1
00:00:14,280 --> 00:00:18,240
Hello, this is Eva, and you're 
listening to the In Between Tech

2
00:00:18,240 --> 00:00:21,120
and Trust podcast. 
In this week's episode, we dive 

3
00:00:21,120 --> 00:00:25,160
deep into all aspects around 
threat intelligence. 

4
00:00:25,280 --> 00:00:29,720
And for that important topic, I 
have Asaf kidneys with me in 

5
00:00:29,720 --> 00:00:33,200
conversation. 
And Asaf comes with over 10 

6
00:00:33,200 --> 00:00:35,840
years of experience in that 
industry. 

7
00:00:35,840 --> 00:00:39,160
He has worked for some of the 
major tech companies, for 

8
00:00:39,160 --> 00:00:43,800
example, Meta or LinkedIn. 
And currently he's building his 

9
00:00:43,800 --> 00:00:47,880
own platform because he's 
convinced that data provenance 

10
00:00:47,880 --> 00:00:52,600
is one of the most important 
aspects to provide and help us 

11
00:00:52,600 --> 00:00:55,800
engaging with the future. 
And so together we look at the 

12
00:00:55,800 --> 00:01:00,000
intersection of technology and 
trust from a threat Intel 

13
00:01:00,000 --> 00:01:03,560
perspective and also from a 
defense perspective. 

14
00:01:03,640 --> 00:01:08,160
We talk a lot about what it 
actually means to avoid threats 

15
00:01:08,160 --> 00:01:12,720
and also counter them, of how 
the operations behind it really 

16
00:01:12,720 --> 00:01:16,800
work and what in times of 
becomes most important To then 

17
00:01:16,800 --> 00:01:21,600
also dive deep into the actual 
happenings of attacks and what 

18
00:01:21,600 --> 00:01:24,600
happens behind the scenes. 
And also how to, you know, 

19
00:01:24,600 --> 00:01:26,800
leverage the knowledge behind 
it. 

20
00:01:26,920 --> 00:01:32,520
And we do discuss of why 
understanding your product and 

21
00:01:32,520 --> 00:01:37,680
your platform is the most 
important aspect for you to 

22
00:01:37,760 --> 00:01:42,040
enable security and also to 
avoid threats going forward. 

23
00:01:44,520 --> 00:01:48,440
Welcome Asaf and happy to have 
you on the In Between Tech and 

24
00:01:48,440 --> 00:01:49,600
Trust podcast all. 
Right. 

25
00:01:49,800 --> 00:01:52,120
Thank you so much for having me.
I really appreciate it. 

26
00:01:52,200 --> 00:01:55,240
For the listeners that don't 
know you, do you briefly just 

27
00:01:55,240 --> 00:01:58,680
want to say a bit about your 
background and also with what 

28
00:01:58,680 --> 00:02:01,480
perspective on tech and trust 
you come into the conversation? 

29
00:02:01,480 --> 00:02:03,880
Sure. 
So my name is Asaf Kipnis. 

30
00:02:03,920 --> 00:02:10,960
I've been in, let's call it the 
tech space for over 12 years 

31
00:02:10,960 --> 00:02:12,960
now. 
I've been in information 

32
00:02:12,960 --> 00:02:17,440
security and threat intelligence
integrity spanning LinkedIn, 

33
00:02:17,440 --> 00:02:20,960
Google, Meta 11 Labs for a 
little while and I've been 

34
00:02:20,960 --> 00:02:24,120
mostly working on the 
investigation space and the 

35
00:02:24,120 --> 00:02:29,560
threat intelligence space within
Infosec and Integrity, trust and

36
00:02:29,560 --> 00:02:32,240
safety. 
What were underlying challenges 

37
00:02:32,240 --> 00:02:35,160
that you keep identifying over 
and over again? 

38
00:02:35,160 --> 00:02:38,400
And it doesn't need to be 
dependent on the tech company. 

39
00:02:38,400 --> 00:02:41,360
On the contrary, is there 
anything that was particularly 

40
00:02:41,360 --> 00:02:44,320
visible for you in the tech 
space and also in the background

41
00:02:44,320 --> 00:02:46,760
that you worked out? 
I think the main thing that I've

42
00:02:46,760 --> 00:02:51,080
noticed throughout my career, 
and This is why I decided to go 

43
00:02:51,080 --> 00:02:55,640
build something on my own, is 
there's a big focus in, and this

44
00:02:55,640 --> 00:02:59,440
is more in this security and 
safety and threat Intel space. 

45
00:02:59,440 --> 00:03:03,120
There's a big focus on dealing 
with the problem that's right in

46
00:03:03,120 --> 00:03:06,440
front of our faces and dealing 
with the manifestation of that 

47
00:03:06,440 --> 00:03:10,360
problem. 
And what that causes is that we 

48
00:03:10,400 --> 00:03:13,160
end up dealing with the same 
problems over and over and over 

49
00:03:13,160 --> 00:03:15,520
again. 
And you can see that the 

50
00:03:15,520 --> 00:03:20,360
industry is very much on a 
reactive kind of work. 

51
00:03:20,680 --> 00:03:24,400
And a lot of the work that it's 
done is, is not learning from 

52
00:03:24,400 --> 00:03:28,040
what we what we identified. 
There's a big lack of kind of 

53
00:03:28,040 --> 00:03:31,960
gap and learning as we 
continuously fight fires to find

54
00:03:31,960 --> 00:03:35,000
the next shiny thing that is in 
front of us. 

55
00:03:35,080 --> 00:03:38,600
And why do you think is that so?
I think there's multiple reasons

56
00:03:38,600 --> 00:03:40,800
for that. 
I think the most kind of like 

57
00:03:41,160 --> 00:03:46,160
structural reason is that it's 
very hard to measure what you 

58
00:03:46,160 --> 00:03:49,280
didn't, what didn't happen. 
Riding in on a White Horse and 

59
00:03:49,280 --> 00:03:52,120
saving everybody from a fire 
that looks really good, that 

60
00:03:52,120 --> 00:03:55,680
measures really well. 
You can say we took down X 

61
00:03:55,680 --> 00:03:59,000
amount of actors or we stopped 
an attack. 

62
00:03:59,000 --> 00:04:02,720
And so if you want to keep your 
team working and viable in the 

63
00:04:02,720 --> 00:04:04,240
company, you need to show 
something. 

64
00:04:04,240 --> 00:04:10,480
The other issue there is that I 
think the learning piece falls 

65
00:04:10,480 --> 00:04:13,360
between teams. 
Usually you'll have the team 

66
00:04:13,360 --> 00:04:16,000
that's actually doing the 
prevention or the detection. 

67
00:04:16,000 --> 00:04:18,600
You'll have the teams that are 
doing the analysis and the 

68
00:04:18,600 --> 00:04:24,360
finding and it's, it's very hard
to connect between those two 

69
00:04:24,360 --> 00:04:25,880
teams. 
So a thing I've been thinking 

70
00:04:25,880 --> 00:04:30,000
about is how threat intelligence
and Intel in general is not 

71
00:04:30,120 --> 00:04:33,680
incorporated into those spaces 
into safety and, and, and 

72
00:04:33,880 --> 00:04:36,880
security. 
It's more kind of like adjacent 

73
00:04:36,960 --> 00:04:39,480
and feeds the information when 
needed. 

74
00:04:39,560 --> 00:04:43,480
But there isn't a clear 
structure that controls the kind

75
00:04:43,480 --> 00:04:47,360
of inflow or the influx of 
information from threat 

76
00:04:47,360 --> 00:04:49,760
intelligence into actual 
detection. 

77
00:04:49,800 --> 00:04:52,840
Over the years, can you to 
describe a bit of how threat 

78
00:04:52,840 --> 00:04:57,960
intelligence has potentially 
also changed and how systems 

79
00:04:57,960 --> 00:05:02,400
have also evolved over time to 
acknowledge potential blind 

80
00:05:02,400 --> 00:05:04,640
spots that they have or might 
not have? 

81
00:05:04,640 --> 00:05:09,800
So I think the way threat 
intelligence has changed is in a

82
00:05:09,800 --> 00:05:12,920
good way and a bad way. 
So in a good way, I think threat

83
00:05:12,920 --> 00:05:17,400
intelligence have become more 
front and center when when we're

84
00:05:17,400 --> 00:05:21,040
working on complex actors and we
want to try to understand how 

85
00:05:21,040 --> 00:05:24,520
actors are operating. 
So threat intelligence is taking

86
00:05:24,520 --> 00:05:27,280
more of a kind of front of the 
house area. 

87
00:05:27,280 --> 00:05:31,800
On the flip side of of that, 
some companies have are using 

88
00:05:31,800 --> 00:05:35,120
threat intelligence just to 
identify new upcoming fires and 

89
00:05:35,120 --> 00:05:38,040
kind of and threat intelligence 
just stays in the point where 

90
00:05:38,160 --> 00:05:42,040
they're not telling you how to 
prevent. 

91
00:05:42,360 --> 00:05:45,240
They are, they're, they're 
focused on telling you, hey, 

92
00:05:45,240 --> 00:05:49,520
what's coming up right now that 
you need to block right now. 

93
00:05:49,520 --> 00:05:54,880
And they're not very well 
empowered to actually prevent 

94
00:05:54,920 --> 00:05:58,080
attacks or prevent abuse. 
And, and we're seeing that is in

95
00:05:58,080 --> 00:06:02,640
the scam space that it's just 
become completely rampant and 

96
00:06:02,640 --> 00:06:06,560
super complex. 
And there is no, I haven't seen 

97
00:06:06,560 --> 00:06:10,240
any, any good structured way of 
dealing with it at scale. 

98
00:06:10,400 --> 00:06:13,640
Your second question was how did
teams evolve? 

99
00:06:13,640 --> 00:06:17,440
So some teams have evolved into 
connecting threat intelligence 

100
00:06:17,440 --> 00:06:22,320
with detection and really doing 
their best to take all findings 

101
00:06:22,320 --> 00:06:25,360
and tell, take new things that 
are found and putting them into 

102
00:06:25,520 --> 00:06:27,840
into detection, putting them 
into the understanding of the 

103
00:06:27,840 --> 00:06:30,000
attackers. 
On the other hand, a lot of 

104
00:06:30,000 --> 00:06:36,160
teams have evolved into kind of 
working with how do we make the 

105
00:06:36,160 --> 00:06:39,000
metrics look really good. 
So and it's kind of like two 

106
00:06:39,000 --> 00:06:42,240
sides of the spectrum. 
There's a how do we work this? 

107
00:06:42,240 --> 00:06:44,640
And those are those are the more
complex teams of how do we 

108
00:06:44,640 --> 00:06:47,280
actually identify what is, what 
is actually going on. 

109
00:06:47,280 --> 00:06:50,480
And on the other side, you have 
the teams that evolved into, 

110
00:06:50,600 --> 00:06:52,880
well, what can I measure? 
Let's just do that. 

111
00:06:52,960 --> 00:06:56,120
And that's because that's going 
to give us more funding or make 

112
00:06:56,120 --> 00:06:58,840
us look better. 
So imagine you would be head of 

113
00:06:59,160 --> 00:07:01,360
the threat intelligence again at
one of the companies that you 

114
00:07:01,360 --> 00:07:07,360
work for and you have you've 
identified either an upcoming 

115
00:07:07,360 --> 00:07:10,280
someone or one that might be on 
the horizon. 

116
00:07:10,360 --> 00:07:11,880
How? 
What happens? 

117
00:07:12,000 --> 00:07:13,680
What do you do? 
So from a threatened 

118
00:07:13,680 --> 00:07:16,200
intelligence perspective, we 
want to understand what the 

119
00:07:16,200 --> 00:07:18,360
attackers are doing. 
They have been doing other 

120
00:07:18,360 --> 00:07:21,000
places. 
So for example, you take 

121
00:07:21,000 --> 00:07:24,160
investigations that were done in
other companies that are 

122
00:07:24,160 --> 00:07:26,600
similar. 
You take reports from the FBI, 

123
00:07:26,600 --> 00:07:29,760
reports from CISA, report from 
anything out there that can give

124
00:07:29,760 --> 00:07:31,760
you information which threat 
intelligence do that, 

125
00:07:31,760 --> 00:07:35,680
Intelligence teams do that. 
And then you start also you want

126
00:07:35,680 --> 00:07:40,520
to understand what you are 
vulnerable to what, what attacks

127
00:07:40,520 --> 00:07:43,760
have happened on your platform 
in the recent past, in the 

128
00:07:44,000 --> 00:07:46,840
further past that you did not 
identify. 

129
00:07:47,000 --> 00:07:50,680
You can identify now hopefully, 
but what did you not identify in

130
00:07:50,680 --> 00:07:53,280
the past? 
And you synthesize this 

131
00:07:53,280 --> 00:07:57,800
information to basically create 
a threat after journey. 

132
00:07:57,960 --> 00:08:01,720
So we want to understand whether
it's on our platform or not on 

133
00:08:01,720 --> 00:08:04,280
our platform. 
So there's the end of the chain,

134
00:08:04,280 --> 00:08:07,320
which is what actually we saw 
and what happened. 

135
00:08:07,320 --> 00:08:10,240
Where's the harm? 
But a good threat intelligence 

136
00:08:10,240 --> 00:08:15,240
team or a good team will go and 
pick up all the pieces of how 

137
00:08:15,280 --> 00:08:17,920
this happened along along the 
way. 

138
00:08:18,200 --> 00:08:23,360
And the Holy Grail there is not 
how do we stop the attack is how

139
00:08:23,360 --> 00:08:27,200
do we make this exhausting and 
expensive for the attacker to 

140
00:08:27,200 --> 00:08:29,440
get to the point of their 
attacking. 

141
00:08:29,520 --> 00:08:32,520
At Facebook, one of the teams, 
they had this saying it was 

142
00:08:32,520 --> 00:08:35,760
like, get off my platform and 
get off my platform says exactly

143
00:08:35,760 --> 00:08:38,000
that. 
I just want to make it so you 

144
00:08:38,159 --> 00:08:41,960
just think that MAG platform is 
the worst place for you to be 

145
00:08:42,159 --> 00:08:45,920
and you'll go somewhere else. 
And breaking down your path 

146
00:08:45,920 --> 00:08:49,800
towards the attack is where that
becomes more difficult because, 

147
00:08:49,880 --> 00:08:52,760
and the really, really good 
teams that do that, they focus 

148
00:08:52,760 --> 00:08:55,920
on the threat actor journeys and
how to circumvent them along the

149
00:08:55,920 --> 00:08:58,240
way. 
Was there an incident or a 

150
00:08:58,240 --> 00:09:02,480
threat in your career that was 
quite memorable that you have or

151
00:09:02,600 --> 00:09:07,280
have either lived through or 
prevented, that you could say of

152
00:09:07,280 --> 00:09:09,040
why it was so memorable? 
Yeah. 

153
00:09:09,040 --> 00:09:13,400
So right before the 2020 
elections, we were looking into 

154
00:09:13,400 --> 00:09:18,320
specific actor group or a set of
actor groups that in the past 

155
00:09:18,320 --> 00:09:22,920
were taken down by the company 
was was very clear that this is 

156
00:09:22,920 --> 00:09:24,800
we, we need this not to happen 
again. 

157
00:09:24,800 --> 00:09:27,120
This happened in 2016. 
We need this not to happen again

158
00:09:27,120 --> 00:09:30,320
in 2020. 
So I received the the structure 

159
00:09:30,320 --> 00:09:33,520
and the resources to actually 
deal with that at scale, meaning

160
00:09:34,240 --> 00:09:37,560
I could investigate it with the 
team that I had, but we also had

161
00:09:37,640 --> 00:09:41,000
a direct connection to the team 
that was deploying detection and

162
00:09:41,000 --> 00:09:45,720
operations and policy and then 
kind of put it all together. 

163
00:09:45,800 --> 00:09:48,800
That was very successful because
the the intelligence part of the

164
00:09:48,800 --> 00:09:51,360
team was able to identify what 
they're doing, identify how 

165
00:09:51,360 --> 00:09:54,160
they're doing it, and then 
immediately put that into 

166
00:09:54,160 --> 00:09:58,680
policy, into operational flows, 
into prevention and detection. 

167
00:09:58,680 --> 00:10:02,480
And the great thing about it is 
that we literally saw them 

168
00:10:02,480 --> 00:10:05,320
leaving the platform. 
They were talking to each other 

169
00:10:05,320 --> 00:10:07,600
and saying we don't, this 
doesn't work for us anymore. 

170
00:10:07,800 --> 00:10:11,840
We're now in 2026. 
Threat landscape moves faster 

171
00:10:11,840 --> 00:10:13,480
than ever. 
Where do you see the biggest 

172
00:10:13,480 --> 00:10:17,160
cracks in Be it detection, 
attribution, context, 

173
00:10:17,320 --> 00:10:19,600
provenance? 
Choose the field that you want 

174
00:10:19,600 --> 00:10:24,360
to explore with us. 
So the generic answer is AIAI 

175
00:10:24,360 --> 00:10:28,520
makes everything bad and scary. 
It's true that with the advent 

176
00:10:28,520 --> 00:10:33,520
of AI and we're God in the last 
three years, attackers are armed

177
00:10:33,520 --> 00:10:37,440
with more tools that can just 
make them faster and more agile.

178
00:10:37,480 --> 00:10:42,200
But the way I look at it is, 
while yes, this is a kind of 

179
00:10:42,720 --> 00:10:45,760
somewhat of a pivot point that 
attackers are getting faster, 

180
00:10:45,840 --> 00:10:49,400
but I feel attackers have been 
getting ahead of us for the at 

181
00:10:49,400 --> 00:10:52,440
least the last six years, if not
more. 

182
00:10:52,480 --> 00:10:57,480
So they are already far ahead 
because of the way we were. 

183
00:10:57,480 --> 00:11:01,440
Even as defenders, we don't know
our product as well as as 

184
00:11:01,440 --> 00:11:03,720
attackers know our product and 
our landscape. 

185
00:11:03,760 --> 00:11:06,440
And I think kind of the thing 
I've always said is as an 

186
00:11:06,440 --> 00:11:11,720
attacker, I can focus on on a 
target and then learn everything

187
00:11:11,720 --> 00:11:13,400
about that target and just keep 
going. 

188
00:11:13,600 --> 00:11:17,360
As a defender, I need to defend 
everything that's coming across.

189
00:11:17,360 --> 00:11:21,360
So we're already hamstrung. 
So I think we've always been 

190
00:11:21,360 --> 00:11:24,760
like that in trust and safety 
and in security that we're kind 

191
00:11:24,760 --> 00:11:28,960
of like plugging holes and 
trying to get ahead of attacks 

192
00:11:29,400 --> 00:11:31,680
now. 
So the attackers with AII able 

193
00:11:31,680 --> 00:11:33,960
to do 2 things. 
One, they're able to be a lot 

194
00:11:33,960 --> 00:11:37,360
faster. 
And two, they are able to 

195
00:11:37,360 --> 00:11:39,960
enhance their knowledge and 
enhance their tactics by 

196
00:11:40,000 --> 00:11:42,960
learning faster. 
It's not just automating, it's 

197
00:11:42,960 --> 00:11:45,520
just they can automate and then 
they can learn from it really 

198
00:11:45,520 --> 00:11:47,440
quickly and then they can 
iterate. 

199
00:11:47,480 --> 00:11:51,440
And we get to a point that where
we used to worry about the 

200
00:11:51,440 --> 00:11:55,680
complex actors and the much less
complex actors, but not and then

201
00:11:55,680 --> 00:11:58,240
we would say, OK, we would just 
make it very difficult for the 

202
00:11:58,240 --> 00:12:00,880
non complex actors and then 
we'll deal with the more complex

203
00:12:00,880 --> 00:12:03,080
actors. 
But now a lot of the less 

204
00:12:03,080 --> 00:12:07,120
complex actors have the ability 
to become a lot more agile, a 

205
00:12:07,120 --> 00:12:12,280
lot more complex and challenge 
us a lot more, while we are kind

206
00:12:12,280 --> 00:12:16,040
of in the same space of we need 
to defend against everything. 

207
00:12:16,120 --> 00:12:20,160
And now you're part of a podcast
that looks at the intersection 

208
00:12:20,160 --> 00:12:22,960
of tech and trust. 
But if I listen to you, I might 

209
00:12:22,960 --> 00:12:26,520
assume that trust in tech is 
something that doesn't come 

210
00:12:26,520 --> 00:12:31,400
naturally in the sense that you 
necessarily need to 1st think 

211
00:12:31,400 --> 00:12:35,320
about everything that could 
happen before you start trusting

212
00:12:35,320 --> 00:12:39,280
into the ways that things don't 
happen or how is it for you. 

213
00:12:39,440 --> 00:12:43,600
So I think the way I see trust, 
I see it from a practitioner 

214
00:12:43,600 --> 00:12:47,960
perspective, trust is really 
important to me from first of 

215
00:12:47,960 --> 00:12:49,880
like how do the customers trust 
you? 

216
00:12:50,120 --> 00:12:52,760
And then how can I trust the 
data I'm looking at? 

217
00:12:52,760 --> 00:12:57,440
And that the, if we go into the 
trusting the data I'm working 

218
00:12:57,440 --> 00:13:00,560
with, that's really complex 
because as you grow in scale, 

219
00:13:00,680 --> 00:13:04,400
it's much harder to validate 
what you're looking at and say, 

220
00:13:04,720 --> 00:13:07,280
yeah, and this is 100% what's 
happening. 

221
00:13:07,440 --> 00:13:10,160
And then I can, I can make 
assumptions from there. 

222
00:13:10,240 --> 00:13:14,680
The problems that I've seen in 
the industry or in my specific 

223
00:13:14,680 --> 00:13:19,880
work is if I can't trust my 
findings, then it's very hard 

224
00:13:19,880 --> 00:13:24,280
for me to deploy them into 
something that's scaled because 

225
00:13:24,280 --> 00:13:27,080
you can make a small mistake. 
And in a small company it might 

226
00:13:27,080 --> 00:13:30,480
be a small issue. 
But as you scale, you're going 

227
00:13:30,480 --> 00:13:33,600
to have, you're going to come 
across across growth, you're 

228
00:13:33,600 --> 00:13:35,880
going to come across false 
positives, you're going to come 

229
00:13:35,880 --> 00:13:37,840
across, you're going to break 
your network. 

230
00:13:37,840 --> 00:13:42,040
So trusting in what you're 
doing, or at least the data 

231
00:13:42,040 --> 00:13:44,560
you're dealing with, is very, 
very important. 

232
00:13:44,680 --> 00:13:47,960
And you've now said that you're 
working on a business idea 

233
00:13:47,960 --> 00:13:51,600
yourself and that you also look 
into the way of how data 

234
00:13:51,600 --> 00:13:56,080
provenance can be deployed. 
Can you explain to me or also 

235
00:13:56,080 --> 00:14:00,160
the listeners of what data 
provenance like really is and if

236
00:14:00,360 --> 00:14:03,560
it's connected to the way that 
you can trust data? 

237
00:14:03,560 --> 00:14:07,040
So my friend and I now came up 
with an idea we called the our 

238
00:14:07,040 --> 00:14:13,160
company Catalyst Labs. 
The idea behind it is how do we 

239
00:14:13,160 --> 00:14:16,720
help companies not fight the 
same fires over and over and 

240
00:14:16,720 --> 00:14:19,680
over again? 
How do we actually leverage the 

241
00:14:19,680 --> 00:14:22,760
intelligence so it doesn't sit 
on a shelf somewhere? 

242
00:14:22,760 --> 00:14:25,640
Because what I found and what I 
throughout the years, this is a 

243
00:14:25,640 --> 00:14:27,960
systems engineering problem. 
Like I said, you have 

244
00:14:28,160 --> 00:14:30,640
information security on one is 
like a system. 

245
00:14:30,880 --> 00:14:34,480
You have threat intelligence 
that's tangential, but threat 

246
00:14:34,480 --> 00:14:37,320
intelligence is only pulled in 
when it's necessary. 

247
00:14:37,320 --> 00:14:41,360
And even then it's very 
difficult to take tactic 

248
00:14:41,360 --> 00:14:45,440
techniques, procedures and 
actually narrative or prose and 

249
00:14:45,440 --> 00:14:48,800
turn that into something you can
you can deploy. 

250
00:14:48,800 --> 00:14:52,480
So what I created and I'll 
explain the Providence thing is 

251
00:14:52,720 --> 00:14:57,040
a way to take let's say an 
analyst or FBI said threat actor

252
00:14:57,040 --> 00:15:00,720
X does this and then this and 
then that and then and then does

253
00:15:00,720 --> 00:15:03,400
all these actions and this is 
how they X filled it, their 

254
00:15:03,400 --> 00:15:06,000
information. 
How do we turn that into code? 

255
00:15:06,000 --> 00:15:09,720
So my system, instead of 
producing it to a detection 

256
00:15:09,720 --> 00:15:12,720
engineer, that will take hours 
or days or weeks to turn that 

257
00:15:12,720 --> 00:15:15,880
into actual detection. 
We can do that within two 

258
00:15:15,880 --> 00:15:17,840
minutes. 
But the first question that I 

259
00:15:17,840 --> 00:15:21,880
had when I thought about it is 
if I do this with an LLM, if I 

260
00:15:21,880 --> 00:15:25,920
do this with an AI, I don't 
trust it, especially at scale, 

261
00:15:25,920 --> 00:15:29,480
because it can read whatever 
information is on the on the 

262
00:15:29,640 --> 00:15:33,560
document and then it can infer 
something that's not true or it 

263
00:15:33,560 --> 00:15:37,120
can get bias from the document. 
And that's where I came up with 

264
00:15:37,800 --> 00:15:42,040
how do I have data provenance 
that I can actually go to to a 

265
00:15:42,040 --> 00:15:45,520
team like the team I worked at 
at Facebook and say here is 

266
00:15:45,520 --> 00:15:50,240
detection logic. 
But I know 100% that this came 

267
00:15:50,360 --> 00:15:54,080
exactly from the document that 
you provided at the very core of

268
00:15:54,080 --> 00:15:57,520
the product, the extraction 
doesn't happen with the LLM. 

269
00:15:57,520 --> 00:16:01,200
It's a lot more programmatic 
that that provides you the here 

270
00:16:01,200 --> 00:16:04,440
is the rule and and then you 
have full provenance of it came 

271
00:16:04,440 --> 00:16:07,160
from this page of the document 
that you provided me from this 

272
00:16:07,160 --> 00:16:09,280
line. 
It is exactly what it says. 

273
00:16:09,280 --> 00:16:12,000
This is why we turned it into 
this detection logic. 

274
00:16:12,240 --> 00:16:15,080
And that's really critical 
because as I've been looking at 

275
00:16:15,080 --> 00:16:18,360
other companies doing it, 
there's this sense in the 

276
00:16:18,360 --> 00:16:22,360
industry that AI is this like 
magic tool that can do these 

277
00:16:22,360 --> 00:16:26,880
things, can do AI can do a lot, 
but what it can't do because 

278
00:16:26,880 --> 00:16:30,520
it's not built to do that is be 
deterministic. 

279
00:16:30,600 --> 00:16:33,840
So while you can trust it for 
doing one report, maybe 2 

280
00:16:33,840 --> 00:16:37,280
reports, as you start scaling 
you're going to start getting 

281
00:16:37,280 --> 00:16:41,720
very weird information flowing 
your way that will look like 

282
00:16:41,720 --> 00:16:44,120
it's real detection, but it's 
actually going to cause a lot 

283
00:16:44,120 --> 00:16:47,760
more work than anything. 
Why do you think what you what 

284
00:16:47,760 --> 00:16:51,360
you are building is so 
foundational? 

285
00:16:51,640 --> 00:16:53,520
Also, how does it work? 
How can I? 

286
00:16:53,520 --> 00:16:55,640
Yeah, if I use it, what would 
happen? 

287
00:16:55,760 --> 00:16:59,720
OK, So the reason it's 
foundational in my eyes is that 

288
00:16:59,840 --> 00:17:04,440
we've tried to do this forever. 
We've always tried to say how do

289
00:17:04,440 --> 00:17:07,760
we take our intelligence and 
make it so it's not shelf wear. 

290
00:17:07,760 --> 00:17:10,319
So the intelligence is not just 
sitting there or, or for 

291
00:17:10,319 --> 00:17:13,839
example, I would see an attack 
and then I would say, I worked 

292
00:17:13,839 --> 00:17:15,880
on this exact thing three years 
ago. 

293
00:17:16,040 --> 00:17:18,200
I remember this. 
It's the same issue. 

294
00:17:18,200 --> 00:17:19,960
It's just a completely different
actor. 

295
00:17:19,960 --> 00:17:22,720
So this has always been a 
problem. 

296
00:17:22,720 --> 00:17:26,079
And I think the one of the 
things that have changed is 

297
00:17:26,079 --> 00:17:29,200
that, yes, you can start doing 
that more with the help of LLMS 

298
00:17:29,200 --> 00:17:31,800
of turning intelligence into 
actual detection. 

299
00:17:31,800 --> 00:17:34,440
But I think the deeper problem 
is different. 

300
00:17:34,520 --> 00:17:38,880
The deeper problem is that this 
issue falls between teams. 

301
00:17:39,040 --> 00:17:41,560
So that's the big foundational 
problem here. 

302
00:17:41,640 --> 00:17:47,280
That's it's very, very difficult
to have this even at smaller 

303
00:17:47,280 --> 00:17:50,080
scale deployed across teams and 
have it. 

304
00:17:50,160 --> 00:17:52,240
Work. 
And during your design process 

305
00:17:52,240 --> 00:17:55,320
for the platform, what 
trade-offs do you face when you 

306
00:17:55,320 --> 00:18:00,040
need to choose between speed or 
trust, openness and security, 

307
00:18:00,040 --> 00:18:02,120
and usability versus 
verification? 

308
00:18:02,120 --> 00:18:06,280
So right now my biggest trade 
off is speed and currently I'm 

309
00:18:06,280 --> 00:18:09,320
OK with it. 
The speed is not that major, 

310
00:18:09,480 --> 00:18:12,240
major of a difference. 
I would like it to be under a 

311
00:18:12,240 --> 00:18:15,560
minute, but now it's 2 to 6 
minutes depends on the size of 

312
00:18:15,560 --> 00:18:17,720
the document. 
You cannot let go of the 

313
00:18:17,720 --> 00:18:19,880
Providence. 
It must be there. 

314
00:18:19,880 --> 00:18:24,080
So you can always the, the let's
say that the secure engine 

315
00:18:24,080 --> 00:18:27,480
engineer can always say I know 
exactly where this rule came 

316
00:18:27,480 --> 00:18:29,440
from. 
And then it actually provides 

317
00:18:29,440 --> 00:18:33,640
you with an audit trail that you
can say that rule that that did 

318
00:18:33,680 --> 00:18:36,680
XYZ, maybe that rule failed, 
maybe that rule's really 

319
00:18:36,680 --> 00:18:39,480
effective. 
We can actually say that rule 

320
00:18:39,480 --> 00:18:43,600
was created at this point by 
breaking down this type of 

321
00:18:43,600 --> 00:18:47,720
report at that time. 
So the provenance and the trust 

322
00:18:47,720 --> 00:18:50,360
are critical here. 
Much, much more than speed. 

323
00:18:51,760 --> 00:18:56,640
And if we now do you see any 
issue with the new like AI tool 

324
00:18:56,640 --> 00:19:02,400
providers that could potentially
influence the user trust and 

325
00:19:02,400 --> 00:19:05,640
that also you would advise them 
to change? 

326
00:19:05,640 --> 00:19:09,320
Yes. 
So LLMS are non deterministic by

327
00:19:09,320 --> 00:19:12,360
design. 
If you tell it never do a thing,

328
00:19:12,600 --> 00:19:15,360
you are telling it be 
deterministic, always find this 

329
00:19:15,360 --> 00:19:18,200
thing and never do it, and 
that's you're going against the 

330
00:19:18,200 --> 00:19:21,600
design of the actual idea or the
actual system. 

331
00:19:21,680 --> 00:19:24,640
What I have been seeing with AI 
is a couple of things. 

332
00:19:24,640 --> 00:19:29,320
There's a mad dash to implement 
AI into absolutely everything, 

333
00:19:29,480 --> 00:19:32,880
and some places that's great. 
Some places don't really need 

334
00:19:32,880 --> 00:19:37,160
it, but that's not the issue. 
The issue is that there is, I'm 

335
00:19:37,160 --> 00:19:40,480
noticing this around leadership 
mostly of AI can just do 

336
00:19:40,480 --> 00:19:42,320
everything. 
We'll just need to implement it 

337
00:19:42,320 --> 00:19:44,480
and it will solve everything and
it will automate. 

338
00:19:44,520 --> 00:19:48,640
And then this, there's this push
of you either implement AI or 

339
00:19:48,920 --> 00:19:51,920
we're not going to talk to you. 
And then I am seeing new 

340
00:19:51,920 --> 00:19:56,440
companies that are acting in 
kind of the same way machine 

341
00:19:56,440 --> 00:19:58,520
learning works is this is a 
black box. 

342
00:19:58,720 --> 00:20:01,800
You put your information, this 
spits out the right things and 

343
00:20:01,800 --> 00:20:04,720
trust it. 
And we are putting a lot of 

344
00:20:04,720 --> 00:20:09,080
trust into prompt engineering 
into. 

345
00:20:09,760 --> 00:20:13,320
Specific models and saying, 
yeah, we'll put this here and it

346
00:20:13,320 --> 00:20:15,960
will just magically create what 
I wanted to create. 

347
00:20:15,960 --> 00:20:20,440
And I think there's a big chasm 
opening between providers of AI 

348
00:20:20,440 --> 00:20:22,800
solutions and actual 
practitioners. 

349
00:20:22,840 --> 00:20:26,760
Have you ever worked in defense 
in some sort of defense tech and

350
00:20:27,040 --> 00:20:31,520
threat intelligence on a defense
and regional kind of context? 

351
00:20:31,520 --> 00:20:35,240
I have but not in tech. 
So I was in the military and I 

352
00:20:35,240 --> 00:20:39,320
was doing defense, border 
defense, and interestingly 

353
00:20:39,320 --> 00:20:41,520
enough, it is exactly the same 
concepts. 

354
00:20:41,520 --> 00:20:45,440
That's what I wanted to get at 
because there's so much strategy

355
00:20:45,520 --> 00:20:48,360
in the way that threat 
intelligence needs to be 

356
00:20:48,360 --> 00:20:52,400
designed and that could be 
translated either from a defence

357
00:20:52,400 --> 00:20:53,880
tech. 
And I do want to ask that 

358
00:20:53,880 --> 00:20:56,720
because we're currently in quite
tense times. 

359
00:20:56,720 --> 00:20:59,440
Also from a regional 
perspective, I'm not getting 

360
00:20:59,440 --> 00:21:02,080
into US, whatever Europe kind of
discussion. 

361
00:21:02,080 --> 00:21:06,360
I'd rather want to abstract, 
like have an abstract view on 

362
00:21:06,360 --> 00:21:10,360
the way that this is approached.
Do you have insights on that, on

363
00:21:10,360 --> 00:21:14,040
how this is moving forward 
according to your views? 

364
00:21:14,040 --> 00:21:17,800
This is something I've said for 
for years in tech that we would 

365
00:21:17,800 --> 00:21:20,920
see. 
So in kinetic defense, like 

366
00:21:21,000 --> 00:21:25,200
order defense, we would see 
actors behave in a in a specific

367
00:21:25,200 --> 00:21:27,400
way. 
We would see actors pretending 

368
00:21:27,400 --> 00:21:31,080
to be just benign activity. 
And that's really you can really

369
00:21:31,080 --> 00:21:34,600
correlate it to, for example, 
network defense of you're saying

370
00:21:34,800 --> 00:21:39,720
are you see actor go low and 
slow and or actor not automating

371
00:21:39,720 --> 00:21:42,840
but or making different 
automation that doesn't look 

372
00:21:42,840 --> 00:21:47,200
like it's repetitive activity. 
What I have seen is that actors,

373
00:21:47,200 --> 00:21:51,760
bad actors, no matter what they 
are, their main job is to learn 

374
00:21:51,760 --> 00:21:54,080
your defenses. 
And once they figure out your 

375
00:21:54,080 --> 00:21:57,760
defenses, they will start 
chaining A vulnerability and 

376
00:21:57,760 --> 00:22:00,000
another vulnerability and 
another vulnerability. 

377
00:22:00,000 --> 00:22:04,160
So an example would be you have 
a fence with the border, you 

378
00:22:04,160 --> 00:22:07,280
have cameras on the fence. 
You will it will it will take 

379
00:22:07,280 --> 00:22:09,880
them, could take them a year. 
They will find the place where 

380
00:22:10,000 --> 00:22:12,600
they get to the fence and you're
not seeing them with the 

381
00:22:12,600 --> 00:22:15,280
cameras. 
And then they will see how long 

382
00:22:15,280 --> 00:22:18,520
it takes you to actually show up
when they touch the fence. 

383
00:22:18,520 --> 00:22:20,760
And what do they need to do if 
they need to not touch the 

384
00:22:20,760 --> 00:22:24,640
fence. 
And then a lot of times we see 

385
00:22:24,640 --> 00:22:29,920
those as specific atomic 
instances and we'll say, oh, so 

386
00:22:29,920 --> 00:22:32,400
we need to add a camera here. 
Oh, we need a response time to 

387
00:22:32,400 --> 00:22:34,840
be faster. 
But what they're doing is 

388
00:22:34,840 --> 00:22:38,960
they're testing, continuously 
testing until they can say I 

389
00:22:38,960 --> 00:22:44,160
know instead of a zero day, I 
can now say that I know exactly 

390
00:22:44,160 --> 00:22:47,960
where you can't see me, how long
it is until you see me. 

391
00:22:48,240 --> 00:22:51,280
If I, if I do something, how 
long it will take you to get 

392
00:22:51,280 --> 00:22:53,560
here. 
And then I can figure out my 

393
00:22:53,560 --> 00:22:56,360
tactic around that. 
Where do I strike? 

394
00:22:56,440 --> 00:22:59,360
How long will it take? 
What exactly what are the tools 

395
00:22:59,360 --> 00:23:01,920
that I need to use in order for 
you to not see me? 

396
00:23:02,480 --> 00:23:04,840
I think that the military is a 
lot better at that because their

397
00:23:04,840 --> 00:23:06,640
lifes are at stake. 
There aren't metrics that you 

398
00:23:06,640 --> 00:23:08,720
need to measure. 
You measure and how many people 

399
00:23:08,720 --> 00:23:10,360
died. 
You don't even measure that. 

400
00:23:10,400 --> 00:23:13,200
But there's a lot of in the, in 
the military that there was 

401
00:23:13,200 --> 00:23:17,200
constant learning. 
And I, I think this is a part of

402
00:23:17,320 --> 00:23:21,520
kind of space that I'm seeing 
that there is time to learn. 

403
00:23:21,520 --> 00:23:24,280
We are constantly chasing the 
new thing that's happening. 

404
00:23:24,440 --> 00:23:29,680
We are unable to, to learn which
is, which is, it's a scale 

405
00:23:29,680 --> 00:23:31,360
issue. 
It's how many attackers are 

406
00:23:31,360 --> 00:23:33,680
attacking you issue, which the 
military doesn't have in the 

407
00:23:33,680 --> 00:23:35,880
same way. 
But that's the thing that I've 

408
00:23:35,880 --> 00:23:39,120
been always leaning towards at 
any company that I've been. 

409
00:23:39,120 --> 00:23:41,800
I said, OK, there was a big 
attack, something happened. 

410
00:23:42,120 --> 00:23:44,240
Are we doing a postmortem? 
And you would start doing a 

411
00:23:44,240 --> 00:23:46,600
postmortem and then who has time
for that? 

412
00:23:46,800 --> 00:23:49,200
A new, new fire came. 
Now we need to fix this. 

413
00:23:49,200 --> 00:23:53,760
So that's at least when I look 
at at issues like that, I look 

414
00:23:53,760 --> 00:23:56,640
at them from that perspective. 
And for someone who's now 

415
00:23:56,680 --> 00:23:59,280
building up a threat 
intelligence team, what are the 

416
00:23:59,280 --> 00:24:02,280
top three things that you would 
advise them to do? 

417
00:24:02,880 --> 00:24:08,080
The top thing to do first is to 
understand your platform as well

418
00:24:08,080 --> 00:24:10,280
as you can. 
It's very, very hard, but you 

419
00:24:10,280 --> 00:24:13,840
really need to understand the 
platform and appreciate that 

420
00:24:13,840 --> 00:24:15,680
you're not going to understand 
the platform as well as your 

421
00:24:15,680 --> 00:24:18,560
attackers, but do your very, 
very best to understand the 

422
00:24:18,560 --> 00:24:22,360
attackers, the platform. 
Then the second thing is to 

423
00:24:22,400 --> 00:24:27,360
break down your adversaries into
adversaries that are are 

424
00:24:27,360 --> 00:24:30,440
opportunistic or like low 
sophistication. 

425
00:24:30,440 --> 00:24:34,040
And then kind of what's the 
scale of that versus attackers 

426
00:24:34,040 --> 00:24:36,640
that are going to attack you? 
They're going to wait and do 

427
00:24:36,640 --> 00:24:40,880
something massive and and work 
with that the and can really 

428
00:24:40,880 --> 00:24:43,800
understand the threat actor 
journeys for both. 

429
00:24:43,880 --> 00:24:48,480
The last critical thing is 
relationships must be on 

430
00:24:48,480 --> 00:24:50,920
understanding your product. 
You must if you're a threat 

431
00:24:50,920 --> 00:24:53,880
Intel team, you need to 
understand how the detection 

432
00:24:53,880 --> 00:24:56,480
teams work. 
What do they need from you? 

433
00:24:57,360 --> 00:25:03,000
What are they gold on and then 
work with them to empower them 

434
00:25:03,080 --> 00:25:07,280
and the business versus being a 
team that says no, don't do this

435
00:25:07,280 --> 00:25:10,400
now do that you want to 
understand your partners and 

436
00:25:10,400 --> 00:25:15,400
then see how can I empower them 
to move forward safely and with 

437
00:25:15,400 --> 00:25:19,520
adherence of the law and the 
word escapes me regulations. 

438
00:25:20,120 --> 00:25:24,120
If we now come back to the lab 
that you built and the platform 

439
00:25:24,120 --> 00:25:27,360
that you aim to deploy in the 
future, so how does provenance 

440
00:25:27,360 --> 00:25:31,680
help us rebuild the concept of 
evidence in that world and also 

441
00:25:31,680 --> 00:25:34,240
for a particular potential 
users? 

442
00:25:34,360 --> 00:25:37,920
So that's a great question. 
The, the most critical thing 

443
00:25:37,960 --> 00:25:42,400
that I'm thinking about when I'm
building is how do we build a 

444
00:25:42,400 --> 00:25:46,920
knowledge corpus that we know an
attack happened or, or we 

445
00:25:46,920 --> 00:25:50,000
learned something. 
Now we can utilize it to learn 

446
00:25:50,000 --> 00:25:53,280
something else or now we can, 
when something new comes, we can

447
00:25:53,280 --> 00:25:57,840
say we actually have this in 
our, in our, you know, evidence 

448
00:25:57,840 --> 00:26:00,520
storage. 
And we, we put a new report and 

449
00:26:00,520 --> 00:26:04,440
we say actually that's another 
attack that happened somewhere 

450
00:26:04,440 --> 00:26:08,120
else or happened with us a month
ago, a year ago, or this is 

451
00:26:08,120 --> 00:26:10,560
something that we got from the 
FBI couple of months ago. 

452
00:26:10,560 --> 00:26:13,480
We should actually incorporate 
that information into what we're

453
00:26:13,480 --> 00:26:15,360
doing. 
The way I was thinking about it 

454
00:26:15,360 --> 00:26:19,440
is one, we create this knowledge
corpus of everything that's 

455
00:26:19,440 --> 00:26:24,400
happening and two, we are able 
to remove the friction between 

456
00:26:24,400 --> 00:26:27,320
teams into something that flows 
a lot faster. 

457
00:26:27,440 --> 00:26:30,440
Instead of producing something 
that an detection engineer will 

458
00:26:30,440 --> 00:26:34,040
have to now figure out what to 
do with, you produce them with 

459
00:26:34,240 --> 00:26:38,080
here's here's actual detection 
that you just need to review and

460
00:26:38,080 --> 00:26:41,080
deploy and then you can go do 
the other things you want to do.

461
00:26:41,160 --> 00:26:44,720
This actually brings all these 
teams together into having the 

462
00:26:44,720 --> 00:26:47,320
ability to circumvent the 
attackers together. 

463
00:26:47,480 --> 00:26:51,280
And if you now look ahead in a 
near future, what do you see? 

464
00:26:51,360 --> 00:26:55,480
What will be critical to deploy 
and also to follow through from 

465
00:26:55,520 --> 00:26:59,040
a platform provider and from a 
user perspective? 

466
00:26:59,080 --> 00:27:05,160
So I think one of the critical 
things to deploy are well is, is

467
00:27:05,160 --> 00:27:09,200
a robust understanding. 
We are currently talking about 

468
00:27:09,200 --> 00:27:11,800
it. 
I see people frustrated with 

469
00:27:11,800 --> 00:27:14,960
attacks that keep coming back. 
They that I see it a lot in 

470
00:27:14,960 --> 00:27:20,680
scams of we are expecting other 
other entities to save us. 

471
00:27:20,680 --> 00:27:25,320
For example, we're expecting the
government to create rules to to

472
00:27:25,320 --> 00:27:27,480
save us, which which is great. 
The government, the government 

473
00:27:27,480 --> 00:27:29,880
creates rules that makes 
companies do things. 

474
00:27:29,880 --> 00:27:34,000
That's great that that usually 
doesn't happen because what 

475
00:27:34,000 --> 00:27:37,680
happens is that the government 
creates rules, smart company 

476
00:27:37,680 --> 00:27:40,400
figures out how to do the very 
bare minimum. 

477
00:27:40,400 --> 00:27:44,520
So I think what we need to move 
forward is if I think about it 

478
00:27:44,520 --> 00:27:47,200
from the AI perspective, is one 
of the things that's really 

479
00:27:47,200 --> 00:27:51,720
critical is not to look at AI as
how can we use, how can we have 

480
00:27:51,720 --> 00:27:53,680
less people? 
How can we reduce headcount? 

481
00:27:53,840 --> 00:27:58,680
But instead, how do we give the 
people that we have superpowers 

482
00:27:58,760 --> 00:28:01,240
so they're faster. 
They're, they can, they can 

483
00:28:01,240 --> 00:28:04,200
analyze things faster, they can 
deploy things faster. 

484
00:28:04,360 --> 00:28:07,800
And that's again where the trust
comes in and the Providence 

485
00:28:07,800 --> 00:28:11,360
comes in that as we move faster,
we also need to move with 

486
00:28:11,360 --> 00:28:13,720
confidence. 
We need to know that what we're 

487
00:28:13,720 --> 00:28:17,600
doing is the correct issue so we
don't fall back into 

488
00:28:17,600 --> 00:28:19,960
firefighting. 
Most teams are just stuck in 

489
00:28:19,960 --> 00:28:23,120
firefighting mode and it's very,
very hard to get out of that. 

490
00:28:23,280 --> 00:28:26,640
But I think if we don't get out 
of firefighting mode, we're 

491
00:28:26,640 --> 00:28:29,120
going to continue losing. 
We're now coming to the end of 

492
00:28:29,120 --> 00:28:32,320
our podcast, even though I could
talk to you probably for another

493
00:28:32,320 --> 00:28:34,760
hour. 
And before we end our 

494
00:28:34,760 --> 00:28:37,560
conversation, I want to get into
some in between moments with 

495
00:28:37,560 --> 00:28:39,200
you. 
At the first moment that I want 

496
00:28:39,200 --> 00:28:43,200
to start with you is what does 
trust online feels like to you? 

497
00:28:43,320 --> 00:28:46,880
Currently, Trust Online feels 
like a pipe dream, like fiction.

498
00:28:46,920 --> 00:28:50,840
And what is the one thing that 
AI must verify in the future? 

499
00:28:50,840 --> 00:28:53,640
AI needs to verify both the 
output and the input. 

500
00:28:53,680 --> 00:28:58,520
Have AI verify both the input 
that is not junk and the output 

501
00:28:58,520 --> 00:29:02,480
that it can actually relates to 
something that wasn't invented 

502
00:29:02,480 --> 00:29:05,160
by the LLM. 
What is the biggest blind spot 

503
00:29:05,160 --> 00:29:08,560
in information security? 
Bias on that, But the biggest 

504
00:29:08,560 --> 00:29:11,120
blind spot is adversarial 
complexity. 

505
00:29:11,280 --> 00:29:14,360
Everybody likes to talk about 
adversarial complexity, but then

506
00:29:14,360 --> 00:29:18,400
it ends up being a discussion 
about 0 days, which persistent 

507
00:29:18,400 --> 00:29:21,400
actors don't use zero days Willy
nilly. 

508
00:29:21,400 --> 00:29:25,600
They consistently get around you
daily without 0 days. 

509
00:29:25,720 --> 00:29:28,120
I need a sidestep here. 
What are 0 days 0? 

510
00:29:28,160 --> 00:29:30,520
Day is an exploit that nobody 
has heard of before. 

511
00:29:31,400 --> 00:29:34,920
Is this is a new vulnerability 
that nobody has heard of that 

512
00:29:34,920 --> 00:29:38,080
they can they can now leverage 
and there are no defenses for it

513
00:29:38,080 --> 00:29:40,280
because this is the first time 
it's ever been used. 

514
00:29:40,400 --> 00:29:41,120
All right. 
Understood. 

515
00:29:42,200 --> 00:29:46,680
What does provenance unlock? 
Provenance unlocks trust in the 

516
00:29:46,680 --> 00:29:51,760
system, trust in the fact that 
you can move forward without 

517
00:29:51,760 --> 00:29:53,920
without creating a additional 
fiction. 

518
00:29:53,960 --> 00:29:56,880
What is the future that we are 
not preparing for? 

519
00:29:57,120 --> 00:29:59,880
I think we're not preparing. 
I think we're talking about it a

520
00:29:59,880 --> 00:30:03,080
lot, but nobody's really 
preparing for the future where 

521
00:30:03,080 --> 00:30:07,120
threat actors will be using 
image, voice, video generation 

522
00:30:07,120 --> 00:30:12,240
to completely go around any 
current static mitigations. 

523
00:30:12,240 --> 00:30:14,840
And what is one word that you're
currently in between? 

524
00:30:14,840 --> 00:30:18,520
Currently in between. 
I'm currently stuck on on 

525
00:30:18,520 --> 00:30:22,080
accuracy and robustness. 
I think those are the words. 

526
00:30:22,480 --> 00:30:26,280
What do you mean with that? 
So as I'm building and working 

527
00:30:26,280 --> 00:30:31,240
with partners and people to work
with on deploying this product, 

528
00:30:31,440 --> 00:30:34,960
I constantly see opportunities 
to make the rules more robust, 

529
00:30:34,960 --> 00:30:38,320
to make the rules more accurate.
But that's how you get into 

530
00:30:38,320 --> 00:30:42,080
analysis paralysis of like, we 
are not, we are not there yet. 

531
00:30:42,080 --> 00:30:44,360
We're not there yet where we 
need to worry about that, that 

532
00:30:44,360 --> 00:30:46,120
much. 
This needs to work. 

533
00:30:46,120 --> 00:30:48,480
And then we'll see how we make 
it work better. 

534
00:30:48,480 --> 00:30:52,600
But accuracy is very important 
to me and also robustness that 

535
00:30:52,600 --> 00:30:55,840
I'm not telling you here's an 
attack or here's a threat. 

536
00:30:55,840 --> 00:30:57,240
And this is how you can mitigate
it. 

537
00:30:57,440 --> 00:31:00,480
And you can say, oh, actually 
you're missing a bunch of parts.

538
00:31:00,640 --> 00:31:02,240
That's that's the thing that 
scares me the most. 

539
00:31:02,240 --> 00:31:06,240
For now, thank you so much for 
the time, for sharing all your 

540
00:31:06,240 --> 00:31:08,840
insights, and for joining us on 
the podcast. 

541
00:31:09,000 --> 00:31:10,400
Thank you so much. 
I appreciate it.

