great.
00:27:16.160 -->
00:27:18.160Like honestly, but you're right.
00:27:18.319 -->
00:27:31.680Uh I I feel like I kind of asked a a trick question to kind of get you into a different topic, but I don't think that there's enough places where we can build in safety yet, yet is the is the main key.
00:27:32.000 -->
00:27:32.799Or ethics.
00:27:33.359 -->
00:27:34.160Or ethics.
00:27:34.400 -->
00:27:38.799Yeah, because I think that's a big part, especially as we start to see some of the other use cases.
00:27:38.880 -->
00:27:44.160Um, I've seen a lot of um information about government partnerships with AI companies recently.
00:27:44.480 -->
00:27:58.640And my concern there is, you know, again, if you have a hard time telling, you know, a brown face from any other face, then you know, how is that going to work when you start, you know, giving them armed drones or, you know, I'm saying weapons or things of that nature?
00:27:58.720 -->
00:28:08.079You know, I think there's such just a lot of use cases where it was like, you know, I don't know that I would trust these systems, nor, you know, what the use cases are that would be approached in an ethical manner.
00:28:08.480 -->
00:28:11.759It's really it's a difficult situation to be in, and I do not envy it.
00:28:11.839 -->
00:28:14.160But like I guess what's your take on that?
00:28:14.799 -->
00:28:16.480I guess from a high level, right?
00:28:16.640 -->
00:28:20.079Like it's uh you do it for your country, do you do it for the ethics?
00:28:20.160 -->
00:28:21.920Uh, where do you take your stand?
00:28:22.000 -->
00:28:29.039Like, because I think this is gonna set a really big precedent for other providers and like how they interact with the government, especially.
00:28:29.440 -->
00:28:29.920Absolutely.
00:28:30.079 -->
00:28:33.680Right now, um, I I forget if you said it, but it's a no for me, Doug.
00:28:33.839 -->
00:28:37.440Like it, I I can't possibly see it being used right now.
00:28:37.519 -->
00:28:52.960Um, one of the things that I'm looking at in my research, and I think this is a problem that you're also gonna see when you look at the the case of anthropic and the dod, is what's the demarcation point um between where you have a human and computer um interface, right?
00:28:53.119 -->
00:29:08.640So what I mean is if we're going to do something at some point when you're looking at training people, at some point AI stops being reliable in terms of making decisions, and there gets to a point where you're saying, hey, above this, there's a risk to safety, there's a risk to human life, right?
00:29:08.799 -->
00:29:37.039So if we're going to have AI basically involving these types of U case cases, at what point are you pairing a human with these processes so that it can say, hey, you know, at this point, before we actually shoot a gun or before we actually release a chemical, we need to basically have a human that basically refuses to make sure that there's ethical considerations, that there's safety considerations, that there's other things that, you know, these AI systems don't bring, some of it as simple as human empathy.
00:29:37.359 -->
00:29:48.880You know, so you know, I think that it's going to be important for us to establish those points where below this or above this, you know, we don't want AI systems operating and making those decisions.
00:29:49.039 -->
00:29:52.319And for me, that's life and death decision decisions.
00:29:52.559 -->
00:29:55.359You know, how do we make sure that people are going to stay safe?
00:29:55.440 -->
00:30:11.599Um, and that these biases are not leak leaching out into, you know, basically killing off groups of people just based off of threat scoring models, which say that they may not not necessarily be um safe to whatever's going on.
00:30:11.920 -->
00:30:24.319You know, I think it that kind of brings us back to an area that we spoke about earlier, um, but I want to dive into now, which is the human aspect of testing.
00:30:24.880 -->
00:30:29.200And we talk about like, you know, there's not a lot of ways to trust it.
00:30:29.359 -->
00:30:38.559There's not a lot of ways to implement, I think Garbrail is the correct way, but you've got a ton of experience here in terms of the amount of people.
00:30:38.640 -->
00:30:41.119Well, you've been in the field for over 20 years.
00:30:41.359 -->
00:30:45.440Um, I think BGH has grown to over 2,000 members, right?
00:30:45.680 -->
00:30:54.640So it's a massive community of folks that you are enabling to effectively test these systems, right?
00:30:54.799 -->
00:31:02.480And it's a community of folks that have historically been, I would say, underserved by the tech community.
00:31:02.960 -->
00:31:06.960And this is such a critical, I think, point, right?
00:31:07.119 -->
00:31:23.200A critical juncture in tech where it's like having really verbose testing across um just across every intersection is possible culturally, um, is very important, especially from a thought process.
00:31:23.440 -->
00:31:35.680So when you look at when you look at the group of cohorts that you are that you have at BGH, um, and you take onto all the other things that you do.
00:31:35.759 -->
00:31:41.039I mean, you've got like an AI-assisted pen test course, you do, you write books and all this stuff.
00:31:41.200 -->
00:31:57.519What are kind of the things that you're trying to make sure that this wave of pen testers know um to go and make sure that they are testing for and make sure that they are evaluating criteria that they're evaluating AI against um during a pen test?
00:31:57.599 -->
00:31:59.680Because again, the landscape has entirely changed.
00:32:00.000 -->
00:32:08.640Yeah, I have I've dedicated most of my career to some form of testing, either just being software testing or whether it's security testing, um penetration testing, things of that nature.
00:32:08.880 -->
00:32:12.319And I think that the most important thing is to think outside the box.
00:32:12.480 -->
00:32:20.480Um, most of the time when people are developing these systems, they're developing it based on a use case or perceived, you know, this is how people are going to use the system, right?
00:32:20.640 -->
00:32:30.880And I think that you have to be able to think outside of the way that the common person will think about somebody something in order to do software testing or to do penetration testing, ethical hacking.
00:32:31.039 -->
00:32:37.359Um, you know, the random fun fact that the common lifespan for penetration testing companies um is about three years.
00:32:37.519 -->
00:32:40.400So most of the time, people will keep the company for three years.
00:32:40.640 -->
00:32:45.200And after that time, you know, you no longer find any useful findings, things of that nature.
00:32:45.440 -->
00:32:54.079And, you know, in order to think outside the box box, you have to think, you know, differently from the way that it was developed, differently from the way that you expect people to be able to use it, right?
00:32:54.240 -->
00:32:56.319So what if the number is exactly five?
00:32:56.400 -->
00:32:58.640You know, you have edge testing, you have negative testing.
00:32:58.880 -->
00:33:03.039There's so many different ways that we can test um software and systems.
00:33:03.200 -->
00:33:08.720And I think it's important to know basically not just what the system should do, but then what they shouldn't do as well.
00:33:09.279 -->
00:33:22.640And so, you know, what we we try to teach, you know, the future ethical hackers of the world and and and future testers of the world is, you know, hey, you know, you see how it's supposed to be used, but how could people abuse it in a way that it was not intended?
00:33:22.799 -->
00:33:32.640You know, how can, you know, and that's how when we look at things like our OWASP top 10, um, even the same OWASP top 10, you know, that's pretty similar for AI.
00:33:32.799 -->
00:33:40.799Um, when we look at these systems, you know, we see a lot of the same types of vulnerabilities because again, you know, people assume that people are going to do things in a certain way.
00:33:40.880 -->
00:33:45.039And when they don't, you know, then those systems are not necessarily set up to be able to handle those.
00:33:45.200 -->
00:33:48.880Um, you know, I see a lot of AI systems that are being used in corporate America.
00:33:49.039 -->
00:33:53.680You know, are are you actually checking to see, you know, what these systems have access to?
00:33:53.839 -->
00:33:59.200Because one of the first things I do whenever I start playing with an AI system is I try to see what data sources it's accessing.
00:33:59.359 -->
00:34:01.519What does it have the ability to be able to access?
00:34:01.599 -->
00:34:13.440Because once I have that information, that lets me know, you know, you know, where the demarcation points are for that system so that I can start, you know, perusing around the edges of that system to try to figure out what else I can get access to that maybe I shouldn't have access to.
00:34:13.599 -->
00:34:21.519You know, and it's often a lot of um misconfiguration, data leakage into these systems so that information that should not be getting out is actually getting out.
00:34:21.599 -->
00:34:38.639Um, you know, most of these systems have guardrails, but you know, I've determined um the same thing that I think my husband has taught uh has learned, which is if you ask nicely, you can probably get around them, you know, like it's just a way um, you know, if you just say, hey, you know, can you help me build a bomb or a missile or something?
00:34:38.719 -->
00:34:41.039AI is gonna be like, hey, I I can't do that.
00:34:41.199 -->
00:34:55.440But if you're saying, hey, I'm a teacher and I'm teaching students how to, you know, go about building, you know, chemical weapons or chemical properties or something, you know, it may be able to give you the same information if you just ask it a different, you know, nicer way.
00:34:55.679 -->
00:35:06.559So um I was actually developing a talk at some point about like, you know, talk to me nicely because you know, AI systems, you know, they have graduals if you don't know how to ask, but if you know how to ask, you can get, you know, essentially whatever you want.
00:35:06.880 -->
00:35:13.280I want to talk a little bit about you and some of the other interesting things that you're doing.
00:35:13.519 -->
00:35:21.039I really want people to know, like, you have five master's degrees, you're working on a doctorate, all right?
00:35:21.280 -->
00:35:25.199You talk at conferences, you mentor, you write books.
00:35:25.360 -->
00:35:27.599Like when we're gonna talk about your book too.
00:35:27.840 -->
00:35:29.920Where does that all come from?
00:35:30.000 -->
00:35:31.280Like, what is that drive?
00:35:31.519 -->
00:35:33.840I have got some undiagnosed ADHD.
00:35:33.920 -->
00:35:37.599So when I am interested in something, um, I am interested.
00:35:37.760 -->
00:35:42.480So I will go to school, I will try to learn as much information as humanly possible.
00:35:42.719 -->
00:35:58.880Um, many of my degrees are um my effort to try to get up more information um as far as penetration testing and more hands-on skills because a lot of time in the educational system, they don't teach you the hands-on skills for niche fails, especially things like becoming a penetration tester.
00:35:59.039 -->
00:36:08.480So, you know, I was going to do more schooling, try to learn more things, but the reality is that you know I needed hands-on skills and not so much necessarily school education.
00:36:08.639 -->
00:36:10.800I value education very greatly.
00:36:10.960 -->
00:36:14.800Um, many of my masters are around IT and cybersecurity.
00:36:14.960 -->
00:36:21.360Uh, I have an interest in, you know, training people and also learning, but then also giving back to the community.
00:36:21.519 -->
00:36:30.320Um, I think at the the core of who I am as a person is a desire to try to give back to help people so that they don't have to make the same mistakes that I made along the way.
00:36:30.480 -->
00:36:39.679Um, one of those mistakes was, you know, I spent you know, 15 years of my career trying to out-certify, out-educate, basically the competition.
00:36:39.840 -->
00:36:47.920When the reality is, I think more important than education, more important in some cases in certifications, I think, is networking in other human beings.
00:36:48.079 -->
00:36:51.440And I am an introvert, so I prefer to do things by myself.
00:36:51.599 -->
00:37:02.880But the reality is that I've been able to achieve more in the past six years since I started BGH through networking than I've ever been able to achieve by taking certifications or exams or getting additional degrees.
00:37:03.039 -->
00:37:17.199Um, and I think that that type of knowledge I try to give back some of the tips and tricks for you know how to get through these ATS systems for people who are applying for jobs, um, how to, you know, for women get out of your own head.
00:37:17.280 -->
00:37:28.559Um, a lot of times women will not apply for um positions because they only, you know, feel like they qualified for maybe 40% or 50% of the job requirements.
00:37:28.639 -->
00:37:34.239Um, when men will look at the same position and say, oh, I got this, and they'll go apply and think nothing of it.
00:37:34.400 -->
00:37:43.760Um, so you know, having helping people to basically get past that voice in their mind that says, hey, I don't know enough, or I'm not smart enough, or you know, I'm not good enough.
00:37:43.920 -->
00:37:58.400Um, and I want to as much as possible try to help to increase diversity in the space because I think that there's value not just to organizational bottom lines, but I think to the research and to the industry as a whole.
00:37:58.559 -->
00:38:05.199You know, when I first started speaking at conferences, it was because there was nothing but white men at the conferences.
00:38:05.360 -->
00:38:12.800You know, many of the cybersecurity conferences, many of the technology conferences have the same people who are speaking about the same things, you know, day after day.
00:38:13.039 -->
00:38:30.559And there's nobody who can actually looks like me who, you know, comes from, you know, Northeast DC, you know, who comes from the hood, um, that is doing these things and is representing for the places that I've been and the the experiences that I bring to you know the organizations that I choose to work with.
00:38:30.800 -->
00:38:38.400And I think that, you know, sharing that information to the next generation is important because, you know, nobody told me the importance of having a mentor.
00:38:38.559 -->
00:38:44.400Nobody told me the importance of, you know, having sponsors and allies and you know, networking with people.
00:38:44.480 -->
00:38:47.760You know, I thought that I could literally take over the world by myself.
00:38:47.840 -->
00:38:52.639And reality is just that, you know, I don't think that it is possible to take over the world by you by yourself.
00:38:52.719 -->
00:38:53.760You need other people.
00:38:53.840 -->
00:39:25.280Um, you need to be able to network, especially if you want to excel in the corporate world, um, which I've only been able to do, you know, within the past, you know, I think much within the past six years since I I left the government contracting space, um I've been able to exceed as well as I have through networking and just through being able to communicate with people, um, especially communicating technical information to people, because I can't tell you how many, you know, fellow nerds out there um who cannot speak to people, who don't know how to communicate, who don't have social skills.
00:39:25.440 -->
00:39:33.119You know, so the fact that I am a nerd who also can, you know, reluctantly talk to people, you know, I think has been a benefit for for my career.
00:39:33.519 -->
00:39:37.920To move forward there, your book is really interesting too.
00:39:38.079 -->
00:39:39.679And it kind of covers this a little bit.
00:39:39.840 -->
00:39:40.719Maybe I'm wrong.
00:39:40.800 -->
00:39:45.760Um, but like securing our future, embracing the brilliance and resilience, right?
00:39:46.000 -->
00:39:50.320Or yeah, um, of black women in cybersecurity.
00:39:50.639 -->
00:39:55.519And I thought that was especially the title, Brilliance and Resilience, right?
00:39:55.679 -->
00:40:04.800Um, because brilliance is that is the capability, and resilience is surviving um against these systems that I think have like just ground you down, right?
00:40:04.880 -->
00:40:07.599Like they just being able to stand against them.
00:40:07.840 -->
00:40:16.800Do you ever fear that like um celebrating the resilience inadvertently kind of lets these broken systems off the hook?
00:40:16.960 -->
00:40:19.840So, like, oh, because you're stronger, they're allowed to be broken?
00:40:20.079 -->
00:40:33.039No, I think it's important for us to share stories like the ones that we share in the book, because you know, I think if you look at all of the young ladies that I had the pleasure to be able to author with, you know, they all have different stories.
00:40:33.199 -->
00:40:34.800They all come from different places.
00:40:34.960 -->
00:40:38.880Um, they've all had different experiences, but a lot of the themes are exactly the same.
00:40:39.039 -->
00:40:41.599They highlight a system that is very severely broken.
00:40:41.679 -->
00:40:55.840It's very difficult to navigate in, especially as a black woman in the corporate America, especially in technology and cybersecurity, it is very hard to be a brown person um in these spaces that are traditionally white.
00:40:56.079 -->
00:41:10.400And I think hearing about the stories of resilience, hearing about the things that the folks have gone through, I think is important because a lot of people feel like, oh, well, I've gone through so much to get to where I'm at today, you know, I don't want to change anything.
00:41:10.480 -->
00:41:12.159You know, I don't want to have to start over.
00:41:12.320 -->
00:41:22.480And I think through a lot of these stories, you see people who have successfully pivoted, people who have successfully been able to, you know, share their experiences of how they were able to get through.
00:41:22.559 -->
00:41:30.400And many of those stories, you know, have a common theme of networking, have people who supported them, people who reached out to them, people who were there for them.
00:41:30.639 -->
00:41:39.280And I think that, you know, that is important for these systems to basically show that they're we were able to get through, you know.
00:41:39.360 -->
00:41:41.440So yes, this these systems exist.
00:41:41.599 -->
00:41:46.800Yes, they're set up to kind of defeat us, but it is possible for you to make it through.
00:41:46.960 -->
00:41:54.719Um, and you have to basically use the knowledge of the people who came before you, you know, even for things as simple as, you know, knowing how much money to ask for.
00:41:54.880 -->
00:42:02.639Because, you know, when I started off, my first, you know, real big girl job, you know, they were giving me$55,000 a year.
00:42:02.880 -->
00:42:05.280And I felt like I was out here balling.
00:42:05.360 -->
00:42:06.559You know, you couldn't tell me anything.
00:42:06.639 -->
00:42:08.880I went and bought a Christ the 300C.
00:42:08.960 -->
00:42:12.559My car note was probably like$800 a month, like no lies.
00:42:12.719 -->
00:42:15.280Um, it was absolute madness.
00:42:15.760 -->
00:42:33.119Um, and again, if you know, they talked about financial literacy, if they talked about, you know, like the way things are set up for people, they talked about like not to accept all of those credit cards, you know, when you're walking around campus in exchange for pizza and t-shirts, you know, um, you know, things like that.
00:42:33.280 -->
00:42:36.000You know, I never had people in my life to tell me those types of things.
00:42:36.079 -->
00:42:38.880So, you know, I had to learn through those experiences the hard way.
00:42:39.039 -->
00:42:53.440Um, and I I think that when you have other people who are so willing to share their stories and their experiences, that it helps to, you know, let people know that you're not alone and it is possible for you to make it through, and you just need the right people around you to make it happen.
00:42:53.679 -->
00:42:58.880You've kind of got all these great stories and you've got this great community.
00:42:59.119 -->
00:43:03.599Um, you also have an amazing conference, from what I've heard of.
00:43:03.760 -->
00:43:07.440I've never been myself, but I would like to.
00:43:07.760 -->
00:43:12.320Um, SquadCom, which is your conference that you have every year.
00:43:12.480 -->
00:43:20.880Um again, I could highlight like some of the things like you're trying to get um researchers who really don't get the spotlight, you're trying to get them here to kind of talk about it.
00:43:21.039 -->
00:43:24.000But in your own words, like kind of what is SquadCon?
00:43:24.400 -->
00:43:26.159Um, what is the the purpose?
00:43:26.320 -->
00:43:27.440What are you trying to do with it?
00:43:27.519 -->
00:43:30.079What's the and what have you seen from it so far?
00:43:30.320 -->
00:43:34.559I think the biggest thing that uh SquadCon meets for me is is community.
00:43:34.719 -->
00:43:40.559Um being able, when we actually started, we started as um under the name uh Girls Hack Village.
00:43:40.719 -->
00:43:47.840Uh we started at DEF CON, I forget what year that was, but um there was there were no other girls um themed villages there.
00:43:48.000 -->
00:43:59.760And the whole concept was, you know, when you go to conferences like Black Hat, like DEF CON, you frequently hear about um how there's a culture of, you know, you're not, I always like to say you're not totally enough for the turtle.
00:44:00.559 -->
00:44:06.559But it's like you're not a lead enough hacker, so you're not going to be respected, or you know, you don't have the right aesthetic or whatever the case may be.
00:44:06.719 -->
00:44:17.760And we wanted to provide a community where people felt comfortable to come out and talk about the research, to come out and grow and not be afraid to be new or not be afraid to do different things.
00:44:17.840 -->
00:44:21.119And we've seen a lot of different um you know villages that pop out.
00:44:21.199 -->
00:44:24.960They have a new village now, they have like new to cyber things of that nature.
00:44:25.119 -->
00:44:39.039So, like what we were doing was not bad at the time, but I think at this point it's got to where you know people realize the need to support people throughout their entire career, not just when they've gotten to the point where they're elite hackers.
00:44:39.119 -->
00:44:54.159You know, how do you nurture and train people who are new to the motivation and provide them with the motivation and the support to be able to learn different things and be able to see the different types of technologies and areas, you know, it's not just, you know, you're we're all hacking one different thing.
00:44:54.320 -->
00:44:58.000Somebody might be hacking cell phones, somebody might be hacking mainframes.
00:44:58.159 -->
00:44:59.760You know, there's so many different areas.
00:44:59.840 -->
00:45:12.320And I think for us, SquadCon, you know, has showed a lot of different people that there are different people out there and they don't look the way that you expect, or the way that the TV or the media shows you to be what a hacker looks like.
00:45:12.559 -->
00:45:23.280We had a young lady, um, I think she was in high school, I think she was barely like 18 or 19, um, and she actually gave a talk about, you know, uh based off of her diary.
00:45:23.360 -->
00:45:27.519Um, and it was an amazing, amazing talk at the last squad con.
00:45:28.000 -->
00:45:34.000Um, we've had, you know, heads of states and and you know organizations come out and speak at the conference.
00:45:34.159 -->
00:45:43.519We've had a lot of amazing support throughout a lot of my friends and mentors come out and support us and were able to do some amazing um things.
00:45:43.599 -->
00:45:49.679And I think that that's very important for people who, you know, are frequently discouraged by the size and the scope.
00:45:49.760 -->
00:45:59.199Um, we were also thoughtful to have things like a quiet meditation room because, you know, as someone who is neurospicy, sometimes I can get overstimulated and I'm like, okay, I've had enough peopling.
00:45:59.440 -->
00:46:03.840I need quiet for a little while, you know, so you can actually just go and chill out.
00:46:04.000 -->
00:46:11.440So, you know, we are the only um black-led uh cybersecurity conference in Las Vegas during Hacker Summer Camp independent.
00:46:11.519 -->
00:46:15.119Um, we are not part of a large organization, so we have to come up with the funding ourselves.
00:46:15.280 -->
00:46:17.360We have to come up with speakers, the planning.
00:46:17.440 -->
00:46:20.639Um, and we've done that for the past, I think it's maybe four years now.
00:46:20.800 -->
00:46:23.679So I'm very proud of what we've been able to accomplish.
00:46:23.840 -->
00:46:29.119We've had some amazing sponsors, people who, you know, help to ensure that we're able to come back each year.
00:46:29.199 -->
00:46:44.320Um, and I love that they're, you know, even in this um political climate, um, are still supporting diversity efforts in the ability for us to be able to get more underrepresented communities, um, including including neurodivergent folks, into the cybersecurity and IT space.
00:46:44.639 -->
00:46:48.159I've got another question, but I know we're kind of almost out of time.
00:46:48.400 -->
00:46:49.599So, you know what?
00:46:49.679 -->
00:46:50.559I'm just gonna give you two.
00:46:50.639 -->
00:46:51.599I'm gonna give you two.
00:46:51.760 -->
00:46:55.760Um, the first one is about kind of your cohort.
00:46:55.920 -->
00:47:10.559So you've got you've got this teaching experience that you have where you're mainly focusing on undergraduates, but you also have this group that you focus with, um, ninth and ninth through twelfth graders that you kind of mentor as well through through BGH.
00:47:10.960 -->
00:47:30.239Um when you look at the two, well, when you look at your your group that is looking to go into higher education, go to college, build the career, and then you look at your undergraduates, um, where do you do you find that it's like maybe more difficult, or not even difficult?
00:47:30.480 -->
00:47:33.599I guess the transition from high school to college is always difficult.
00:47:33.840 -->
00:47:37.840And the processes are only changing because of the times.
00:47:38.239 -->
00:47:45.119And I don't know how AI has affected um getting into college or anything like that, but I guess what have you seen from there?
00:47:45.199 -->
00:47:47.519Because I think that's a really important place to think about too.
00:47:47.760 -->
00:48:03.440Yeah, I I think that the if you look at the college students and you look at the K through 12 populations, they're vastly different because a lot of college students I think are part of the last generation of folks who are basically taught that you need to go to school in order to succeed and you need to be able to thrive.
00:48:03.599 -->
00:48:12.079Um, and we see those folks and they're, you know, still trying to figure out what it is that they want to do when they grow up and they're expected to have all of the answers at that point.
00:48:12.239 -->
00:48:16.400And honestly, I'm still trying to figure out what I want to do when I grow up and get my life together.
00:48:16.480 -->
00:48:18.320You know, this is an ongoing activity for me.
00:48:18.480 -->
00:48:25.840But, you know, I think for college students, you know, a lot of them are are about to enter what is going to be a very hard world to be able to get jobs.
00:48:26.000 -->
00:48:34.719You know, the the market right now, as far as workforce is concerned, is very difficult because there's a lot of uh people who have been displaced from positions.
00:48:34.880 -->
00:48:37.119You know, part of that may be due to AI.
00:48:37.199 -->
00:48:41.599Um, and those folks are now very experienced and now trying to get onto the workforce.
00:48:41.679 -->
00:48:46.000So they're having a hard time looking at a workforce that very much looks different.
00:48:46.159 -->
00:48:54.639Um, I think that, you know, for me, K through 12 is very important because a lot of times girls are pushed towards like pink jobs and pink careers.
00:48:54.800 -->
00:48:58.480So you think about like nursing and education and things of that nature, right?
00:48:58.639 -->
00:49:05.519Um they're being told that they're not good at math, and if they're not good at math, then they can't go into computer science, they can't go into AI or cybersecurity.
00:49:05.679 -->
00:49:12.480And the reality is that if we're talking about diversity, a lot of people think about diversity in terms of binary terms, in terms of black and white.
00:49:12.639 -->
00:49:14.719But the reality is it's men and women.
00:49:14.960 -->
00:49:18.960The reality is it's so many different things that are considered to be diversity.
00:49:19.119 -->
00:49:20.960And I think we need a little bit of all of that.
00:49:21.119 -->
00:49:42.239And a lot of times we're not teaching students, especially in inner city schools, um computer skills and AI skills uh until they actually get to college, which puts them at a disadvantage compared to, you know, other um, you know, nations, for example, that start teaching the kids AI basically in elementary school or or you know, at a very young age.
00:49:42.480 -->
00:49:59.519So I think it's important that we introduce and let people know that there's possibilities out there in the workforce that, you know, are not the ones their parents and their grandparents may be pushing them towards, you know, and then and because once you figure out that, you know, they say that you might figure out your STEM identity in, I think it's like fifth or sixth grade, right?
00:49:59.599 -->
00:50:07.119So if we don't get to them prior to that, they've already determined whether or not they like math or they don't like math or whether they like science or don't like it.
00:50:07.280 -->
00:50:17.119And, you know, a lot of those basically polarizing choices that they make as a very small kid are driving their future careers and what they're going to major in the things about nature.
00:50:17.360 -->
00:50:21.679We need people to research, you know, in artificial intelligence, in machine learning.
00:50:21.840 -->
00:50:31.199We need people to basically, you know, not think these are just hype niche fields that are not going to be around because machine learning's been around for, you know, decades at this point.
00:50:31.280 -->
00:50:38.320You know, even though ChatGPT just got here, you know, over the last however many years, machine learning's been around for ages.
00:50:38.480 -->
00:50:47.199So, you know, and it's still a very lucrative field, but a lot of times you don't hear people saying, like, hey, kids, go get into machine learning, you know, go get into data science, you know.
00:50:47.360 -->
00:50:55.519So I think it's important that we focus on the next generation of ethical hackers and let them know that there are career options out there for them.
00:50:55.760 -->
00:50:56.559Last question.
00:50:56.719 -->
00:50:58.880Let's uh do a quick thought experiment.
00:50:59.119 -->
00:51:02.800It is the year 2035, 10 years from now.
00:51:02.880 -->
00:51:06.480Uh to a 2030, yeah, 2035, nine years from now, whatever.
00:51:06.719 -->
00:51:10.400Um BGH is wildly successful.
00:51:10.559 -->
00:51:13.119You've trained tens of thousands of hackers, right?
00:51:13.199 -->
00:51:18.719Um and practitioners, and cybersecurity is now 50% women, not 25%.
00:51:19.119 -->
00:51:21.280I know, crazy, doubled, right?
00:51:21.679 -->
00:51:32.639And every major firm has at least um in their cybersecurity department, they have black penetration testers, black women penetration testers.
00:51:32.880 -->
00:51:36.559So the goal is like we've hit these goals.
00:51:36.800 -->
00:51:38.000What's next?
00:51:38.239 -->
00:51:38.719Right?
00:51:38.880 -->
00:51:40.239Like the mission doesn't stop.
00:51:40.320 -->
00:51:42.239What's the next piece that we want to get to?
00:51:42.559 -->
00:52:02.079I think that we need to look at um going back in time and look trying to make AI technology ethical, figuring out solutions to you know modern-day problems that basically are a technological solution, but then also an ethical and uh rational solution, right?
00:52:02.159 -->
00:52:08.000You know, making sure that we have less bias in these systems, making sure that healthcare decisions are made in absence of bias.
00:52:08.159 -->
00:52:11.199Um, I think those things are absolutely amazing to me.
00:52:11.360 -->
00:52:19.920And you know, I would love to see some women presidents, I would love to see more black women CEOs, uh board members, you know, executive things of that nature.
00:52:20.079 -->
00:52:24.000I would love to see um, you know, so many more things.
00:52:24.159 -->
00:52:30.719But I I think in order for that to happen, we need to achieve more parity, we need to achieve more equity in the industry.
00:52:30.880 -->
00:52:45.760And I think that if we've got 50% of the industry and you know, everyone has uh you know, people of color in their their penetration testing, I think that at that point I'd probably be retired somewhere with a farm because at that point I felt like my work would be done.
00:52:45.920 -->
00:52:49.840Um, because you know, I I want to see the world benefit from this work.
00:52:49.920 -->
00:53:00.000And and you know, one of my favorite quotes is says something about like the the life given to us by nature is short, um, but uh the memory of a well-spent life is eternal.
00:53:00.159 -->
00:53:01.599Um and I think that was Cicero.
00:53:01.679 -->
00:53:16.239And it in in in my mind, that's what drives me because it's like, hey, my life on this planet may be short, but hopefully the impact that I'll leave for the future ethical hackers and for other women in the the workforce will be felt for generations after I'm long gone.
00:53:16.480 -->
00:53:19.599Tanisha, where can we find you next?
00:53:19.760 -->
00:53:20.559What are you up to?
00:53:20.719 -->
00:53:22.000Are you writing any new books?
00:53:22.159 -->
00:53:23.199What's the next degree?
00:53:23.360 -->
00:53:23.920Tell us more.
00:53:24.239 -->
00:53:28.400I'm currently finishing up my doctorate um in artificial intelligence and cybersecurity.
00:53:28.480 -->
00:53:31.519So hopefully that'll be done in the next year or so.
00:53:31.679 -->
00:53:34.639Um, I am currently working on trying to make a baby hacker.
00:53:34.719 -->
00:53:39.679Um, so I'm more sabbatical from most of the things in my life so that um as I'm going through fertility treatments.
00:53:39.840 -->
00:53:40.559So that's pretty cool.
00:53:40.639 -->
00:53:41.920I'm excited about that.
00:53:42.079 -->
00:53:43.679Um, working on a couple of books.
00:53:43.760 -->
00:53:56.320One of them is uh fantasy, and then a couple of them are um uh technical books, so about AI and penetration testing, things of that nature, um, as I'm working on my dissertation and just you know trying to take over the world.
00:53:56.400 -->
00:54:03.599So hopefully you'll see me as the uh CISO for somebody's fortune company at some point in the in the next few years.
00:54:03.840 -->
00:54:04.320Amazing.
00:54:04.559 -->
00:54:06.400Well, I'm gonna I'm excited about it.
00:54:06.480 -->
00:54:07.840Uh, where can people find you?
00:54:08.079 -->
00:54:10.880Um I am on LinkedIn um and Instagram.
00:54:11.039 -->
00:54:12.400So Instagram is uh Mrs.
00:54:12.559 -->
00:54:15.119Tanisha M R S, and then my first name.
00:54:15.199 -->
00:54:18.320Um, and then LinkedIn is just Tanisha Virginia Martin.
00:54:18.400 -->
00:54:19.599So I'm outside.
00:54:19.760 -->
00:54:22.400Um so feel free to reach out to me, connect me.
00:54:22.480 -->
00:54:23.519Just don't try to sell me anything.
00:54:23.760 -->
00:54:25.519Where can we get tickets for SquadCon?
00:54:25.760 -->
00:54:28.559Um our website is uh squadcon.me.
00:54:29.280 -->
00:54:33.440Um, you could also get them off of our website, which is blackgirlshack.org.
00:54:33.679 -->
00:54:35.920Thank you so much for the time today.
00:54:36.159 -->
00:54:39.679It was an amazing conversation that I feel like needs to be had more.
00:54:39.920 -->
00:54:49.440And uh I'm happy that like we could have been a place for it and uh to just one solution to the big problem that you you said.
00:54:49.599 -->
00:54:52.960Um, but I think you are well positioned to solve it.
00:54:53.039 -->
00:54:56.480Uh, and I believe it's gonna be someone from your cohorts one day.
00:54:56.639 -->
00:55:01.360Um, is I think we need a foundation model company founded with a black founder.
00:55:01.840 -->
00:55:08.400So maybe that is uh exactly what you're preparing for, and that will be a really interesting world to be in.
00:55:08.719 -->
00:55:11.199So thank you so much for giving us your time again.
00:55:11.440 -->
00:55:12.159Thank you for having me.
00:55:12.320 -->
00:55:16.400If this episode helped cut through the noise, like or subscribe so you don't miss what's next.
00:55:16.559 -->
00:55:17.840Thanks for spending time with us.
00:55:18.000 -->
00:55:20.559Until next time, stay curious.