Episode 1 | 2026-06-29 Chinese AI vs Anthropic Mythos
E1

Episode 1 | 2026-06-29 Chinese AI vs Anthropic Mythos

John Strand:

Alright, everybody. We're ready to go. Hey. Hello, and welcome to an ambulance chasing webcast from Black Hills Information Security. I can't remember.

John Strand:

What do we actually call this? They came up with a really good name.

Bronwen Aker:

Pinnacle. In

John Strand:

Focus. In Focus. Right? Of the newscast. It it's kind of funny because anytime I come up with things, like, created our boring marketing propaganda guide, and they really like, a lot of people in the company, Bronwyn liked it.

John Strand:

That's why that's why I love Bronwyn to bits. There there there's a lot of people like, you're calling it the boring marketing propaganda guide, and we can get you a link to it so you can see it. But it literally is now just the marketing propaganda guide. That was the the solution. And then I was like ambulance chasing.

John Strand:

We should call this ambulance chasing. And there's a lot of people who are like, no. No. You what is wrong with you? Like, how how are you running a company?

Derek Banks:

Lots of things.

John Strand:

So I wanna kinda set the stage a little bit and kind of, like, why we're doing this. We're gonna be doing this periodic with these stories percolate up at a certain level. We will be throwing in something. And anytime I see something in information security that's like front page and by the way, if you hate my news sources, that's fine. I don't care.

John Strand:

If it's like front page Drudge Report, it's front page CNN, it's front page Fox News, it's front page, like, whatever I go to, It absolutely rises to level that we need to set up a webcast where we can discuss it with the community as a whole to try to bring our side in a little bit more context about what's going on. The other thing about this particular story that's been really, really interesting is the evolution of the story. I know, Bron, when you were on the news, but you remember when the story first came up about, like, what is it? Anthropic's Mythos packed the NSA's most sensitive systems. Remember the first quote?

John Strand:

Was it from register? I can't remember who it was, but they basically said it hacked all classified systems at the NSA in a matter of moments. And if you remember, whenever that happened, I think we were on the news, and we were going back and forth. We're like, this ain't right. Like, this this just is not right.

John Strand:

And turns out we were right. It wasn't correct at all. And I'll get to the bottom of that a little bit. But, literally, the whole thing that we're talking about right now is what's the level of panic that you need to have right now whenever we're talking about offensive AI, how that relates to China, and what you can do about it in your organization. And I have some guests with me.

John Strand:

Bronwyn is with me a lot on the news. And whenever I'm doing things internally with BHIS with AI and capabilities and really kind of being on the forefront, Bronwyn is right there. And on the offensive side, Derek is with me as well. So we might have another guest possibly drop in on this. Maybe I was like, that one.

John Strand:

Yep. Yep. Yep. Yep. Possibly, that person will be coming in here shortly to kinda bring their take into it as well.

John Strand:

But I wanna kind of set the stage a little bit before we get started. I'm gonna go through some of these some of these news stories. No slides because I'm a recovering SANS instructor, and I'm trying to do less with slides. And I wanna talk about news stories. If you have any questions, you absolutely should put it into Discord because that's where we have most of our conversation with the community as a whole.

John Strand:

So I wanna go to this one. I'm seeing lots of people on Discord. They're like, yeah. This absolutely kinda smells like bullshit. And it turns out it was.

John Strand:

The initial story that first came out and the quote that got everyone completely freaked out is there was a US senator, and I think it's down here in the bottom of this article. There was a US senator that basically said

Derek Banks:

Oh, it was my senator.

John Strand:

Oh, good. Yes. Warner.

Derek Banks:

Good. Senator Warner. Awesome. I'm sorry, everybody.

John Strand:

This is your dog that peed on the floor. Yes. You've gotta deal with this. And the senator said it hacked absolutely all the classified systems in a matter of moments. And that basically was like a bomb going off in the news community.

John Strand:

And there's more context around it. And I think, Derek, you were talking about this seems like it was a highly contained, constrained test scenario, and it did very well in that test scenario. And then the game of telephone began, and it kept getting bigger and bigger and bigger and bigger. And then shortly thereafter, we started seeing stories about Five Eyes. I'm gonna try to get them right, but it's like The United States, Australia, New Zealand, The United Kingdom, and whoever else is in the five eyes, that basically were saying, we are not ready.

John Strand:

What what what is it? Australia. Australia. I missed it. Canada was another one.

John Strand:

So there's a lot of panic right now in those specific spaces. And trust me, I've been seeing that panic as well in those communities and people asking me lots of questions about it. So we really wanna level set this as much as we possibly can. So first and foremost, the story that Anthropic Mythos packed all the NSA's highly classified systems was not true. Okay?

John Strand:

Now as you know with a lot of stories, that initial news burst pops and explodes. That's the one that gets all the press. You know, senator McCarthy figured all this way out back in the fifties and sixties, y'all. And then whenever people start walking it back and trying to bring context to the story and explinating explinating the actual story. That gets, like, pushed to, like, page 26.

John Strand:

Right? And this one already, the author of the report and the economist, the one that had the initial cause that it caused all the worry, admitted that their portrayal of the NSA's tests with Mythos had been misleading. The tests surely involved using Mythos along other other tools and are very particular conditions. He wrote in the X Post, I quoted senator Warner to give a sense of the potency, but it was a mistake not to add the caveats and the context. So at first out, wanna call out the economist, do better.

John Strand:

Alright? Then this is weird saying this to a publication like The Economist or Forbes or any of those, but do better because this absolutely did cause a lot of panic. Now when we were talking about all of that, and if we get our special guest to attend, maybe he can bring some additional context to this as well. Anytime you read a news story and it broke into multiple DOD or intelligence community systems that were highly classified, I want you to remember this. Most of the technology that is in classified environments is worse secured and has more vulnerabilities than in nonclassified spaces.

John Strand:

Alright? You need to understand that, and that is true for a couple of reasons. The first reason why that is true is getting, like, connections and getting patches and getting updates into air gapped networks, I should put that in air quotes, is incredibly difficult and time consuming, number one. Number two, a lot of these projects are very expensive. The defense contractors build these highly complicated systems, and there's oftentimes very little money available for maintenance and updating of these systems.

John Strand:

A long time ago in a galaxy far, far, far away, I remember doing a code analysis on a classified network, and it was a 100,000 lines of code, and I had a 100,001 101,000 vulnerabilities. The total code base was 25,000,000 lines of code. It's very, very common in these particular networks, classified networks, financial networks, health care networks, that some of the most sensitive systems have the most legacy hardware and software, and you're basically not allowed to effing touch those networks ever. So if you ever see anybody that's talking about classified networks and saying these are some of the most highly secured environments in the world, they're usually saying, I don't have an effing clue what I am talking about, and I shouldn't be quoted at all about the security of any classified computer systems. That is one of the reasons why the United States government's default action to a lot of these things is to air gap them.

John Strand:

Air gap in quotes. Right? So when you're reading these things, you gotta be able to understand the hype associated with these articles. So if anybody released Mythos in a classified environment and it took over a whole bunch of systems, anybody that has ever worked in a classified environment can attest, yeah, that pretty much checks out. So just keep that in mind when we're talking about the hype.

John Strand:

Some of the people Chad chatter are talking about military grade encryption. Military grade anything will terrify anyone that has ever been in the military. Right? Like, those are gonna be military grade vehicle safety. Everyone's like, we're all gonna die.

John Strand:

We're gonna die. There's no safety. You're not terrified.

Bronwen Aker:

You're not paying attention.

John Strand:

If you're not terrified, you're not paying attention. I can't remember what quote it was from what military book. I wanna say starship troopers. But it basically said all it might have been the forever war. But it basically said the mill the com but not companies.

John Strand:

Countries will spend the absolute minimum they have to to achieve their minimum viable military objectives, and that is absolutely true.

Bronwen Aker:

It was Starship Troopers. Okay. If if it if it wasn't Starship Troopers, it might have been old man's war.

John Strand:

Old man's war. Yes.

Bronwen Aker:

Old man's It was old man's war because the the whole justification was, yeah, you love these nice shiny tools. Guess what? The enemy has better ones.

John Strand:

They're cheap compared to what we have. Right? So please keep that in mind with this story. The next story, this is where I get into this stuff quite a bit. If you've been on a number of webcasts with me, you know I really, really get into China and history of China.

John Strand:

And I'm gonna talk a little bit about parity and what China is doing, and then Derek and Bronwyn can come in, and they can talk a little bit about what they're saying whenever it comes, especially for some of the models that are released that we're getting from China as well. So this is I don't know how in the hell anyone came up with a story that China has matched Anthropic and Cybersecurity resetting the AI race. Now the whole point of this is the fact that The United States has locked down Mythos and has restricted access to certain security testing capabilities in Anthropic's toolset. Right? And the thought process is, well, China isn't restricted, and they're going full tilt ahead.

John Strand:

I agree with that state. I agree a 100% with that statement because I think it's incredibly shortsighted. It's incredibly stupid for the United States government to restrict access to these tools to legitimate security professionals, legitimate firms, legitimate companies, and legitimate government organizations helping secure their environments. They didn't solve any problems because all of the bad is already out of Pandora's box. The only thing you're doing is you're saying we opened Pandora's box, all of this shit got out, and now we've closed Pandora's box.

John Strand:

Problem solved. Which I'm not as into government bashing as Derek is, but that's pretty on point for the government, to be honest with you. That that kinda checks out when we look at it. So this is true. It is absolute truth when we're talking about the United States government's reaction is incredibly stupid, It's possibly politically motivated, which makes it even dumber than what we thought it was, and we thought it was pretty dumb.

John Strand:

But this absolutely is tying the hands of security professionals in The United States. And if you believe for a second that China is completely shut down and they're like, we're just waiting for Mythos to come out so we can know what to do, that is absolutely not the case. I'm gonna get to that here in a couple of moments because I need to put some additional context from a geopolitical and technical perspective for everybody that is here. Alright? Okay.

John Strand:

So there's a company. I've talked about this in some things. I've talked about this on LinkedIn, and I've talked about this in some other things. Right? I'm gonna come back to that.

John Strand:

This company, ASML, is the single most powerful monopoly in the on the planet right now. Okay? And it's not even close. And the reason why is because every computer chip that is created at the sub seven nanometer scale is produced in a machine that these guys make. And it's a complete and utter monopoly by this particular company.

John Strand:

They're the only company that makes the machines that makes the chips. NVIDIA doesn't make these machines. Intel doesn't make these machines. TSMC does not make these machines. There's only one company out in Netherlands that makes these machines.

John Strand:

So when you're talking about GPUs, whenever you're talking about these high end computer systems, you're talking about the most cutting edge technologies available to humanity to generate these computer chips. And if you want to spend an entire evening on YouTube learning about what they do, I want you to know it's time well spent because it's black freaking magic, what they do. Not like like whenever you hear about what they're doing at the scale that they're doing it and it's repeatable, and then then they can produce chips, like, just flying out, it's magic or as close as we have to magic. This company is banned and has a policy of not selling these machines to China. Let me repeat that.

John Strand:

China does not have the capability of generating sub seven nanometer chips on their own. They cannot purchase these machines. Now you may think, well, they'll just reverse engineer it. No. That's what got China in trouble.

John Strand:

They tried to reverse engineer these machines. These machines have the capability of absolutely destroying themselves if anybody tampers with them. They have an have to have an always on Internet connection with multiple backup redundancies so ASML can connect to these machines and see what these machines are doing. You take a freaking panel off to clean behind it, it will break this machine. And I think these machines are about $500,000,000 just for the machine.

John Strand:

That does not include the installation. That does not include the building, which has very rigorous tech specs to be able to build and handle these machines. They're incredibly expensive. You're not gonna sneak one out of your house and put it in a bank. It's just not gonna happen.

John Strand:

China has been aggressively trying to gain access to these machines. Alright? They've been aggressively trying to reverse engineer these machines through hiring engineers from ASML. And it's not an issue of just getting engineering know how. It's about suppliers.

John Strand:

I'll give you an example. There's a mirror inside of this machine, and it uses something called extreme ultraviolet lithography. Do you wanna think how these chips are made? It's literally like old school, like, photography where they flash the circuits onto chips through extreme ultraviolet. I'll come back to that here in a second.

John Strand:

That's really, really important. Okay? So there is a company in Germany that makes the mirrors inside of this thing. The mirrors are so precise. I want you to imagine a mirror the size of The United States or a Twinkie the size of Manhattan accelerating at the speed of light.

John Strand:

But, anyway, think of this think of this mirror, the size of The United States. If I have a credit card in Kansas, that mirror fails. That size of imperfection is enough to cause this mirror to fail. That's not an issue of somebody just saying, you need this mirror that's really accurate. You need to build technology stacks upon technology stacks upon technology stacks.

John Strand:

And China is trying really, really hard to develop their own machines. The reason why this matters, and the reason why this matters so much is if anybody is talking about parity, China has to have the ability to either, a, acquire these machines or, b, produce these machines on their own. That's the only way that they can build data centers at the scale that The United States and every other country Taiwan, as an example, by the way. That's a whole other geopolitical thing that we're not going to get into. China does have the ability to buy the older style machines from ASML that do 14 to 28 nanometers using deep ultraviolet techniques instead of extreme ultraviolet techniques.

John Strand:

China has come up with a weird way of doing a multipattern technique to get sub seven, but it's not very reliable. You can't produce mass produced technique chips with that. So that's very important. China does not have the capability to build the chips that are needed to power an AI infrastructure like we are talking about. So they're working on models, to be honest with you, that are more efficient.

John Strand:

And and Derek and Bronwyn, I'm gonna bring them in here in a little bit, and they can talk more about that. I think that that's really, really super important. In fish efficiency in models, Derek, I don't know if you've read some of the stuff about, you know, they're skipping words and LLMs to still build the same level of context, but do it faster, but not rendering and analyzing every word in the chain as it does vectoring. I don't know if you read that, but that was kind of cool. But there's all of these different techniques to develop more efficient models when you're developing AI, and that's really one of the things where China has been shining quite a bit.

John Strand:

Now if you wanna know stories that scare the living hell out of me, there's been rumors that China has been getting these machines. ASML has denied selling extreme UV chip making to China after there's been a concern. I have seen nothing that this has been validated, but it ends a concern from a geopolitical perspective if the politics of the situation are such that all of a sudden ASML decides, screw it. YOLO. We're now tighter with China than we are in The United States.

John Strand:

Maybe we need to start selling them chips. If we start seeing stories that they have the capability to be able to, like, acquire even one of these machines, the game is up. Like, then China can start mass producing chips to producing the data capacity to be able to do these things. So I'm giving you this context because, one, the initial story that came out about the NSA was incorrect, or more accurately, the economists didn't provide the appropriate context of what happened with Mythos. Two, talking about parity of China and The United States.

John Strand:

Understand that there's a little bit of hardware things that have to happen for that to be true. If you want to, watch China, see what's going on. Right now, ASML has a stance that if China invades Taiwan, they're going to break every one of the machines in China. If anything changes on that front, I guarantee you China's going into Taiwan. We're already seeing them take a far more aggressive stance than they've ever taken before with positioning and setting up boats to be able to invade China.

John Strand:

That's a whole another conversation, as I said. I don't wanna go there. So those are kind of the main stories. I wanna get into hugging phase, and I really wanna get into this. I I didn't know Walmart sold these stupid things.

John Strand:

But I was I was surprised

Derek Banks:

by online only, though? I mean, do they have them actually at go

John Strand:

to my local Walmart and get one of these. We'll talk about that more here in a little bit.

Bronwen Aker:

I I just can't believe how much the price has jumped in a couple of weeks.

John Strand:

Agreed. I think it's since we've started to leak. Well, we're in a chip shortage and Everyone's going into it. Oh, the memory in it is 178 gig. Is that what they have?

Derek Banks:

If you found John's monologue there very interesting, I wanna know more about chip stuff in the chip market. There is a company called Semi Analysis Semi Analysis. Their newsletter is fantastic, and I would highly recommend signing up to get their newsletter. It's all they do is chip market research, and it's very eye opening. It's a whole world of of interesting stuff there.

John Strand:

So I wanna take it back. I just kinda set the stage, Bronwyn. I would like to get your thoughts on this because you research it quite a bit. And, you know, like, I absolutely value your opinion on what this what this all means and what the models mean and things like that. So what is your thought take on this as well?

Bronwen Aker:

God. I don't even know where to start. I mean, you cover that, by the way. It's it really it it really is hard to know where to start because did I did I fade out?

John Strand:

You did. It looked like a bruise.

Bronwen Aker:

Oh, shoot. I know why. I know why things should get better at a moment.

John Strand:

Okay. I'm gonna answer Kathy's question in Discord.

Bronwen Aker:

Go for it.

John Strand:

Is it John? Okay. So they get the machines. They produce the chips. Then what?

John Strand:

World domination. Serious question. Yeah. So let's take the capabilities of if they have the ability to produce the chips at the scale that they want to. If we look at Chinese infrastructure, we're looking at power grid.

John Strand:

Chinese power grid is is well, depends on where you're at, of course. Chinese power grid is much better than what we have in The US. They're pushing nuclear far more than we are, while a lot of countries are actually retreating from it. So the point I'm trying to get to is once they get to that chip capacity, they can start generating the data centers, and they can start building up AI models that can absolutely go toe to toe, and they can put it on the hardware that those models need to be able to do the level of exploit development and the level of exploitation that they have.

Derek Banks:

To me, that's the key. Right? Is Yeah. Okay. You can build the model, but inference is where it's at.

Derek Banks:

Right? That's why we currently still have the edge is because we got a lot more chips. Right? And so, I mean, if you listen, if you've been following the Anthropic and OpenAI saga over the last couple of weeks, you know that OpenAI actually came out when Anthropic was having some inference issues when they got, you know, really popular. And OpenAI basically said, we're an inference company.

Derek Banks:

And so, you know, running the AI is a lot more difficult in a lot

John Strand:

of ways than building the AI. Yeah. So I hope that answers Kathy's question because it's a really, really good one. Right? Because, you know, what are we worried about here?

John Strand:

And and, honestly, we can get into, should we be worried about China? Yes. No. Maybe so. I think that that's that's a conversation.

John Strand:

That's a really interesting conversation to have. But I think it's out of the scope of the dentist because I wanna eventually get into what the hell do we do? Like, is there a certain level of panic that people need to have in their in their organizations? And I honestly believe the answer is, oh, god. Yes.

John Strand:

You're If taking everything that we've said here saying don't panic, then you completely missed the point. I I guess what I'm gonna say, and I would like to you you all's take Bronwyn, if you're back, should we be panicking yet, or was the best time to panic five years ago?

Bronwen Aker:

The best time to panic was several years ago. And, unfortunately, the political shenanigans going on right now are not helping anyone on a practical level because we've got all of this stuff going on. We have major well well, we've got the the nation states now using this as basically, it's the latest area of warfare. It's not it's not just commercial competition anymore. It's moving into the the military space.

Bronwen Aker:

It's moving into warfare space. And so all of these things are gonna cause problems. I I you know, there's so many ways to go. I don't know which way to start. Is there one direction in particular that you want me to address, John?

John Strand:

I okay. So I wanna look at look at the direction of like, we let's try to stay out of AI is going to suck all of our souls and sell us more ads. I I think we really let's stay focused on the cybersecurity side.

Derek Banks:

It's already been doing that, by the way. I know it

John Strand:

has been well before they got in.

Bronwen Aker:

It has been. And well, and it was doing it even before the LLMs came on on the scene, and and this is something I think a lot of people forget. AI has been around for decades.

Derek Banks:

Mhmm.

Bronwen Aker:

All we're seeing is that it's evolved into a new modality that has more capabilities, but AI has been around for decades. And so what we're seeing is kind of like the what the Romans did with technologies that they absorbed from countries that they conquered. They then refined those new technologies and improved them. We're in that type of a process where it's getting much better, and the the potential is wonderful and and awful, and I feel like a broken record saying this over and over again. Because, yes, we've got all of these models.

Bronwen Aker:

I think for the model creators, the next big barrier is going to be getting more output from less input. So in other words, right now, the big claim to fame is our model has 927,000,000,000 transforms. Well, yeah, it's also expensive as heck to run when you have that many transforms and that many tokens. So now do the same thing 10% of what you're starting off with. That's gonna be the next major frontier.

John Strand:

There's also the reason why China wants chips so fast.

Bronwen Aker:

There's also stuff going on. I would have to go in, and I didn't have enough prep time to be able to pull the story links. But I'm seeing from multiple reporting sources that there's also a push to develop chips that are even better at working with models of different kinds. And they're also now applying diffusion processes to language, and that's gonna be interesting to follow too. I don't even there's there's so many different ways to go where it's it's kind of like pick your nightmare.

Bronwen Aker:

What nightmare do you want to be most terrified by? And if you wanna do a nightmare of the day club regarding AI chips, the use of power, the, amount of moisture going into the atmosphere because of all the data centers. I mean, my god. You can I feel like we should have a little spinner? Time to

John Strand:

be a hypochondriac. It's right.

Derek Banks:

It's the ancient Chinese curse. Right? May you live in interesting times. So you asked for a hot take. I'll give you a hot take.

Derek Banks:

I shared it before we came online. The US built a Ferrari and locked it in the garage for national security. China mailed everyone a kit car. Guess which one's on the road. Right?

Derek Banks:

Everybody makes such a big deal about Mythos and I I and Fable, and I'm sure that they are more capable models. But, I mean, I've been doing a lot of work recently of getting AI to hack things. Right? And I use a Chinese open weight model. And I gotta tell you that the I mean, the model is important, but it's not as important as the harness.

Derek Banks:

I feel like we sometimes lose, you know, the forest for the trees. Would I like to have access to Mythos? Sure. But using the Chinese open weight model, it sure is. It's like 90% cheaper than just like Opus 4.6.

Derek Banks:

And so there's a real cost concern there. But I mean, really, it's not, you know you know, when I when I heard that, you know, Mythos hacked all the classified systems in a matter of moments, my first thought was, well, did it get in and, like, use, like, some kind of, like, weird, like, way to, like, listen to the frequency of the CPU across like the air the air gap. No. No. It was just obviously overhype.

Derek Banks:

But to me, it's still a bigger story that, you know, and and also a lot more boring because you can't hype it up. You know, the story about Light LLM, how a supply chain got hacked and then, you know, spread spread malware. Right? And that had nothing to do with the actual model. And and John, you're you're very correct.

Derek Banks:

I mean, the the the genie is out of the bottle. The Pandora's box is completely open, and there's no stuffing it back in. And, you know, one last thing, you know, to Anthropic, what did you think was going to happen? Like, what what really? Like, the only lever the US government had was to do what they did.

Derek Banks:

There was no other there isn't time to, you know, to to establish a a committee and pass regulations

John Strand:

and Blue Ribbon committee.

Derek Banks:

Yeah. Blue ribbon. There's none of that time. So, like, when when you made it such a thing and I personally, I think they did it as a combination of marketing and to stop the Chinese from diffusing their latest models. And they said, this is too powerful for everybody to use.

Derek Banks:

We'll just, you know, like, make it select. When you when you hyped it up in that way, what did you think was gonna happen? And if there are any GPT five five users out there, do you think it's better than than the Claude stuff? Because a lot of people do. And so and again, like, I'm I'm using a a local 27,000,000,000 parameter model, and I saw somebody ask, are we up to the trillions now?

Derek Banks:

Yeah. It's rumored that the frontier models are trillions of parameters now. We don't really know because they don't tell us. Right?

Bronwen Aker:

They're very good about keeping it in a black box.

Derek Banks:

Yeah. It is a black box. You don't get to see it. But, I mean, to me, at this point in time, you know, I think the open weight models have gotten to a point right now where, John, if you told me that we're only gonna be able to use open weight models because companies won't let us use inference anymore because of national security, I think we'd be okay. Yeah.

Derek Banks:

I think I think that we'd be fine.

John Strand:

Do have some questions. Cloudstrife brought up a question. Geopolitically, I'm not convinced it's adaptations to the Chinese priorities to bring all of our fears to life. This is another webcast that I did talking about China, and you have to understand China in context of the hundred years of humiliation. China is not really in the game right now of trying to do domination and take over a bunch of things.

John Strand:

They're literally trying to get as much access as they possibly can so they don't get invaded and get attacked and get humiliated in the way that they have been in in their history going all the way back to, like, the Boxer rebellion. But that's a whole another webcast that we haven't. You can find it online, but you have to have a little bit of understanding insofar as, like, how Xi Jinping, long marchers Xi Jinping's not a long marcher. That's Mao Zedong's area. But when you're looking at China and how they look at themselves and the rest of the world going from the Middle Kingdom to being oppressed and beaten multiple times, they're pushing an agenda of never being in a position for that to happen again.

John Strand:

And that doesn't mean that they're gonna be hacking everyone, burning the entire planet to the ground, but they wanna make sure that they have that power as well.

Bronwen Aker:

So Well and they've proven that they're very good at long term infiltration of Yep. Our government, our corporations, basically, any any organization that has the kind of of technology or information that they want, they're very good. And it's because of that long look, that that looking at the long game. And that allows them to make plans that are going to have maybe not a short term payoff, but you get that long term payoff in terms of of data acquisition, technology acquisition, all of that stuff. It's Mhmm.

Bronwen Aker:

It that's why they keep doing it because it works.

John Strand:

Cool. Alright. So I wanted to Derek, can you talk a little bit can you elaborate more? You were talking about, you know, standing up offensive AI for the research that you've been doing. And this is one of those questions that we keep knocking around in BHIS on how much we should invest in building our own infrastructure versus running it on Bedrock.

John Strand:

I shared this wonderful little NVIDIA DGX Spark that is available apparently on Walmart's website, which blows my mind for $4,679. Can you explain to people, like, if somebody were to buy this with a 128 gig of memory of unified RAM and it's got a four terabyte hard drive, What exactly can someone do from an offensive perspective with a system like this? Like, I know you're not gonna be writing brand new zero days for the Linux kernel, or maybe you are.

Derek Banks:

No. Maybe you could.

John Strand:

I'm not sure. What do what do you think? What can what can you do with this? So If you had something like

Bronwen Aker:

this, and

John Strand:

a little bit of know how.

Derek Banks:

Yeah. So, the first, you know, I I've been really diving deep in, custom agentic systems, like, it's it's not a secret anymore that, you know, we have a a platform that does external penetration testing. Basically, we design the agents to act like our pen testers. And, no, it doesn't replace our pen testers. It goes and finds things that would've taken them, you know, forever, staying up all night working twenty four seven.

Derek Banks:

You know, it can look at 1,500 web services while you sleep at night, and it's found some really interesting things. Now that's using mostly g l m five one in Bedrock, which is a Chinese ZAI's, you know, earlier model. And in testing, you know, when I first started, I I was basically using Opus, and John can attest to this, it was quite expensive. And then GLM five one on Bedrock is about 90% cheaper. And so it makes it a whole lot more a whole lot more, I guess, like feasible, I suppose.

Derek Banks:

And then, locally, there's a couple of different models that I've used locally. I've used Quinn, and I've used Gemma four. I think Quinn is actually better. It's that's from Alibaba. And the reason I think that it is is because when Google did their supervised fine tuning, they did it in a weird, like, tool call way.

Derek Banks:

So you have to do some weird stuff to in my opinion, to get Gemma for working. The things that I've been doing with it so I'm using a local inference engine called VLLM, and I've been using it to kinda run like parallel tests. Like, the things that I would normally do as like a pen tester using Claude, like writing a script or verifying something or doing research or something like that. I've been kinda comparing Claude to using Hermes with the open weight model, and I found that they're they're quite capable. In fact, I ran a test over the weekend and they basically came to the same conclusion of what I was having the model do.

Derek Banks:

And so to me, as we, like, move forward, like, the the hacker in me wants control of the model and control of the harness. Oh, and I forgot, I'm, you know, using Hermes on the Spark. And I was trying to go with all open weight, open source stuff. And I think right now, if you can get one of these, or even if you have like a a gaming card at home, you can get I mean, I'm I'm kinda probably spitballing here, maybe kinda 80% of where the frontier is. I think China lags behind somewhere maybe six months or so, but the gap is really kinda closed.

Derek Banks:

I really wish that US manufacturers would or US frontier models would start release or frontier companies would start releasing more open weight models. Because to me, if you kinda try and close it off and ban it, you're going like what we've you know, what happened with Mythos, you're going to stifle innovation. You're going to basically be behind the curve. I mean, I was saying this earlier, like, what what would have happened in the, you know, like, mid or, you know, the mid two thousands to information security if we couldn't have had Metasploit? Or if we didn't have, you know, like some of the open source tools that we all rely on, the government said you can't use those, you have to use this closed source thing, and only a few kind of people do that.

Derek Banks:

Would we be where we are right now in the security world? No. It'd be a lot worse probably. What what hardware, I'm using the local LLM. I'm using the Spark DGX that John said that we were that he had the the picture from Walmart up.

John Strand:

Yeah. So, you know, kind of going back to kind of like picking at the question. You know, when when we're looking at our testers, and a lot of our testers have these boxes and they're debbing and they're trying all kinds of different things. If you're trying to do the standard scan data, feed that into it, like, we know some people are using n eight n where they're loading the data in, and they're invoking the AI model on their local system that they're running, and then it's doing initial, you know, just just review of the scan data. That's not super powerful requirements.

John Strand:

Like, some of the API research that we're seeing the models do over the past couple of weeks, we've gotten really good results in just kind of sticking with standard pen test methodology without getting into, like, crazy zero

Derek Banks:

to Yeah.

John Strand:

I mean exploitation.

Bronwen Aker:

Well and So Here's but here's the thing. The models that are out there have been trained on information up to whatever their con, cutoff point was. So they're likely to have many, many, many tried and true security cybersecurity techniques already burned into them, already embedded. So for as you were saying, John, run of the mill stuff, it should be fine. Will it be as fast as if you're running a front or middle model?

Bronwen Aker:

No. But you have to do fire and forget a lot anyway. So why not do it with local systems, with local tools so that you can maintain that data sovereignty that we want so much?

Derek Banks:

Yeah. So you hit on the thing that's the the thing that that that I left out that's very important is that there's definitely a speed difference. It's not that I mean, the the local model on that Spark d g x and even on my MacBook that has an m four Pro Max. I mean, it'll run, but it runs a lot slower. Now, does that mean it's unusably slow?

Derek Banks:

Absolutely not. In fact, one of the things that, like, impressed me the most was I would do something with Claude, and it would, you know, be done in like five, seven minutes. I'd do the same thing. It would take thirty minutes with the local model. Now, yeah, that's a big difference in time, but I also didn't have to pay token costs for that.

Derek Banks:

Right?

John Strand:

So Jake has just joined the chat.

Derek Banks:

Yay. Keep in it.

John Strand:

Getting Jake kind of up to speed. We're we were just talking about all of the news about, you know, the NSA being hacked. Okay. Maybe the NSA wasn't completely hacked. Maybe the story wasn't wasn't put as best as it could have been by economists.

John Strand:

And we're kind of at the point in the conversation, Jake, where the whole idea of locking down models, shutting down companies, and trying to protect it doesn't matter. The genie is out of the bottle. There's a number of different ways that people can do this stuff, and they don't need a $400,000 supercomputer to be able to do it. Do you wanna talk a little bit about that?

Jake Williams:

Yeah. I'm joining you from a, you know, an an m five max with a hundred hundred and twenty gigs of memory, unified memory, specifically to run local models. And so, you know, I I I bought this after dealing with a bunch of of issues with, you know, refusals from local models. I've got a big machine learning workstation with a couple a six thousands in it, but yikes. It's it's just I mean, it's it's a space heater, and I can't take it with me.

Jake Williams:

And so so yeah. 100%. I'm using local models now. To your point earlier, that genie is out of the bottle, man. No no question.

Jake Williams:

And so to Derek's point, I use the heck out of these. They're not as fast as, you know, sometimes as as using, you know, clogged co worker or what have you. But but I get zero refusals. I'm a 100% in charge of change control because, you know, I I adapt the model when refusals, by the way, when the guardrail kicks in and says no. You know, and I've got fine tuned models explicitly that don't say no.

Jake Williams:

Dolphins, by the way, in case anybody's chasing these these models. And the dolphin models typically have refusals fine tuned out. And so so here we sit. You know, I I again, I'm one of the biggest problems that I've had thus far with and this data sovereignty. One of the biggest problems I've had thus far has been the safety filters They get changed on a given model day to day.

Jake Williams:

And and I have refusals one day where I didn't the day before. Alright? So yay.

John Strand:

So on the on the on the like like, I know you and I are kind of at the same place. Like, we're getting further and further away from the classified world. But when you first saw the news articles that were like, NSA has been running this internally, it scared the living shit out of people, kind of what was your what was your first reaction to that?

Jake Williams:

My my first reaction to that was that I think it probably scared the living, stuff out of some people. And so and I I think that's that's probably worth, you know, really diving into. There's a Ford or sorry. A story, over the weekend I saw where Ford had been rehiring a bunch of engineers, 300 some odd engineers, that they had let go, because of AI, and thought that AI could handle a bunch of the engineer requirements and whatnot. And it turns out that the devil's in the details on this stuff.

Jake Williams:

So I think that there are probably some people at NSA who looked at these models and was like, oh my gosh. Like, you know, the this this is earth shattering. This is the same thing I'm getting from my vulnerability analyst without understanding there's a lot of nuance on how the sausage is made and how we get to that output. And so I I I think that the these models were not scaring everybody at NSA. I guess is maybe a good way to say that.

John Strand:

Cool. Space Touch has got a question, and I think you're just in time for it. And I really think that this is critical because the the hype is overhyped, but the hype is real. And I think that that's what I'm trying to get across to people. If you go back to the .com boom, there's a whole bunch of failed companies that were Internet.

John Strand:

We're gonna order food on the online, and we're gonna be able to buy pet food online, and we're gonna have all this stuff. And remember the Super Bowl, every ad was a .com company, like pets.com. And everybody thought that was a joke. It was all hype, and it all burst. But all of it was real.

John Strand:

Because now I can buy pet food online. Now I can order food and have the groceries delivered online. All the things that people talked about eventually happened. It just was a little bit early on the curve. So if we're looking at this, I'm I'm not I don't want people to panic.

John Strand:

Right? And that's me personally, Jake. I wanna get your take as we close out. I don't want people to panic, but you better demo get ready. Because my take on this is the traditional security approach of we are going to firewall, we're going to patch, we're gonna change configurations, the security vulnerabilities come up is dead.

John Strand:

You're gonna enter in a world where the vulnerabilities are coming faster and more numerous than many teams are gonna be able to handle. They're gonna be dealing with a situation where patching may not be available when the exploit exists. So the the phrase that you need to learn is compensating controls. Right? You're gonna have to start developing skills that we've had in security for years, and a lot of the old gray beards have had to try to figure out back in the day when we only patch once every three months.

John Strand:

We had to figure out how to secure shit before we even had a patch that was going to be released to production. Everybody better get into that game, number one. Number two, you better get into network threat hunting. With NPM packages and all of the different supply chain crap that's hitting right now, people in that that's being accelerated by AI. That's gonna be landing on devices.

John Strand:

It's gonna be in software packages that are either trusted or not protected by EDR. And you've gotta start looking for how you're gonna deal with that type of security vulnerability in your environment. So, Jake, I'd to get your take. That's just my two cents on this. So let's get your your your take on it as well.

Jake Williams:

I'll I'll give you my my easy take here. I feel like I keep beating the zero trust drum again year after year after year. And and then, you know, look. But let's be let's be clear about this. Right?

Jake Williams:

Vendors have done us wrong by jumping on the zero trust hype train. Because before everything was AI at RSA, everything was zero trust at RSA, whether it was or not. When I say zero trust here, right, we're never getting to zero, but we do need to think about two things very, very specifically when it comes to VOLM, you know, remediation here and even just just preparing for that, you know, eventuality. You know, one really is that we we have to be ready for have to be ready for thinking about how threat actors are gonna be able to exploit and abuse identity. So once they've compromised a, you know, compromised an application, can they assume the identity of that application?

Jake Williams:

As we get into cloud environments, that matters a lot more. Right? If they can assume a role or what have you, most of us are not professional cloud cloud security engineers and can't work through the full threat model of what a compromised identity and a workload really means for overall cloud infrastructure. Second place is network, you know, network zero trust. Right?

Jake Williams:

So limiting that blast radius, and very specifically focusing around lateral movement there. Right? So so that I I term those into the first one. But the second one is not a security thing. It is a place where you as a security professional need to go be a champion.

Jake Williams:

You've gotta go out. You've really gotta beat the drum on on as John mentioned. Right? Sometimes patches aren't gonna be available. But when they are, we're we're taking folks out of what used to be if you're Oracle DBA, a ninety day patch cycle.

Jake Williams:

If you're anything else, a thirty day patch cycle, for a lot of folks, and you're asking them to stop doing that. And so communicate with communicate with with IT leadership, communicate with risk managers that when folks stop batching and they have to go and drop everything, right, that means we need more IT staff to be able to handle this. And I know that's a hard message to deliver as a security professional, but it's one that you've got to start beating the drum on because the the reality is that if if the remediation centers are folks that patch aren't able to do that thing, right, then then we overall are not gonna have good security. So those are my big two takeaways.

John Strand:

So the one on identity really resonates because right now, whenever we're doing, like, source code analysis, things like that, I don't know why, but AI rocks at identity issues on

Jake Williams:

source code

John Strand:

analysis. Yep. It does really, really good. So that's that's that's great. With kind of the other thing that I wanna kind of hit for people moving forward on this, you you talked a little bit about hiring.

John Strand:

And it's so weird because I have CISOs and CTOs that I'm talking to that one side I'll give you an example. I was talking to a gentleman that works at a law firm, and he said, a year ago, I had no developers. He said, today, I have 98 developers, and a good percentage of them have no coding experience. So as a security professional in a firm like exception. That is the rule.

John Strand:

I'm seeing that all over the place. We literally have people that are developing code. I'll give you another example. I was talking to someone. They're like, we need to secure this app.

John Strand:

Here's the main developer of this app. Super excited about the app. He used AI to generate the app. It did all these things that they always wanted from their SaaS providers, and they never could get it for their SaaS providers. And I asked a question.

John Strand:

What coding language did you write it in? And he said, I have no idea. Yeah. So So I So my point in the Derek, I'm gonna kick it over to you. This is a great time.

John Strand:

It may not be a great time yet to be in security. Wait. It's about to blow up. There's not enough security professionals to handle what's coming at us. Be ready.

Bronwen Aker:

Get trained. Developers in general were so good at at security stuff to begin with.

Derek Banks:

Yeah. So I'm actually apologizing to our testers often for going, dude, I am so sorry I brought you more work, but here's some more work.

John Strand:

Well, we thought, Eric, we thought when we started this grand experiment that we'd be able to do tests faster and cheaper. And what we're finding is we're finding way more vulnerabilities, we're having really hard conversations with customers about the compensating controls. Mhmm.

Derek Banks:

Right. So my my I have two takeaways for your question to Jake. My first takeaway would be, you better know what you're hosting on the outside of your network. Like, better know if you're using some open source thing to do some business practice, because we are seeing a whole I just thought I was texting John on Saturday morning. Like, I don't know why I keep texting you that I found another critical.

John Strand:

Don't stop.

Derek Banks:

It's great. Like, and and so, if you're hosting APIs, you're using, you know, whatever stuff that was cobbled together by somebody way back when and it's still out there, you should be concerned. You need to know exactly what you're doing on the outside of your network. The second one is to your point of, now we have 98 developers. Two things that I would do.

Derek Banks:

One is everything that gets coded is in a container. Use Docker. Learn how to use Docker. And and and only give it the keys that you need to get the job done. Do not let it have access to the bare metal on your on your on your on your system if you're doing that kind of work.

Derek Banks:

Now, the other thing I would say is age gate or pin packages, like, with poetry or UV. So that way because that to me, like I said earlier, the scariest thing I've seen so far is supply chain, like, Light LLM getting hacked. That is crazy scary. Not Mythos.

John Strand:

Yep. I have another question I wanna throw at at y'all. I I've been I I think we've had a couple of news stories, Bronwyn and Derek, about, like, MCP servers and different things like n eight n being exposed to the Internet. And I was playing around with Shodan a little bit, and, oh my god, there's a lot of exposed infrastructure that we haven't traditionally been going after.

Bronwen Aker:

But there's a

John Strand:

ton of people that are clearly dev ing directly against the Internet, YOLO ing it, default credentials, and very little security. And what do you so, Derek, I'm gonna throw this to you first. But what do what are we doing to try to secure this stuff that we're building and we're testing and we're playing with and we're trying out? Because we have to know how it works. We have to try a lot of different models.

John Strand:

But if you remember, I kinda freaked out, and I said, we need to have a to secure this.

Derek Banks:

Yeah. So on our platform, every single tool call is logged. Every single one of them. Like, anything that an agent does is logged. Two, any communication outside of the scope that we gave for the IP addresses and domain names is denied.

Derek Banks:

It it won't were

John Strand:

Outside of the system.

Derek Banks:

Outside of the system. So it can't communicate outside of what the scope is. It's only gonna so if it somehow got indirect prompt injected in some way, then if it did happen, it wouldn't be able to communicate out. Also, we have band commands, like you can't use like, say, you can't net cat something off the box, for example. And the final thing is we do a full packet capture audit, like, to to make sure that if if something happened, we have all the logs.

Derek Banks:

And I know it all works because I frequently have to troubleshoot and look at the what was told and what was done. So Alright.

Bronwen Aker:

Logs for the win. Yeah.

John Strand:

Oh, quickly. What do you recommend for people to try to secure their stuff in the security side? And then I'm gonna let Jake take us out.

Bronwen Aker:

Oh my god. Yeah. Definitely, Docker is a good way to go. VMs, if you're more comfortable with them. I know a lot of people like to to work on stuff in the cloud, but then you're adding a layer of of complexity because, oh my god, local LLMs have a lot of benefits over and above not going through your token budget, but also because then you can legitimately establish and maintain not only domain or data sovereignty, but also token sovereignty.

Bronwen Aker:

And, I saw somebody asked earlier in Discord, if you're running a local system, how much of a difference is gonna that gonna make on your utility bill? Though it'll probably be akin to using an appliance on heavy load for a while, I would love to see some analytics on it because I haven't seen anybody testing that. I would I would think, though. Until I'm

John Strand:

plugging my computing cluster into a two twenty plug, I'm not gonna get that worried.

Derek Banks:

So

Bronwen Aker:

Well well, ditto. And, I mean, I know I've got a a decent gaming rig for my private system, and I'll run it up on something. And, yeah, it spins up the the GPU, and I've got, the RAM is I've got the indicators showing that it's being heavily impacted. And it really isn't that much longer a wait, especially because I don't know anybody who does multitask anymore.

John Strand:

Alright. Jake, any any closing thoughts? Really glad that you were able to make it, especially since you're in your car.

Jake Williams:

I I am so sorry, man. Timing and and whatnot. But but yes. So for being in the car here and being late. But all that said, you know, to just a couple of things to take us out.

Jake Williams:

I saw in the the Discord, you know, what are folks offering? You know, there is training coming to Wabas Hackenfest. I know Derek has a class. I have a class, you know, that that focus take basic approaches from different ways, but but both very, very hands on. You know, what I will close us out with, though, all great approaches so far.

Jake Williams:

One thing that I didn't hear mentioned, you know, as we talk about logs is we as security professionals have to be really, really careful with, anything that we're logging from LLMs. And the reason for this is, folks, the vast majority and I'll close with this. Right? The vast majority of what we log in security is metadata. It's not data.

Jake Williams:

And that means that, you know, under GDPR I'm not a lawyer. Not this is not legal advice. Go talk to yours. But, like, GDPR and other regulatory, you know, regimes typically have a carve out for security logs. Logging the contents of of prompts and responses from LLMs, that's not metadata.

Jake Williams:

That's data. It's it just is. That's application data. We're pulling in particularly retrieval augment a generation or rag systems. We're pulling in a lot of very, very sensitive context, potentially trade secrets.

Jake Williams:

Right? And and bringing that all in. And if we're logging that, we now have sovereignty concerns around the logs themselves. Right? And how we can handle outsourced security op centers and dot dot dot.

Jake Williams:

And I'm gonna tell you, I think that probably the majority of my expert witness work over the next several years as it relates to AI is gonna be because of these specific issues. It's gonna be trade secrets and whatnot that are caught up in logs that are then sent out to, you know, overseas third parties and what have you. So the the what Derek said a 100% is correct. I need those logs to be able to troubleshoot. I'm not in any way, shape, or form knocking what Derek said, but we gotta be really, really careful about where we put those logs and how we handle them.

Jake Williams:

John, thanks so much for having me, man.

John Strand:

Dude, one last thing. Who are you working for? Who are you representing before you go?

Jake Williams:

Oh, Hunter Strategy. I'm the VP of r and d over there. Research and development. Thank you so much for for letting me pimp them. Appreciate that.

Jake Williams:

And, yeah, thanks so much.

John Strand:

Jake, it

Derek Banks:

was good seeing you again, by the way. Oh. Look forward to see you out in devlog. Always. You can you can always call me out.

Derek Banks:

It's fine.

Jake Williams:

Super upset. Come on.

Derek Banks:

Come on. No. We're we're actually we are logging the tool calls, not the conversations.

Jake Williams:

Oh, perfect. Okay. Good to go.

John Strand:

Yep. Alright. And we to put this on, other than Jake, we're Black Hills Information Security. If you need to get hacked, you're afraid you've been hacked, or trying to prevent yourself from getting hacked, we're here to help for all your hacking needs. So check us out.

John Strand:

Thank you so much everybody for joining. Let's get out of here. It's getting late. It's not stress. Let's just focus.

John Strand:

What do we say? Remain calm, stay focused, panic later. Education is the solution to every one of our problems.

Bronwen Aker:

Stay on breathe.

John Strand:

Remember to breathe. Take care.

Episode Video