Privacy Please
Welcome to "Privacy Please," a podcast for anyone who wants to know more about data privacy and security. Join your hosts Cam and Gabe as they talk to experts, academics, authors, and activists to break down complex privacy topics in a way that's easy to understand.
In today's connected world, our personal information is constantly being collected, analyzed, and sometimes exploited. We believe everyone has a right to understand how their data is being used and what they can do to protect their privacy.
Please subscribe and help us reach more people!
This podcast is part of The Problem Lounge network — conversations about the problems shaping our world, from digital privacy to everyday life.
Privacy Please
S7, E276 - Ransomware Doesn't Have to Hit Like a Hurricane (with Jonathan Sander)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Jonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about.
Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now.
Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized.
Articles referenced:
- Ransomware Doesn't Have to Hit Like a Hurricane (Myota): https://www.myota.io/articles/ransomware-doesnt-have-to-hit-like-a-hurricane
- Why We Need an AI Agent Taxonomy Right Now But We Can't Have One (42 Notions): https://blog.42notions.com/why-we-need-an-ai-agent-taxonomy-right-now-but-we-cant-have-one/
Chapters:
- 00:00 – Catch-up with Sander
- 14:30 – The hurricane analogy: why Myota built resilience instead of a wall
- 20:30 – What actually makes Myota different from standard backup/cyberstorage
- 22:15 – Why you can't build a clean AI agent taxonomy (and the six dimensions Sander landed on instead)
- 28:50 – The hybrid agent problem: acting "on behalf of" vs. "for the benefit of"
- 45:10 – Sander's one takeaway: get the basics right before chasing the AI hype
Cold Open: No Easy Answers
SPEAKER_00And you know, I don't really give them great consolation because I kind of tell them the answers don't exist yet to some degree, right? Like we're we're writing history in real time, um, and that means we have to invent the ideas in real time as well.
SPEAKER_03So right now the business hates the answer that you don't have the answer.
SPEAKER_00Right. Even when it's true, even when it's actually the best answer, right?
Reunion And Guest Check In
SPEAKER_02All righty, and ladies and gentlemen, welcome back to another episode of Privacy Please. Cameron Ivy here with Dave Dum.
SPEAKER_03It's been way, way, way, way, way too long. Things have been busy. It's hard to get you on the screen. It's hard to get me anywhere. Get me between the teeth. May all your ups and downs be between the sheets, my friends. May all your ups and downs be between the feet.
SPEAKER_02Well, maybe we got one person here that might be able to get in between those sheets. I don't know. Well, boy. Wait a minute. That went too far.
SPEAKER_03Who's on the line today? Who's on the line today?
SPEAKER_02We got Jonathan Sander over here. Uh Sander, what's going on, man? It's been a while.
SPEAKER_00Um yeah, it has been a while, and uh usually I would come in with something you know very colorful to say, but uh I think Gabe just filled the colorful quotient for the entire uh podcast. So I guess I'll just uh play it uh straight, I think is the right word here. Um and uh just say uh you know, it's it's been good. Life has been very busy, let's just put it that way. Um I've been yeah, I've been all over the place.
SPEAKER_02Um besides that, what what what have you been what have you been like thinking about lately?
Secrets And LLM Harness Reality
SPEAKER_00Oh, I mean, uh, you know, if I had to pick, you know, everyone likes top three lists, right? So if I if I had to pick three things I'm thinking about right now a lot, the one thing I think about all the time is secrets, right? That's a sort of the core of my entire career, and I still think about that a lot. And I just obviously exited um you know the NHI company where we were thinking a lot about secrets in specific contexts. Um and uh second thing is uh people are people are very interested in um the LLM strapping profession. Uh and what I mean by that is building harnesses um for these things and you know locking them down, obviously related to secrets to some degree. Um so I've been thinking a lot about that. Um and the last thing it's kind of funny. It it's a consequence of the second thing. A lot of it is going just like really back to basics. Um I think there's a lot of there's a lot of things in tech right now that are at risk because the pace of things is going so fast and everyone's digging into every detail of every system so deeply that all the old hits are new again, right? And all the things that people thought they could forget about uh are now they're now being very violently reminded, right? And and yeah, you could say that like you know, some of that is all the uh ooh mythos type of stuff, but uh it's also just even we're moving back to a place where the people who are driving the future of tech for a lot of organizations are not the technologists. And whenever that happens, that's a great recipe for bad security results. Sadly, sadly, but that is the case, right? So there's been a lot of going back to basics, trying to keep up with all the uh whack-able of people standing up crazy systems, mostly AI systems, but not all, right? Not all. Probably a longer answer than you wanted, Cam. But there you go.
SPEAKER_03You wanna,
When The Business Skips Security
SPEAKER_03and you don't have to, but you want to name names. Who are these who are these nefarious people that are getting in the way of uh you know the adults in a room actually making the tech decisions?
SPEAKER_00So I you know, there's two ways to look at it, right? I mean, part of it's the classic problem, right? Is that the business, quote unquote, the business, right? And and if you want to be more specific, what do I mean by that? I mean revenue generating parts of organizations that are data rich and trying to turn that data into it pro a product of itself, right? That's what they're trying to accomplish, right? Um those people view the security function as the department of no, right? The classic meme. Um, and so they don't get invited to the party a lot of times. So it's not even that they stand in in the way of the adults in the room game. It's like they the adults don't even get into the room. Um, and so that's that's one way to look at the problem. The other way to look at the problem is that I talk to a lot of people in the security world, and right now they're feeling pretty numb in large part, right? Because they don't feel like they actually have the exposure and the answers to these problems. And you know, I don't really give them great consolation because I kind of tell them the answers don't exist yet to some degree, right? Like we're we're writing history in real time, um, and that means we have to invent the ideas in real time as well.
SPEAKER_03Um so I can tell you right now the business hates the answer, you don't have the answer.
SPEAKER_00Right. Even when it's true, even when it's actually the best answer, right? Right? Like that is that is you know sometimes what you have to say. Um but which is what which is why, by the way, I keep coming back to basics right now. Because I think, you know, if you can't do anything really specific for some fancy new AI in a box type thing, then the question becomes, all right, well, what can you do? Can you to the first thing I was thinking about, provide a better way to protect the secrets that this thing might need to handle or be hooked up to? Can you make sure that if it's gonna have access to real data, that there's resilience to make sure that when it, you know, oops, sorry, I deleted everything. Or that you have a solid path back to a working world, right? Can you be sure that the controls you put on the lateral systems that you might have are well executed so that somebody's finance AI bot doesn't go running rampant with accounting information that somebody forgot to lock down with the right kind of role management. Right? These are these are sort of the meat and potatoes, like you know, identity and security questions. And, you know, I I I I what I've counseled people with is fine, you don't have some fancy answer for how the latest model in the latest harness for the latest business purpose is going to be secured in some really specific way that talks to exactly that scenario. But do you have all the other stuff taken care of? Because if you don't, that's the answer for now, right? That's the answer you need to go after.
CVE Noise And Real Priorities
SPEAKER_03What's top of that list? Because a lot of times when I hear people talk basics in InfoSec, they literally will go back to patching. I'm a firm believer that patching is still a necessity. But you know, we've got this C VE problem that's only been made worse by AI. Like they're not really 0.1% are exploitable. Or 0.2% have actually been seen in the wild. Right.
unknownRight.
SPEAKER_03That creates a basics problem where like the business here is we gotta patch everything because mythos is on the loose.
SPEAKER_04But you and I know it's like, sure, but all the things don't all have to be touched and patched at the same time.
SPEAKER_01Hmm.
SPEAKER_00You don't have to touch all the things at the same time. I will agree with that. Um whether or not you have to patch all the things probably depends on how much discipline you've had up to this moment, right? So somebody's out there with uh wholly exposed, obviously compromised versions of Ubuntu from like five years ago that have all sorts of local privilege escalation issues and remote code exploits that are well known, well, yeah, they should really actually patch all the things right now, right? Like that's so so so it kind of depends. But if you're talking about like, let's say a reasonably responsible organization, I would agree the patching is probably not that's probably not where you need to throw your accelerant right now, right? I think if if you're looking for the places to throw your accelerants, right, I think those are the those are basically the three places that I was talking about, right? Which, you know, number one, it would be secrets. Number two, it would be resilience, because you can't be sure right now how these things are going to do the bad thing and maybe result in bad things then happening and you having to recover from the bad thing. So you want to make sure you have recovery capabilities, right? Um, and the third thing are those identity management concerns that will be with us literally forever because it's relationship management and relationships change.
SPEAKER_02Yeah, yeah.
LLM Non Determinism Changes Security
SPEAKER_02Have we ever to what you guys are talking about? Have we ever seen anything in history um with the way that AI is and the speed of things and have we ever seen anything like this? Is this like is there any way to compare where we're at in a state of cybersecurity and ransomware and all the things?
SPEAKER_00I mean the the comparison that gets made most often is to like the cloud shift, right? And I know why people make that comparison, because from the point of view of scale and how much it affects everyone and everything, it seems comparable, right? But um actually team knows that we haven't seen something that's really like this. And it's because up to now everything that a computer system was going to do, right? As long as you had access to all the layers of that computing system, you could predict what would happen. It might be really, really complex to do that, but it was theoretically possible. At this moment, introducing LLMs means that we can no longer say that right. It is non-deterministic and that has real knock-on effects to how you would approach doing security specifically, but even like beyond security, right? Even things like how do you build a system to handle all the combinatorics of how your application may behave if you don't if you literally don't know how your application may behave. Um, so I do think there is a difference in kind here that is very important. Um and, you know, I again, right, back to basics. I don't necessarily think it changes the game. Um what it does is just it re-emphasizes the importance of some of those fundamentals. That was as close to a sports metaphor as I'll ever get, probably, just the way I put that.
SPEAKER_03Abe, what's your take on that? Look, I'm inclined to agree. I I intentionally injected the uh the fear, uncertainty, and doubt that mythos has created. Because the the the whole glut of the CVEs has has just become uh for me at least, a bit of a uh a public annoyance. I think it does more harm to the greater security con conversation than it does good, right? Like yes, the attackers have definitely gained a speed advantage in many ways. But I could argue that some of those speed advantages kind of always existed so long as you're detecting response capability stuff in the first place, right? Like it's like it's like, oh no, they got faster. Yeah, but you're detected in it's still like you know, it's all is molas, it's still like they're getting faster and didn't really change anything except when the New York Times published the headline, right? Like that's that's really the only difference. Like nothing else has changed. There are those that have been good you know, citizens of the cyber world that yeah, it's a real concern. It's a real concern. And we've seen still in a moment, I think every time we see a significant shift in compute as a whole, we see the test. Right? So we've seen compute shift from the edge to the to the, I'll call it the top, but to the core and back and forth again. And every time that happens, we we we create problems. We push code out to the browser edge and oh no, now now I can I can manipulate input back to the like we've been doing this for so long. It's like we're gonna learn this lesson one day, though, right? Like we absolutely will. And really AI for me is it's kind of a it's kind of tugged in both directions. We've pushed a lot of compute intelligence back to the edge, namely putting it in the hands of everyone. But we've also done the same thing back at the core. And so I think what Stan is really describing is you kind of have this perfect. In fact, before we went live, what we were talking about cold fronts and warm fronts coming together to create hurricanes. And it's and it's like that, right? You've got the cold front on this side and the warm front on this side, and hurricane season, maybe.
SPEAKER_02Indeed, it's such a such a perfect uh uh segue.
Ransomware Resilience Beyond The Wall
SPEAKER_02Segway, thank you. Perfect segue into my next question for Sander, which is we host podcasts for for uh fun and profit. This is our first time. Um Sander, uh I saw a blog you wrote for Myota. Um ransomware doesn't have to hit like a hurricane. Let's let's dig into that. What I mean, I guess that kind of answers the first question. Like, where did the title come from? What made you come up with that title?
SPEAKER_00And yeah, well well, it's interesting. So, you know, I I've been doing, you know, I have an operational role at Myota now. Um people who pay attention to LinkedIn for reasons I can't fathom why you would. But um, if you do, you know I've been uh messing around with LinkedIn for or LinkedIn with uh Moyota for years, and now I've moved into an operational role there. Um but it made me, you know, obviously think quite a bit. And um when I'm trying to stop thinking, what I do is watch YouTube. And um though what I watch typically is like educational content, and I and I was watching and I saw this video um for this channel called the B1M, if anyone's interested, it was it's a construction channel when they talk about construction projects, usually very high-scale ones. They were talking about how New York City, I'm pointing to New York City, um, handle is is planning rather to handle their storm surge issues in certain parts of the coast of Manhattan Island. And the way they're handling it is instead of just building a wall, which is one way that places have handled it, they're actually building a lot of beneficial infrastructure for the communities around these areas of Manhattan that will act as a wall, right? Because the idea is that like if you just build a wall, I mean, it does the job you need to in terms of stopping the disaster, but it doesn't give anybody else anything good, right? It just sort of is what it is. Um and you know, the thing with the the Moyota product that I noticed really, like, you know, it is funny, as I'm getting more deeply involved, I'm I'm noticing things I didn't realize before, is that it it simultaneously builds a wall against things like ransomware and you know delivers resilience in general, right? But is on the way to doing it, it delivers better security results and um does so typically by removing hard costs and all these other, and I don't want to get like pitchy, but like my point is that just like this infrastructure New York City is building, um these ransomware attacks don't have to be about like bad thing happens, build wall, bad thing happens, a little less bad, but in between you're just waiting for bad and you have a wall. It doesn't have to be that, right? You can actually plan for something that will enhance the way life is lived between the disasters, but also help them the disaster strikes, right? And that was like the analogy that that's where that's where that the analogy came from.
SPEAKER_02That's cool. I like that. Gabe, you got anything in there?
SPEAKER_03No, I I think Sander summed it up rather effectively. I mean, it's uh it's a good analogy. It's a very good analogy. It holds well.
SPEAKER_00I mean, I hope it is because that's literally the whole blog post. It's like, here's an analogy. Um so if it's not a good analogy, then it was kind of a waste of time, is what it boils down to. So I hope it's a good analogy. That's that's that was actually the whole point.
SPEAKER_01Yeah.
SPEAKER_02Honestly, you kind of ran into one of my questions because I was gonna say I love the line, it doesn't need the park because it doesn't need the wall, but that's you basically just broke that down for us. And you also referenced Johnny deleted the critical data. What what's the real version of that story? Do you know? Do you have anything on that part? That's it. Johnny deleted it.
SPEAKER_00I mean, obviously, I I will not, you know, I will keep I will keep names out of it to protect the guilty. Um but but believe it or not, this is about a human. And a human who made a mistake in this case. Not Johnny Five? Not Johnny Five. Ooh, Johnny Five is alive. I love that movie. I was gonna say that's that's that's that's that's the 80s kids right there. Um but uh but yeah, I mean, listen, it could be a story about any organization on earth. Ever every one of us has done it at some point. We've deleted something we didn't want to delete, right? The only question is how much power do you have over some IT system? Um, and therefore how much can your brain fart affect the people around you, right? Um and you know, uh we could also obviously we were talking about AI. We could, you know, there was that very uh topical story where um I believe it was Claude, but I'm not 100% sure, um, actually went and deleted an entire Postgres database, right? Just like gone, um, basically begged forgiveness, uh, but could not, in fact, solve you know, fix the problem. Um these things happen, right? And you have to plan for some sort of ability to be resilient in the face of those mistakes. You have to, right? The question is, again, right, just like the park can be the wall, can you have something that doesn't necessarily just solve the disaster case, right? It solves other things. Which, by the way, to be really fair, maybe not things you were planning on solving right now, right? Like you know you need the wall, right? You know you need that, right? And your New York City knows they need to stop that storm surge, right? You know you need to be prepared when the next ransomware hit or you know the next Johnny team mistake happens, right? You know you need that, but are you gonna settle for just that, right? I think that's the question I'm asking people to ask themselves, right?
SPEAKER_02Yeah.
Backup Architecture And Recovery Design
SPEAKER_02You hear a lot of companies having backups and you have security. Um I guess for both of you, what what what kind of stands out that makes Myota a little bit different than your normal cyber storage or what's the niche for Mayota?
SPEAKER_00Well, let's take Kate take the first crack at that one.
SPEAKER_03I mean, look, I'm obviously uh biased, but biased aside, what Myota's done differently is attacked the problem at the architecture level. Full stop. Because that's a lot of what's wrong with and I say this in a loving way. Speaking of 80s babies, right? Like I grew up before the internet and I was there for a lot of its its creation. And we're still using a lot of what was created decades later. And so architecturally processed. Specifically, and I tell the following story too, right? Like IBM and partnership with a few others created the first backup drive before the first hard drive. That's how long we've been thinking about resilience.
SPEAKER_02You've been a busy man. You've been you're doing a lot of uh speaking events, and we can get to that at the end on some that are coming up in the future if anybody wants to go see Sander and uh stalk him or anything like that and be weird. Um you wrote another blog and well yeah, that's fair.
Why AI Agents Need Taxonomy
SPEAKER_02You uh Sander, you wrote another blog um why we need an AI agent taxonomy right now, yeah, but we can't have one. Uh what who was that through again?
SPEAKER_00That was just through my LLC 42 Notions, which um any hitchhiker's guide to the Galaxies fans will know um why my company is named that. Um but uh basically um you you know it's interesting, right? A lot of the time I spend um sort of in advisory work, uh both on the vendor side and on the, let's say, organizational side, is right now around AI agent security. Um there's no coincidence that the reason people are asking me those questions is that a lot of that sort of centers around secrets and identity, and those are the two things I've spent a lot of time around. Um and of course, you know, just recently out of an NHI company, all that jazz. But the blog a lot of the times, and this is almost a quote for the blog, but I think this does tell you what the problem is, like a lot of the times when these conversations start, people will say things like, well, AI agents do blah blah blah blah blah or blah blah blah blah blah and you know as it applies to AI agents. And it really makes it sound like all the AI agents are kind of one type of thing, right? And to me, in my ears, the way that rings is if someone said, well, you know, all the animals on earth are uh, you know, but can you really make a statement that would be sensible or educational in any way about all the animals on earth other than the fact that they happen to be on earth, right? Like it's just it's not like you know, AI agents all use AI, but that's about where you have to stop when you're comparing them in that group fashion. Um and by the way, if you want to convince yourself of that, right, just think about if you use almost everybody uses a chatbot in the browser at some point, right? And you ask it to do things. Like you ask to ask it a question, it goes and searches for you, right? That is agentic, right? It's doing a thing for you on behalf of you, right? And so that's agentic, right, in some way. It's an AI agent. If you also use something like, you know, uh cowork or like Claud Code on your desktop, especially now since they the the UI they actually made it really apparent when it's you know spawning sub-agents and doing all these things and has all this access that basically is your access on your machine and everything it can reach from there. Clearly, the thing running on your desktop that can touch all your files and span out dozens of agents that are also running on your desktop and doing all these things, you've that's gotta be a different kind of thing than the thing that lives in the browser and maybe can search on your behalf, you know, on someone else's system where it doesn't touch your compute at all, right? But those are clearly different things, right? And that's just the beginning of a taxonomy, as as the blog is talking about, about these agents. And what I really wanted, right, is I wanted to say, okay, here are all the types, right? I wanted to organize it literally into like here are the families, here's the genera, here's the species, right? Like, I wanted to do that. And I failed. I tried so many ways to like build a taxonomy. And by the way, open invitation to anyone who can convince me they can do better. I want to have this enough where I would prefer to be wrong and have my failure be, you know, advertised to the entire universe that I failed, but this person is like, please solve the problem. I'm more interested in that than being right. Now, what's fascinating talking with Claude, my favorite person to talk to these days, um, with one notable exception, uh, you know, I I I we did come to like some some like ways you can kind of classify agents, like some axes, if you will, right, that you can use to do these things. But ultimately, right, um, it's definitely not a taxonomy, right? It's not like something where you can say this is exactly how it is. The dimensions, um, and I literally just brought up the blog so I could read them to you. I don't have them memorized. Um, just there were six of them, which by the way, you can tell that this was a compromise permission because I would never normally do six of anything. Even number is a terrible list. You always want an odd number. Three, five, seven, nine, like, you know, just terrible to have an even number for a list. But um I got authority, location, trigger, persistence, delegation, and tool reach, right? And the, you know, the in in the blog it literally says, and I will quote, right, if you take clawed code on the desktop as an example, it has access to all your authority from your desktop, it executes in your location, right? Has multiple triggers, meaning you can tell it to do things, or it might do things on its own after you've told it, right? It can be resumable and persistent if you let it be. I have a clawed code session running right now. Um, and you can, it delegates, right? It has its own internal delegation model to its subagents, and it has a lot of tool access, cross-domain tool access, even, right? So that gives it a lot of different security surfaces to think about, right? And then if you take those things and try to apply it to the browser, you'll obviously come up with very different results, right? So that was the best I could come up with at that point. It still gives me, I've already used it, by the way, in conversation with people. I mean, it still gives me a better result than when I was just trying to say, like, they're all different, right? Like I actually having some sort of dimensions to use has made the conversations more lubricated, right? And like, you know, gotten people to think the work way. Um, but it was all just really about this problem that I observed with the way the dialogue is happening.
SPEAKER_03I'm almost compelled to take up an act, but the thing is I know that you're a gentle, Brad, and if you can't come up with the taxonomy, I I don't know what way am I I I would have activated your tax.
SPEAKER_00I I I I I too have studied that model by friends.
On Behalf Of Versus Benefit Of
SPEAKER_02No, it's uh the you meant I don't know if you dug into uh the hybrid agent part of it using some like if no one's familiar with it, using someone's delegated access one moment, its own identity the next. As like the hardest one to deal with. What where are you actually seeing that? Is it just in Claude? No, no, no, no, no.
SPEAKER_00So um so it's it's sort of interesting to me, right? Like the I'm using like Claude and Gemini and all these as examples because these are the ones that everyone knows, right? Like everyone has heard of that. But that's really not where a lot of the conversations I'm having are centered right now. Right now, most of it is actually about how organizations are trying to build agents that are very specific in kind and purpose, right? So they're trying to build things that are for them, by them. And it might use a model from one of those frontier providers as the LLM, um, but it will do a lot of different things. The the harness that they build, right? Because because again, there's another misconception, right? People say AI agents and they're really focused on the AI part, right? The LLM. That's honestly not the interesting part to me. The more interesting part to me is the harness and what you do with the LLM through that harness, what you allow it to do and what you allow it to have. And that all comes the an LLM, like it's inert until you give it something to do, right? Um, when you watch something like building a response for you, everyone thinks, oh, the LLM is thinking. No. No, no, no, no, no. The LLM is generating responses to a harness that is feeding back feedback, feeding back to it from its own generations, right? And by the way, this can also slosh around, right? One of the things that's really interesting, and I will get to your hybrid question, I swear, um, is when you have a mixture of models in some of these agents, right, where potentially you'll use a frontier model for deep planning tasks, but then that will go through a harness to many small models, right, that are potentially self-hosted or hosted in something like Bedrock and AWS or whatever it might be, right? Whatever your cloud of choice is. Um, and that is where then some tactical stuff gets done, and then that feedback is given back to the larger model and sloshes back and forth. But again, the interesting part of that sloshing is the shore in between, the harness, right, that's making that happen back and forth. The reason I say all of that to answer the hybrid question is that the hybrid agent is actually the norm in those circumstances. Right? Because unlike like if you think about like a clawed code type of scenario, the hybrid nature of it seems interesting because it's an odd use case when it's swapping between like an on behalf of versus a for-year benefit situation. Right? In these agents that are being built by these organizations to be very particular in task, it's very normal for them to be doing that. And in fact, it's very normal for them to run as what I would actually call a true agent, and of course everyone who knows I'm a philosopher is gonna say, but no true Scotsman's a fallacy. Yes, I understand. It is a fallacy on purpose in this case. Um the point being though that these agents when I say they're true agents, what I mean is that like they're kind of like a travel agent, like once was, right? One of my favorite analogies right now is I tell people if you have an agent, right? A travel agent, you might give them the capability to do some things on your behalf, but they don't travel with your passport. They don't literally pretend to be you, right? The other thing to think about, you call a call center and that call center agent, right?
SPEAKER_01Words matter.
SPEAKER_00That call center agent you call them why? Well, if you could go online and do what they could do to your account, you wouldn't need to call them. You call them because they actually have privileges that you don't have that you can't have. And that access is not used on behalf of, because that implies you have the access to grant, you don't, right? It's used the model I think of here is for the benefit of, which is not a thing that anyone talks about. Um I keep trying to make it a thing. Um, but like literally, they are wielding power in systems that you don't actually have. And we can now go back to the AI agents and say, all right, well, what does hybrid even mean? Because maybe I'm talking to an agent that lives in bedrock that does this sort of sloshing of things back and forth, and it talked to me for a minute, and it wielded some of my ability to go get certain data that I asked it to go get to put it into the mix on behalf of me. But then it went and did a lot of things on its own, completely with its own authority, right? Here's the hybrid part that you were talking about, right? So it has it switches to its own authority.
SPEAKER_06Right.
SPEAKER_00Then there's this third potential use case that we could keep going, by the way. I could build out like 20 of these, but like the third general class is for the benefit of. It may assume power that neither you nor normally it would have, maybe even calling on a second agent. Ooh, fancy, but it's true. I've already seen this in the real world. Um, where then that is using for the benefit of that task some power that neither you nor that agent have, right? To do something in the system that it needs to happen. One agent calls another agent to make that agent do a thing for it, just like you call the agent in the call center to make it do something for you. Or it, the person. The pronouns get weird in these analogies.
SPEAKER_02Uh it's getting deep like uh like that game where you can make a life of your life within a life and you can keep making a life within a life.
SPEAKER_00And now you know why I called it 42 notions, right? Hitchhiker's Guide to the Galaxy, ultimate, ultimate recursion, um, the infinite improbability drive is the only way that we're gonna get through uh traveling this. For those of you who know, you know, and you can you can you can laugh. But um hopefully that wasn't too much, Cam. I talked a lot there.
SPEAKER_02No, I I think that was fascinating. I mean, is it you say nobody really talks about it? Is there a reason? Is it that people aren't really using it or don't know how to use it?
SPEAKER_00Or well when I when I say nobody talks about like the for the benefit of i i it's it they talk about it all the time, right? Just like they talk about different types of AI agents all the time and they don't distinguish what they are. My point is that like people are not classifying this notion of for the benefit of this agent like the agent in the call center that does something with authority you'll never have, right? And they and even worse than that, they'll miscategorize that as on behalf of. Because they're like, well, I told it to do the thing, so it's doing it on behalf of no, no, no, no, no, no, no. The behalf part of it was always I break off, and like you know, I always think of these in like OAuth and OIDC terms, right? Like I break off some little piece of my authorization and I hand it as a token to a process, an agent in this case, and it goes and does the thing, right? And that's on behalf of, right? And you know, you could do it other ways than OAuth and OIDC, but like that's my my mental model uses that. Um this is completely different. You do not have the authority to give to them, right? You it is not your authority that it wields, right? It is authority that is completely divorced from it and brings us all the way back to the first thing I think about secrets. Because ultimately, what does that mean? It means that it has to take some authority from some place um that's either been you know inculcated into the actual structure of the agent, bad, bad, bad, um, but hopefully been put into some system that will temporarily grant it, right? And by the way, just like that call center agent might say to you, can you please um confirm your home address for me? Everyone knows that phrase, right? Why do you think that happens, right? For people who don't know, that happens because they are about to do something to affect your account with authority you don't have, but the system asks them for data that is you giving it to them to confirm that they are actually working with you, right? And that's why the data is sometimes different. Can you confirm um the you know your your home social? Can you confirm your social? That that's the bad one if they ask you that. That's that's a badly designed system. But you're not wrong, Cam. That does happen. People ask for that. But that's all you cooperating with that agent to unlock authority that neither of you can wield all the time, right? So at least it is a temporary token, essentially, of authority, right? So even if it's done with a social security number, which is terrible, they shouldn't do. At least they tried to keep it scoped in time, right?
SPEAKER_02No, it's
Nerd Break: Cards And Spider Man
SPEAKER_02fascinating. Gabe, you got anything on any of that? I'm not following that.
SPEAKER_04Get out of here. Trap card number two. I mean, yeah, Sandra wrote it. I mean trap card number two.
SPEAKER_03If not following card two, I try. I try.
SPEAKER_00So Magic the Gathering just came out with a whole Marvel set of cards. And since people know my predilections, um, a house guest we had recently was very kind. They work at a gaming shop, and they actually give to speaking of trap cards, they they got me a bunch of the cards for uh for the magic set. Of course, you know, good old uh Modoc here, who I always love. And then, of course, very timely. The next one here is uh, you know, Doom, who we're about to see a lot of. But uh you want to talk about trap cards. There, there's two good trap cards there for you. But modoc and doom. Those are two cards you don't want to try to follow. Yeah. Yeah, not at all.
SPEAKER_03Hey, related, unrelated, that new Spider-Man movie's coming out. What's what's what what what's your uh what are you doing?
SPEAKER_00I am seeing it twice already. I've got two um two viewings uh down uh so I'll see it Sunday and Monday. Okay. Um I'm particularly excited for my Monday viewing because um one of my best friends from college and his um almost adult son, which is just a psychotic thing to say out loud, um, they'll be traveling, they live in Virginia, but they'll be traveling through the area. Um they were always planning to stop here in New Jersey and like spend the night with us. Um and but that that evening, um, when they arrive, we're gonna go see Spider-Man together. And he's like his he's not as big a nerd as his son. Um so actually him, me and his son are gonna sit next to each other and we're gonna let him get on his phone. Um we're we're gonna we're gonna nerd out the whole time. So uh that's uh looking forward to the second viewing more than the first already, you know.
SPEAKER_02That takes away my uh my question. One of my questions is what's the nerdiest thing about you? And I think we already have it.
SPEAKER_03There's no one answer to that question. Nerdy, nerdy activated yet another.
SPEAKER_00Yeah, I mean, nerdy, nerdy. The EST is a hard one, Cam. There's there's a lot of I'm standing in a room with about 13,000 comic books right now, so that that's that's one that's one level of nerd we could talk about.
SPEAKER_02But uh Okay, well, since I don't know if we've ever asked you this because I I I love Marvel. I think I mean I don't think there's anything greater in cinema than when Captain America got Thor's hammer um in theaters. That was epic. Um Yes.
SPEAKER_00I will I don't know if I'll agree with you about ever in cinema, but yes, that was epic, no doubt.
SPEAKER_02Okay, fair. Fair. Um what is what is your favorite like Marvel character of all time?
SPEAKER_01Oh, so pick your favorite child. That's that's that's the question, Cam. Pick the other one. So so I mean Wow, that's hard.
SPEAKER_03Every parent tells, by the way.
SPEAKER_00So you you you pared it down to Marvel, so so that that's one helpful thing, right? I mean, if I had to pick a favorite, and and I'll tell you why I tell you to say that.
SPEAKER_02Let me let me rephrase it. What's your favorite movie that was recreated of your favorite Marvel characters?
SPEAKER_00Oh well, that makes it so much easier. Okay. So on my so my my the character I was gonna say was gonna be Deadpool. Because Deadpool and I just like there's so many notes that it hit like between us, like mostly in fantasy of the comics, but that movie premiered on my birthday. And um, so I actually got to go with a bunch of my friends. It was my birthday party essentially, and I'll tell you, Cam, I've never been more nervous about seeing a movie because I I just I love the character so much, and I was so nervous about like how it would be depicted. And before I tell you my reaction, I'll tell you this. Do you know how that movie got made? Do we have 90 more seconds for me to tell that story?
SPEAKER_01Sure. So the short, short, short version.
SPEAKER_04Ryan Reynolds is also a fan of the character.
SPEAKER_00He's playing all sorts of things, and he gets an opportunity to come play Deadpool in the Wolverine Origins movie, which all nerds have just like taken a short pause when that movie gets mentioned mentioned, like like move into silence because ooh. Um and the version of him in of Deadpool in that movie is terrible. But Ryan Reynolds is a schmuck, so he doesn't have any power. But after the movie, he's like, hey, listen, it would be so cinematic to make a Deadpool movie, blah blah blah. And basically the studios were like, I'm sorry, who are you?
SPEAKER_05Yeah.
SPEAKER_00So he builds a bit more of a career. Says, Hey, I'd really love to do this Deadpool thing. It's like, Ryan, you've had some success. Now they know his name. But you know, go go go back to the corner. We'll tell you what roles to take. Ryan waits. And then some of the comic book stuff builds up, he's got more juice. And basically he goes to the studio and says, I want to make this movie. And they're like, fine, go make some test footage. And for those of you who don't know, it's basically like a preview, right, um, that you make for the studio. Not for the the world, but for the studio to prove to them this would be cool. Now, for those of you who saw the Deadpool movie, if you remember the part where he drops off the highway, lands in the car, and starts beat the crap at all the bad guys with music playing, and it's all like uh time to the music, and it's just like encapsulates so much of what the film's energy was. That was what the test footage was.
SPEAKER_01So he goes in, right, shows it to them, and they go then.
SPEAKER_00somehow that footage leaked to the internet and and and somehow it just was timed to when the contract said that if they didn't take the project Ryan would become the owner and executive producer of of material. It's almost planned. And then somehow millions of nerds like me went give me this movie. Take my money now. Like where is it? And they had to crawl back to him, and the result was the movie we got. Which was basically created by fans, for fans, and it I mean to to this day I have not had a more fun experience in a comic book movie ever because it was just it it was just just perfectly made for a Deadpool fan. It hit all the right notes. Now there's some Deadpool fan out there going, well, actually, you know what? You know what? If you're doing that right now, question your life choices. Like, have more fun. Like, I know I yeah, I know the T guy was not in the movie. Not even gonna say the whole name, T Ray, but like I know there was all these things that were wrong. It wasn't the Joe Kelly version of Deadpool, right? Talking to all the Deadpool nerds who are screaming at me. Um but oh my god, they got so many things right. More things right than I ever imagined they would. Way longer answer than you probably expected, Cam, but there you go. That's that is my answer.
SPEAKER_02That's a great answer. You can tell the passion, man. I love that.
SPEAKER_00Yeah.
unknownYeah.
SPEAKER_02I don't think I knew that about that either.
SPEAKER_00A lot of people don't. Yeah, it's sort of inside of baseball.
SPEAKER_02That's really cool.
Basics To Bet On And Closing
SPEAKER_02Um, before we let you go, uh one thing our listeners should one thing you want to leave them with about everything we've talked about today, backup exposure, age and identity, I don't know, resiliency, fifty percent reduction in cost, and Deadpool, Deadpool versus or Deadpool and Wolverine, which is a great movie.
SPEAKER_00They they did a good job with that, actually. They they did. I I actually agree. So I if if there's one thing, it's probably the notion of just like back to the basics, right? Because in the face of all this AI stuff, I think a lot of people are just panicking and grasping for I mean, frankly, a lot of stuff they probably don't need right now, because they're because like there's so much stuff that's claiming to solve all these problems, and the problems are so ill-defined that I I we're not there yet, right? I just don't think we're there yet. But if you can convince your powers that be that investing in resilience, investing in good identity management, and investing in secrets management, especially, right now, and that that's the way to protect yourself from all this AI stuff, that will that will pay dividends. That's that's my belief.
SPEAKER_02Strong. Um, where where are you gonna be in the next couple months speaking and stuff? Anywhere that people can go see you?
SPEAKER_00Um, so there's a partner webinar with our friends at Wasabi, uh a Moyota, I should say Moyota and Wasabi webinar that's coming up um for sure. Um I'll be going to KubeCon. Um I don't know if we've confirmed a speaking slot there, um, but um if you can't tell, I'll be talking. Um, because that's just what I do. Um so like you know, that that will definitely happen. Um and a few more things, like I don't I don't I don't have it memorized. I have to look at my calendar. I didn't know you were gonna ask me. Um but uh but those are two things I could say off the top of my head um that I will definitely be at.
SPEAKER_02Perfect. I I'll be uh I'll get some more info too from you and then um I can always share it in the show notes along with uh two blogs that we referenced today. Make sure that 42 options one gets into the uh show notes for sure. Yes, agreed. Gabe, you got anything before we uh end this thing?
SPEAKER_03Some of my favorite people having some of my favorite conversations. Part of me is just sitting back just smiling through it through it all. It's uh it's always a pleasure. It's always a pleasure to catch up with you both, quite frankly. It's uh it's been too long since we just sat down and stopped the day today. Yeah, no, I think language I know. That's the only reason we spun up a whole other like series on the platform was so that I could be I could be a little bit more free in my language, but you know, tuning in for the good stuff today.
SPEAKER_00So here we uh but yeah, no, that's that's it in advance so I can play along.
SPEAKER_02Well I appreciate you both for being here, and um we'll see you guys on the next one.
SPEAKER_00Thank you. Thank you.