WEBVTT

1
00:00:01.169 --> 00:00:04.790
<v Speaker 1>How'd you like to listen to. NET Rocks with no ads? Easy.

2
00:00:05.370 --> 00:00:08.789
<v Speaker 1>Become a patron. For just $ 5 a month, you get

3
00:00:08.890 --> 00:00:11.710
<v Speaker 1>access to a private RSS feed where all the shows

4
00:00:11.789 --> 00:00:14.890
<v Speaker 1>have no ads. $ 20 a month will get you that

5
00:00:15.109 --> 00:00:18.839
<v Speaker 1>and a special. NET Rocks patron mug. Sign up now

6
00:00:18.890 --> 00:00:36.520
<v Speaker 1>at patreon.dotnetrocks.com. NET Rocks Hey, and welcome back to. NET Rocks.

7
00:00:36.700 --> 00:00:39.399
<v Speaker 1>I'm Carl Franklin. And I'm Richard Campbell. And Michael Howard's

8
00:00:39.439 --> 00:00:41.770
<v Speaker 1>here with us. We'll have him jump in if he

9
00:00:41.799 --> 00:00:45.090
<v Speaker 1>wants to in the beginning. And we'll introduce him a

10
00:00:45.090 --> 00:00:47.789
<v Speaker 1>little bit later after the first bits. You know what

11
00:00:47.829 --> 00:00:49.869
<v Speaker 1>those are. Here we go. Here we go. 2020.

12
00:00:49.850 --> 00:00:53.950
<v Speaker 2>It's episode 20 when we're almost done, right? Like this

13
00:00:54.030 --> 00:00:56.850
<v Speaker 2>ends in 20 after 2026. So we got like six

14
00:00:56.909 --> 00:00:57.390
<v Speaker 2>more of these.

15
00:00:57.609 --> 00:01:00.429
<v Speaker 1>And it's becoming less and less interesting because most people

16
00:01:00.490 --> 00:01:01.729
<v Speaker 1>have lived through the last six years.

17
00:01:01.929 --> 00:01:05.599
<v Speaker 2>It's so current. Yeah. It's kind of now. Especially 2020,

18
00:01:05.599 --> 00:01:08.280
<v Speaker 2>because of course, what can you talk about except COVID?

19
00:01:08.439 --> 00:01:10.680
<v Speaker 1>Oh my God, COVID. All right, I'm done, Richard. What

20
00:01:10.700 --> 00:01:12.000
<v Speaker 1>about space? Yeah, thanks for playing, guys.

21
00:01:13.079 --> 00:01:14.700
<v Speaker 2>Well, the other thing I would talk about is this

22
00:01:14.769 --> 00:01:16.829
<v Speaker 2>is when the UK officially leaves.

23
00:01:18.450 --> 00:01:21.109
<v Speaker 1>The EU. Oh, there's more news, but COVID is the

24
00:01:21.150 --> 00:01:24.189
<v Speaker 1>big one. George Floyd. It is the big one, yeah.

25
00:01:24.209 --> 00:01:29.760
<v Speaker 1>George Floyd killed. Big, big reaction to that that sparked

26
00:01:29.900 --> 00:01:34.700
<v Speaker 1>off a lot of stuff. Joe Biden beat Donald Trump. Yes, there,

27
00:01:34.819 --> 00:01:39.519
<v Speaker 1>I said it because that's the truth. Worldwide economic collapse

28
00:01:39.579 --> 00:01:43.560
<v Speaker 1>caused by COVID. Lockdowns. Yeah, it's just stall. It was

29
00:01:43.609 --> 00:01:47.109
<v Speaker 1>just horrible. Donald Trump was impeached for the first time. Oh,

30
00:01:47.129 --> 00:01:49.790
<v Speaker 1>in the first year. I was at the end. A

31
00:01:49.849 --> 00:01:53.189
<v Speaker 1>lot of wildfires in Australia and Western US. The terrible ones.

32
00:01:55.549 --> 00:01:58.989
<v Speaker 2>Know about and now and today it's really relevant in

33
00:01:59.030 --> 00:02:05.049
<v Speaker 2>september the second nagorno-karabakh war so this is between azerbaijan

34
00:02:05.209 --> 00:02:08.990
<v Speaker 2>and armenia this is an enclave that normally is controlled

35
00:02:09.030 --> 00:02:12.280
<v Speaker 2>by armenia but the azerbaijanis wanted it and they attack

36
00:02:12.360 --> 00:02:14.379
<v Speaker 2>and so the azerbaijanis are the ones with the oil

37
00:02:14.419 --> 00:02:18.159
<v Speaker 2>money and they're muslim the uh the armenians are predominantly

38
00:02:18.180 --> 00:02:22.039
<v Speaker 2>christian uh the azerbaijanis attack and to be clear this

39
00:02:22.060 --> 00:02:24.719
<v Speaker 2>is a very complicated conflict like it's gone on literally

40
00:02:24.740 --> 00:02:27.169
<v Speaker 2>for centuries But it was a drone war. It was

41
00:02:27.229 --> 00:02:28.750
<v Speaker 2>arguably the first drone war.

42
00:02:28.969 --> 00:02:29.289
<v Speaker 1>Wow.

43
00:02:29.710 --> 00:02:36.259
<v Speaker 2>The Azerbaijanis bought Turkish Bayraktar drones. They had bought some

44
00:02:36.300 --> 00:02:41.039
<v Speaker 2>of the surveillance equipment from the Israelis. And so they

45
00:02:41.060 --> 00:02:45.639
<v Speaker 2>had continuous surveillance. They were using drones for attack. They

46
00:02:45.759 --> 00:02:49.620
<v Speaker 2>destroyed missile sites and so forth. The Iranians were fighting

47
00:02:49.659 --> 00:02:52.539
<v Speaker 2>the old style with Soviet equipment. and just kind of

48
00:02:52.560 --> 00:02:54.560
<v Speaker 2>got rolled over. Like you'd think the Russians would have

49
00:02:54.599 --> 00:02:57.699
<v Speaker 2>taken a hint watching their stuff be torn up by

50
00:02:57.780 --> 00:03:01.509
<v Speaker 2>drones in 2020. Instead, they bought a lot of drones. Well,

51
00:03:01.530 --> 00:03:04.729
<v Speaker 2>they did eventually, but first they got hit pretty hard. Anyway,

52
00:03:05.310 --> 00:03:08.110
<v Speaker 2>it was only six weeks. And that doesn't change the

53
00:03:08.150 --> 00:03:10.629
<v Speaker 2>fact that a lot of people died. It did result

54
00:03:10.669 --> 00:03:13.030
<v Speaker 2>in the fall of the, of the region and the

55
00:03:13.069 --> 00:03:15.479
<v Speaker 2>change in the, in the environment over there. But it's

56
00:03:15.500 --> 00:03:18.360
<v Speaker 2>just a precursor conflict to, to, you know, we saw

57
00:03:18.580 --> 00:03:21.120
<v Speaker 2>an example, just of course it was COVID and, There

58
00:03:21.129 --> 00:03:23.599
<v Speaker 2>was all the things going on at that time in

59
00:03:23.620 --> 00:03:25.300
<v Speaker 2>that year that nobody was paying attention to.

60
00:03:25.319 --> 00:03:25.539
<v Speaker 3>Yeah.

61
00:03:25.599 --> 00:03:30.219
<v Speaker 1>A couple other notable deaths in 2020. Ruth Bader Ginsburg.

62
00:03:31.580 --> 00:03:32.099
<v Speaker 1>What a blunder.

63
00:03:32.280 --> 00:03:32.620
<v Speaker 3>Yeah.

64
00:03:32.979 --> 00:03:37.439
<v Speaker 1>Kobe Bryant. Yeah, the helicopter accident. And good trouble himself,

65
00:03:37.840 --> 00:03:38.430
<v Speaker 1>John Lewis.

66
00:03:38.750 --> 00:03:38.949
<v Speaker 3>Right.

67
00:03:39.150 --> 00:03:41.469
<v Speaker 1>Died civil rights icon. Yeah. Yeah, it was just a

68
00:03:41.550 --> 00:03:44.129
<v Speaker 1>bad- Tough year. Bad years. Tough year.

69
00:03:44.229 --> 00:03:45.590
<v Speaker 2>Yeah. Do you want to know what happened in space?

70
00:03:45.629 --> 00:03:48.969
<v Speaker 2>There wasn't a ton, but there's some important ones. In February,

71
00:03:49.069 --> 00:03:52.189
<v Speaker 2>Solar Orbiter launches. You don't really know much about this one.

72
00:03:52.310 --> 00:03:55.449
<v Speaker 2>This was a joint ESA-NASA mission in that order. It's

73
00:03:55.469 --> 00:03:58.990
<v Speaker 2>very much a European mission with NASA instrumentations and They

74
00:03:59.009 --> 00:04:00.810
<v Speaker 2>provided the Atlas V as well, but it was built

75
00:04:00.830 --> 00:04:03.810
<v Speaker 2>by Airbus. And its goal was to get a view

76
00:04:04.050 --> 00:04:07.710
<v Speaker 2>of the poles of the sun. Normally, you're launching your

77
00:04:07.729 --> 00:04:10.270
<v Speaker 2>spacecraft because the Earth's in the plane of the ecliptic.

78
00:04:10.310 --> 00:04:11.909
<v Speaker 2>Your spacecraft are going to be as well. Trying to

79
00:04:11.930 --> 00:04:13.780
<v Speaker 2>get to high inclination is very, very difficult. Not that

80
00:04:13.789 --> 00:04:17.579
<v Speaker 2>they got all that high. They'll fly down into a

81
00:04:17.920 --> 00:04:21.560
<v Speaker 2>looping orbit inside the orbit of Mercury and then use

82
00:04:21.860 --> 00:04:26.199
<v Speaker 2>Venus to do the slingshots and repeatedly tip the spacecraft.

83
00:04:26.230 --> 00:04:29.089
<v Speaker 2>So it is about 24 degrees off the planet ecliptic.

84
00:04:29.110 --> 00:04:30.569
<v Speaker 2>It takes a ton of energy to do that. They

85
00:04:30.589 --> 00:04:34.110
<v Speaker 2>borrowed lots of energy from Venus, but it's a one-ton spacecraft,

86
00:04:34.129 --> 00:04:34.290
<v Speaker 2>so it.

87
00:04:34.269 --> 00:04:34.670
<v Speaker 1>Can do that.

88
00:04:35.490 --> 00:04:38.790
<v Speaker 2>But it'll get us our first visual views of the

89
00:04:38.829 --> 00:04:39.560
<v Speaker 2>poles of the sun.

90
00:04:39.920 --> 00:04:41.779
<v Speaker 1>Cool mission. Yeah, that is cool.

91
00:04:41.920 --> 00:04:45.560
<v Speaker 2>In May. the first crew dragon demo mission. So this

92
00:04:45.579 --> 00:04:48.790
<v Speaker 2>was Bob, uh, Benneken and Doug Hurley go up to

93
00:04:48.810 --> 00:04:52.889
<v Speaker 2>the space station and demonstrate that, uh, the commercial spacecraft

94
00:04:52.930 --> 00:04:55.370
<v Speaker 2>can actually go to the space station properly. And that'll

95
00:04:55.389 --> 00:04:57.589
<v Speaker 2>be followed up in November with a regular crew flight

96
00:04:57.629 --> 00:04:59.750
<v Speaker 2>of four astronauts to crew the space station.

97
00:04:59.850 --> 00:05:01.110
<v Speaker 1>So there you go.

98
00:05:01.250 --> 00:05:04.730
<v Speaker 2>After what this would be nine years since the Atlantis

99
00:05:04.750 --> 00:05:07.769
<v Speaker 2>had landed. And the only support for the station was, uh,

100
00:05:08.160 --> 00:05:10.920
<v Speaker 2>Via Soyuz, now the Americans had a vehicle again, the

101
00:05:10.959 --> 00:05:11.519
<v Speaker 2>former crew driver.

102
00:05:11.540 --> 00:05:14.290
<v Speaker 1>I got a question, which Michael might know the answer to,

103
00:05:14.370 --> 00:05:18.949
<v Speaker 1>but you said ESA and NASA did this thing together

104
00:05:19.110 --> 00:05:22.279
<v Speaker 1>in 2020, but Brexit was in 2020. Was Was Britain

105
00:05:22.339 --> 00:05:24.990
<v Speaker 1>part of ESA in 2020? Did they participate?

106
00:05:25.319 --> 00:05:27.370
<v Speaker 3>Yeah, I don't think so. I could be wrong, but

107
00:05:27.389 --> 00:05:28.009
<v Speaker 3>I don't think so.

108
00:05:28.250 --> 00:05:29.430
<v Speaker 2>It's mostly Germany, France.

109
00:05:29.470 --> 00:05:29.769
<v Speaker 4>Yeah.

110
00:05:29.829 --> 00:05:32.750
<v Speaker 1>Okay. It's Airbus, it's Defense of the Space. All right.

111
00:05:32.810 --> 00:05:36.480
<v Speaker 2>July, the Perseverance rover. So, this was the test article

112
00:05:36.620 --> 00:05:39.660
<v Speaker 2>for the original Curiosity rover with a bunch of upgraded things,

113
00:05:39.699 --> 00:05:41.259
<v Speaker 2>better wheels, better suspension.

114
00:05:41.300 --> 00:05:41.399
<v Speaker 3>Yeah.

115
00:05:42.079 --> 00:05:46.939
<v Speaker 2>New instruments, the Ingenuity helicopter, all of that stuff gets

116
00:05:47.000 --> 00:05:50.189
<v Speaker 2>launched in July. July is the perfect time to launch

117
00:05:50.230 --> 00:05:53.449
<v Speaker 2>to Mars, July 2020. There's a synchronicity to the orbits, right?

118
00:05:53.470 --> 00:05:56.629
<v Speaker 2>They're in a two, three period. And so every roughly

119
00:05:56.689 --> 00:05:58.069
<v Speaker 2>two years, you get a chance to do a bunch

120
00:05:58.089 --> 00:05:59.889
<v Speaker 2>of flights. And so July, there's actually three. There's the

121
00:05:59.930 --> 00:06:03.500
<v Speaker 2>Perseverance rover, which is huge. There's also China's very first

122
00:06:03.560 --> 00:06:08.329
<v Speaker 2>mission to Mars, Tianwen-1. And then the UAE. the United

123
00:06:08.389 --> 00:06:13.829
<v Speaker 2>Aramids launches their Hope climate orbiter to Mars. So three

124
00:06:13.870 --> 00:06:15.250
<v Speaker 2>launches in the same month. Wow.

125
00:06:15.269 --> 00:06:15.970
<v Speaker 3>Did they all make it?

126
00:06:16.310 --> 00:06:16.980
<v Speaker 2>In October.

127
00:06:17.420 --> 00:06:18.339
<v Speaker 3>The U.S. made it.

128
00:06:18.379 --> 00:06:19.089
<v Speaker 2>They all make it.

129
00:06:19.120 --> 00:06:20.740
<v Speaker 1>Yeah, actually. Very cool.

130
00:06:20.899 --> 00:06:24.160
<v Speaker 2>And I mean, I'll talk more about the Tianwen-1 when

131
00:06:24.180 --> 00:06:27.189
<v Speaker 2>it lands next year. So in episode 2021. Because that

132
00:06:27.209 --> 00:06:29.310
<v Speaker 2>was China's first attempt to go to Mars and it

133
00:06:29.470 --> 00:06:33.750
<v Speaker 2>fully worked. Nobody's pulled that off before. Everybody loses a

134
00:06:33.769 --> 00:06:34.889
<v Speaker 2>few trying to get to Mars.

135
00:06:35.589 --> 00:06:37.810
<v Speaker 1>Just name it. Everybody does. But China didn't.

136
00:06:38.009 --> 00:06:40.550
<v Speaker 2>But, you know, the advantage of being, I don't know,

137
00:06:40.670 --> 00:06:44.660
<v Speaker 2>fourth or fifth mover or something like that. In October, OSIRIS-REx,

138
00:06:44.779 --> 00:06:49.420
<v Speaker 2>one of the asteroid missions, touches on asteroid Bennu. and

139
00:06:49.480 --> 00:06:51.480
<v Speaker 2>collects a sample there. In fact, it does a little

140
00:06:51.560 --> 00:06:54.759
<v Speaker 2>too well because when it touches, Bennu is very much

141
00:06:54.790 --> 00:06:57.350
<v Speaker 2>a rubble pile and all that gravel goes everywhere and

142
00:06:57.750 --> 00:07:01.509
<v Speaker 2>they actually have trouble closing up the sample container because

143
00:07:01.529 --> 00:07:03.709
<v Speaker 2>there's too much stuff. They have to come up with

144
00:07:03.730 --> 00:07:07.629
<v Speaker 2>such technical maneuvers as shaking a little off to try

145
00:07:07.689 --> 00:07:09.310
<v Speaker 2>and get the thing closed up so they can put

146
00:07:09.329 --> 00:07:12.209
<v Speaker 2>it in the capsule to return. Another asteroid mission at

147
00:07:12.250 --> 00:07:14.529
<v Speaker 2>the end of the year in December, Hayabusa 2, will

148
00:07:14.569 --> 00:07:19.040
<v Speaker 2>actually successfully return It's sample payload from the asteroid Regu,

149
00:07:19.060 --> 00:07:22.240
<v Speaker 2>and that is a JAXA mission. A little recap on

150
00:07:22.279 --> 00:07:25.779
<v Speaker 2>what SpaceX did in 2020. There was actually 25 launches

151
00:07:25.819 --> 00:07:28.699
<v Speaker 2>from SpaceX, which at the time was an amazing number.

152
00:07:29.459 --> 00:07:33.899
<v Speaker 2>Just remembering that SpaceX will do 150 this year. So obviously,

153
00:07:34.259 --> 00:07:37.870
<v Speaker 2>there's the two Crew Dragons, the test run in March,

154
00:07:37.949 --> 00:07:41.519
<v Speaker 2>and then the full payload in November. They'll also fly

155
00:07:41.519 --> 00:07:45.310
<v Speaker 2>14 Starlink missions, 833 satellites for a network of almost

156
00:07:45.310 --> 00:07:47.029
<v Speaker 2>900 by the end of the year.

157
00:07:47.050 --> 00:07:47.120
<v Speaker 4>Wow.

158
00:07:47.129 --> 00:07:51.350
<v Speaker 3>Have you ever seen the Starlink satellites leaving the spaceship? Yeah.

159
00:07:51.370 --> 00:07:52.800
<v Speaker 3>It's like pizza boxes going out.

160
00:07:52.939 --> 00:07:55.660
<v Speaker 2>Yeah, yeah. Well, now they've gotten bigger because of the

161
00:07:55.699 --> 00:07:58.000
<v Speaker 2>V2 minis. And so, they only fly like 24 or

162
00:07:58.000 --> 00:08:00.819
<v Speaker 2>28 of them depending on the inclination. But at this time,

163
00:08:00.879 --> 00:08:03.370
<v Speaker 2>they're flying 60 a run.

164
00:08:03.389 --> 00:08:04.230
<v Speaker 1>That's crazy. Wow.

165
00:08:04.620 --> 00:08:07.879
<v Speaker 2>Just these huge numbers of satellites. And that's where they also,

166
00:08:08.259 --> 00:08:10.240
<v Speaker 2>this is the year where they have the reflectivity problems.

167
00:08:10.439 --> 00:08:12.870
<v Speaker 2>And so you can see them for an extended period

168
00:08:12.879 --> 00:08:15.720
<v Speaker 2>of time until they learn how to orient them and

169
00:08:15.759 --> 00:08:18.160
<v Speaker 2>paint them correctly so they're not so visible and don't

170
00:08:18.199 --> 00:08:19.139
<v Speaker 2>bother people so much.

171
00:08:19.250 --> 00:08:21.189
<v Speaker 1>I remember there was a bunch of astronomers that were

172
00:08:21.230 --> 00:08:23.949
<v Speaker 1>complaining they were polluting the night sky with their telescopes.

173
00:08:24.209 --> 00:08:27.009
<v Speaker 2>Yeah. Well, and that's still an issue, although let's face it,

174
00:08:27.009 --> 00:08:28.550
<v Speaker 2>digital processing can fix that.

175
00:08:28.769 --> 00:08:29.290
<v Speaker 1>Right.

176
00:08:29.449 --> 00:08:32.750
<v Speaker 2>But making bright lights make it worse. So making sure

177
00:08:32.769 --> 00:08:34.250
<v Speaker 2>it doesn't reflect sunlight helps.

178
00:08:34.549 --> 00:08:37.139
<v Speaker 1>I've seen them though. I've seen the trail go across

179
00:08:37.240 --> 00:08:40.500
<v Speaker 1>and it's pretty fascinating and a little bit I don't know.

180
00:08:40.539 --> 00:08:42.970
<v Speaker 1>You know, SpaceX does some things that if you weren't

181
00:08:43.009 --> 00:08:45.570
<v Speaker 1>paying attention, you'd think we're being invaded by aliens.

182
00:08:45.769 --> 00:08:48.330
<v Speaker 2>Well, or, you know, or Dr. No is in full swing.

183
00:08:48.389 --> 00:08:51.879
<v Speaker 2>Like the line between supervillain and tech billionaire is getting

184
00:08:51.899 --> 00:08:52.799
<v Speaker 2>very narrow.

185
00:08:53.000 --> 00:08:55.220
<v Speaker 1>Just people don't know. Like, you know, the first time

186
00:08:55.259 --> 00:08:57.840
<v Speaker 1>that I saw the booster rocket spinning, you know, when

187
00:08:57.879 --> 00:09:01.789
<v Speaker 1>it– I thought it was like a spaceship. And so

188
00:09:01.809 --> 00:09:03.769
<v Speaker 1>did a million other people until I found out, oh,

189
00:09:03.809 --> 00:09:05.730
<v Speaker 1>that's just SpaceX. That's what they do. And what are

190
00:09:05.769 --> 00:09:08.470
<v Speaker 1>those lights going? Hey, is that Santa Claus? No, that's

191
00:09:08.509 --> 00:09:09.250
<v Speaker 1>just SpaceX.

192
00:09:09.309 --> 00:09:13.600
<v Speaker 3>Yeah. I use Stellarium and it'll show you all the SpaceX.

193
00:09:13.960 --> 00:09:17.620
<v Speaker 1>Sure. Something's whizzing around out there. I know. Must be

194
00:09:17.659 --> 00:09:21.340
<v Speaker 1>my Facebook friends. They're at average intelligence or ability to

195
00:09:21.399 --> 00:09:22.379
<v Speaker 1>look things up.

196
00:09:22.379 --> 00:09:24.460
<v Speaker 2>10,000 plus of them by the end of this year,

197
00:09:24.519 --> 00:09:26.990
<v Speaker 2>just so you know. There'll be a bunch of other

198
00:09:27.009 --> 00:09:29.049
<v Speaker 2>missions as well, including a couple of GPS satellites. They'll

199
00:09:29.080 --> 00:09:32.100
<v Speaker 2>also start doing their Starship flights, the hop tests, and

200
00:09:32.120 --> 00:09:34.820
<v Speaker 2>the first, what they called belly flop test, where they

201
00:09:34.860 --> 00:09:36.840
<v Speaker 2>fire it up to a few kilometers up and then

202
00:09:36.879 --> 00:09:38.419
<v Speaker 2>let it fall on its belly so they could actually

203
00:09:38.480 --> 00:09:41.059
<v Speaker 2>land it. That was SN8 by the end of 2020.

204
00:09:41.059 --> 00:09:43.799
<v Speaker 2>It does not go well, but they'll solve that and

205
00:09:43.879 --> 00:09:45.940
<v Speaker 2>prove that this whole idea is even possible. All right,

206
00:09:45.960 --> 00:09:46.960
<v Speaker 2>should we move on to computing?

207
00:09:47.120 --> 00:09:47.279
<v Speaker 3>Yeah.

208
00:09:47.440 --> 00:09:50.440
<v Speaker 2>We'll start in January with the OpenAI paper called the

209
00:09:50.559 --> 00:09:54.779
<v Speaker 2>Neural Scaling Laws. Lead author is Jared Kaplan. There's a

210
00:09:54.779 --> 00:09:57.679
<v Speaker 2>whole bunch of others, including Daryl Modi, who this time

211
00:09:57.720 --> 00:09:59.970
<v Speaker 2>is at OpenAI, will eventually be the CEO of Anthrop.

212
00:10:00.600 --> 00:10:02.759
<v Speaker 2>And this was the paper that sort of kicked off

213
00:10:02.840 --> 00:10:06.450
<v Speaker 2>this idea of, you know, different from all the other

214
00:10:06.490 --> 00:10:08.929
<v Speaker 2>machine learning models we did where we worry about overfitting

215
00:10:08.970 --> 00:10:12.539
<v Speaker 2>and training sets and so forth. that for large language models,

216
00:10:12.580 --> 00:10:13.970
<v Speaker 2>we should just train on as much data as we

217
00:10:13.990 --> 00:10:17.509
<v Speaker 2>can possibly get. There's lots of debate as to whether

218
00:10:17.529 --> 00:10:19.809
<v Speaker 2>this is that good an idea. We've definitely come into

219
00:10:19.889 --> 00:10:22.909
<v Speaker 2>other techniques from there. But this paper is kind of

220
00:10:22.950 --> 00:10:25.570
<v Speaker 2>the stimulus for what will be the insanity coming in

221
00:10:25.590 --> 00:10:28.720
<v Speaker 2>the next couple of years. January is also when Microsoft

222
00:10:28.740 --> 00:10:30.960
<v Speaker 2>switches over to Chromium as the rendering engine in the

223
00:10:31.039 --> 00:10:35.190
<v Speaker 2>new Edge browser. The pandemic's in full swing in March

224
00:10:35.210 --> 00:10:38.360
<v Speaker 2>is when lockdowns really kick off and everybody goes home

225
00:10:38.429 --> 00:10:41.940
<v Speaker 2>and everybody's got Zoom. Teams explodes for better or worse.

226
00:10:42.559 --> 00:10:48.629
<v Speaker 2>But a little thing I paid attention to was Terry Breton,

227
00:10:48.690 --> 00:10:53.879
<v Speaker 2>who is the EU Internal Market Commissioner. reached out to

228
00:10:54.240 --> 00:10:58.139
<v Speaker 2>Netflix and YouTube and Amazon Prime and asked him to

229
00:10:58.179 --> 00:11:01.679
<v Speaker 2>turn off all the 4K features. He was concerned about

230
00:11:01.700 --> 00:11:05.899
<v Speaker 2>the amount of available bandwidth across Europe as everybody went

231
00:11:06.000 --> 00:11:10.610
<v Speaker 2>home and used the internet differently. Was it actually a crisis?

232
00:11:10.690 --> 00:11:13.470
<v Speaker 2>Nobody knows for sure, or at least he's not talking

233
00:11:13.509 --> 00:11:17.090
<v Speaker 2>about it. They started turning up the bandwidth again in May,

234
00:11:17.230 --> 00:11:20.889
<v Speaker 2>and Netflix's Posts about this are interesting because they talk

235
00:11:20.929 --> 00:11:23.750
<v Speaker 2>about network changes and increasing capacity and things like that.

236
00:11:24.370 --> 00:11:26.519
<v Speaker 2>So maybe there really was a crisis because of the

237
00:11:26.559 --> 00:11:29.440
<v Speaker 2>change in the Internet consumption due to COVID. But, you know,

238
00:11:29.519 --> 00:11:32.440
<v Speaker 2>a lot of details aren't revealed necessarily. But that to

239
00:11:32.480 --> 00:11:33.320
<v Speaker 2>me was very interesting.

240
00:11:33.340 --> 00:11:33.480
<v Speaker 1>Yeah.

241
00:11:34.250 --> 00:11:37.600
<v Speaker 2>April is when Uncle Satchit says, two years worth of

242
00:11:37.639 --> 00:11:42.580
<v Speaker 2>digital transformation in two months. Because everybody had to all work.

243
00:11:42.620 --> 00:11:44.419
<v Speaker 2>This is when I started doing True Run As a week,

244
00:11:44.539 --> 00:11:49.850
<v Speaker 2>just talking about topics around what was necessary for sysadmins

245
00:11:51.529 --> 00:11:52.769
<v Speaker 2>with everybody working from home.

246
00:11:52.990 --> 00:11:56.169
<v Speaker 1>My brother is a programmer at a local company. He's

247
00:11:56.190 --> 00:11:59.169
<v Speaker 1>been there for years and years. And they basically do

248
00:11:59.490 --> 00:12:02.309
<v Speaker 1>online vehicle registrations. And they were the first in the

249
00:12:02.409 --> 00:12:07.840
<v Speaker 1>area to do it. And their customers are states, not

250
00:12:07.960 --> 00:12:15.730
<v Speaker 1>individual sales places, dealerships. But anyway, they were renting an

251
00:12:15.830 --> 00:12:19.470
<v Speaker 1>office building in an office park out here, umpteen billion

252
00:12:19.529 --> 00:12:22.809
<v Speaker 1>square feet. And during COVID, people went to work at home.

253
00:12:23.450 --> 00:12:27.259
<v Speaker 1>And I just remember Jay coming to rehearsal once and said, Well,

254
00:12:27.279 --> 00:12:29.759
<v Speaker 1>I've resigned myself to the idea that I'm never going

255
00:12:29.799 --> 00:12:32.889
<v Speaker 1>back to the office. And they basically moved out of

256
00:12:32.929 --> 00:12:35.590
<v Speaker 1>the office. Yeah, lots did. They stopped renting it. And

257
00:12:35.629 --> 00:12:38.289
<v Speaker 1>I think, in general, office space took a big dive

258
00:12:39.049 --> 00:12:39.850
<v Speaker 1>in 2020.

259
00:12:39.850 --> 00:12:42.210
<v Speaker 2>You think about all the property that Microsoft gave up

260
00:12:42.269 --> 00:12:42.850
<v Speaker 2>in Bellevue.

261
00:12:43.000 --> 00:12:43.409
<v Speaker 1>Yeah.

262
00:12:43.600 --> 00:12:46.480
<v Speaker 2>They kept their buildings in Redmond, but all that rented space.

263
00:12:46.299 --> 00:12:47.019
<v Speaker 1>In Bellevue went away.

264
00:12:47.340 --> 00:12:47.519
<v Speaker 3>Right.

265
00:12:47.659 --> 00:12:48.559
<v Speaker 1>And all of it went to Zoom.

266
00:12:48.820 --> 00:12:49.059
<v Speaker 3>Yeah.

267
00:12:49.559 --> 00:12:50.120
<v Speaker 1>Well, to Teams.

268
00:12:50.139 --> 00:12:54.769
<v Speaker 2>Teams. The first virtual build in May is also when

269
00:12:54.909 --> 00:12:58.929
<v Speaker 2>they do the full release of Blazor WebAssembly.

270
00:12:59.129 --> 00:12:59.649
<v Speaker 1>Yeah.

271
00:13:00.309 --> 00:13:02.429
<v Speaker 2>Obviously, a bunch of other cool announcements around building that

272
00:13:02.450 --> 00:13:05.990
<v Speaker 2>time span. Of course, Blazor, not the first WA programming language,

273
00:13:06.070 --> 00:13:10.740
<v Speaker 2>Golang added WA support back in 2018. In June, and again,

274
00:13:10.759 --> 00:13:14.679
<v Speaker 2>no people remember much about this because it was mid-pandemic.

275
00:13:15.429 --> 00:13:19.690
<v Speaker 2>Microsoft is a big splash about OpenAI GPT-3 being built

276
00:13:19.769 --> 00:13:22.990
<v Speaker 2>on what they called the Azure supercomputer, which was a

277
00:13:23.070 --> 00:13:26.120
<v Speaker 2>bunch of different Azure data centers harnessed together with 10,000 GPUs, 285,000 CPUs.

278
00:13:28.679 --> 00:13:33.120
<v Speaker 2>cpu cores to build a get this 175 billion parameter

279
00:13:33.159 --> 00:13:36.029
<v Speaker 2>model wow i mean big big big for the time

280
00:13:36.250 --> 00:13:38.230
<v Speaker 2>not so much anymore but at the time.

281
00:13:38.110 --> 00:13:40.629
<v Speaker 1>I remember uh brian mckay who's one of my happy

282
00:13:40.649 --> 00:13:43.789
<v Speaker 1>next guys getting on slack and telling us how awesome

283
00:13:43.809 --> 00:13:46.289
<v Speaker 1>this gpt thing was but it was difficult to set

284
00:13:46.350 --> 00:13:48.570
<v Speaker 1>up at the time but then yeah you know i

285
00:13:48.610 --> 00:13:51.269
<v Speaker 1>tried it and of course like everybody else was kind

286
00:13:51.289 --> 00:13:51.919
<v Speaker 1>of blown away.

287
00:13:52.029 --> 00:13:55.600
<v Speaker 2>Yeah Later that year in September is when Microsoft actually

288
00:13:55.679 --> 00:14:00.649
<v Speaker 2>licenses GPT-3 from OpenAI, which I presume is how GitHub

289
00:14:00.669 --> 00:14:03.049
<v Speaker 2>gets access to it. They'll make GitHub Copilot the following.

290
00:14:03.970 --> 00:14:08.610
<v Speaker 2>A couple more stories. In November, Apple announces the M1 processor.

291
00:14:08.769 --> 00:14:09.009
<v Speaker 1>Yes.

292
00:14:09.250 --> 00:14:11.840
<v Speaker 2>And I mention this because this, I would argue, is

293
00:14:12.460 --> 00:14:17.000
<v Speaker 2>Tim Cook's most memorable move. He was always a hardware guy.

294
00:14:17.019 --> 00:14:18.879
<v Speaker 2>This is an astonishing piece of hardware. There's a system

295
00:14:18.919 --> 00:14:23.879
<v Speaker 2>on a chip where the GPU and CPU, NPU, the

296
00:14:24.100 --> 00:14:26.440
<v Speaker 2>IO and security buses and so forth are all literally

297
00:14:26.480 --> 00:14:28.820
<v Speaker 2>in the same die. The memory is in the same package.

298
00:14:29.899 --> 00:14:33.679
<v Speaker 2>So this is made by TSMC, five nanometer process, about

299
00:14:33.679 --> 00:14:37.679
<v Speaker 2>16 billion transistors total. That includes eight CPU cores, eight

300
00:14:37.700 --> 00:14:40.610
<v Speaker 2>GPU cores, a 16 core neural engine, and up to

301
00:14:40.610 --> 00:14:42.580
<v Speaker 2>16 gigabytes of RAM right.

302
00:14:42.490 --> 00:14:43.070
<v Speaker 1>On the package.

303
00:14:43.110 --> 00:14:46.669
<v Speaker 2>So you get both lower power consumption and higher performance.

304
00:14:47.720 --> 00:14:48.759
<v Speaker 2>And little would we realize.

305
00:14:48.899 --> 00:14:51.419
<v Speaker 1>I have a MacBook Pro with an M1. Yeah. First gen.

306
00:14:51.679 --> 00:14:52.279
<v Speaker 1>And it's good.

307
00:14:52.440 --> 00:14:54.580
<v Speaker 3>Is that 16? Is that megabytes or gigabytes?

308
00:14:54.860 --> 00:14:55.139
<v Speaker 1>Gigs.

309
00:14:55.490 --> 00:14:57.750
<v Speaker 3>Yeah. That's RAM, RAM, not cache.

310
00:14:57.769 --> 00:14:58.429
<v Speaker 2>That's RAM, RAM.

311
00:14:58.490 --> 00:14:58.889
<v Speaker 3>Okay. Yeah.

312
00:14:58.909 --> 00:15:01.009
<v Speaker 2>They're not putting cache on. The cache is there too.

313
00:15:01.269 --> 00:15:01.429
<v Speaker 1>Okay.

314
00:15:01.450 --> 00:15:03.230
<v Speaker 2>And also that RAM is shared with the GPU.

315
00:15:03.549 --> 00:15:04.549
<v Speaker 1>Right.

316
00:15:04.570 --> 00:15:08.519
<v Speaker 2>So what we're doing right now with LLMs and the

317
00:15:08.559 --> 00:15:10.919
<v Speaker 2>new agent models and so forth, The M1 was built

318
00:15:10.940 --> 00:15:13.019
<v Speaker 2>for it, not knowing it was built for it. They

319
00:15:13.039 --> 00:15:14.779
<v Speaker 2>were just trying to make the most efficient computer they

320
00:15:14.799 --> 00:15:17.149
<v Speaker 2>could consume the least power. And this is Apple's move

321
00:15:17.210 --> 00:15:20.769
<v Speaker 2>back to ARM, having come from the Motorola chipset, moved

322
00:15:20.789 --> 00:15:23.190
<v Speaker 2>to Intel for a few years. Now they're making their

323
00:15:23.230 --> 00:15:24.549
<v Speaker 2>own thing based on ARM.

324
00:15:26.029 --> 00:15:26.289
<v Speaker 1>Two more.

325
00:15:26.450 --> 00:15:29.720
<v Speaker 2>December, both in December. The SolarWinds supply chain attack. So

326
00:15:29.740 --> 00:15:34.919
<v Speaker 2>this is Russian SVR. The pure brilliance of this is unbelievable.

327
00:15:35.429 --> 00:15:38.860
<v Speaker 2>So in September of 2019, hackers successfully break into the

328
00:15:38.899 --> 00:15:43.519
<v Speaker 2>SolarWinds development environment and they insert code into the development chain.

329
00:15:43.960 --> 00:15:45.940
<v Speaker 2>The way they do it is incredibly insidious. It's part

330
00:15:45.960 --> 00:15:49.200
<v Speaker 2>of their build system that they replace code in the

331
00:15:49.279 --> 00:15:52.399
<v Speaker 2>build without actually changing the visible source code. So developers

332
00:15:52.419 --> 00:15:53.889
<v Speaker 2>don't think their code has changed at all, but what

333
00:15:53.909 --> 00:15:56.909
<v Speaker 2>they're actually compiling is different code with this thing called

334
00:15:56.929 --> 00:16:01.750
<v Speaker 2>the sunburst backdoor. They, they, they, It takes them a

335
00:16:01.769 --> 00:16:03.389
<v Speaker 2>few months of doing testing to get this to work.

336
00:16:03.460 --> 00:16:06.700
<v Speaker 2>By March, they have actually figured it out. And the

337
00:16:06.779 --> 00:16:10.399
<v Speaker 2>Orion monitoring software, SolarWinds builds this infrastructure monitoring software, is

338
00:16:10.440 --> 00:16:14.019
<v Speaker 2>now distributed to 18,000 customers with the Sunburst backdoor in it.

339
00:16:15.389 --> 00:16:18.190
<v Speaker 2>The Russians are successful enough that in June, they actually

340
00:16:18.269 --> 00:16:21.870
<v Speaker 2>removed the whole build injection system. Like, they're done. And

341
00:16:21.929 --> 00:16:24.580
<v Speaker 2>are happily operating it. Now, admittedly, they don't actually use

342
00:16:24.600 --> 00:16:27.539
<v Speaker 2>that backdoor much. Maybe 100 customers are totally affected. But

343
00:16:27.580 --> 00:16:30.799
<v Speaker 2>it's in December when one of those customers, a security

344
00:16:30.840 --> 00:16:36.149
<v Speaker 2>company called FireEye, realizes they've been exploited and traces it

345
00:16:36.210 --> 00:16:39.149
<v Speaker 2>back to the Orion code base and basically pops the

346
00:16:39.190 --> 00:16:42.940
<v Speaker 2>whole thing open. It's an incredibly sophisticated supply chain attack

347
00:16:42.980 --> 00:16:45.399
<v Speaker 2>and scares just not actually everybody. It's not the first one,

348
00:16:45.440 --> 00:16:46.750
<v Speaker 2>but in a lot of ways, it's the one that

349
00:16:46.759 --> 00:16:47.970
<v Speaker 2>made the most news.

350
00:16:48.309 --> 00:16:51.350
<v Speaker 1>It could be made into a feature film, actually, if

351
00:16:51.409 --> 00:16:52.470
<v Speaker 1>it was handled correctly.

352
00:16:52.850 --> 00:16:53.830
<v Speaker 2>It's astonishing.

353
00:16:53.850 --> 00:16:55.190
<v Speaker 1>Yeah.

354
00:16:55.309 --> 00:16:58.029
<v Speaker 2>And if the Russians hadn't decided to go after FireEye,

355
00:16:58.269 --> 00:17:00.360
<v Speaker 2>who knows when it would have been detected. Just he

356
00:17:00.399 --> 00:17:02.759
<v Speaker 2>went after the guys who were in the security space

357
00:17:02.799 --> 00:17:04.319
<v Speaker 2>and good enough at attacking breach properly.

358
00:17:05.869 --> 00:17:08.170
<v Speaker 3>Yeah, I remember when I was invited to a meeting

359
00:17:08.190 --> 00:17:11.779
<v Speaker 3>to be briefed on the attack when we sort of

360
00:17:11.799 --> 00:17:14.339
<v Speaker 3>knew what was going on. And yeah, I'll be frank,

361
00:17:14.700 --> 00:17:17.640
<v Speaker 3>I was kind of gobsmacked actually by- Gobsmacked, yeah. By

362
00:17:17.660 --> 00:17:18.440
<v Speaker 3>the sophistication.

363
00:17:18.640 --> 00:17:22.500
<v Speaker 2>It's so clever. Holy man. I don't expect bad guys

364
00:17:22.539 --> 00:17:25.279
<v Speaker 2>to be this smart, right? If they were smart, they'd

365
00:17:25.299 --> 00:17:27.240
<v Speaker 2>be good guys. Like the idea that bad guys would

366
00:17:27.259 --> 00:17:30.009
<v Speaker 2>come up with something this clever. But again, state actors,

367
00:17:30.069 --> 00:17:32.170
<v Speaker 2>like they're working for more than just a paycheck here.

368
00:17:32.490 --> 00:17:36.420
<v Speaker 3>Yeah, but remember though, you know, As Sherrod Dugripo has

369
00:17:36.460 --> 00:17:39.599
<v Speaker 3>told me many, many times, this is their day job, right?

370
00:17:39.680 --> 00:17:41.799
<v Speaker 3>They come to work, they clock in, they do the work,

371
00:17:41.839 --> 00:17:44.740
<v Speaker 3>they have reviews every year, they go home to their families,

372
00:17:45.029 --> 00:17:46.109
<v Speaker 3>and they start again tomorrow.

373
00:17:46.150 --> 00:17:47.829
<v Speaker 2>They get promotions by figuring this stuff out.

374
00:17:48.009 --> 00:17:49.529
<v Speaker 3>Exactly. It's just their job.

375
00:17:49.569 --> 00:17:52.789
<v Speaker 1>Yeah. As Dwayne LaFleur would say, oh, this is awesome, guys.

376
00:17:53.329 --> 00:17:55.690
<v Speaker 1>This is awesome. It's a stunner.

377
00:17:56.670 --> 00:17:59.690
<v Speaker 2>I'll finish out the year of compute in 2020 with

378
00:18:00.049 --> 00:18:04.430
<v Speaker 2>China's Zhuheng Photonic Quantum Computer, which I think is particularly

379
00:18:04.490 --> 00:18:08.740
<v Speaker 2>relevant for today's conversation. This was a dedicated machine using

380
00:18:09.000 --> 00:18:12.700
<v Speaker 2>photonic quantum entanglement, which is very, very clever, unique, very

381
00:18:12.740 --> 00:18:16.480
<v Speaker 2>different from Sycamore, the Google's device from the previous year,

382
00:18:16.539 --> 00:18:19.799
<v Speaker 2>which was the … The hanging chandelier in liquid helium,

383
00:18:19.839 --> 00:18:21.279
<v Speaker 2>this doesn't need any of this, but it was built

384
00:18:21.319 --> 00:18:23.940
<v Speaker 2>specifically for Gaussian boson sampling.

385
00:18:24.299 --> 00:18:27.849
<v Speaker 1>Nobody knows what you're talking about, Richard. I'm okay with that.

386
00:18:27.920 --> 00:18:29.109
<v Speaker 1>I might contest.

387
00:18:29.190 --> 00:18:32.230
<v Speaker 3>I mean, I know enough to be dangerous. Talk to

388
00:18:32.250 --> 00:18:33.470
<v Speaker 3>me about the software side of it.

389
00:18:33.890 --> 00:18:35.890
<v Speaker 2>Yeah, and that's the whole thing is this is nowhere

390
00:18:35.970 --> 00:18:38.670
<v Speaker 2>near a general purpose computer or even a supercomputer. This

391
00:18:38.730 --> 00:18:41.650
<v Speaker 2>is a machine to demonstrate that quantum entanglement can tackle

392
00:18:41.990 --> 00:18:45.009
<v Speaker 2>one kind of problem, the Gaussian boson sample problem. Now,

393
00:18:45.029 --> 00:18:46.450
<v Speaker 2>that's an important problem, but it was sort of a

394
00:18:46.609 --> 00:18:49.150
<v Speaker 2>proof point I think very much this is a, hey,

395
00:18:49.210 --> 00:18:51.170
<v Speaker 2>we get to play too. And I think everybody reacted

396
00:18:51.190 --> 00:18:54.299
<v Speaker 2>to it that way. Because this 200-second run for something

397
00:18:54.319 --> 00:18:57.880
<v Speaker 2>that in theory would have taken this supercomputer 2 billion years,

398
00:18:57.940 --> 00:19:00.720
<v Speaker 2>not that anybody's going to test that, it just put

399
00:19:00.740 --> 00:19:05.009
<v Speaker 2>China instantly on the map and really made it very clear.

400
00:19:05.529 --> 00:19:07.809
<v Speaker 2>There's more than one way to quantum. And this is

401
00:19:07.869 --> 00:19:10.190
<v Speaker 2>a wildly different way. Not that we've heard much from

402
00:19:10.269 --> 00:19:13.569
<v Speaker 2>them since. But in 2020, that was a really big deal.

403
00:19:13.589 --> 00:19:14.490
<v Speaker 3>But does it run Doom?

404
00:19:14.829 --> 00:19:15.390
<v Speaker 2>It really doesn't.

405
00:19:15.670 --> 00:19:17.630
<v Speaker 1>No, not a bit. No, it won't.

406
00:19:18.799 --> 00:19:21.140
<v Speaker 2>I mean, supercomputers are limited in their own way, too,

407
00:19:21.200 --> 00:19:24.180
<v Speaker 2>as well. But this was literally built for one thing.

408
00:19:24.200 --> 00:19:28.430
<v Speaker 2>This is like Turing's device for cracking Enigma. Good for

409
00:19:28.549 --> 00:19:31.900
<v Speaker 2>one thing. The idea of general-purpose computing is a much

410
00:19:31.960 --> 00:19:33.960
<v Speaker 2>different idea than what we're doing in this kind of

411
00:19:33.980 --> 00:19:34.460
<v Speaker 2>class of work.

412
00:19:34.619 --> 00:19:34.859
<v Speaker 1>Anyway.

413
00:19:34.920 --> 00:19:37.759
<v Speaker 3>Yeah, 100%. I think people need to understand that. Yeah,

414
00:19:37.880 --> 00:19:41.099
<v Speaker 3>still people don't grapple that. There won't be an office

415
00:19:41.140 --> 00:19:43.269
<v Speaker 3>for quantum. It's not going to exist.

416
00:19:43.329 --> 00:19:44.250
<v Speaker 1>Oh, man.

417
00:19:44.490 --> 00:19:44.990
<v Speaker 3>I'm sorry.

418
00:19:45.569 --> 00:19:49.890
<v Speaker 1>You sold me that subscription. Let's get them on the phone. Yeah.

419
00:19:51.059 --> 00:19:54.680
<v Speaker 2>And as much as we can tell at this time,

420
00:19:55.039 --> 00:19:58.220
<v Speaker 2>these will always be supercomputers for particular problem spaces. Most

421
00:19:58.259 --> 00:20:02.009
<v Speaker 2>of them very deterministic problem spaces, too. But let's wrap

422
00:20:02.089 --> 00:20:04.670
<v Speaker 2>up the history lesson and get on to our larger

423
00:20:04.710 --> 00:20:05.529
<v Speaker 2>conversation about quantum.

424
00:20:05.819 --> 00:20:07.839
<v Speaker 1>Well, but first, we have to do.

425
00:20:07.960 --> 00:20:08.460
<v Speaker 2>But first.

426
00:20:08.619 --> 00:20:10.680
<v Speaker 1>Better know a framework. Roll the music. Awesome.

427
00:20:10.700 --> 00:20:15.059
<v Speaker 3>All right, man.

428
00:20:15.160 --> 00:20:19.539
<v Speaker 4>What do you got?

429
00:20:19.660 --> 00:20:22.150
<v Speaker 1>All right. So, as people who listen to me on

430
00:20:22.400 --> 00:20:26.009
<v Speaker 1>my various podcasts and stuff probably know, I bought this

431
00:20:26.890 --> 00:20:32.339
<v Speaker 1>big GPU machine. a year or so ago, just because

432
00:20:32.420 --> 00:20:34.720
<v Speaker 1>I anticipated being able to run local models.

433
00:20:35.160 --> 00:20:36.960
<v Speaker 2>And you got it ahead of the hardware crisis too.

434
00:20:37.000 --> 00:20:38.400
<v Speaker 2>So how smart are you?

435
00:20:38.599 --> 00:20:38.960
<v Speaker 3>Yeah.

436
00:20:40.059 --> 00:20:44.460
<v Speaker 1>I got it at walmart.com for $ 6, 000. It uses an

437
00:20:44.660 --> 00:20:48.480
<v Speaker 1>NVIDIA RTX 1590 with 32 gigs of VRAM.

438
00:20:49.339 --> 00:20:51.740
<v Speaker 2>Today that card's 15 grand if you can find one.

439
00:20:51.960 --> 00:20:55.509
<v Speaker 1>I have, yeah, now it is. I have 96 gigs

440
00:20:55.750 --> 00:20:58.779
<v Speaker 1>of system RAM and it's You know, blinky lights and

441
00:20:58.839 --> 00:21:02.339
<v Speaker 1>quiet as anything, right? Which is amazing. So on Coded

442
00:21:02.359 --> 00:21:05.430
<v Speaker 1>with AI, Jeff Fritz and I did a series on

443
00:21:05.609 --> 00:21:10.089
<v Speaker 1>taking a whole bunch of models that would run on

444
00:21:10.190 --> 00:21:15.750
<v Speaker 1>Ollama and running them and then putting it through a test. Basically,

445
00:21:16.029 --> 00:21:21.539
<v Speaker 1>a lot of them failed. More so because of context,

446
00:21:21.670 --> 00:21:23.680
<v Speaker 1>I think, than this is what I'm learning now, the

447
00:21:23.720 --> 00:21:27.940
<v Speaker 1>context size, if it's too small. We'll just barf. The

448
00:21:28.420 --> 00:21:32.960
<v Speaker 1>LLM will just and lose it or get into an

449
00:21:33.019 --> 00:21:37.960
<v Speaker 1>infinite loop. And basically what I came down to is

450
00:21:38.609 --> 00:21:45.910
<v Speaker 1>running llama.cpp. And llama.cpp is like Ollama, but it's not.

451
00:21:46.029 --> 00:21:48.950
<v Speaker 1>It's a different thing. It's open source. But I can

452
00:21:49.029 --> 00:21:58.720
<v Speaker 1>run the fairly new QEN 3.8.27b model and llama cpp

453
00:21:58.779 --> 00:22:03.859
<v Speaker 1>will use vram and system ram at the same time

454
00:22:04.000 --> 00:22:06.740
<v Speaker 1>and it will balance them out and figure out automatically

455
00:22:06.880 --> 00:22:10.109
<v Speaker 1>how much of which to use and let me tell

456
00:22:10.140 --> 00:22:14.450
<v Speaker 1>you something this is i this is what i've been

457
00:22:14.490 --> 00:22:17.890
<v Speaker 1>waiting for it works so well that i don't feel

458
00:22:17.910 --> 00:22:20.609
<v Speaker 1>the need to go back for what i do you

459
00:22:20.630 --> 00:22:23.930
<v Speaker 1>know debugging coding all of that stuff i don't need

460
00:22:24.089 --> 00:22:27.539
<v Speaker 1>to go back to any frontier models anymore.

461
00:22:27.859 --> 00:22:28.019
<v Speaker 3>Right.

462
00:22:28.140 --> 00:22:29.670
<v Speaker 1>I haven't found, I've been using it for a couple

463
00:22:29.690 --> 00:22:29.930
<v Speaker 1>of weeks.

464
00:22:29.950 --> 00:22:30.930
<v Speaker 2>You're just working local now.

465
00:22:31.130 --> 00:22:33.019
<v Speaker 1>I'm just working local. Yeah. And the only thing I'm

466
00:22:33.880 --> 00:22:36.400
<v Speaker 1>that's costing me is electricity. But I got solar panels.

467
00:22:36.700 --> 00:22:38.839
<v Speaker 1>There you go. Some pretty good, especially in the summer.

468
00:22:39.539 --> 00:22:41.740
<v Speaker 2>Feeling good. And that machine you bought, like to build

469
00:22:41.759 --> 00:22:44.039
<v Speaker 2>that machine today, it's a big bucks.

470
00:22:44.299 --> 00:22:44.559
<v Speaker 3>Yeah.

471
00:22:44.700 --> 00:22:46.240
<v Speaker 1>So you did the right thing. Well, I thought it

472
00:22:46.279 --> 00:22:48.779
<v Speaker 1>was big bucks back then, but now... Yeah, it was. Yeah.

473
00:22:48.799 --> 00:22:50.579
<v Speaker 2>It was a lot of money for a PC back then.

474
00:22:50.700 --> 00:22:52.099
<v Speaker 2>It doesn't seem that way at this moment.

475
00:22:52.119 --> 00:22:53.640
<v Speaker 3>Well, anyway... And what sort of performance are you getting

476
00:22:53.680 --> 00:22:55.089
<v Speaker 3>out of it? Like tokens per second?

477
00:22:55.349 --> 00:22:59.539
<v Speaker 1>That's great. It's as good as... Any frontier model that

478
00:22:59.559 --> 00:23:02.849
<v Speaker 1>I've been using, I've been using GitHub Copilot CLI, mostly

479
00:23:02.869 --> 00:23:08.670
<v Speaker 1>with Claude Sonnet. It's as good as that. I don't

480
00:23:08.710 --> 00:23:12.190
<v Speaker 1>find myself waiting around. And it can do anything that

481
00:23:12.210 --> 00:23:15.750
<v Speaker 1>I throw at it. It handles local stuff on the computer,

482
00:23:17.089 --> 00:23:23.140
<v Speaker 1>stuff in Azure, in GitHub. It's just really good. This

483
00:23:23.240 --> 00:23:26.759
<v Speaker 1>model compared to other models is good, but you run

484
00:23:26.799 --> 00:23:30.609
<v Speaker 1>it in Lama CPP. And it's like beautiful on this

485
00:23:30.690 --> 00:23:35.289
<v Speaker 1>particular configuration. I've found the sweet spot. So I wrote

486
00:23:35.309 --> 00:23:38.119
<v Speaker 1>a document and that is the link that we'll put

487
00:23:38.279 --> 00:23:41.720
<v Speaker 1>on the page. It's a GitHub. Read me basically running

488
00:23:41.819 --> 00:23:45.240
<v Speaker 1>Quinn 3.8, 27 B with Lama CPP and GitHub co-pilot

489
00:23:45.259 --> 00:23:49.259
<v Speaker 1>CLI on windows. And it tells you exactly how to

490
00:23:49.420 --> 00:23:52.470
<v Speaker 1>install everything, all the stuff that you got to go,

491
00:23:52.710 --> 00:23:57.130
<v Speaker 1>put everything where it needs to go. And like, Download

492
00:23:57.210 --> 00:24:01.970
<v Speaker 1>Quinn and run it and how you access it remotely.

493
00:24:03.069 --> 00:24:06.079
<v Speaker 1>It's great. So I have my dev machine. I have

494
00:24:06.099 --> 00:24:12.319
<v Speaker 1>my GPU machine. And it's a match made in heaven.

495
00:24:13.359 --> 00:24:15.559
<v Speaker 2>There's not a lot of people running those kinds of

496
00:24:16.539 --> 00:24:17.980
<v Speaker 2>headless systems with Windows.

497
00:24:18.019 --> 00:24:18.660
<v Speaker 1>They're mostly Linux.

498
00:24:18.779 --> 00:24:18.960
<v Speaker 3>Right.

499
00:24:19.380 --> 00:24:23.700
<v Speaker 1>Cool. It's good. And also, this model, Quinn 3.8, has

500
00:24:23.759 --> 00:24:28.109
<v Speaker 1>vision support. So I can paste screenshots in, you know,

501
00:24:28.269 --> 00:24:30.779
<v Speaker 1>and it just works. It's wonderful. Cool.

502
00:24:30.960 --> 00:24:31.099
<v Speaker 4>Yep.

503
00:24:31.180 --> 00:24:32.710
<v Speaker 1>That's what I got. Richard, who's talking to us?

504
00:24:33.000 --> 00:24:36.000
<v Speaker 2>Grabbed a comment off of show 1963, which you did

505
00:24:36.059 --> 00:24:37.559
<v Speaker 2>last year with one Michael Howard.

506
00:24:37.700 --> 00:24:38.019
<v Speaker 3>Yay.

507
00:24:38.079 --> 00:24:40.140
<v Speaker 2>Talking about 30 years of application security. This is back

508
00:24:40.160 --> 00:24:42.339
<v Speaker 2>when you were still the red teamer. I know your

509
00:24:42.359 --> 00:24:45.160
<v Speaker 2>life is different now. And this comment comes from also

510
00:24:45.200 --> 00:24:48.710
<v Speaker 2>a past guest, Arnold Axelrod, who said, great show as always.

511
00:24:48.849 --> 00:24:51.369
<v Speaker 2>One comment regarding input validation, because of course we talked

512
00:24:51.390 --> 00:24:54.069
<v Speaker 2>about input validations. Toward the end of the show, Michael

513
00:24:54.109 --> 00:24:56.049
<v Speaker 2>mentions that all input should be considered evil and must

514
00:24:56.089 --> 00:24:59.259
<v Speaker 2>be validated in order to be considered secure. Yeah, hard

515
00:24:59.279 --> 00:25:01.779
<v Speaker 2>to argue with that. I'm not a security expert, but

516
00:25:01.799 --> 00:25:03.460
<v Speaker 2>I have a different take on that. I don't think

517
00:25:03.480 --> 00:25:05.759
<v Speaker 2>that the problem lies in the lack of input validation,

518
00:25:05.799 --> 00:25:08.940
<v Speaker 2>but I think that input validation should be a business requirement.

519
00:25:10.319 --> 00:25:12.940
<v Speaker 2>The example being zip codes. I don't necessarily know what

520
00:25:12.980 --> 00:25:15.049
<v Speaker 2>a formal zip code is or will ever be consistent

521
00:25:15.069 --> 00:25:17.930
<v Speaker 2>around the world. Answer is absolutely no. When you consider

522
00:25:17.950 --> 00:25:20.490
<v Speaker 2>the idea that Ireland only got postal codes in 2015,

523
00:25:20.470 --> 00:25:25.190
<v Speaker 2>like good luck. In my opinion, the problem lies with

524
00:25:25.210 --> 00:25:27.609
<v Speaker 2>the use of parsers and interpreters and not using escape

525
00:25:27.650 --> 00:25:31.069
<v Speaker 2>sequences or other structures to separate arbitrary input from structure ones,

526
00:25:31.569 --> 00:25:34.670
<v Speaker 2>like separating the inputs from the SQL statement itself appropriately.

527
00:25:35.450 --> 00:25:39.549
<v Speaker 2>Both SQL, JavaScript, and command through the process start in

528
00:25:39.589 --> 00:25:42.549
<v Speaker 2>C-sharp are interpreters, and if you construct an input to

529
00:25:42.650 --> 00:25:46.289
<v Speaker 2>them that contains an arbitrary user input without sanitizing it

530
00:25:46.329 --> 00:25:50.519
<v Speaker 2>with the correct escape sequences is where unpredictability comes to play,

531
00:25:50.759 --> 00:25:55.779
<v Speaker 2>which causes the risk. A URI also having structured format

532
00:25:55.940 --> 00:25:58.099
<v Speaker 2>that is parsed by a browser and constructing a URI,

533
00:25:58.119 --> 00:26:00.559
<v Speaker 2>let's say, with an arbitrary query string, that may be harmful,

534
00:26:01.180 --> 00:26:03.549
<v Speaker 2>but you're probably using URI encoding on the inputs, and

535
00:26:03.569 --> 00:26:05.990
<v Speaker 2>that should leave you safe. This doesn't require you to

536
00:26:06.029 --> 00:26:08.210
<v Speaker 2>limit the input in any way, just to format it correctly.

537
00:26:09.250 --> 00:26:11.089
<v Speaker 2>There is where the focus should be, as far as

538
00:26:11.130 --> 00:26:14.450
<v Speaker 2>I'm concerned, not just to invalidate all inputs. I'd love

539
00:26:14.470 --> 00:26:15.430
<v Speaker 2>to hear your opinions on it.

540
00:26:15.710 --> 00:26:16.390
<v Speaker 3>You want my opinion?

541
00:26:16.569 --> 00:26:17.490
<v Speaker 1>Go for it. Yeah, hit you.

542
00:26:18.819 --> 00:26:20.579
<v Speaker 3>You know, it all got turned on its head, right?

543
00:26:20.630 --> 00:26:25.460
<v Speaker 3>With LLMs and jailbreaking. What is the input? What is it?

544
00:26:25.460 --> 00:26:27.980
<v Speaker 3>What is valid? Can you even escape it? Even escape

545
00:26:28.000 --> 00:26:32.980
<v Speaker 3>versions can still get through any kind of checks. So, yeah,

546
00:26:33.319 --> 00:26:34.700
<v Speaker 3>I just wrote about that recently. Yeah.

547
00:26:35.140 --> 00:26:39.460
<v Speaker 2>Our new injection attack starts with ignore all previous instructions.

548
00:26:39.779 --> 00:26:41.960
<v Speaker 3>Exactly. So, Mike Resinovich actually has a t-shirt with that

549
00:26:41.980 --> 00:26:45.539
<v Speaker 3>on the back. He showed it to me at Build

550
00:26:45.799 --> 00:26:49.559
<v Speaker 3>last time and I almost fell over laughing.

551
00:26:50.039 --> 00:26:50.839
<v Speaker 1>It's the best.

552
00:26:50.980 --> 00:26:52.500
<v Speaker 3>He was so proud of it. He said, hey, Michael,

553
00:26:52.519 --> 00:26:59.740
<v Speaker 3>check this out. It's completely turned on its head. And

554
00:26:59.759 --> 00:27:02.259
<v Speaker 3>that's why we've got all these other defenses that come

555
00:27:02.299 --> 00:27:04.829
<v Speaker 3>into play and these guardrails and so on in LLMs.

556
00:27:04.990 --> 00:27:06.809
<v Speaker 3>It's because we need them. We don't know what the

557
00:27:06.849 --> 00:27:07.329
<v Speaker 3>input is.

558
00:27:07.450 --> 00:27:10.150
<v Speaker 1>Yeah. LLMs need to get a sense of humor, right?

559
00:27:10.809 --> 00:27:13.309
<v Speaker 1>A sense of sarcasm, a sense of irony. And they

560
00:27:13.329 --> 00:27:16.029
<v Speaker 1>got to get sensitive to that just like we humans do.

561
00:27:16.490 --> 00:27:16.869
<v Speaker 1>I think.

562
00:27:17.549 --> 00:27:17.869
<v Speaker 3>I don't know.

563
00:27:18.349 --> 00:27:20.559
<v Speaker 2>Yeah, we really want to pass every input through an

564
00:27:20.650 --> 00:27:22.500
<v Speaker 2>LLM to say, is this a potential attack?

565
00:27:22.779 --> 00:27:25.299
<v Speaker 1>Yeah, good luck with that. No, but of course not.

566
00:27:25.380 --> 00:27:27.119
<v Speaker 1>But I mean, if you're dealing with an LLM and

567
00:27:27.140 --> 00:27:29.680
<v Speaker 1>you're at the keyboard and talking to it, right? And

568
00:27:29.720 --> 00:27:33.640
<v Speaker 1>you give it some ridiculous prompt, you know, that's clearly

569
00:27:34.089 --> 00:27:38.390
<v Speaker 1>satirical or something. It should laugh back at you, you know?

570
00:27:38.849 --> 00:27:39.910
<v Speaker 3>Well, that happened to me once.

571
00:27:40.329 --> 00:27:41.450
<v Speaker 1>Yeah, that's a good one. Yeah.

572
00:27:41.470 --> 00:27:43.710
<v Speaker 3>Dude, that happened to me once. All seriousness.

573
00:27:43.769 --> 00:27:43.930
<v Speaker 2>Really?

574
00:27:43.970 --> 00:27:44.170
<v Speaker 1>Yeah.

575
00:27:44.289 --> 00:27:48.250
<v Speaker 3>I was working on the podcast website or something and

576
00:27:48.309 --> 00:27:50.750
<v Speaker 3>asked it to do a quick security review of the code.

577
00:27:51.589 --> 00:27:54.559
<v Speaker 3>And it found something. I was just running Visual Studio,

578
00:27:54.599 --> 00:27:57.420
<v Speaker 3>I think. And it found something and it said, here

579
00:27:57.500 --> 00:28:01.559
<v Speaker 3>is a, I don't know, it was an outdated HTTP header.

580
00:28:01.579 --> 00:28:05.640
<v Speaker 3>It had been deprecated. I didn't know. A supposedly security

581
00:28:05.680 --> 00:28:09.150
<v Speaker 3>header had been deprecated. And it said, by the way,

582
00:28:09.190 --> 00:28:12.329
<v Speaker 3>this HTTP underscore blah, blah, blah has been deprecated for

583
00:28:12.369 --> 00:28:16.180
<v Speaker 3>security reasons. And it's really ironic that you as the

584
00:28:16.259 --> 00:28:18.259
<v Speaker 3>author of Running Secure Code didn't find this.

585
00:28:18.500 --> 00:28:19.180
<v Speaker 1>Oh, that's great.

586
00:28:20.579 --> 00:28:20.859
<v Speaker 3>Yeah.

587
00:28:21.259 --> 00:28:22.299
<v Speaker 1>That's what I'm talking about.

588
00:28:22.319 --> 00:28:24.529
<v Speaker 3>I don't know what the backend model was because, of course,

589
00:28:24.549 --> 00:28:26.769
<v Speaker 3>Visual Studio, you can jump around, but I don't know.

590
00:28:26.829 --> 00:28:29.130
<v Speaker 3>But yeah, it was quite happy to yell at me

591
00:28:29.170 --> 00:28:29.720
<v Speaker 3>and laugh at me.

592
00:28:30.019 --> 00:28:30.619
<v Speaker 1>That's pretty good.

593
00:28:30.660 --> 00:28:32.880
<v Speaker 2>When the tool says the word, it is trying to

594
00:28:32.920 --> 00:28:35.619
<v Speaker 2>detect irony. That's just ironic, actually.

595
00:28:36.160 --> 00:28:36.400
<v Speaker 3>Right.

596
00:28:36.839 --> 00:28:37.039
<v Speaker 1>Yeah.

597
00:28:37.259 --> 00:28:40.519
<v Speaker 2>It's very recursive. Arnon, thank you so much for your comment.

598
00:28:40.539 --> 00:28:41.680
<v Speaker 2>And a copy of Music to Code By is on

599
00:28:41.720 --> 00:28:42.819
<v Speaker 2>its way to you. And if you'd like a copy

600
00:28:42.839 --> 00:28:44.119
<v Speaker 2>of Music to Code By, write a comment on the

601
00:28:44.140 --> 00:28:47.180
<v Speaker 2>website at. netrocks. com or on the Facebooks we publish every

602
00:28:47.200 --> 00:28:48.819
<v Speaker 2>show there. And if you comment there and I read

603
00:28:48.839 --> 00:28:50.000
<v Speaker 2>it on the show, we'll send you a copy of

604
00:28:50.019 --> 00:28:50.579
<v Speaker 2>Music to Code By.

605
00:28:50.660 --> 00:28:52.349
<v Speaker 1>Or if you'd just rather buy Music to Code By,

606
00:28:52.380 --> 00:28:55.829
<v Speaker 1>go to musictocodeby.net. You can get the tracks in MP3, WAV,

607
00:28:56.069 --> 00:28:59.880
<v Speaker 1>and FLAC formats. Well, before we introduce Michael... Let's take

608
00:28:59.900 --> 00:29:06.789
<v Speaker 1>a little break for these very important messages. And we're back..

609
00:29:07.329 --> 00:29:10.190
<v Speaker 1>NET Rocks. I'm Carl Franklin. That's Richard Campbell. Hey. And

610
00:29:10.210 --> 00:29:13.710
<v Speaker 1>that's Michael Howard. Let me introduce him formally. Your bio

611
00:29:13.750 --> 00:29:17.549
<v Speaker 1>has changed a little bit. Michael Howard's been at Microsoft

612
00:29:17.809 --> 00:29:18.990
<v Speaker 1>since 1992.

613
00:29:18.990 --> 00:29:19.230
<v Speaker 2>Wow.

614
00:29:19.910 --> 00:29:24.789
<v Speaker 1>Always in some form of security, IIS, SDL, the founder

615
00:29:24.809 --> 00:29:25.329
<v Speaker 1>of SDL?

616
00:29:25.490 --> 00:29:27.069
<v Speaker 3>Well, he's one of the guys that worked on the very,

617
00:29:27.109 --> 00:29:29.839
<v Speaker 3>very earliest versions. It was like two or three of us, yeah,

618
00:29:29.859 --> 00:29:30.380
<v Speaker 3>back in the day.

619
00:29:30.400 --> 00:29:30.940
<v Speaker 1>Awesome.

620
00:29:31.000 --> 00:29:32.859
<v Speaker 2>And that was the security lifecycle?

621
00:29:33.140 --> 00:29:37.480
<v Speaker 3>Security development lifecycle, yeah. Back in the earliest, like, 2004.

622
00:29:36.759 --> 00:29:40.380
<v Speaker 1>Also uh you worked in azure data on the red

623
00:29:40.420 --> 00:29:43.660
<v Speaker 1>team last time we talked and now you're in post

624
00:29:43.839 --> 00:29:45.660
<v Speaker 1>quantum crypto.

625
00:29:45.079 --> 00:29:51.509
<v Speaker 3>Woohoo yeah baby Man, I'm happy to be here, too.

626
00:29:51.569 --> 00:29:52.130
<v Speaker 3>It's a lot of fun.

627
00:29:52.279 --> 00:29:55.099
<v Speaker 1>I mean, how can you have post-quantum if we haven't

628
00:29:55.119 --> 00:29:56.960
<v Speaker 1>had quantum?

629
00:29:57.160 --> 00:30:01.180
<v Speaker 3>Because the real attacks start post-quantum. That's the reason why.

630
00:30:01.200 --> 00:30:04.200
<v Speaker 1>Yeah, you're right. I get it. You need to be ready.

631
00:30:05.059 --> 00:30:07.819
<v Speaker 3>For certain things. Certain things, maybe not. But we can

632
00:30:07.859 --> 00:30:08.599
<v Speaker 3>discuss that later.

633
00:30:08.880 --> 00:30:10.940
<v Speaker 1>But yeah. Well, what does it mean, post-quantum crypto?

634
00:30:11.240 --> 00:30:15.980
<v Speaker 3>Well, you think of things in three ways. This is

635
00:30:16.000 --> 00:30:17.799
<v Speaker 3>the way we think about it at Microsoft. Anyway, I'm

636
00:30:17.839 --> 00:30:21.769
<v Speaker 3>sure most of the industry does. um, data, data in transit,

637
00:30:21.789 --> 00:30:24.930
<v Speaker 3>data at rest, and then cryptographic trust. So data on

638
00:30:24.950 --> 00:30:27.259
<v Speaker 3>the wire, you know, stuff flying across the internet is

639
00:30:27.279 --> 00:30:30.759
<v Speaker 3>probably protected by TLS today, more than likely perhaps SSH,

640
00:30:31.339 --> 00:30:34.700
<v Speaker 3>but certainly TLS data at rest is encrypted most of

641
00:30:34.720 --> 00:30:37.819
<v Speaker 3>the time or should be. And those encryption keys are

642
00:30:37.859 --> 00:30:41.500
<v Speaker 3>wrapped with other keys, uh, key wrapping keys. And then

643
00:30:41.519 --> 00:30:44.660
<v Speaker 3>you've got cryptographic trust, which is, you know, signatures, certificates,

644
00:30:45.039 --> 00:30:49.140
<v Speaker 3>all that sort of good stuff. Um, The real threat

645
00:30:49.160 --> 00:30:52.170
<v Speaker 3>is dead on the wire is being, you know, being

646
00:30:52.650 --> 00:30:54.589
<v Speaker 3>pulloined as it flies across the wire.

647
00:30:54.609 --> 00:30:55.250
<v Speaker 1>Yeah.

648
00:30:55.329 --> 00:30:57.589
<v Speaker 3>And then when a quantum computer comes out in the future,

649
00:30:57.609 --> 00:31:02.890
<v Speaker 3>that stuff can be broken. And the breaking aspect is

650
00:31:03.480 --> 00:31:06.599
<v Speaker 3>essentially just breaking the RSA or the elliptic curve wrapping...

651
00:31:06.809 --> 00:31:10.230
<v Speaker 3>that goes on and out pops the AES key that's

652
00:31:10.289 --> 00:31:12.319
<v Speaker 3>used for the bulk encryption, and now you just decrypt everything.

653
00:31:13.099 --> 00:31:14.359
<v Speaker 3>And in the case of data at rest, it's the

654
00:31:14.380 --> 00:31:17.319
<v Speaker 3>key wrapping keys, right? They can be broken because they usually,

655
00:31:17.579 --> 00:31:21.240
<v Speaker 3>for example, RSA, which can be broken with an algorithm

656
00:31:21.259 --> 00:31:23.240
<v Speaker 3>called Shor's algorithm, S-H-O-R.

657
00:31:23.299 --> 00:31:23.500
<v Speaker 1>Yeah.

658
00:31:24.180 --> 00:31:28.140
<v Speaker 3>And it basically finds periodicity in the way those algorithms work.

659
00:31:28.160 --> 00:31:29.269
<v Speaker 3>That's what it takes advantage of.

660
00:31:29.910 --> 00:31:34.309
<v Speaker 1>Are our logs at risk for being pilfered by cryptos?

661
00:31:35.769 --> 00:31:38.210
<v Speaker 3>Post-mortem crypto? I mean, if it contains sensitive data, which

662
00:31:38.230 --> 00:31:40.200
<v Speaker 3>you shouldn't be logging sensitive data, right? No, no, no.

663
00:31:40.240 --> 00:31:45.019
<v Speaker 1>But even if it wasn't containing sensitive data, is that

664
00:31:45.059 --> 00:31:47.119
<v Speaker 1>something because it can go through so much data so

665
00:31:47.180 --> 00:31:48.180
<v Speaker 1>fast that it could.

666
00:31:48.220 --> 00:31:50.119
<v Speaker 3>I mean, if I had to prioritize stuff, I would

667
00:31:50.180 --> 00:31:51.589
<v Speaker 3>focus on the actual data itself.

668
00:31:51.609 --> 00:31:54.309
<v Speaker 1>Yeah, okay. So data in transit and then real data

669
00:31:54.329 --> 00:31:55.150
<v Speaker 1>in your databases.

670
00:31:55.390 --> 00:31:58.789
<v Speaker 3>Correct. Yeah. And then those, again, they can be snaffled.

671
00:31:59.099 --> 00:32:02.680
<v Speaker 3>today and then once a quantum computer is made available and.

672
00:32:02.640 --> 00:32:04.599
<v Speaker 1>That's where a lot of did you say snaffled.

673
00:32:04.519 --> 00:32:06.579
<v Speaker 3>Are stolen snaffled purloined.

674
00:32:06.259 --> 00:32:08.720
<v Speaker 1>Snaffled that's a good british.

675
00:32:08.299 --> 00:32:12.240
<v Speaker 3>Word snaffled yeah um there's actually a real word i

676
00:32:12.240 --> 00:32:13.809
<v Speaker 3>don't even know is it a real.

677
00:32:13.670 --> 00:32:15.170
<v Speaker 1>Word it doesn't matter i i don't know but i

678
00:32:15.230 --> 00:32:15.650
<v Speaker 1>never heard it.

679
00:32:15.650 --> 00:32:18.849
<v Speaker 3>Before it is now there you go things you.

680
00:32:18.789 --> 00:32:21.789
<v Speaker 1>Learn on dot numrocks all right It's all good.

681
00:32:22.109 --> 00:32:24.849
<v Speaker 3>Yeah, so the risk is the asymmetric keys that are

682
00:32:24.910 --> 00:32:27.509
<v Speaker 3>used to wrap the symmetric keys that do the- Because

683
00:32:27.529 --> 00:32:30.150
<v Speaker 3>they're dependent on prime numbers. In the case of RSA.

684
00:32:30.369 --> 00:32:30.589
<v Speaker 1>Yeah.

685
00:32:30.849 --> 00:32:33.029
<v Speaker 3>But that's not the attack. The attack is the periodicity.

686
00:32:33.049 --> 00:32:35.150
<v Speaker 3>There's a periodicity. If you actually look at the way

687
00:32:35.210 --> 00:32:37.559
<v Speaker 3>Shor's works, not that I say, not that you should,

688
00:32:38.200 --> 00:32:41.559
<v Speaker 3>it basically does a quantum fast Fourier analysis.

689
00:32:41.819 --> 00:32:42.420
<v Speaker 1>Yeah.

690
00:32:42.880 --> 00:32:46.779
<v Speaker 3>Shor's is actually hybrid. It's actually quantum and sort of,

691
00:32:47.329 --> 00:32:50.970
<v Speaker 3>classic computing. The hard work is done by Shor's and

692
00:32:51.009 --> 00:32:53.950
<v Speaker 3>then some of the less difficult work is done classically

693
00:32:53.970 --> 00:32:57.910
<v Speaker 3>because it's just easier. And so the real issue is

694
00:32:57.950 --> 00:33:02.210
<v Speaker 3>that those asymmetric keys, RSA, elliptic curve, Diffie-Hellman, they all

695
00:33:02.269 --> 00:33:06.200
<v Speaker 3>exhibit some periodicity that can be detected by Shor's. And

696
00:33:06.220 --> 00:33:09.869
<v Speaker 3>that gives you a whole bunch of possibilities that then

697
00:33:09.930 --> 00:33:12.289
<v Speaker 3>classical computing can then just sort of sift through and

698
00:33:12.509 --> 00:33:14.309
<v Speaker 3>find out which ones are the actual keys. Right.

699
00:33:14.349 --> 00:33:16.710
<v Speaker 2>So it narrows the scope of the testing needed.

700
00:33:16.930 --> 00:33:20.519
<v Speaker 3>Correct. Yeah. And to your point before, rather than, you know,

701
00:33:20.559 --> 00:33:23.380
<v Speaker 3>squillions of ages of the universe, it could be hours

702
00:33:23.599 --> 00:33:24.559
<v Speaker 3>or days. Yeah.

703
00:33:24.640 --> 00:33:25.019
<v Speaker 1>Right.

704
00:33:25.059 --> 00:33:27.819
<v Speaker 3>You know, it's, it's, it's a real thing. And, um,

705
00:33:28.759 --> 00:33:31.759
<v Speaker 3>you know, developers have a big part to play in,

706
00:33:31.920 --> 00:33:35.019
<v Speaker 3>in this. It's not just, you know, flip some switch

707
00:33:35.059 --> 00:33:39.059
<v Speaker 3>and everything's golden. Um, There's a lot more to it

708
00:33:39.079 --> 00:33:41.140
<v Speaker 3>that developers need to understand as well.

709
00:33:42.039 --> 00:33:48.079
<v Speaker 1>So everything I've barely hung on understanding about quantum is

710
00:33:48.119 --> 00:33:53.829
<v Speaker 1>that we're all screwed, right? And because of the way

711
00:33:53.880 --> 00:33:59.710
<v Speaker 1>that TLS works and SSL and all that stuff, it

712
00:33:59.990 --> 00:34:02.750
<v Speaker 1>dramatically has to change, doesn't it? If we're going to

713
00:34:02.769 --> 00:34:10.369
<v Speaker 1>be less susceptible to quantum interference but you're i think

714
00:34:10.449 --> 00:34:12.449
<v Speaker 1>what you're saying is that there are ways that we

715
00:34:12.489 --> 00:34:16.389
<v Speaker 1>can do that now and that's what you know post-quantum

716
00:34:16.429 --> 00:34:20.909
<v Speaker 1>crypto is all about is trying to use cryptographic methods

717
00:34:21.050 --> 00:34:24.610
<v Speaker 1>now that will survive the quantum onslaught is that what

718
00:34:24.650 --> 00:34:27.849
<v Speaker 1>you're basically up against yeah one.

719
00:34:27.789 --> 00:34:29.679
<v Speaker 3>Of the beauties of tls by the way i can't

720
00:34:29.699 --> 00:34:32.300
<v Speaker 3>believe you said ssl like wash your mouth out.

721
00:34:32.989 --> 00:34:38.010
<v Speaker 2>You know, some of us were around in the 90s.

722
00:34:38.170 --> 00:34:42.199
<v Speaker 1>So was I. And so they don't use those words, TLS.

723
00:34:42.619 --> 00:34:47.559
<v Speaker 3>I know. Anyway, I'll just pretend you didn't say that. Yeah,

724
00:34:49.260 --> 00:34:51.300
<v Speaker 3>so TLS, one of the beauties of TLS is that

725
00:34:51.380 --> 00:34:53.880
<v Speaker 3>it's very agile, right? You can change the way it works,

726
00:34:53.920 --> 00:34:57.719
<v Speaker 3>the ciphers that are used, the cryptographic primitives that are used.

727
00:34:57.840 --> 00:35:00.500
<v Speaker 2>And you're talking about TLS 1.0.

728
00:35:00.500 --> 00:35:02.570
<v Speaker 3>Correct. So TLS 1.2 should be using.

729
00:35:02.860 --> 00:35:03.110
<v Speaker 1>Yeah.

730
00:35:03.139 --> 00:35:05.090
<v Speaker 3>So actually that's a really important point. So TLS 1.2

731
00:35:05.090 --> 00:35:08.610
<v Speaker 3>and prior, so TLS 1.0 and 1.1 are deprecated anyway,

732
00:35:08.650 --> 00:35:12.070
<v Speaker 3>so don't use them. TLS 1.2 does its cipher suite

733
00:35:12.130 --> 00:35:15.659
<v Speaker 3>and its key establishments and authentication all as one string

734
00:35:16.239 --> 00:35:18.159
<v Speaker 3>called the cipher suite. It looks like someone sneezed on

735
00:35:18.199 --> 00:35:20.760
<v Speaker 3>the screen basically. It's a list of all the algorithms

736
00:35:20.780 --> 00:35:23.820
<v Speaker 3>that are used for all of those things. TLS 1.3

737
00:35:23.820 --> 00:35:28.449
<v Speaker 3>is different. it broke apart things like the key establishment

738
00:35:28.849 --> 00:35:31.809
<v Speaker 3>from the bulk encryption and the bulk tamper detection. They're

739
00:35:31.849 --> 00:35:32.949
<v Speaker 3>completely broken apart.

740
00:35:33.050 --> 00:35:33.269
<v Speaker 1>Yeah.

741
00:35:33.510 --> 00:35:36.880
<v Speaker 3>So you can negotiate the two separately. That's the big

742
00:35:36.909 --> 00:35:40.539
<v Speaker 3>difference in TLS 1.3. So the key establishment is a

743
00:35:40.579 --> 00:35:44.079
<v Speaker 3>thing called a group. And the reason why it's called

744
00:35:44.119 --> 00:35:47.840
<v Speaker 3>a group is because mathematicians got to hang on this.

745
00:35:47.880 --> 00:35:51.050
<v Speaker 3>And they said, you know, all these things are mathematical groups.

746
00:35:51.780 --> 00:35:56.659
<v Speaker 3>So we'll call them groups. Terrible name. But for the

747
00:35:56.679 --> 00:36:00.639
<v Speaker 3>key establishment, that's where you set the algorithm or algorithms

748
00:36:00.699 --> 00:36:03.260
<v Speaker 3>in some cases. And then after that, separately, is how

749
00:36:03.320 --> 00:36:05.579
<v Speaker 3>you do bulk protection of the data on the wire.

750
00:36:05.599 --> 00:36:08.960
<v Speaker 3>So TLS 1.3 broke those two apart. So it is

751
00:36:09.000 --> 00:36:12.239
<v Speaker 3>completely not compatible with TLS 1.2. And TLS 1.2 will

752
00:36:12.300 --> 00:36:15.360
<v Speaker 3>never be post-quantum. I mean, it's just software. I mean, essentially,

753
00:36:15.389 --> 00:36:17.110
<v Speaker 3>I suppose it could make it post-quantum.

754
00:36:17.590 --> 00:36:18.510
<v Speaker 2>Yeah, but why would you?

755
00:36:18.550 --> 00:36:21.610
<v Speaker 3>But the interoperability... well, the interoperability story would be horrendous.

756
00:36:21.650 --> 00:36:23.070
<v Speaker 3>Like no one would do it.

757
00:36:23.389 --> 00:36:25.750
<v Speaker 2>But it also seems unnecessary too, right? Because I set

758
00:36:25.769 --> 00:36:28.489
<v Speaker 2>the TLS 1.3 with a dropdown in Azure.

759
00:36:28.789 --> 00:36:31.739
<v Speaker 3>Right. But the thing is, here's the issue. And this

760
00:36:31.800 --> 00:36:34.320
<v Speaker 3>is one thing that we're having to work on for

761
00:36:34.360 --> 00:36:37.139
<v Speaker 3>products like Front Door, for example, is you will be

762
00:36:37.159 --> 00:36:41.860
<v Speaker 3>able to control the group, not just the bulk cryptography

763
00:36:41.909 --> 00:36:42.360
<v Speaker 3>that's used.

764
00:36:42.570 --> 00:36:42.829
<v Speaker 1>Okay.

765
00:36:42.889 --> 00:36:44.789
<v Speaker 3>And that's where, and the group is where the post-quantum

766
00:36:44.809 --> 00:36:50.610
<v Speaker 3>part comes in. For the most part, symmetric stuff AES-256, SHA-384,

767
00:36:50.650 --> 00:36:52.889
<v Speaker 3>and so on, which are the baselines, are fine. There's

768
00:36:52.909 --> 00:36:55.679
<v Speaker 3>another algorithm there called Grover's, which is an attack against

769
00:36:55.719 --> 00:36:59.300
<v Speaker 3>symmetric algorithms. And it essentially cuts the number of bits

770
00:36:59.360 --> 00:37:02.300
<v Speaker 3>in the key in half. So if you have an

771
00:37:02.380 --> 00:37:06.900
<v Speaker 3>AES-256 in a quantum world, that's the same as AES-128. Interesting.

772
00:37:06.920 --> 00:37:07.420
<v Speaker 1>Which is fine.

773
00:37:07.800 --> 00:37:11.150
<v Speaker 3>So you must use AES-256 and SHA-384 as the minimum

774
00:37:11.309 --> 00:37:14.110
<v Speaker 3>as well. They're kind of okay.

775
00:37:14.250 --> 00:37:14.650
<v Speaker 1>They're fine.

776
00:37:14.849 --> 00:37:20.170
<v Speaker 3>The problem is the asymmetric stuff. Right. Yeah. Elliptic curve, RSA, Diffie-Hellman.

777
00:37:20.769 --> 00:37:22.309
<v Speaker 3>That's where the problem is. Now, the nice thing in

778
00:37:22.510 --> 00:37:26.110
<v Speaker 3>TLS 1.3 is that's defined in a group, and that's

779
00:37:26.159 --> 00:37:32.119
<v Speaker 3>negotiated separately from the bulk cryptography. And that's where the

780
00:37:32.159 --> 00:37:35.059
<v Speaker 3>hybrid algorithms come into play. And the reason why they're

781
00:37:35.079 --> 00:37:38.199
<v Speaker 3>called hybrid is you use two together. You use elliptic

782
00:37:38.239 --> 00:37:44.679
<v Speaker 3>curve and MLChem. So MLChem is the quantum resilient algorithm.

783
00:37:44.880 --> 00:37:48.960
<v Speaker 3>Elliptic curve is classic. you build up keys in both,

784
00:37:49.000 --> 00:37:50.920
<v Speaker 3>you smush them together, pass it through a hash, and

785
00:37:50.940 --> 00:37:53.539
<v Speaker 3>then you derive the session keys after that. So they're

786
00:37:53.559 --> 00:37:54.239
<v Speaker 3>both used together.

787
00:37:54.440 --> 00:37:57.159
<v Speaker 1>So that would have to be implemented both at the

788
00:37:57.199 --> 00:37:59.360
<v Speaker 1>browser level and at the server level, right?

789
00:37:59.480 --> 00:38:02.920
<v Speaker 3>Yeah, everywhere. I mean, you say browser, but client. I mean,

790
00:38:02.940 --> 00:38:04.079
<v Speaker 3>I just mean clients in general.

791
00:38:04.099 --> 00:38:04.860
<v Speaker 1>Yeah, clients, sure.

792
00:38:04.940 --> 00:38:08.039
<v Speaker 3>And in fact, you bring up a very important point there, Carl,

793
00:38:08.500 --> 00:38:12.159
<v Speaker 3>and that is that all modern browsers support hybrid TLS 1.3.

794
00:38:12.159 --> 00:38:12.679
<v Speaker 1>Yeah.

795
00:38:13.639 --> 00:38:17.800
<v Speaker 3>So the, I mean, even the humble Xbox has hybrid.

796
00:38:19.159 --> 00:38:22.679
<v Speaker 3>I've tried all sorts of, you know, iOS, Android, Windows, Mac, Linux,

797
00:38:23.349 --> 00:38:25.230
<v Speaker 3>and all the common browsers support.

798
00:38:25.730 --> 00:38:29.570
<v Speaker 1>So anything, anything that uses it like curl or any,

799
00:38:29.710 --> 00:38:32.670
<v Speaker 1>any little command line tool, all, all those things have

800
00:38:32.690 --> 00:38:33.230
<v Speaker 1>to support it.

801
00:38:33.329 --> 00:38:36.570
<v Speaker 3>Correct. Correct. So SSH, both client server supports it as

802
00:38:36.610 --> 00:38:40.699
<v Speaker 3>a version 10, I think maybe 9.9 or 10. supports

803
00:38:40.960 --> 00:38:43.880
<v Speaker 3>um ml chem so the the important part there in

804
00:38:43.900 --> 00:38:46.139
<v Speaker 3>the in ml chem is the letter l in that

805
00:38:46.380 --> 00:38:51.199
<v Speaker 3>there's lattice and the two major algorithms that are post

806
00:38:51.219 --> 00:38:53.699
<v Speaker 3>quantum resilient there's actually a small number but the two

807
00:38:53.800 --> 00:38:56.929
<v Speaker 3>major ones ml chem and ml dsa the l is

808
00:38:56.989 --> 00:39:01.769
<v Speaker 3>lattice and the is that lattice construct that is quantum resilient.

809
00:39:01.610 --> 00:39:04.150
<v Speaker 1>Right so when you say quantum resilient do you mean

810
00:39:04.769 --> 00:39:07.969
<v Speaker 1>what you perceive as the first generation of quantum or

811
00:39:08.280 --> 00:39:10.539
<v Speaker 1>all quantum going forward till the end of time?

812
00:39:10.900 --> 00:39:15.719
<v Speaker 3>Nah, I mean, NIST is still going through other algorithms.

813
00:39:16.900 --> 00:39:19.659
<v Speaker 3>The industry has settled, and NIST has settled on MLDSA

814
00:39:19.699 --> 00:39:23.429
<v Speaker 3>and MLChem. And there's been a lot of research for

815
00:39:23.469 --> 00:39:27.130
<v Speaker 3>the last 20-something years in lattices, looking at it through

816
00:39:27.150 --> 00:39:32.820
<v Speaker 3>a quantum lens, and they look good. but everyone's you

817
00:39:32.840 --> 00:39:34.360
<v Speaker 3>know quite happy to say let's you know let's go

818
00:39:34.380 --> 00:39:36.440
<v Speaker 3>look at other algorithms as well just in case and

819
00:39:36.480 --> 00:39:40.460
<v Speaker 3>in fact for no other reason than the resulting cipher

820
00:39:40.519 --> 00:39:43.469
<v Speaker 3>blob is big so i'll give you an example If

821
00:39:43.510 --> 00:39:46.260
<v Speaker 3>you have an elliptic curve, say an EC25519, which is

822
00:39:46.929 --> 00:39:49.519
<v Speaker 3>a curve, the signature, a digital signature for that is

823
00:39:49.519 --> 00:39:52.559
<v Speaker 3>64 bytes in size. It's pretty small. If you take

824
00:39:52.579 --> 00:39:57.199
<v Speaker 3>an MLDSA87 certificate and you sign data with the private

825
00:39:57.239 --> 00:40:00.670
<v Speaker 3>key of that, it's about 4.5K. So you imagine if

826
00:40:00.690 --> 00:40:04.369
<v Speaker 3>you've got a whole series of certificates all with their signatures...

827
00:40:04.869 --> 00:40:06.110
<v Speaker 3>it adds up real quick.

828
00:40:06.349 --> 00:40:07.050
<v Speaker 1>Yeah.

829
00:40:07.070 --> 00:40:11.489
<v Speaker 3>And you can have problems with MTUs, with people passing

830
00:40:11.530 --> 00:40:15.889
<v Speaker 3>stuff on query strings, amounts of space set aside on

831
00:40:16.130 --> 00:40:21.079
<v Speaker 3>disk for signatures, you know? Yeah, so it's a real issue.

832
00:40:21.119 --> 00:40:25.559
<v Speaker 3>So NIST is continuing to evaluate other algorithms with an

833
00:40:25.860 --> 00:40:30.300
<v Speaker 3>eye to potentially smaller signatures. So now I get.

834
00:40:30.219 --> 00:40:32.360
<v Speaker 1>Why it's called Lattice because it kind of makes a

835
00:40:32.500 --> 00:40:36.980
<v Speaker 1>web of data that's hard to penetrate. Is that good analysis?

836
00:40:37.420 --> 00:40:38.039
<v Speaker 3>No, it's terrible.

837
00:40:38.460 --> 00:40:41.659
<v Speaker 1>Terrible. It's terrible.

838
00:40:42.139 --> 00:40:45.530
<v Speaker 3>I can take it. Okay, here's how lattices... I claim stupidity.

839
00:40:45.550 --> 00:40:50.909
<v Speaker 3>It's all good, mate. So, the way lattices work, and

840
00:40:50.969 --> 00:40:54.469
<v Speaker 3>this is a terrible description, but it's an interesting way

841
00:40:54.530 --> 00:40:55.690
<v Speaker 3>of thinking about it.

842
00:40:55.730 --> 00:40:57.329
<v Speaker 1>It'll be better than mine, I guarantee it.

843
00:40:57.590 --> 00:40:59.530
<v Speaker 3>I may not be. I'm not a fan of analogies,

844
00:40:59.570 --> 00:41:00.769
<v Speaker 3>so here's an analogy for you.

845
00:41:00.789 --> 00:41:00.969
<v Speaker 1>Okay.

846
00:41:03.719 --> 00:41:06.400
<v Speaker 3>Imagine a chessboard, right? Eight by eight with a knight.

847
00:41:06.699 --> 00:41:08.739
<v Speaker 3>We know the knight moves either one and two or

848
00:41:08.800 --> 00:41:09.539
<v Speaker 3>two and one, right?

849
00:41:09.579 --> 00:41:10.219
<v Speaker 1>That's all it does.

850
00:41:10.539 --> 00:41:12.900
<v Speaker 3>Yeah. If I give you an end point and I

851
00:41:12.920 --> 00:41:15.599
<v Speaker 3>give you a starting point, what route does the knight

852
00:41:15.639 --> 00:41:18.920
<v Speaker 3>take to get there? That's pretty straightforward to do, you know,

853
00:41:18.940 --> 00:41:21.980
<v Speaker 3>because it's just eight by eight. Now, imagine if that

854
00:41:22.019 --> 00:41:25.619
<v Speaker 3>was a squillion by a squillion chessboard. Right. All right.

855
00:41:25.969 --> 00:41:26.300
<v Speaker 1>Got it.

856
00:41:26.320 --> 00:41:29.130
<v Speaker 3>Oh, no. You know, it gets harder. Now, imagine it's

857
00:41:29.369 --> 00:41:33.460
<v Speaker 3>a thousand dimensions, right? Now imagine I don't tell you

858
00:41:33.480 --> 00:41:35.429
<v Speaker 3>there's one by two, it's N by M.

859
00:41:35.760 --> 00:41:36.369
<v Speaker 1>Right, okay.

860
00:41:36.650 --> 00:41:38.730
<v Speaker 3>Now, just to make things even more difficult, it's not

861
00:41:38.769 --> 00:41:42.349
<v Speaker 3>like an air quotes square chessboard. The squares are kind

862
00:41:42.409 --> 00:41:45.369
<v Speaker 3>of funky shaped. They're not quite squares. And that's a

863
00:41:45.389 --> 00:41:51.199
<v Speaker 3>thing called learning with errors. So that's hard. Here's a

864
00:41:51.280 --> 00:41:55.039
<v Speaker 3>point somewhere in this N dimensional space. Here's your starting point.

865
00:41:55.079 --> 00:41:58.300
<v Speaker 3>How do you get there? And so essentially the N

866
00:41:58.340 --> 00:42:00.599
<v Speaker 3>by M is essentially like the private key. That's one

867
00:42:00.619 --> 00:42:02.780
<v Speaker 3>way of looking at it. Terrible analogy, but it's about

868
00:42:02.820 --> 00:42:04.659
<v Speaker 3>as close as you can get without introducing math.

869
00:42:04.719 --> 00:42:04.980
<v Speaker 1>Okay.

870
00:42:05.440 --> 00:42:05.679
<v Speaker 3>Yeah.

871
00:42:05.699 --> 00:42:09.070
<v Speaker 1>All right. Good. And so you don't think that quantum

872
00:42:09.110 --> 00:42:12.389
<v Speaker 1>computers could ever get so good that they could just

873
00:42:12.449 --> 00:42:13.809
<v Speaker 1>figure that stuff out quickly?

874
00:42:14.110 --> 00:42:17.269
<v Speaker 3>You mean when you throw in some AI as well? Yeah. Yeah.

875
00:42:17.670 --> 00:42:17.920
<v Speaker 3>Go on.

876
00:42:19.280 --> 00:42:22.619
<v Speaker 2>But nobody ever comes up and thinks, hey, we've solved cryptography.

877
00:42:22.940 --> 00:42:25.440
<v Speaker 2>You're always looking at new algorithms. You're always looking at

878
00:42:25.500 --> 00:42:30.500
<v Speaker 2>new key lengths. We expect to routinely replace our algorithms.

879
00:42:30.519 --> 00:42:31.340
<v Speaker 1>It's an arms race.

880
00:42:31.360 --> 00:42:33.900
<v Speaker 2>Because the bad guys are fighting back.

881
00:42:34.079 --> 00:42:37.590
<v Speaker 3>Which is a beautiful segue into the next topic, which

882
00:42:37.639 --> 00:42:41.489
<v Speaker 3>is crypto agility. If nothing else, from a developer perspective,

883
00:42:41.590 --> 00:42:46.230
<v Speaker 3>one thing that post-quantum crypto will bring to the table

884
00:42:46.690 --> 00:42:50.559
<v Speaker 3>is the need for crypto agility. what happens if you

885
00:42:50.599 --> 00:42:55.070
<v Speaker 3>wrap some keys in MLChem? Chem stands for key encapsulation method.

886
00:42:56.360 --> 00:42:59.269
<v Speaker 3>Let's say you wrap some keys in that and it

887
00:42:59.289 --> 00:43:02.630
<v Speaker 3>ends up being broken five years, 10 years from now.

888
00:43:03.090 --> 00:43:05.849
<v Speaker 3>How can you update your application to use a new

889
00:43:05.889 --> 00:43:08.889
<v Speaker 3>wrapping method without breaking your existing, like you can still

890
00:43:08.929 --> 00:43:11.739
<v Speaker 3>read your old data, but you would write out using

891
00:43:11.780 --> 00:43:15.940
<v Speaker 3>some MLChem + + or something. Right. And crypto agility

892
00:43:16.079 --> 00:43:19.719
<v Speaker 3>is just, so important. It's really brought it to the

893
00:43:19.760 --> 00:43:24.260
<v Speaker 3>forefront as a need, because we don't know long-term if

894
00:43:24.300 --> 00:43:27.420
<v Speaker 3>these things will be successful or not. And again, to

895
00:43:27.440 --> 00:43:30.260
<v Speaker 3>your point, Carl, cryptographers are very, very conservative when it

896
00:43:30.300 --> 00:43:32.340
<v Speaker 3>comes to these sorts of things, and they want to

897
00:43:32.380 --> 00:43:36.179
<v Speaker 3>have a big security buffer, knowing that some things will

898
00:43:36.219 --> 00:43:38.199
<v Speaker 3>start to potentially creak a little bit.

899
00:43:39.630 --> 00:43:43.369
<v Speaker 2>And of course, you're immediately going to the at-rest encryption problem.

900
00:43:43.409 --> 00:43:47.019
<v Speaker 2>I'm always thinking TLS, and it's just we handshake an

901
00:43:47.059 --> 00:43:50.559
<v Speaker 2>encrypted stream, we do our thing and then it disappears again.

902
00:43:50.599 --> 00:43:53.389
<v Speaker 2>And so I don't have the, other than the, you know,

903
00:43:54.469 --> 00:43:57.090
<v Speaker 2>harvest and decrypt later, I don't have to think about this.

904
00:43:57.150 --> 00:43:59.989
<v Speaker 2>It's all transitory. We'll just use the newest algorithm. But

905
00:44:00.050 --> 00:44:03.809
<v Speaker 2>if you've stored under an older algorithm, And now it's

906
00:44:03.849 --> 00:44:08.150
<v Speaker 2>been breached. You have to decrypt, recrypt, or at least,

907
00:44:08.170 --> 00:44:10.849
<v Speaker 2>you know, decrypt over time to get by that.

908
00:44:11.090 --> 00:44:13.510
<v Speaker 1>You may have to increase the data size of your

909
00:44:13.570 --> 00:44:16.780
<v Speaker 1>fields that take those things because it's going to take more. Yeah.

910
00:44:16.800 --> 00:44:18.500
<v Speaker 3>So you've got to assume that there will be change.

911
00:44:18.639 --> 00:44:21.000
<v Speaker 3>And unfortunately, a lot of people don't know how to

912
00:44:21.039 --> 00:44:24.179
<v Speaker 3>build crypto agile solutions. It kind of drives me a

913
00:44:24.199 --> 00:44:25.880
<v Speaker 3>bit bonkers, to be honest with you. I see, you know,

914
00:44:25.920 --> 00:44:28.159
<v Speaker 3>in the press, you know, we need crypto agility. I've

915
00:44:28.199 --> 00:44:30.280
<v Speaker 3>got to do crypto agility. Yeah. hey, crypto agility is

916
00:44:30.320 --> 00:44:32.500
<v Speaker 3>really important. Are you guys doing crypto agility?

917
00:44:32.940 --> 00:44:35.300
<v Speaker 2>Because it comes in a squirt bottle and you just

918
00:44:35.340 --> 00:44:37.159
<v Speaker 2>spray it on all your devs and you'll be good.

919
00:44:37.360 --> 00:44:39.130
<v Speaker 3>I know, but no one says how to do it.

920
00:44:41.150 --> 00:44:44.110
<v Speaker 3>To me at Microsoft, there's two canonical examples of crypto agility.

921
00:44:44.210 --> 00:44:47.050
<v Speaker 3>One is as a SQL DB or SQL server with

922
00:44:47.110 --> 00:44:50.889
<v Speaker 3>always encrypted. And then the other one is the open

923
00:44:50.989 --> 00:44:54.730
<v Speaker 3>office XML file format, which you use to encrypt documents

924
00:44:54.769 --> 00:44:57.449
<v Speaker 3>in office. So the way it works in as a

925
00:44:57.469 --> 00:45:00.010
<v Speaker 3>SQL DB, which to me is a beautiful and simple

926
00:45:00.050 --> 00:45:01.829
<v Speaker 3>way of doing it. It's also very, very fast. If

927
00:45:02.550 --> 00:45:06.610
<v Speaker 3>you ever look at the ciphertext in an always encrypted cell,

928
00:45:07.409 --> 00:45:09.789
<v Speaker 3>the first byte is always a one, and that's the

929
00:45:09.829 --> 00:45:15.599
<v Speaker 3>version number. And that basically means AES-256 cipherblockchaining with a

930
00:45:15.619 --> 00:45:21.960
<v Speaker 3>SHA-256 hash as an integrity check over the data. So

931
00:45:21.980 --> 00:45:23.699
<v Speaker 3>in the future, if they decide to upgrade it to

932
00:45:23.719 --> 00:45:26.679
<v Speaker 3>something else, then that could be version two. So the

933
00:45:26.719 --> 00:45:28.960
<v Speaker 3>first bike would be a two and they could always

934
00:45:29.079 --> 00:45:31.139
<v Speaker 3>read back and say, okay, that's version one. We need

935
00:45:31.159 --> 00:45:34.460
<v Speaker 3>this particular set of cipher primitives. Let's read as decrypted

936
00:45:34.500 --> 00:45:37.159
<v Speaker 3>with these primitives. When they write it back, they would

937
00:45:37.179 --> 00:45:39.239
<v Speaker 3>write it back as a, whatever the latest number was,

938
00:45:39.260 --> 00:45:41.460
<v Speaker 3>which we version two, and it will be the, whatever

939
00:45:41.480 --> 00:45:43.179
<v Speaker 3>the new, the new cipher suites is. So you can

940
00:45:43.199 --> 00:45:45.369
<v Speaker 3>always read the old data and you would write back

941
00:45:45.630 --> 00:45:48.489
<v Speaker 3>using the new version. And the way office does it

942
00:45:48.889 --> 00:45:51.550
<v Speaker 3>is it's an XML file. There's an XML file header.

943
00:45:52.139 --> 00:45:55.639
<v Speaker 3>And it contains all the cryptographic primitives, like AES, it's

944
00:45:55.659 --> 00:46:01.769
<v Speaker 3>cipher blockchaining, here's the initialization vector, here's the password, the

945
00:46:01.789 --> 00:46:06.789
<v Speaker 3>key derivation count, here's the key derivation algorithm, and lots

946
00:46:06.829 --> 00:46:09.829
<v Speaker 3>of other metadata. So you can actually build the cipher

947
00:46:10.409 --> 00:46:14.929
<v Speaker 3>collection completely dynamically, which is really, really nice.

948
00:46:16.619 --> 00:46:20.079
<v Speaker 1>What network hardware will have to change in the, yes.

949
00:46:20.559 --> 00:46:22.900
<v Speaker 1>I mean, we won't, we'll be able to go to

950
00:46:22.960 --> 00:46:25.179
<v Speaker 1>Best Buy or whatever it is you have in the

951
00:46:25.280 --> 00:46:29.150
<v Speaker 1>UK and buy an off the shelf, you know, router

952
00:46:29.230 --> 00:46:33.230
<v Speaker 1>that is crypto happy. Oh, I mean, in theory, I

953
00:46:33.250 --> 00:46:34.710
<v Speaker 1>think a lot of quantum happy rather.

954
00:46:34.730 --> 00:46:37.150
<v Speaker 3>I mean, unless they're doing some kind of inspection, if

955
00:46:37.170 --> 00:46:39.050
<v Speaker 3>they're just like passing data on, there should be no

956
00:46:39.130 --> 00:46:40.909
<v Speaker 3>need for it, right? They're not decrypting stuff, but if

957
00:46:40.929 --> 00:46:44.019
<v Speaker 3>they are decrypting stuff, then yeah, they're going to have

958
00:46:44.039 --> 00:46:46.239
<v Speaker 3>to have access to these algorithms. If you're doing, you know,

959
00:46:46.460 --> 00:46:48.320
<v Speaker 3>TLS termination, then yeah, for sure.

960
00:46:48.889 --> 00:46:50.769
<v Speaker 2>The other that's not something you'll have in your home

961
00:46:50.969 --> 00:46:53.329
<v Speaker 2>i did that stuff in racks of computers for companies

962
00:46:53.389 --> 00:46:54.070
<v Speaker 2>but ah but.

963
00:46:54.010 --> 00:46:56.090
<v Speaker 3>There's a fly in the ointment there's a huge fly

964
00:46:56.110 --> 00:46:57.989
<v Speaker 3>in the ointment though and that is your laptop and

965
00:46:58.010 --> 00:47:00.679
<v Speaker 3>your computer with tpms and trusted boots and that sort

966
00:47:00.699 --> 00:47:03.900
<v Speaker 3>of stuff right right now those keys are probably rsa

967
00:47:03.920 --> 00:47:06.340
<v Speaker 3>and well they are rsa or elliptic curve.

968
00:47:06.019 --> 00:47:08.139
<v Speaker 2>They are and we're just going through the secure boot

969
00:47:08.179 --> 00:47:10.119
<v Speaker 2>crisis thanks very much right.

970
00:47:09.900 --> 00:47:12.699
<v Speaker 3>So that will all get that will all get busted

971
00:47:13.099 --> 00:47:15.980
<v Speaker 3>and um you know so the hardware industry out there

972
00:47:16.429 --> 00:47:17.909
<v Speaker 3>We're being mean here, Michael.

973
00:47:17.929 --> 00:47:20.139
<v Speaker 1>Richard's squinting, but I think you've got to look at

974
00:47:20.179 --> 00:47:22.320
<v Speaker 1>it like this. Hey, you've got to buy a new laptop.

975
00:47:22.960 --> 00:47:23.900
<v Speaker 1>That's not a bad thing.

976
00:47:24.400 --> 00:47:26.800
<v Speaker 2>But it's also like we're fixing keys all the time.

977
00:47:27.260 --> 00:47:30.800
<v Speaker 2>These are BIOS updates. This will come in firmware.

978
00:47:31.000 --> 00:47:32.619
<v Speaker 1>You think? There'll be new drivers.

979
00:47:34.179 --> 00:47:37.650
<v Speaker 2>And they might be slower than a hardware-dedicated version of it,

980
00:47:37.760 --> 00:47:41.139
<v Speaker 2>but I just don't feel– a lot of the stuff

981
00:47:41.159 --> 00:47:43.579
<v Speaker 2>you're describing here, Michael, to me sounds like configuration settings

982
00:47:43.639 --> 00:47:46.610
<v Speaker 2>in Azure. you've already done the work in the browser. Like,

983
00:47:46.619 --> 00:47:49.170
<v Speaker 2>as long as I haven't done anything stupid in code,

984
00:47:49.630 --> 00:47:50.889
<v Speaker 2>I don't think I have to do anything as a

985
00:47:50.929 --> 00:47:51.489
<v Speaker 2>web dev.

986
00:47:51.849 --> 00:47:53.110
<v Speaker 3>That's correct. 100% correct.

987
00:47:53.349 --> 00:47:54.809
<v Speaker 2>I just got to make sure that my admins have

988
00:47:54.849 --> 00:47:55.530
<v Speaker 2>set stuff right.

989
00:47:55.590 --> 00:47:57.449
<v Speaker 1>Well, if you're using IIS, you're going to have to

990
00:47:57.510 --> 00:47:59.630
<v Speaker 1>make sure you're in the latest version that supports it.

991
00:47:59.690 --> 00:48:00.730
<v Speaker 1>But in Azure.

992
00:48:01.150 --> 00:48:04.050
<v Speaker 3>Well, http.sys... So I actually wrote a blog post on

993
00:48:04.070 --> 00:48:08.929
<v Speaker 3>this because about six-ish weeks ago, we released a version

994
00:48:08.949 --> 00:48:12.170
<v Speaker 3>of S Channel, which is the Windows TLS stack that

995
00:48:12.190 --> 00:48:19.449
<v Speaker 3>supports TLS 1.3 hybrid. And I wrote a dumb ASP.NET application,

996
00:48:19.469 --> 00:48:21.050
<v Speaker 3>you know, dumber than a bucket of rocks just to

997
00:48:21.070 --> 00:48:25.340
<v Speaker 3>keep it really, really simple and did no configuration whatsoever

998
00:48:25.380 --> 00:48:27.760
<v Speaker 3>in the code. And that's a really important point. Like,

999
00:48:27.800 --> 00:48:31.099
<v Speaker 3>you know, thou shalt not do any TLS configuration in code,

1000
00:48:31.159 --> 00:48:33.280
<v Speaker 3>like leave it to the OS or to some configuration

1001
00:48:33.320 --> 00:48:36.659
<v Speaker 3>somewhere else, definitely not in code. And yeah, I just

1002
00:48:36.699 --> 00:48:39.280
<v Speaker 3>turned on that. I wanted X35519 MLChem768 in priority zero.

1003
00:48:43.219 --> 00:48:47.010
<v Speaker 3>in the Cypher suite and group order. And I ran

1004
00:48:47.050 --> 00:48:49.949
<v Speaker 3>this application and I connected it, connected using a browser

1005
00:48:50.010 --> 00:48:51.630
<v Speaker 3>and I was living in the future.

1006
00:48:52.570 --> 00:48:52.829
<v Speaker 4>Nice.

1007
00:48:53.090 --> 00:48:55.650
<v Speaker 1>Michael, how long do we have before we need to

1008
00:48:56.329 --> 00:48:57.789
<v Speaker 1>configure things correctly?

1009
00:48:58.010 --> 00:49:01.230
<v Speaker 3>How long do we have? I mean, I mean, it

1010
00:49:01.269 --> 00:49:05.449
<v Speaker 3>depends on risk. I was talking to a large retailer.

1011
00:49:06.309 --> 00:49:07.719
<v Speaker 3>You know who they are, but I can't say who

1012
00:49:07.739 --> 00:49:07.969
<v Speaker 3>they are.

1013
00:49:07.989 --> 00:49:08.340
<v Speaker 1>Perfect.

1014
00:49:08.710 --> 00:49:09.610
<v Speaker 3>And they're not concerned.

1015
00:49:09.650 --> 00:49:10.880
<v Speaker 1>The one I bought my computer from?

1016
00:49:10.889 --> 00:49:15.619
<v Speaker 3>They're not concerned about right now anyway with their devices

1017
00:49:15.739 --> 00:49:18.389
<v Speaker 3>that they use for shop floor inventory management, right? Because

1018
00:49:18.429 --> 00:49:21.980
<v Speaker 3>it's just shop floor inventory management. It's not sensitive data.

1019
00:49:22.519 --> 00:49:26.079
<v Speaker 3>So their Android devices that they're using will never support post-quantum.

1020
00:49:26.239 --> 00:49:29.650
<v Speaker 3>They're okay with that. Now, their corporate systems that run

1021
00:49:29.989 --> 00:49:32.969
<v Speaker 3>HR and payroll and all that sort of stuff, yes,

1022
00:49:33.010 --> 00:49:35.710
<v Speaker 3>they do care. So how long do we have? I mean,

1023
00:49:35.730 --> 00:49:38.989
<v Speaker 3>the clock started now for certain types of data. Depends

1024
00:49:39.050 --> 00:49:42.010
<v Speaker 3>on the data. If you've got really sensitive data or

1025
00:49:42.070 --> 00:49:46.719
<v Speaker 3>data that must be secret for a long time, healthcare information,

1026
00:49:46.820 --> 00:49:51.820
<v Speaker 3>military secrets, intelligence, financial records in some cases, perhaps. I

1027
00:49:51.840 --> 00:49:56.079
<v Speaker 3>don't know. I'm not a regulatory person. You know, they

1028
00:49:56.119 --> 00:50:00.869
<v Speaker 3>have a time that they must maintain their secrecy. And

1029
00:50:00.909 --> 00:50:03.079
<v Speaker 3>that clock's already started. Because if we take a 2029,

1030
00:50:03.079 --> 00:50:06.469
<v Speaker 3>2030 timeframe, that's only four years. It's not even four

1031
00:50:06.510 --> 00:50:07.039
<v Speaker 3>years away. Hmm.

1032
00:50:07.969 --> 00:50:10.400
<v Speaker 1>On the screen behind you, a sentence came up a

1033
00:50:10.420 --> 00:50:14.389
<v Speaker 1>little while ago. There's no such thing as low-risk data.

1034
00:50:14.929 --> 00:50:17.630
<v Speaker 1>But apparently this large retailer seems to think there is.

1035
00:50:17.829 --> 00:50:20.420
<v Speaker 3>I think it said no low-risk secrets.

1036
00:50:21.150 --> 00:50:23.010
<v Speaker 1>Oh, low-risk secrets. That's right. Yeah.

1037
00:50:23.050 --> 00:50:24.610
<v Speaker 3>Yeah. Low-risk secrets.

1038
00:50:25.070 --> 00:50:25.780
<v Speaker 2>Secret is secret.

1039
00:50:25.800 --> 00:50:28.880
<v Speaker 1>So, if it's a secret by default, it's by definition

1040
00:50:28.940 --> 00:50:29.219
<v Speaker 1>a risk.

1041
00:50:29.559 --> 00:50:32.420
<v Speaker 3>Well, a small, air quotes, small secret can lead to

1042
00:50:32.480 --> 00:50:36.440
<v Speaker 3>access to bigger secrets. Like a low credential, for example,

1043
00:50:36.480 --> 00:50:37.860
<v Speaker 3>it can lead to something like a key.

1044
00:50:38.320 --> 00:50:38.610
<v Speaker 1>Sure.

1045
00:50:38.730 --> 00:50:38.929
<v Speaker 3>Yeah.

1046
00:50:38.949 --> 00:50:42.670
<v Speaker 2>The old classic, I got your Wi-Fi password from your

1047
00:50:42.750 --> 00:50:45.010
<v Speaker 2>light bulb because you thought, well, it's just a light bulb.

1048
00:50:45.030 --> 00:50:46.289
<v Speaker 1>What are you going to do to me? Right.

1049
00:50:46.530 --> 00:50:48.610
<v Speaker 2>But the fact that I got chain attack, once I

1050
00:50:48.630 --> 00:50:50.269
<v Speaker 2>got into the wifi, there was a whole lot of

1051
00:50:50.309 --> 00:50:51.219
<v Speaker 2>other things that were there.

1052
00:50:51.280 --> 00:50:53.599
<v Speaker 3>Yeah. And that's why I put all my IOT stuff

1053
00:50:53.619 --> 00:50:56.400
<v Speaker 3>on his own virtual network is our own isolated.

1054
00:50:56.460 --> 00:50:57.619
<v Speaker 2>Oh, you're darn right. You do.

1055
00:50:57.699 --> 00:50:58.739
<v Speaker 1>Absolutely. Yeah.

1056
00:50:58.920 --> 00:50:59.099
<v Speaker 3>Yeah.

1057
00:50:59.199 --> 00:51:02.139
<v Speaker 2>But, uh, at the same time, you know, it's still,

1058
00:51:02.219 --> 00:51:05.219
<v Speaker 2>I'm still sorting through what do I have to code

1059
00:51:05.360 --> 00:51:09.650
<v Speaker 2>as a dev versus what I have to, uh, you know,

1060
00:51:09.710 --> 00:51:12.849
<v Speaker 2>what's going to come to me, uh, just by making

1061
00:51:12.909 --> 00:51:15.869
<v Speaker 2>sure we're using the latest bits. I love your info

1062
00:51:15.929 --> 00:51:18.570
<v Speaker 2>on always encrypted. It's like, hey, now I want to

1063
00:51:18.590 --> 00:51:20.510
<v Speaker 2>go talk to my DBA. And it's like, we're up

1064
00:51:20.590 --> 00:51:22.690
<v Speaker 2>on this version, right? Because we have all this encrypted

1065
00:51:22.730 --> 00:51:25.550
<v Speaker 2>and REST stuff, and you don't want a crisis. So

1066
00:51:25.570 --> 00:51:30.050
<v Speaker 2>if you're already running always encrypted in SQL, then we

1067
00:51:30.070 --> 00:51:33.469
<v Speaker 2>should be good. When the new algorithms are needed, they'll work.

1068
00:51:33.989 --> 00:51:36.630
<v Speaker 3>The big issue, and this is one thing that a

1069
00:51:36.690 --> 00:51:38.530
<v Speaker 3>lot of products at Microsoft are having to deal with,

1070
00:51:38.710 --> 00:51:41.750
<v Speaker 3>is the symmetric stuff's fine. It's the key wrapping that

1071
00:51:41.769 --> 00:51:44.010
<v Speaker 3>has to change. The beauty of it, though, is it's

1072
00:51:44.030 --> 00:51:46.969
<v Speaker 3>just the key wrapping. So if you have a 256-bit

1073
00:51:47.369 --> 00:51:51.110
<v Speaker 3>AES key, you just decrypt it or unwrap it using RSA,

1074
00:51:51.150 --> 00:51:56.159
<v Speaker 3>for example, and then you rewrap it using AES-KW. which

1075
00:51:56.360 --> 00:51:59.349
<v Speaker 3>managed HSM in Azure, and now Key Vault, actually, Key

1076
00:51:59.369 --> 00:52:03.880
<v Speaker 3>Vault Premium in public preview, supports AESKW key wrapping, which

1077
00:52:03.940 --> 00:52:04.860
<v Speaker 3>is post-quantum resilient.

1078
00:52:05.139 --> 00:52:06.519
<v Speaker 1>Yeah, go ahead.

1079
00:52:06.739 --> 00:52:09.619
<v Speaker 3>So there's two issues that I see developers need to really,

1080
00:52:09.639 --> 00:52:12.800
<v Speaker 3>really think about. The number one is please don't put

1081
00:52:12.900 --> 00:52:15.019
<v Speaker 3>any TLS anything in your code.

1082
00:52:15.119 --> 00:52:16.619
<v Speaker 2>Yeah, it'll hurt you later.

1083
00:52:16.860 --> 00:52:20.599
<v Speaker 3>Don't restrict protocol version. Don't restrict cipher suites. Don't do

1084
00:52:20.739 --> 00:52:25.219
<v Speaker 3>any of that. Just let it be configured completely outside

1085
00:52:25.260 --> 00:52:29.139
<v Speaker 3>of the application. That's number one. Number two is this

1086
00:52:29.179 --> 00:52:35.289
<v Speaker 3>whole crypto agility thing. If you've got crypto code with

1087
00:52:35.329 --> 00:52:37.570
<v Speaker 3>the algorithms hard-coded in the code.

1088
00:52:37.590 --> 00:52:38.230
<v Speaker 2>You're in trouble.

1089
00:52:38.909 --> 00:52:42.659
<v Speaker 3>And you're encrypting squeaky bytes of data... You know, you've

1090
00:52:42.679 --> 00:52:44.280
<v Speaker 3>got to update your code and probably can't read the

1091
00:52:44.360 --> 00:52:45.840
<v Speaker 3>old data. So now you've got, you know, it's just

1092
00:52:45.900 --> 00:52:48.170
<v Speaker 3>a mess. And that's where the whole crypto agility comes in.

1093
00:52:48.199 --> 00:52:52.179
<v Speaker 3>And honestly, if you haven't got crypto agility in place,

1094
00:52:52.199 --> 00:52:57.179
<v Speaker 3>there are patterns you can use to wrap existing non-crypto,

1095
00:52:57.309 --> 00:53:01.210
<v Speaker 3>crypto agile blobs into like some sort of crypto agile

1096
00:53:01.289 --> 00:53:02.949
<v Speaker 3>envelope that contains all the metadata.

1097
00:53:03.150 --> 00:53:06.670
<v Speaker 1>So Azure's really good about letting me know when I

1098
00:53:06.710 --> 00:53:09.989
<v Speaker 1>need to move off of some version of something and

1099
00:53:10.070 --> 00:53:13.119
<v Speaker 1>onto something else because it's being deprecated. Do you think

1100
00:53:13.159 --> 00:53:15.900
<v Speaker 1>that sometime in the future, we're going to get an

1101
00:53:15.980 --> 00:53:18.800
<v Speaker 1>Azure thing when we log into the portal that says, hey,

1102
00:53:19.519 --> 00:53:23.480
<v Speaker 1>you need to upgrade your whatever it is to be

1103
00:53:23.599 --> 00:53:28.110
<v Speaker 1>quantum happy. You think that's going to happen? Like, should

1104
00:53:28.119 --> 00:53:30.219
<v Speaker 1>I just leave it up to Azure to warn me

1105
00:53:30.260 --> 00:53:33.130
<v Speaker 1>about things like that? Or is there stuff that I

1106
00:53:33.170 --> 00:53:33.869
<v Speaker 1>need to do now?

1107
00:53:34.329 --> 00:53:36.650
<v Speaker 3>I think it depends. If you look at the shared

1108
00:53:36.690 --> 00:53:40.969
<v Speaker 3>responsibility model, that's where it really becomes important. Like if

1109
00:53:41.010 --> 00:53:43.300
<v Speaker 3>you've got a platform managed key to encrypt data, then

1110
00:53:43.320 --> 00:53:45.139
<v Speaker 3>we're going to take care of that, right? Because a

1111
00:53:45.159 --> 00:53:48.079
<v Speaker 3>platform managed key. But if you've got a customer managed key,

1112
00:53:48.099 --> 00:53:52.340
<v Speaker 3>which is basically a key wrapping key, then they'll probably

1113
00:53:52.360 --> 00:53:54.699
<v Speaker 3>look at, I can't predict the future, but my guess,

1114
00:53:54.860 --> 00:53:59.070
<v Speaker 3>just my guess, Is that there will be notifications to say, hey,

1115
00:53:59.300 --> 00:54:03.360
<v Speaker 3>you know, we've now got the ability in Azure, blah, blah, blah,

1116
00:54:03.980 --> 00:54:08.099
<v Speaker 3>to wrap your encryption keys in quantum resilient keys. Would

1117
00:54:08.119 --> 00:54:11.239
<v Speaker 3>you like to do this? Yeah. And click here. Yeah.

1118
00:54:11.360 --> 00:54:14.599
<v Speaker 2>And the consequence is going to be very likely that

1119
00:54:14.659 --> 00:54:17.539
<v Speaker 2>the data streams are going to get larger because the

1120
00:54:18.400 --> 00:54:21.389
<v Speaker 2>quantum resilient keys are bigger. But I don't know what

1121
00:54:21.429 --> 00:54:22.570
<v Speaker 2>other impacts I'm going to see.

1122
00:54:22.670 --> 00:54:24.670
<v Speaker 3>No, you shouldn't see it. No, because the only thing

1123
00:54:24.690 --> 00:54:27.409
<v Speaker 3>you're really changing is the key wrapping. Right. Which is,

1124
00:54:27.929 --> 00:54:29.219
<v Speaker 3>so if you've got a 256-bit AES key, you're going

1125
00:54:29.239 --> 00:54:35.849
<v Speaker 3>to wrap it in AES-KW. And in fact, it'll probably

1126
00:54:35.869 --> 00:54:38.099
<v Speaker 3>be smaller than RSA, to be honest with you. But

1127
00:54:38.119 --> 00:54:39.880
<v Speaker 3>if you wrap it in MLChem, it will be bigger.

1128
00:54:39.900 --> 00:54:40.360
<v Speaker 1>Right.

1129
00:54:40.380 --> 00:54:41.739
<v Speaker 3>Yeah, but it's just the key.

1130
00:54:41.940 --> 00:54:42.559
<v Speaker 1>It's just the key.

1131
00:54:42.699 --> 00:54:43.719
<v Speaker 3>Yeah, the data doesn't change.

1132
00:54:43.780 --> 00:54:46.340
<v Speaker 2>Am I even choosing that or I'm just configuring to

1133
00:54:46.400 --> 00:54:48.269
<v Speaker 2>allow this and it'll optimize itself?

1134
00:54:49.110 --> 00:54:52.250
<v Speaker 3>No, what do you mean? When do I have to

1135
00:54:52.289 --> 00:54:57.199
<v Speaker 3>make a decision about this, about the rewrap? Well, first

1136
00:54:57.239 --> 00:54:59.679
<v Speaker 3>of all, the nice thing is it's very low friction. Right. Very,

1137
00:54:59.739 --> 00:55:02.500
<v Speaker 3>very low friction. Like it's microseconds to do the work.

1138
00:55:02.940 --> 00:55:06.550
<v Speaker 3>You're not decrypting and re-encrypting petabytes of data.

1139
00:55:07.070 --> 00:55:07.619
<v Speaker 1>Right.

1140
00:55:07.949 --> 00:55:11.650
<v Speaker 3>So my guess is personally, as soon as it becomes available,

1141
00:55:11.829 --> 00:55:15.550
<v Speaker 3>I would just opt in and just re-wrap your keys.

1142
00:55:15.829 --> 00:55:18.030
<v Speaker 2>So I'm going to wait for your blog post and

1143
00:55:18.070 --> 00:55:19.690
<v Speaker 2>then I'm just going to switch this stuff on.

1144
00:55:19.809 --> 00:55:21.489
<v Speaker 3>No, we'll push it through Azure Update.

1145
00:55:21.630 --> 00:55:21.750
<v Speaker 1>Okay.

1146
00:55:21.909 --> 00:55:23.869
<v Speaker 3>I guess it'll be through the Azure Updates website.

1147
00:55:24.010 --> 00:55:24.170
<v Speaker 1>Yeah.

1148
00:55:24.190 --> 00:55:24.820
<v Speaker 3>Yeah. Yeah.

1149
00:55:24.860 --> 00:55:27.659
<v Speaker 1>Good. And is this imminent like in the next year?

1150
00:55:27.679 --> 00:55:27.760
<v Speaker 2>Yeah.

1151
00:55:28.239 --> 00:55:28.400
<v Speaker 1>Wow.

1152
00:55:28.440 --> 00:55:31.360
<v Speaker 3>It'll depend on the service. Yeah. So, so, so I

1153
00:55:31.360 --> 00:55:33.639
<v Speaker 3>really want to point something out here is that, you know,

1154
00:55:33.659 --> 00:55:36.000
<v Speaker 3>this post-quantum stuff is very layered, right? So the very

1155
00:55:36.039 --> 00:55:37.619
<v Speaker 3>bottom of the layer, you've got the algorithms. Well, that

1156
00:55:37.639 --> 00:55:39.280
<v Speaker 3>stuff's been in place in windows for.

1157
00:55:39.300 --> 00:55:39.900
<v Speaker 1>For ages.

1158
00:55:40.219 --> 00:55:43.389
<v Speaker 3>Um, we have called sim crypt available in windows, Linux

1159
00:55:43.429 --> 00:55:47.489
<v Speaker 3>and Mac hand optimized C code. Absolutely beautiful to read.

1160
00:55:47.550 --> 00:55:50.670
<v Speaker 3>It's so well written. Honestly, it really is. Then above that,

1161
00:55:50.730 --> 00:55:55.210
<v Speaker 3>you've got, um, say TLS 1.3 with hybrid, right? You

1162
00:55:55.269 --> 00:55:57.710
<v Speaker 3>open those floodgates because now people can use that stack.

1163
00:55:58.530 --> 00:56:00.429
<v Speaker 3>So basically on windows is to use the new S

1164
00:56:00.449 --> 00:56:02.489
<v Speaker 3>channel stack. And in the case of Linux use open

1165
00:56:02.590 --> 00:56:05.690
<v Speaker 3>SSL 3.5, um, which has ML chem built into it.

1166
00:56:05.730 --> 00:56:08.690
<v Speaker 3>So you've got those two options are now available to you. Um,

1167
00:56:08.889 --> 00:56:10.789
<v Speaker 3>so that's, that's the data in transit taken care of.

1168
00:56:11.309 --> 00:56:13.489
<v Speaker 3>And then the last one, which is incredibly important is

1169
00:56:13.510 --> 00:56:17.639
<v Speaker 3>the key wrapping. And we now have that in, in Azure.

1170
00:56:17.679 --> 00:56:22.420
<v Speaker 3>So managed HSM has had a key wrapping since day one. And, um,

1171
00:56:22.969 --> 00:56:25.369
<v Speaker 3>as your Key Vault now has it, ASKW. So what's

1172
00:56:25.389 --> 00:56:27.369
<v Speaker 3>going to happen is that's going to open these floodgates

1173
00:56:28.090 --> 00:56:34.119
<v Speaker 3>and there'll be a Cambrian explosion of services coming online

1174
00:56:34.179 --> 00:56:37.460
<v Speaker 3>right as they adopt. And look, it won't happen like overnight,

1175
00:56:37.639 --> 00:56:40.079
<v Speaker 3>because everyone's going to do testing, make sure it works,

1176
00:56:40.159 --> 00:56:43.010
<v Speaker 3>make sure it fails correctly and that sort of stuff.

1177
00:56:43.550 --> 00:56:46.869
<v Speaker 3>But Richard, to your point, next year, We'll see a

1178
00:56:46.909 --> 00:56:48.590
<v Speaker 3>lot of services rolling this out.

1179
00:56:48.610 --> 00:56:49.630
<v Speaker 1>Starting to switch over.

1180
00:56:49.869 --> 00:56:52.349
<v Speaker 2>But I also remember when we started switching up keys,

1181
00:56:52.389 --> 00:56:54.739
<v Speaker 2>when attacks got smarter and so forth, there was a

1182
00:56:54.820 --> 00:57:00.199
<v Speaker 2>period where we changed a number of times different flavors of, yes, SSL,

1183
00:57:00.280 --> 00:57:04.639
<v Speaker 2>and then into TLS. We are restarting this in some

1184
00:57:04.659 --> 00:57:07.809
<v Speaker 2>respects with these new cryptography. I've got to think. The

1185
00:57:07.849 --> 00:57:10.710
<v Speaker 2>first move we make may not stick for more than

1186
00:57:10.750 --> 00:57:12.809
<v Speaker 2>a year or two before it's like, hey, now we

1187
00:57:12.829 --> 00:57:15.090
<v Speaker 2>found some problems and you probably want to switch to this.

1188
00:57:15.889 --> 00:57:18.469
<v Speaker 2>I just remember going through this with AAS and a

1189
00:57:18.510 --> 00:57:21.969
<v Speaker 2>few others. Like, we've done this before. In some ways,

1190
00:57:21.989 --> 00:57:25.230
<v Speaker 2>we've gotten really lazy because it's worked so well for

1191
00:57:25.349 --> 00:57:26.010
<v Speaker 2>so long.

1192
00:57:27.150 --> 00:57:30.469
<v Speaker 3>Well, actually, it's worse than that. And that is that,

1193
00:57:31.050 --> 00:57:33.699
<v Speaker 3>so we've actually become really lazy because of RSA.

1194
00:57:33.969 --> 00:57:34.199
<v Speaker 1>Right.

1195
00:57:34.579 --> 00:57:39.300
<v Speaker 3>RSA is interesting. RSA can do all the crypto primitives. Right.

1196
00:57:39.460 --> 00:57:41.460
<v Speaker 3>It can do signing, it can do encryption and all

1197
00:57:41.480 --> 00:57:44.679
<v Speaker 3>that sort of stuff. Elliptic Curve and Diffie-Hellman cannot. They

1198
00:57:44.699 --> 00:57:47.460
<v Speaker 3>can't do everything. And so we've been used to, like

1199
00:57:47.500 --> 00:57:49.980
<v Speaker 3>you said before, Richard, I'm not trying to laugh at you,

1200
00:57:50.000 --> 00:57:51.420
<v Speaker 3>but he said, you know, prime numbers. Well, that's just

1201
00:57:51.460 --> 00:57:53.860
<v Speaker 3>an RSA thing. That's not an elliptic curve thing. Right.

1202
00:57:53.940 --> 00:57:55.699
<v Speaker 3>Because everyone thinks of RSA.

1203
00:57:55.860 --> 00:57:56.079
<v Speaker 1>Yeah.

1204
00:57:56.159 --> 00:57:58.980
<v Speaker 3>And RSA is this Swiss army knife. It does absolutely everything.

1205
00:57:59.159 --> 00:57:59.380
<v Speaker 1>Sure.

1206
00:57:59.480 --> 00:58:02.070
<v Speaker 3>And the problem is it does absolutely everything.

1207
00:58:02.159 --> 00:58:02.909
<v Speaker 2>Absolutely everything.

1208
00:58:02.969 --> 00:58:05.809
<v Speaker 3>Which means we've got to change it absolutely everywhere. Yeah.

1209
00:58:06.949 --> 00:58:10.269
<v Speaker 2>It went everywhere. Well, the other side of this was

1210
00:58:10.289 --> 00:58:14.269
<v Speaker 2>because compute, I remember when it was expensive to do encryption,

1211
00:58:14.309 --> 00:58:18.210
<v Speaker 2>where we literally had separate servers from the website for

1212
00:58:18.269 --> 00:58:21.429
<v Speaker 2>doing just the encrypted pages. It's okay, well, now you're

1213
00:58:21.449 --> 00:58:23.809
<v Speaker 2>going to take your shopping cart and start a payment

1214
00:58:23.849 --> 00:58:27.400
<v Speaker 2>cycle that needs to be asked to sell. Now, it

1215
00:58:27.440 --> 00:58:29.480
<v Speaker 2>was this big thing about moving the cart over to

1216
00:58:29.519 --> 00:58:34.000
<v Speaker 2>the other much more expensive dedicated stack for completing a transaction.

1217
00:58:34.659 --> 00:58:37.980
<v Speaker 2>Because encryption used to be so costly. You know, these

1218
00:58:38.019 --> 00:58:40.099
<v Speaker 2>days our CPUs are so damn fast. They're sitting around

1219
00:58:40.119 --> 00:58:42.679
<v Speaker 2>playing poker and smoking cigarettes waiting for something to do.

1220
00:58:43.380 --> 00:58:46.780
<v Speaker 2>So sure, encrypt everything. Who cares? RSA is fast.

1221
00:58:46.969 --> 00:58:49.889
<v Speaker 3>Well, the funny thing is that first of all, it's

1222
00:58:49.929 --> 00:58:51.769
<v Speaker 3>just the key wrapping and unwrapping part.

1223
00:58:51.869 --> 00:58:52.670
<v Speaker 1>Yeah.

1224
00:58:52.710 --> 00:58:56.050
<v Speaker 3>Let's just call it key establishment because there's all different

1225
00:58:56.070 --> 00:58:56.570
<v Speaker 3>ways of doing it.

1226
00:58:56.570 --> 00:58:57.550
<v Speaker 2>That's really what's going on.

1227
00:58:57.630 --> 00:59:01.230
<v Speaker 3>That's the expensive part because it's all asymmetric stuff. And Windows,

1228
00:59:01.369 --> 00:59:03.159
<v Speaker 3>I think it still exists. There used to be a

1229
00:59:03.260 --> 00:59:09.519
<v Speaker 3>registry key called modexp offload for modular exponentiation offload, which

1230
00:59:09.579 --> 00:59:14.019
<v Speaker 3>is a very expensive RSA operation. And there was a

1231
00:59:14.039 --> 00:59:16.739
<v Speaker 3>way you could actually set a DLL in there, a

1232
00:59:16.760 --> 00:59:19.139
<v Speaker 3>name for DLL. It would actually offload that work to

1233
00:59:19.199 --> 00:59:21.420
<v Speaker 3>a DLL, which was a shim into some hardware to

1234
00:59:21.440 --> 00:59:24.860
<v Speaker 3>actually do the modular exponentiation work. But we don't need

1235
00:59:24.929 --> 00:59:28.190
<v Speaker 3>any of that stuff anymore. You know, when I look

1236
00:59:28.210 --> 00:59:32.190
<v Speaker 3>at the work that... you know, as your front door

1237
00:59:32.210 --> 00:59:33.829
<v Speaker 3>have done, for example, they've done a whole bunch of

1238
00:59:33.889 --> 00:59:39.579
<v Speaker 3>analysis on performance and the performance is like just a

1239
00:59:39.659 --> 00:59:42.519
<v Speaker 3>couple of percent, you know, going from elliptic curve to

1240
00:59:42.539 --> 00:59:46.980
<v Speaker 3>elliptic curve plus ML, ML chem. And that's because of

1241
00:59:47.619 --> 00:59:48.960
<v Speaker 3>optimizations made in the library.

1242
00:59:49.260 --> 00:59:49.449
<v Speaker 1>Sure.

1243
00:59:50.119 --> 00:59:52.019
<v Speaker 2>I got to tell you, Michael, there's this weird dichotomy

1244
00:59:52.059 --> 00:59:55.349
<v Speaker 2>going on where it's like the catastrophizing of quantum destroying

1245
00:59:55.409 --> 00:59:58.969
<v Speaker 2>everything and the, oh, just touch this button, problem goes away.

1246
00:59:59.130 --> 01:00:02.769
<v Speaker 1>Yeah. Yeah. I'm feeling that too. You're right.

1247
01:00:03.710 --> 01:00:05.010
<v Speaker 3>I wish it was that simple.

1248
01:00:05.309 --> 01:00:07.860
<v Speaker 2>Yeah. I keep waiting for what's not the simple part.

1249
01:00:08.230 --> 01:00:10.449
<v Speaker 2>I mean, for me, it's the frontline dev.

1250
01:00:10.510 --> 01:00:10.949
<v Speaker 1>Right.

1251
01:00:11.070 --> 01:00:14.909
<v Speaker 2>I mean, the administrator in me is a little sticky

1252
01:00:14.949 --> 01:00:17.369
<v Speaker 2>in the shorts right now because this is all very scary. Like,

1253
01:00:17.429 --> 01:00:19.469
<v Speaker 2>I want to check everything. I don't want to be

1254
01:00:19.510 --> 01:00:21.139
<v Speaker 2>the guy who didn't do his homework.

1255
01:00:21.179 --> 01:00:21.389
<v Speaker 1>Right.

1256
01:00:21.820 --> 01:00:24.420
<v Speaker 2>But for the dev, unless you've done something dumb, I

1257
01:00:24.599 --> 01:00:27.800
<v Speaker 2>think you're good as long as your administrators are on it.

1258
01:00:27.860 --> 01:00:30.460
<v Speaker 3>As I mentioned before, the two big dumb things are

1259
01:00:30.980 --> 01:00:34.500
<v Speaker 3>baking in crypto algorithms into your code and not being crypto-natural.

1260
01:00:34.699 --> 01:00:38.039
<v Speaker 3>That's dumb thing number one. Dumb thing number two is

1261
01:00:38.099 --> 01:00:40.019
<v Speaker 3>if you hard code your TLS configuration.

1262
01:00:40.820 --> 01:00:40.940
<v Speaker 2>Right.

1263
01:00:40.980 --> 01:00:43.840
<v Speaker 3>You're right. Those are the two big ones. Let's just

1264
01:00:43.880 --> 01:00:48.530
<v Speaker 3>ignore compatibility for a moment. If you change a server

1265
01:00:48.550 --> 01:00:52.030
<v Speaker 3>to use TLS 1.3 hybrid and only hybrid, by the way,

1266
01:00:52.130 --> 01:00:53.989
<v Speaker 3>the reason why it's called hybrid is because you do

1267
01:00:54.369 --> 01:00:57.659
<v Speaker 3>elliptic curve and MLChem together. The keys are derived from both.

1268
01:00:58.289 --> 01:01:00.630
<v Speaker 3>That's why it's called hybrid. But if you do hybrid

1269
01:01:00.650 --> 01:01:02.769
<v Speaker 3>and the client doesn't talk hybrid for whatever, you got

1270
01:01:02.789 --> 01:01:07.199
<v Speaker 3>like a crusty old Java application or C sharp application

1271
01:01:07.219 --> 01:01:10.480
<v Speaker 3>written 15 years ago, it's probably not going to work.

1272
01:01:10.820 --> 01:01:11.039
<v Speaker 1>Yeah.

1273
01:01:11.199 --> 01:01:12.360
<v Speaker 2>And it's really a question of, is it going to

1274
01:01:12.460 --> 01:01:14.559
<v Speaker 2>fail with some grace to tell you what the hell's

1275
01:01:14.599 --> 01:01:15.159
<v Speaker 2>going on?

1276
01:01:15.199 --> 01:01:15.400
<v Speaker 3>Yeah.

1277
01:01:15.739 --> 01:01:16.829
<v Speaker 1>Right. Yeah.

1278
01:01:17.050 --> 01:01:19.949
<v Speaker 3>It says, don't understand this cipher suite and gives you

1279
01:01:19.989 --> 01:01:22.190
<v Speaker 3>a hex value. Yeah. Really useful.

1280
01:01:22.389 --> 01:01:22.630
<v Speaker 1>Yeah.

1281
01:01:22.849 --> 01:01:25.570
<v Speaker 2>Well, that's better than object not found.

1282
01:01:27.289 --> 01:01:29.090
<v Speaker 3>One of the best ones in office back in the

1283
01:01:29.110 --> 01:01:29.829
<v Speaker 3>day was out of memory.

1284
01:01:30.190 --> 01:01:32.820
<v Speaker 1>Yeah. Michael, tell us about your book.

1285
01:01:33.070 --> 01:01:33.909
<v Speaker 3>Oh, my new book, man.

1286
01:01:34.119 --> 01:01:34.340
<v Speaker 1>Yeah.

1287
01:01:34.360 --> 01:01:37.820
<v Speaker 3>So, I wrote this book with Sean Hernan, Lee Holmes,

1288
01:01:37.880 --> 01:01:39.980
<v Speaker 3>and Sherry DeGrippo. So, Sean and I have known each

1289
01:01:40.000 --> 01:01:44.139
<v Speaker 3>other for many, many years. He's a partner engineering manager

1290
01:01:44.239 --> 01:01:46.309
<v Speaker 3>in Azure Security. I've been around for a long time,

1291
01:01:46.349 --> 01:01:50.309
<v Speaker 3>got the utmost respect for Sean, great guy. Lee Holmes,

1292
01:01:50.349 --> 01:01:52.070
<v Speaker 3>he was the security guy in PowerShell.

1293
01:01:52.289 --> 01:01:53.650
<v Speaker 1>Yeah, he's been on the show before too.

1294
01:01:53.769 --> 01:01:55.349
<v Speaker 3>Yeah, my boy Lee, great guy.

1295
01:01:55.429 --> 01:01:56.030
<v Speaker 1>Yeah, he's a good man.

1296
01:01:56.190 --> 01:01:58.670
<v Speaker 3>He and I actually worked together in the earliest days

1297
01:01:58.710 --> 01:02:02.909
<v Speaker 3>of the SDL because when Monad, as it was back

1298
01:02:02.929 --> 01:02:05.150
<v Speaker 3>in the day, had to go through all its SDL checks,

1299
01:02:05.750 --> 01:02:06.510
<v Speaker 3>I was the.

1300
01:02:07.050 --> 01:02:08.989
<v Speaker 2>Precursor to PowerShell?

1301
01:02:09.030 --> 01:02:09.929
<v Speaker 3>To PowerShell, correct.

1302
01:02:10.130 --> 01:02:10.809
<v Speaker 1>Yeah.

1303
01:02:11.030 --> 01:02:13.920
<v Speaker 3>I was like the SDL contact for Monad. And so

1304
01:02:13.980 --> 01:02:15.579
<v Speaker 3>Lee and I got to know each other incredibly well.

1305
01:02:16.500 --> 01:02:20.260
<v Speaker 3>And he's also a partner engineer in Azure. And then

1306
01:02:20.360 --> 01:02:22.920
<v Speaker 3>Sherrod DeGrippo, she's actually left Microsoft now. She goes to

1307
01:02:22.940 --> 01:02:28.469
<v Speaker 3>Palo Alto Labs. She is easily one of the preeminent

1308
01:02:28.510 --> 01:02:32.349
<v Speaker 3>experts in the world on threat actors. She knows absolutely

1309
01:02:32.369 --> 01:02:35.429
<v Speaker 3>everything about threat actors. So the book is Threat-Driven Software Development.

1310
01:02:35.989 --> 01:02:38.389
<v Speaker 3>And basically what it is is looking at software development

1311
01:02:38.409 --> 01:02:41.030
<v Speaker 3>through the eyes of threat actors, like what do threat

1312
01:02:41.070 --> 01:02:41.820
<v Speaker 3>actors actually do?

1313
01:02:41.840 --> 01:02:41.960
<v Speaker 2>Mm-hmm.

1314
01:02:42.550 --> 01:02:45.420
<v Speaker 3>And every chapter starts off... So first of all, Sherrod

1315
01:02:45.440 --> 01:02:47.880
<v Speaker 3>has her own chapter at the beginning. But every chapter

1316
01:02:47.980 --> 01:02:51.480
<v Speaker 3>after that looks at the contents of that chapter through

1317
01:02:51.500 --> 01:02:55.679
<v Speaker 3>the lens of threat intel. So every chapter starts off

1318
01:02:55.719 --> 01:02:59.840
<v Speaker 3>with anywhere between half and two pages of threat intel perspective,

1319
01:02:59.880 --> 01:03:02.500
<v Speaker 3>where Sherrod gives it a whole bunch of color. And

1320
01:03:02.539 --> 01:03:06.969
<v Speaker 3>then Lee, myself, and Sean go through and sort of

1321
01:03:07.030 --> 01:03:10.489
<v Speaker 3>explain that particular topic in detail. And a lot of it's...

1322
01:03:11.579 --> 01:03:14.099
<v Speaker 3>A lot of it's not just, don't think of it

1323
01:03:14.159 --> 01:03:15.559
<v Speaker 3>like just security best practices.

1324
01:03:15.739 --> 01:03:16.159
<v Speaker 1>It's not.

1325
01:03:16.860 --> 01:03:23.079
<v Speaker 3>It's DevOps as well as it's operational security, AppSec, and

1326
01:03:23.119 --> 01:03:26.139
<v Speaker 3>also Threat Intel all sort of munched together into one book.

1327
01:03:26.400 --> 01:03:26.880
<v Speaker 1>Sounds good.

1328
01:03:27.280 --> 01:03:28.340
<v Speaker 3>Yeah, a lot of fun. I did one when I

1329
01:03:28.340 --> 01:03:31.559
<v Speaker 3>was in the red team. Funny thing is, so Mark

1330
01:03:31.599 --> 01:03:34.719
<v Speaker 3>Rasinovich wrote the forward. And my manager at the time,

1331
01:03:35.809 --> 01:03:38.269
<v Speaker 3>Craig Nelson, who's CVP of the red team, he said,

1332
01:03:38.309 --> 01:03:40.110
<v Speaker 3>oh man, I really love this book. I gave him

1333
01:03:40.130 --> 01:03:44.530
<v Speaker 3>draft to look at. Can I write a chapter? I'm like, well,

1334
01:03:44.550 --> 01:03:45.889
<v Speaker 3>why don't you write the afterword? I said, I've never

1335
01:03:45.909 --> 01:03:47.090
<v Speaker 3>had an afterword in a book. Why don't you write

1336
01:03:47.110 --> 01:03:53.000
<v Speaker 3>the afterword? So he did. Nine pages. But the afterword...

1337
01:03:53.239 --> 01:03:56.739
<v Speaker 3>The after chapter. Yeah, the after chapter. Look, I'm not

1338
01:03:56.760 --> 01:04:02.940
<v Speaker 3>trying to besmirch Craig at all. That afterword is absolutely brilliant.

1339
01:04:03.420 --> 01:04:04.840
<v Speaker 3>If you were to sum up the afterword in like

1340
01:04:05.380 --> 01:04:08.519
<v Speaker 3>one sentence or two words, it would be So what?

1341
01:04:09.380 --> 01:04:12.300
<v Speaker 3>And he does a really, really good job of answering.

1342
01:04:12.340 --> 01:04:14.199
<v Speaker 3>So what? Yeah. It's really good. Yeah.

1343
01:04:14.219 --> 01:04:16.750
<v Speaker 1>That's good. It's really cool. Michael, what can we say?

1344
01:04:16.789 --> 01:04:20.829
<v Speaker 1>It's been enlightening having you here and talking about all

1345
01:04:20.869 --> 01:04:23.570
<v Speaker 1>this crazy stuff that we barely understand. Well, I barely

1346
01:04:23.610 --> 01:04:26.230
<v Speaker 1>understand anyway, but I understand a little more thanks to you.

1347
01:04:26.269 --> 01:04:27.230
<v Speaker 1>So thank you very much.

1348
01:04:27.449 --> 01:04:28.889
<v Speaker 3>You're welcome. Thanks for having me on.

1349
01:04:28.929 --> 01:04:30.880
<v Speaker 1>Great show, friend. Thank you so much. And we'll talk

1350
01:04:30.889 --> 01:04:33.119
<v Speaker 1>to you next time on. NET Rocks!. NET Rocks!

1351
01:04:54.269 --> 01:04:57.030
<v Speaker 4>NET Rocks is brought to you by Franklin's Net and

1352
01:04:57.090 --> 01:05:01.809
<v Speaker 4>produced by Plop Studios, a full-service audio, video, and post-production

1353
01:05:01.869 --> 01:05:05.849
<v Speaker 4>facility located physically in New London, Connecticut, and, of course,

1354
01:05:05.909 --> 01:05:14.050
<v Speaker 4>in the cloud, online at pwop.com. Visit our website at dotnetrocks.com

1355
01:05:14.489 --> 01:05:19.190
<v Speaker 4>for RSS feeds, downloads, mobile apps, comments, and access to

1356
01:05:19.210 --> 01:05:22.590
<v Speaker 4>the full archives going back to show number one, recorded

1357
01:05:22.610 --> 01:05:23.829
<v Speaker 4>in September 2002.

1358
01:05:23.829 --> 01:05:27.139
<v Speaker 1>And make sure you check out our sponsors. They keep

1359
01:05:27.219 --> 01:05:30.400
<v Speaker 1>us in business. Now go write some code. See you

1360
01:05:30.420 --> 01:05:30.840
<v Speaker 1>next time.
